Category: Blog

Commentary and analysis on current privacy, surveillance, cybersecurity, civil liberties, and related public-interest technology issues.

  • Age Assurance Is Becoming Internet Infrastructure

    What a global debate over child safety, privacy, digital identity, standards, and online access reveals about the future of the internet

    Legal and regulatory status checked through July 17, 2026.

    Asking a person’s age sounds like a minor change to a website.

    For most of the open internet’s history, people could read, search, watch, learn, argue, play, and join communities without first proving that they belonged to an approved age category. Age mattered at particular boundaries—buying alcohol, entering a casino, opening certain financial accounts—but it was not a routine prerequisite for participation in digital public life.

    That assumption is changing.

    On July 16, the Software Freedom Law Center, India convened a global panel titled What Age Assurance Means for the Future of Digital Rights, Online Safety, and the Internet at Large. The discussion brought together civil-liberties advocates, child-rights researchers, trust-and-safety specialists, technologists, and organizations from Australia, South Korea, Europe, Africa, India, the United Kingdom, and the United States.[1]

    Moderator Mishi Choudhary began with the tension that shaped the event. Children face real harms online: exploitative contact, harmful recommendation systems, compulsive design, sexualized and violent material, and products that can manipulate a young user’s attention or emotions.

    But once a service must know whether a user is sixteen, seventeen, or eighteen, it must decide how it will know.

    Will the user upload an identity document? Will a company estimate age from a face? Will a platform infer age from years of behavior? Will the phone, operating system, app store, bank, or government supply an age signal?

    A small interface question can become a new relationship among users, platforms, vendors, and the state.

    The question beneath the age gate

    Age assurance is not simply a way to classify children. It can determine whether every user must submit to an identity, biometric, behavioral, financial, or device-based process before accessing lawful information and services.

    The panel did not divide neatly between people who care about children and people who care about privacy. Nearly every participant accepted that harmful online systems require action. The disagreement concerned the intervention.

    Is the state addressing the product features and economic incentives that produce harm—or creating a new identity checkpoint for every user? Can age assurance provide children with safer, developmentally appropriate experiences without blocking lawful access to information and community? Can a proof disclose only an age threshold while resisting tracking, coercion, and expansion into a general digital-identity layer?

    And what happens to people who lack accepted documents, private devices, stable connectivity, or the ability to challenge an automated decision?

    Editorial illustration of a web access gate branching into identity document, face scan, behavioral analysis, device signal, and anonymous credential pathways.
    Editorial illustration of a web access gate branching into identity document, face scan, behavioral analysis, device signal, and anonymous credential pathways.

    Child safety and digital rights are not opposites

    The most useful lesson from the panel was that children’s rights include more than protection from harmful content.

    Children also possess rights to privacy, expression, association, participation, and access to information. Those interests can conflict in a particular case, but they do not disappear because a policy is described as protective.

    Protection can remove support as well as risk

    John Pane of Electronic Frontiers Australia described his country’s under-sixteen social-media regime as a blunt prohibition aimed at the visible part of the problem: children’s access. The deeper causes, in his account, include harmful design, surveillance-based data extraction, and recommendation systems engineered to maximize engagement.

    Australia’s law is no longer hypothetical. Since December 10, 2025, designated platforms have been required to take reasonable steps to prevent Australians under sixteen from creating or keeping accounts.[13] The eSafety Commissioner reported that platforms restricted access to approximately 4.7 million accounts during the first implementation period.[14] Three months later, however, the regulator identified significant compliance concerns involving Facebook, Instagram, Snapchat, TikTok, and YouTube and moved toward possible enforcement.[15]

    The account figure demonstrates large-scale implementation. It does not establish improved wellbeing. Australia has begun a two-year evaluation following more than 4,000 children and families to examine intended and unintended effects.[16]

    The distinction matters because online services can provide LGBTQ+ youth, children in unsafe homes, disabled users, and people in geographically remote communities with information and relationships unavailable nearby. A restriction may remove risk, but it can also remove agency, education, and support. Children may respond through borrowed accounts, circumvention, alternative services, or platforms with weaker protections.

    Adults encounter the gate too

    Paige Collings of the Electronic Frontier Foundation connected age assurance to both privacy and freedom of expression.

    Age restrictions do not operate only on children. Adults must also demonstrate eligibility. For young people, the effects can be particularly serious when lawful information about health, identity, abuse, politics, or community is unavailable offline. Platforms also gain another reason to place difficult or controversial material behind a gate.

    The United Kingdom’s existing Online Safety Act duties already require highly effective age assurance in several circumstances involving pornography and content harmful to children. The government then announced in June 2026 that it intends to prohibit covered social-media services from offering accounts to under-sixteens. Regulations are expected before the end of 2026, with implementation planned for spring 2027; the final service definitions and operational rules were still being developed when this article was written.[17]

    The gate must be implemented somehow. Depending on the method, users may be asked for identity records, financial information, account history, a facial image, or an operating-system signal.

    One of the recurring errors in public debate is to treat the final response—“over eighteen” or “under sixteen”—as though it were the complete data flow.

    Identity requirements can chill ordinary users more than determined wrongdoers

    Professor K.S. Park of Open Net Korea supplied a historical warning.

    South Korea’s Information and Communications Network Act once imposed a general identity-verification requirement on users of covered message boards. The official English legislative record states that the provision applying that requirement to private service providers was removed after the Constitutional Court found it unconstitutional on August 23, 2012; the statutory deletion followed in 2014.[20]

    Park argued that privacy-conscious ordinary users withdrew while people intentionally committing illegal acts found other identifiers or methods. That assessment is his interpretation of the policy’s effects, but the legal history confirms the broader lesson: identity-linked participation can deter lawful speakers without eliminating determined misconduct.

    A person seeking ordinary speech, political participation, or sensitive information may be discouraged by a record connecting identity to activity. A motivated bad actor may treat the checkpoint as another obstacle to evade.

    Digital life is part of children’s real life

    Moritz Katzner of Stop Killing Games and James Baker of Open Rights Group focused on gaming, preservation, learning, and relationships.

    A child interested in a complex game may rely on videos, forums, guides, and interaction with other players. Blocking YouTube, Reddit, or another social platform may not simply remove idle entertainment; it can remove the instructional and community structure surrounding an important hobby.

    The same applies to creative work, disability access, identity exploration, education, and friendships. Calls to move children into the “real world” often assume that online life is somehow unreal. For many children—and adults—the internet is already where meaningful parts of life occur.

    Children possess rights before adulthood

    Nicholas Williams of Index on Censorship argued that child protection is too often placed in one conceptual box while freedom of expression is placed in another.

    The UN Convention on the Rights of the Child does not treat children solely as objects of adult protection. Children have rights to expression, participation, privacy, association, and access to information. Those rights may be limited for legitimate protective purposes, but they do not suddenly appear on a person’s eighteenth birthday.

    Dr. Kim R. Sylwander of the Digital Futures for Children centre developed that point through children’s evolving capacities. Numerical age is relevant, but children of the same age do not have identical needs, maturity, or circumstances. A single hard boundary can create a cliff that is poorly suited to developmental differences.

    The stronger question is not simply whether age assurance admits or excludes a child. Where it is used, does it enable a safer and age-appropriate experience while preserving agency and access?

    That is a much more demanding standard than placing a gate in front of an unchanged and potentially harmful product.

    One label, many systems

    “Age assurance” is an umbrella category. It includes verification, estimation, inference, self-declaration, parental confirmation, financial checks, device signals, and privacy-enhancing credentials.

    Each method answers a different question with different evidence. Each creates a different balance among confidence, privacy, accessibility, cost, and resistance to circumvention.

    Comparison of age-assurance methods across evidence required, confidence, privacy risk, exclusion risk, centralization risk, and likely failure.
    Comparison of age-assurance methods across evidence required, confidence, privacy risk, exclusion risk, centralization risk, and likely failure.
    Comparison of age-assurance methods
    Method Typical evidence Main advantage Principal risk
    Self-declaration Birthday or checkbox Minimal collection Easy to evade
    Document verification Government or authoritative record High confidence Identity-rich collection and exclusion
    Facial estimation Selfie or short video Lower friction than ID Threshold errors, demographic performance, image processing
    Behavioral inference Account activity and observed behavior No new document Continuous monitoring and opaque decisions
    Parental confirmation Verified adult approval Supports family features Does not prove relationship; unsafe for some children
    Financial/database check Card, bank, carrier, or brokered record Uses existing records Hidden data chain and economic exclusion
    Device/OS signal Age band from device, account, or app store Reduces repeated disclosure Centralized gatekeeping and shared-device problems
    Anonymous credential Cryptographic threshold proof Minimizes disclosure to the website Enrollment, recovery, revocation, and institutional control

    Self-declaration: private but weak

    A birthday field or “I am over eighteen” box collects relatively little information. It is also easy to evade.

    That makes self-declaration a plausible way to tailor low-risk experiences, but a poor mechanism for enforcing a hard prohibition. ISO/IEC 27566-1 treats self-assertion alone as ineffective for deciding access to age-restricted goods, content, services, venues, or spaces. Steve Wood’s 2026 review found that eleven of the seventy examined platforms still relied on self-declaration alone even as stronger age assurance became common across the wider sample.[2]

    The weakness of self-declaration is often used to justify stronger methods. That is the point at which privacy and access costs begin to increase.

