background image blur
background image
  • Blog
    >
  • News
    >
  • Internet Freedom in July 2026: The Month in Review

Internet Freedom in July 2026: The Month in Review

Image of author
By Tech Writer and VPN Researcher Gintarė Mažonaitė
clock icon
Last updated: 31 July, 2026
A turned off laptop at a home office

July 2026 was the kind of month that makes the internet freedom beat feel both urgent and exhausting. Let’s take a look at what happened!

Nebraska’s Age Verification Law Blocked by Federal Judge

A federal judge ruled that multiple components of Nebraska's LB 1074 (which would have required age verification on social media platforms) likely violate the First Amendment and blocked them from going into effect in July. The ruling is a preliminary injunction, meaning the law is paused while legal challenges proceed, but the court's language was clear: these provisions are probably unconstitutional. 

Courts across the US are increasingly pushing back on overbroad internet safety laws, and Nebraska is the latest example of why blunt age verification mandates don't survive First Amendment scrutiny.

Read the full article here.

Australia Doubles the Fine for Social Media Ban Breaches

Australia's under-16 social media ban has been in effect since December 2025, and the government's own eSafety Commission found that seven out of ten affected children still have "some access" to banned platforms. The response? Double the maximum penalty for non-compliant platforms to $99 million AUD and hand regulators new enforcement powers. 

Prime Minister Anthony Albanese framed this as "doubling down." I'd frame it as escalating the pressure on a policy that demonstrably isn't achieving what it set out to do — and hoping no one notices.

Read the full article here.

The Kids Act Cleared the House. Privacy Experts Are Warning Against It.

The House passed the Kids Internet and Digital Safety (KIDS) Act in a 267–117 vote, with bipartisan support. The bill would mandate age verification for pornography sites, new safety features on platforms, restrictions on minors' data, and new rules for AI chatbots. 

The Electronic Frontier Foundation called it "a mess, with different age-gating schemes for different services, using different standards," warning that platforms will simply default to restrictive age-checking across their entire user base. Trade groups and free speech advocates raised similar concerns.

Read the full article here.

EFF Urges Illinois Governor to Veto Sweeping Age-Gating Bill

The Illinois legislature passed House Bill 5511, a device-level age-gating framework that would apply across nearly all internet-enabled hardware, operating systems, and online services in the state. The Electronic Frontier Foundation formally urged Governor J.B. Pritzker to veto it, calling it a "massive privacy and free speech nightmare." 

The bill closely mirrors California's A.B. 1043 and New York's SAFE for Kids Act, neither of which has gone into effect or been tested in court.

Read the full article here.

Iowa’s Age Verification Law for Adult Content Is Now Live

Iowa's House File 864 took effect in July 2026, requiring adult websites to verify users' ages before granting access. Major platforms — Pornhub, Redtube, YouPorn, Brazzers — chose to block Iowa users entirely rather than collect government ID. Platforms that do comply require identity documents run through third-party verification systems. 

Every adult in Iowa who wants to access legal content now has to either submit their most sensitive identifying documents to a private company or find that the platform has blocked them completely. The teenagers this law was meant to stop have other options. The adults absorbing the privacy cost largely don't.

Read the full article here.

Türkiye Blocked Pride Accounts During Pride Month

Turkish courts issued orders blocking access (within Türkiye) to the Instagram accounts of Kaos GL, one of the country's oldest LGBTQ+ rights groups, along with Istanbul Pride Week, Istanbul Trans Pride Week, Ankara Pride, and Izmir Pride. The accounts remain accessible from outside Türkiye. During the same week, Istanbul's Tek Yön (a gay nightclub that operated legally for 18 years) was shut down after pro-government media amplified a social media post inviting cruise passengers to visit.

Kaos GL's editor-in-chief has been in jail since June 25th, detained under a "terror" probe launched ahead of the NATO summit in Ankara. Online censorship that targets one community is a warning for everyone.

Read the full article here.

Pegasus Was Used Against the MEP Investigating It

Researchers at Citizen Lab found that Pegasus spyware (made by NSO Group and sold to governments for the stated purpose of fighting serious crime) was used against Greek MEP Stelios Kouloglou while he was serving on the European Parliament's Pega committee, which was established specifically to investigate spyware abuses. 

