EU calls VPNs "a loophole that needs closing" in age verification push

Hacker News Top News

Summary

The European Parliamentary Research Service (EPRS) has labeled VPNs 'a loophole that needs closing' in the context of online age-verification laws, raising concerns about children bypassing regional content restrictions. The push has sparked pushback from privacy advocates and VPN providers, highlighting tensions between child safety regulation and digital privacy rights.

No content available
Original Article Export to Word Export to PDF
View Cached Full Text

Cached at: 05/09/26, 06:33 AM

# EU calls VPNs “a loophole that needs closing” in age verification push Source: [https://cyberinsider.com/eu-calls-vpns-a-loophole-that-needs-closing-in-age-verification-push/](https://cyberinsider.com/eu-calls-vpns-a-loophole-that-needs-closing-in-age-verification-push/) ![](https://cyberinsider.com/wp-content/uploads/2026/05/73592.jpg)The European Parliamentary Research Service \(EPRS\) has warned that virtual private networks \(VPNs\) are increasingly being used to bypass online age\-verification systems, describing the trend as “a loophole in the legislation that needs closing\.” The warning comes as governments across Europe and elsewhere continue expanding online child\-safety rules that require platforms to verify users’ ages before granting access to adult or age\-restricted content\. VPNs are privacy tools designed to encrypt internet traffic and hide a user’s IP address by routing connections through remote servers\. While widely used for legitimate purposes such as protecting communications, avoiding surveillance, and enabling secure remote work, regulators are increasingly concerned that the same technology allows minors to circumvent regional age checks\. The[EPRS notes](https://x.com/EP_EPRS/status/2051959573917929731)that[VPN usage surged](https://cyberinsider.com/proton-vpn-signups-in-uk-surge-1400-after-online-safety-act-comes-into-force/)after mandatory age\-verification laws took effect in countries including the United Kingdom and several US states\. In the UK, where online services are now required to prevent children from accessing harmful content, VPN apps reportedly dominated download charts after the law came into force\. > — European Parliamentary Research Service \(@EP\_EPRS\)[May 6, 2026](https://twitter.com/EP_EPRS/status/2051959573917929731?ref_src=twsrc%5Etfw) The[document](https://www.europarl.europa.eu/RegData/etudes/ATAG/2026/782618/EPRS_ATA(2026)782618_EN.pdf)explicitly frames VPNs as a regulatory gap, stating that some policymakers and child\-safety advocates believe VPN access itself should require age verification\. England’s Children’s Commissioner has also called for VPN services to be restricted to adults only\. However, forcing users to verify their identity before accessing VPN services could significantly weaken anonymity protections and create new risks around surveillance and data collection\. VPN providers and other privacy advocates have already expressed their objections to this approach in a[letter sent to the UK policymakers](https://cyberinsider.com/mozilla-mullvad-proton-sign-letter-opposing-uk-age-verification/)\. Last month, researchers found[multiple security and privacy flaws](https://cyberinsider.com/eus-official-age-verification-app-found-exposing-sensitive-user-data/)in the European Commission’s official age\-verification app shortly after its release\. The app, promoted as a privacy\-preserving tool under the DSA framework, was discovered storing sensitive biometric images in unencrypted locations and exposing weaknesses that could allow users to bypass verification controls entirely\. The EPRS paper acknowledges that age verification remains technically difficult and fragmented across the EU\. Current systems based on self\-declaration, age estimation, or identity verification are described as relatively easy for minors to bypass\. The report highlights emerging approaches, such as “double\-blind” verification systems used in France, where websites receive only confirmation that a user meets age requirements without learning the user's identity, while the verification provider does not see which websites the user visits\. At the same time, regulators are beginning to address VPN use directly in legislation\. Utah recently became the first US state to[enact a law explicitly targeting VPN](https://cyberinsider.com/utah-becomes-first-us-state-to-require-age-verification-for-vpn-use/)use in online age verification\. The state’s SB 73 defines a user’s location based on physical presence rather than apparent IP address, even if VPNs or proxy services are used to mask it\. The EPRS suggests VPN providers may face increasing scrutiny as the EU revises cybersecurity and online safety legislation, noting that future updates to the EU Cybersecurity Act could introduce child\-safety requirements aimed at preventing VPN misuse to bypass legal protections\. If you liked this article, be sure to follow us on**[X/Twitter](https://twitter.com/CyberInsidercom)**and also**[LinkedIn](https://www.linkedin.com/company/cyberinsider/)**for more exclusive content\.

Similar Articles

US tech firms successfully lobbied EU to keep datacentre emissions secret

Reddit r/singularity

US tech firms including Microsoft successfully lobbied the EU to keep individual datacentre emissions data confidential, with industry language incorporated almost verbatim into EU rules, hindering environmental scrutiny and potentially violating transparency conventions.

Accelerating AI adoption in Europe

OpenAI Blog

OpenAI and Allied for Startups released the Hacktivate AI report featuring 20 policy proposals to accelerate AI adoption across Europe, ahead of the European Commission's Apply AI Strategy launch. The initiative brought together 65 participants from EU institutions, governments, enterprises, and startups to design practical solutions for broader AI uptake and competitiveness.

Teen safety, freedom, and privacy

OpenAI Blog

OpenAI outlines its approach to balancing teen safety, user freedom, and privacy in ChatGPT, including building an age-prediction system, parental controls, and stricter content rules for under-18 users. The company also signals plans for advanced privacy features and advocates for AI conversation privilege with policymakers.

Introducing data residency in Europe

OpenAI Blog

OpenAI announces data residency capabilities in Europe for ChatGPT Enterprise, ChatGPT Edu, and API Platform, enabling organizations to store customer data at rest in-region and meet local data sovereignty and GDPR compliance requirements.