The Kids Online Safety Act requires age verification. Age verification requires identity verification. Identity verification requires a government-linked digital ID system that logs every adult who accesses the internet. On February 10, 2026, 40 state and territory attorneys general asked Congress to build exactly that, and they framed it as protecting children.
The National Association of Attorneys General (NAAG) published a bipartisan letter urging Congress to advance the Senate version of KOSA over the House version, H.R. 6484. The coalition spans red and blue states. Tennessee Attorney General Jonathan Skrmetti and Pennsylvania Attorney General Michelle Henry Sunday both issued individual statements backing the push. Their core objection to the House version: it preempts state laws, weakens the duty of care platforms owe to minors, and strips states of enforcement authority they have already built. The Senate version preserves all of that. On paper, this is a fight over federalism. In practice, it is a fight over who controls the surveillance apparatus that age verification will create.
What Age Verification Actually Requires
No one in this debate is being honest about the technical implications. To verify that a user is over thirteen, or sixteen, or eighteen, a platform needs proof. Not a checkbox. Not a self-reported birthday. Proof. That means a device-level verification system tied to government-issued identification. A driver’s license scan, a passport upload, a biometric check, or a third-party identity service that cross-references your face against a government database.
Every one of those mechanisms creates a record. Someone, whether it is Apple, Google, a third-party age verification vendor, or the platform itself, now holds a verified link between your real identity and your online activity. Multiply that across every website, app, and platform subject to KOSA’s duty of care provisions, and you have not built child safety. You have built a national digital ID system with surveillance capabilities that would make any intelligence agency envious.
The Electronic Frontier Foundation flagged this trajectory in their 2025 year-end review, titling it “the year states chose surveillance over safety.” Multiple states passed age verification laws in 2025. The pattern is identical everywhere: invoke children, mandate ID checks, create infrastructure that applies to all users regardless of age. The bipartisan nature of the NAAG letter only reinforces the point. This is not a partisan project. Both parties want the infrastructure. They just disagree on who gets to operate it.
The Playbook Is Global
This is not an American invention. Vietnam shut down millions of bank accounts that failed to complete facial verification requirements, using financial access as leverage to force citizens into biometric databases. Australia moved to ban minors from social media entirely, a policy that requires age verification for everyone to determine who qualifies as a minor. The logic is circular by design: to protect some users, you must identify all users.
The domestic version adds another layer. Companies like Flock Safety are already selling drone and camera surveillance systems to private businesses and municipalities, normalizing persistent monitoring as a public good. KOSA’s age verification mandates would extend that normalization into every digital interaction. The physical world gets license plate readers. The digital world gets ID checkpoints.
The strongest rebuttal is that children are genuinely harmed online and legislators have an obligation to act. Social media platforms have failed to self-regulate. Internal documents from Meta, TikTok, and others have repeatedly shown that these companies understood the damage their products caused to minors and chose engagement metrics over safety. The attorneys general are not inventing a crisis. They are responding to one. Privacy-preserving age verification methods do exist in theory: zero-knowledge proofs, on-device age estimation, token-based systems that verify age without transmitting identity. The Senate version of KOSA does not mandate any specific verification technology, which leaves room for implementations that protect both children and privacy. Dismissing the entire effort as a surveillance plot risks abandoning children to platforms that have proven they will not protect them voluntarily.
That rebuttal deserves serious weight, and it has a structural flaw. The privacy-preserving technologies it relies on do not exist at scale. No major platform has deployed zero-knowledge age verification. No government has certified an age estimation system that does not create identity records. The theoretical possibility of privacy-safe compliance does not change the practical reality: every age verification system deployed so far has required identity disclosure. Legislation built on technology that does not exist yet is legislation built on trust. And the entities asking for that trust, state attorneys general and federal legislators, have not earned it on surveillance questions.
