17 Sep 2026
Planet Mozilla
The Mozilla Blog: Mila and Mozilla announce new initiative to build trustworthy open source AI for everyone, with Canadian government support

Today at ALL IN, Canada's largest AI and technology event, Mozilla and Mila announced a new initiative and fresh investment to build an open source AI foundation layer that enables organizations and institutions to own and operate advanced AI systems locally, ensuring full control over their technology and data.
Doubling down on its commitment to open source AI, the Government of Canada announced its support for the initiative. Mila will lead the technical delivery and coordination of the project, while Mozilla contributes technical expertise. It also provided the initial $5 million investment to kick off the project. Hypertec is committing an additional $1 million in first-year funding to accelerate initial Canadian deployments of the open source AI foundation layer on Hypertec hardware.
"Canada has a choice: depend on technologies developed elsewhere, or build more of what we need here at home," said The Honourable Evan Solomon, Minister of Artificial Intelligence and Digital Innovation and Minister responsible for the Federal Economic Development Agency for Southern Ontario. "Open source AI gives Canadian businesses and institutions greater control over their technology and data, while making powerful tools more affordable, accessible, and easier to adapt. By supporting this work, we are strengthening Canada's capacity to build and adopt AI on our own terms."
Mila and Mozilla will lead the work together: Mila drawing on a world-class community of close to 2,000 researchers and professionals, Mozilla as technical partner from industry, bringing 25 years of experience stewarding open infrastructure others build on. Mila and Mozilla are actively engaging new partners, inviting companies, research institutions, funders, governments, and developers to join and support this work.
What's being built
The goal is simple: make owning your AI as easy as renting it. Using open source models was never the hard part. Turning a raw open source model into something a small business, a hospital, a local charity, or a government can run in production - secure, reliable, plugged into everything else - takes an engineering team most organizations and institutions do not have and months they can't spare.
The goal is to offer businesses and organizations a ready-to-use AI package that they can run privately and keep under their own control, rather than having to build a complex system themselves or rely entirely on expensive, pay-per-use proprietary AI services.
For example, a small manufacturer could use the system as a private AI assistant for its employees. It could search the company's manuals, procedures, and past project files; help staff draft reports or answer technical questions; and help its software team write and improve code. Because the system is designed to be able to run locally, the company could do this while keeping its proprietary information and data within its own environment.
That also means lower costs. For the vast majority of everyday business tasks, companies will be able to use open source AI running on open source tools instead of paying a commercial provider every time an employee makes a request. But this requires reducing the technical work and expense involved in putting open source AI into practice.
This initiative was founded to solve that problem, building the free layer that makes owning open source AI easy - the same kind of layer the web was built on. It has two halves: An open standard, published as interface contracts, so any part of the stack can be swapped for a better one. And a working "reference implementation" any organization can install on its own machines or the ones it chooses, running the models and controls it chooses against its own data, with governance and access control built in from the start. The ambition is that with the standards and foundation in place, open source AI can be built anywhere, by anyone.
"Six months ago, we announced our partnership with Mozilla to advance open source and sovereign AI. Today, we are bringing that work to a whole new level," said Valérie Pisano, President and CEO of Mila. "By delivering an open, secure AI foundation layer, we empower organizations, from small businesses to non-profits to governments, to own their technological future so they can run, control, and maintain AI models themselves. At Mila, our research community has always believed that for AI to be trustworthy and accessible, it must be built on open standards that keep control in local hands."
The work already underway
Over the last six months, Mila and Mozilla have been designing the architecture, deciding which open source components belong at each layer, and testing that the whole system works end to end. This investment builds on that progress.
Working alongside Mila and Mozilla, Hypertec will help move the initiative from research and reference implementation to real-world adoption by Canadian businesses and institutions, providing a practical, private, and cost-effective path to deploy AI while maintaining greater control over their data and technology.
"AI is advancing at an extraordinary pace and has the potential to transform our economy and society for the better. Canada has an important role to play in ensuring that AI is developed and adopted responsibly, said Simon Ahdoot, CEO of Hypertec Group. "Hypertec is proud to help turn open source innovation into AI that Canadian organizations can deploy securely and under their own control. This is exactly the kind of partnership between government, research, and Canadian industry needed to realize the full potential of AI."
