the surveillance state(s)
Legislative Trojan horses
🇪🇺 Chat Control 1.0 and 2.0
🇪🇺 Social media ban for children
🇪🇺 Addictive design ban for adults
🇪🇺 Combat fraud and serious crime
🇦🇺 Social media ban for children
🇺🇸 Social media ban for children
🇺🇸 Addictive design restrictions for children
🇳🇿 Social media ban for children
🇮🇪 Social media ban for children
🇫🇷 Social media ban for children
🇨🇦 Social media ban for children
🇬🇧 Social media ban for children
🇬🇧 Addictive design restrictions for children
🇬🇧 Child exploitation & grooming protection
🇬🇧 Force platforms to prioritise "trusted" news
🇦🇪 Social media ban for children
🇪🇸 Social media ban for children
🇬🇷 Social media ban for children
🇩🇰 Social media ban for children
🇳🇴 Social media ban for children
🇦🇹 Social media ban for children
🇵🇱 Social media ban for children
🇸🇮 Social media ban for children
🇹🇷 Social media ban for children
🇮🇩 Social media ban for children
🇲🇾 Social media ban for children
🇧🇷 Social media restrictions for children
🇵🇹 Social media restrictions for children
🇮🇳 Social media ban for children
🇸🇪 Social media ban for children
🇩🇪 Social media restrictions for children
🇮🇹 Social media restrictions for children
🇨🇳 Social media restrictions for children
I’m sharing this because more journalists have started following my work, and I want to show what I’m exposing through technical analysis anyone can understand.
I’m working on one of my most consequential investigations into legislation and technology built for digital surveillance. It’s called Chat Control. What follows looks like coordination between governments and a handful of tech companies.
Tech companies get more data to monetise. Governments gain the ability to monitor who says what, to whom, why, where they go and how they spend money.
Technical Trojan horses
🇪🇺 Compulsory identity verification
🇪🇺 Scan private communications
🇪🇺 Weaken end to end encryption
🇪🇺 Expand lawful access
🇬🇧 Compulsory identity verification
🇬🇧 Compulsory on-device scanning for every app
🇬🇧 Algorithms to prioritize trusted news sources
🇦🇺 Compulsory identity verification
🇳🇿 Compulsory identity verification
🇮🇪 Compulsory identity verification
🇫🇷 Compulsory identity verification
🇪🇸 Compulsory identity verification
🇬🇷 Compulsory identity verification
🇩🇰 Compulsory identity verification
🇳🇴 Compulsory identity verification
🇦🇹 Compulsory identity verification
🇵🇱 Compulsory identity verification
🇸🇮 Compulsory identity verification
🇹🇷 Compulsory identity verification
🇦🇪 Compulsory identity verification
🇮🇩 Compulsory identity verification
🇲🇾 Compulsory identity verification
🇧🇷 Compulsory identity verification
🇵🇹 Compulsory identity verification
🇨🇦 Compulsory identity verification
🇺🇸 Compulsory identity verification
Spot the pattern.
🔞 Australia set the stage. Other countries are now following with "robust" age assurance language in their TV appearances, including the US, UK and Ireland. The US AGs have added it to the proposed legislation following the Meta lawsuit.
💡 Australia’s own standard says age checks must be "technically accurate, robust, and reliable".
"Robust" means fault proof. It brings meaning like "best" endeavours.
Age estimation can’t meet that standard. As Australia defines it, age verification determines age "to a high level of accuracy", while age estimation only provides an approximate age.
Fault proof age checking requires identity verification.
Now look at the tech companies and what they built recently.
Apple, Google, Meta and Microsoft built identity verification capabilities before governments started saying existing age assurance wasn’t "robust" enough.
They knew what was coming.
🪪 Apple has age assurance APIs that can return verified age ranges, including confirmation using government ID, and its Wallet API lets apps verify age or identity from government issued digital ID.
🪪 Google recently built an Age Signals API so apps can receive age ranges and verification status. Android already lets parents block apps by age across the entire device, so this isn’t technically necessary for child safety.
Google has also added facial verification to Google Account and Gmail recovery through selfie video matching, presented as account security.
🪪 Meta launched selfie based Facebook verification that checks a video selfie against profile photos and plans to expand it globally.
🪪 Microsoft has rolled out age assurance across Microsoft Accounts using facial age estimation, identity documents and government systems. Refuse to verify and some content and features are blocked.
💭 A handful of tech companies control the operating systems, app stores and identity layers across almost every mobile device. Governments barely need to negotiate outside G7 rooms. If Apple, Google, Meta and Microsoft enforce the same rules, billions of people are instantly impacted.
The same technical capability keeps appearing: identify verification.
Identity the person first, then decide what they’re allowed to do, who they're allowed to speak to, and when they're allowed to move money.
p.s. Anthropic and OpenAI have identity verification services and the US government holds a kill switch that decides who has permission to use AI.
---
Let me know if I got anything wrong. I have 60 minutes to make an edit. Or just leave a comment so others can see your correction.