Think of the children!
![]()
Since the 27th of July, Austria's under-14 social media ban is no longer a plan but a text. The government has sent the draft out for consultation, the Begutachtung, which is the stage where anybody can file a written comment, and the deadline is the 21st of September.
This post has been sitting in my drafts since April. Not for lack of things to say, but because until recently there was nothing to go on. A press conference, a few statements and a great many confident summaries of a law that did not exist yet.
The most common question first, because for months it was mine too: do I need ID Austria, the state's digital identity app, for this? No. The app appears in the text of the bill exactly zero times. That roughly everybody believes the opposite comes down to most reports describing the press conference instead of the paragraphs. I fell for it myself in April.
Then the number I keep holding on to in this debate. In February, Marketagent, an Austrian polling firm, asked a thousand Austrians whether social media needs a legal minimum age. Ninety percent said yes, naming fifteen as the right age on average. The same survey also asked whether platforms can check age reliably. There, 62 percent said no.
Nine in ten want this law. Six in ten do not believe the platforms can deliver the part it stands on. Same questionnaire, same afternoon. I do not think those ninety percent are hysterical and I am not going to open a piece about child protection by talking the problem away.
I am writing this as a computer scientist, not as a lawyer or an educator. Which mostly means one thing: when a law says something has to be checked "according to the state of the art", my first question is not whether that is fair to ask of people, but whether the state of the art can do it at all. Most of what follows is simply what came out of looking.
What's in it is better than its reputation
Let's start with the part the outrage skips: the draft is smarter than the defiant "just ban TikTok" both sides like to shrink it to.
The new § 54e Abs. 3 Z 5 does not lock under-14s out of "social media". It locks them out of platforms that use any of five features:
- a recommender feed where more than a third of the content comes from strangers
- autoplay or infinite scroll
- reward mechanics built to drive interaction counts up
- notifications that nudge you to come back
- sharing with people you have no mutual contact relationship with
Pure messengers that only connect contacts you chose yourself meet none of the five features and stay out.
The list reads like the blueprint of an addiction machine. The explanatory notes say it openly: the target is addictive design, not the medium. And the research backs exactly that layer. The evidence that engagement-optimised design harms some adolescents is considerably stronger than the evidence that social media below age X harms across the board. A law aimed at the five mechanics stands on better ground than any blanket ban. That an Austrian draft of all things pulls this off, I did not expect.
The fines hit the platforms, not the children and not the parents either. Nor are they for show: up to now 150,000 euros at most, in future up to six percent of worldwide annual turnover for very large platforms. That is the weight class of the Digital Services Act, the EU's big platform law. The six percent come with one caveat though: almost every large platform sits in Dublin and whether Austria may fine them on its own is an open question, France got whistled back this year for exactly that kind of solo run.

The summer cabinet meeting on the 27th of July in Salzburg, where the draft was approved. On the left, Vice-Chancellor and media minister Andreas Babler, who carries the bill. Photo BKA/Andy Wenzel
Two things sit further back in the text though, and they made it into almost no report.
First: the same verification architecture also applies to the existing 18-plus rule for pornography. Which means this is no longer a regulation for a few school years of kids. It is the infrastructure for the question of when anybody in this country has to show ID on the internet.
Second, Abs. 3b, subsection 3b in Austrian legal shorthand, says how reliably the age has to be established: by a standard of care that matches or is equivalent to the Finanzmarkt-Geldwäschegesetz, Austria's financial-market anti-money-laundering act. That act is the standard a bank uses to screen you when you open an account. Remember this subsection, it comes back later.
What's promised is not in the law
State Secretary Alexander Pröll sold the verification like this: "no passport, no data, no home address" reaches the platforms. The Chancellery describes a "double-blind" model with zero-knowledge proofs, cryptography that proves "over 14" without revealing who you are. Sounds splendid.
Now the part you have to open the text for. That ID Austria appears zero times, we had already. "Zero-knowledge" appears exactly as often, I searched. Not that the draft is silent on privacy, quite the opposite: Abs. 3a demands the most data-minimising methods available according to the state of the art, unobservability and unlinkability (the verifier must not learn where you use the proof, nobody may trace it back to you) and no central log of who was checked where. That really is in the text and it is more than most countries ever wrote down. Right next to it sits Abs. 3b with the bank-grade check though. The two go together: establish the identity once, then pass on nothing but "over 14", but the establishing happens. And what becomes of the ID data collected along the way, how long who may store it and when it has to be deleted, the draft regulates with not a single word, as the Greens alone say out loud.
