Identosphere 174: Children Online 4 articles • Video: C2PA explained • New in Privacy Law • The FCC just killed anonymous phones
Kaliya "Identity Woman" Young's newsletter about all things digital identity, self-sovereign identity and the emerging developments in the field.
Children online
Do Not Turn Child Protection Into Internet Access Control (Jaromil, Dyne)
Moderation is partly technical. Guardianship is relational, local, and situated in specific contexts.
This is the wrong solution. It treats an educational and social problem as an authentication problem.
[Book 1st 40 Pages] Age Assurance in Practice
Age assurance is not simple and it is not static. But it can be approached responsibly. This book is written for those who need to do so without illusions and without pretending that complexity can be avoided.
Age Assurance on the Internet: Identity, Privacy, and the Limits of Verification
How can someone prove they are old enough to access something—whether that means buying alcohol in person, signing up for social media, or accessing restricted content online—without exposing more personal information than necessary?
Online Platform Regulation and Children’s Rights and Safety in a Digital World.
This report provides a comparative legal analysis of platform regulation in six jurisdictions, namely Australia, the European Union (EU), India, Kazakhstan, South Africa, and the United Kingdom (UK). The analysis, reflecting regulatory developments as of June 2025, identifies emerging trends in online platform regulation and potential implications for children’s rights and safety online.
How Creators will prove thir work isn’t AI
Standards
veri-good
A Web Component for easily adding fully self-contained verification of Verifiable Credentials to any web site
(OpenID) Announcing the new Digital Credentials Harmonized Presentation Working Group
The new DCHP WG supports a joint initiative between experts of ISO/IEC JTC1/SC 17 (ISO) WG10 and WG4 and the OpenID Foundation’s Digital Credentials Protocols Working Group (DCP WG) to harmonize their credential presentation protocols.
Can Digital Trade Achieve True Singularity without creating new third party dependencies?
The UNCITRAL Model Law on Electronic Transferable Records, commonly known as MLETR, is a proposal by UNCITRAL on how legislation in all jurisdictions shall be updated for digital in the interest of creating greatest possible interoperability on the legal layer. It addresses this challenge by proposing the assertion of reliable methods to achieve Integrity, Exclusive Control, and Singularity for electronic transferable records. Together these concepts form the legal foundation for ETRs.
Considering Systems and their Development
What Issuers and Acquirers Need to Know as Biometrics Become the Payment Default
Digital wallets are taking over in-store payments; biometric authentication is becoming an everyday habit. Issuers and acquirers need to ensure their pilots boost conversion while remaining sensitive to dynamic customer spending patterns
SECOIA builds identity systmes and writes about them
𝗬𝗼𝘂 𝗰𝗮𝗻𝗻𝗼𝘁 𝗱𝗶𝗴𝗶𝘁𝗶𝘀𝗲 𝗮𝗻 𝗶𝗱𝗲𝗻𝘁𝗶𝘁𝘆 𝘀𝘆𝘀𝘁𝗲𝗺 𝘁𝗵𝗮𝘁 𝗱𝗼𝗲𝘀𝗻’𝘁 𝗸𝗻𝗼𝘄 𝘄𝗵𝗼 𝘄𝗮𝘀 𝗯𝗼𝗿𝗻, 𝘄𝗵𝗼 𝗱𝗶𝗲𝗱, 𝗮𝗻𝗱 𝘄𝗵𝗼 𝗺𝗮𝗿𝗿𝗶𝗲𝗱 𝘄𝗵𝗼𝗺.
𝗔𝘀𝗸 𝗮𝗻𝘆𝗼𝗻𝗲 𝗶𝗻 𝘆𝗼𝘂𝗿 𝗽𝗮𝘀𝘀𝗽𝗼𝗿𝘁 𝗮𝘂𝘁𝗵𝗼𝗿𝗶𝘁𝘆 𝘁𝗼 𝗱𝗿𝗮𝘄 𝘁𝗵𝗲 𝘀𝘆𝘀𝘁𝗲𝗺 𝗮𝗿𝗰𝗵𝗶𝘁𝗲𝗰𝘁𝘂𝗿𝗲 𝗼𝗻 𝗮 𝘄𝗵𝗶𝘁𝗲𝗯𝗼𝗮𝗿𝗱. 𝗧𝗶𝗺𝗲 𝗵𝗼𝘄 𝗹𝗼𝗻𝗴 𝗶𝘁 𝘁𝗮𝗸𝗲𝘀 𝗯𝗲𝗳𝗼𝗿𝗲 𝘁𝗵𝗲𝘆 𝗿𝗲𝗮𝗰𝗵 𝗳𝗼𝗿 𝗮 𝗹𝗮𝗽𝘁𝗼𝗽.