His device was first infected during an intense period of the committee's deliberations in October 2022, and hacked again while the committee was finalizing its report in March 2023. This is the first confirmed instance of a Pega committee member being targeted. Citizen Lab's senior researcher noted that the committee's recommendations have "essentially been ignored."

Read the full article here.

The EU May Announce a Social Media Ban in September

European Commission President Ursula von der Leyen is expected to use her State of the Union address on September 16th to propose an EU-wide social media age restriction for children, according to multiple EU officials and diplomats who spoke to Euractiv. The minimum age, enforcement mechanism, and legal framework are all still undecided. 

Von der Leyen has repeatedly cited Australia's under-16 ban as a model, which is worth noting, given that Australia's own data shows the ban isn't keeping most children off the platforms it targets. If the EU adopts a framework in September, it will set regulatory expectations that ripple outward well beyond Europe's borders.

Read the full article here.

Missouri Joins the Age Verification Wave as SCOTUS Backs Texas App Store Checks

Missouri Governor Mike Kehoe signed HB 1839 on July 9, making age verification for adult sites permanent state law, with fines up to $10,000 a day for skipping it and up to $250,000 more if a minor gets through anyway. Pornhub had already blocked Missouri users rather than comply, joining more than 20 other states where it has pulled out entirely.

That same week, the Supreme Court declined to block Texas's App Store Accountability Act, letting the state keep requiring app stores to verify ages and secure parental consent before a minor can download anything. Missouri's law lets a platform simply exit the state to dodge compliance, but Texas moved verification up to the operating system layer, where leaving isn't an option.

Read the full article here.

Language Is the Internet Freedom Problem Nobody Discusses

Content moderation systems were built with English as the default, and Myanmar showed what that costs. When Facebook had almost no Burmese-speaking moderators during the mid-2010s, a UN fact-finding mission later concluded the platform played a "determining role" in violence against the Rohingya.

That same gap now shapes AI. Models trained mostly on English data perform worse in Yoruba, Quechua, or Tibetan, and UNESCO counts over 7,000 languages the internet barely serves. Kiswahili got an AI dictionary this week for World Kiswahili Language Day, a real step, but most languages aren't even close to that.

Read the full article here.

EU Finds a Procedural Trick to Force Chat Control Through Without a Real Vote

The European Parliament voted down extending chat control in March, 311 against to 228 in favor. The EPP revived the identical text anyway, routing it through the ordinary legislative procedure, which now needs 361 MEPs, an absolute majority, to block it instead of a simple majority to pass it.

A procedural vote lands Tuesday, with the real vote on Thursday, timed for the last plenary day before summer recess. Independent MEP Martin Sonneborn tried to block the maneuver by citing Parliament's own rulebook. Losing once apparently just means finding a rule that makes losing harder the second time.

Read the full article here.

Governments Don't Delete Posts Anymore. They Ban Outlets

OONI's Russia research found 279 news media domains blocked at the network level, double the 139 confirmed the year before, with outlets including Meduza and TV Rain unreachable from a standard Russian connection. When the EU blocked RT and Sputnik, Russia retaliated by blocking 81 EU outlets in return.

The Committee to Protect Journalists recorded 132 journalists and media workers killed in 2025 and 336 imprisoned, while Freedom House tracked people arrested for online expression in a record 57 of 72 countries. Block the newsroom, jail the journalist, and the message stops being about one article.

Read the full article here.

Australia's Under-16 Social Media Ban Can't Even Clear Its First Hurdle

Testers created 50 trial accounts across nine platforms covered by Australia's under-16 ban, each declaring the user was sixteen, and not one platform asked for proof. Some accounts received ads targeted at young audiences, and one registered on X was served adult content anyway.

Kick, a smaller live-streaming platform with less user data to lean on, was the only one of ten covered services that verified age before signup, while nine platforms with more resources simply estimated and let it slide. Australia has already deleted 4.7 million suspected minor accounts, and none of that paperwork proves anyone checked an age at the door.

Read the full article here.

How Digital ID Systems Make Refusal Impossible

India's Aadhaar launched in 2009 as a voluntary biometric ID and enrolled over a billion people before courts ruled mandatory linkage unconstitutional in 2018. By then it was already woven into banking, tax records, and welfare, and breaches of databases holding Aadhaar data have leaked hundreds of millions of records.