Why now
Mozilla's State of Open Source AI report found that while 79% of developers adding AI functionality use open models, only 53% of teams ever reach production, stopped by cost, security, integration, and maintenance. This work aims to change that.
"AI today is at a crossroads, where it could be closed and owned by a few, or open and available to every coder, developer, enterprise, and nation," said Mark Surman, President of Mozilla. That's what we're building - an open source AI ecosystem that fits together as seamlessly as the web, and that anyone, anywhere can build on. We're so grateful to Canada for scaling this work, and call on partners across sectors - from enterprises and governments to coders and startups - to join us in building this future."
Within six months, Mozilla and Mila expect to publish working reference implementations for enterprise, government and public-interest use cases. The two-year ambition is bigger: to have solved this problem outright, so that open source AI can be adopted fully and easily, anywhere, by anyone.
The post Mila and Mozilla announce new initiative to build trustworthy open source AI for everyone, with Canadian government support appeared first on The Mozilla Blog.
17 Sep 2026 7:30pm GMT
Firefox Nightly: High-speed Release Trains – These Weeks in Firefox: Issue 209
Highlights
- Firefox 155 just released! That's the first release that went through the full 2-week release cycle process.
- The WebExtensions team added a new backgrounds_area theme property so themes can explicitly control whether background images apply to the whole window or only the top toolbars
- Thanks to Emilio for the new theme property to control background image placement!
- This is targeting Firefox 156, and developer documentation will be added to MDN soon.
- The multi-context address bar for New Tab has been enabled in Nightly!

-
- There are a number of known bugs to address before this can ride. We're tentatively aiming to have this release sometime in Q4.
- Notice an issue with it? File a bug here!
- Volunteer contributor Andrew fixed a white flash for the New Tab page on startup for users that have dark mode enabled by default.
- The DevTools team has made it possible to inspect and edit stylesheets from within the JavaScript Debugger pane.

- The feature can also be enabled from the experimental section in the devtools settings panel, or by setting devtools.debugger.features.stylesheets-in-debugger to true in about:config.
Friends of the Firefox team
Resolved bugs (excluding employees)
Script to find new contributors from bug list
Volunteers that fixed more than one bug
- :Benjamin Peterson
- ExplodingJoysticks
- Gopalarathnam Venkatesan
- Khalid AlHaddad
- Lukáš Lipinský
- Chris Van Linden
New contributors (🌟 = first patch)
- 🌟 Amadi: Update comments that point at the removed openUILinkIn function
- 🌟 dchen705: Remove unnecessary module import in browser/components/urlbar/tests/browser/head.js
- Ekerin Agboola: Remove old documentation related to the removed SEARCH_SUGGESTIONS_LATENCY_MS histogram
- ExplodingJoysticks:
- Gopalarathnam Venkatesan:
- 🌟 Andrew: White flash on startup caused by abouthome_cache storing incompatible startup frame
- 🌟 Kana: browser_privatebrowsing_resetPBM.js awaits an array instead of Promise.all, so the tab-close wait does nothing
Project Updates
Add-ons / Web Extensions
- As part of Nova about:addons work:
- Restyled the Extensions panel empty states to match the Figma specs, including a new illustration for the disabled add-ons and private browsing states - Bug 2058450
- Fixed a jiggle effect when scrolling through theme previews in about:addons - Bug 2059917
- Added spacing between message bars and their sibling elements in the about:addons page (empty state promo, theme appearance mode control) - Bug 2066436
- Set focus on the extension permissions prompt dialog so keyboard users can reach it - Bug 2059855
- Removed activeAddons/activeTheme/activeGMPlugins from the legacy telemetry environment, now collected only through Glean - Bug 2055613
DevTools
- Nicolas Chevobbe [:nchevobbe] fixed an issue in the inspector to stop showing the HTML editor for nodes (e.g text or whitespace nodes) which should not be editable when F2 is pressed. (#2064213)
- Sebastian Zartner [:sebo] updated the documentation for the Rules view to include details around the @media emulation panel added some weeks back. (#2063851)

- Chris Van Linden fixed an styling issue in debugger editor file search bar where the button hover background overlapped the focus outline (#2063466)
- Nicolas Chevobbe [:nchevobbe] fixed an a11y issue where the keyboard focused sliders in the fonts panel did not have the correct contrast against the background. This allows keyboard users to easily see which control currently has focus. (#2062576)
- Hubert Boma Manilla (:bomsy) added telemetry to track the usage of styles sheets shown in the debugger (#2060500)
WebDriver
- Khalid AlHaddad improved Marionette and Remote Agent to quit Firefox with a custom error code when they failed to start their server.
