background image blur
background image
  • Blog
    >
  • News
    >
  • Internet Freedom Weekly: News Recap, September 28th–October 2nd 2026

Internet Freedom Weekly: News Recap, September 28th–October 2nd 2026

Image of author
By Tech Writer and VPN Researcher Gintarė Mažonaitė
clock icon
Last updated: 2 October, 2026
Young woman reads the news on her phone while on the subway

The EU KIDS Act Explained: What It Does and What It Means

We covered the KIDS Act announcement within hours of von der Leyen's State of the Union address. Now that the Commission has published its full FAQ, the picture is clearer. The law does two things: a three-tier age staircase — no accounts under 13, parent-supervised accounts for ages 13 to 14 with a one-hour daily limit, independent accounts from 15 — and a safe-by-design mandate covering social media, video platforms, games, AI chatbots, and app stores, banning infinite scrolling, streak mechanics, and recommender systems optimized for engagement over wellbeing. 

Age verification uses "zero-knowledge proof" technology that tells the platform only whether a user is above or below the threshold. Very large platforms must submit audited compliance plans before their services come into contact with children, at their own expense. Fines reach 6% of global annual turnover.

Read the full article here.

A Federal Judge Blocked Utah's VPN Age Verification Law

U.S. District Judge David Barlow granted a preliminary injunction against Utah's SB 73 — the first US state law to explicitly require platforms to identify and geolocate users even when they're using a VPN — finding the mandates "likely to violate the United States Constitution." 

The judge's reasoning is technical and constitutional simultaneously: perfect geolocation doesn't exist, and demanding platforms bypass encrypted traffic to determine a user's physical location isn't just unreliable; it creates free speech and privacy problems that the age verification goal doesn't justify. The law also banned websites from explaining how VPNs work — a direct restriction on communicating lawful information. The ruling is preliminary, and Utah may appeal, but it creates a judicial record other states drafting similar provisions will need to reckon with.

Read the full article here.

Pennsylvania's Age Verification Bill Would Expose Adults to ID Theft and Blackmail

Pennsylvania's Senate Judiciary Committee advanced SB 603 on September 28th, requiring state ID verification before accessing any website where at least one-third of content is adult material — without specifying how that data must be secured or protected from misuse. The bill uses private right of action enforcement rather than state attorney general oversight, meaning any website arguably in scope faces lawsuit risk and will over-gate content to avoid it. 

Sen. Maria Collett voted against it after naming the specific risk: age verification for adult content creates a linkage between an identity document and a record of access — exactly the data that enables targeted blackmail. A third senator voted yes while acknowledging the privacy concerns and calling for future amendments, saying "I suspect this will not be the last word on this."

Read the full article here.

Russia Struck Ukraine's Largest Mobile Provider

According to Reuters, Russia struck the Kyiv headquarters of Kyivstar — Ukraine's largest mobile service provider — with a jet drone on September 27th, the same day Russia's defense ministry claimed a strike on a Vodafone Ukraine data center. Over the preceding week, attacks on Ukrainian internet provider infrastructure caused outages for around 100,000 households in Kyiv and the region. 

Ukraine's foreign minister said missile alert systems depend on the communications infrastructure Russia is bombing — the alerts that tell people to take shelter run on the same networks being struck. We wrote this week that cutting connectivity has become a deliberate weapon of war rather than a side effect of fighting. The Kyivstar strike is what we were describing.

Read the full article here.

Malaysia Wants a Freedom of Information Law. It's Not Enough

September 28th was the International Day for Universal Access to Information, and Malaysia's parliament is currently considering its first federal FOI bill. The Center for Law and Democracy assessed it at 47 out of 150 points under its Right to Information Rating methodology — reflecting gaps including no independent oversight body, no requirement for proactive disclosure, and no protection against existing secrecy laws like the Official Secrets Act overriding it. 

The same culture of secrecy is on live display in the Najib Razak pardon case, where the Pardons Board minutes, the AG's submission, and the conditions governing a politically sensitive house arrest arrangement haven't been published. Civil society organizations are calling for the bill to be substantially strengthened before it passes.