    Documents and authoritative records: confidence bundled with identity

    A passport, driver’s license, national identity card, or birth record can supply a reliable date of birth when the document is genuine and belongs to the person presenting it.

    But a document contains far more than most websites need. A service asking only whether a user is over eighteen does not inherently need the person’s name, address, document number, nationality, photograph, signature, or exact birth date.

    A verifier can separate those attributes from the final result. The relying website may receive only “over eighteen.” That is a real improvement over handing a complete document to every website.

    It does not make the evidence disappear. The verifier, document-checking provider, identity authority, fraud service, or human reviewer may still process it.

    The important privacy question is therefore not merely what the website receives. It is what the whole system collects, transmits, retains, and can later connect.

    Facial estimation and behavioral inference: less conventional identity, new forms of surveillance

    Facial age estimation predicts an age or age range from a selfie or short video. Wood found it was the most commonly identified method among the twelve forms of age assurance used across the seventy services he examined.[2]

    Its appeal is obvious. It may be faster than finding a document, and the platform may never learn the user’s name. But the method still asks a person to place their face into a technical and commercial process. Liveness detection, anti-spoofing controls, device information, and a fallback document check may be added around the estimate.

    The hardest cases occur near the legal boundary. Distinguishing a young child from a middle-aged adult is different from distinguishing a seventeen-year-old from an eighteen- or nineteen-year-old. An error can either admit someone the rule intends to exclude or deny lawful access to someone entitled to enter.

    Behavioral inference creates a different problem. A platform can estimate age from account history, searches, videos watched, language, social relationships, school references, or other signals. This can be presented as less intrusive because no new document or selfie is requested.

    But the apparent advantage depends on repurposing information collected for other reasons. A checkpoint becomes continuous monitoring.

    An adult researching schools for a child, watching youth-oriented entertainment, or sharing an account with family members may resemble a minor. A child can also produce carefully selected adult-looking signals. The user may never learn which behavior triggered the decision.

    Parents, payments, and databases: convenient assumptions that fail many users

    Parental confirmation can support family accounts and age-appropriate settings. It cannot automatically prove a child’s age or establish that the adult is a safe and legitimate guardian.

    Some children do not have an available adult who can help. Others seek information precisely because the adults around them are hostile, controlling, abusive, or unsafe.

    Financial and commercial-record checks make different assumptions. A credit-card authorization may show access to an adult-controlled payment instrument, but not that the person at the keyboard is the cardholder. Cards can be borrowed, and many lawful adults do not have them.

    Commercial databases, phone-account checks, and open banking can rely on information assembled across data brokers, financial institutions, carriers, or identity services whose role is invisible to the user.

    These methods can make age assurance dependent on the same commercial surveillance economy that child-safety policy is often supposed to constrain.

    Device and operating-system signals: fewer checks, greater central power

    A phone, app store, console, or operating system can provide an age range to an application. This may reduce repeated disclosure: a user does not upload an ID to every service, and the application receives only a limited signal.

    The privacy of an individual interaction may improve while power becomes more concentrated.

    A small number of operating-system and app-store companies could become issuers of age-related permission for ordinary digital activity. Alternative operating systems, older devices, shared tablets, public computers, and platforms outside the approved ecosystem may be unable to produce the expected signal.

    Once the device can answer one age-related question, governments and companies may ask it to enforce additional rules for games, purchases, political information, health content, AI companions, or services unrelated to the original mandate.

    Anonymous credentials: the strongest technical answer, not a complete social answer

    Cryptography can prove a limited fact without revealing the underlying identity.

    Steven Bellovin describes a system in which a trusted issuer verifies a person’s age and supplies a private credential. The holder can derive unlinkable proofs such as “over eighteen.” A website verifies the proof without learning the person’s name, exact birth date, or source document.[8]

    That is substantially more private than sending an ID or selfie to each website.

    But someone must still enter the system. An issuer must decide which records are acceptable, verify them, fund the process, secure the credential, help users recover it, and determine whether it can be revoked. People without documents, private devices, transportation, stable housing, or technical assistance may remain excluded.

    Bellovin also identifies a paradox. If a credential is useful only for age-gated content, adults may lend it to minors. Making it valuable for banking, employment, public services, or other essential functions discourages sharing—but turns it into a far more consequential identity system.

    A private proof can exist inside a coercive institution.

    Privacy-preserving is not the same as anonymity-preserving

    A website may receive only an age threshold while the issuer, device operator, verifier, or surrounding metadata still allows transactions to be linked to one another or to a person.

    From one age check to internet infrastructure

    These methods are usually evaluated one transaction at a time: what does this website learn from this check? But the larger policy question emerges when the same signals, credentials, vendors, and device systems begin operating across many services.

    Moving assurance to the device is often described as the privacy solution.

    Instead of requiring every website to perform a separate check, the operating system or app store establishes or receives an age range and sends a limited signal to applications. The relying service learns less. Users repeat the process less often.

    Those advantages are real.

    So are the structural consequences.

    One device is not one person

    Families share phones, tablets, consoles, televisions, and computers. Libraries and community centers provide public devices. Schools issue devices that may be used by more than one student.

    A device-level signal must either assume one user, require reliable multi-user profiles, or repeatedly identify the person currently present.

    The first produces wrong results. The second depends on families configuring accounts correctly. The third reintroduces friction and surveillance.

    People with the least money, time, and technical expertise are often the most likely to share devices and the least able to maintain a complex multi-user assurance system.

    Alternative systems can become second-class

    A mandate tied to approved operating systems can disadvantage:

    • de-Googled Android builds;
    • Linux distributions;
    • older devices;
    • independent app stores;
    • accessibility-specific hardware;
    • public terminals;
    • devices made for markets outside the dominant ecosystem.

    The open internet historically allowed a standards-compliant browser to reach a service regardless of who manufactured the computer. Device-level eligibility can replace that principle with a chain of approved hardware, software, accounts, and issuers.

    The gatekeeper gains policy power

    Apple, Google, Microsoft, console companies, and major app stores could become intermediaries for age-related access across thousands of services.

    They would need to decide which evidence is accepted, which age bands exist, how shared devices work, how appeals operate, whether developers receive exact or coarse results, how often signals expire, and what happens after account suspension.

    A law aimed at platform safety can therefore increase the power of the largest platform companies.

    The European model shows both the promise and the risk

    The European Commission’s age-verification blueprint became technically ready for national customization in April 2026.[21] It can operate as a standalone application or be integrated into a future European Digital Identity Wallet. The Commission says the design can prove that a user satisfies a threshold without revealing identity or exact age, and it has urged Member States to make compatible tools available by the end of 2026.[22]

    That architecture is materially different from uploading a passport to every website. It separates issuance from presentation and is intended to reduce disclosure and cross-service tracking.

    Simeon de Brouwer of European Digital Rights warned that privacy-preserving intent does not end the governance analysis. Enrollment can still require a passport, identity card, national eID, banking application, or in-person authority. Identity providers and relying services may face legal demands, implementation errors, metadata correlation, or later architectural changes.

    Perfect enforcement creates pressure for more identity

    Every method can be evaded somehow:

    • users can lie;
    • documents can be borrowed or forged;
    • adults can complete checks for minors;
    • facial systems can be spoofed;
    • accounts and credentials can be transferred;
    • behavior can be manipulated;
    • users can move to another site or jurisdiction;
    • a VPN can change apparent location.

    A government dissatisfied with those results can escalate:

    1. require a stronger method;
    2. bind the result to a device;
    3. add liveness or biometrics;
    4. repeat the check;
    5. monitor behavior for inconsistency;
    6. restrict anonymous access or VPNs;
    7. retain logs for enforcement;
    8. connect the credential to a persistent identity;
    9. penalize platforms for any successful evasion.

    The Global Network Initiative’s multistakeholder review identifies the central limit: policymakers should not demand complete resistance to circumvention when achieving it requires unacceptable privacy and rights costs.[9]

    The endpoint may not be a perfectly safe internet. It may be an internet in which every user is continuously classifiable and access can be revoked.

    Escalation ladder showing how efforts to prevent evasion can move from self-declaration toward persistent identity and behavioral monitoring.
    Escalation ladder showing how efforts to prevent evasion can move from self-declaration toward persistent identity and behavioral monitoring.

    AI companions are the next expansion point

    The panel’s closing discussion anticipated the rapid movement of age-assurance policy from social media to chatbots and AI companions.

    These systems create distinct risks:

    • emotionally dependent relationships;
    • simulated grooming or sexual conversation;
    • encouragement of self-harm;
    • manipulation;
    • hallucinated personal or medical advice;
    • collection of intimate disclosures;
    • profiling from continuous conversation.

    An age signal may help apply different safeguards. But a chatbot is not simply another social-media feed. It responds privately, adapts to the user, and may become a confidant.

    Wood found regulatory gaps around AI chatbots and warned that companies may define their own child-safety standards without clear public rules.[2] The report recommends explicit coverage, risk tiers, and obligations addressing simulated grooming and emotional dependency.

    The UK moved further while this article was in production. Its July 2026 package proposes blocking under-eighteens from AI services primarily offering sexualized content, restricting sexual role-play features on other chatbots, and considering protections such as mandatory breaks and limits on systems offering mental-health advice. These were announced proposals, not yet final operating rules.[18]

    A device-level age signal may be deployed before governments have decided what an age-appropriate AI relationship should be.

