top of page

First Tehran, then Moscow, and soon Brussels

Writer: Thijs Jansen
Thijs Jansen
May 21
9 min read

In July 2025, the Online Safety Act came into force in the United Kingdom, a law designed to keep children away from pornography and other "harmful content." Websites were required to verify "robustly" whether a visitor was of legal age. One of the permitted methods seemed both clever and privacy-friendly: instead of uploading your passport, you simply held your face up to the webcam, after which an AI estimated your age from your facial features. No documents, no hassle. Just a single selfie.


Until the British discovered where every facial scanner falls apart: it does not check whether a real human is sitting in front of the camera, only whether an adult face is visible. Holding a screenshot of actor Norman

Reedus, the main character from the video game Death Stranding, up to the camera was sufficient. The algorithm saw an adult man, and the gate opened. A digital avatar of an actor defeated billions of pounds worth of compliance investments.


Internet Privacy under attack in EU
Internet Privacy under attack in EU

The rest of Great Britain chose an even simpler escape route. In the first month after the law came into effect, one developer alone reported a 1,800 percent increase in downloads of his VPN service. At one point, half of the top ten free apps in the British App Store consisted of VPN services. In August 2025, more than 1.4 million Britons logged in via a VPN daily, more than double the previous number, simply because they had no interest in uploading their passport to read a news article. A VPN can be seen as a secure tunnel for your internet traffic. It makes it harder for websites and governments to see where you are, what you are doing, or which sites you visit. This makes it appear as though your internet connection originates from a different location, namely the location of the server of the VPN provider rather than your own computer.


And a VPN is far more than a convenient trick for bypassing an age gate. Imagine a journalist in Iran trying to pass sensitive information to the outside world. A dissident in China sharing evidence of oppression without immediately being arrested. An activist in Russia making contact with family members in exile. Without a VPN, this becomes nearly impossible. It encrypts your connection, hides your IP address, and enables anonymous communication. For journalists, it is indispensable for protecting sources. For those living under an oppressive regime, it is a lifeline to the outside world: reading the news, seeking help, sharing evidence, without the state watching over your shoulder. In short, it is not a luxury for criminals seeking anonymity or children wanting to play an online game. It is basic infrastructure for a free internet.


The obvious conclusion from the British fiasco would be: perhaps our age verification is not working as intended. Yet the conclusion drawn by British and European policymakers is a different one. The Children's Commissioner for England is now openly advocating for VPNs to be classified as adult services. In Brussels, Henna Virkkunen, European Commissioner for Tech Sovereignty and Security, says the European age verification app, planned for rollout across all 27 member states by the end of 2026, "must also ensure it cannot be circumvented." And a briefing from the European Parliament dated January 2026 already puts

it in black and white: the revised European Cybersecurity Act will "likely include measures to prevent VPNs from being misused to bypass legal protections." Translated into plain language: for the first time in modern European history, anonymity tools themselves are becoming a political target.


We have arrived on a slippery slope more dangerous than many people realise. Because we have seen this film before. Not yet in Brussels, but certainly in Tehran, Moscow, and Beijing.


The regime playbook.


In Iran, using an unauthorised VPN has been punishable by up to a year in prison since February 2024. During the Mahsa Amini protests, WhatsApp and other apps were blocked. In early 2026, following new protests, the Iranian internet was shut down for many weeks in the largest shutdown the world had seen at

that point. The Committee to Protect Journalists counted at least 96 arrested Iranian journalists since September 2022. Those who still managed to report did so thanks to a black market for VPNs. For them, a VPN is not a convenience for watching Netflix in another country. It is the difference between working and silence.


In Russia, the Federal Service for Supervision of Communications, Information Technology and Mass Media, Roskomnadzor, had nearly a hundred VPN apps removed from app stores since 2024, and in 2025 the country sank to its lowest ever position on the RSF press freedom index. In China, only state-approved, and therefore monitored, VPNs are permitted, shielded behind the Great Chinese Firewall. Turkey blocks entire VPN networks during protests; the United Arab Emirates does the same. In North Korea, Belarus,

Turkmenistan, Oman, and Iraq, VPNs are outright illegal.


