France accelerates online age verification
France has become, in just a few months, one of the most active European countries regarding online age-based access control. Two major texts structure this policy: the SREN law (Law No. 2024-449 of May 21, 2024), which imposes robust age verification to access pornographic content, and a new law adopted by Parliament in July 2026, which prohibits social media for individuals under 15 years old starting January 2027.
These initiatives, championed by President Emmanuel Macron and defended in the name of minors’ mental health, are also inspired by the Australian example, which has prohibited access to social media for those under 16 since December 2025.
A binding technical framework via Arcom
Under the SREN law, Arcom (the regulatory authority for audiovisual and digital media) published a technical framework on October 11, 2024, gradually coming into effect until April 2025. This framework is based on four pillars:
- Reliability and non-discrimination of verification methods;
- Independence of the verifier (a third party separate from the platform);
- Double-blind confidentiality (the verifier does not know the visited site, and the site does not know the user's identity);
- Minimization and non-retention of data.
Platforms must offer at least two methods of verification, one of which must be double-blind. Penalties for non-compliance are heavy: up to 2% of global revenue in case of breach, and up to 6% in case of reoffending. Arcom can also order blocking and de-indexing by ISPs within 48 hours.
Verification methods: biotechnology and identity documents
The methods validated by Arcom include:
- Age estimation via biometrics: analysis of a selfie combined with AI-based liveliness detection;
- Identity document verification: with 1:1 facial matching and liveliness detection;
- Reusable identifiers: digital identity wallets to minimize friction.
This is precisely where the issue arises for defenders of digital freedoms.
Why this is a problem: privacy concerns
1. Large-scale biometric data collection
AI-based age estimation relies on analyzing the user's face. Even though the "double-blind" model is intended to prevent correlation between identity and the site visited, the technical reality raises questions:
- What happens to the facial image after analysis? The framework foresees non-retention, but trust in the effective destruction of data entirely depends on the service provider.
- Who certifies the providers? The age verification ecosystem is dominated by private companies (Didit, Yoti, etc.) whose algorithms are opaque.
- What is the real accuracy? AI-based age estimation systems are known for their discriminatory biases, especially based on gender, ethnicity, or facial morphology.
2. A dangerous precedent for mass surveillance
The validation of "per-session" age verification means that each connection can generate a traceable authentication token. Critics fear that this infrastructure could someday be used for other purposes: content control, political surveillance, behavioral profiling.
The double-blind model is technically appealing on paper, but it creates a centralized authentication infrastructure that could be misused in the future.
3. The dubious effectiveness of bans
The Australian example is telling: according to the Australian eSafety Commission, seven out of ten children under 16 with an account before the ban still had access to platforms in March 2026. Technical workarounds (VPNs, fake accounts, non-compliant platforms) remain widely accessible.
4. The risk of pushing towards unregulated spaces
Security and child protection experts warn: a strict ban could drive minors to less moderated alternative platforms, where risks (cyberbullying, illegal content, predation) are heightened.
5. Restricting access to information
Civil society organizations emphasize that social media are also a vector for information, education, and civic participation for young people. A blanket ban risks depriving adolescents of these spaces without distinction between a public social network and a supervised discussion platform.
A European movement underway
France is not isolated. European Commission President Ursula von der Leyen has proposed delaying children's access to social media. The UK is also considering a ban for those under 16 starting January 2027. This movement is creating a continental dynamic that could redefine the relationship between privacy and the protection of minors online.
In conclusion
The desire to protect minors is legitimate and widely shared. However, the measures adopted in France raise a fundamental dilemma: can we verify the age of everyone without creating a permanent digital surveillance infrastructure? The technical response of “double-blind” attempts to reconcile both, but the risks of drift, limited effectiveness, and large-scale biometric collection remain real. The debate is far from over — it has only just begun.