EU Age Verification Project Sparks Backlash Over Mandatory Hardware Ties
Critics warn that requiring hardware-bound attestation grants tech giants gatekeeping power over digital identity.
The European Union's open-source age-verification project has ignited controversy among privacy advocates and developers after maintainers confirmed that hardware-bound attestation is a mandatory architectural requirement. The move has sparked fears that the system will exclude users of non-standard hardware and custom software.
According to project documentation, the system requires digital credentials to be tied to protected hardware, such as Apple's Secure Enclave or Android's StrongBox and Trusted Execution Environment (TEE). This design is intended to prevent the cloning or unauthorized reuse of credentials. Furthermore, Proof of Age providers are expected to issue these credentials only to applications that appear on a compliant list maintained by the European Commission.
The Trust Gap
The EU is developing this digital identity framework to allow citizens to verify their age for online services—such as gambling or adult content—without revealing their full identity or exact birth date. While the project is open-source, the reliance on hardware-level security shifts the root of trust from the transparent code to the hardware manufacturers and operating system providers.
Project maintainers have pushed back against suggestions to make these security measures optional. "Hardware-bound attestation is a requirement of this project, not an implementation detail we can simply drop," a project maintainer stated.
Implications for Digital Sovereignty
This architectural choice creates a fundamental tension between the EU's stated goal of an open-source identity system and the reality of hardware monopolies. By mandating attestation, the EU effectively grants companies like Google and Apple the power to determine who can access the system.
Industry critics argue this creates a systemic exclusion of users who prioritize digital sovereignty, including those using "de-Googled" phones, custom Android ROMs, or Linux-based systems. Because these devices often cannot provide the specific hardware attestation required by the European Commission's compliant list, their users may be locked out of the verification ecosystem entirely.
What's Next
As the project progresses, the primary point of contention remains whether a truly open-source identity framework can exist while relying on proprietary hardware silos. Observers are now watching to see if the European Commission will expand its list of compliant applications or if the project will maintain its strict hardware requirements, potentially cementing the role of big tech as the ultimate arbiters of digital identity in Europe.