The EU's Digital Identity Wallet, rolling out under eIDAS 2.0, carries the same voluntary label Aadhaar once did. A system with 99.9% accuracy still fails a million people out of a billion, and those failures land hardest on people with the least power to contest them.

Read the full article here.

The UN's Answer to Bad Age Verification Laws

Age verification laws are spreading fast, from Australia's under-16 social media ban to the EU's Digital Services Act, trading privacy for a thin layer of protection. This week, UNESCO and Réseau Canopé released a different kind of response, a family guide called Growing Up in a Connected World, built with input from 37 experts.

The guide skips ID checks entirely and instead covers screen time, misinformation, and cyberbullying in plain language, leaning on device settings and real conversations families can start tonight. It also reminds readers that kids have privacy and free expression rights of their own, treating parents as capable partners instead of another database to build.

Read the full article here.

Meta's AI Image Tool Lasted 96 Hours

Meta rolled out Muse Image inside Instagram, WhatsApp, and the Meta AI app this month, letting anyone @-mention a public Instagram account inside the chatbot and generate new AI images using that person's face, with no message sent and no permission asked. Private accounts and minors were excluded, but every adult public account was opted in by default.

Creative Artists Agency and SAG-AFTRA, representing more than 160,000 film and television workers, called the opt-out design an utter miscalculation of public sentiment, and Meta pulled the @-mention feature within four days. The content-reuse setting that fed the tool remains active by default, and Meta's invisible watermark may not satisfy the EU AI Act's visible-labeling rule starting in August.

Read the full article here.

Elections Show the Internet a Government Actually Wants

Governments that shut down the internet during elections aren't reacting to a crisis; they're revealing a decision made well in advance. Venezuela blocked social media and anti-censorship tools around its 2024 election while journalists were detained and dissenters disappeared, and Bangladesh cut mobile internet for eleven days during 2024 protests before an interim government took over.

Serbia, Kenya, and Uganda show the same pattern outside the usual list of authoritarian states, with Freedom House recording Kenya's steepest ranking decline after a seven-hour shutdown during tax protests. Freedom on the Net 2025 tracked a 15th consecutive year of declining internet freedom, and elections keep being the moment that trend becomes impossible to explain away.

Read the full article here.

Paris Weighed Buying the Spyware Morocco Was Already Using on Its Ministers

France's government explored buying Pegasus spyware from NSO's French reseller starting in mid-2019, while Morocco's domestic intelligence agency was already running the same software against French officials, a program the country would go on to repeatedly deny. Emmanuel Macron ultimately rejected the purchase, but future prime minister Sébastien Lecornu had already been targeted from that July onward.

A former Moroccan intelligence officer using the pseudonym Safir has now detailed how the agency hid its fingerprints through a private intermediary tied to a UAE defense group, with journalist Omar Radi among those targeted and later pardoned. The revelations landed the same week Lecornu led twelve ministers to Rabat for what his office called a high-level reconciliation meeting.

Read the full article here.

Wearable Makers Are Failing Basic Privacy Tests

EFF reviewed ten major wearable makers, including Amazfit, Apple, Coros, Garmin, Google, Oura, Polar, Suunto, and Whoop, and found only Apple and Google currently publish transparency reports showing how often governments request user data. Oura updated its privacy policy in June after a journalist pressed the company, but seven companies never responded at all.

Apple Watch is the only mainstream wearable offering end-to-end encryption, and only for data stored inside the Apple Health app, while every other device leaves the company able to see and store everything. Heart rate spikes and step counts have already been used as evidence in criminal investigations, and surveillance vendors openly market wearables to investigators for exactly that reason.

Read the full article here.

Labour Signals a UK VPN Ban Announcement Is Just Days Away

Technology Secretary Liz Kendall has promised a robust statement on VPN restrictions this month, following a rollout that already covered AI chatbot limits and teen curfews. The bill has been bouncing between the Lords, which voted to ban VPN access for under-18s outright, and the Commons, which substituted a broad ministerial power to restrict children's VPN use instead.

Internet Matters research found only 7% of children use a VPN to bypass age checks, dwarfed by fake birthdays, borrowed logins, and shared devices. The EU's digital chief and French officials have separately signaled VPN restrictions are next on their own agendas, meaning a robust UK announcement hands them a ready-made template.

