On 1 January 2027, France will verify the identity of all its adults
The law passed on 21 July bans social media for under-fifteens. To enforce it, it requires forty million adults to prove their identity before they can speak. Only one of the two measures was debated; it is the other that will remain.

The Katiba des Narvalos is a non-partisan collective of anonymous citizens that has tracked jihadist propaganda online for a decade: mapping and reporting accounts, counter-propaganda, and above all infiltrating cyber-jihadist networks. That last activity, the most useful of all, rests on a single non-negotiable condition, that no one on the other side can link a pseudonym to a name, an address, a family.
From 1 January 2027, each of its members will have to prove their identity to keep their accounts.
The problem is not only that they will stop. It is that there will then exist, somewhere at a technical provider, a file linking civil identities to infiltration accounts. That is, exactly what the infiltrated organisations have been looking for over ten years, gathered for them in one place.
In October 2025, roughly 70,000 photos of ID documents collected by Discord for age verification leaked, not from Discord but from its customer-support subcontractor. They came not from sign-ups but from appeals filed by users the system had wrongly classified as minors. The breaking point is never the front door, it is the complaints desk.
The Katiba is only the clearest case. The same reasoning applies to the employee documenting fraud from inside their company, to a journalist's source, to the person who has moved city so as not to be found. None of these uses belongs to a political camp. None survives a duty to identify.
Parliament voted this obligation on Tuesday evening, by a large majority, at the end of a debate devoted almost entirely to teenagers.
What the law of 21 July 2026 actually provides
On Tuesday 21 July 2026, Parliament gave final approval to the bill brought by MP Laure Miller banning access to social media for minors under fifteen. The Senate passed it by 243 votes to 2, with 100 abstentions. The National Assembly followed a few hours later, 279 votes to 81. The adopted text comes out of a compromise reached the previous day in a joint committee, in a little over two hours, behind closed doors.
Two dates. On 1 September 2026, no account may any longer be created by a minor under fifteen. On 1 January 2027, the ban extends to accounts that already exist. The four months separating the two deadlines are for the platforms to run an age-verification campaign across all their users.
The text also bans mobile phones from high schools starting with the 2026-2027 school year.
The scope covers online social media services, with no size threshold or audience condition, with a few exceptions including online encyclopaedias. A Mastodon instance run by three volunteers falls under the same regime as TikTok.
The Socialist MPs announced a referral to the Constitutional Council, which has one month.
Why age verification concerns all adults, not just minors
There are two provisions in this law, and only one was debated.
The first bans under-fifteens from opening an account. The second follows mechanically: it forces everyone to prove their age, because you do not keep a minor out without checking the adult. The law does not hide it, since the four months granted to the platforms are there to run the entire base through the sieve. Not the suspicious accounts. All accounts.
Parliament did not vote an age restriction. It voted the installation of an identity-attestation layer in front of public speech, for the entire population.
MP Louis Boyard said it in the chamber: the purpose of the text is to impose identity verification on the whole population. He was told he was talking nonsense. It remains to be explained how you establish that forty million adults are of age without asking them to prove it.
How will the platforms verify age and identity?
The law does not decide. It sets the obligation and refers the details to the decree and to Arcom's framework.
Neither exists. The only age-verification framework available is the one from the SREN law, written for pornographic sites. MP Arthur Delaporte flagged it on Tuesday evening in the chamber: the control procedures are not settled one month before entry into force. No one contradicted him.
Parliament voted an obligation whose method of execution is still to be written, with a deadline six weeks away.
The genuinely available methods can be counted on one hand. The photo of an ID document sent to a third-party verifier, with liveness detection. State digital identity, in France the France Identité app, which reads the chip of the national ID card. Biometric face estimation, which the CNIL ruled out for tobacconists and which a pencil stroke drawing a moustache was enough to fool in the Australian tests. Attestation by the telecom operator, based on the plan subscribed in an adult's name. And from the end of 2026, the European digital identity wallet.
Four out of five run through an ID document or through the state. The fifth does not hold up technically and will drop out as soon as the reliability requirement rises. There is no sixth path.
No platform will have forty million people scan an ID document in four months. They will start with inference on the signals they already hold: account age, past declarations, social graph, device, behaviour. Then they will escalate to documentary verification for accounts classified as minors and for those who contest that classification.
So the collection of ID documents will concentrate on the misclassified users, that is, on the atypical accounts: recent, quiet, with no identifiable social graph. The investigation accounts.