- Khalid AlHaddad updated the moz:debugging module to properly handle nested pauses.
- Sameem updated the handling of user contexts to clean up the settings set per a user context (e.g., proxy settings or accepting of insecure certificates) also when a user context is removed outside of WebDriver BiDi.
- Henrik Skupin updated the WebDriver:GetElementTagName command to return the element's qualified name.
- Henrik Skupin improved the Perform Actions command in both Marionette and WebDriver Bidi to dispatch intermediate events at more precise intervals when duration is greater than 0.
- Alexandra Borovova updated the "browsingContext.startScreencast" command to handle a screencast file creation on operating systems that don't have a dedicated download folder.
Lint, Docs and Workflow
- The TypeScript linter has been promoted to tier-2.
- There is no automation for the core type updates yet.
- However, several areas have been working on support, hence the promotion to tier 2.
- Until we get the automation in place, we will not be ready for wider roll-out, as it will be more likely that core patches will break the TypeScript reporting.
New Tab Page
- Developer experience improvement: it's no longer necessary to create the WebPack bundles when updating New Tab JSX / SCSS files. This occurs automatically during the ./mach build [faster] step. Thanks to Nathan Barrett for his work there!
- Mike Kaply made it so that New Tab Settings honor Locked Preferences in policy by making the New Tab settings UI read and respect policy-locked preferences and disabling corresponding controls so managed/enterprise users cannot override locked prefs from the settings surface.
- Mike Conley landed a patch to address potential shutdown hangs / crashes when newtab trainhop XPIs are in the midst of being downloaded during a shutdown.
- Irene Ni made it so that we always show an add shortcut button for New Tab shortcuts when hovering the outside edge of the shortcuts area

- Irene Ni fixed some <hr> seperators that were leaking out of some containers by scoping the HR rules to the briefing-card container.
- Reem Hamoui added missing alt text/ARIA labels to the New Tab Page weather widget, restoring screen‑reader semantics for weather images in the NTP widgets.
- Jack Brown added scroll100 and scroll250 boolean metrics to the newtab ping to capture 100px/250px scroll‑depth thresholds for analytics-this is a telemetry/schema change with no UI impact.
- Scott Downe created the 'spaces' content layout variant for the New Tab Page, introducing an alternate DOM/CSS layout for Spaces that changes tile/content rendering and is gated by the Spaces rollout flag/pref.
- A Stocks widget is in-flight, starting with the US market

-
- Nina Pypchenko [:nina-py] added a Markets/Watchlist dropdown to the Stocks widget on New Tab so users can switch views in-place; the dropdown selection is persisted in the widget state.
- Nina Pypchenko [:nina-py] let users add default tickers to their Stocks Watchlist so new or reset users see a curated set of tickers and the add-flow now persists defaults to the watchlist storage.
- Nina Pypchenko [:nina-py] added a small size to the Stocks New Tab widget, introducing a compact 1×1 Stocks tile in the Firefox New Tab Page layout so users on narrow windows or dense NTP configurations can keep Stocks visible without consuming medium/large slots.
- Nina Pypchenko [:nina-py] updated the Stocks widget feed to fetch data for individual stock tickers, changing the widget network layer to per-ticker requests so added symbols get independent, timely updates and per-symbol errors are surfaced instead of breaking the entire feed.