Read the full article here.

Public Education Shouldn't Run on Big Tech's Terms

UNESCO marked World Youth Skills Day on July 15th by launching a Skills for the Future Platform alongside a new Charter for Public Digital Learning Platforms built with UNICEF and the ITU. The Charter names the problem directly, pointing out that platforms like Google Classroom and Microsoft Teams were built for workplace productivity, not learning.

It calls for student and teacher data to stay under national jurisdiction and public control by default, and takes direct aim at asking families to click through lengthy terms just to access compulsory education. UNESCO also centers media information literacy, the ability to evaluate sources and recognize when a platform's design is working on a student rather than for them.

Read the full article here.

Internet Shutdowns and the Meaning of African Democracy

Access Now and the #KeepItOn coalition documented 313 internet shutdowns across 52 countries in 2025, a new record, with 30 of those shutdowns across 15 African countries. Tanzania imposed a five-day nationwide blackout during its October 2025 elections while security forces turned on citizens in the streets, and the African Union declared the vote undemocratic.

Uganda cut connectivity during its January 2026 elections despite warnings from human rights bodies, but civil society is pushing back, with the ECOWAS Court ruling Senegal's shutdown unlawful and the International Criminal Court linking shutdowns to crimes against humanity. On the eve of Nelson Mandela Day, the question is whether an election counts when a government can silence the network.

Read the full article here.

India Shut Down Delhi’s Internet During a Protest Without Publishing the Order

On July 20, thousands of students marched to parliament in the "Chalo Sansad" protest. The government suspended mobile internet in central Delhi, reportedly from as early as 10 am until 6 pm, describing it as a "precautionary measure." No suspension order was published — in direct violation of a 2020 Supreme Court ruling and India's own Telecommunications Rules 2024. 

The Internet Freedom Foundation condemned the shutdown and will file Right to Information applications to force disclosure.

Read the full article here.

Telecom Companies Confirmed the Order, the Government Still Won’t Publish It

The follow-up was more damning than the original story. Officials at two major telecom providers confirmed receiving government directives to cut mobile internet in central Delhi. The government's position is now clear: it's not denying the shutdown happened. 

It's simply refusing to give the public any legal basis to challenge it. An unpublished order is an unaccountable order. India recorded 65 internet shutdowns in 2025, the highest of any democracy in the world.

Read the full article here.

The Court of Justice of the European Union explicitly categorized VPNs as "lawful technical tools" in a ruling stemming from a dispute over a scholarly online edition of Anne Frank's manuscripts. The court found that publishers who deploy state-of-the-art geo-blocking can't be held liable when users circumvent it with a VPN — and that the mere existence of VPNs doesn't make geo-restrictions legally inadequate. 

It's the clearest judicial recognition of VPNs' legitimate status under EU law yet, at exactly the moment governments across Europe are looking for ways to restrict them.

Read the full article here.

France Banned Under-15s From Social Media — and Everyone Will Have to Verify Their Age

France's parliament adopted a law banning social media for under-15s, making it the first EU country to do so. From January 2027, every person in France — regardless of age — will need to verify their identity to access social media. The government cited Australia's ban as a model. 

By March 2026, seven out of ten affected Australian children still had "some access" to banned platforms. France is watching a failed experiment and calling it a template.

Read the full article here.

A Chinese Journalist Faces Deportation From Thailand Back to China

More than 50 press freedom organizations, including Amnesty International, Human Rights Watch, and the Committee to Protect Journalists, have urgently called on Thailand not to deport Bai Zhaodong — a Chinese investigative journalist who exposed corruption implicating senior Communist Party officials. He's been held in Bangkok immigration detention since January 2026. 

China is the world's largest jailer of journalists, with 120 imprisoned. If returned, Bai faces arbitrary detention, enforced disappearance, and torture. The window to act is closing.

Read the full article here.

A New EU Court Ruling Could Push Platforms to Censor More Speech

The EU Court of Justice's Coyote System ruling found that when a platform's algorithm determines how content is ranked and disseminated, the platform "controls" that content and loses its hosting liability protection. The Electronic Frontier Foundation warns the reasoning is broad enough to apply to virtually every major social media platform. 