Does Arcom's "double anonymity" really protect you?
The platform does not know your identity, the verifier does not know which service you are accessing. The term was coined on the government side from 2023, taken up by the CNIL in a technical study, then written by Arcom into its framework.
Double anonymity produces no anonymity. It produces a separation between two actors, and a separation is an implementation promise. It holds if the architecture is correctly designed, correctly deployed and correctly audited, and it stops holding the moment any one of those three links gives way.
In 2025, AI Forensics showed that AgeGo, a verification provider for many pornographic sites, was collecting the full URL of the video being viewed. The promised separation was a box ticked in a compliance document.
Beneath the separation, whatever its quality, an identity check remains. You do not prove your age, you prove who you are, to someone, before you have the right to speak. The word "anonymity" was chosen to make you forget that sentence.
What identity verification actually destroys
Public debate treats online anonymity as a convenience, sometimes as a vice. For a number of activities it is an operational requirement, on the same footing as the protection of a journalist's sources or the cover of an undercover agent.
Infiltrating a propaganda network requires an account that traces back to no one. The day that account is tied to a civil identity stored at a provider, the activity stops, and not only because the person gives it up. The file itself becomes a very high-value target for the adversary.
The employee documenting fraud from inside their company will not do it from an identified account. The domestic-violence victim who has moved to another department will not keep a profile tied to their civil status. The civil servant who raises the alarm about a malfunction, the doctor who testifies about a practice, the former member of a cult who warns the next ones, all depend on the same condition.
None of these uses is right-wing or left-wing. They form the informal infrastructure by which a society learns what the official channels do not report.
Why I defend anonymity even though I have no use for it
I work under my own name. My face is on my talks, my analyses are signed, my clients have my number, my business address is public. I have no anonymous account, I never have, and I will probably never need one. My position protects me, my profession protects me, and what I write costs me no more than a polite disagreement.
That is precisely why I defend it.
A right is not judged from the situation of those who have no use for it. I do not need legal aid, which gives me no authority to abolish it. "I have nothing to hide, so no one needs to hide" is the shortest path to a society where only those who risk nothing speak.
What I defend is not anonymity as a way of life, but its possibility as a condition of debate. A society where everyone is anonymous is ungovernable. A society where no one can be anonymous any longer hears only the channels that have an interest in speaking.
The balance between the two is being removed without having been discussed.
Does age verification really protect minors?
Australia has applied a ban on under-sixteens since 10 December 2025. The government claims more than five million accounts deleted, deactivated or restricted. The figure was cited heavily in France during the debates.
A peer-reviewed evaluation, published in June 2026 in the British Medical Journal, followed more than four hundred children before entry into force and then three months after: insufficient evidence of a marked drop in use, substantial circumvention. A survey by the Australian regulator found that seven parents out of ten reported their teenagers still present on the targeted platforms. The Australian government responded in June 2026 with a text doubling the maximum penalties, around 99 million Australian dollars.
Five million accounts processed, use unchanged. An indicator that rises, a risk that does not move.
This is what I call the green dashboard: the organisation hits its metrics, no one asks any more questions, and the real fragility remains intact beneath the indicators. Except that here, the price of the green dashboard is a permanent identification infrastructure.
The most vulnerable minors will be the first excluded: those without papers, those whose documents do not match their appearance, those with no one at home to handle an appeal. The others will carry on as before.
The European timeline for digital identity
The eIDAS 2 regulation requires each member state to make at least one digital identity wallet available before the end of December 2026. The very large platforms will have to accept it as a means of identification from 2027. The Commission is aiming for 80% of European citizens equipped with a digital identity solution by 2030.
The Commission published a first technical model for age verification on 14 July 2025, then a second on 10 October 2025, nicknamed the mini wallet, integrating enrolment by passport and ID card. This second model is built on the same technical specifications as the European wallet, to allow its later integration. It is written on the Commission's website.
On 10 October 2025, in Horsens, the digital ministers of twenty-seven European countries signed the Jutland declaration, which calls for a clear European legal requirement of age verification. The Danish digital minister there demanded digital gatekeepers to stop children from entering before the age. In November 2025, the European Parliament voted by 483 to 92 a resolution in favour of a harmonised digital age of majority. The expert report handed to the President of the Commission recommends a ban under thirteen and progressive access thereafter. The roadmap arrives at the end of summer 2026.