- Nina Pypchenko [:nina-py] added ticker search to find and add individual stocks, adding a search/lookup UI and add flow that calls the ticker lookup API and updates widget state/local storage so users can search, add, and immediately see new symbols on their New Tab Page.
- Bryan Olsson added a plural selector to the Fluent string newtab-stocks-watchlist-full in the New Tab Page localization so the Stocks widget shows correct singular/plural wording for watchlist sizes across locales, fixing grammar that could confuse users when their watchlist count changes and touching the NTP stocks string bundle used by all localized builds.
- We've also started rolling out an experimental Privacy widget

-
- Reem Hamoui changed the Privacy widget copy color to grey in the New Tab Page so the "Nightly blocks trackers as you browse. You will see them here." text displays with correct muted contrast (2063205).
- Reem Hamoui restored the ETP OFF state rendering in the New Tab Page privacy widget so the widget shows the actual ETP OFF status instead of misleading 'blocks trackers' copy for users who disable ETP (2063525).
- Reem Hamoui applied UX fixes to the New Tab Page privacy widget to correct alignment, labels, and click-targets so users see and interact with the widget reliably and accessibility attributes behave as expected.
- Reem Hamoui fixed the blocked-tracker count not updating after opening a new tab by ensuring the tally is recomputed on tab open (cache invalidation + UI binding refresh), restoring accurate tracker numbers in the widget.
- We've also started tinkering with some new layout variants
- Here's one such layout (widget column on left):

-
- Irene Ni updated SectionsLayoutFeed's 7-double-row-2-ad fallback to match Remote Settings so feed layout and ad fallback counts align with remote config, reducing layout mismatches and incorrect ad placements in feeds using the fallback (2063684).
- Irene Ni implemented a carousel card type for the New Tab feed, adding slide-based card rendering and navigation hooks so users get swipeable/rotating cards in the carousel component.
- Irene Ni deduped impressions for a carousel slide that cycles back into view, preventing duplicate impression pings when a slide reappears and improving the accuracy of telemetry/ad metrics.
- Dre cleaned up orphaned wallpapers in the wallpaper service to remove broken entries and reduce wasted storage so users no longer see missing background tiles.
- Dre uploaded new wallpaper assets to match updated margins so backgrounds render without cropping or misalignment under the new NTP layout.
- Nina Pypchenko [:nina-py] fixed wallpaper attribution rendering in the Nova New Tab flow by adjusting the Nova-specific NTP component's conditional rendering (CSS/JS) so the attribution node is not skipped when the nova feature is enabled, restoring photographer/credit metadata on New Tab pages for users on Nova-enabled desktop builds and preventing missing attribution UX.
- We're in early days in building out the infrastructure for a Recent Searches widget
- Nina Pypchenko [:nina-py] added a blank widget scaffold to the New Tab Page widget registry for the Search team (bug 2065011), creating a no-op/placeholder widget registration hook so the Search team can iterate on experiments without changing current NTP visuals - no immediate visible impact for end-users until the widget is populated.
- Dão Gottwald fixed an unscoped panel-item::part(button) rule that stripped the icon slot from panel-items it didn't own, restoring missing icons in New Tab panels and preventing blank/empty buttons in the UI.
- Maxx Crawford added support for auto-minimized the New Tab widgets section after a short delay, closing expanded widgets automatically to reduce visual clutter and accidental persistent open state.
- Irene Ni implemented the Topic Navigation Strip V1 in the New Tab Page, adding a horizontal topic-nav UI in the New Tab (top-sites/topics area) that improves discoverability and lets users switch topic feeds faster.
Picture-in-Picture
- Pier Angelo Vendrame made the document PiP video size spoofable under resist fingerprinting.
- Lukáš Lipinský fixed WebVTT tracks failing to display after opening a PiP window.
Search and Urlbar
Nova UI refresh
- Drew and Daisuke continued polishing the urlbar experience in Nova.
- Bug 2067360, Bug 2063170, Bug 2063167, Bug 2063127
Suggest
- Drew fixed alignment of the explanation text on various result types. Bug 2063460
- Drew enabled more providers (like Wikipedia) for DE, FR, IT regions. Bug 2064557
- Drew updated important dates suggestions for 2027 in DE, FR, GB, IT and US regions. Bug 2064437
- Dao fixed a regression with the result menu being empty on certain results. Bug 2066758
Adaptive autofill
- James is analyzing results of experiments and working with Product to let the feature ride to Release in the near future.
