Digital ID Laws and the End of Online Anonymity [2026]
Age verification mandates have spread to more than 25 US states, the Supreme Court has upheld them, and device-level age signals are being written into operating systems. This guide separates the anonymity you have already lost from the anonymity you still control — and shows how to strip identifying detail out of video before you publish it.

For most of the internet's history, the default was that you could read, watch, and publish without proving who you were. That default is being dismantled, quickly and from several directions at once. More than 25 US states now require some form of age verification before you reach large categories of online content. The Supreme Court has held that at least one version of the mandate is constitutional. Two states have written age signals directly into the operating system layer, which means the check will eventually happen on the device rather than the website. And an investigation published in August 2026 argues that a coordinated set of foreign-funded advocacy groups helped export the British regulatory model into American statehouses.
Whatever you make of the politics, the practical question for anyone who publishes video is narrower and more answerable: which parts of your anonymity are actually gone, and which parts do you still control? The answer is sharper than the general gloom suggests. Account-level anonymity is genuinely eroding. Publication-level anonymity — control over whose face, plate, address, and voice appear in the footage you upload — is still entirely yours, still entirely legal, and takes about three minutes to exercise.
| Question | Answer |
|---|---|
| How many US states require age verification? | 25+ for online sexual material, plus a separate wave of social media design laws |
| Is it constitutional? | Yes for adult-content mandates — Free Speech Coalition v. Paxton, 6-3, June 27, 2025 |
| Do I have to upload my ID? | Depends on the model: document-based (Texas HB 1181) yes; device-level (California AB 1043, Illinois HB 5511) no |
| When do device-level laws bite? | California January 1, 2027; Illinois OS signal January 1, 2028, apps July 1, 2028 |
| Illinois penalty? | Up to $50,000 per violation, enforced by the state Attorney General |
| Are VPNs banned? | No — the UK explicitly declined to age-gate or ban them in July 2026 |
| What can you still control? | Publication-level anonymity — whose face, plate, and voice appear in what you upload |
| Does BGBlur touch age verification? | No. It protects the people in your footage, a separate and unregulated layer |
Who Is Actually Writing America's Age Verification Laws?
The honest answer is that it is a mix of domestic and foreign actors, and the domestic side is larger than the recent coverage implies. An investigation published by Effort News in August 2026 traces five foreign NGOs and their US affiliates promoting age verification and digital ID legislation across 21 states and Congress, arguing that they converged on child-safety framing to advance identity mandates. Its central documented claim is well supported by public records: the 5Rights Foundation, founded by Baroness Beeban Kidron of the House of Lords, registered under the Foreign Agents Registration Act and disclosed paid lobbying in California on AB 2273, the Age-Appropriate Design Code Act that the bill's own authors described as drawing on the UK model.
That much is verifiable. It is also incomplete as a theory of what happened. Texas HB 1181 — the law that produced the Supreme Court ruling and the template many states copied — was driven by Texas legislators and domestic advocacy, not by a British NGO. Meta has spent heavily backing parent-facing groups that push device-level and app-store-level verification, which conveniently relocates the compliance burden away from platforms. Several of the strongest age-verification pushes are homegrown, and the trade association of age-verification vendors has an obvious commercial stake in every mandate that passes.
So the useful framing is not "a foreign plot" versus "a grassroots movement." It is that a British legislative template, a US constitutional green light, a genuine wave of parental frustration, and a vendor industry with revenue on the line all pointed in the same direction at the same time. The result is the fastest expansion of internet identity requirements in the medium's history, and it is bipartisan enough that no election result is likely to reverse it.
Are Age Verification Laws Now Law in Most US States?
Roughly half of them, yes. At least 25 states have enacted statutes requiring age verification before users can access online sexual material, with nine of those passing in 2025 alone — South Carolina, Florida, Tennessee, Georgia, Wyoming, North Dakota, Arizona, Ohio, and Missouri. Additional provisions took effect through 2026, and a second category of law targeting social media design and minors' accounts is moving in parallel.