Line up the dates. Mini wallet built on the specifications of the European wallet. Wallet mandatory in the twenty-seven states by the end of 2026. Mandatory acceptance by the large platforms in 2027. Verification of every French account on 1 January 2027.
Each brick was announced separately, justified separately, voted separately. No consolidated impact assessment exists over the whole. You do not need a secret plan to obtain an architecture: a series of decisions each presentable in isolation, none of which is reversible, is enough.
On 15 April 2026, the President of the Commission presented the European age-verification app, insisting on its fully open character. The next day, a security consultant published a bypass demonstration in under two minutes: a PIN code stored in an editable configuration file, a resettable attempt counter, biometric authentication disableable by a boolean. The public code repository carried a warning stating that the version was not recommended for a real-world deployment. That warning was on the code. It was not in the political announcement.
Chat Control: the method
On 26 March 2026, the European Parliament refused to extend the derogation allowing platforms to scan private messages. The regime expired in early April. A real victory, wrested after months of mobilisation.
On 2 July, the Council adopted the text as its second-reading position, which changed all the arithmetic: at second reading, rejecting requires an absolute majority of members, 361 votes out of 720. On 7 July, an urgency procedure passed by 331 votes to 304. On 9 July, the last day before recess, the rejection motion gathered 314 votes to 276. A majority of those voting said no. It took 361.
A text rejected by a majority applies until April 2028, because that rejection did not clear a procedural threshold, thanks to a timetable that emptied the chamber. The permanent regulation, the one that would make detection mandatory right down to encrypted messaging, comes back into negotiation in September.
Neither conspiracy nor coup. Patience, rules of procedure, and a month of July.
After social media, VPNs
On 30 January 2026, on Franceinfo, the deputy minister for digital affairs declared that VPNs were among her next priority subjects. In the United Kingdom, the House of Lords has already voted an amendment subjecting access to VPNs to age verification. Since the Online Safety Act came into force in the summer of 2025, whole swathes of the British web have moved behind a wall of identification, with blocks that hit documentary content on Gaza and on Ukraine. In the United States, half the states impose age verification on adult content.
You install a wall, people get around it, you close the way around. Each closure is justified by the failure of the previous one. No one needs to announce the final objective. It is enough never to go back.
Fifteen weeks before the presidential election
The first round is set for 18 April 2027. The verification of every existing account falls on 1 January. Between the two, fifteen weeks.
An identity check placed at the entrance of a service always produces drop-off, and never at random. Those who fall away are the ones whose papers have expired, the ones who do not understand why they are being asked for a selfie, the ones with no one to contest a refusal. Exactly the same people who already get their news from television and radio.
Across tens of millions of accounts, a few points of attrition remove hundreds of thousands of voters from the primary political news channel of the under-thirty-fives, just as the campaign starts.
They will not stop getting informed. They will switch to a landscape whose ownership fits in five names: Bolloré, Niel, Arnault, Kretinsky, Saadé.
And the authority that controls speaking time on television during the campaign is the one that will write the technical framework closing off access to the rival channel. Arcom on both sides.
No impact assessment measured this effect. The Council of State did not raise it, the joint committee did not discuss it, no one put it in the chamber. A predictable, quantifiable effect, and not a line to look at it.
The age verifier, an unsupervised critical third party
This law creates a new category of actor. From 1 January 2027, the availability of the age verifier conditions the access of tens of millions of people to the space of public discussion. Its compromise exposes a database of correspondences between civil identities and online activity. Its failure, even temporary, produces an unavailability of public speech.
No supervision regime matches this function.
These providers will fall into heterogeneous boxes depending on the status they adopt. Those who issue qualified electronic attestations of attributes under eIDAS 2 will be trust service providers, therefore entities falling under NIS2 as digital infrastructure, with risk-management and incident-notification obligations. The others, mere processors in the sense of the GDPR, will have neither a NIS2 notification obligation, nor supervised certification, nor sectoral oversight. Two providers performing the same critical function, two regimes with nothing in common.
DORA settled this problem for the financial sector by creating a critical-third-party status placed under direct supervision, because the concentration of risk at a handful of suppliers made contractual control insufficient. Nothing equivalent here, even though the systemic dependency is of the same order and the exposed asset is far more sensitive than a payment flow.
It is a design flaw a decree can fix, provided someone formulates it before 1 September and not after the first incident.