    What real deployments reveal

    That infrastructure concern is not merely hypothetical. Existing deployments show how quickly a binary age result can create concentrated intermediaries, multi-company data flows, and incentives for broader enforcement.

    The 2026 study Papers, Please: A First Look at Age Verification on the Web built technical signatures for age-assurance providers and crawled a large set of popular websites from Texas, Georgia, and New York. The researchers found more detected age-verification deployments in the two states with mandates than in the control state, showing that state law can change what users encounter online.[3]

    They also found a concentrated market. Yoti appeared on more than sixty percent of detected deployments in the mandate-state crawls. A rule applied across many websites can therefore create a small number of central intermediaries through which sensitive transactions pass.

    Apparent compliance remained low

    The researchers used the voluntary “Restricted to Adults” label as a rough proxy for sites likely to contain covered material. Only about fourteen percent of those labeled sites in Texas and Georgia had detectable age verification.

    That is not a definitive legal compliance rate. The label is voluntary, the laws differ, and the detection system can miss implementations.

    It nevertheless illustrates a basic enforcement problem: a user who refuses a check can often move to a site that does not impose one. A compliant service adds friction and loses traffic; a noncompliant competitor can absorb it.

    The result may be a two-tier internet in which well-known services implement intrusive gates or withdraw while less accountable sites gain users.

    A binary result can require a large data supply chain

    The website is often only the relying party. The user is redirected to a verifier, which may contact other services for network location, payment processing, document validation, fraud detection, database matching, or manual review.

    The researchers observed browser and device information that could contribute to fingerprinting. They also identified method-specific connections to outside services. In a card-based flow, Stripe could receive contextual information about the originating service; a bank could learn that a Yoti transaction occurred. Government-ID workflows could involve additional identity and document-validation partners.[3]

    Not every method sends every data type to every party. Precision matters. But the central lesson survives: a binary result can be produced by a much richer data chain.

    Data-flow diagram showing a user, device, website, age-assurance provider, and method-specific outside parties.
    Data-flow diagram showing a user, device, website, age-assurance provider, and method-specific outside parties.

    The correction matters

    Yoti challenged an allegation that facial images used for facial age estimation were shared with third parties. Georgia Tech and the University of California, Irvine removed that allegation after review, according to Yoti’s June 2026 update.[4]

    A responsible account must not repeat the withdrawn claim.

    The correction does not automatically resolve the study’s separate findings about device metadata, market concentration, particular outside services, retention statements, or the security test in which researchers substituted a prepared image during the browser capture process. Each claim must be evaluated on its own evidence.

    The episode is also a reminder that privacy reporting must identify the exact method, recipient, and data flow. “The vendor shares user data” is too broad to be useful. Which data? In which workflow? With whom? For what purpose? For how long?

    What responsible deployment is supposed to require

    The Digital Trust & Safety Partnership’s best-practices framework is more candid than many political descriptions of age assurance. It says no approach is one-size-fits-all and that accuracy, privacy, inclusion, circumvention resistance, and affordability can conflict.[5]

    Its principles call for:

    • assessing the actual risk to young people;
    • selecting a proportionate method;
    • treating privacy and data protection as part of design and ongoing evaluation;
    • ensuring inclusion and accessibility;
    • using layered enforcement rather than assuming one check solves every problem;
    • explaining practices publicly and reporting on effectiveness.

    The framework’s value is that it rejects the idea that the most invasive method is automatically the most responsible.

    Its limitation is equally important. It is a best-practices document, not evidence that companies follow those practices or that a deployment reduces harm. “Layered enforcement” can mean careful escalation from a low-intrusion method, but it can also become continuous monitoring followed by facial or document verification.

    ISO/IEC 27566-1 contains serious safeguards

    ISO/IEC 27566-1:2025 is the most formal effort in this source set to describe what an age-assurance system should look like. It covers functional performance, privacy, security, accessibility, complaints, and public practice statements.[6]

    The standard is more privacy-conscious than a superficial description might suggest.

    It calls for minimum necessary collection, discourages disclosure of exact age or underlying evidence when a limited result will suffice, and establishes a presumption that personal data used to create a result should be deleted afterward. Audit logs must not contain biometric images or copies and extracted data from identity documents.

    It also asks whether providers or relying parties can correlate the same person across services, whether collaborating sites can recognize a user, whether a verifier can learn where a result is used, and whether a token can be linked to an identity.

    The standard requires systems to be testable and calls for reporting of classification accuracy, false approvals, false denials, demographic error parity, completion rates, performance, and scalability.

    Complaint processes and practice statements are expected to explain how users can challenge inaccurate or incomplete information, automated decisions, and security incidents.

    These are meaningful protections.

    The standard leaves central policy questions unresolved

    The framework also permits reusable credentials, provider accounts, stored attestations, and memorized results. It does not impose complete unlinkability, one universal accuracy threshold, a mandatory independent appellate body, or an unambiguous requirement that every deployment undergo recurring third-party audit.

    Most importantly, it does not decide whether age assurance is necessary in a particular context, whether the threshold is justified, or whether the intervention will reduce the targeted harm.

    What ISO/IEC 27566-1 does

    • Defines system actors and age-related results
    • Addresses minimization, deletion, security, testability, inclusion, complaints, and transparency
    • Recognizes tracking and cross-service correlation as privacy risks
    • Supports audits, certification, and practice statements

    What it does not do

    • Prove that a gate is necessary or proportionate
    • Establish that children will be safer
    • Require complete anonymity or unlinkability
    • Guarantee an independent appeal or recurring independent audit
    • Prevent a compliant system from becoming part of broader identity infrastructure

    A technically competent gate can still be attached to an unjustified wall.

    Standards are also governance

    Technical standards increasingly function as implementing rules for public policy. Legislatures can reference them, regulators can treat them as evidence of due diligence, and companies can use conformity claims to win contracts or defend practices.

    That makes participation a question of power.

    Emma Day and Sabine Witting warn that labels such as “privacy-preserving,” “fair,” and “rights-respecting” can become rights-washing when they are defined without meaningful human-rights expertise. Standards processes demand fees, sustained staff time, technical submissions, and repeated meetings. Large companies can participate continuously; civil-society and children’s-rights organizations often cannot.[7]

    The issue is not that engineers should be excluded. It is that technical decisions embed assumptions about acceptable error, identity, anonymity, access, and enforcement. Those are legal, social, and political decisions too.

    The governance questions should include:

    • Who drafted the rule?
    • Which sectors and regions were represented?
    • Were children or organizations representing their rights included?
    • Who certifies compliance?
    • Who selects and pays the auditor?
    • Are the major results public?
    • Can regulators inspect the evidence?
    • Can users challenge a conformity claim?

    A standard can improve safety and privacy. It can also make contested infrastructure easier to procure, certify, and scale.

    What regulation has changed—and what remains unproven

    Steve Wood’s Phase II study provides the best available bridge between policy and outcome. It examined seventy social-media, video, gaming, and AI platforms and documented 108 child-safety and privacy changes between 2024 and 2026.[2]

    The findings show that regulation is having effects. They also show why counting changes is not enough.

    Regulation is producing visible activity

    Wood found new measures across Meta, Google, TikTok, Snapchat, and thirty-one other platforms. Across the wider set of services, protections enabled by default were the largest category of change, with age assurance the largest subcategory.

    Examples included:

    • private or more restricted accounts;
    • reduced geolocation;
    • limits on targeted advertising;
    • content filters;
    • restrictions on adult-to-child contact;
    • age checks for chat or adult features;
    • protective upload warnings;
    • parental time controls;
    • reporting and support tools.

    Some changes were directly linked to the UK Online Safety Act or interventions by the UK Information Commissioner’s Office.

    Major platforms shifted responsibility toward families

    Among Meta, Google, TikTok, and Snapchat, the pattern changed. Earlier regulatory pressure had produced more protections enabled by default. During 2024–2026, the greatest volume of changes shifted toward user-operated tools, especially parental controls.

    A default protection works without a child or parent finding, understanding, and activating it. A tool transfers responsibility to the user.

    That matters because families vary in time, digital literacy, language, safety, technical skill, and household relationships. A platform can announce a control that few people use and still count it as a safety measure.

    Wood found that platforms did not publish comprehensive, independently audited data on the use or performance of parental controls. Some outside research suggested limited effectiveness as a standalone response to compulsive use.[2]

    Age assurance was widespread, but transparency was weak

    Most of the seventy platforms had some form of age assurance, although the researchers could not identify it on thirteen. They found twelve types of mechanism, and most services with age assurance offered more than one option.

    Offering alternatives can reduce exclusion. A person without photo ID may use a facial estimate; someone who cannot or will not provide a face may use another method.

    But multiple choices do not guarantee rights-respecting implementation. Wood found that platform explanations often failed to identify the standards the system followed, and the study did not test whether the mechanisms were accurate or effective.

    A majority of platforms with age assurance in place relied on in-house solutions (31) rather than third-party providers (23). Some platforms used both: in-house for one method, such as behavioral inference, and a third-party vendor for another, such as facial age estimation. Yoti was the most-used third-party provider.[2]

    Ofcom’s first statutory report shows scale and displacement

    On July 15, 2026, Ofcom published its first statutory assessment of age assurance under the Online Safety Act. Thirty-two sampled services reported more than 69 million completed age checks between July and December 2025—twenty-three times the number reported in the preceding six months. Ofcom described the findings as early and warned that the sample was not representative of an entire sector.[19]

    The regulator found signs that checks were deterring some children from pornography and that the largest sites had broadly implemented gates. It also found that almost half of the pornography services visited by children had no age checks, while some noncompliant sites gained traffic as gated competitors lost it.

