On July 25, 2025, the UK switched on mandatory age checks for adult content under the Online Safety Act. Within hours, Proton VPN reported signups running roughly 1,400% above its normal baseline. Top10VPN measured UK VPN traffic spiking 1,327% on the 25th, and close to 2,000% two days later. Half the top-ten free apps in the UK App Store were VPNs. When Australia enforced its own adult-content age checks on March 9, 2026, the pattern repeated almost to the decimal: VPN installs nearly tripled around the deadline. Across the same window, Reddit threads about bypassing age checks grew from one in May 2025 to sixty-five in April 2026.
The headline wrote itself, and every outlet ran a version of it: age verification is backfiring. If a determined user can install a free app and tunnel out to a server in another country in ninety seconds, what exactly did the age gate accomplish?
It is the wrong question, and answering it wrong is how operators end up either panicking into over-collection or dismissing a real problem as somebody else’s. The VPN surge is not a verdict on whether age verification works. It is two separate signals wearing one headline — and only one of them is your problem.
The category error underneath the headline
“Age verification failed because people used VPNs” quietly fuses two claims that have nothing to do with each other.
The first claim is that age assurance should be unbypassable — that a control which a determined person can route around is a control that failed. No regulator anywhere has ever written that standard, because it is not achievable for any access control on the open internet. The same logic would condemn the lock on your front door because lockpicks exist. Determined circumvention is the assumed background condition of every safety regime, not the event that invalidates one.
The second claim is that age assurance drives away legitimate adults — people who are plainly old enough, entitled to the content, and reaching for a VPN not to sneak past a gate but to avoid the gate’s demands. That claim is true, it is measurable, and it is the one operators should lose sleep over. Cybernews researchers looking at the 2026 surge were explicit that it is not only minors driving VPN downloads: a large share are privacy-conscious adults who will not hand a pornography site or a social platform their government ID or submit to a facial scan.
Those two claims point in opposite directions. The first says the gate is too weak. The second says the gate is too heavy. Merge them into one “backfiring” narrative and you cannot act on either, because the fixes are contradictory. Pull them apart and the operator picture gets clear fast: you are not required to solve the first, and the second is almost entirely self-inflicted.
What regulators actually require — and it is not “unbypassable”
Read the statutes and the gap between the headline and the law is stark.
The UK Online Safety Act requires “highly effective age assurance,” and Ofcom’s guidance defines that against criteria — technical accuracy, robustness, reliability, fairness — none of which is “no user can ever circumvent it.” The EU’s approach under the Digital Services Act, the various US state laws, and Australia’s regime all converge on the same shape of standard: proportionate, reasonable, effective in practice. The recurring statutory verb is “reasonable steps,” not “perfect prevention.”
Circumvention is handled explicitly, and not the way the panic implies. Under the OSA, services already have to assess circumvention risk and apply proportionate measures as part of their Children’s Access Assessments. The UK government’s position through 2026 has been that VPN use does not negate a service’s other duties — meaning the existence of VPNs does not excuse a weak age gate, but equally, a spike in VPN usage is not itself proof that a compliant service broke the law. Services that actively promote VPNs as a bypass can face enforcement; services whose users independently choose VPNs are in a different category. Ofcom has been tasked with publishing guidance by the end of October 2026 on what more services can do to detect and prevent VPN use — which tells you two things: the regulator does not currently mandate VPN blocking, and it intends to raise the bar on proportionate anti-circumvention effort, not to declare the whole exercise futile.
So a VPN surge, on its own, is not a compliance failure. If your age check meets the effectiveness bar for the users who present themselves honestly, and you have documented proportionate circumvention measures, you are inside the standard even while Top10VPN’s dashboard lights up. The 69 million age checks Ofcom recorded across 32 services in the second half of 2025 — a 23-fold jump — are the compliance story. The VPN spike is a parallel story, and conflating the two is exactly the mistake that leads a nervous compliance team to bolt on invasive checks that make everything worse.
The half that actually is your problem
Here is where the surge stops being someone else’s narrative and becomes an operating metric you own.
Every adult who reaches for a VPN rather than complete your age check is a legitimate user you lost at the door — and the reason they left is almost always the design of the check, not the fact of it. The privacy-conscious adult is not objecting to being asked whether they are over 18. They are objecting to the specific bargain you offered: upload a government ID to a website you do not trust, or let it scan your face, and hope the vendor behind it deletes the file. Given that bargain, the VPN is the rational move, and the 2026 data is what a few million people making that move at once looks like.
