background image blur
background image
  • Blog
    >
  • News
    >
  • Internet Freedom Weekly: News Recap, September 21st–September 25th 2026

Internet Freedom Weekly: News Recap, September 21st–September 25th 2026

Image of author
By Tech Writer and VPN Researcher Gintarė Mažonaitė
clock icon
Last updated: 25 September, 2026
A brunette woman scrolls her phone while drinking coffee in her kitchen

The EU Kids Act Will Create a Privacy Minefield

The EFF published a detailed critique of the EU Kids Act on September 21, arguing that the proposal's age gates, mandatory verification, and safety-by-design requirements will undermine privacy and civil liberties for all users — not only minors. The three-tier access system covers virtually all mainstream platforms, requires parents of 13- to 15-year-olds to verify their own identity in addition to their child's age, and reserves full unrestricted internet access for adults only. 

The EFF's broader objection is structural: age gates build infrastructure that concentrates power in large tech companies, disproportionately exclude marginalized groups, and can easily slide from safety requirements into content requirements. The proposal also bypassed a full impact assessment process, meaning the Commission hasn't formally examined whether less rights-restrictive alternatives could achieve the same goals.

Read the full article here.

Discord Is Now Profiling Every User's Age

Discord rolled out age verification globally on September 22, automatically sorting every account into adult, teen, or unconfirmed age groups using a machine learning model trained on behavioral signals — server membership, account age, activity patterns — without reading messages or content. Discord says more than 90% of users will be placed automatically with no action required; the remaining 10% can verify through a credit card, app store age signals, Google Wallet, a video selfie, or an ID scan. 

The rollout follows a delayed February 2026 launch after user backlash, and a September 2025 data breach at a third-party vendor that exposed government ID photos and selfies from around 70,000 users. Discord has built the least bad version of this — the 90% figure is framed as a privacy win, but it means the platform has already inferred and acted on the probable age of almost its entire user base from behavioral data, without asking.

Read the full article here.

The US Called Australia's Algorithm Opt-Out Law "Censorship"

The US embassy in Canberra filed formal objections to Australia's draft Digital Duty of Care laws, warning that vague harm definitions enforced by the eSafety Commissioner risk "viewpoint-based censorship" and that mandated algorithm design requirements could affect users globally. Prime Minister Albanese, at the UN General Assembly, responded that the law is about giving individuals control over their feeds — not giving government control over content. 

Both arguments are partly right, which is the problem: the US is correct that a regulator with nine-figure fines and no precise content standard creates conditions for politically shaped enforcement, while Albanese is correct that engagement-optimized algorithms cause real harm. What neither side is fully engaging with is that the bill bundles a popular algorithm opt-out with a vague enforcement power, and the US submission is aimed at the second while Australia defends the first.

Read the full article here.

Ireland Fined Google €403M for Unlawful Location Data Processing

Ireland's Data Protection Commission fined Google €403 million on Monday after a six-year inquiry into how the company handled location data across three features between May 2018 and February 2020. The DPC found Google's processing was unlawful, unfair, and non-transparent — users had no clear picture of how their location was being used to target advertising or infer their interests, and Google retained it longer than necessary. 

Google has also been ordered to bring its practices into compliance within six months, indicating the DPC isn't satisfied that its post-2019 updates fully meet GDPR's requirements. The six-year gap between complaint and fine is its own problem: Ireland handles an outsized share of Europe's major tech enforcement cases and consistently takes years to resolve them.

Read the full article here.

Gates Foundation Builds a Coalition to Fix AI's Language Gap

The Gates Foundation announced on September 21 that it's convening 60 organizations — including Anthropic, Google, and the OpenAI Foundation — to build more representative language data sets for AI tools, aiming to reach more than 3 billion people over five years. The Mozilla Data Collective's CEO described the core problem as the "original sin" of AI: models were trained on internet-scraped data, and the internet isn't representative — a pregnant woman in Malawi describing her water breaking could receive a mistranslation so literal it becomes medically meaningless. 

Google's Project Vaani is already collecting more than 150,000 hours of audio across every district in India just to cover dialects within a single language. This is, for once, movement in the right direction on a problem we've been documenting for some time.

Read the full article here.

A Rogue OpenAI Agent Hacked a Government Site — and Told No One for Months

According to the BBC, a rogue OpenAI agent accessed Australia's Medicare Statistics Reporting Service portal in June, entering public and non-public government files without authorization — the first known case of an AI agent breaching a government system of its own volition. OpenAI says it didn't discover the breach until August, and notified the relevant agency on September 10th via a general inbox email; it took five more days before the Prime Minister was informed. 

Albanese told OpenAI CEO Sam Altman directly that the disclosure took too long and that there would be legal consequences; Altman acknowledged "issues with protocols." The disclosure timeline is the second story: OpenAI's response to its model doing something it wasn't supposed to was to internally review it, wait, and send an email to a general inbox.

Read the full article here.

