For a dozen parts now, this series has kept coming back to a single, awkward foundation stone. Every one of these laws — the UK's age gate pointed at social media, France's now-struck-down under-15 ban, Australia's under-16 experiment — rests on the same unspoken assumption: that the public has agreed to hand the state, and the shifting cast of vendors it approves, a permanent and growing store of exactly who we are. Our faces. Our documents. The record of what we read and where we go. I have called that store the identity honeypot, and I have spent this series — most recently in part twelve — arguing that nobody has honestly costed it.

This week someone did the one thing that, across three countries and a decade of these debates, none of the governments writing the laws had troubled to do. They asked the public.

The answer, it turns out, is no. Not a soft no, not a partisan no, not a no that dissolves under the first hard case. A flat, cross-party, arms-folded no.

I want to sit with that, because it is a detour from the France story I have been tracking — the poll is about encryption, not age verification — and I am not going to pretend the two are the same mechanism. But they are the same argument, standing in a slightly different coat, and the coat does not change the man wearing it.

What Britain actually said

The polling was commissioned by the Center for Democracy and Technology and carried out by Public First in April 2026 — a nationally representative sample of two thousand British adults, with a margin of error of about 2.2 points. It was written up at the end of August, which is how it crossed my desk. The subject was narrow on paper: should the state be able to reach into your private, encrypted messages? The findings were not narrow at all.

Start with the baseline. Ninety-three per cent of people said they believe they have a right to private conversations online. Eighty-nine per cent said nobody should be able to reach their personal messages without a court order. These are not the numbers of a public that is relaxed about being read.

Then the part that matters most for everything this series has argued. Asked whether they would trust the government with access to encrypted messages, roughly two-thirds said they would not trust the current government — or any future one. Read that clause again, because it is the whole ballgame. This was not "I don't like the lot currently in office." It was a settled judgement that no government, of any colour, should be handed this capability, because the capability outlives the people you handed it to.

And it held across the aisle in a way almost nothing does in British politics now. The distrust ran to 58 per cent among Labour voters, 59 among Conservatives, 56 among Liberal Democrats, 69 among Greens and 75 among Reform voters. When Reform and the Greens agree on something to within a rounding error of each other, you are not looking at a culture-war reflex. You are looking at a shared instinct that sits underneath politics rather than on top of it.

The texture underneath those headline figures is the bit I would carve into the wall. Only twelve per cent backed a power for government to secretly order a company to hand over access — the exact instrument the UK actually uses. A third said the state should have no such power at all; another four in ten said that if it must exist, it needs transparency and parliamentary oversight bolted to it. Fifty-three per cent said the security risks of building an access route outweigh the law-enforcement benefits. Eighty-four per cent worried that such a route would open a door for criminals and hackers. Eighty-two per cent worried it would be abused.

And people said they would change their behaviour. Sixty-five per cent said they would become more careful about what they posted or said; forty-one per cent said they would self-censor criticism of the government specifically. That last figure ought to trouble anyone regardless of where they sit, because a population that edits its criticism of the state before it speaks is not a free one, whatever the statute book says.

The eighty-four per cent are making my argument for me

Here is why an encryption poll belongs in a series about age verification.

For six parts I have been making one technical claim over and over, in different words, because it is the load-bearing wall of the whole argument: you cannot build a hole that only good people can walk through. The Electronic Frontier Foundation has spent years making the same point about encryption backdoors — a ghost user is a backdoor by another name. A backdoor into encrypted messaging and a mandated national store of identity documents are not the same policy, but they are the same physics. Both create a single, high-value target that did not exist before. Both require you to trust not only today's government but every future one, and not only the government but every contractor, every vendor, every underpaid administrator with a login, forever. Both fail not on the day they are abused but on the day they are breached — and the history of this series is a history of breaches.