When hosting user content carries liability risk, platforms censor preemptively — including lawful speech. The ruling sits directly against the logic of the EU's own Digital Services Act.

Read the full article here.

California’s DROP Lets You Delete Yourself From 614 Data Brokers

California's DELETE Request and Opt-out Platform (DROP) lets residents send a single deletion and opt-out request to all 614 registered data brokers in the state. From August 1, brokers have 45 days to act. It covers social security numbers, precise geolocation, browsing history, inferred health and political data, and more. It doesn't cover Google or Meta. It doesn't stop data collection — only its sale. 

And you'll need to refile periodically. But it's one of the most practical privacy tools a US state has produced, and it's worth using.

Read the full article here.

The Internet Isn’t Equally Safe for Everyone

Women and girls of African descent navigate the internet at the intersection of gendered and racialized targeting simultaneously. Facial recognition systems misidentify them at higher rates. Content moderation flags their speech while leaving the harassment directed at them in place. Coordinated abuse campaigns are designed specifically to push them off public platforms. 

Critical data gaps mean their experiences of online harm are poorly measured and, as a result, poorly addressed. Formal equality of access — the fact that anyone can create an account — doesn't resolve any of this.

Read the full article here.

Climate Information Is Manipulated — a Digital Rights Problem

Outright climate denial has largely given way to delay narratives: manufactured uncertainty about timelines, costs, and the viability of action. These spread faster through algorithmic recommendation systems than corrections do. In countries with large fossil fuel industries and low press freedom, climate journalists face direct pressure, harassment, and in some cases physical danger. 

Communities in the Global South bear the heaviest climate impacts and have the least influence over the information systems that shape global climate discourse. UNESCO is now framing this as a governance problem, not just a fact-checking one. It's right to.

Read the full article here.

Western Australia Launched Real-Time Facial Recognition

Western Australia police launched a real-time facial recognition trial capable of scanning hundreds of faces per minute and cross-referencing them against police databases. An arrest on the first day is being used as proof of concept. Privacy advocates have immediately flagged concerns about false alerts, algorithmic bias, and function creep. 

A day-one arrest isn't evidence of accuracy or proportionality. It's evidence the system can produce a match. Western Australia is at the beginning of a curve that doesn't tend to end with less surveillance.

Read the full article here.

A "no-logs" VPN kept 58 million logs — and got breached

The Mysterium VPN Research Team verified a breach of NotVPN (also known as SplitVPN), a Russian VPN marketed with explicit no-logs promises. The leaked database contains approximately 23.4 million user records, 13.6 million device records, and — most damningly — nearly 58 million connection logs recording which device connected to which server and when. 

The logs run continuously up to the day of the breach. NotVPN's own marketing promised: "We never store your activity or connection logs. 100% privacy guaranteed." The database says otherwise. If you used NotVPN or SplitVPN, treat your email and associated IPs as compromised.

Read the full article here.

Nicegram and eSIM Plus — here's what’s hiding inside

Following OCCRP reporting that Nicegram (50M+ downloads) and eSIM Plus (1M+ downloads) are presented as Lithuanian products while allegedly developed from Belarus, the Mysterium VPN Research Team performed a static teardown of both Android packages. The findings: eSIM Plus is cryptographically signed by "Mobyrix, Minsk, Belarus" — a Belarusian signature on an app marketed as Lithuanian. It also ships live integrations with Yandex AppMetrica and Voximplant, routing through a .ru endpoint. 

Nicegram shares the same development operation but doesn't carry those Russian SDKs in the version we analyzed. The lesson: an app's listed publisher and its actual origin can be two different things — and the binary is where the truth is.

Read the full article here.

The 5th Circuit blocked Texas's "harmful speech" filtering law

The US 5th Circuit Court of Appeals blocked a Texas law that would have required websites to filter content deemed "harmful." The ruling strikes down a state-level mandate for government-directed content moderation — and the core problem with such laws is always the same: "harmful" is defined by whoever holds political power at the time. Laws built around vague harm standards don't stay narrow. 

They expand to cover whatever the current majority finds inconvenient, and they push platforms toward systematic over-moderation of the most important speech.

Read the full article here.

