Try this experiment. Go sign up for a porn site in Texas, open a new messaging app in the UK, or apply for a driver's license in an EU country rolling out its digital wallet. In every one of those cases, in 2026, you're going to be asked to prove who you are before you're allowed to do the thing. Not because you did anything wrong. Just because you showed up.Now, try a different experiment. Go find the guy running a ransomware operation out of a bulletproof hosting provider in a jurisdiction with no extradition treaty, paid in Monero, routed through three compromised VPS boxes and a stolen AWS credential. Ask him for his ID.That contrast is the whole article. Governments have spent the last decade building an impressive amount of new infrastructure to identify, verify, and monitor internet users, all justified by cybercrime, child safety, fraud, and national security. The infrastructure works great on the first guy. It does basically nothing to the second one. And that gap between who complies and who adapts is the thing nobody wants to talk about honestly.I'm not arguing that cybercrime isn't real, or that governments have no legitimate role in fighting it. They do, and I'll get into where I think that role is genuinely justified. What I'm arguing is narrower and, I think, harder to dismiss: a lot of the specific mechanisms being deployed right now don't actually target the threat model they're sold on. They target the compliant majority, because the compliant majority is the only population these systems can actually reach.The pattern, stated plainly.Look across enough of these policies and a shape emerges. It goes like this:A harm gets identified, usually a real one, sometimes a genuinely serious one. A law gets proposed that requires identification, verification, or logging as the solution. The law gets scoped broadly because narrow scoping is technically and politically harder. The verification or logging requirement gets centralized, because centralized systems are easier to build, audit, and mandate compliance for than distributed ones. That centralized system becomes a valuable target and a permanent capability, with costs that extend well beyond its original surveillance purpose. And once it exists, it tends to get used for more than the original stated purpose, because infrastructure doesn't enforce its own limits, policy does, and policy changes.Identification leads to data collection. Data collection leads to centralization. Centralization creates surveillance capability that didn't exist before. And surveillance capability, once built, has a way of outliving the emergency that justified it.None of this requires a conspiracy. It requires normal bureaucratic incentives, normal vendor lock-in, and normal mission creep. That's actually the more disturbing version of the story, because it means it doesn't need a villain. It just needs time.Case One: Mass metadata retention, and the court that said no.Start with the clearest example, because it's the one that actually got tested and struck down. In 2006, the EU passed the Data Retention Directive, requiring telecom and internet providers to retain communications metadata- who called whom, when, from where- for up to two years, so law enforcement could access it for serious crime investigations. In 2014, the Court of Justice of the European Union declared the whole directive invalid.The court's reasoning is worth sitting with, because it's basically the technical argument this article is making, delivered by a judiciary instead of a blogger. The court found that the retained data, taken as a whole, could reveal "the habits of everyday life, permanent or temporary places of residence, daily or other movements, activities carried out, social relationships and the social environments frequented" of essentially the entire population, most of whom were never suspected of anything.It wasn't limited to serious crime targets. It wasn't subject to prior judicial review before access. It didn't require the data to even stay inside the EU. The directive was, in the court's words, not "limited to what is strictly necessary."This is the "it's just metadata" argument getting demolished by a Supreme Court, not a privacy advocate. And it's worth understanding why metadata is so revealing, because the phrase "we're not reading your messages" gets used constantly to make bulk collection sound harmless.Here's a simplified version of the kind of query a retained-metadata system is built to answer:-- Simplified illustration of a "metadata only" retention querySELECT caller_id, recipient_id, timestamp, cell_tower_id, durationFROM call_metadataWHERE caller_id = '+1-555-0134' AND timestamp BETWEEN '2026-01-01' AND '2026-06-30'ORDER BY timestamp;The EU rebuilt parts of this under national laws anyway. The UK's Investigatory Powers Act still authorizes bulk communications data retention. The underlying tension never went away; it just moved to different legal vehicles.Case Two: Encryption, or the part where governments ask for something that doesn't technically exist.The UK's Online Safety Act 2023 gives the regulator, Ofcom, power to require platforms to use "accredited technology" to scan for child sexual abuse material, including, in principle, on encrypted messaging services. The catch that the government's own officials have acknowledged is that this only applies where it's technically feasible, and cryptographers have been fairly unified in saying that scanning inside end-to-end