The verification methods the statutes accept vary more than most coverage suggests:
| Model | Example | What you hand over | Where the data sits |
|---|---|---|---|
| Document-based | Texas HB 1181 | Government ID scan or selfie | Third-party vendor database |
| Transactional | Louisiana, Arkansas | Credit or commercial-record lookup | Data broker |
| Facial age estimation | Widely deployed under UK OSA | A face scan, usually not retained | Vendor, ideally ephemeral |
| Device-level signal | California AB 1043, Illinois HB 5511 | A birth date at device setup | Operating system, bracket only |
These are meaningfully different in privacy terms, and lumping them together is the single most common analytical mistake in this debate. A device-level age bracket passed from your operating system to an app is not the same thing as uploading your passport to a website. It is worth knowing which one a given law actually requires before deciding how alarmed to be — a distinction we also draw out in our guide to what "digitally anonymized" actually means.
Do These Laws Mean I Have to Upload My Government ID?
Sometimes, and increasingly less often. The newest wave of legislation deliberately avoids document collection. California's AB 1043, the Digital Age Assurance Act, signed in October 2025 and effective January 1, 2027, requires operating system providers to collect an age at account setup and transmit only a bracket — under 13, 13 to under 16, 16 to under 18, or 18 and over — to apps that request it. No ID scan, no document, no photo.
Illinois went further in the same direction. HB 5511, the Children's Online Social Media Safety Act, passed unanimously in both chambers in June 2026 and was signed on July 31, 2026. It requires OS providers to expose an age-signal interface at device setup by January 1, 2028, transmit the signal encrypted, and have covered apps consume it by July 1, 2028, with penalties up to $50,000 per violation. Once an account is flagged as a minor, feeds are restricted, profiles are hidden from adult strangers, precise location is masked, and notifications go dark overnight.
Critics of this model are not wrong to be uneasy, and the reason is structural rather than immediate. A self-declared birth date is trivially falsifiable, which means the mandate as written does very little unless it is eventually backed by something harder. Every OS-level age field is, in that sense, infrastructure waiting for a validity requirement. Nothing in the current statutes requires ID-backed attestation. Nothing in them prevents a later amendment from adding it either.
What Happens to My ID After I Upload It?

It joins a database that someone will eventually try to steal, and the track record here is not theoretical. In October 2025, Discord disclosed that roughly 70,000 users had government ID photos exposed after attackers compromised a third-party customer support vendor and retained access for about 58 hours. Those were images of people holding their passport or driver's licence next to their face — the exact artifact that document-based age verification produces at scale.
Months later, Discord announced a phased global rollout of mandatory age assurance anyway, prompting the EFF to point out the obvious tension in pushing ID collection immediately after leaking IDs. The Tea app breach in July 2025 followed the same pattern from a different direction: an app built explicitly around women's safety leaked roughly 13,000 verification selfies and ID images, plus tens of thousands of other photos.
The pattern generalizes. Verification vendors are attractive targets precisely because a mandate concentrates high-value identity documents in a small number of intermediaries. We covered the downstream consequences of exactly this failure mode in our breakdown of the Nefos and PuffPal passport data breach, where leaked identity documents circulated long after the incident was nominally closed. An ID document, unlike a password, cannot be rotated after a breach.
Did the Supreme Court Say Age Verification Is Constitutional?
For one category of law, yes. In Free Speech Coalition, Inc. v. Paxton, decided 6-3 on June 27, 2025, the Court upheld Texas HB 1181, holding that its age-verification requirement for sites where more than one-third of content is sexual material harmful to minors "triggers, and survives, review under intermediate scrutiny because it only incidentally burdens the protected speech of adults." Justice Thomas wrote for the majority; Justices Kagan, Sotomayor, and Jackson dissented, arguing strict scrutiny should apply to a content-based burden on adults' access to protected speech.
That decision is the hinge. Before it, the main risk to any state age-verification statute was a First Amendment injunction. After it, that risk largely evaporated for the adult-content category, and the legislative floodgates opened.