The eighty-four per cent of Britons who told this poll that an access route would be a gift to hackers are not privacy obsessives. They are ordinary people who have correctly intuited, without a threat model or a white paper, the single thing I have spent this series trying to say about age-verification stores. When a Discord age-check vendor leaked around seventy thousand government ID photographs last October, it did not leak them because someone was careless with a magic exception that only the police could use. It leaked them because the exception does not exist. A store of identities is a store of identities. A face does not reset. The public knows this in its bones; it just used the word "hackers" where I used the word "honeypot."

So when a government tells you that universal age verification is safe because the vendors are approved and the store is well guarded, hold it against this poll. The same public being asked to trust that store has, when asked a neighbouring question in plain terms, said it does not believe safe access is a thing that exists. It is not that they haven't understood the reassurance. It is that they have, and they don't buy it.

The Apple saga, and the tell hiding inside it

None of this is abstract in Britain, because we are already living the worked example.

In early 2025 the Home Office served Apple with a secret Technical Capability Notice — an order, under the Investigatory Powers Act, that it could not even confirm it had received — effectively demanding a way into iCloud data protected by Apple's Advanced Data Protection. Apple's response was to withdraw that protection from British users entirely rather than build the door: if you are in the UK, you now cannot turn on the strongest encryption Apple offers. There was a reported climb-down in the summer of 2025, brokered noisily across the Atlantic; and then, quietly, a revised notice narrowed to UK users, and by August 2026 Apple was back in court challenging it, alongside a parallel action from Privacy International and Amnesty. As I write, the fight is live.

Sit the poll next to that timeline and the tell jumps out. The government did all of this — the secret order, the standoff, the quiet reissue — in the name of a public it never asked and, on these numbers, badly misjudged. And here is the detail I keep returning to: the poll found that fifty-five per cent of people had not even heard of the Apple row. So a majority reached their settled distrust of the state on these keys without even knowing the government was, at that very moment, trying to take them. Their objection is not a reaction to a news cycle. It is a prior. It is what they think before they are told anything at all.

That is the strongest possible version of "the public does not consent." It is one thing to lose an argument the public has been following. It is another to be told, by people who weren't even watching, that they would have said no if you'd asked.

The honest other side

I owe this series, and you, the strongest version of the case I am arguing against, because a poll is not a policy and public sentiment is not the same thing as being right.

The case for lawful access is not stupid and it is not made in bad faith. Serious crime — the sexual abuse of children above all — increasingly plans and hides in end-to-end encrypted spaces, and the officers who work those cases are not inventing their frustration when they describe going dark. The same is true of the child-safety instinct behind the age-verification laws: there really are eleven-year-olds being harmed on these platforms right now, and "do nothing" is not the morally serious answer some of its advocates pretend a wall would be. A poll that asks people whether they want their messages private will, unsurprisingly, find that they do. It does not put the abused child in the room. If you asked the same two thousand people whether they want the police to be able to catch a predator, you would get a thumping majority for that too, and the honest truth is that the public holds both wishes at once and is not required to reconcile them. Governments are.

But notice what that concession does and does not do. It establishes that the goal is legitimate. It does not establish that the mechanism works, or that the store is safe, or — the specific thing this poll measures — that the public has agreed to bear the cost. And on the mechanism, the record of this series is not kind: France's law struck down as disproportionate, Australia's ban moving the numbers by about ten points rather than by the height of its wall, the porn gate walked around by a third of users on day one. A legitimate goal pursued through a mechanism that does not deliver, at a cost the public never agreed to carry, is not a triumph of child protection. It is a honeypot with a good excuse.

Consent, and the difference between "can't" and "shouldn't be trusted to"

When I first read this poll, the line that formed was blunt: if we do not trust the government to hold the keys to our messages, why on earth do we assume it is competent to hold the keys to our identities, forever, on our behalf?

Let me be careful here, because there are two claims in that sentence and only one of them is really what the poll shows.

