Six months and nineteen global texts, the terrifying convergence

HR 8250, CSAR, verdict Meta, World ID, Online Safety Act. Six months, nineteen texts, four continents. One direction.

Six months and nineteen global texts, the terrifying convergence

JULY 2026 UPDATE. No calendar on the CSAR side: the trilogue on May 4th took place, and on July 9th the Parliament allowed the renewal of Chat Control 1.0 (voluntary, E2E excluded) without the 361 votes needed to block it, majority against. Mandatory scanning (2.0) described in this map is not settled: it goes back to trilogue in September. Details in the radar.

Your Privacy? It’s not really yours anymore.

No one took it from you all at once, no. That’s for rushed regimes. They’re just nibbling at it, slowly, so you don’t notice.

A bill in Washington making your Mac an identity checkpoint. An EU regulation replacing your encrypted messages with a snitch. A jury in New Mexico slapping Meta with a $375 million fine for daring to deploy strong encryption.

Six months. Nineteen texts. Four continents. One direction.

Here’s the map.


Three mechanics, one trajectory

The nineteen texts I’m presenting don’t look alike on the surface. An American law, a European regulation, a court decision, a private product. But piled up, three mechanics emerge, and they work together.

M1, universal identification. No more anonymity on the internet, not even for adults. Every connection, every sign-up, every message demands an identity proof.

M2, breaking end-to-end encryption. Encryption stays on paper. But contents are scanned before it applies, or deploying it becomes legally risky.

M3, centralization with two or three actors. Apple, Google, Microsoft, or a Sam Altman eager to monopolize humanity verification. You no longer log in to a site, you log in through an identity broker.

Most of these texts passed under the radar because they arrived one by one. When you see them together, the picture changes.


M1, universal identification without adult exception

On April 13, 2026, Josh Gottheimer (D-NJ) and Elise Stefanik (R-NY) introduced HR 8250 Parents Decide Act in the US House of Representatives. The bill requires Apple, Google, and Microsoft to demand a birthdate when creating any account, and then expose that information to app editors via a dedicated interface. No adult exception. You set up a new Mac in 2027, the system identifies you, and every app can read it.

Andy Yen, CEO of Proton, summed up the issue in one sentence: « We cannot accept a world where every adult has to present an ID just to go online. » Eight days later, the Illinois HB 5511 was passed by the House, 82 to 27. The same logic, moving age verification from apps to the OS, harder to circumvent because the OS is linked to the verified account and the payment method.

This logic isn’t just American. The UK Online Safety Act came into effect on July 25, 2025. In the first quarter of 2026, the Ofcom opened over ninety investigations and issued six fines, including a £1.35 million fine against 8579 LLC. Australia activated its Online Safety Amendment on December 10, 2025, extended to ten platforms. Brazil enacted law 15,211/2025 in September 2025. And on April 14, 2026, the European Commission unveiled its harmonized age verification app for the twenty-seven member states.

By the way, it was hacked in two minutes by a British consultant, Paul Moore. For the details, you can read the radar at the link below. Either laughable or crying, depending on your perspective.

Read: EU Age Verification, Hacked in 2 Minutes, the Poorly Coded Surveillance

On March 2, 2026, 371 cybersecurity researchers from 29 countries signed an open letter. Ronald Rivest, Turing Award and co-inventor of RSA. Bart Preneel, president of the IACR. Not exactly Sunday activists.

The letter argues that the method isn’t secure and risks exposing users to malware or scams on illegal sites that don’t implement age verification, or revealing more personal information to service providers. Their conclusion on the deployments in progress: « dangerous and socially unacceptable ».

To make age verification work properly, they write, « state-issued IDs with strong cryptographic protection » are needed for every interaction with the service.


M2, breaking encryption in law or in case law

On the EU side, the dossier is known, I’ve detailed it before.

Read: Chat Control 2.0: The EU Wants to Read Your Messages Before You Send Them

Read: NIS2 Forces Companies to Encrypt. CSAR Prevents Them From Doing It Properly.

The novelty here is the admission. Vera Jourova, Vice-President of the Commission, publicly acknowledged at the EDPS summit that CSAR would break encryption. Three years of « CSAR doesn’t break encryption » discourse from Ylva Johansson, refuted by her own colleague. The next trilogue is set for May 4, 2026, with adoption targeted for July. The clock is ticking.

But the most brutal attack on end-to-end encryption comes from the US, and it’s not a law. It’s case law, and it’s much worse.

On March 24, 2026, a jury in New Mexico condemned Meta to a $375 million fine for civil penalties. The attorney general used Meta’s decision to deploy end-to-end encryption in Messenger as proof of irresponsibility towards minors.

And the sequence that follows is even more telling than the verdict: during the trial, before even the sentence, Meta announced the withdrawal of end-to-end encryption from direct Instagram messages. Effective on May 8, 2026. The mere existence of the trial was enough to decide them.