Broader design-code laws have fared worse. California's AB 2273 — the 5Rights-influenced Age-Appropriate Design Code — has been in litigation since 2023, and in March 2026 the Ninth Circuit held that a majority of it was unconstitutional, finding terms like "materially detrimental," "best interests," and "well-being" impermissibly vague, while leaving some age-estimation and default-privacy obligations intact. The imported British model, in other words, has had a considerably rougher ride in American courts than the homegrown Texas one. That is a real limit on the export thesis worth holding onto.
Will VPNs Be Banned Next?
Not currently, though the question stopped being hypothetical in 2025. When UK age checks came into force on July 25, 2025 under the Online Safety Act, VPN demand exploded — Proton reported sustained daily signup increases of 1,400 to 1,800 percent, NordVPN reported a roughly 1,000 percent spike, and half of the top ten UK App Store downloads that day were VPN or identity apps. A meaningful share of British traffic simply stopped looking British.
Ofcom's statutory report on the use of age assurance, published in July 2026, found that more than 69 million age checks were completed across a sample of just 32 regulated services in the second half of 2025 — a 23-fold increase on the prior six months, and the regulator noted the true national total is likely materially higher. Exposure to non-self-declaration age assurance among UK users rose from 25 percent in July 2025 to 43 percent by January 2026.
Some advocates responded by arguing that circumvention tools should be closed off too. The UK government declined: on the eve of the Ofcom report, the Technology Secretary told Parliament the government "will therefore not age-gate or ban" VPNs, placing the burden on platforms to detect circumvention themselves. That is where things stand. We track the broader compliance picture in our Online Safety Act face blurring compliance guide and the related UK GDPR and Data Protection Act video privacy guide.
What Kind of Anonymity Can You Still Protect in 2026?

This is the question that actually has a useful answer, and it starts with splitting one word into two.
Account-level anonymity is your ability to reach content without a service knowing who you are. This is what age verification, digital ID, and device age signals attack directly. Realistically, in the categories these laws cover, it is receding and no personal workaround changes the law.
Publication-level anonymity is control over what identifying information leaves your hands when you upload something. Whose face is in your frame. Whose licence plate. Which house number. Which voice. This layer is untouched by every statute discussed above — and it is the layer that causes most concrete harm to real people, because it is the one that exposes bystanders who never consented to being in your video at all.
The asymmetry matters. A creator who cannot avoid an age check on a platform can still avoid publishing a neighbour's child, a stranger's face, a colleague's plate, or their own street address to an audience of millions. The regulatory conversation is fixated on the first layer. The second one is where you retain full agency, and where a few minutes of editing removes risk permanently.
Does Blurring Faces in Video Actually Protect Anyone's Identity?
Only if the blur is strong enough and consistent enough. This is where a lot of well-intentioned redaction fails. Light Gaussian blur and coarse mosaic can be partially reversed by de-pixelation techniques, and regulators have increasingly treated reversible obscuring as a failure to anonymize rather than a good-faith attempt — a problem we examined in detail in why weak blur fails GDPR.
Effective redaction has three properties:
✅ Sufficient strength
A heavy blur radius or a solid block, not a decorative softening. The test is whether a motivated person with an upscaling model could recover recognizable features — if the underlying structure of the face is still present in the pixels, it can often be brought back.
✅ Full-head coverage
Blur the head, not a tight crop of the eyes and nose. Hairline, jaw, ear shape, and profile silhouette are all identifying, and partial coverage leaves more than people expect. The same applies to plates: cover the entire plate, not just the characters.
✅ Every single frame
This is the failure that catches almost everyone editing manually. At 30 frames per second, a ten-second clip has 300 frames, and one frame where the subject turns and the blur lags is enough to undo the entire edit. Screenshots of exactly those frames are how "anonymized" footage gets deanonymized. Motion tracking exists precisely to solve this, and it is the reason frame-by-frame keyframing in a general-purpose editor is the wrong tool for this job.
How to Strip Identifying Detail From a Video Before You Publish It
Step 1: Upload the clip
Open BGBlur's face blur tool in a browser — no app install, no account required to start. It accepts MP4, MOV, and M4V up to 4K. Processing happens client-side, and uploaded files are deleted within 24 hours with no permanent storage, which matters when the footage you are redacting is sensitive in the first place.
