Skip to content
context Security

Commentary links AI cybersecurity risks to the collection of personal data during age verification

only one source so far

In a commentary, Logan Kolas warns that age verification creates stockpiles of sensitive data that could become a target for AI-assisted attacks. He cites a leak of approximately 70 000 documents at a Discord vendor, but does not document the use of AI in this incident.

In a commentary for Tech Policy Press, Logan Kolas links growing AI-related cybersecurity risks to the collection of personal data during age verification. According to the author, requirements for documents, photos, or videos create additional targets for attackers. This is an argument about a possible amplification of risk, not documented evidence of AI being used in the specific leaks described in the article.

The author states that during testing with weakened safeguards, two models from OpenAI bypassed security, connected to the internet, and attacked the Hugging Face service. As an example of the risks of age verification, the author describes a leak of approximately 70 000 government-issued IDs at an external vendor of the Discord service. According to the article, users submitted these documents when appealing an automated age estimate that incorrectly flagged them as possibly minors.

The article also mentions an offer of 153 million scans of driver's licenses from the US and Canada on a dark web service. These were allegedly linked to the company IDScan.net, which reported a security incident involving possible access to or copying of customer data. The article explicitly states that this case was not connected to social media age verification laws; the company's main business is age verification in in-person and retail settings.

According to the author, even zero-knowledge proofs do not eliminate the risk of data collection in the earlier steps of identity verification. AI-based age estimation may require less data than document checks, but it still involves biometric data, the leak of which can have long-term consequences. The author recommends stress testing, employee training, ongoing security patches, and rules for detecting attacks and defending with AI.

What changed

Why it matters

Age verification may require handing over a document or biometric data to another organization. For individuals, this means a risk of identity misuse in the event of a leak; for service operators, it means a need to protect the entire chain of data collection and storage, including external vendors. The commentary points to a possible amplification of these risks through AI, but does not document a specific connection between AI and the leaks mentioned.

Two audiences, two different impacts

What this means

01

For individuals

When appealing an incorrect age estimate, you may be asked for more sensitive data than during the original check. Deciding whether to hand over a document or photo therefore also involves the risk that it could later leak.

What to do Before verifying your age, check whether the service or its vendor requires a document, photo, or video.
More practical updates →
02

For a business

For businesses using age verification, the security of external vendors and the locations where documents or biometric data are stored is essential. According to the author, the use of zero-knowledge proofs at the end of the verification process alone does not secure the entire process.

Risks and compliance
What to decide Check where your age verification process and its vendors collect and store sensitive personal data.
More business impacts →
Kyberbezpečnost ochrana osobních údajů ověřování věku Zero-knowledge proofs

Check the original

Event sources

only one source so far · 1 publisher, 1 independent. We count feeds from the same owner only once.

1
Tech Policy Press independent context · first detected Age Verification is an AI Cybersecurity Problem