The result is a text from which three observers pulled three different truths, all of them defensible. NEOS, the liberal party inside the governing coalition, read: "no real-name requirement, ID Austria just one option". The German tech site heise reads: "compulsory ID". The Greens, in opposition, read: "in effect a register of every person who wants to use social media". All three are looking at the same paragraph. That only works because the paragraph contains anonymity as a requirement and the bank-grade check as a duty at the same time and stays silent on the third question, where the data ends up.
To be fair in both directions: whoever writes that Austria is making ID Austria compulsory is wrong, measured against the text. But the all-clear is no all-clear either: if the method stays open and nobody regulates what becomes of the ID data, then it is not parliament that decides the privacy price of this law. It is the platforms' procurement departments deciding it later. No mandate, but an open door.
In case you are wondering how final all this is: not at all. The text is a draft in the middle of exactly this consultation phase, after that it goes to parliament and plenty can still change there. The gaps could get plugged by then and I hope they will be. Only the government is advertising its privacy promises now, on the basis of exactly this text, in which they do not appear. What is being sold is a version of the law that does not exist yet.
The calendar
Three dates govern this law. On the 1st of January 2027 it enters into force. By the 31st of March 2027 the platforms have to comply. And the certification bodies that are supposed to sign off which age check counts in the first place? Expected mid-2027. The law is thus in force half a year before the institutions that are supposed to run it exist. Even the platforms have to deliver three months before there are certifiers. That is not a privacy objection and not ideology, it is simply a calendar. The fourth line in the diagram, the EU deadline, belongs to the wallet, more on that in a second.
So check with what? The draft prescribes no method and the three tools floating around for the job all fall away. The certification bodies do not exist even on paper yet, and what the trade press expects of them once they do, its comparison of choice says plainly: Kaufhaus Österreich, the state-run web shop that went down in 2020 under general ridicule and became Austria's byword for failed government IT. The European age verification app has appeared in not a single member state and has still been publicly broken twice already (April, July), most recently with a browser extension that simply reuses somebody else's age proof. A proof that for privacy reasons is bound to nobody works like a festival wristband, no matter whose wrist it came from. That is not a bug of this one app, it is the price of any anonymous check, more on that under the proposals. And the wallet? That is the state's planned digital wallet, where ID Austria and an age proof like this are supposed to live one day, and Austria has to offer it like every EU state by the 24th of December 2026. The Chancellor's answer to a parliamentary question about it: a budget of twelve million, additional staff none, external contractors "not envisaged", five months before the deadline. The money is there, nobody is working with it.
Of course parliament can still move the dates. But a draft whose execution is months late already on paper tells you rather precisely what mattered more: entering into force or working. On the 31st of March 2027 there is a duty and none of the things you would fulfil it with. The platforms pick method and contractor themselves, and the starting state is foreseeably what exists today: a birthday field. Or, the other direction, straight to the ID, more on that later. How that plays out has luckily been measured already.
Three countries, three ways to fail
Every discussion opens with the determined teenager outsmarting the face scanner. Luckily there is a country where you can look up how it actually goes: Australia has banned social media accounts under sixteen since December 2025, the strictest law of its kind in the Western world. And the data from there tells a less spectacular story: outsmarting is rare, mostly there is no scanner standing there at all.
The Molly Rose Foundation, a British child-safety organisation founded after the suicide of fourteen-year-old Molly Russell, surveyed 1,050 Australian children between 12 and 15: more than half still had access to their accounts, and of those, about six in ten said the platform had done nothing with their account whatsoever. The Australian regulator eSafety found the same thing from the other side: the most common reason a child's account survived was simply that nobody ever asked about age.
That was the questionnaire side, the measurements say the same. A study in the British Medical Journal measures more than 85 percent of under-16s still on the restricted platforms, with or without an account of their own. And a working paper by the US National Bureau of Economic Research estimates how many minors the ban actually keeps out: 27 percent in April, six two months later. The effect crumbles as more children find the way back in.
And the second-favourite argument along with it: no, it is not the VPNs. VPN use among the affected children sat at four to five percent per platform. The actual circumvention is a birthday field and the older brother's account. The Austrian draft, by the way, has verification happen once per account, not at every login. Data-minimising thinking, only the borrowed brother's account stays open permanently that way. No technology helps against that, because the system is not being outsmarted, it simply does not exist.
For honesty's sake the counter-numbers, they exist. The parental-control app Qustodio is the only Australian source measuring directly on the device instead of by questionnaire, and it sees Snapchat use among Australian 13 to 15 year olds genuinely fall, by more than the Australian summer holidays the ban launched into would explain. A weak filter is measurably not the same as none. The same data shows the effect already fading again though, and whether any child is doing better, none of these numbers answers. The BMJ study did not even measure wellbeing.