All those regimes have one thing in common. They never describe their approach to VPNs as "an attack on the press and on citizens." They call it "protection." Against immoral content, foreign interference,

terrorism, drugs, or the protection of children. The language used to justify the restrictions is the same everywhere.


Brussels wants restrictions too.


This did not come out of nowhere in Europe. For years, Brussels attempted through "Chat Control," the proposal to have all private messages, including encrypted ones, automatically scanned for child abuse material, to create a breach in encryption.It repeatedly failed because of resistance from privacy advocates and critical member states. Yet the same motivation kept returning under a new name. In April 2025, the European Commission launched ProtectEU, the Brussels security plan that explicitly opens the door to stricter regulation of encrypted and anonymous communication tools.


In June, a roadmap followed: by 2030, law enforcement agencies must have "lawful" access to the encrypted data of citizens. Under the umbrella of the so-called Going Dark initiative, expert groups are

working on legislation that the Commission plans to propose this summer. One working group is focused specifically on data in transit. In other words: VPN traffic as well.


The ambition is clear. Mandatory registration of metadata, IP addresses, timestamps, session duration, data usage, by every online service, VPN providers included. Anyone whose business is built on the promise "we keep no logs" would thereby become de facto illegal. Mullvad, one of the best-known no-log VPN providers, has already announced it would leave the European market in that scenario. ProtonVPN called the proposal a "cybersecurity suicide mission." And they have a point: the same Europe that, through NIS2, the European law mandating stricter cybersecurity standards for essential companies and infrastructure, urges us to better protect critical infrastructure, is now preparing to force the very tools we use for that protection to dismantle their own defenses. And let us not forget that VPNs are not only used by journalists and dissidents, but also by companies, hospitals, civil servants, and infrastructure operators to work securely remotely. Weakening them directly contradicts Europe’s own legislation.


At the same time, child protection is increasingly becoming the moral lever for expanding control by Brussels. On 10 October 2025, almost all EU member states, plus Norway and Iceland, signed the Jutland Declaration on the protection of minors online. That same day, the Commission opened its first DSA investigations into Snapchat, YouTube, the Apple App Store, and Google Play. On 26 November 2025, the European Parliament adopted a resolution calling for a European "digital age of majority" of sixteen for

social media. It is a term that does not yet exist in our legal system, but Brussels is getting in its practice.


The democracies are sliding too.


And it is not only Brussels. Outside the EU, things are moving even faster. In the United States, Utah became in March 2026 the first state to explicitly include VPNs in its age verification law: under Senate Bill 73, in force since 6 May, websites remain liable even if a visitor conceals their location with a VPN, and they

are not even permitted to explain how a VPN works. The fact that enforcement has already been delayed until September following a lawsuit from Aylo, the parent company of Pornhub among others, illustrates above all how unworkable the legal knot has become. Once a ruling has been issued, I will return to this topic in a future column.


And in Australia they went even further, becoming the first country in the world to ban social media for under-sixteens as of 10 December 2025. The result? Nothing at all. Research shows that more than sixty percent of teenagers who previously had an account still have access. When policy fails, governments rarely conclude that the policy was wrong. They usually conclude that citizens should have even less room to escape it, and the Australian codes of conduct are now extending age verification to email, games, search engines, and app stores. And if even email, a digital letter, is to be forbidden for young people, are

they soon no longer allowed to receive a birthday card from their grandparents?


From protection to control.


It is, as always, not the final destination that shocks, but the slippery slope leading there. And it follows the same script everywhere. First it is "only for child protection." Then comes the bureaucracy: age verification for pornography sites, then for social media, then for VPNs, then to read the news. At the end of the chain

sits a digital identity check at every corner of the web, and the VPN that might still let you avoid it no longer has a place in a constitutional democracy.