This is a friction-and-architecture failure dressed up as a circumvention story. And it compounds a problem this blog has covered before from the conversion side: heavy verification flows shed legitimate users at exactly the moment you are trying to onboard them. The VPN surge is that same abandonment, except instead of churning quietly it exits through a Netherlands server and shows up in a “your law failed” headline. Worse, the check that provoked the exit is frequently the one that also creates your largest liability — because the document image and biometric you collected to run it become the breach surface you now have to defend. You spent friction to lose the adult and to acquire the data that will hurt you if it leaks. Two failures for the price of one control.
Notice what does not fix this: making the check heavier. Every increment of intrusiveness you add to satisfy the “too weak” reading of the surge directly enlarges the “too heavy” problem that is actually costing you users. A facial scan bolted onto an ID upload does not recover the adult who left over the ID upload; it gives the next adult a second reason to leave. The two readings of the surge are not just different — they are in tension, and optimizing for the wrong one accelerates the real damage.
What to build instead
The way out is to make the honest path the path of least resistance — so low-friction and so obviously private that the marginal adult never reaches for the VPN in the first place. Concretely, that is a short list in a deliberate order.
Lead with the lightest resolving check. Most of your traffic can be cleared without a document at all: a browser-based age check, an on-device estimation whose model runs on the user’s phone and emits only a pass/fail, or — for a returning user — a lookup against a credential they already hold. The cheapest, least-abandoned verification is the one the user never has to repeat, which is why reusable age credentials are the single highest-leverage move available: verify once, prove everywhere, and the second platform never re-runs the check that drove the user to a VPN the first time.
Make privacy the visible default, not the fine print. The adult reaching for a VPN has one fear — that you will keep their ID. Answer it in the architecture: minimize retention to the assertion, not the evidence, discard the document and the selfie once the decision is made, and be able to tell a user (and a regulator) that a breach of your system yields a log of pass/fail results, not a vault of identity artifacts. Privacy-preserving is not a compliance nicety here; it is the specific feature that keeps the privacy-conscious adult on your side of the gate.
Reserve the heavy path for the contested band, and make it real. The minority the light checks cannot resolve get a genuine step-up — a chip-verified document or a mobile driver’s licence with selective disclosure, not a credit-card check that proves nothing about age and not a raw photo upload that synthetic IDs now pass routinely. This is the layered waterfall: the expensive, high-friction verification only ever runs on the users who actually need it, which keeps it from becoming everyone’s reason to leave.
Then document your circumvention posture, because the standard is proportionate effort and the bar is about to rise. Record the anti-circumvention measures you take, keep them proportionate to your risk, and get ahead of Ofcom’s October 2026 VPN guidance rather than scrambling after it. The service that can show a regulator a low-abandonment, privacy-preserving gate plus a reasoned circumvention assessment is in a defensible position no matter what Top10VPN’s chart does next enforcement day.
Where Xident fits
This is the split Xident is built around. A Check — a browser-based age check, on-device liveness, a returning-user lookup, an OAuth handoff — is the low-friction, privacy-preserving front door that resolves the large majority of your traffic without ever asking for a document, which is precisely what keeps the privacy-conscious adult from tunnelling out. A Verification — document read plus face match — is the higher-assurance step-up you reserve for the contested minority. Because the assurance can be issued as a reusable credential, an adult who clears once does not have to face the gate again on the next site, and because the architecture retains the decision rather than the evidence, the check does not become the breach you have to explain later. That is how you meet “highly effective” for the honest user without manufacturing the VPN demand that makes the whole exercise look like it failed.
The takeaway
The VPN surge is real, and it is not going away — determined users will always find the tunnel, and no age check on the open internet will stop them. But “some people used a VPN” was never the standard, and treating it as one leads directly to the over-collection that drives legitimate users to the same VPNs. The number that should govern your roadmap is not how many people circumvented; it is how many adults you lost at the door because the door demanded too much. Lower that number with a lighter, more private front door, reserve real verification for the cases that need it, keep the evidence out of your database, and document your proportionate measures. Do that and the next time the “age verification failed” headline runs, it will not be describing you.
Losing legitimate adults to a heavy age gate — and watching them show up in the VPN numbers? Talk to Xident — a low-friction, privacy-preserving Check up front, a chip-grade Verification only for the contested band, and a reusable credential so nobody has to prove it twice.