    Several social platforms continued to depend on proprietary behavioral inference that Ofcom did not accept as inherently capable of being highly effective.[19]

    This is the evidence ladder in action:

    Law enacted → regulator acts → system deployed → behavior changes → exposure changes → harm declines

    Most public evidence currently establishes the first three stages. Evidence becomes much thinner at exposure and actual harm.

    Ofcom itself stated that no method eliminates circumvention and called for vendor due diligence, privacy compliance, and system-wide involvement by search engines, app stores, operating systems, and device providers.[19]

    Those recommendations may improve enforcement while also accelerating the infrastructure expansion examined in this article.

    Design rules have produced some of the clearest privacy gains

    The most concrete improvements in Wood’s research came from specific design and data rules:

    • reducing precise geolocation;
    • making profiles private by default;
    • limiting personalized advertising to minors;
    • restricting contact;
    • adding protective prompts;
    • filtering certain content;
    • changing recommendation behavior.

    These interventions target the environment rather than requiring every user to prove eligibility before entering it.

    That does not make age assurance irrelevant. A service may need an age signal to apply the correct protections. But the signal should enable safer design, not substitute for it.

    The global inequality problem

    The Digital Rights Alliance Africa report covers Algeria, Botswana, Egypt, Ghana, Kenya, Nigeria, Rwanda, South Africa, Tanzania, and Uganda. It treats privacy as both a protective and enabling right: children need it not only to avoid exploitation but to learn, communicate, explore identity, and exercise expression.[10]

    The report identifies laws and policies across the region, but repeatedly returns to implementation:

    • many legal frameworks are general rather than child specific;
    • regulators and enforcement bodies lack resources;
    • digital literacy is uneven;
    • rural users may lack secure connectivity;
    • international standards are adopted slowly or incompletely;
    • parents and caregivers may lack the knowledge assumed by consent-based systems;
    • companies operate across borders that local complainants and regulators struggle to cross.

    Only a minority of African Union states had ratified the Malabo Convention at the time of the report, and the convention itself lacks detailed child-specific privacy rules. The African Union’s 2024 Child Online Safety and Empowerment Policy recognizes safety, privacy, participation, best interests, and non-discrimination, but national implementation remains uneven.[10]

    A technically neutral rule can deepen inequality

    Consider a law that permits government ID, smartphone-based facial estimation, or a mobile-network check.

    For a well-documented urban adult with a current phone, stable connectivity, and technical confidence, the process may be inconvenient.

    For a person without a recognized birth record, national ID, private device, data plan, accessible interface, nearby government office, or ability to pay, the same rule can become exclusion.

    A country with lower internet penetration may lose more from blocking lawful users because the network already reaches fewer people. A government with a history of surveillance or political repression creates additional risks when identity infrastructure becomes attached to speech and association.

    Bridgette Ndlovu’s panel remarks emphasized that identity coverage and connectivity cannot be assumed. Patricia Ainembabazi stressed that technologies adopted in African countries are often designed elsewhere, with little input from the people governed by them. Annette Opiyo centered proportionality, evidence, accountability, inclusion, and child participation.

    These are not regional side issues. They expose weaknesses in the universal model.

    Children must participate in the design

    CIPESA argues that children are not only vulnerable users but active participants in learning, play, creativity, and social life. Its work on AI governance calls for children’s experiences to shape systems from the beginning, including limits on profiling and manipulation, data minimization, independent audits, and AI literacy.[11]

    Its 2026 policy-to-practice article similarly calls for child-specific laws, funded institutions, accountable platforms, transparency, independent audits, and meaningful participation by young people.[12]

    Children should be asked:

    • Which services matter to them and why?
    • What harms do they experience?
    • Which controls help?
    • Which restrictions drive them elsewhere?
    • What happens when a parent is not safe?
    • What appeal process would they understand?
    • How do age rules affect disabled, rural, queer, migrant, low-income, or undocumented young people?
    • Which protections should apply to everyone rather than only minors?

    Participation does not mean children decide every legal question. It means policy is not designed around an imagined average child who has no voice, no agency, and a safe adult standing nearby.

    A rights-respecting test for any proposal

    Before procurement, certification, or deployment, policymakers should answer the following questions.

    Fifteen-question checklist covering necessity, data use, performance, accountability, expansion risk, and participation.
    Fifteen-question checklist covering necessity, data use, performance, accountability, expansion risk, and participation.
    1. What specific harm is being addressed? “Protect children” is an objective, not a defined problem. Pornography, grooming, compulsive use, targeted advertising, gambling, and AI companionship require different interventions.

    2. What evidence connects an age gate to that harm? Explain the causal theory and how displacement, circumvention, and unintended effects will be measured.

    3. Have less intrusive design measures been tried? Consider safer defaults, contact restrictions, advertising limits, recommendation changes, moderation, reporting, product liability, and consumer-protection enforcement.

    4. What does the service actually need to know? Identity, exact age, age range, or one temporary threshold result are not equivalent.

    5. What data are collected from the person and device? Include documents, images, biometrics, financial details, IP address, device characteristics, behavior, location, and fraud telemetry.

    6. Who receives the data? Identify the platform, verifier, operating system, app store, document validator, bank, processor, data broker, cloud provider, reviewer, and subprocessor.

    7. What is retained, and for how long? Separate original evidence, images, document data, device information, age results, credentials, transaction logs, and complaint records.

    8. Can transactions be linked? Determine whether the provider, issuer, collaborating websites, or surrounding metadata can recognize the same person across services or over time.

    9. What are the errors? Publish threshold-specific false approvals, false denials, demographic disparities, completion rates, abandonment, and accessibility failures.

    10. What alternatives exist? A lawful user should not lose access because they lack an ID, credit card, smartphone, camera, private device, safe parent, stable internet, or conventional records.

    11. What happens when the system is wrong? Require clear notice, understandable reasons, human review where appropriate, correction, restoration of access, deadlines, and independent escalation.

    12. Who tests and audits the system? Testing should occur before launch and regularly afterward. Auditors need expertise in security, privacy, accessibility, discrimination, and children’s rights.

    13. What prevents secondary use? Age-assurance evidence should not become material for advertising, general profiling, AI training, unrelated fraud models, political surveillance, or data-broker sale.

    14. What is the expansion boundary? State which services are covered, who may add categories, when legislative approval is required, how necessity is reviewed, and when the authority expires.

    15. Were children and affected communities involved? Include users of different ages, abilities, locations, incomes, identities, family circumstances, and patterns of internet access.

    The better question

    Age assurance is often presented as a contest between safety and privacy.

    That framing is too narrow.

    The policy choice affects safety, privacy, anonymity, expression, association, equality, competition, device freedom, platform power, government identity, technical standards, children’s participation, and the architecture of the internet.

    Some age-related protections will require some knowledge of age. Some systems can disclose much less than others. Standards can meaningfully reduce collection, retention, tracking, error, and exclusion.

    None of those facts establishes that a gate should exist everywhere a child might encounter risk.

    The clearest evidence in the source set is not that age assurance has solved online harm. It is that regulation is rapidly producing infrastructure: vendor markets, facial-estimation systems, reusable credentials, app-store signals, audit schemes, practice statements, and enforcement expectations.

    Infrastructure persists. It becomes interoperable. It attracts investment. It gains new uses.

    That is why the most important question must come before the technical one.

    Not: How do we verify everyone’s age?

    But: What specific protection do children need here, and can we provide it without turning identity or eligibility into the price of ordinary participation online?

    The answer will not be identical for pornography, gambling, a public encyclopedia, a multiplayer game, a support forum, an encrypted messenger, a school tool, or an AI companion.

    That is not a failure of policy.

    It is the complexity that rights-respecting policy must be willing to face.

    Related reading

    For a set of concrete, Oregon-specific illustrations of how a poorly built age-verification system could go wrong — including immigration-enforcement exposure, data breaches, and custody-dispute subpoenas — see When “Protecting Kids” Goes Wrong.