Quick actions
- Dale improved the Open Firefox Labs action. Bug 2063849
- Dale improved styling of disabled actions. Bug 2056488
Multi Context Address Bar
- Dao and Moritz made great progress with having the urlbar code work in different contexts, including across processes.
- Dao migrated some text input context menus (address bar, search bar, Thunderbird compose subject) onto a single shared menu with a new custom-item API, allowing removal of the legacy moz-input-box component.See EditContextMenu for documentation and usage. Bug 2064369.
- Dharma started refactoring the urlbar code to use extended classes. Bug 2064728
- New tab search bar has been enabled in Nightly! Bug 2062212
- The uipc variant of urlbar tests is now tier1, failures will be backed out.
Other notable Address Bar fixes
- Dao made tabbing from the urlbar field focus the search field, if present on the toolbar, instead of the search button inside it. Bug 2009628
- Daisuke addressed an issue where an autofilled URL was ignored just after launching Firefox. Bug 2057763
- Moritz fixed a regression causing undo to no longer work in the urlbar. Bug 2061633
- Moritz fixed a regression with the placeholder text in the urlbar showing garbled characters. Bug 2063779
Search
- Mark added support for POST search engines to the contextual actions in the urlbar. Bug 2064047
- Caleb fixed an accessibility issue in the add search engine dialog. Bug 2041438
Places
- Caleb fixed a bug where moving a group of folders could move some bookmarks out of their parent folder. Bug 2044707
17 Sep 2026 5:14pm GMT
Mozilla Open Policy & Advocacy Blog: Pragmatic principles for more rights-respecting age assurance architectures
This is the second part of a two-part series in which we explore approaches to protecting children online while safeguarding privacy, security and the open web. Part one covers our concerns regarding age gates, and suggests alternative policy proposals that address the root causes of online harms. Part two explores better ways to build age assurance architectures that respect users' rights and autonomy.
Across the world, legislation to introduce age gates and social media bans is proliferating. Many governments are still considering age restrictions a straight-forward and cost-effective tool to achieve their child safety goals. However, evidence is mounting that age assurance mandates pose risks to users' privacy, security, free expression and access to information, threaten the open web and competition, and undermine policymakers' goals: enabling young people to have safe and trustworthy experiences online, while enabling the digital economy to grow.
As we have said before, we believe that blunt tools like social media bans are overly broad, undermine users' rights and do not address the root causes of online harm. Reducing risks to young people online requires a holistic, privacy-first approach to online harms emphasizing enforcement of existing rules, addressing harmful design, and equipping all users with better defaults, more choice and granular controls over their experiences online.
Age gates alone are insufficient to address online harms, but age signals can contribute to more holistic approaches by helping achieve age-appropriate experiences online. Where age assurance obligations are considered as one tool out of many to foster age-appropriate experiences, their potential benefits must be balanced against their negative implications for users' privacy and security, access to services, and the openness of the web.
From the service to the device - taking stock of regulatory models
Implementing age assurance is not a single intervention, but a series of steps. A user's age is first assessed, which can happen through a variety of sources of age information and with varying degrees of accuracy. That signal is secondly shared with the actor responsible for age-appropriate experiences, and thirdly acted upon or enforced by that actor.
Dominant approaches to age assurance obligations focus on online platforms - given that this is where many risks encountered by young people unfold. In practice, this has led to online services - websites or apps - turning to third-party age assurance providers to perform age assurance, whether through biometric age estimation, age inference based on users' behavioral data, ID-based checks, or other methods.
In this model, third-party age assurance companies both assess users' ages and share that signal with the platforms responsible for implementing it. To retain access to social media platforms, messaging services and many other online offerings, users are thus forced to surrender their sensitive personal data to these age brokers, often a different one for each service.
