All posts
5 min readOpenKYC Team

Age Verification Under the EU Digital Services Act: Where It's Heading

age-verificationregulationeu

The EU is taking a different road to the same destination as the US and UK: mandatory age assurance for services that pose risks to minors. Instead of a single age-check statute, the obligation emerges from the Digital Services Act's minor-protection duties, Commission guidelines, and, most interestingly, an EU-built technical solution that tells you exactly what the endgame looks like. Platforms that read the direction of travel now can integrate once and be ready before enforcement hardens.

Article 28: the duty behind the headlines

Article 28 of the DSA requires online platforms accessible to minors to put in place appropriate and proportionate measures to ensure a high level of privacy, safety, and security for minors. It's deliberately principles-based. The DSA does not say "verify every user's age." But for platforms whose content or features create real risk for children, age assurance is the obvious "appropriate measure," and the Commission has said as much.

Very large online platforms (VLOPs) carry additional weight: their systemic-risk obligations under Articles 34 and 35 explicitly cover risks to minors, and the Commission has opened formal DSA proceedings against several major platforms (including adult-content sites designated as VLOPs) with age verification and minor protection among the stated concerns. The enforcement stick is the DSA's standard one: fines of up to 6% of global annual turnover.

The 2025 guidelines: what "appropriate" means in practice

In July 2025, the Commission published guidelines on the protection of minors under Article 28. Guidelines aren't binding law, but they are the Commission's enforcement yardstick, and they sharpened the picture considerably:

  • Risk-based approach. The intensity of age assurance should match the risk. Pornography and gambling sit at the top, where the guidelines point to actual age verification rather than weaker estimation methods.
  • Self-declaration is out as a meaningful measure for risky services.
  • Privacy-preserving by design. Age assurance should minimise data collection: proving an age attribute, not disclosing an identity.
  • Accompanying measures like safer defaults for minors' accounts, recommender-system adjustments, and limits on addictive design features.

The message to platform operators: if your service hosts adult content or other high-risk material and you serve EU users, the Commission expects real age verification, implemented in a way that doesn't strip-mine user data.

The EU's own answer: the age verification blueprint

Here's where the EU diverges from everyone else. It built the reference implementation. In July 2025, the Commission published an age-verification blueprint and white-label app, often called the "mini-wallet," developed as a precursor to the EU Digital Identity (EUDI) Wallet arriving under eIDAS 2.0.

The model: a user proves they are over 18 once, using an eID, identity document, or other trusted source, and receives a cryptographic proof of age stored on their device. When a website needs an age check, the user presents that proof. Several member states began piloting and adapting the app in the months after release, and the long-term plan is for the capability to fold into the full EUDI Wallet that member states must offer their citizens.

The technical foundations are the open standards stack: W3C Verifiable Credentials-style attestations and the OpenID4VC family of protocols for issuance and presentation. The EU didn't invent a proprietary scheme; it standardised on the same rails the broader digital-identity ecosystem uses.

Double anonymity: the principle that makes it work

The blueprint is built around a principle worth understanding because it's becoming the regulatory benchmark: double anonymity (or double-blindness).

  • The verifier learns only the claim. The website receives proof that the user is over 18, not a name, birthdate, or document. It cannot identify the user from the age proof.
  • The issuer doesn't learn where the proof is used. The party that verified the user's age cannot see which sites the user visits with it.

No single party ever holds both "who you are" and "what you browse." That's the property that resolves the privacy objections which have dogged age-verification mandates everywhere, and it's a property per-site ID upload can never deliver. France's data-protection authority helped pioneer this requirement, which brings us to the member states.

Member states aren't waiting

While the Brussels machinery moves, national regulators have acted. France has been the most aggressive: its SREN law empowered ARCOM to require age verification on pornographic sites, backed by a published technical standard that mandates double-anonymity, and enforcement actions against non-compliant sites, including blocking measures, have been working through French courts, with some major adult sites temporarily withdrawing from the market in protest. Italy's regulator AGCOM has introduced its own age-verification requirements for adult sites, and Germany has long enforced youth-protection rules through its media authorities. A group of member states has also pushed the Commission for EU-wide mandatory age verification, and proposals around a "digital majority age" for social media have circulated at the political level, with details still in flux as of mid-2026.

The practical consequence: an operator serving the EU already faces national age-verification mandates today, with harmonised EU expectations layering on top. This mirrors the fragmentation playing out in the US, and the UK regime, covered in our Online Safety Act guide, adds a third variant. Three regimes, one underlying capability.

What platforms should do now

A pragmatic sequence for 2026:

  • Classify your exposure. Are you hosting adult content, gambling, or features the 2025 guidelines flag as high-risk for minors? That determines whether you need verification or lighter assurance.
  • Don't build per-jurisdiction silos. A bespoke flow for France, another for the UK, another per US state is unmaintainable. Target the credential model all of these regimes are converging on.
  • Choose open standards. The EU has committed to W3C Verifiable Credentials and OpenID4VC through the EUDI Wallet programme. Integrating that stack means EU-issued age proofs will work with your service natively, and the same integration accepts credentials from other issuers.
  • Design for data minimisation. Regulators on both sides of the Channel now treat "collect the minimum" as part of the legal standard, not just good practice.

The direction is unambiguous: reusable, privacy-preserving age credentials, issued once and presented anywhere, on open protocols. Platforms that integrate that stack now aren't betting on a prediction. They're adopting the architecture the EU has already published.

Where OpenKYC fits

OpenKYC is building a reusable KYC marketplace on open standards (W3C Verifiable Credentials, OpenID4VC): verify once, hold the credential in your own wallet, reuse it everywhere, and earn every time it's used. Join the waitlist at openkyc.org.

This article is general information, not legal advice.

Verify once. Use everywhere. Earn every time.

OpenKYC is building the reusable KYC marketplace on open identity standards. Be first in line.

Join the waitlist