Product1 publisherNot yet confirmed elsewhere3 min readPublished
Zero-knowledge age checks move the risk to enrolment, and that is where nobody is looking
The proof hides a birthdate from the website. It does not remove the entity that established the birthdate, issues a token at every login, and can be told to stop.
The Product Desk · Product desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
What happened
- Techdirt argues that zero-knowledge-proof age verification schemes are gameable and hackable rather than the cure-all their proponents describe.
- In these designs the user gets a token vouching for their age at every login, which keeps a standing link back to the party that verified them.
- The non-interactive zk-SNARK construction is now the preferred method in age verification products.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- constraint The proof shrinks what each website learns but cannot remove the enrolment record, so a team's data footprint relocates to a single issuer instead of getting smaller.
- exposure Whoever holds the issuer role ends up with a per-use log across every service a user visits, and that log is reachable by anyone with leverage over the issuer.
- decision Choosing a ZKP vendor is really choosing a party that can revoke your users' access, which makes it a procurement and dependency question rather than a cryptography one.
- precedent With dozens of regimes converging on wallet-issued tokens, the architecture is being locked in before the testing evidence on it has been published.
The cryptography does what it says. A zk-SNARK lets one machine prove a statement to another without handing over the underlying data, and the shortened non-interactive form is verified instantly rather than through a long run of challenges [14]. Nothing in that exchange is the weak part. The weak part sits upstream of it: something has to establish the age first, and in the schemes Techdirt describes the user is issued a token that vouches for that age every time they log in, which keeps a live link back to whoever did the verifying [10].
That is a redistribution of collection, not a removal of it. Techdirt's own description of the good case is that one entity collects the private information, usually on the user's device, instead of every site and app that needs an age attested [15]. So the enrolment record still exists, it just exists in one place with better leverage. From there the issuer can see each time the credential is used, which is a per-service, per-session trail on any user someone cares to look at [11], and the issuer can be pressured by a government to pull a user's access [12]. Techdirt's framing is that without oversight of who may operate these systems, the design puts critical internet infrastructure in very few hands [5].
For a team shipping a compliance flow, the mismatch is concrete. The obligation in these laws is to assure or estimate that a user is of a certain age [9]. A zero-knowledge proof addresses disclosure to the relying party, which is not the thing the statute measures you against, and it does nothing about the enrolment step it depends on. The decision in front of the team is therefore a vendor decision: who enrols the user, what that party retains, and who is able to instruct it to revoke. The cryptographic primitive was not built for this job in the first place [13], even though zk-SNARKs are now the preferred construction in age verification products [4].
The scale is worth stating plainly, because it is the part that makes an architecture default rather than a choice. Roughly half of US states already have an internet age verification law [6], and all 27 EU member states are expected to have age verification running inside a mini-wallet in the EUDI wallet by the end of 2026 [2]. That is on the order of 52 separate regimes converging on wallet-issued tokens [19], with about four months left before the EU date as of Techdirt's 21 August 2026 piece [18]. Australia already has one very broad restriction live [8], and KOSA and the KIDS Act are moving federally in the US [7].
One caution on the evidence. Techdirt says these schemes are gameable and hackable rather than a cure-all, and rests that on recent real-world testing [1][3], but the excerpt available here stops at the start of its EU rollout section, so the specific failures are the publisher's assertion rather than something reproduced here. The structural argument does not need them. Techdirt's prior position is that most of these laws fail at keeping children out anyway while creating privacy exposure for everyone [16], and a proof system layered on top of an issuer inherits that issuer's reach.
What to watch
- Whether the EU mini-wallet inside EUDI actually ships across all 27 member states by the end of 2026, or slips into national pilots.