Drooid Logo
Back to story perspectives

Full Breakdown

EU Age-Verification App: Launch, Flaws and the Ongoing Debate

4/25/2026, 5:34:34 AM

Launch and Immediate Security Findings

On 15 April 2026 the European Commission released its age-verification app, declaring it ready; within 48 hours security consultant Paul Moore demonstrated a bypass that reset the PIN and generated a valid age credential without decrypting stored data.

Policy Background and Intended Function

The app is designed to satisfy the Digital Services Act by issuing zero-knowledge age proofs after users scan an ID or passport and complete a face-match, thereby avoiding direct data sharing with online platforms.

Key Actors and Groups

President Ursula von der Leyen promoted the tool; security consultant Paul Moore, cryptographer Bart Preneel (KU Leuven), and Ping Identity CTO Alex Laurie examined the code, while civil-society voices such as Hanna Bözakov and Eva Simon raised concerns, and European Commission spokesperson Thomas Regnier defended the rollout.

Data & Statistics

A prior Discord breach exposed 70 000 records, over 400 scientists signed a petition to halt the EU scheme, 61 % of Australian teens still access restricted sites, and the OECD reports 25 countries pursuing similar age-verification laws.

Why It Matters / Impact

Storing unencrypted biometrics creates a prime target for identity theft, while mandatory verification may exclude undocumented migrants and enable state surveillance, and the focus on age checks does not address algorithmic harms that drive online abuse.

Official Statements & Responses

Commission spokesperson Thomas Regnier called the project open to feedback and said improvements were underway; MEP Christel Schaldemose called the app a first step but urged a harmonised EU approach; President von der Leyen insisted there are no more excuses for delay.

Criticism & Opposition

Security experts label the design a fundamental flaw, with Preneel stating the technology simply will not work; civil-society groups warn it threatens anonymity and free expression, especially for marginalized users.

Conflicting Reports & Gaps

Analyst Milosz Gaczkowski argues the bypass does not expose sensitive data and the threat model is overstated, while others maintain the trust-boundary design is insecure regardless of patches; no independent audit has been published.

What’s Next

The Commission plans a public download by summer 2026, with wallet integrations slated for France, Denmark, Greece, Italy, Spain, Cyprus and Ireland, while debates continue over whether to pair the tool with stronger platform-design regulations under the DSA.

Verbatim Quotes

  • “It is completely anonymous: users cannot be tracked,” — Ursula von der Leyen, President of the European Commission
  • “If an app fails to purge high-resolution passport scans or selfies after a crash or cancellation, it’s creating a toxic accumulation of unmanaged risk for the user," he told TechRadar.” — Alex Laurie, CTO, Ping Identity
  • “The concept simply doesn't work, even if the implementation were perfect," he told TechRadar.” — Paul Moore, security consultant
  • “But the real problem is that you roll out a technology that's not going to work," he told TechRadar.” — Bart Preneel, cryptographer, KU Leuven
  • “The more data these systems collect, the more attractive they become to hackers,” — Hanna Bözakov, Managing Director, Tutao