    Source notes

    1. [1] Event recording and working transcript. Software Freedom Law Center, India, What Age Assurance Means for the Future of Digital Rights, Online Safety, and the Internet at Large, July 16, 2026. Recording: https://www.youtube.com/watch?v=euSkCvhzweQ. The event discussion is based on a locally generated Whisper transcript; any exact quotation should be checked against the recording.
    2. [2] Steve Wood, Digital Futures for Children / London School of Economics and 5Rights Foundation. Impact of Regulation of Children’s Digital Lives: Phase II and Appendices A and B, May 2026. https://www.digital-futures-for-children.net/our-work/regulation-impact 1 2 3 4 5 6
    3. [3] Shreyas Minocha, Isaac Sheridan, Harry Oppenheimer, Paul Pearce, and Michael A. Specter. Papers, Please: A First Look at Age Verification on the Web, 2026. https://mikespecter.com/assets/pdf/AgeVerification.pdf 1 2
    4. [4] Yoti. An open letter to Georgia Institute of Technology and University of California, Irvine requesting retraction and correction of false statements, updated June 19, 2026. https://www.yoti.com/blog/open-letter-to-georgia-institute-of-technology-university-of-california-irvine-requesting-retraction-correction-false-statements/
    5. [5] Digital Trust & Safety Partnership. Age Assurance: Guiding Principles and Best Practices, September 2023. https://dtspartnership.org/age-assurance-guiding-principles-best-practices/
    6. [6] ISO/IEC 27566-1:2025. Information security, cybersecurity and privacy protection — Age assurance systems — Part 1: Framework. Public record: https://www.iso.org/standard/88143.html. The analysis is paraphrased from a lawfully obtained single-user copy.
    7. [7] Emma Day and Sabine Witting. Human Rights Experts Should Engage in Age Assurance Standards, Tech Policy Press, June 29, 2026. https://www.techpolicy.press/human-rights-experts-should-engage-in-age-assurance-standards/
    8. [8] Steven M. Bellovin. Privacy-Preserving Age Verification—and Its Limitations, October 2025. https://www.cs.columbia.edu/~smb/papers/age-verify.pdf
    9. [9] Hilary Ross, Global Network Initiative. Examining the Rights Implications of Age Assurance Requirements, July 6, 2026. https://globalnetworkinitiative.org/examining-the-rights-implications-of-age-assurance-requirements/
    10. [10] Digital Rights Alliance Africa. Child Protection and Safety Online in Africa: The Law, Privacy, Challenges and Solutions, June 2025. https://digitalrightsalliance.africa/download/child-protection-and-safety-online-in-africa/ 1 2
    11. [11] Patricia Ainembabazi, CIPESA. Elevating Children’s Voices and Rights in AI Design and Online Spaces in Africa, July 18, 2025. https://cipesa.org/2025/07/elevating-childrens-voices-and-rights-in-ai-design-and-online-spaces-in-africa/
    12. [12] Patricia Ainembabazi, CIPESA. Protecting Children Online in Africa Must Move from Policy to Practice, June 11, 2026. https://cipesa.org/2026/06/protecting-children-online-in-africa-must-move-from-policy-to-practice/
    13. [13] Australian Department of Infrastructure, Transport, Regional Development, Communications, Sport and the Arts. Minimum age for social media access, December 11, 2025. https://www.infrastructure.gov.au/department/media/news/minimum-age-social-media-access
    14. [14] eSafety Commissioner. Platforms restrict access to 4.7 million under-16 accounts across Australia, January 16, 2026. https://www.esafety.gov.au/newsroom/media-releases/platforms-restrict-access-to-47-million-under-16-accounts-across-australia
    15. [15] eSafety Commissioner. Five social media platforms flagged for compliance issues, March 31, 2026. https://www.esafety.gov.au/newsroom/media-releases/five-social-media-platforms-flagged-for-compliance-issues
    16. [16] eSafety Commissioner. eSafety begins evaluation of Australia’s world-first social media minimum age, February 26, 2026. https://www.esafety.gov.au/newsroom/media-releases/esafety-begins-evaluation-of-australias-world-first-social-media-minimum-age
    17. [17] UK Department for Science, Innovation and Technology. Fact sheet: New rules to protect children online, updated July 17, 2026. https://www.gov.uk/government/publications/fact-sheet-new-rules-to-protect-children-online/fact-sheet-new-rules-to-protect-children-online
    18. [18] UK Department for Science, Innovation and Technology. New social media curfews and crackdown on addictive features to better protect 16- and 17-year-olds online, July 15, 2026. https://www.gov.uk/government/news/new-social-media-curfews-and-crackdown-on-addictive-features-to-better-protect-16-and-17-year-olds-online
    19. [19] Ofcom. Use of Age Assurance Report 2026, July 15, 2026. https://www.ofcom.org.uk/online-safety/protecting-children/use-of-age-assurance-report-2026 1 2 3
    20. [20] Korea Legislation Research Institute. English statutory record for Article 44-5 of the former Act on Promotion of Information and Communications Network Utilization and Information Protection. The record states that paragraph (1) 2 was deleted in 2014 pursuant to the Constitutional Court’s August 23, 2012 unconstitutionality decision. https://elaw.klri.re.kr/eng_service/lawViewContent.do?hseq=46968
    21. [21] European Commission. The EU approach to age verification, updated May 13, 2026. https://digital-strategy.ec.europa.eu/en/policies/eu-age-verification
    22. [22] European Commission. Commission urges Member States to rollout EU age verification app, April 29, 2026. https://digital-strategy.ec.europa.eu/en/news/commission-urges-member-states-rollout-eu-age-verification-app
  • What Two Weeks of Advocacy Accomplished — And What Comes Next

    What Two Weeks of Advocacy Accomplished — And What Comes Next. Bend Privacy Alliance, June 2026. Infographic summarizing campaign growth, June 3 Deschutes County BOCC outcome, and June 3 Bend City Council outcome.

    Two weeks ago, the Bend Privacy Alliance didn’t have a Facebook group, a public petition, or a community showing up to two government meetings on the same day. Today we do. Here’s what happened, what it produced, and where we go from here.

    How it started

    In mid-May, Deschutes County quietly scheduled a vote on Contract No. 2026-0327 — a five-year, $2,412,669 agreement with Axon Enterprise for body-worn cameras, Tasers, and fleet cameras for the Deschutes County Sheriff’s Office. The contract included the Axon Fleet 3, a camera with integrated license plate reader capability, along with Auto-Tagging and Auto-Transcribe software licenses. The two-page staff report said nothing about whether the ALPR capability would be activated or what policy would govern it.

    We submitted written comment. The Board deferred the item. A second meeting was scheduled for June 3.

    In the two weeks between those dates, the campaign grew beyond one person with a laptop.

    The numbers

    Combined views across Reddit and jonathanwestmoreland.com reached approximately 100,000 over the two-week period — roughly 70 percent from Reddit, 30 percent from the website. A Facebook group dedicated to the campaign reached 71 members in about a week. Someone independently built a website on the topic, unconnected to this organization — a sign the issue had taken on a life of its own.

    None of those numbers include shares from other groups, organic Facebook reach, or the petition signatures. We can’t fully measure what we started.

    June 3 — the county

    Seven people spoke at the Deschutes County BOCC meeting — four in person, three online. Written comment submitted before the meeting addressed six specific asks grounded in Oregon law and the contract itself:

    • Confirmation of whether ALPR capability would be activated
    • A published SB 1516-compliant ALPR policy before deployment
    • Board-level authorization required for ALPR activation
    • A written SB 1587 attestation from Axon
    • Production of the missing Data Processing Agreement
    • A status report on all seven recommendations from the December 2025 Internal Audit

    Of those six asks, four were addressed. The Board adopted a meaningful condition: the Fleet 3’s integrated ALPR capability may not be activated unless DCSO returns to the Board for a separate authorization vote. That condition did not exist before this campaign raised the issue.

    On SB 1587, Axon’s attorneys stated through DCSO that Axon does not meet Oregon’s definition of "data broker" — meaning the law’s attestation requirement, in their view, does not apply. That is Axon’s legal position, not a judicial or agency determination. It will be revisited.

    The audit status report was not addressed.

    The contract passed unanimously.

    One more detail worth noting: the Data Processing Agreement — the governing document for how Axon handles all footage and metadata under the contract — was not in the Board’s original packet. It was transmitted to BOCC staff at 8:07 AM the morning of the vote and handed to attendees as a printed paper document before the meeting began. The Board voted on a $2.4 million contract without having seen that document during their review period. That procedural gap is now on the record.

    June 3 — the city

    Eight people spoke in person at Bend City Council that evening, with two online. Speakers raised surveillance technology oversight broadly, called for policy before deployment, and named a surveillance ordinance as a goal. The Council committed on the record that any stationary ALPR expansion will come before them for a vote and public comment.

    The petition filed under Bend Code 1.30.005(C) requesting Council review of Police Department Policy 428 — the department’s ALPR policy — was submitted the same day and confirmed received by the City Recorder.

    Policy 428 governs ALPR use by Bend PD, which has deployed the Axon Fleet 3 in more than 70 patrol vehicles since July 2023. The petition asks the Council to review whether the policy meets the requirements of SB 1516, which took effect March 31, 2026.

    What the contract review found

    A full review of the contract packet produced findings the staff report never disclosed.

    The Axon Service Level Agreement gives Axon authority to push firmware updates to all devices — body cameras, fleet cameras, Tasers — without DCSO authorization. The same SLA defines "Axon Cloud Services" to include Fusus, Axon’s real-time crime center platform. The staff report mentioned neither.

    The privacy notice attached to the contract designates Axon as the independent Data Controller — not DCSO — for all operational metadata generated under the contract. Oregon’s own State Chief Information Security Officer confirmed in writing that Axon holds the encryption keys to all data stored on its platform, not the agency. At the meeting, DCSO cited Axon’s SOC 2 Type II certification in response. SOC 2 audits whether a vendor’s controls work as the vendor describes them — it does not require end-to-end encryption and does not address who controls access to data under a federal legal process. The CISO’s finding stands unrebutted.

    Primary source documents from this proceeding — the BOCC meeting packet, the December 2025 Internal Audit, and the Oregon State CISO letter — are in the source library at jonathanwestmoreland.com/source-library-bend-surveillance-oversight.

    What comes next

    The city fight is the longer one. Bend PD’s ALPR system has been operating in more than 70 patrol vehicles for nearly three years. The Council’s commitment to a public vote before any stationary ALPR expansion is an important line. Holding it requires the governance framework to be in place before the next technology decision arrives.