Privacy Practicalities
[Law Review Article] Against Privacy Essentialism — Daniel Solove
Foundational framing of what privacy is, why it matters, and how privacy concepts apply in the digital age — a useful anchor for everything else in this issue.
[Law Review Article] Duty of Loyalty for Privacy Law — Richards & Hartzog
Legal paper proposing a duty of loyalty framework for privacy — shifting the obligation from individuals protecting themselves to institutions honoring trust.
If You Intentionally and Severely Break Privacy... — Karel Kubicek
Post on accountability and consequences for intentional, severe privacy violations — the enforcement side of the privacy equation.
Surveillance & Repression
The FCC just killed anonymous phones.
And they’re calling it a robocall fix.
On April 30, the FCC unanimously approved requiring every telecom provider — carriers, mobile operators, VoIP services, to verify your identity before activating service. It’s known in the industry as KYC (Know Your Customer).The FCC is borrowing from banking’s anti-money-laundering playbook. They’re even asking whether carriers should retain your identity docs for 4 years after you leave and check you against law-enforcement watchlists. See also the official FCC KYC document.
How AI Is Powering Transnational Repression — Tech Policy Press
Taken together, these trends reveal a widening gap between the speed of technological change and the pace of democratic governance. Unless governments act decisively, the current policy landscape risks normalizing and enabling AI-driven TNR rather than constraining it. Responding effectively will require sustained coalition building and rigorous collaboration across civil society, academia, governments, and international organizations. It demands rights-based, community-centered approaches that prioritize those most at risk, strengthened by international, participatory oversight mechanisms capable of monitoring violations and ensuring accountability. It also requires mandatory impact assessments, meaningful transparency from both governments and technology companies, and accessible remedies for those harmed.
Data Sovereignty & AI Governance
We May Be Entering A Second Axial Age
The transition from small hunter-gatherer societies into complex civilizations gave rise to the first Axial Age. Today, the planetary polycrisis of climate chaos, mass migration, increasing warfare and transformative AI represents a rupture of comparable magnitude.
Data Problem Is Now Larger Than Human Cognition — Lara Mueller
The modern world no longer suffers from information scarcity. It suffers from informational excess. Humanity now produces data at a velocity that exceeds unaided human cognition: in short; our collective dataset is 600+ trillion pieces of civilization information and 90% of it is useless. The problem is no longer whether information exists. The problem is whether humans can operationally navigate it.
Field Guide to AI Privacy and Security — Noah M. Kenney
Free 230-page resource documenting 180+ AI/privacy/security regulations across 50 US states and 60+ countries.
The Elephant in the Room Has a Memory Problem — Greg Malpass
AI governance is missing control over what AI systems remember — organizational sovereignty over AI depends on controlling the memory layer.
Biometrics & Verification
Yoti Fined €950K — Biometrics Under GDPR Pressure — Ben Robertson
GDPR fine on Yoti biometric storage signals a shift from “Capture, Store, Reuse” to “Verify, Prove, Discard” — biometrics stay on device, identity becomes cryptographic proof.
Data Sovereignty & Security (continued)
[Paper] The Triad of Tech Sovereignty and Europe’s Package: Dependency, Openness, and Agency
We claim that viewing sovereignty purely through the lens of infrastructure ownership misses the core issue: the crucial factor is who has the power to shape, govern, and challenge these systems. Since the concentration of power is a choice, not an unavoidable outcome, merely creating new asymmetries won't solve the problem. Leveraging the principle of digital self-determination, we propose a "stewardship architecture": a nuanced framework of engagements and oversight mechanisms rooted in existing EU law. This approach would allow Europe to prioritize agency, rather than mere ownership, as the true measure of its digital sovereignty, empowering its citizens and institutions in the process.’



