Cardano Foundation CEO Frederik Gregaard says the privacy dangers of age verification are no longer theoretical. In a CoinDesk opinion column, he argues they have been visible for years and are now becoming harder to ignore.
He points to a series of breaches to make the case. In 2024, identity verification provider AU10TIX, which served companies including TikTok and Uber, was found to have exposed drivers’ licenses to hackers for more than a year. In 2025, the provider handling age-verification systems for Discord was breached, potentially exposing government IDs belonging to 70,000 users. By 2026, Gregaard writes, the lesson should already be obvious: once age verification depends on vendors and stored identity data, a system built for safety can turn into a breach vector.
He also says AI is accelerating the problem, making attacks faster and the resulting damage easier to inflict.
The KIDS Act has moved to the Senate
Gregaard places that argument against the backdrop of new U.S. legislation. On June 29, the House passed the Kids Internet and Digital Safety Act, a broad package built around the Kids Online Safety Act, or KOSA, by a 267-117 vote.
The bill now sits in the Senate. According to the column, KOSA’s original authors, Democrat Richard Blumenthal and Republican Marsha Blackburn, strongly rejected the House version and are pressing for a tougher one. Part of that push involves tying the legislation to federal preemption of state AI laws. A Senate Commerce Committee markup is expected this month. Whatever comes out of that process, Gregaard writes, will shape how identity works online for years.
He says the aim is to protect minors. The danger, in his view, is that the mechanism used to do that could require a much larger surveillance apparatus than supporters openly acknowledge.
No explicit mandate can still produce verification
Gregaard argues that KIDS does not need to explicitly order age verification to make platforms adopt it. If companies can be held liable for harm to minors who access their services, the compliance math becomes simple: verify age or accept the legal risk that comes with not knowing who is a minor.
That means liability without a verification mandate can still lead to verification in practice. He says that point matters because the defense that there is “no explicit age check in the bill” may be technically correct while still missing how the incentive structure works in the real world.
Once disclosure becomes the cost of access, he writes, the collection dragnet tends to expand. A tool meant only to confirm that a user is old enough can become a tool for confirming who that user is. A database created to reduce liability can then become a liability of its own, another pool of identification data waiting for the next AU10TIX-style breach.
If all a platform needs is age, it should not demand full identity
The column says that if a platform only needs to know whether a user is old enough, it should not require a full identity file or other data that could act as a proxy for age. If the real goal is to reduce exposure to harmful content, Gregaard says, there is no reason to build a database that could later be repurposed.
Those distinctions may look small, but he argues they are significant.
Veridian is presented as a privacy-preserving model
As an example, Gregaard points to Utah, where State-Endorsed Digital Identity legislation has been passed. There, Veridian, built by the Cardano Foundation, has already shown that digital identity can be delivered in a privacy-preserving way, according to the article. The system lets users prove whether they are above or below a specific age without revealing any other data.
He describes that as a working model for responsible verification and says it shows trust does not require unnecessary disclosure. Privacy, in his view, can be designed into the system from the start.
That is the standard he says bills such as KIDS and KOSA should favor.
The article calls for data minimization and limited retention
Gregaard’s broader argument is that tools meant to protect children online should be narrow, purposeful and minimally invasive. Broad requirements that push every platform toward collecting more data, keeping it longer and depending more heavily on identity systems are too blunt, he writes, and may create a long list of new problems alongside the ones they claim to solve.
His proposed alternative is direct: build around data minimization, limit retention and use privacy-preserving verification only where verification is genuinely needed. If digital trust can be established without exposing personal data, lawmakers should choose that route. If safety can be improved without turning the internet into an identity checkpoint, he says, that should be the only option.
The column closes by arguing that children deserve protection online, but not through a policy framework that makes everyone more visible in order to make the internet and the companies that profit from it more accountable. Gregaard’s standard is simpler: protect minors, limit data, preserve privacy and build trust without unnecessary disclosure. He says that should be the test for KIDS because safety can be built without surveillance.
A note at the end of the piece says the views expressed are those of the author and do not necessarily reflect those of CoinDesk, Inc. or its owners and affiliates.

