Being of legal age is not enough to bypass the French restriction on Pornhub. Under the blocking system implemented by Aylo, the platform’s owner, the site relies on the user’s geographic location rather than their age. An adult may therefore be blocked before even having the chance to prove they are of legal age.
This situation creates a tension between two legitimate requirements: protecting minors and allowing adults to view legal content without revealing their identity or private habits. Everything then depends on how age is verified, what information is shared, and which entity is entrusted with this responsibility. A VPN comes into play at the end of this story: it can change the conditions of access, but leaves these questions entirely unresolved.
A Voluntary Shutdown, Under Legal Pressure
On June 4, 2025, Aylo suspended access to Pornhub, YouPorn, and RedTube from France. For these platforms, this was not a block enforced by internet service providers at the regulator’s direction. The group chose to deny French connections rather than implement the age verification system it opposed. Its public statement also announced a campaign aimed at raising awareness among internet users about French policy.
France’s objective is different: to require the services in question to distinguish between adults and minors before granting access to content. The SREN Act of May 21, 2024, strengthened Arcom’s powers, establishing technical guidelines, penalties, and the ability to request the blocking of services that fail to meet their obligations. The decree of February 26, 2025, extended the measures to certain service providers based in other European Union member states.
Legal back-and-forth explains the changes in access during the summer of 2025. After a temporary reinstatement in June, Aylo reinstated the restriction in July. On July 15, the Council of State refused to suspend the decree, citing a lack of demonstrated urgency. It noted that the measure did not prohibit adult content. However, this interim ruling did not resolve the legality of the decree on its merits: maintaining an obligation during litigation does not settle all the issues it raises.
On June 16, 2026, the Court of Justice of the European Union clarified the scope of a Member State’s authority to intervene with regard to services established in another EU country. It distinguishes between general obligations—which it opposes in this context—and measures targeting a specific service, which are permissible under certain conditions. The case concerned the French regulatory framework prior to the SREN Act: it neither automatically validates nor invalidates the rules adopted since then.
European pressure is also being exerted through another channel. In its preliminary findings of March 26, 2026, the Commission found that Pornhub and three other platforms do not sufficiently protect minors under the Digital Services Act (DSA). This is a separate proceeding—still in the adversarial phase at this stage—and not a final sanction. Age verification is therefore no longer just a one-on-one battle between Aylo and France.
Proving You’re of Legal Age Without Giving the Site Your Name
The most immediate concern involves the link between a person’s identity and their viewing of intimate content. Submitting a document to access sexual content may raise fears that a data breach (and there are many!) could one day allow the two to be linked. This concern warrants a precise technical response, even when the purpose of the verification appears justified.
The French regulatory framework does not require pornographic websites to maintain a database of identification documents. The CNIL explains how “double anonymity” works: the website receives proof of legal age without knowing the user’s identity; the service provider that issues this proof must not know which website is being accessed. The guidelines require the relevant services to offer at least one solution of this type after the transitional period.
In this double anonymity model, the process can be visualized in two steps. A person first verifies that they are at least 18 years old, then presents proof that can be used to pass the verification process. The receiving service must be informed that the user meets the age requirement, without receiving their name or date of birth. Depending on the system, this proof may be stored or generated locally: this is one of the approaches favored by the CNIL to avoid systematically relying on a third party.
The effectiveness of this approach depends on the actual separation between the parties involved. The Arcom guidelines specifically set forth requirements regarding independence, confidentiality, and limiting the ability to link proofs to one another. A well-designed system must prevent the verification process itself from becoming a means of tracking visits.
This does not make all browsing anonymous. The safeguards pertain to age verification; they do not eliminate other information that a website may collect. Nor do they preclude the need to examine the service provider, its security measures, and the data actually retained. For an adult, the practical issue is knowing what information they are transmitting, to whom, and what remains once the verification is complete.
The scope of the verification also matters. In its 2022 recommendations, the CNIL advocates for access to the web without identity or age verification by default and reserves these measures for situations where they are necessary. Accepting proof of legal age for adult-only content does not, therefore, equate to approving its extension to all browsing.
What Aylo Contests—and Why It Deserves Attention
Aylo argues that increasing the number of verification checks on platforms heightens the risks to personal data. While this argument necessitates an examination of the quality of these systems, it is not sufficient grounds to condemn all possible architectures. A copy of an ID received by the site and proof of age transmitted via double anonymization do not expose the same information to the same parties.
The group puts forward a second argument, which is central to its reasoning: if platforms that verify age drive their visitors away to competitors that do not verify anything, regulation may simply shift the problem. Aylo asserts that these alternative sites would be less regulated and more dangerous. This is the position of a player directly affected by the loss of traffic; it must be weighed against independent observations, without being dismissed for that reason alone.
The economic mechanism is understandable. An age verification process adds a step that is sometimes perceived as tedious or intrusive. A user may abandon the site. A competitor that grants immediate access then has a user experience advantage. However, several pieces of information are still missing to draw a conclusion: how many visitors actually leave, how many switch to another site, what proportion are minors, and what content do they access afterward?