Once in the hands of these providers, peoples' data is at risk of being sold, repurposed or accessed by law enforcement. The recent data breach of a ID and age verification provider that exposed more than 153 million IDs underscores that this is not a theoretical concern, but a significant risk for anyone asked to prove their age online. Rather than being asked to trust companies, some of which have already been exposed for their harmful data practices, people deserve verifiable guarantees that their data is safe and secure.
Emerging regulatory models are considering the role that device intermediaries, like operating systems, device manufacturers, and app stores, can play in age assurance. In such models, these actors are either required to communicate an age signal to the actor responsible for acting on it, or to restrict access to services themselves, based on an age signal created at the device level.
Device intermediary focused approaches, too, come with significant challenges: Given the significant concentration of power among (mobile) operating systems and app stores, such a legislative design can easily further entrench the dominance of Apple and Google, disadvantage open source competitors, and undermine users' privacy and control, including over their devices. These implications must be carefully mitigated.
Principles for better age assurance architectures
Every approach to age assurance comes with important trade-offs, and we maintain that there is no age assurance system that mitigates all risks to users' fundamental rights, access to services, competition and the open web, while being effective in avoiding every instance of under-age access. However, we do believe that better age assurance architectures are possible. In many situations, unverified age signals may be sufficient to provide age -appropriate experiences without undermining fundamental rights. Where stronger assurances are considered necessary, zero knowledge architectures can help protect users' privacy.
Better age assurance architectures must be private, secure, accessible to all users, and, crucially, must provide them with autonomy, choice and control. Designing age assurance obligations that live up to these values is a question of governance, not technology. Hence, policymakers have a crucial role to play in defining requirements for rights-respecting age assurance systems.
1. Assign responsibilities deliberately.
From people's devices, to operating systems, app stores and websites or apps, many actors can be involved in age assurance processes. Some of these actors will be better suited to be responsible for certain steps of age assurance processes than others to avoid negative outcomes for fundamental rights and the open web.
Given that websites and apps know most about their services, their features and content hosted, we argue that they are in the best place to act on age signals to provide age-appropriate experiences. Implementing age signals at this level allows for more granular choices for creating age appropriate experiences. Other actors, like network operators or device vendors, simply do not have the necessary information.
While websites or apps are best placed to create age appropriate experiences, device intermediaries like operating systems are well-placed to facilitate the privacy-preserving sharing of age signals created locally. Moving age assessments to the device-level allows users to interact with an age provider once, rather than having their age assessed by a different age provider for every service they use. If such approaches are pursued, strong protections need to be in place for open source operating system providers, as well as mandates for the development of open and free standards to avoid fragmentation and competition harms, and to strengthen transparency and user consent
2. Ensure choice, equity and accessibility.
Age can be attested to, approximated or verified in many ways. Every age assessment method comes with important trade-offs, but people should not be forced to take risks on their personal data and safety to retain access to services and information. Users should thus always have a choice between multiple age providers that are privacy-preserving, non-discriminatory and accessible. This is especially important for young people who often don't have access to more privacy-preserving age assurance methods, and are expected to hand over their biometric data to stay online.
The question of which providers are deemed trustworthy enough to participate in such a system is a crucial one. Policymakers must ensure that the options available to people protect their privacy and security, and that a diverse list of providers prevents people from being locked out. Only if everyone has the ability to access age assurance systems through privacy-preserving and rights-respecting providers, will the web remain accessible and open. People should be able to rely on a plurality of institutions, government or private, that can either attest to their age, including face-to-face, or have existing knowledge of their ages that they can share through the use of anonymous credential technology. Examples might be banks, public health and educational institutions, libraries, or services like phone providers, ISPs, subscription services or other services that are able to attest to a user's age.
3. Put people in control.
We should always be in control over what information is shared about us, and to whom. Once an age signal is created, age assurance architectures should empower users to hold that signal - in the form of a credential - on their device. Whether an age signal is shared with an app or website by the operating system or the browser, users must be in control of the decision whether and to whom that information is shared with.
Users must also retain control over - and trust in - their devices. Digital devices are the interface through which we all navigate increasingly large parts of our lives; they are our trust anchors. Enforcing restrictions at the device level on what people can or cannot do online would undermine the already fragile trust relationship between the two - pushing people toward less secure workarounds, rather than addressing the underlying policy concern.