And the real problem with case law is that one judge was enough to make all the others adopt his ruling in other judgments. With heavy fines to follow, which will discourage startups from aiming to encrypt their services in the very near future. Because $375M for Meta is pocket change. For a startup, it’s death.

Even more effective than a law or a regulation.

While it may be tempting, we can’t blame the judge alone. Meta’s voluntary (?) irresponsible behavior shaped the decision. I’ll explain:

An internal note signed by Monika Bickert (director of content policy at the time) ended up in the trial documents. Irony at its peak: « We’re about to do something bad as a company. It’s so irresponsible. » Bickert wasn’t criticizing encryption itself, she was warning her superiors about the timing.

Enabling end-to-end encryption by default on Messenger without first finding a way to detect abuses involving minors was like voluntarily blinding Meta’s systems. The prosecutor in New Mexico used this note to prove the hardest thing to prove in a civil case: that Meta knew its decision would let predators through, and made the decision anyway.

Here, it’s really important not to get the roles wrong. Meta isn’t the victim of the trial. For Zuckerberg, end-to-end encryption was never a value, it was a marketing argument to stay competitive against WhatsApp and Signal.

That’s exactly what separates Meta from Signal or Proton. Signal can’t remove end-to-end encryption, it would dissolve the product. Proton can’t either, its entire proposition rests on it. Meta can, because for them, end-to-end encryption was an optional feature, not a foundation.

And that’s precisely what creates the precedent that judges can use against Signal or Proton later. « See, even Meta backed down, you can too. » Meta isn’t just the victim of the end-to-end encryption retreat. It’s actively participating in it.

And that’s also Bruce Schneier’s conclusion. Deploying strong encryption on your product can now be attacked legally as an act of bad faith. Not illegal in itself. Just… harmful in civil court, before an American judge.

The US picture is completed with FISA Section 702. The law was set to expire on April 20, 2026. Congress voted a ten-day emergency extension and blocked the « warrant requirement » amendment in advance. The NSA is vacuuming up communications of targeted foreigners outside the US, Americans who write to them then enter the base, the FBI queries it without a warrant. Seven thousand US-person queries in 2025, under-declared by the DOJ itself.

At the other end of the world, Hong Kong. On March 23, 2026, the enforcement rules of the National Security Law were modified, the police can now demand your passwords and your encryption keys. Refusing is a criminal offense. Schneier wrote a blog note about it. Hong Kong is forcing it. Democracies, they’re circumventing it through contract (CSAR), through case law (Meta NM), or through age barriers at the OS level (US). Same result, different packaging.

Convergence without coordination, but convergence nonetheless.


M3, private and public brokers, identity as infrastructure

Once HR 8250 is passed, or Illinois HB 5511, Apple and Google become age brokers. Not by choice, by legal constraint. Technically, it’s just a regional option, the kind of switch Apple already flips for the GDPR. The real risk is that other governments will see the system running in the US and copy it. Reverse GDPR effect, by mimicry.

While states debate, Sam Altman is pushing his private alternative. On April 17, 2026, World ID announced its integration with Tinder, Zoom, DocuSign, Okta, Shopify, and VanEck. Eighteen million users already verified by iris scan (The Orb), in 160 countries. The pitch: « the first decentralized identity layer for humanity », against bots and deepfakes, which the same industry AI produces in bulk.

It’s elegant. You create the problem (AI deepfakes), you sell the solution (iris scan), and in the process, you build a private global biometric database, connected to Tinder, Zoom, DocuSign, and Shopify. The scanned becomes a free beta tester of humanity, paying with their iris. The AI industry gets even more free, high-quality data, but especially qualified.

You can’t really do better than that, can you?

On the state side, the UK is advancing its GOV.UK Wallet and its digital driving license, full deployment by the end of 2026. Not mandatory yet, physical cards still valid until 2030. But the infrastructure is there, ready to become mandatory whenever a future government decides.

Three actors emerge as dominant identity brokers, Apple plus Google on the OS side, World ID on the private global side, GOV.UK Wallet and its twins on the state side. No one coordinated. The convergence is political, economic, structural.


Why this convergence

It’s not a conspiracy. It’s more boring than that, it’s systemic mechanics.

First, transatlantic imitation. The UK Online Safety Act passed in 2023 served as a model. Australia replicated it in 2025. The European Commission cited it explicitly as « good practice » for its age verification app. HR 8250 and Illinois HB 5511 picked up the same architecture six months later. No secret coordination, just « look, it works there, let’s copy it ».

Next, the zero marginal cost for Apple, Google, and Microsoft. Once the age verification infrastructure is built on the OS for one state, exporting it to other countries costs nothing more.