encryption without breaking it for everyone is not a solved problem.Signal's president publicly said the company would exit the UK market rather than build that capability. Apple went further in practice: in early 2025, rather than comply with a UK government demand under the Investigatory Powers Act to build backdoor access into iCloud's Advanced Data Protection encryption, Apple simply withdrew that feature for UK users entirely.That's a genuinely important data point. When pushed, one of the largest platforms on earth chose to reduce security for an entire country's users rather than build a backdoor, because there's no such thing as a backdoor that only the "right" people can use. A vulnerability introduced for law enforcement access is a vulnerability, full stop. It doesn't check IDs before it gets exploited.The EU has been trying to do something structurally similar since 2022 with its proposed CSAM Regulation, nicknamed "Chat Control" by critics, which would require detection orders capable of scanning private communications, including encrypted ones, for known and new abusive material.It has been rewritten, softened, reintroduced, and fought over across multiple Council presidencies for years, precisely because the privacy and security communities keep pointing out the same unresolved problem: client-side scanning is a general-purpose surveillance mechanism wearing a child-protection costume, and once it's mandatory infrastructure on a billion phones, what it's used to detect is a policy decision that can change without anyone rearchitecting anything.India has its own version of this privacy and surveillance fight. WhatsApp sued the Indian government in Delhi High Court over IT Rules requiring "traceability," the ability to identify the original sender of a message on request, arguing it's technically impossible to add without breaking end-to-end encryption for everyone on the platform. That case has dragged on for years without full resolution, which tells you something about how unresolved the underlying tension actually is, not just in the UK or EU.Case Three: identity as a precondition for existing online.Age verification is the fastest-growing front here, and it's the one where the "protect the children" framing is hardest to argue against on its face, because the underlying concern is legitimate. Texas passed a law, HB 1181, requiring adult sites to verify visitors' ages, typically via government ID or data broker verification.The Free Speech Coalition challenged it, and the case went to the US Supreme Court as Free Speech Coalition v. Paxton. The Court sided with Texas, moving away from the strict scrutiny that had previously protected online speech from this kind of gatekeeping and toward a more permissive standard for age-verification mandates. A dozen-plus other states have similar laws now or are moving toward them.Meanwhile, the EU finalized its European Digital Identity Regulation in 2024, requiring member states to offer citizens a digital identity wallet by 2026, usable for everything from banking to age verification to, eventually, a lot more than that. Australia has moved to require age verification for social media access for under-16s. The UK's Online Safety Act layers age assurance requirements on top of its content and encryption provisions.Here's my actual problem with all of this, and it's not "age verification is bad." It's that every one of these systems requires either a government-run identity database, a third-party identity verification vendor holding scans of driver's licenses and faces, or a data broker cross-referencing your browsing to your real identity, sitting between you and content that in most cases is completely legal for you to view. That's a new, permanent, valuable target that didn't exist five years ago, tied specifically to the kind of browsing history people have the strongest reason to want kept private.South Korea tried a version of mandatory real-name verification for internet commenting back in 2007. Its Constitutional Court struck it down in 2012, finding it barely reduced the malicious behavior it targeted while chilling ordinary speech, and in the meantime, the real-name-linked user databases at major Korean portals became exactly the kind of target you'd expect: a honeypot, breached at scale. The lesson wasn't subtle. Identity gates don't just filter access. They create a database, and databases get stolen.The asymmetry nobody likes to name.Here's the part of the argument I think actually holds up under scrutiny, more than any single case study: ordinary users and serious criminals do not respond to these systems the same way, because they don't have the same incentives or capabilities.A normal person signing up for a service will hand over their ID, because refusing means they don't get to use the service, and most people's threshold for "is this worth fighting" is low.A determined cybercriminal, running a phishing operation or trafficking stolen credentials, has every incentive to route around the exact same requirement, and often the technical means to do it: compromised or synthetic identities, infrastructure hosted in jurisdictions that don't cooperate with requests, VPNs and Tor, stolen accounts that already passed verification once under someone else's name, or simply moving operations to a platform that doesn't yet have the restriction.I want to be careful here, because it would be dishonest to claim criminals always win this race. Verification