Cardano Foundation CEO argues child safety online should not come at the cost of privacy

Cardano Foundation CEO argues child safety online should not come at the cost of privacy

N
News Editor
2026-07-15 14:58:50
Cardano Foundation CEO Frederik Gregaard argues that the push to protect minors online is colliding with a long-running weakness in digital identity systems: age checks often rely on vendors that collect and store highly sensitive personal data. In his CoinDesk opinion piece, he points to recent breaches involving identity verification providers, including AU10TIX in 2024 and a Discord age-verification provider in 2025, as evidence that systems built for safety can turn into breach vectors once they depend on stored identity records and third-party operators. The piece arrives as the U.S. House has passed the Kids Internet and Digital Safety Act, or KIDS Act, on June 29 by a 267-117 vote. The bill is now before the Senate, where KOSA co-authors Richard Blumenthal and Marsha Blackburn have rejected the House version and are backing a tougher approach. Gregaard’s argument is that even without an explicit age-verification mandate, liability rules can still push platforms toward collecting more user data. He says a narrower model is possible. Citing Veridian, built by the Cardano Foundation and already used in Utah’s State-Endorsed Digital Identity framework, Gregaard says users should be able to prove whether they are above or below a certain age without disclosing broader identity information. His proposed standard is simple: protect minors, minimize data collection, limit retention, and preserve privacy.
Cardano FoundationFrederik GregaardKIDS ActKOSAage verificationdigital identityprivacy

Cardano Foundation CEO Frederik Gregaard says the privacy dangers of age verification are no longer theoretical. In a CoinDesk opinion column, he argues they have been visible for years and are now becoming harder to ignore.

He points to a series of breaches to make the case. In 2024, identity verification provider AU10TIX, which served companies including TikTok and Uber, was found to have exposed drivers’ licenses to hackers for more than a year. In 2025, the provider handling age-verification systems for Discord was breached, potentially exposing government IDs belonging to 70,000 users. By 2026, Gregaard writes, the lesson should already be obvious: once age verification depends on vendors and stored identity data, a system built for safety can turn into a breach vector.

He also says AI is accelerating the problem, making attacks faster and the resulting damage easier to inflict.

The KIDS Act has moved to the Senate

Gregaard places that argument against the backdrop of new U.S. legislation. On June 29, the House passed the Kids Internet and Digital Safety Act, a broad package built around the Kids Online Safety Act, or KOSA, by a 267-117 vote.

The bill now sits in the Senate. According to the column, KOSA’s original authors, Democrat Richard Blumenthal and Republican Marsha Blackburn, strongly rejected the House version and are pressing for a tougher one. Part of that push involves tying the legislation to federal preemption of state AI laws. A Senate Commerce Committee markup is expected this month. Whatever comes out of that process, Gregaard writes, will shape how identity works online for years.

He says the aim is to protect minors. The danger, in his view, is that the mechanism used to do that could require a much larger surveillance apparatus than supporters openly acknowledge.

No explicit mandate can still produce verification

Gregaard argues that KIDS does not need to explicitly order age verification to make platforms adopt it. If companies can be held liable for harm to minors who access their services, the compliance math becomes simple: verify age or accept the legal risk that comes with not knowing who is a minor.

That means liability without a verification mandate can still lead to verification in practice. He says that point matters because the defense that there is “no explicit age check in the bill” may be technically correct while still missing how the incentive structure works in the real world.

Once disclosure becomes the cost of access, he writes, the collection dragnet tends to expand. A tool meant only to confirm that a user is old enough can become a tool for confirming who that user is. A database created to reduce liability can then become a liability of its own, another pool of identification data waiting for the next AU10TIX-style breach.

If all a platform needs is age, it should not demand full identity

The column says that if a platform only needs to know whether a user is old enough, it should not require a full identity file or other data that could act as a proxy for age. If the real goal is to reduce exposure to harmful content, Gregaard says, there is no reason to build a database that could later be repurposed.

Those distinctions may look small, but he argues they are significant.

Veridian is presented as a privacy-preserving model

As an example, Gregaard points to Utah, where State-Endorsed Digital Identity legislation has been passed. There, Veridian, built by the Cardano Foundation, has already shown that digital identity can be delivered in a privacy-preserving way, according to the article. The system lets users prove whether they are above or below a specific age without revealing any other data.

He describes that as a working model for responsible verification and says it shows trust does not require unnecessary disclosure. Privacy, in his view, can be designed into the system from the start.

That is the standard he says bills such as KIDS and KOSA should favor.

The article calls for data minimization and limited retention

Gregaard’s broader argument is that tools meant to protect children online should be narrow, purposeful and minimally invasive. Broad requirements that push every platform toward collecting more data, keeping it longer and depending more heavily on identity systems are too blunt, he writes, and may create a long list of new problems alongside the ones they claim to solve.

His proposed alternative is direct: build around data minimization, limit retention and use privacy-preserving verification only where verification is genuinely needed. If digital trust can be established without exposing personal data, lawmakers should choose that route. If safety can be improved without turning the internet into an identity checkpoint, he says, that should be the only option.

The column closes by arguing that children deserve protection online, but not through a policy framework that makes everyone more visible in order to make the internet and the companies that profit from it more accountable. Gregaard’s standard is simpler: protect minors, limit data, preserve privacy and build trust without unnecessary disclosure. He says that should be the test for KIDS because safety can be built without surveillance.

A note at the end of the piece says the views expressed are those of the author and do not necessarily reflect those of CoinDesk, Inc. or its owners and affiliates.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.