    The next steps are: understanding the full inventory of surveillance technology Bend PD currently operates, completing the surveillance ordinance and procurement framework, and bringing both before the Council.

    That work is underway.

    More to come.

  • ALPR Oversight Is a Democracy Issue

    Signals & Safeguards — A standalone civic-oversight post on license plate readers, public consent, federal access, and the safeguards local governments should require before surveillance networks become hard to unwind.

    ALPR oversight is becoming a democracy issue

    The strongest surveillance story this week is not one camera system by itself. It is the fight over who gets to approve, search, share, and shut down a network once it is already in place.

    Automatic license plate readers, often called ALPRs, are usually introduced as practical public-safety tools. Police agencies point to stolen-vehicle recovery, suspect identification, Amber Alerts, and serious investigations. Those uses can be real. But the democratic problem begins when a system that looks like a set of cameras turns into a searchable movement database shared across agencies, jurisdictions, vendors, and sometimes federal systems.

    That is why the key question is no longer simply, “Do these cameras help police?” The better question is: who controls the system once it exists?

    When public consent breaks down

    In Troy, New York, a dispute over Flock license plate readers escalated after residents objected to cameras installed without meaningful public input, the City Council voted to end the program, and the mayor declared a state of emergency to keep the cameras operating. The fight became larger than Flock: it became a dispute over emergency authority, public consent, and whether elected bodies can still control surveillance systems once public-safety claims are used to preserve them.

    That should concern any community considering ALPRs or similar systems. If ordinary approval channels can be bypassed, delayed, or overridden after cameras are installed, then the public debate happens too late. The technology gains institutional momentum before the rules are settled.

    The democracy issue: surveillance systems should not go live first and receive public rules later.

    Once a camera network is installed, agencies, vendors, and outside partners may develop expectations around continued access. That makes it politically and operationally harder for elected officials to narrow, pause, or end the system.

    The pattern is spreading

    The pattern is appearing elsewhere. In Cleveland and nearby communities, residents and advocates are challenging Flock deployments over privacy, immigration-enforcement access, and uncertainty about who can search the system. In Bend, The Source Weekly reported that federal immigration officials made 279 queries into Bend’s Flock Safety data in the first three weeks after the cameras went live, and Bend Police reportedly did not authorize those searches.

    That Bend example matters because it shows how quickly the debate can move from “Should we install cameras?” to “Who searched the data, why, under what authority, and what did they see?” A local system may be approved for local purposes, but the practical risk is that local vehicle-location data becomes useful to agencies far beyond the community that generated it.

    The federal layer changes the stakes

    The federal layer makes the issue sharper. Reporting from 404 Media says the FBI wants to buy nationwide access to license plate reader data. If local and private cameras can become part of a national movement-search network, then approving a few cameras is not only a local equipment decision. It is a decision about whether local vehicle-location data can become searchable far beyond the community that generated it.

    That does not mean every ALPR deployment is the same, or that every agency intends to misuse the system. It means the rules must be written for the system’s real capabilities, not only for its best-case sales pitch.

    Public safety and public oversight are not opposites

    The public-safety case should not be dismissed. ALPRs can help find stolen vehicles, locate suspects, and respond to serious threats. But that is exactly why governance has to come first. A system useful enough to solve crimes is also useful enough to misuse, over-share, or repurpose.

    Good oversight does not require pretending the technology has no value. It requires acknowledging that useful tools can still create serious risks when access is broad, retention is long, audit logs are weak, vendor permissions are unclear, or outside-agency sharing is treated as a default instead of an exception.

    Why it matters for Bend

    Why it matters for Bend: Bend has already seen how quickly the question can move from “Should we install cameras?” to “Who searched the data, why, and what did they see?” Bend and Redmond are also working through automated traffic-enforcement systems, which are not the same as ALPRs but raise overlapping questions about vendors, retention, access, audit logs, public notice, error correction, and repurposing.

    Traffic cameras, retail ALPRs, police ALPRs, and connected-vehicle data are not identical systems. But they all point toward the same local-governance challenge: ordinary movement is becoming easier to capture, store, search, and share. Communities need clear rules before those records become too convenient to give up.

    “The liberty of every man is at the mercy of every petty officer.”— James Otis, arguing against writs of assistance (1761)

    Safeguards local officials should require

    Before approving, renewing, expanding, or continuing an ALPR program, public officials should require written rules that answer the basic governance questions up front:

    • Purpose limits: define exactly what the system may and may not be used for.
    • Access limits: identify who can search the system and whether outside agencies can access it.
    • Federal-access rules: state whether federal or immigration-enforcement searches are allowed, blocked, or require a specific legal process.
    • Short retention: automatically delete plate data quickly unless it is tied to a documented investigation.
    • Search documentation: require a case number, purpose, user identity, and timestamp for every search.
    • Exportable audit logs: make logs available for independent review, public reporting, and investigation of misuse.
    • Vendor restrictions: define vendor access, support access, data use, training use, subcontractors, and breach obligations.
    • Public reporting: publish regular transparency reports showing searches, outside-agency access, hits, false positives, retention, and policy violations.
    • Democratic review: require council approval before expansion, new integrations, new sharing relationships, or emergency continuation.

    Bottom line: ALPR oversight is becoming a democracy issue because the most important decision is not only whether cameras exist. It is whether the public, through elected officials and enforceable rules, still controls how movement data is searched, shared, retained, audited, and shut down.

  • Police-Tech Vendors Are Becoming Public-Safety Platforms

    Why platform contracts require ongoing oversight

    Body cameras, TASERs, evidence storage, drones, AI tools, analytics, and report-writing software are increasingly being bundled into long-term public-safety platforms. That changes what local oversight has to look like.

    Core issue: Public agencies are no longer just buying individual police tools. They are often entering long-term platform relationships where today’s contract can shape tomorrow’s data access, AI features, evidence workflows, analytics, storage, integrations, and switching costs.

    Axon is no longer just a TASER and body-camera vendor. Its own Q1 2026 financials show a public-safety platform business built around hardware, software, cloud evidence storage, AI tools, analytics, subscriptions, drones, real-time operations, and long-term agency relationships. Axon reported Q1 2026 revenue of $807 million, up 34% year over year.

    That platform model is showing up in public contracts. Baltimore approved a $153 million Axon agreement for body-worn cameras, TASERs, and other public-safety tools, while some city leaders questioned whether the agreement was the best deal for taxpayers. Savannah approved a 10-year, $27 million Axon agreement. Connecticut State Police rolled out upgraded TASERs, body-worn cameras, AI translation capabilities, VR training, drones, and evidence-management tools as part of a broader modernization package.

    Those examples matter because they show how police technology is becoming a bundle: hardware, cloud storage, evidence systems, report workflows, analytics, AI features, training tools, subscriptions, and future upgrades. The public may hear “body cameras” or “TASERs,” but the contract can also shape data access, retention, search tools, audit logs, and the agency’s ability to leave later.

    Investors have noticed the same shift. Business Insider reported that an Axon pitch at the Sohn conference emphasized AI tools such as automated police-report drafting from body-camera footage. That is a market signal: public-safety data, AI workflows, and subscription platforms are becoming part of the growth story.

    Why the platform model changes oversight

    When a city buys a single device, oversight can focus on that device: what it does, who uses it, and how it is maintained. But a platform is different. A platform can expand over time. New features can be added. Workflows can change. Data can be connected across systems. A contract that starts as a body-camera or TASER purchase can become a broader operational environment for evidence management, report writing, analytics, training, records, drones, and real-time response.

    That does not make every feature harmful. Some tools may improve officer safety, evidence handling, language access, disclosure, or administrative efficiency. But the public needs to understand the tradeoff: each added feature can create new questions about data collection, access permissions, audit logs, retention, vendor access, system dependencies, and whether elected officials will be asked to approve meaningful changes before they happen.

    The safeguard question is not simply “Should the agency buy the tool?” It is also: what future capabilities does this platform make possible, who can enable them, and what public process is required before they are used?

    What local officials should ask before approving or renewing a police-tech platform

    • Feature scope: Which tools are included now, which are disabled, and which can be enabled later without a new public vote?
    • AI and analytics: Are report-writing, transcription, translation, facial recognition, object recognition, predictive analytics, or other AI-assisted tools included or available as add-ons?
    • Data storage: What data enters the vendor’s cloud systems, where is it stored, and how long is it retained?
    • Access controls: Who has administrator access, who can search records, and can access be limited by role, case type, unit, or investigation status?
    • Audit logs: Are searches, views, exports, deletions, administrator changes, and vendor-support access logged in a way the agency can export and review?
    • Vendor access: Can vendor employees access agency data for support, product development, testing, demos, analytics, or AI model improvement?
    • Data sharing: Can outside agencies, task forces, prosecutors, federal agencies, or private partners access the platform or receive exports?
    • Exit rights: If the city leaves the platform, can it export complete evidence records, metadata, audit logs, retention schedules, and chain-of-custody information in a usable format?

    Why it matters for Bend

    Axon-style contracts should be reviewed as evolving governance systems, not static equipment purchases. Council and staff should know which features are enabled, who has administrator access, what data moves into vendor cloud systems, and whether new AI or analytics tools can be added without a fresh public discussion.

