The Correct Term for “Age Verification” is “Censorship”
A bill was introduced last month in the Senate that would “require operating system providers to require users to indicate their age and developers of applications, covered internet website operators, and browser providers to request a signal from operating system providers that indicates a user’s age.”
The bill basically covers every device under the sun with an OS, and defines a provider as “a person that develops, licenses, or controls the operating system software on a covered device.” And these providers would need to design their OS such that a user would need to set up an account and provide their age and date of birth. A user under the age of seventeen would need to have a linked guardian account. From there, the provider would need to supply a signal (containing an age bracket of the user) to app, website, and browser providers who are already legally required to know a user’s age.
The bill has no exemption for open-source developers, meaning developers of an OS like Linux would need to implement the mechanisms for a user to create an account and provide their age, and be capable of supplying that information to apps, websites, and browsers. As it exists today, Linux is publicly available for download by anyone. A user installs it offline on their local device and has no association with the community of independent developers that maintain the software.
But this bill would change all of that. If it passes, open-source developers would need to transition from merely contributing to a public project to collecting users’ information and administering a system that conditions access to general-purpose software on the basis of their age, unless they link a guardian account.
There are, of course, privacy concerns here and the bill encourages the use of evolving privacy-preserving technologies, like zero-knowledge proofs and verifiable credentials, when sending signals to apps, websites, and browsers. But let’s be clear, despite any privacy protections or procedures, this is still gatekeeping open-source software and the internet based on a government-approved personal attribute. Today it is age, tomorrow it is (fill in the blank). We don’t need to consider what age verification would look like with proper privacy protections because it shouldn’t be required for the use of publicly available tools or infrastructure at all.
And we know the rebuttal here: the age verification movement has a history of being promoted around the world as a necessary protection for children. The European Union has especially been pushing for it, as well as the United Kingdom under this very premise. This bill is no different. But we’re here to set the record straight: age verification is censorship. Full stop. It is the very mechanism necessary for a government to keep a watch of their citizens’ use of certain software and their online presence, and then decide who can access information or share their ideas and who cannot.
At the moment, the bill only requires that users “indicate” their age and date of birth. This is likely different from full on verification with government-issued documents. However, in the event that the OS provider “receives clear and convincing information” that contradicts what the user has indicated, then the provider must “verify” their age. “Verify” is quite an escalation from “indicate.” The bill doesn’t clarify what age verification would be required of the provider here, but such a broad claim could lead a provider to do more than necessary in order to comply with the law.
Just look at the UK’s model, which requires an age assurance process to be “highly effective” at determining if a user is a child. The regulation provides methods that may be capable of doing so (even without documentation), but such broad requirements have led platforms to conduct traditional verification methods of requiring documentation in order to be “highly effective.” Why risk non-compliance?
In any case, the mere enactment of this bill would enter us into the realm of requiring a government-approved personal attribute in order to use an open-source OS or to generally access the internet.
This also raises First Amendment concerns. Open-source developers are merely publishing code that users can run locally and independently on their computers. In other words, open-source code is a set of publicly available instructions for people to use to conduct their own activities with the tools at their disposal—no different than a recipe for cooking or a music sheet for performing a symphony.
So, by requiring age verification mechanisms in the OS, the federal government is having open-source developers write or rewrite their protected speech in a manner the government finds favorable. The Supreme Court has defined this as “compelled speech” and ruled that it is outright unconstitutional.
You can read all about this in Peter and I’s First Amendment report. We focus on blockchain node clients, smart contracts, and user interfaces, but the premise broadly applies to open-source software.
All that said, this bill is disastrous. In the 1990s, internet activist and Grateful Dead lyricist (big fan) John Perry Barlow wrote A Declaration of the Independence of Cyberspace. Here, he made it clear that the internet was being built so that “all may enter without privilege or prejudice accorded by race, economic power, military force, or station of birth,” where we can live in “a world where anyone may express his or her beliefs, no matter how singular, without fear of being coerced into silence or conformity.”
The world that Barlow dreamed of has always been threatened by governments and large corporations, but internet activists have fought alongside open-source developers and cryptographers to hold the line. This is yet another battle in this long, drawn out war over privacy and speech, and we are again called to act. Let us proceed apace. -Laz
Does the first amendment protect viruses? or open-weight models?
When does publishing code become something the government can treat as conduct? A conversation with an expert from encrypted corners of the internet. Participants anonymized and lightly edited.
Q: You’ve spilled much ink on how the lower court rulings on software as speech go against SCOTUS rulings on software as speech. Do you believe, in the current gestalt, that someone writing a virus (but not using it) would be protected at the Supreme Court level?
A: Virus software is a great way to test these theories because it has almost no non-criminal uses apart from security research to defend against viruses.
Your hypothetical is a little vague. Why did this person write a virus?
If it was as part of a proven criminal scheme to infiltrate someone else’s computer, then there’s a strong argument that the speech was integral to the illegal act and therefore gets no protection.
A harder hypothetical would be a security researcher who publishes virus code to study and improve anti-virus techniques. There the “integral to crime” claim doesn’t work because you can’t prove any criminal intent or act, just publication.
That’s actually pretty close to the Tornado Cash debate. The question isn’t whether software can facilitate crime. It’s whether publishing software makes you part of the crime.
Q: This could be exactly the kind of case we end up with if there’s an attempt to prevent the spread of open-weight AI models on the grounds that they can be used in hacking.
A: Maybe. But one of the biggest differences between open-weight models and frontier models right now is that the open models still allow you to do security research. It’s a very bad-faith argument that the only reason someone would want an open-weight model is for hacking.
Q: The positive use cases for open models are just so massively obvious and voluminous.
A: I could still see lower courts ruling against them. They might say the software is simply too functional, or not expressive enough, to warrant robust First Amendment protection. But I think the Supreme Court would be much more likely to reject that reasoning. Cases like United States v. Stevens suggest that usefulness, or even the potential for harm, is not itself a reason to deny strong First Amendment protection to speech. The remedy is to punish criminal conduct, not publication.
It looks like we could have a pretty live fight over free speech for open-weight model distribution soon
Peter wrote a guest thread for the Ethereum Foundation on the need for infrastructure blindness for true neutrality. The ability to see flows will inevitably become pressure to influence flows. Only privacy enables a neutral stack.
What else we’re reading
If AI Outputs Aren’t Speech, Who Has to Prove They’re Human? - If AI output is not protected speech, platforms have to sort protected human speech from unprotected machine speech at scale. Anthropic’s watermarking technology could help here, but it’s hard not to see how this leads to more KYC.
CBP Workers Allegedly Used Government Databases to Spy on Exes, Crushes, and Colleagues - This and the Flock incidents are showing us what happens when powerful surveillance tools are put into the hands of average joe cops. They can’t resist taking a little peek.
Thanks for taking the time to read this far. If you found this issue useful or insightful, please consider sharing it. We are trying to grow this thing and would be grateful for your help!
