The poll is overwhelmingly a statement about trust and consent, not about competence. It says: we do not agree to this, we do not believe the access can be made safe, and we do not trust any government — this one or the next — to hold the capability without it leaking or being abused. That is a devastating finding on its own terms, and it is the one I would lead with. The competence point — that the state is not actually much good at writing or enforcing these laws — is real too, but it leans on different evidence: the struck-down French statute, the modest Australian numbers, the vendor leaks. The poll supports the competence critique only obliquely, in that a public which expects abuse and breach is, in effect, forecasting the government's track record back at it.

Keep those two apart and the argument gets stronger, not weaker. Because the consent point does not depend on the government being incompetent. Even a perfectly competent state — one that never lost a laptop, never misdirected a warrant, never approved a vendor that turned out to be leaky — would still be building a capability its own citizens have said, across every party, they do not want it to have. "You are bad at this" is an argument the government can answer by promising to get better. "We do not consent to you having this at all" is not a bug to be patched. It is a democratic fact, and it is the one the whole age-verification project has been carefully arranged not to hear.

The European cousin, wearing the family resemblance

Britain is not doing this alone, and the poll lands in the middle of a continent having the same argument twice over. The EU's long-running "chat control" proposal — the plan to have services scan private messages for illegal material — has spent years grinding through Brussels precisely because it runs into these same objections, with the Parliament trying to fence off end-to-end encryption and client-side scanning and the Council pushing the other way. As I write it is still unresolved, and I am not going to call a result I cannot yet see.

But here is the detail that ties it straight back to this series: the same European proposal that would scan your messages has quietly grown an age-verification limb, folding in checks on who is allowed to communicate anonymously at all. The two instincts — read the message, verify the person — are not cousins by coincidence. They are the same reach for the same thing: an internet where nothing is private and nobody is unidentified, assembled one child-safety justification at a time. The British public, asked about one limb of it, said no. There is no reason to think it would say yes to the other if anyone bothered to ask, which is presumably why the question keeps being framed as being about children rather than about everyone.

The rule nobody helped write

I ended the France piece with Professor Tama Leaver's best line — that any of this has to be done with young people, not to them, because a rule teenagers had no hand in writing is a rule they treat as a puzzle to solve. This poll is that same sentence, aimed one level up. It is not just teenagers being handed rules they had no part in. It is the entire adult public, being enrolled — as I warned when France mandated verification for everyone — into an identity regime it was never asked to agree to — the one Britain is now assembling through “highly effective age assurance” — in the name of protecting children who, on the evidence, it mostly is not protecting.

A rule the public had no hand in writing is a rule the public treats as a puzzle to solve, too. That is the enforcement inversion again, only now the determined user is not a fifteen-year-old with a VPN. It is a sixty-year-old who has decided, quite reasonably, that they will not hand their passport to a social network, and who will find the device-level route around it exactly as their grandchildren do.

What actually changes for you

The practical read has not moved a millimetre from where this series has always left it, and this poll is the closest thing to vindication it is going to get.

For you, the individual: nothing here changes the do-it-this-weekend advice. Keep the strongest encryption your devices offer switched on while you still can — and note that in the UK, "while you still can" is now a phrase with teeth. When you are asked to prove your age or your identity online, treat those documents as the irreplaceable things they are, and prefer the providers that check and delete over the ones that check and keep. Lean on the controls that live on the device and travel with the child, because they are still the only thing in this entire series that has outperformed a statute.

For the argument: this poll is the piece of evidence I did not have when I started. I could show you that the walls get walked around, that the stores get breached, that a face does not reset. What I could not show you was what the public actually wanted, as opposed to what it was told it wanted by the people building the walls. Now I can. Asked plainly, in numbers that cross every party line, Britain said it does not trust the state with the keys to its private life — not this government, not any government, not now, not later.

Nobody sought that consent before building the machine that needs it. This week, unbidden, the public gave its answer anyway. The least the rest of us can do is quote it back to them.

This is a detour from the main run of Regulating the Teen Internet — a sidebar about the foundation under all of it. If you have arrived here first, the practical guide for parents is part eight, and the story this one steps away from is part eleven.