Privacy activists are right to warn that this hollows out anonymity and data protection. The aim is to protect a large group, but as Ayn Rand once wrote: "The smallest minority on earth is the individual. Those who deny individual rights cannot claim to be defenders of minorities." Whoever places the collective above the individual, even under the guise of protection, ultimately sacrifices the smallest minority there is: the citizen with their right to privacy and anonymity. And again, do not think only of a child in the UK who wants to play

an online game, but above all of the brave citizens and journalists in Tehran and Moscow who dare to speak out and provide us with information we would otherwise never receive.


Moreover, the approach fails on its own terms. In France, a law has required age verification on all pornographic sites since January 2025. Pornhub, one of the largest in the world, blocked its French site in protest, and VPN usage shot up. But researchers warn that traffic partly shifted to smaller, less cooperative foreign sites and to social media, which, according to that same European briefing, remains an important gateway to both pornography and online grooming. And in Denmark, 94 percent of children have a social media account before the age of thirteen, despite the age limits platforms have had in their terms of service for years. Slapping a digital age of sixteen on top of that solves nothing. It merely shifts the location where people lie. On top of that, every centralised age database is sooner or later a target for criminals, foreign intelligence services, or data breaches.

For Belgium and the rest of Europe, that is particularly bitter. We have an open economy with a strong tradition of press freedom and individual rights. Yet we risk sliding along into a model in which the state determines what is "safe" and who gets access to information. Belgian journalists, activists, businesses, and ordinary citizens who take privacy seriously will ultimately foot the bill: higher costs, less innovation, and an internet that increasingly resembles a controlled intranet. The Chinese endpoint, reached via the gentle path of good intentions.


The lifeline we cut ourselves.


That same EPRS document from January this year explicitly describes VPNs as tools that in authoritarian regimes "support freedom of information and digital inclusivity, as censorship becomes harder to enforce through VPN use." The same briefing then describes how the revised Cybersecurity Act seeks to curtail that use and increasingly views it as a policy problem. Two sentences, one document, one paragraph apart. Anyone wanting to understand how a slippery slope develops in slow motion only needs to read those

paragraphs in order.


The Emergency VPN programme run by software company Surfshark has provided approximately a hundred journalists and activists in nine countries with free access since 2022, allowing them to continue their work. The same tool that we in Europe are happy to offer a journalist in Tehran or Moscow, we are making legally untenable in our own legislation.


That is not a detail. That is outright moral short-circuit. The painful question is therefore not whether these measures will catch pedophiles or drug dealers. A few, perhaps. The real test lies elsewhere. What do we do when China requests the log files of a European VPN provider for a Uyghur activist in Brussels? What do we do when a future Spanish prime minister requests the connection data of a journalist? How do we explain to an Iranian dissident that the VPN she once used is now illegal in Europe, because a Belgian teenager might otherwise watch an online sports match without showing identification?


The question is therefore no longer whether we need VPNs. The question is whether we still have enough freedom left to keep them. And the next time the European Commission condemns the Iranian regime for blocking VPNs, I sincerely hope there is someone in the room who hands it a copy of its own revised Cybersecurity Act.


Beijing, Moscow, and Tehran have known it for years: those who wish to control citizens do not begin by banning free speech, that is where it ends. It begins with restricting the means by which citizens stay in

contact with one another and can think independently. Brussels is not Tehran. But Brussels today is voluntarily taking a step in that direction, with the best of intentions written prominently across its forehead: "the protection of children." Yet history has proven to us often enough that the road to hell is paved with good intentions.


Thijs Jansen is a Dutch cybersecurity expert with experience in threat analysis and digital defense. He follows the intersection of technology and geopolitics, with a particular focus on cyber operations carried out by authoritarian regimes and other foreign actors against European governments, companies, and critical infrastructure. As a staunch defender of individual freedom and sovereignty, he combines technical insights with strategic analysis in his columns to make readers aware of the hidden digital battlefields that affect our security and sovereignty, as well as the many geopolitical dimensions of cyber threats.


Image Credits: Privecstasy via Unsplash






bottom of page