
When 'age assurance' becomes surveillance, our children pay the price
The technology proposed to keep children safe online risks becoming a form of surveillance in disguise, a permanent identity layer that outlasts the childhood it was meant to protect.
I talk to parents, educators, and tech teams every week. There''s a common theme: we all want children to be safe and to thrive in digital spaces. That instinct to protect is good. It is human. It is right. But intention isn''t the same as impact.
Increasingly, the technology being proposed to keep children safe online, especially age assurance and age verification systems, runs the risk of becoming a form of surveillance in disguise. At first it sounds reasonable: prove you are old enough to be online, prevent access to adult content, or restrict data collection for younger users. But what we are building today could become a permanent identity layer on our children''s lives, and the long-term consequences of that are enormous, both for security and for civil liberties.
I call this the surveillance spiral. Something that begins as safety infrastructure slowly becomes an identity infrastructure so pervasive that children''s digital and physical lives are tracked longer and more deeply than we ever intended.
There''s a serious difference between protecting children and profiling children. Age assurance as it is often implemented today walks that line poorly. Many systems use biometric checks, device fingerprints, behavioural heuristics, or third-party identity providers to make inferences about a user''s age. These systems accumulate identifiers long before we, as adults, even notice.
This accumulation of data is not inherently malicious. But it inevitably forms an identity graph that feels a lot like surveillance, especially when that data is reused, combined, or shared across services. One day it''s ''prove your age to watch a video'', and the next it''s an age-verified record that travels across platforms, tied to everything the child does online. What we ultimately end up with isn''t just age assurance. It is an ongoing digital identity anchor. It follows the child into social spaces, into services, into products, into behaviour profiles that persist through adolescence, adulthood, and potentially for life.
From a security standpoint alone, this is a ticking time bomb. Identity data is high value on the open market. It anchors behavioural profiles. It supports targeted abuse. It becomes a key that unlocks far more than age-gated content. Every database holding age assurance records is a liability, a target for attackers who know that children''s identity and behaviour data is among the most sensitive and most harmful to leak or manipulate. That''s not opinion. That''s what evidence shows about the value of identity data in cybercrime economies.
From a civil liberties perspective, the implications are equally profound. Children grow and change. Their identities are meant to be explorative and fluid, not fixed forever by a verification record created when they were six or ten or twelve. When a system stores age verification as an identity assertion, even if designed for safety, it becomes a lens through which every future decision is made. What content they see, how their data is processed, who can reach them, and what assumptions algorithms make about them.
In Australia we''re already heading in this direction with debates about age assurance, digital identity frameworks, and emerging privacy reforms. The intent of those reforms is noble: protect children, empower parents, and reduce harm. But we have to be vigilant that safety does not become surveillance by default.
I want to be clear about something: protecting children does not mean tracking them everywhere they go online. True protection means minimising data footprint, decentralising identity, and designing systems that preserve autonomy and dignity. It means asking harder questions about whether we really need persistent identity, or whether we can achieve safety with less, not more, data.
When we conflate age verification with identity tracking, we set up a digital architecture that prioritises control over consent, and accumulation over minimised risk. That architecture is not just a security risk; it fundamentally shapes how children see themselves in relation to technology and the world.
We have to resist the easy path where safety is delivered by building bigger digital surveillance nets. Because once those nets are woven into essential infrastructure, into schools, into social platforms, into government services, they are almost impossible to remove without cost, disruption, and harm.
We can, and must, do better. We can design for age-appropriate experiences without turning age assurance into an identity anchor that outlasts the childhood it was meant to protect. We can build tools that respect privacy, limit data retention, and don''t convert safety into lifelong surveillance.
If we don''t, we risk giving our children a digital record they never asked for, never understood, and never should have had to carry.
They deserve freedom and safety. Not a system that watches them forever.
Free CyberSafety training for every Australian family
Video lessons, downloadable guides and completion certificates — all free, forever.
Start free training