The bipartisan consensus here is the tell. Forty attorneys general from both parties cannot agree on anything except expanding the power of the state to monitor digital activity. That should tell you everything about what this is actually about. Child safety is real. The kids are genuinely being harmed. But the solution being proposed is not proportional to the problem. You do not build a national digital ID system to keep a thirteen-year-old off Instagram. You build a national digital ID system because you want a national digital ID system, and “protect the children” is the one argument that makes it politically impossible to oppose.
What This Means for Everyday People
If the Senate version of KOSA passes, platforms will need to verify user ages. That means you will be asked to prove who you are before accessing services you currently use anonymously. The verification might be a license scan, a face check, or a third-party service. Regardless of the method, the era of pseudonymous internet use moves closer to ending.
The infrastructure does not come with an expiration date. Once built, digital ID systems expand. They get applied to new contexts. They get shared across agencies and jurisdictions. The system designed to keep a thirteen-year-old off Instagram becomes the system that verifies your identity for every digital interaction. Forty attorneys general just asked Congress to lay the foundation. Whether you trust the people who will build on it next is a question worth answering before the concrete sets.
For inquiries and analysis contact laterstack@proton.me
By the time 2025 ended, the illusion of stability was gone. Not because of one single collapse, but because nearly every system we interact with began behaving more honestly, if not more recklessly. Technology, finance, culture, and governance stopped pretending they were aligned with the public interest and started acting in ways that exposed their real incentives.
This was the year when the gap between how things are marketed and how they actually function became impossible to ignore.
Across every category Laterstack covers, the same pattern repeated. Speed over safety. Growth over trust. Automation over accountability. And a public that is slowly realizing it has been participating in systems it no longer understands or controls.
What follows is not a highlight reel. It is a map.
Technology Stopped Feeling Neutral
In 2025, technology finally lost its last claim to neutrality. AI tools moved from novelty to infrastructure. They quietly embedded themselves into hiring systems, creative pipelines, customer service, surveillance tools, and financial decision making.
The problem was not that AI existed. It was that it became untraceable. Companies stopped clearly disclosing when it was used. Awards bodies struggled to define what counted as acceptable use. Developers admitted that AI tools were already baked into workflows long before public conversations caught up.
The result was confusion and mistrust. Not because people rejected technology, but because they were no longer sure who was making decisions. When a system fails and no human is clearly responsible, accountability evaporates.
This year showed that convenience scales faster than ethics.
Cybersecurity Became Personal
Data breaches in 2025 were no longer abstract. They were intimate. Search histories. Viewing habits. Location data. Internal employee communications. Entire lives reduced to databases and then passed around as leverage.
What stood out was not just the volume of breaches, but the normalization of them. Companies issued statements. Regulators promised reviews. Users were advised to reset passwords and move on.
At the same time, governments expanded surveillance quietly. Employee monitoring increased. Border technologies became permanent. Drones, analytics platforms, and internal tracking tools moved from pilot programs into standard operations.
The line between protection and observation blurred. Many people did not notice it happening. That was the point.
Startups Learned Capital Has a Shorter Memory Than Hype
2025 was brutal for startups that required massive infrastructure, long timelines, or regulatory patience. Battery swapping. Autonomous logistics. Climate hardware. Ambitious platforms that once raised hundreds of millions quietly filed for bankruptcy.
The lesson was not that innovation failed. It was that venture capital rewards narrative far longer than viability. Once market conditions tightened and incentives shifted, many companies were left without a path forward.
Meanwhile, smaller and less visible startups thrived. Tools that solved narrow problems. Services that operated in legal gray areas. Platforms that scaled first and dealt with consequences later.
It became clear that the future belongs less to vision and more to adaptability.
Finance and Gambling Drifted Into the Same Space
Prediction markets, crypto casinos, and financialized gaming expanded rapidly in 2025. Often faster than regulators could respond. Often faster than users understood the risks.
These platforms did not advertise themselves as gambling. They framed participation as insight, forecasting, or strategy. But the mechanics were familiar. Risk was abstracted. Losses were individualized. Profits were centralized.