The obvious objection: their own fault. Whoever passes a ban but prescribes no method and does not consistently punish violations should not be surprised by the result. True, only that sentence does not describe Australian sloppiness, it describes rather exactly the starting position Austria lines up with on the 31st of March 2027: duty yes, method open, nobody to say which method satisfies the bank-grade check. Australia even had more at launch, namely a finished regulator with million-dollar fines in the law. It has measurably done the children there little good.
And checking harder does not save the day either, because for that there is the counter-example: Britain, where checking actually happens. More than 69 million age checks in six months, all ten of the country's largest pornography sites dutifully locked. The result is in the remarkably honest report of the regulator Ofcom: the number of gated services among the hundred biggest is falling again, because the traffic wanders to the ungated ones.
Where it wanders, the Washington Post has measured: of the 90 biggest pornography sites in the country, 14 do not check at all, and exactly those 14 grew briskly, one doubled its British visits to over 350,000 a month. Some explain Tor to their users right away, the anonymisation browser that also gets you into the darknet, the place no regulator and no age check in the world ever reaches. A pornography site has exactly one reason to recommend a tool like that to its visitors: the customers should be able to keep clicking without any law getting in the way, whatever their age. And exactly there, according to child-protection experts, the more extreme content circulates too, up to and including abuse imagery. The age check thus works as a state-ordered detour to the sites that follow no rules at all.
Ofcom's own verdict: effective at the level of the individual service, not at the level of the sector. And the share of children reporting harmful content sat at 73 percent a few months after the checks started. Before, it was 70.
And South Korea is the stress test for the argument that you just have to be strict enough. The only country that ever enforced with a real state identity number scrapped its night-time gaming ban for under-16s after ten years. Enforcement worked, and the measurable yield per the Journal of Adolescent Health and a second evaluation: practically no change in internet use and about a minute and a half of sleep per child. When Korea's media regulator thinks about age limits for social media today, it cites its own law as a warning.
You can pick whichever of the three ways to fail hurts least. The Molly Rose Foundation, really not an anti-regulation lobby, draws a remarkable conclusion from all of it: it would be "deeply unwise" for other countries to follow with social media bans now.
That is the child-protection organisation talking, and Austria follows anyway.
The wrong number and the technology that can't hit it
Even if you push all of that aside, two problems remain that every age-threshold law drags along: the number itself and the question whether any technology can measure it.
The number first. The best available work on it comes from Orben, Przybylski and colleagues, of all people the research group that usually warns against overstated effects in this debate. With data from about 84,000 British adolescents they showed: the association between social media use and falling life satisfaction clusters in age windows, for girls 11 to 13, for boys 14 to 15, for both again around 19.
Austria's line sits at fourteen. It ends exactly after the girls' window and in the middle of the boys' one. It also was not chosen from developmental research but from the legal order: fourteen is where Austrian law stops treating you as a minor in the strict sense, where limited contractual capacity begins and where the GDPR age of digital consent sits. Australia and the EU Parliament say sixteen, the EU Commission's expert panel says thirteen. If the same evidence can justify numbers from thirteen to sixteen, it justifies none of them.
The technology. Australia let its field trial cost it 6.5 million Australian dollars, 48 vendors, more than 28,000 facial image tests. The headline of the final report: age assurance can be done "privately, efficiently and effectively". The tables of the same report: at a 16 gate, 73.3 percent of fifteen-year-olds get through, 13.9 percent of sixteen-year-olds are wrongly turned away and around every gate the report itself concedes a grey zone of two to three years. Fourteen, fifteen, sixteen: every threshold discussed in Europe sits entirely inside that grey zone.
Plus one detail you need to know: the trial was run by a certification company that, by its own conflict-of-interest register, sells certificates to exactly the vendors it tested. The examiner earns on the success of the examined. Accordingly, the numbers diverge: the company itself says its face estimation is off by one and a half years on average, while the US standards institute NIST, which tests the same technology independently, measures three to five years for adolescents. You may pick whom to believe, only one of the two lives off selling good grades.
Where the IDs end up
So face estimation cannot hit the chosen thresholds, which means reliable checking comes down to documents. That is how the ID enters the picture, not because anybody mandates it, but because the alternative is too imprecise. The benchmark is already in the draft: Abs. 3b, the bank-grade check. The only open question is where the documents sit afterwards. Discord can tell you about that: 70,000 ID photos of its users leaked in 2025, not at Discord itself, but at an external contractor whose name hardly anybody knew before. The draft that will make contractors like that everyday business in Austria regulates neither retention period nor deletion duty nor who may take a document into their hands at all. The objection that the GDPR covers this anyway is limited comfort, because it was in force in 2025 too.