Step 2: Let detection find the subjects, then correct it
AI detection locates faces and license plates automatically and tracks each one across the timeline, so the blur follows a subject who turns, walks out of frame, and comes back. Review the tracked boxes rather than trusting them blindly: check the frames where someone enters or exits the shot, and where two people cross. If you need to obscure something detection does not cover — a house number, a name badge, a screen, a tattoo — select it by text prompt and it gets tracked the same way. Our step-by-step face blur walkthrough covers the interaction in more detail.
Step 3: Choose strength, then export
Pick a heavy blur or a solid block for anyone whose identity genuinely needs protecting; save the lighter settings for aesthetic background work, which is a different task with different stakes. Export to MP4, MOV, or WebM, then scrub the exported file once at speed before publishing. Ninety seconds of review catches the one bad frame.
If the footage contains children, apply the strictest setting available and read our guide on blurring kids' faces before posting first — that is the category where the legal exposure and the real-world harm are both highest, and where the G7's 2026 child safety roadmap is pushing platform obligations hardest.
Who Needs Publication-Level Anonymity Most
Journalists and documentary makers: Sources, bystanders, and protest participants can face real consequences from a recognizable frame. Redaction at the edit stage is the only reliable protection, since publication is irreversible.
Vloggers and street creators: Anyone filming in public captures dozens of non-consenting people per minute. Most jurisdictions do not require consent to film in public, but publishing is a separate question — see is it illegal to show faces in YouTube videos without consent.
Dashcam and fleet operators: Incident footage is often shared with insurers, police, or online. Plates and faces of uninvolved drivers should be blurred before the file leaves your control.
Parents posting family content: Other people's children appear in birthday parties, school events, and playground clips. Their parents did not consent.
Employers and educators: Training footage, classroom recordings, and workplace video routinely capture people whose employment or enrolment gives them no meaningful ability to refuse.
Pro Tips for Publishing Video in a Digital ID Era
- Redact before upload, not after. Once a platform has the original, deletion does not un-transmit it. Blur locally, upload the redacted version only.
- Treat audio as identifying too. A distinctive voice deanonymizes as effectively as a face. Voice anonymization belongs in the same pass as the blur.
- Strip metadata. GPS coordinates and device identifiers in EXIF and video container metadata undo a perfect visual redaction instantly.
- Assume upscaling improves. A blur strength that resists recovery today should have margin built in, because the models that attack it get better every year.
- Keep the unredacted original offline. If you need it for legal or archival reasons, store it locally, not in the same cloud account you publish from.
- Do not confuse the two layers. Nothing in your video file affects an age check, and no age check protects the people in your frame. Solve both separately or you will solve neither.
The Anonymity Worth Defending Is the One You Still Control
The expansion of digital ID and age verification requirements across more than 25 states, backed now by a Supreme Court decision and moving into the operating system layer, is a real and probably durable change in how the internet works. It came from a genuine mix of imported policy templates, domestic legislative energy, corporate liability-shifting, and parental frustration that no amount of arguing online is going to dissolve. Pretending otherwise, in either direction, does not help anyone decide what to do on a Tuesday afternoon.
What does help is separating what you have lost from what you have not. You may end up proving your age to reach a platform. You will never be required to publish a stranger's face, a child's face, a licence plate, or your own street to that platform — and every one of those exposures does more concrete damage to a real person than an age bracket ever will. Effective, motion-tracked, every-frame redaction remains fully legal, actively encouraged under GDPR and UK data protection law, and available in a browser in about three minutes.
The infrastructure of identity is being built around you. The footage you publish is still yours to control. Blur it with BGBlur before you post it.
Update — August 11, 2026: Identity infrastructure is also arriving through hardware, not just statute. For Meta's planned facial recognition in Ray-Ban and Oakley glasses and the 75-organization coalition opposing it, see smart glasses facial recognition and the ACLU backlash.