The EU's new age-verification app was bypassed in under 2 minutes, exposing deep flaws in regulatory AI-backed identity infrastructure.
A WIRED investigation found that the EU's newly deployed age-verification application — designed to restrict minors from accessing adult content — can be circumvented in approximately 2 minutes. The flaw undermines the EU's broader digital identity and age-gating regulatory push, including obligations under the Digital Services Act. No patch or timeline for a fix has been publicly announced. The app was positioned as a privacy-preserving alternative to submitting government ID directly to platforms.
The EU's age-verification app failing in 2 minutes is a security architecture failure, not just a policy one. It signals that government-mandated identity layers will be technically unreliable for years, meaning any product that depends on regulatory compliance tooling for age-gating cannot offload security responsibility to these systems. Developers building on top of DSA-compliant flows need to treat third-party verification as untrusted input and add their own fraud/signal layers.
If your product relies on a third-party age-verification API for DSA compliance, run a threat model this week: assume the verification result can be spoofed and design your fallback — rate limiting, behavioral signals, or secondary checks — before regulators audit you for relying on broken infra.
Go to claude.ai and open a new conversation
Tags