The British government is steadily expanding regulation of the digital sphere, officially justified by the need to protect minors and combat harmful content. Yet the combination of age-assurance requirements, user-verification mechanisms and broader regulatory powers is creating a technical infrastructure that could make access to online services conditional on proving age or, in some cases, identity.
At the centre of this policy is the Online Safety Act, overseen by Ofcom, alongside mechanisms for verifying users. Labour MP Kanishka Narayan, Parliamentary Under-Secretary of State for AI and Online Safety, has played a key role in shaping this framework. His portfolio covered artificial intelligence, online safety and technological development, signalling the government’s seriousness about embedding regulation into the digital environment.
Britain’s online-safety regime is developing along several tracks: restricting minors’ access to harmful content, introducing age-assurance mechanisms, increasing platform responsibility and embedding user verification. Together, these measures could fundamentally alter the relationship between the state, platforms and citizens.
Age Assurance at Scale
Until recently, internet users could access resources without proving their age or identity. That presumption is changing. Platforms must now determine with confidence whether a user falls within a protected age category. Ofcom’s July 2026 report noted the unprecedented scale of age-assurance technologies being deployed, with regulators considering a multi-layered approach involving websites, app stores, operating systems and devices.
This shift moves beyond filters on individual sites towards a potential infrastructure spanning the entire digital ecosystem. While authorities stress the distinction between age verification and identity verification, the boundary is increasingly blurred. Establishing age often requires interaction with systems that rely on identity documents, banking data, facial estimation or third-party providers.
Embedding “Verified Users”
Narayan confirmed in March 2026 that Ofcom was preparing guidance on user identity verification under the Online Safety Act. The legislation allows adult users of major services to limit interactions with accounts that are not verified. While anonymity is not abolished, the concept of a “verified user” is being embedded into the regulatory architecture.
This raises a central question: where does age verification end and personal identification begin? Even if platforms do not directly receive passport details, users may still be required to engage with infrastructures designed to confirm compliance with age thresholds. Regulators emphasise data protection, but the reality is that access to digital content increasingly depends on prior verification.
Protecting Minors, Affecting Adults
The government’s intention to restrict social-media use by children under 16 illustrates the dilemma. Such restrictions are difficult to enforce without determining users’ ages. To exclude minors, platforms must also verify adults. A policy aimed at children therefore inevitably extends verification procedures to the wider population.
This pattern is clear. Age checks were first applied to pornography and harmful content after the Online Safety Act came into force in 2025. Authorities are now considering expansion to social media. Verification introduced for politically defensible categories of content gradually spreads into the wider digital environment.
The Anonymity Question
Anonymity itself is not unlawful. It protects journalistic sources, whistleblowers, activists and ordinary citizens who prefer privacy. Yet embedding identity or age verification as a standard condition for access could fundamentally change online communication. The concern is not a centralised government database of browsing history, but the creation of infrastructure that makes access conditional on verification. Once such systems exist, their scope becomes a political rather than technical question.
Research published in 2026 revealed a sharp increase in British interest in VPN services following the introduction of age-assurance requirements. Citizens sought not only to circumvent restrictions but also to protect privacy and avoid sharing personal data with third-party providers. Regulation may therefore undermine trust, encouraging users to conceal activity rather than engage openly.
Balancing Safety and Freedom
The need to protect minors from harmful material is not disputed. The real issue is how far the state should go in building mechanisms to provide that protection. There is a difference between requiring platforms to remove illegal content and requiring users to prove eligibility before access. In the first case, regulation targets corporate conduct. In the second, scrutiny shifts to individuals.
Britain’s experiment matters beyond its borders. If politically accepted, it could become a template for other countries. Without abolishing anonymity outright or introducing a universal “internet passport,” authorities could progressively establish verification barriers across the digital infrastructure. Protecting children provides a powerful justification, but the mechanisms created could be adapted for entirely different purposes.
A Threshold Moment
Britain is approaching a threshold. It is premature to speak of “total digital censorship” or mandatory passport identification for every user. Yet the state is already assembling elements of a system in which anonymous access is no longer the norm. Under the banner of protecting minors, Britain is developing infrastructure that expands the ability of the state and platforms to verify users. Today, boundaries are defined by age and harmful content. Tomorrow, expansion will depend on political decisions.
The central question is no longer whether Britain has created a “ministry of censorship,” but whether it is building a system capable of turning anonymity into the exception and proof of eligibility into the norm. That is the most consequential change.