This means that it is best when responsibility for sharing the results of age assessments is performed by users and their devices.
4. Assess risks end-to-end.
Many jurisdictions require age assurance systems to be "highly effective". We believe that the effectiveness of an age assurance system should be considered end-to-end, and not be limited to the assessment step: After all, where an older relative or friend is willing to help a child circumvent a block, no technical mechanism can be effective.
Given these considerations, we think there is value in considering age assurance approaches that empower parents to attest to their child's age when setting up their device. Coupled with barriers to resetting the age once set, such an age signal would provide a high degree of confidence without requiring invasive proofs of age through biometric analysis or ID document checks. As noted above, such approaches need to ensure that age attestation is not another factor cementing the dominance for a few actors, and that open source projects are meaningfully protected from being locked out of participating in a market.
Despite those challenges, we believe that it is crucial to not only consider the potential risks young people could encounter online, but also the risks flowing from age assurance systems themselves. Given those risks, parental age attestation can be a lower-risk approach suitable in many contexts.
5. Leverage zero-knowledge architectures.
Where high-assurance age credentials are used, zero-knowledge architectures are the right step towards sharing age signals in a privacy preserving way. Such approaches allow users to verify the truth of a statement about them, like their age or age range, without having to reveal the information on which the statement is based.
While zero-knowledge architectures are promising, they do not solve every issue. Beyond limiting disclosure of information about people (such as attributes other than their age), hiding the issuer of age credentials (like a bank, public service or educational institution) is key to preserving users' privacy and choice of assessment methods. This prevents discrimination against users of smaller or less common age providers.
Likewise, the issuer of an age credential should not know which service or feature someone is accessing with an age proof. The example of Spain's Catera Digital, or "porn passport", shows why: The Spanish age verification system created tokens that the verifying authority could use to infer a user's browsing history, undermining users' privacy, trust, and ultimately the adoption of the system.
Zero-knowledge proofs themselves also do not prevent abuse of age information, such as by using age data in ad targeting. Beyond strict prohibitions on repurposing age data, we believe that any age assurance system should be open source to facilitate trust, accountability and transparency.
To prevent the sharing of age tokens, we believe rate limits, which restrict how often an age token can be used, are the best and most effective solution. We strongly caution against linking tokens to attested hardware, such as trusted platform modules (TPMs). Hardware-bound tokens force users to use specific, approved hardware. Hardware attestations can leak details about the device's configuration and location, thus enabling tracking or unjustified discrimination at the moment of certification issuance. Attestations undermine users' freedom over their own devices, including what software they can install and run. People who run older or unsupported devices might be excluded as old, weak hardware is routinely found to be compromised, such that it needs to be revoked. Rate limits offer a far simpler and more robust answer to these challenges.
6. Don't break the internet.
The open internet - and the web built on top of it - is a global public resource that millions depend on every day, and that has become a cornerstone of our societies. This openness thrives on open standards, shared protocols, and interoperability. Age checks risk fragmenting the web in more ways than one: Incompatible requirements will create a patchwork of age-gated communities, and age gates in the hands of a few will push people further into closed ecosystems, undermining the wider digital competition and the decentralization that gives the internet its strength.
To avoid the hollowing out of fundamental rights online, and the undermining of the open internet, international collaboration and free and open standards are urgently needed to govern age assurance across borders.
***
We believe the principles set out above can help mitigate the large-scale erosion of privacy, security, and agency that the first wave of age assurance laws and social media bans has introduced.
But improved legislative mandates and technical fixes alone are not enough to improve young people's online experiences in a rights-respecting way. Enabling young people to develop positive relationships with digital technologies is foremost a societal issue, not a technical one. Changing norms around how we engage with technology, what we ask of companies seeking our attention, and how we have conversations about what safety means beyond abstinence and control will require a whole-of-society approach to digital well-being.
The post Pragmatic principles for more rights-respecting age assurance architectures appeared first on Open Policy & Advocacy.
17 Sep 2026 10:08am GMT