Language: English
Privacy in Europe, and the wider Western world, is undergoing a structural shift toward proactive systems of identity verification, communication governance, environmental sensing, and data infrastructure control.
This talk examines four converging mechanisms driving this transition: age verification frameworks that bind access to verified identity; ongoing EU-level proposals around inspection of private encrypted communications under the guise of child safety; expansion of ubiquitous physical-world surveillance through biometric systems, and mobile inference; and the accelerating impact of AI systems that transform public data into inferential and generative models with limited provenance guarantees. Together, these developments suggest a move away from privacy as a default property of digital systems toward privacy as a conditional, regulated state contingent on compliance with layered technical and legal requirements. Using global trajectory as the primary case study, the talk argues that these mechanisms are not isolated policy choices but components of a broader convergence toward an "access-controlled internet," where identity, communication, and content are increasingly mediated by interoperable governance systems rather than open network principles.
Outline [do not publish]
Opening - "Nothing to Hide" Revisited
a. "If you have nothing to hide, you have nothing to fear" as enduring political slogan
b. What changed over the last 8 years? Shift from surveillance debate to access control debate
c. Privacy no longer framed as secrecy, but as conditional permission
Core thesis: internet is becoming a permission system, not a networkWhat Privacy Used to Mean
a. Autonomy over data processing and interpretation
b. Ability to communicate without systemic inspection
c. Right to remain untracked in physical and digital space
d. Anonymous access as default, not exceptionThe Structural Shift (2018 -> 2026+)
a. From observation (surveillance) to enforcement (compliance)
b. From "data collection" to "identity verification"
c. From passive tracking to active gatekeeping
d. From technical capability to legal obligationIdentity Layer - Age Verification
a. California's Digital Age Assurance Act enforcing age assurance for access to content
b. Canada's Safe Social Media Act and UK's Online Safety Act following in California's footsteps
c. EU digital identity frameworks enabling cross-platform verification- Facial age estimation, ID checks, financial verification systems
- Anonymous access increasingly treated as risky
Communication Layer - Chat Control
a. EU proposals for scanning private communications, including encrypted contexts (chat-control)
b. Canadian Lawful Access Act "modernizing" police access to communications
c. "Safety obligations" and Online Safety Bill (so-far failed) attempts to backdoor encrpytionEnvironment Layer - Ubiquitous Physical Surveillance
a. CCTV + facial, gait recognition expansion in public space
b. EU border systems (biometric entry/exit, travel tracking)
c. Mobile location inference, telecom metadata, transport, "smart city" infrastructure linking identity
d. Movement data becomes continuous identity signal rather than discrete eventsContent Layer - AI Systems and Information Collapse (worldwide)
a. Web data ingestion into training pipelines
b. Re-identification and inference from aggregated datasets
c. Synthetic content flooding original human content in a self-degrading feedback loopUnification - The Four-Layer Stack - supported by the EU Data Act
a. Identity: who you are (verification systems)
b. Communication: what you say (chat inspection pressure)
c. Environment: where you are (sensing systems)
d. Content: what is created (AI generation + training loop)
e. Data becomes governed infrastructureConvergence Pattern
a. Different legal systems, shared architectural direction
b. Regulation drives interoperability of identity systems
c. Platform liability shifts enforcement onto infrastructure providersClosing - Redefinition of Privacy
a. "Nothing to Hide" is now an access requirement
b. The internet will become verified, inspectable, and attributable
Kirils Solovjovs is Latvia's leading white-hat hacker and privacy activist. He began programming at age 7, and by grade 9 was already writing machine code directly in a hex editor during lunch breaks. His hobby is asking "what are you gonna do with that piece of information about me?" everywhere every time.
Renowned for uncovering and responsibly disclosing critical vulnerabilities in national and international systems, today Kirils serves as lead researcher at Possible Security.