What remains open
The Council of State, in its opinion of 14 January 2026, judged the general ban disproportionate under European law and recommended targeted measures by decree. The European Commission held on 7 July 2026 that certain provisions of the text breached the regulation on digital services, which forced MPs to rewrite in a hurry.
Article 28(3) of the DSA provides in black and white that platform providers are not required to process additional personal data to determine whether a user is a minor. An age-verification obligation does the opposite. The legal basis invoked by Paris and by Brussels contradicts the text it invokes.
In a case pending before the Court of Justice of the European Union concerning the age verification imposed by the SREN law, the advocate general cast doubt on the compliance of the French scheme with Union law, on the grounds that platform regulation is in principle a matter for the European level.
The Constitutional Council has been referred and has one month. The implementing decree and Arcom's framework remain to be written. That is where the rest is decided.
Three requirements, without giving an inch on the protection of minors. That verification providers be qualified as critical third parties, with supervised certification, mandatory incident notification and published separation audits. That the scheme come with a sunset clause and an independent evaluation, the history of Chat Control showing well enough what a temporary regime becomes when no one sets its term. That the identity layer stop being treated as an execution detail left to the decree, when it is the only part of the text whose effects will fall on the entire population.
The real debate, the one about interoperability imposed on platforms, about the advertising model, about the retention mechanics designed to capture teenagers, did not take place. It was replaced with an ID card.
On 1 September, a fourteen-year-old will no longer be able to open an account. On 1 January, tens of millions of adults will have to prove who they are to keep theirs. Only the first sentence was debated. It is the second that will remain.
Sources
- Final adoption, content of the text and parliamentary debates: LCP, franceinfo and Touteleurope, 21 July 2026.
- Council of State opinion of 14 January 2026 and European Commission position of 7 July 2026: Touteleurope.
- Double anonymity, scope, Article 28 of the DSA and the case pending before the CJEU: La Quadrature du Net, 21 May 2026.
- Technical age-verification models of 14 July and 10 October 2025: European Commission, page on the European approach to age verification.
- eIDAS 2 Regulation (EU) 2024/1183, end-of-December-2026 deadline for member states.
- Jutland declaration, 10 October 2025, Danish presidency of the Council of the European Union.
- European Parliament resolution on the protection of minors online, November 2025.
- European age-verification app and vulnerabilities demonstrated on 15 and 16 April 2026: Politico, Cybernews, TechPolicy.Press.
- Chat Control, votes of 26 March, 7 July and 9 July 2026: Euronews, 10 July 2026, and European Parliament releases.
- Australian assessment: British Medical Journal, June 2026; eSafety Commissioner; Al Jazeera, 27 June 2026.
- Discord incident: official Discord statements of 3 and 8 October 2025.
- Katiba des Narvalos: press coverage in France Info, Le Parisien, StreetPress, L'Obs.
- Statement on VPNs: Anne Le Hénanff, Franceinfo, 30 January 2026.
Frequently asked questions
When does the law come into force?
On 1 September 2026 for the creation of new accounts, and on 1 January 2027 for accounts that already exist. The text still has to clear review by the Constitutional Council, referred by Socialist MPs, which has one month to rule.
Will I have to send my ID card to keep my account?
The law does not say so explicitly. It sets an age-verification obligation and leaves the details to a decree and to Arcom's framework, neither of which has been published to date. The genuinely reliable methods rely on an ID document, on the state digital identity or, eventually, on the European digital identity wallet.
Does double anonymity protect my data?
It ensures a separation between the platform and the third-party verifier, which is not anonymity. That watertightness depends entirely on the quality of the implementation, and failures have already been documented at age-verification providers.
Which platforms are affected?
Online social media services, with no size threshold, with some exceptions including online encyclopaedias. The precise list will depend on the decree taken after Arcom's opinion.
Can a VPN get around age verification?
Using a VPN remains legal in France for adults. VPN circumvention is the main failure factor observed in Australia, and the French government indicated as early as January 2026 that regulating VPNs was among its priorities.
What is the connection with the 2027 presidential election?
The verification of all existing accounts happens on 1 January 2027, fifteen weeks before the first round set for 18 April. No impact assessment has examined the effect of this timeline on access to information during a campaign.
Can the law still be struck down?
Three routes remain open: the Constitutional Council's decision, compliance with the European Digital Services Act, and a case pending before the Court of Justice of the European Union on the age verification introduced by the SREN law.

Être en cybersécurité
A cyber roadmap in plain language, for everyone, not just the experts.