does raise costs and does catch some fraud, some account takeover attempts, some low-effort abuse. Law enforcement does sometimes get real value from retained metadata in serious investigations; that's part of why the CJEU didn't say retention itself was illegitimate, only that this particular scheme was disproportionate.The honest version of the claim isn't "these systems never work." It's narrower: the burden of these systems falls overwhelmingly on the hundreds of millions of people who were never the actual target, while the smaller population of sophisticated, motivated bad actors retains meaningfully more room to adapt than the marketing behind these laws admits. That's a proportionality problem, not a total-failure problem, and proportionality is exactly the standard the CJEU said the EU's own directive failed to meet.What happens when the "safety" infrastructure gets hit?There's a version of this risk that isn't hypothetical anymore: the surveillance and identity infrastructure itself becomes the attack surface.In 2024, US federal agencies disclosed that Chinese state-linked hackers, tracked under the name Salt Typhoon, had penetrated major American telecom carriers, including systems tied to the lawful intercept infrastructure carriers are legally required to maintain for court-authorized wiretaps. The system built so government could access communications under proper legal process became a system a foreign intelligence service could access too. That's not a slippery-slope argument. That's what happened.This is the question that "trust us, it's for safety" answers never grapple with: every centralized identity system, every mandatory backdoor, every bulk retention database is also infrastructure that has to be defended against every other actor on earth who wants what's in it, forever, perfectly, with no exceptions.Governments are not uniquely good at running secure infrastructure. Neither are the private vendors they contract age verification and digital ID out to. Concentrating sensitive data in one place doesn't just make it easier for the intended authority to access. It makes it a more attractive, more valuable, more catastrophic single point of failure for everyone else too.Taking the other side seriously.I don't think it's honest to write this without engaging the strongest versions of the counterargument, so here they are, as fairly as I can put them.Governments genuinely do have a legitimate role in fighting cybercrime that operates across their jurisdiction; that's not in dispute. But that role should remain part of a rights-based and user-centred approach to internet policy. Anonymity genuinely is abused by some fraction of bad actors, and some verification friction genuinely does reduce some categories of low-sophistication abuse.Age verification, done well, could reduce a minor's exposure to some genuinely harmful content, and that's a real value even if the current implementations are clumsy. Data retention has, in specific documented cases, helped resolve serious crimes that would otherwise have gone unsolved. Platforms do have legitimate reasons to moderate content that facilitates real harm, and "just don't moderate anything" isn't a serious policy position either.All of that is true, and none of it, on its own, gets you to "therefore the identity check has to sit in a centralized government or vendor database with unclear breach liability, indefinite retention, and no independent judicial gate before access." The gap between "this harm is real" and "this specific implementation is proportionate" is where almost all of these laws actually fail, and it's the gap the CJEU explicitly ruled on in 2014, and that keeps getting relitigated in different jurisdictions with different names.Who actually gets more powerful?So, back to the question this whole piece keeps circling. Are governments making the internet safer, or are they making ordinary people easier to monitor?The honest answer is probably both, in uneven proportions. Some of this infrastructure catches some real harm. Almost all of it also expands, permanently, the visibility governments and the private vendors they rely on have into the daily behavior of people who were never suspected of anything. And infrastructure built for one purpose doesn't stay scoped to that purpose by default; it stays scoped to that purpose only if something, usually a court, a law with a sunset clause, or sustained public pressure, keeps forcing the question.The people who get more powerful when the internet gets easier to monitor are, unsurprisingly, the people who get to query the monitoring system: the state agencies with lawful access, the platforms that now hold your verified identity alongside your behavioral data, and, when the infrastructure gets breached, whoever compromises it next. The people who get less powerful are the ones who now have to justify wanting privacy and internet freedom in the first place, when privacy used to be the default and justification was what the state needed to provide before it could take it away.Cybercriminals adapt. Ordinary users get monitored. I don't think that's the whole story, but after looking at the actual court rulings, the actual breaches, and the actual asymmetry in who can afford to route around these systems versus who just complies, I think it's more true than false, and it's true in enough places, across enough different governments and legal systems, that it stops looking like a coincidence.