Product1 distinct publisher3 min readUpdated
The proof hides a birthdate from the website. It does not remove the entity that established the birthdate, issues a token at every login, and can be told to stop.
The Product Desk · Product desk
Compiled by The Product DeskSomething wrong?How this is made
The cryptography does what it says. A zk-SNARK lets one machine prove a statement to another without handing over the underlying data, and the shortened non-interactive form is verified instantly rather than through a long run of challenges [11]. Nothing in that exchange is the weak part. The weak part sits upstream of it: something has to establish the age first, and in the schemes Techdirt describes the user is issued a token that vouches for that age every time they log in, which keeps a live link back to whoever did the verifying [7].
That is a redistribution of collection, not a removal of it. Techdirt's own description of the good case is that one entity collects the private information, usually on the user's device, instead of every site and app that needs an age attested [13]. So the enrolment record still exists, it just exists in one place with better leverage. From there the issuer can see each time the credential is used, which is a per-service, per-session trail on any user someone cares to look at [8], and the issuer can be pressured by a government to pull a user's access [9]. Techdirt's framing is that without oversight of who may operate these systems, the design puts critical internet infrastructure in very few hands [14].
For a team shipping a compliance flow, the mismatch is concrete. The obligation in these laws is to assure or estimate that a user is of a certain age [6]. A zero-knowledge proof addresses disclosure to the relying party, which is not the thing the statute measures you against, and it does nothing about the enrolment step it depends on. The decision in front of the team is therefore a vendor decision: who enrols the user, what that party retains, and who is able to instruct it to revoke. The cryptographic primitive was not built for this job in the first place [10], even though zk-SNARKs are now the preferred construction in age verification products [12].
The scale is worth stating plainly, because it is the part that makes an architecture default rather than a choice. Roughly half of US states already have an internet age verification law [1], and all 27 EU member states are expected to have age verification running inside a mini-wallet in the EUDI wallet by the end of 2026 [3]. That is on the order of 52 separate regimes converging on wallet-issued tokens [17], with about four months left before the EU date as of Techdirt's 21 August 2026 piece [19]. Australia already has one very broad restriction live [4], and KOSA and the KIDS Act are moving federally in the US [2].
One caution on the evidence. Techdirt says these schemes are gameable and hackable rather than a cure-all, and rests that on recent real-world testing [5][16], but the excerpt available here stops at the start of its EU rollout section, so the specific failures are the publisher's assertion rather than something reproduced here. The structural argument does not need them. Techdirt's prior position is that most of these laws fail at keeping children out anyway while creating privacy exposure for everyone [15], and a proof system layered on top of an issuer inherits that issuer's reach.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Techdirt argues that ZKP-focused age verification schemes are gameable, hackable, and not the cure-all some claim.
By the end of 2026, the 27 states within the European Union are expected to have infrastructure in place to do age verification within a 'mini-wallet' app that will live inside the EUDI wallet.
Techdirt cites recent real-world testing of these systems as the basis for saying ZKPs are not a silver bullet.
The shortened non-interactive form, zk-SNARK, is the current preferred method for age verification.
Without oversight of who has authority to implement and operate these systems, the approach centralizes critical internet infrastructure in the hands of very few actors.
At the time of writing, about half the states in the US have some internet age verification law in place.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One advocacy source; key findings uncited
The cluster rests on a single publisher writing from a declared prior position. Its descriptive and definitional content (ZKP mechanics, zk-SNARKs, the enrolment-issuer failure modes) is internally coherent and checkable in principle, but the load-bearing empirical items — the demo-only ZKP build, the Chrome-extension token replay, the 400-signature letter — appear without names, links or documents in the supplied text, and no proponent, vendor or regulator response is present.
Mandates broad, ZKP deployment nascent
Regulatory adoption is genuinely wide: roughly half of US states, a very broad Australian restriction, federal US bills in motion, and an end-of-2026 expectation for all 27 EU member states. Technical adoption of the privacy-preserving layer is much thinner — the mini-wallet is shipping but its ZKP features are reported as active only in a closed prototype, and the one tested build was defeated by token replay. The gap between mandate coverage and working ZKP deployment is the story.
Silver-bullet framing outruns what ships
The 'zero-knowledge solves age verification' framing that the story attacks is overstated relative to what is deployed: the proof removes birthdate disclosure to the relying party while leaving an enrolment issuer that mints per-login tokens, sees usage, and can be compelled to revoke, and the flagship implementation reportedly had the ZKP path off and a trivially replayable token. The overstatement is on the proponent side, and the cluster corrects toward reality; the score stays moderate rather than high because Techdirt's own catastrophic framing ('existential threat', 'removing that person's access to the internet entirely') also runs ahead of the single, uncited incident record it offers.
Declared advocacy stance on prior reporting
The only source is a digital-rights-aligned publisher with an explicit stake in the conclusion: it flags its earlier coverage, writes in the first person about 'our concerns', labels federal bills 'dangerous' before analysis, and frames the piece under a 'they-still-put-people-at-risk' department. That is an observable directional incentive to select confirming evidence, and no counterparty with an opposing incentive appears in the cluster to offset it.
One publisher, mechanism firmer than facts
Confidence is limited by the single-publisher, single-item cluster and by advocacy incentives on that source. The structural argument — that a zero-knowledge presentation does not remove the enrolment issuer, its usage visibility, or its revocation power — is mechanistically sound and would survive most corroboration. The specific incident record and the timeline claims would need independent confirmation before being relied on operationally.
product
France's under-15 ban falls, and age-gating now has to pass a proportionality test1 distinct publisher
product
Grok CSAM suit gains a fourth plaintiff and a 7,000-image count2 distinct publishers
build
Thirty lines of Doctrine filter, and the query paths where it is simply not there1 distinct publisher
product
Senators want every TikTok test that disabled a safety feature, not just the one that hit 15 million3 distinct publishers
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 21, 2026