Technical facts disproving political and tech claims on online child safety:
Protecting children online requires knowing who is a child. Knowing who is a child requires knowing ages. Knowing ages requires knowing everyone's age across all devices, apps, and internet services. That requires age checking services.
Age checking services cannot comply with government mandates to be "robust". "Robust" age checking originated in Australia and is now in US and EU legislation. It means "best endeavours" with specific legal intent.
"Robust" age checking requires proving age beyond doubt. Age estimation services can never be "robust". You cannot have a "robust" service without verifying everyone's identity through government issued ID or extensive personal, financial, or behavioural data. Without enough data, device, app, or service access is denied until official ID is provided.
Verifying every identity destroys privacy. Storing verification data on servers creates instant risk. Identity verification enables governments to monitor citizens and censor speech. As Larry Ellison said, people change behaviour when monitored through digital surveillance.
Parents can already protect children from online harms using existing technology. In 2012, I demonstrated poor parental controls on BBC Newsnight, leading me to build early safety tools for Samsung and Apple. I also built the first Android time curfew capability 14 years ago.
Today, iOS and Android offer built in controls to block unsuitable apps, websites, and content by age rating, alongside granular curfews. Real world risks like bullying exist online, but parents can manage access just as they manage real world exposure.
Exhibit A: If parents can already block access for free on their own phones, why do governments push legislation that forces identity collection, exposing data to cybercriminals and tech companies?
Exhibit B: Why are governments, tech companies, and NGOs not educating parents on existing settings that are free of charge and "robust", even while citing tragic cases to push legislation?
In 2004, I co-founded the W3C standard for Content Labelling and URI Classification, co-inventing account and folder classification to label content based on risk and compliance. I advocated for voluntary account verification to stop impersonation long before people knew it was even possible.
Mandatory identity verification to use a phone or internet service is dystopian control. I would never advocate or support that.
I have advised the US DOJ, NCMEC, CEOP, and IWF on child exploitation detection. EU Chat Control and UK image scanning mandates will not tackle exploitation. They break end to end encryption and VPNs, introducing dangerous spyware, and puts more children at risk.