A decline in audience numbers does not, on its own, measure the effectiveness of child protection. It may reflect effective protection, the departure of reluctant adults, or a shift toward other services. These effects can coexist. Confusing them could lead just as easily to prematurely declaring the law a success as to declaring it a failure.
The United Kingdom Does Not Provide a Clear-Cut Answer
Observations from the United Kingdom add fuel to this discussion. In its report published in July 2026, Ofcom notes sharp declines in traffic on many sites that have implemented age verification, while certain services without such controls are gaining popularity. The risk of users simply switching to other sites, as mentioned by Aylo, cannot therefore be ruled out.
The same regulator nevertheless reports signs that access is being curtailed. In its follow-up study on the online behavior of children aged 8 to 14, 8% of participants visited pornographic services; half of these children accessed only sites equipped with age verification. The visits were often very brief. Ofcom views this as a deterrent, while noting that these brief visits may also reflect an attempt to find a site accessible without age verification.
These British findings do not directly measure the effect of the French system nor do they represent all adolescents. Above all, they prompt us to collectively assess the obstacles encountered and the routes that still allow access to such content. Simply counting the number of age verifications performed would be insufficient: an additional step may be widespread without always being effective.
The CNIL noted as early as 2022 that no system is perfectly effective and that workarounds remain possible. The existence of a vulnerability therefore does not prove a total lack of usefulness. Rather, it requires us to weigh the benefits gained against the errors, access difficulties, and risks imposed on users.
A credible policy must be able to meet these two requirements: document the reduction in minors’ exposure and limit the information requested from adults. Child protection does not justify abandoning efforts to measure effectiveness; nor is the defense of privacy sufficient to establish that no acceptable controls would be possible.
Control at the Device Level: A Different Allocation of Responsibilities
Aylo advocates for verification at the level of phones, tablets, and computers. In the model it proposes, devices would be protected by default, and only verified adults could grant access to content restricted to adults. The group specifically calls for the involvement of operating system manufacturers—Apple, Google, and Microsoft.
The idea has merit: if protection is built into the device, it can apply to multiple services without waiting for each one to cooperate. It also shifts part of the control and its implementation to the system providers. This raises questions about the reliability of their filters, device coverage, and how errors are handled. An account verified as belonging to an adult does not prove that the account holder has the phone in their possession at all times, particularly in a household where devices are shared.
The UK experience shows that this proposal has begun to take concrete form. Aylo introduced age verification methods in the United Kingdom in July 2025, then restricted access to new users in February 2026, citing the system’s poor results. The company then announced, on May 5, 2026, that it was reopening access to eligible UK iOS users who had confirmed they were of legal age through Apple.
Apple’s UK documentation describes age verification linked to the Apple ID for certain services, features, and settings. This can be done, for example, using a credit card or an accepted form of identification. Certain protective settings are automatically applied to users whose age has not been verified. Verification via the device therefore does not necessarily eliminate the need to provide proof of age: it may simply shift the process to the Apple ecosystem.
This case does not demonstrate that the solution can be easily extended to all devices, nor that it replaces the obligations of platforms. Arcom considers protections on devices to be complementary and refuses to allow platforms to shift their responsibility onto other parties. The disagreement thus centers on the method, but also on who must take action and be accountable for the results.
What Using a VPN Changes
A VPN addresses a more limited issue: the apparent location of the connection. It routes traffic through an intermediary server, whose location sees the IP address. When a restriction is based on a French origin, a different location can alter the access conditions. It never constitutes proof of legal age.
Access still depends on the service’s rules in the country of origin and any restrictions it may impose on VPNs. The example of the United Kingdom suffices to show why a foreign IP address does not guarantee access without verification. It would be misleading to promise a country where access would always work, or to present a VPN as a solution to age verification itself.
Privacy warrants a separate discussion. The CNIL emphasizes that the VPN provider becomes a trusted intermediary, capable of knowing your IP address and the sites you visit. Masking your connection to the site does not eliminate all possibilities of monitoring.
It is also important to distinguish this visibility from the content of the communications. When the connection to the site properly uses HTTPS, this encryption protects, in particular, the content of the pages and login credentials in transit. A VPN does not automatically grant access to this information, even though its provider can generally see the domains visited and the times of access. However, an account you log into, cookies, or other tracking methods may still allow the site to recognize you. The Electronic Frontier Foundation details these limitations.
Before entrusting your private browsing to a provider, check what data it retains and how it uses it. The retention period must be clearly stated. A public audit helps verify the provider’s commitments, though it does not guarantee that its practices will remain the same. Promises of total anonymity should be viewed with suspicion. These guidelines are intended for adults; they do not constitute a method for protecting minors.
In a few words
For an adult, the first useful point of reference is the verification process itself. On a service that offers several methods, examine the “double anonymity” option. The service provider must explain what information it transmits to the site and what it retains after the verification. As long as this process remains opaque, a verification requirement alone is not enough to make a request for proof reassuring.
The compromise worth advocating for is based on proof of age limited to this specific use, a verifiable separation between identity and browsing activity, and an assessment of the impact on minors’ access. Device-level protections can supplement this, without exempting platforms from taking action. This requires more work than geographic filtering or a promise of anonymity, but it addresses the two groups the system must take into account: the minor who needs protection and the adult whose privacy must be preserved.