And the leak is not even the worst scenario, the worst is normal operation: your account is then firmly tied to your ID. Instagram offers ID upload today already, the photo then sits 30 days on Meta's servers. Meta is a US corporation and the CLOUD Act obliges US corporations to hand data to their authorities, even when it sits on European servers. What you post is then no longer just roughly attributable to you, but officially.
That hits everybody who needs pseudonymity first: whistleblowers, journalists and their sources. And, in doubt, you. The USA under Trump have been screening the social media profiles of visa applicants since last year, students have to set their accounts to public, the search is for "hostile attitudes" towards America and around 1,500 student visas have already been revoked, many over postings. An age system that ties accounts to IDs does the attribution for checks like that free of charge.
A free hand for the platforms therefore does not mean a little privacy risk. It means: either nothing happens at all, today's birthday field. Or the maximum happens, the ID at the corporation. The draft leaves the choice to the platforms, and neither of the two ends was chosen for you.
What I would do instead
Just being against things is cheap, so concretely:
Regulate the five mechanics for everybody instead of locking children out. The best part of the draft is the feature list and its evidence holds. Infinite scroll, autoplay, streaks and nightly push cascades can be regulated without knowing anybody's age. Do it for everybody and the identification question disappears completely. And "for everybody" would really mean everybody, because being grown up does not make you immune to this design: when economists paid adults to deactivate Facebook for four weeks, they got measurably better, and a follow-up study estimates that about a third of social media use comes down to plain self-control problems. Yes, that is the bigger intervention in the product, but the smaller one in fundamental rights.
Enforce existing law before writing new law. The DSA has long obliged large platforms to protect minors and the Commission has been running proceedings against TikTok and Meta since 2024. The result so far: preliminary findings, zero decisions. Ireland, responsible for almost every large platform in Europe, has had binding age verification rules for social networks for a year now, as the only country. Before building a new machine, you could switch on the one that exists. It would even have undisputed jurisdiction over Dublin, the jurisdiction question from earlier would not exist there.
Double anonymity as a must, not a may. France and Italy show how to write it down: double anonymity binding, a certified third party checks, the platform learns only "over N" and the verifier never learns where the proof is used. That is the double-blind from the press conference, only this time as law. Italy even rates its own state digital identity SPID as non-compliant, because it breaks exactly this blindness. By the same standard, ID Austria would be out as a verification method too. In the European specification, exactly this double anonymity is optional. Making it binding and adding three lines of deletion duty would be the most effective single change in the whole stack, and Austria could make it in its own law without waiting for anybody. The festival wristband from earlier you still buy into, that is the price of any anonymous check, only this variant at least builds no ID archive along the way.
Measure, mandatorily. So far, every country that measured honestly found less than promised. The others are cited as successes to this day, Ireland for instance has published not a single effectiveness figure on its year of age checking. An annual duty to publish how many accounts were checked, by which method and how many minors are inside anyway would end that trick. The draft contains an evaluation clause instead, meaning a report, at some point.
Which leaves the question of why all this has to be so urgent. Being first can no longer be the point, France passed its ban back in July, after the whistling-back from above admittedly without any penalty provision. I have only one explanation that fits the calendar: a child-protection law is the most grateful item on any government's list, because nobody can be against it.
Yet waiting would be cheap right now of all times. The only study that will ever cleanly answer whether a ban like this actually helps children is already running: the official Australian evaluation with Stanford, more than 4,000 young people over two years, including measurement directly on the device, first results later this year. Austria starts its own experiment anyway, on the 31st of March 2027, without certifiers and against every measurement so far, while the lab next door already has the analysis running.
So in the end, everybody gets what they expected. The ninety percent from the survey at the beginning get their minimum age, the 62 percent their confirmation that nobody checks. The twelve-year-old gets her feed, a different birth year costs nothing. And I, at some point, get an ID photo sitting at a contractor whose name I will learn in the next data breach.
Only one thing works today already: the photo from the summer cabinet meeting further up, two satisfied men in front of two flags. In a photo, Announced looks exactly like Done.
And in mid-2027, half a year after the law, the certification bodies that are supposed to carry it open their doors. If they turn out like Kaufhaus Österreich did back then, privacy has won after all: what never works at least stores nothing.
Comments