What made this year different was the confidence. Companies no longer acted like they were pushing boundaries. They acted like boundaries no longer mattered.
This was not deregulation. It was enforcement lag. And it created a new digital frontier where speed determined legitimacy.
Culture Fragmented, Then Hardened
Online culture in 2025 did not just fracture. It calcified. Algorithms rewarded outrage, certainty, and repetition. Nuance became expensive. Long form thinking felt foreign.
At the same time, distrust of institutions deepened. Media. Tech companies. Governments. Even creators. Every entity was assumed to have an agenda, usually financial.
Yet people still searched for meaning. That tension defined the year. A desire for clarity paired with systems designed to obscure it.
This is why subtlety matters now more than ever. People resist being told what to think. But they are still capable of noticing patterns when space is created for them to connect the dots themselves.
What This Meant for Everyday People
For most people, 2025 felt exhausting rather than explosive. Systems did not collapse overnight. They eroded quietly.
Jobs became more automated but less secure. Privacy became conditional. Entertainment blurred with monetization. Participation increasingly meant exposure.
The common thread was that choice remained, but clarity did not. And without clarity, consent becomes performative.
Recognizing that is the first step toward reclaiming agency.
Where Laterstack Fits Into 2026
Laterstack exists to slow the scroll. To connect stories that are usually siloed. To treat readers like adults who can hold competing ideas without needing a conclusion handed to them.
If 2025 showed us anything, it is that understanding the world now requires synthesis, not speed.
Related Laterstack Stories
A rare breach inside China’s cyber ecosystem has exposed a detailed archive of hacking tools, stolen data, and government linked operations. Around 12,000 internal documents from KnownSec, a long running contractor for state agencies, appeared online this week and quickly drew global attention.
The leak was first posted on a Chinese language blog before spreading to Western researchers. The files outline a catalog of remote access Trojans, data extraction programs, and surveillance utilities. They also include a list of more than 80 targets the contractor claims to have infiltrated.
Among the reported data sets are 95 GB of Indian immigration records, three terabytes of call logs from South Korean telecom provider LG U Plus, and hundreds of gigabytes of planning data from Taiwan. The documents also appear to reference direct contracts between KnownSec and Chinese government bodies, removing any ambiguity about who the work served.
An uncommon look inside a closed system
China’s intelligence network has avoided anything resembling a Snowden style exposure. For analysts, any glimpse into the tools and priorities of its contractors is unusual. The KnownSec leak offers evidence of broad regional surveillance and points to an organized system for harvesting and analyzing large data troves.
Researchers say the archive reinforces what many suspected. China continues to rely heavily on private security companies to carry out offensive operations. These firms operate quietly in the background, giving the government distance while providing technical reach.
AI takes a darker turn
The leak follows another notable disclosure this week. Anthropic reported detecting a China linked hacking group using its Claude platform to write malware, analyze stolen files, and prepare intrusion tools. According to the company, the campaign relied on minimal human oversight and attempted to mask its activity by framing all requests as defensive research.
Claude eventually stopped the activity, but not before the group breached four organizations. Even with the low success rate and some hallucinated data, the campaign marks a turning point. State operators are beginning to test how far AI can automate intrusion work.
Growing pressure across the security landscape
The KnownSec leak lands during a year already marked by layoffs, consolidation, and rising tensions in the cybersecurity world. Several major firms have downsized as they shift investment toward automated detection and large scale AI systems.
What remains clear is that governments and contractors are accelerating their offensive capabilities at the same pace. The tools are faster, the targets broader, and the lines between state and private actors increasingly blurred.
For researchers and defenders, the leak is both a warning and an opportunity. It exposes methods that were never meant to be seen and offers a brief window into operations usually sealed behind thick walls.
Related Cybersecurity Stories on Laterstack:
Cybersecurity firm Deepwatch lays off staff as AI reshapes the industry
12 Steps to Better Cybersecurity in 2025