Finally, regulatory momentum creates the private market. Platforms are looking for identity verification providers? Worldcoin raises its hand. States want their sovereign wallet? Integrators (Thales, IDEMIA, Entrust) position themselves on eIDAS 2.0 calls for tenders. Regulation creates need, the market sells the solution.

The result is exactly what the letter from the 371 researchers warned about, a system where every interaction with an online service requires an identity proof issued by a state or a private broker.


The counter-movements

Ending on a totally defeatist note would be unfair.

On April 1, 2026, Governor Brad Little signed Idaho SB 1299, which prohibits government entities in the state from requiring a digital ID. The first US state to push back frontally, text legally solid and replicable.

Two days later, Governor Tony Evers of Wisconsin exercised a veto on AB 105, on an age verification bill for adult sites. The first governor veto in US history on an age verification bill, three well-argued objections, intrusion on adults’ privacy, no restrictions on sharing, vulnerabilities exposing users to theft and blackmail.

On April 23, 2026, Thomas Massie (R-KY) and Lauren Boebert (R-CO) introduced HR 8470 Surveillance Accountability Act. Warrant and probable cause required before any surveillance of Americans, close the « data brokers » loophole. Bipartisan in spirit, a sign that the surveillance debate is crossing both parties.

And on April 8, the French DINUM announced the migration of 2.5 million administration posts to Linux. David Amiel, Minister of the Budget, requests ministerial plans before the autumn 2026. Seven axes for reducing dependence, sovereign video conferencing for 200,000 agents by the end of 2026, 2.5 million by 2027.

Let’s be honest for two seconds. France isn’t migrating to protect the privacy of its civil servants, it doesn’t care. It’s migrating because depending on Microsoft costs between 500 and 800 million euros in licenses per year, and because a Trump 2.0 has finished reminding Brussels and Paris that an American provider can be shut down by a White House decree. Budget sovereignty and strategic sovereignty. Privacy nowhere.

But that’s precisely why the example is interesting. A state exits a hegemonic stack for reasons of money and geopolitics, not ideology.

**And the result, by effect, is that its 2.5 million civil servants stop being continuously telemetred by Redmond.

What a state does for its reasons, a citizen can do for theirs. And protecting your online privacy today is a political choice, not a crime, at least not yet.


Sorting it out, technically and politically

I use Proton Mail and a self-hosted Stalwart mail server for emails, Matrix for instant messaging, a Tailscale wireguard mesh network with Mullvad exit node for security, an unbound self-host DNS resolver, and various other open source tools for my digital sovereignty.

It’s not absolute, of course, but it’s already a huge independence, real privacy, a significant limitation for commercial or state third parties to continuously track you.

Except for Proton, and Infomaniak’s VPS hosting, all these tools are free, open source, audited for the most part, and supported by dynamic communities. Proof that privacy isn’t dead, and it interests many people.

You’re not obliged to go that far, of course, but for your professional activity in particular, I strongly recommend going that far. But every step you take for your privacy counts. It’s your inalienable right to dispose of your digital data as you see fit, and to define who you share it with. It’s as fundamental as the freedom to come and go.

If CSAR passes, if HR 8250 progresses, and you feel concerned, the right reflex is to choose architectures whose technical design makes it impossible to scan your data, and tracking extremely difficult.

Signal and Proton can’t implement client-side scanning without breaking their model. It’s not a policy, it’s an impossibility. Choosing them, or others built on the same model, protects you.

Read: What Digital Sovereignty Means in Practice

Politically, if you’re interested, write to your representatives. The CSAR trilogue on May 4, 2026, is a tipping point. Public pressure worked on Chat Control 1.0, it can work on CSAR 2.0.

EDRi, EFF, noyb maintain tools for direct contact with citizens. Use them and participate in the action, if it speaks to you.

And follow the MacSouverain Radars. Every text, every verdict, every tightening is followed in real time. Vigilance for privacy is daily attention, not episodic.


For the impatient

Six months, nineteen texts, four continents. Three mechanics that fit together, universal identification, breaking encryption, centralizing identity data with two or three brokers. This isn’t a conspiracy, it’s converging trajectories that will result in less privacy, or even no privacy at all, if they’re combined in each country.

Everyone comes out winning, that’s how it’s sold, except for the final user, if you read carefully. Everyone else.

Idaho SB 1299, Wisconsin veto Evers, Surveillance Accountability Act, 371 researchers, real points of support, demonstrate that another path is possible.

Your technical choices today, Signal, Proton, well-configured and up-to-date MacOS, Linux why not, are also political choices. And supporting EDRi and EFF, refusing convenience features that pave the way, is also the right way to combine the two.

What’s happening isn’t written yet, but it’s already inscribed in a trajectory.

It’s up to you to choose what you make of it.


Sources

Official texts and legislation

Analyses and coalitions


See also