What the EU age verification app controversy teaches us about digital identity and trust


This article is part of our Opinions section, where we invite industry professionals to share their views on the most pressing technology questions of our time. Here, Tony Kounnis, CEO of Face Int, explores what the EU age verification app controversy can teach organisations about digital identity and trust. He examines why security vulnerabilities in identity systems can undermine public confidence, particularly when biometric data is involved. 

The article highlights the importance of privacy-by-design, governance and transparency in facial recognition technologies, arguing that long-term adoption will depend not only on functionality and accuracy, but on organisations’ ability to demonstrate that digital identity systems are secure, responsible and worthy of public trust.


Tony Kounnis, CEO of Face Int, shares his views in this opinion piece
Tony Kounnis, CEO of Face Int, shares his views in this opinion piece

The recent controversy surrounding the EU’s age verification app has reignited a familiar problem in technology adoption.

If you missed the news, here is a brief summary. In April, the EU launched a new app to check people’s age online – it was being introduced in preparation for new rules coming in around children accessing social media. Within hours of the app’s release, however, cyber and privacy experts had examined the source code on the GitHub software platform and reported several issues with the app’s design, which made it highly exposed to hackers.

This is much more than a PR blunder. It’s a hugely serious, sensitive problem.

In my mind, while the incident itself centres on age verification, the implications are worth examining, especially for the biometric and facial recognition technology (FRT) sectors.

It shows that, as governments and organisations accelerate the rollout of facial recognition and digital identity technologies, trust will increasingly depend not just on whether systems work, but on whether they are secure and properly governed from the outset.

Identity data raises the stakes

Most cybersecurity failures are serious, but identity systems introduce a different level of risk.

If a password is compromised, it can be reset. If a card is stolen, it can be cancelled. But biometric data is different. A person cannot change their face in the same way they change a login credential.

That is why organisations deploying FRT need to think carefully about the systems sitting behind the technology. It is not enough for verification to be fast, accurate or convenient. The architecture must also be resilient, privacy-first and designed to reduce the amount of sensitive data exposed in the first place.

This is where many digital identity projects can run into difficulty. The public experience is often seamless, but the actual danger lies in what is happening away from public view.

Trust can be lost quickly

For facial recognition, this matters because public confidence is already nuanced.

Face Int UK’s own research (an independent survey of 2,000 UK adults commissioned via Opinium) found that 69% of Britons believe the public should have a say in how FRT is used. To me, that reflects a level of caution around the technology and a sense that acceptance depends heavily on context and safeguards.

Some 81% support its use at border control, 73% back its use by police and security forces, and 71% support it for identity checks by banks. There is clearly an understanding among the public that facial recognition can deliver value in environments where security and identity assurance are important.

But support is not unconditional. Only 24% of respondents believe FRT should be used more widely in the UK regardless of context, while 53% say it should only be deployed where there is a clear public benefit and strong safeguards in place.

That is why incidents like the EU app controversy matter beyond the technology directly involved. When digital identity projects appear vulnerable, it feeds a wider concern that organisations are moving too quickly and asking the public to trust systems that have not been tested thoroughly enough.

Privacy cannot be an afterthought

The key lesson from the EU verification app incident is not that organisations should stop investing in digital identity, biometric authentication or facial recognition. The need for stronger identity assurance is only growing, particularly as fraud, deepfakes and synthetic identities become more sophisticated.

But security and privacy need to be built in from day one. Too often, organisations treat cybersecurity and governance as something to refine later, once systems are already live. In my view, that approach is becoming increasingly risky, particularly where biometric data is involved.

For the FRT sector, privacy-by-design needs to become standard practice. That means minimising unnecessary data collection, reducing centralised storage where possible, and ensuring systems are designed to limit exposure if something does go wrong.

The real test for the FRT sector

Digital identity systems are going to become a much bigger part of everyday life. That direction of travel is already clear. The question is whether organisations can demonstrate that they are deploying these technologies responsibly enough to earn long-term trust.

That means moving beyond conversations around capability alone. Accuracy and convenience matter, but public confidence will only grow if systems are built with transparency, governance and security resilience in mind.

Ultimately, trust in facial recognition will not be built through launch announcements or marketing campaigns. It will be built through systems that prove they are secure, proportionate and designed with privacy in mind from their very conception.

About The Author

Avatar photo
Ricardo Oliveira

Ricardo Oliveira is a Senior Director at TechFinitive, where he frequently collaborates with TechFinitive's editorial team to write and produce content. He's based in Sydney, Australia.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.