    That review should not stop at the purchase vote. A police-tech platform can change through software releases, configuration changes, integrations, add-on modules, and new agency workflows. For major public-safety platforms, the better oversight model is continuing review: regular reporting on enabled features, access settings, audit-log exports, retention changes, vendor access, and any new AI or analytics tools.

    Practical safeguard: Require a quarterly platform change log for major police-tech systems. The log should identify major software releases, enabled or deferred features, AI or analytics tools, search changes, evidence-workflow changes, access-control changes, administrator roles, vendor access, audit-log export capability, retention changes, and new sharing relationships.

    Bottom line

    For public officials, procurement is no longer simply “buying a tool.” It can mean entering a long-term platform relationship where today’s contract shapes tomorrow’s data access, integrations, AI features, analytics, storage, and switching costs. That does not mean cities should reject every new public-safety technology. It means the public rules need to be as durable and adaptable as the technology itself.

    Police technology should be judged not only by what it promises on day one, but by what it allows on day 500: who can search, who can share, who can change the settings, who can audit the system, and who can prove whether the public’s limits were actually followed.

    “No man is allowed to be a judge in his own cause, because his interest would certainly bias his judgment, and, not improbably, corrupt his integrity.”— James Madison, Federalist No. 10 (1787)

  • What Happens Next: Stopping the Boxminer Data Center Deal

    Advocate Road Map · La Pine, Oregon · Issued May 14, 2026

    The process that must occur before any sale is final, the community’s intervention points, and actions to take this week.


    ⚠ Important: The May 13, 2026 public comments were not a legal public hearing. Oregon law requires a formal public hearing before this sale can close.

    Nearly three hours of public opposition were delivered at the May 13, 2026 La Pine City Council meeting. That is significant — but the fight is far from over, and the community has more legal leverage than it may realize.

    Oregon law mandates a formal public hearing before any city-owned land can be sold. That has not happened yet. Every step below must occur before Boxminer can legally take ownership of this property. Each one is an intervention point.

    The Foundational Law: ORS 221.725

    Oregon law is unambiguous: before a city council can sell city-owned real property, it must publish advance notice of the proposed sale in a newspaper of general circulation and hold a formal public hearing prior to the sale.

    At that hearing, the full nature and terms of the sale — including an independent appraisal or other evidence of market value — must be fully disclosed. Any city resident has the right to submit written or oral testimony.

    The May 13 public comment period does not satisfy this requirement. The March 25 vote to begin the purchase-and-sale process does not satisfy this requirement.

    The ORS 221.725 public hearing has not been held. The sale cannot legally close until it is.


    Part One: The Process Map — What Must Happen Before the Sale Can Close

    1. ORS 221.725 Public Hearing — Legally Required, Has Not Occurred

    Legal basis: Oregon Revised Statutes § 221.725 · City of La Pine

    Primary intervention point · Legally mandatory

    The city must publish a formal notice of the proposed sale in the Bend Bulletin, the newspaper of general circulation for La Pine. The notice must state the time and place of the hearing, a full description of the property, the proposed uses, and the reasons for the sale.

    Not earlier than five days after that publication, the council must hold the public hearing. At the hearing, the full sale terms — including an independent appraisal or other evidence of market value — must be publicly disclosed. Any city resident must be given the opportunity to submit written or oral testimony.

    What advocates can do: Demand in writing that the city confirm it will comply with ORS 221.725 and provide the date of the required publication. This is not a request — it is a statement that the community knows its rights.

    2. Full Contract Disclosure at Public Hearing

    Legal basis: Oregon Revised Statutes § 221.725 · Appraisal requirement

    Intervention point · Legally mandatory

    At the ORS 221.725 hearing, the city is legally required to fully disclose the nature and terms of the proposed sale, including an independent appraisal or equivalent evidence of market value. This means the full purchase and sale agreement — including any growth or expansion provisions — must be on the public record before the council votes.

    What advocates can do: File a Public Records Request now, before the hearing, for the full PSA text, all communications between city staff or council members and Boxminer, any appraisal commissioned, and any MidState Electric correspondence. The city has five business days to respond or provide a timeline under ORS 192.311.

    3. City Council Vote to Approve the Purchase and Sale Agreement

    Public body: La Pine City Council · Public agenda item

    Intervention point

    This is a separate vote from the March 25 vote to begin the process. The council must vote to formally approve the finalized PSA. This vote must appear on a public agenda with advance notice, giving advocates another opportunity to submit written testimony and speak during public comment.

    What advocates can do: Monitor the city’s meetings page at lapineoregon.gov/meetings for agenda postings. The next regular meeting is May 27, 2026. Any PSA approval vote must be listed as a new business item with supporting documents in the packet. If it appears without prior public notice of the ORS 221.725 hearing, challenge it immediately in writing.

    4. Deschutes County Deed Transfer — County Publication Required

    Legal basis: Oregon Revised Statutes § 275.120 · Deschutes County Board of Commissioners

    County action required · Intervention point

    The land is currently owned by Deschutes County. Before the county can transfer title, Oregon law requires the county sheriff to publish a notice of the sale in a local newspaper of general circulation once per week for four consecutive weeks prior to the sale. This is a parallel, independent publication requirement that creates another four-week public notice window.

    What advocates can do: Contact the Deschutes County Board of Commissioners now and put them on record. As the current titleholder, the county is a party to this transaction. Submit written testimony to the BOCC and request that the county independently verify the city has completed its ORS 221.725 obligations before proceeding.

    5. Formal Land Use Application and Site Plan Review — Planning Commission

    Legal basis: La Pine Development Code · City Planning Commission · ORS 227.178

    Second major intervention point

    Even after the land sells, Boxminer cannot break ground without submitting a formal land use application for site plan review. This triggers La Pine’s Planning Commission process, which has its own public notice, comment period, and hearing requirements completely independent of the land sale process.

    This is where the zoning question must be formally resolved in writing by city staff: La Pine Development Code Sec. 15.24.300 states that in the Light Industrial zone, “Energy and power generation uses are prohibited.” City staff must publish a written legal determination explaining how a 20MW Bitcoin mining facility is classified under that code before any permit can issue.

    What advocates can do: Central Oregon LandWatch can formally intervene in the land use process when the application is filed and can refer legal counsel to challenge the zoning classification if needed. File a written request with city Community Development now asking staff to confirm in writing the zoning classification that would apply to this use before an application is filed.

    6. Building Permits Issued — Final Gate

    Public bodies: La Pine Building Services · Deschutes County Community Development

    Final gate

    Building permits cannot be issued until after land use approval. Each permit is a public record. If the zoning determination or site plan review is contested, a Land Use Board of Appeals appeal can be filed, which can put a hold on permit issuance while the appeal is heard.

    The Oregon Department of Land Conservation and Development also has oversight authority over local land use decisions that conflict with acknowledged comprehensive plans.


    Part Two: What Advocates Should Do This Week

    🔥 Send a Written ORS 221.725 Demand Letter to City Hall

    Timing: Do within 48 hours.

    Write to City Manager Geoff Wullschlager and the City Recorder demanding:

    • Written confirmation that the city will comply with ORS 221.725 before finalizing any sale.
    • The anticipated date of the required newspaper publication.
    • Confirmation that the ORS 221.725 public hearing will be separately noticed and held before any PSA vote.

    Send by email and certified mail. Keep a copy. This letter creates a paper trail that the city received formal notice of its obligations.

    City Manager: Geoff Wullschlager
    Email: info@lapineoregon.gov
    Phone: (541) 536-1432
    Address: 16345 Sixth Street, La Pine, OR 97739

    🔥 File a Public Records Request for the Full Contract and All Communications

    Timing: Do within 48 hours.

    Under ORS 192.311, the city has five business days to provide the records or give a timeline. Request:

    • The full text of any purchase and sale agreement, letter of intent, or MOU with Boxminer Co. or any related entity.
    • All written communications between city staff or council members and Boxminer Co., Frontier Mining, or Jeff Keller from January 2025 to present.
    • Any appraisal of the subject property.
    • Any MidState Electric correspondence regarding power supply.
    • Any legal opinion on the Light Industrial zoning classification of this use.

    File online: La Pine Public Records Request Form

    🔥 Call Central Oregon LandWatch

    Timing: Do within 48 hours.

    Rory Isbell at Central Oregon LandWatch was previously unaware of this proposal. He now is, but he needs to hear that nearly three hours of public opposition materialized at the May 13 council meeting and that the ORS 221.725 hearing has not been scheduled.

    Share this key fact from the March 11 minutes: Jeff Keller told the council he had been working with MidState Electric and SLED Director Patricia Lucas since 2022 — three years of negotiations before the public heard a word. That timeline is material to any legal challenge about adequate public process.

    LandWatch can provide or refer an attorney to formally intervene at both the public hearing and the Planning Commission site plan review stage.

    Contact: Rory Isbell, Staff Attorney and Rural Lands Program Director
    Email: rory@colw.org
    Phone: (541) 647-2930 x804

    📋 Document the May 13 Comments While They Are Fresh

    Timing: Do within 72 hours.

    The nearly three hours of public comments are part of the official record, but advocates should independently document them. Track the names and addresses of speakers, the specific concerns raised, and any commitments or statements made by council members or city staff in response.

    This record will be essential at the ORS 221.725 formal hearing and any future LUBA appeal. If anyone recorded the meeting, secure those recordings now. The city should also produce audio or video if it exists; request it via public records if needed.

    📋 Write to the Deschutes County Board of Commissioners

    Timing: Do this week.