China is censoring the anniversary of the Zhengzhou floods

Five years after catastrophic flooding killed hundreds in Zhengzhou — including passengers trapped in a flooded subway tunnel — Chinese authorities are censoring online memorials, personal accounts, and any content that contradicts the state's narrative of effective disaster response. The censorship targets grief itself. One suppressed piece read: "Sometimes forgetting is as terrible as the disaster." 

A government that can erase disaster memory can also erase the accountability questions that disaster raised. That's what information control is ultimately for.

Read the full article here.

The UK's immigration AI is misclassifying child refugees as adults

A Guardian investigation found that AI age-assessment tools used by UK immigration authorities exhibit significant bias, causing child refugees to be incorrectly classified as adults. Children misclassified lose access to the legal protections, support, and procedural rights that exist specifically because they're children. Error rates are higher for people with darker skin — meaning child refugees from the Global South are the most likely to be misidentified. 

The government is deploying biased surveillance tools on the most vulnerable people it encounters, and the people bearing the cost of the errors have no power to contest them.

Read the full article here.

Russia fired workers who refused to censor LGBTQ+ books

Russia's largest publishing group terminated employees who refused to comply with censorship orders targeting LGBTQ+ content. They weren't activists. They were editors and staff who drew a line at participating in their community's erasure. The line cost them their jobs. 

This is how institutional censorship scales: not through police raids, but through quiet employment consequences that distribute compliance across enough ordinary workplace decisions that it stops looking like state censorship. The playbook travels. It isn't unique to Russia.

Read the full article here.

Google's Play Store age verification API is rolling out globally

Google is expanding its Play Age Signals API, which lets app developers access age range data for child accounts without requiring ID uploads. The system is built on Family Link, is fully opt-in, and doesn't demand government identification from anyone. That makes it meaningfully more privacy-respecting than most age verification legislation we've covered. 

It also won't stop determined minors who create alternative accounts — which is the honest gap between "creates friction" and "reliably verifies age" that legislators consistently paper over.

Read the full article here.

xAI is suing Minnesota over its AI nudification ban

Elon Musk's xAI filed a federal lawsuit challenging Minnesota's HF 1606, which bans apps enabling the creation of non-consensual AI-generated sexualized images. xAI doesn't contest the goal — it contests the scope, arguing the law covers consensual imagery and artistic content, and imposes strict liability regardless of what mitigations a provider has in place. 

The harm being addressed is real. The First Amendment argument has some substance. The question is whether the law is precisely enough targeted to survive challenge — and whether this lawsuit might produce a narrower, more durable version of the same protection rather than gutting it entirely.

Read the full article here.

The FTC sued Hims & Hers for sending health data to Meta and Snap

The FTC, joined by Utah and California, sued telehealth provider Hims & Hers for sharing consumers' sensitive health data with Meta, Snap, and other advertising platforms — while publicly promising patient privacy. The data was shared via customer lists and third-party tracking technologies embedded on the Hims website. 

The company also allegedly enrolled users in recurring subscriptions before any medical consultation occurred, and designed its cancellation flow to be deliberately difficult to navigate. "We protect your privacy" is not a guarantee without enforcement. This case is the enforcement.

Read the full article here.

India is reviewing its net neutrality rules for 5G

India's government has referred a review of its net neutrality rules to the Telecom Regulatory Authority of India, prompted by questions about whether 5G network slicing is compatible with the current equal-treatment framework. The use cases being cited — healthcare, autonomous vehicles, industrial applications — have genuine technical merit. 

The concern is that once exceptions are carved into a net neutrality framework for technical reasons, the boundary between "technical necessity" and "commercial opportunity" is very difficult to maintain. India's 2018 framework was one of the world's strongest. The TRAI process will determine whether it stays that way.

Read the full article here.


Share on
Facebook share Twitter share Reddit share Linkedin share

Be part of the resistance, quietly.

Get Mysterium VPN Arrow icon
awareness campaign banner img
Image of author
Gintarė Mažonaitė
Tech Writer and VPN Researcher

Gintarė is a cybersecurity writer at Mysterium VPN, where she explores online privacy, VPN technology, and the latest digital threats. With hands-on experience researching and writing about data protection and digital freedom, Gintarė makes complex security topics accessible and actionable.

Read more by this author
© Copyright 2026 UAB "MN Intelligence"