Read the full article here.

A Right to Information Assumes It Still Exists

Access to information laws grant the right to request records. They say very little about whether those records must be preserved and remain reachable. The Internet Archive's Vanishing Culture project documents how much web content published a decade ago is no longer accessible — through link rot, platform shutdowns, and institutional churn. 

The material most likely to vanish is the material nobody was resourced to maintain: local government pages, small publications, the working documentation of bodies that have since been restructured. The closest thing the public has to a systematic record of the web is maintained by nonprofits and volunteers operating without a public mandate or stable funding. A right to request something that no longer exists isn't a meaningful right.

Read the full article here.

The One-Language Internet Is a Form of Censorship

September 30th was International Translation Day. Most of the world's languages are functionally absent from the internet, and the effect on speakers resembles censorship even though nobody issued a ban. AI tools perform well in languages with large training data sets and considerably worse elsewhere — while sounding equally confident in both, making the gap invisible to users. 

The Gates Foundation's coalition of 60 organizations, including Anthropic, Google, and the OpenAI Foundation, represents a genuine shift: treating language coverage as infrastructure rather than a localization step applied after a product already works. How that data gets collected matters as much as whether it exists — communities are asking who controls translations of their languages and whether consent was given.

Read the full article here.

Reddit Is Closing Off the Open Web, One Restriction at a Time

Reddit announced on September 30th that it’ll limit Old Reddit access to logged-in users who've visited within the previous six months — building on a July login requirement — and will discontinue RSS feed support entirely on November 13, with no replacement for non-moderator users. Reddit frames both changes as anti-scraping measures, and scraping is a real problem. 

But the mechanism applies equally to bots and to anyone who reads Reddit through an RSS reader or visits infrequently. Each restriction moves Reddit further from a place you can access without identifying yourself and closer to a fully authenticated, fully tracked platform. "RSS has been a beloved part of the open web for a long time," Reddit's announcement said — in the same post ending its support.

Read the full article here.

Every New Verification Wall Excludes Someone

October 1st was the International Day of Older Persons. The internet has been getting steadily harder to use, and each added verification step — identity checks, biometric scans, app-only access, two-factor codes — quietly removes people who can't complete it. Older adults are the group most affected and also the group most likely to depend on the services now sitting behind those layers. 

Age verification has expanded from adult sites into social media, app stores, and operating systems, and the debate focuses almost entirely on whether it keeps minors out — not on whether it locks an eighty-year-old out of their pharmacy portal. The same identity data being collected also turns up in breaches, transferring risk onto the people least equipped to detect or respond to identity fraud.

Read the full article here.

London Scanned 500,000 Faces in Six Months. Made Zero Arrests

According to a freedom of information document obtained by Liberty Investigates and The Guardian, the British Transport Police's six-month live facial recognition trial at London railway stations scanned more than 500,000 faces, produced one alert — a false match — and led to zero arrests from LFR alerts. The trial cost more than £320,000 and consumed almost 100 hours of police officers' time. 

BTP said officers made "associated arrests" for other offences during the period, but noted those aren't counted in LFR performance data — which recorded nothing. We weren't surprised: when BTP expanded the trial to the London Underground in September, we wrote that the technology being expanded had produced no arrests. Parliament's joint committee on human rights called the rollout a "particularly clear example of risk." The trial is being extended anyway.

Read the full article here.


Share on
Facebook share Twitter share Reddit share Linkedin share

Be part of the resistance, quietly.

Get Mysterium VPN Arrow icon
awareness campaign banner img
Image of author
Gintarė Mažonaitė
Tech Writer and VPN Researcher

Gintarė is a cybersecurity writer at Mysterium VPN, where she explores online privacy, VPN technology, and the latest digital threats in editorial pieces. With hands-on experience researching and writing about data protection and digital freedom, Gintarė makes complex security topics accessible and actionable.

Read our editorial policy here.

Read more by this author
© Copyright 2026 UAB "MN Intelligence"