    The county is the current landowner and must execute the deed transfer. The city itself has publicly confirmed that Deschutes County must sign off on the final land sale and that a county building review is also required before construction.

    This means the BOCC has real authority here — not just a rubber stamp role. Write to the BOCC formally:

    • Notify them that significant organized community opposition exists.
    • Request that the county independently confirm the city has completed its ORS 221.725 obligations before proceeding with any transfer.
    • Ask the BOCC to place the matter on a public agenda for discussion.

    Deschutes County Board of Commissioners:
    deschutes.org
    1300 NW Wall Street, Bend, OR 97703

    🔥 Request a Speaking Slot at the May 29 Oregon Data Center Advisory Committee Meeting</h3

  • Surveillance • Privacy • Local Oversight

    Bend’s Flock Data Shows Why Surveillance Oversight Must Be Built Into the System

    Recent reporting about Bend’s Flock Safety cameras and Oregon’s sanctuary-law lawsuit point to the same lesson: privacy rules only work when the databases enforce them.

    The most important surveillance story in Bend this week is not hypothetical. According to The Source Weekly, federal immigration officials made 279 queries into Bend’s Flock Safety data in the first three weeks after the cameras went live. Bend Police reportedly did not authorize those searches, and it remained unclear what, if any, data may have been retrieved.

    That should concern anyone who cares about local control, public accountability, or civil liberties.

    The issue is not simply whether a particular search was improper. The larger problem is governance. When a surveillance system is installed for one stated purpose, it can quickly become useful to other agencies, vendors, or outside users who were not central to the original public debate.

    If city officials cannot later answer basic questions — who searched the system, why they searched it, what they saw, whether the search was tied to a case number or documented purpose, and whether any result was shared — then the public is being asked to trust a system that cannot be independently verified.

    That is not meaningful oversight. That is a blind spot.

    Audit logs are not a technical detail. They are the oversight system.

    Surveillance oversight often gets discussed as if it is mainly a policy question: Should the city approve the tool? What is the stated purpose? What does the vendor promise? What does the agency say it intends to do?

    Those questions matter, but they are not enough.

    Once a system is live, the real questions become operational:

    • Who can access the system?
    • Can outside agencies search it?
    • Can federal agencies search it?
    • Can vendors access camera feeds, search tools, dashboards, support logs, or stored data?
    • Does every search leave a usable record?
    • Can elected officials or independent reviewers verify how the system was used?
    • Are searches tied to a case number, warrant, emergency, or documented purpose?
    • Are improper searches detectable?

    Without those controls, the public has no practical way to know whether the system is being used as promised.

    This does not require assuming bad faith by local officials. In fact, it shows why good-faith intentions are not enough. A system can be approved by people with narrow intentions and later become available to people with very different priorities. That is why access controls, audit logs, outside-agency limits, vendor-access limits, and public reporting must exist before a system goes live.

    “You must first enable the government to control the governed; and in the next place oblige it to control itself.”
    — James Madison, The Federalist No. 51 (1788)

    Oregon’s sanctuary-law lawsuit is also about database access

    The Bend Flock story now sits inside a larger Oregon data-sharing dispute.

    OPB reported that a lawsuit filed in Multnomah County Circuit Court alleges Oregon State Police allowed federal immigration authorities to access Oregonians’ data through shared law-enforcement databases for years, despite Oregon’s sanctuary laws. Oregon State Police denies wrongdoing.

    The Source Weekly also reported that the complaint alleges federal immigration authorities queried state-run data about Oregonians 1.4 million times between February 2025 and February 2026, an average of 3,835 queries each day.

    The practical lesson is straightforward: a sanctuary policy is only as strong as the database permissions behind it.

    If an agency is legally barred from using data for immigration enforcement, the system should not rely on informal restraint. It should include technical controls that prevent improper access, audit logs that expose improper use, and consequences when policy and practice diverge.

    A privacy rule that lives only on paper is fragile. A privacy rule built into permissions, logging, retention limits, and reporting is much harder to ignore.

    Why this matters for Bend

    Bend residents’ information may pass through city, county, state, vendor, and law-enforcement systems. That information can include license plate scans, police records, driver information, public records, utility records, permits, emergency-service data, and other civic information collected for ordinary public purposes.

    The danger is that data collected for one purpose can become useful for another.

    A license plate reader approved for local public-safety purposes can become searchable by outside agencies. A state database can become an immigration-enforcement tool. A vendor platform can create access points that city officials did not fully understand when the contract was approved. A policy promise can fail if the technology underneath it does not actually enforce the rule.

    That is why surveillance oversight cannot stop at approval. Local officials need to know who can search local systems, what outside agencies can access, what vendors can see, how long data is retained, and whether every search leaves a record that can be reviewed.

    The safeguard standard should be simple

    Before Bend approves, renews, or expands any surveillance or sensitive data system, the city should be able to answer:

    • Who can access the data?
    • Who can search the system?
    • Can outside agencies access it?
    • Can federal agencies access it?
    • Can vendors access it?
    • Is every search logged?
    • Are searches tied to a documented purpose?
    • How long is data retained?
    • Can improper access be detected?
    • Can elected officials and the public receive meaningful reports about system use?

    If those questions cannot be answered clearly, the system is not ready.

    This is not about being anti-technology. It is about making sure public technology remains accountable to the public. Tools that collect sensitive information should not depend on trust alone. They should be designed so that misuse is difficult, detectable, and provable.

    Bottom line

    The Bend Flock story and the Oregon sanctuary-law lawsuit point to the same conclusion: access is the story.

    Who can search the data? Who can receive it? Who can share it? Who can buy it? Who can combine it with other systems? Who can turn an ordinary resident’s movement, record, or routine interaction with government into an investigative lead?

    Privacy safeguards fail when access is undefined, unlogged, or routed through systems the public cannot see.

    The best safeguards are practical and boring by design: collect less data, connect fewer systems, limit outside access, require documented purposes, log every search, review the logs, shorten retention, make vendor access visible, and make misuse provable.

    Surveillance oversight works best when restraint is built into the system before the data becomes too useful to give up.


    Related reading:

  • Is Your Phone Broadcasting More Than You Realize?

    A recent article from De Jure Media caught my attention because it speaks to a broader concern many privacy advocates already share: our phones and other connected devices may be participating in systems of tracking and data collection that most people neither understand nor meaningfully consent to.

    The article, Your Phone Is Watching You Right Now — Here’s How to Prove It, makes serious claims about smartphone-based surveillance, hidden Bluetooth activity, and the possibility that ordinary people can observe part of this phenomenon for themselves using a BLE scanner app. Whether every conclusion in the piece ultimately holds up or not, it raises important questions about transparency, consent, and how much invisible infrastructure now surrounds daily life.

    What the article argues

    De Jure Media presents the story as an investigation that began with a whistleblower and expanded into a broader examination of unusual Bluetooth Low Energy activity. The article argues that readers may be able to detect suspicious nearby devices by scanning their surroundings and looking for long alphanumeric names, unknown manufacturers, and persistent signals that are difficult to identify physically.

    The piece also connects those observations to larger concerns about pandemic-era exposure notification systems, location tracking, overlapping corporate and government surveillance capabilities, and the long-term risk of normalizing infrastructure that can monitor movement and association at scale.

    Why this matters even beyond one article

    Even setting aside the article’s most dramatic conclusions, the underlying privacy concern is real. Modern phones constantly interact with wireless systems, identifiers, sensors, apps, platforms, and data ecosystems that are largely invisible to the public. That creates opportunities for passive tracking, behavioral profiling, and surveillance far beyond what most people realize.

    For me, the value of this article is not just in its strongest claims. It is that it encourages readers to look more closely at the everyday technology around them and ask better questions. What is being broadcast? What is being collected? Who has access to that information? How long is it retained? And what meaningful consent, if any, did users ever provide?

    A note of caution

    Articles like this are worth reading carefully, but also critically. Extraordinary claims deserve verification. It is possible to take the broader privacy issues seriously without treating every inference as proven fact. That is often the right balance in surveillance reporting: remain open to evidence, but do not let uncertainty become an excuse to ignore genuine risks.

    What readers can do

    • Review your phone’s Bluetooth, location, and app permission settings.
    • Learn what Bluetooth Low Energy scanning tools actually show and what their limits are.
    • Be cautious about drawing conclusions from a single scan or unfamiliar device name.
    • Use reporting like this as a prompt to ask for stronger transparency, consent, and privacy safeguards.
    • Read the original article and evaluate the claims for yourself.

    Read the original

    You can read the original De Jure Media article here:

    Your Phone Is Watching You Right Now — Here’s How to Prove It

    Whether you agree with all of its conclusions or not, it is the kind of piece that pushes an important public conversation forward: how much invisible surveillance infrastructure has already been built into the technology we carry every day, and what it would take to bring that infrastructure into the light.

  • Welcome to the blog

    This blog will be used to share updates, commentary, and analysis on current developments in privacy, security, surveillance, cybersecurity, civil liberties, and related public-interest technology issues.

    Some posts will respond to news or policy developments. Others will highlight longer-term trends, practical concerns, and the safeguards that public institutions should keep in view when adopting new technologies or expanding data collection.

    Over time, this space will complement the Signals & Safeguards newsletter by providing a place for shorter updates, reflections, and posts on topics that deserve closer attention.

    Thanks for visiting.