Twenty-one states. One coordinated playbook. And sitting at the table: a trade association that profits from the exact mandates it’s lobbying for. According to a new investigation by Effort, five organizations have been publicly supporting or engaging around UK-style age-verification law and pushing similar measures into American legislatures:
- 5Rights Foundation
- the Center for Countering Digital Hate (CCDH)
- the Institute for Strategic Dialogue (ISD)
- Reset Tech
- the Age Verification Providers Association (AVPA)
Four are British; Reset Tech is a global consortium with a UK branch. All five have supported or engaged around the UK Online Safety Act. The pitch is child safety. What gets installed is something considerably broader.
Start with 5Rights, chaired by Baroness Beeban Kidron. According to the Foundation for Freedom Online and Effort, 5Rights engaged 42 bills across 18 US states; 11 became law. California’s Age Appropriate Design Code Act (AB 2273) was copied from the UK’s AADC “almost verbatim,” according to TBOTE Project. 5Rights paid California lobbying firm Capitol Connection $50,000 in 2022 to work that bill. The Foreign Agents Registration Act disclosure didn’t arrive until 2024 — more than a year after the bill passed. Neither 5Rights nor AVPA responded to requests for comment by publication time.
Baroness Kidron reportedly wrote that social media bans without VPN bans are “for show and headlines, not for children.”
The Vendor in the Room
AVPA lobbies for mandates its members are paid to fulfill — and chairs the standards committee that certifies the technology.
AVPA represents companies that build and sell age-verification technology. When mandates pass, its members get contracts. That alone is a conflict worth naming. Effort’s investigation goes further: AVPA’s Executive Director Iain Corby also chairs the IEEE 2089.1 certification program for online age verification — the technical standard his industry monetizes. AVPA has also pushed for age checks on VPN users under the UK Online Safety Act, treating the privacy tool people rely on as grounds for additional scrutiny.
What the investigation found:
- Reset Tech Action spent approximately $1,352,800 lobbying Congress and state legislatures between 2024 and mid-2026, overlapping with 5Rights on four bills
- ISD holds over $17 million in contracts from the US State Department, EU, and UK ministries; sits on Spotify’s Safety Advisory Council; participates in YouTube’s Trusted Flagger program
- CCDH CEO Imran Ahmed testified as the first witness before the UK Online Safety Act draft bill committee; the US House Judiciary Committee later characterized CCDH as a “biased, left-wing pseudoscience group”
- 5Rights paid Capitol Connection $50,000 in 2022; the FARA disclosure didn’t come until 2024
- All five organizations supported or engaged around the UK Online Safety Act before expanding their legislative efforts to the US
What “Child Safety” Actually Installs
Age-verification infrastructure doesn’t disappear after protecting kids — it becomes the default architecture for everyone.
If these bills pass at scale, platforms face pressure to verify age before granting access — and some implementations tie that process to real identity credentials. Anonymous browsing starts to look like an edge case rather than a default. The child safety argument is genuine; kids do encounter harmful content online. But the infrastructure these bills mandate tends to outlast the specific harms it targets.
The US House Judiciary Committee obtained documents from ISD to investigate how European regulators use third-party organizations to pressure platform speech.
Knowing what gets built before a bill passes matters as much as what the bill claims to protect. The architecture being constructed here — framed around minors, funded by vendors, exported from the UK — will shape how every adult accesses the internet long after any specific measure clears a statehouse. The danger is not hypothetical: a tracking users every four minutes, and a surveillance app built to target political dissidents, both illustrate how safety-framed digital tools can be repurposed well beyond their stated mandates.





