Ofcom Investigates Whether Pornhub's Age Checks Actually Work

According to the BBC, Ofcom has launched a formal investigation into Pornhub owner Aylo over whether its age verification process meets the Online Safety Act's "highly effective" standard — specifically whether Aylo conducted sufficient due diligence before deploying Apple's age check system for UK users. Pornhub's UK traffic dropped more than 75% when tougher OSA checks came into force in October 2025, the site restricted access entirely in January, and partially reopened in May — but the traffic that left didn't disappear; it went to VPNs and non-compliant sites Ofcom can't touch. Age verification creates a gate at the compliant site, generates data in the process, and leaves the non-compliant internet untouched. The checks may not be working. The data collection is.

Read the full article here.

Pakistan Is Planning Another Internet Shutdown — This Time for a Political March

According to Bloom Pakistan, Punjab's Home Department has asked the federal government to cut mobile and internet services in parts of Rawalpindi and Attock from September 27, ahead of PTI's planned long march toward Islamabad — with internet jamming also requested at specific sites along the route. 

Punjab has simultaneously imposed Section 144 across the province banning gatherings of five or more people, and Pakistan-administered Kashmir has been under a partial internet shutdown for more than 100 days — imposed the day protests started in June and still running after the elections it was nominally meant to manage have concluded. The mechanism is identical: law enforcement request, Interior Ministry, telecom regulator, no public order, no legal challenge before it takes effect. What differs is the political target.

Read the full article here.

VPN Restrictions Are Following Age Verification Laws

Today, September 25, is the second annual Defend VPNs Day of Action, organized by Fight for the Future. The pattern driving it is consistent across several jurisdictions: an age verification law passes, VPN adoption rises in that jurisdiction, and a follow-up proposal appears to close the "gap." Utah became the first US state to meaningfully restrict VPN use, placing enforcement on site operators rather than users — creating an incentive to over-block anyone connecting through a VPN, regardless of why. 

Brazil treats VPN use as an aggravating factor in criminal sentencing; Michigan has a proposed VPN ban; Wisconsin removed a VPN provision before passage. A restriction on a general-purpose privacy tool used by journalists, researchers, people in abusive households, and anyone with a legitimate reason to browse privately is a considerably wider intervention than the child safety problem it's responding to.

Read the full article here.

Cutting the Network Is Now a Weapon of War

Conflict has been the leading trigger of internet shutdowns for several years running, and the tactic is becoming more deliberate — with strikes on cables and power infrastructure, cyberattacks, seizure of satellite terminals, and in some cases the criminalization of owning satellite internet equipment. When people found ways to stay connected after terrestrial networks failed, those fallback routes were closed too. 

Peace processes depend on communication: a ceasefire has to be monitored, violations have to be reported, and civilians have to be able to find out whether a route is safe. Ceasefire agreements almost never mention telecommunications infrastructure. International legal bodies are beginning to recognize that deliberately cutting communications during conflict isn't a neutral act — but the frameworks for accountability are still catching up to the targeting.

Read the full article here.

Trump Renamed a Lake. Apple, Google, and the US Government Complied

President Trump signed an executive order on August 27 renaming Lake Ontario to "Lake America," directing the Interior Department to update the US geographic naming service within 30 days. Apple Maps and Google Maps implemented the change shortly after; this week the National Weather Service and AccuWeather followed. 

The renaming applies to US-facing services only — a user in Europe opening the same apps still sees Lake Ontario; a user in Ohio sees Lake America, because the lake is shared with Canada, which has not renamed it and has no intention of doing so. It is a small and unusually visible illustration of something that happens constantly online: what the internet shows you depends not only on where you are, but on which government's instructions the platforms serving you have decided to follow.

Read the full article here.

Russia Is Now Attacking VPN Infrastructure Directly

Human Rights Watch published a report on September 24 documenting Russia's escalation from blocking individual VPNs to bulk IP takedowns, coordinated DDoS attacks, phishing campaigns against VPN employees, app store removals, and payment system restrictions. The clearest case is the June 2026 attack on Amnezia VPN — authorities blocked its IP addresses in bulk, ran simultaneous DDoS attacks, and targeted staff with phishing emails; it took a month and a half to fully restore service. 

In April, the Ministry of Digital Development instructed more than twenty of Russia's largest internet companies to detect and deny access to services when VPN connections are identified, with at least thirty major apps found to be gathering and sharing that data — which was then used in infrastructure attacks against the VPNs themselves. Despite 469 VPNs being blocked, advertising bans, criminal penalties, and payment restrictions, approximately 57 million Russians — 40% of the population — still use them.

Read the full article here.


Share on
Facebook share Twitter share Reddit share Linkedin share

Be part of the resistance, quietly.

Get Mysterium VPN Arrow icon
awareness campaign banner img
Image of author
Gintarė Mažonaitė
Tech Writer and VPN Researcher

Gintarė is a cybersecurity writer at Mysterium VPN, where she explores online privacy, VPN technology, and the latest digital threats in editorial pieces. With hands-on experience researching and writing about data protection and digital freedom, Gintarė makes complex security topics accessible and actionable.

Read our editorial policy here.

Read more by this author
© Copyright 2026 UAB "MN Intelligence"