Utah age verification law: VPNs Out, ID Data In
Utah age verification law: VPNs Out, ID Data In
This episode is based on our article:
Read the full article →Utah age verification law: VPNs Out, ID Data In
Full Episode Transcript
A VPN, that little app millions of people use to hide their location online, can no longer do the one thing it was famous for. Not in Utah. Starting 5/6/2026, Utah became the first U.S. state to write a law that reaches through your VPN and demands you prove your age anyway.
Why should you care if you don't live in Utah
So why should you care if you don't live in Utah? Because this isn't really a story about VPNs. It's a story about who ends up holding your driver's license, your face scan, or your credit card. Utah's Senate Bill 73 says websites have to verify a user's age even when that person is masking where they are. Lawmakers say they're protecting kids from pornography that's everywhere and easy to reach. But critics say the law lands hardest on adults who just wanted a little privacy. So the question threading through all of this, if a website can't tell where you are, how does it prove how old you are?
Let's go back to where this started. Utah passed the country's first age verification law in 2023. And people did something completely predictable. VPN use in Utah jumped almost overnight. Users routed their internet traffic through servers in other states and walked right past the age gates. Senate Bill 73 is Utah's answer to that workaround. The old law checked your location. The new one assumes if you're physically in Utah, you verify, no hiding allowed.
Here's the problem the VPN company NordVPN points to. They call it an unresolvable compliance paradox. In plain terms, a website can't actually know who's standing inside Utah unless it demands invasive identity checks from everybody. But if the site guesses wrong, it faces legal liability. So the safe move for the website is to card everyone. That means you, the adult in another state, could get asked to hand over an I.D. just to read a page.
Think about what "verify your age" really requires
Now think about what "verify your age" really requires. If the VPN escape hatch closes, everyone proves their age the hard way. That means uploading a government I.D., or a scan of your face, or your credit card, straight to a website. Often with no encryption and no privacy promise attached. That's your most sensitive information sitting on a server you'll never see.
And this doesn't stop at the Utah border. One state passes something new. Courts weigh in. Other states copy the parts that survive. The United Kingdom is already moving to restrict children's VPN use under its Online Safety Act. For your family, that means the trade-off spreads. A one-time I.D. check today could become a face scan tomorrow.
But the pushback is real too. Wisconsin stripped the VPN provision out of its own age verification bill entirely, after digital rights groups and regular residents complained. That happened in a conservative state. So this approach is shakier than it looks.
The Bottom Line
Here's the part that reframes everything. When the technology fails to detect your age, enforcement doesn't chase your age. It chases your identity. A lot of these tools only estimate age, they're guessing, based on probability. And when a guess isn't good enough, the fallback is always the same. Show us who you really are.
So let's bring it home. Utah's first age law sent people to VPNs. The new law targets those VPNs, so now websites may card everyone to stay safe. And the price of that safety is your I.D., your face, or your card sitting on someone else's server. This isn't just a debate about protecting kids. It's a question about what you're willing to hand over, and to whom, every time you click. The full story's in the description if you want the deep dive.
Ready for forensic-grade facial comparison?
Full forensic reports with detailed similarity scoring. Results in seconds.
Run My First SearchMore Episodes
AI Identity Verification: 8,065 Deepfakes Hit One Bank
Between January and August of this year, one bank got hit with eight thousand and sixty-five deepfake attacks. Not eight thousand suspicious logins. Eight thousand attempts to fool the camera with an A.I.-generated face.
PodcastBiometric Data Definition: 3 Questions a Face Scan Must Answer
Right now, in Scotland, there's a camera scanning shoppers as they walk into a store — and there's no rule on the books that clearly says it can't. The only official strategy governing public surveillance cameras there wa
PodcastWhat Is Voice Cloning: 3 Seconds of Audio Fakes a Family Call
Three seconds. That's all it takes. Three seconds of your voice — from a voicemail greeting, a TikTok clip, even a few words you say when you pick up a wrong number — and a stranger can clone how you sound. The F.B.I. says
