The European Commission has built one age verification app. It has not built one age verification law.

That distinction is easy to miss in the headlines, which mostly cover the technical rollout: a privacy-preserving app, built on zero-knowledge-proof cryptography, that lets a user prove they're over an age threshold without handing over a birth date or ID scan. What the headlines skip is that the Commission's own framework for this is explicitly non-binding — member states keep full discretion over the actual rules riding on top of the shared technology. As one legal analysis of the rollout put it plainly: a common technical tool is emerging, but the compliance burden still varies by member state, and key compliance questions remain unanswered even as the technology arrives.

For merchants and payment providers operating across the EU, that gap between "one app" and "27 rulebooks" is where the real complexity lives — and it's a payments problem as much as a legal one. Every additional national requirement is a new on-boarding flow to build, a new dispute pattern to watch, and a new variable for the acquirer underwriting the account.

The Common Layer: What the EU Actually Built

On April 15, 2026, Commission President Ursula von der Leyen announced the EU's age verification app was technically ready, built by Scytáles and T-Systems on the European Digital Identity (EUDI) Wallet framework. It works like a digital proof of age — similar to showing an ID in the physical world — but it's designed to integrate with national digital identity systems, stay open source, and reveal nothing beyond a simple yes-or-no answer to an age question. No birthdate, no document, no tracking, no profiling.

Two weeks later, on April 29, the Commission published its Recommendation on a common EU-wide approach to age-verification technology, built around a shared technical "blueprint" aligned with the EUDI Wallet. That Recommendation set two concrete dates: June 30, 2026, by which member states are encouraged to submit implementation plans, and December 31, 2026, the target for at least one EU-compliant age-verification solution to be live in every member state. By May 11, the Commission confirmed the technology itself was ready for immediate deployment — the barrier left standing wasn't technical, it was regulatory.

The Commission has been explicit that it wants to avoid fragmenting the EU's internal market, and the Recommendation says national measures should stay compatible with the DSA's harmonized framework. But "should stay compatible" is doing a lot of work in that sentence. Member states are free to legislate on top of the shared technology, and several already have — years before the EU's own app was ready.

Timeline of the EU's common age verification technology rollout in 2026, from the app's technical debut to the end-of-year EU-wide availability target

The National Layer: Three Very Different Rulebooks

What sits on top of that common technology is where the divergence starts. As of May 2026, 23 of the EU's 27 member states were considering or already enforcing national age-verification legislation — differing on age thresholds, enforcement mechanisms, and which services are even in scope. Even the definition of "minor" isn't harmonized: the Commission's Recommendation uses under-18, but national laws range from 13 to 18 depending on the country. Three examples show how differently this is playing out in practice, and none of them waited for Brussels.

France runs the EU's most prescriptive regime, and it got there years before the EU app existed. The framework traces back to a 2020 law protecting domestic-violence victims, which gave the regulator Arcom power to order pornographic sites blocked for non-compliance. The SREN Law of May 2024 sharpened that into a full technical standard, published by Arcom in October 2024, with platforms given until January 11, 2025 to comply and a further transition — allowing card-based verification as an interim measure — until April 11, 2025. After that date, card-based checks were no longer sufficient on their own. Platforms now need at least two verification methods, with one operating under a "double-blind" model: the platform never learns the user's identity, and the verification provider never learns which site the user visited. Enforcement has been active. In February 2025, an order extended the law's scope to 17 EU-based pornography services; in August 2025, Arcom issued formal notices to five of them for still lacking adequate verification, a decision upheld by France's highest administrative court when challenged. Since June 2025, the law applies to any site reachable from France regardless of where it's hosted — meaning a platform's physical location is no defense. Non-compliant sites face a 48-hour window before internet providers, search engines, and domain resolvers are ordered to cut off access. The scale of what's driving this is worth noting: French regulators have cited roughly 2.3 million minors accessing adult content online every month as the baseline the law is trying to close.

Germany enforces age verification through the JMStV, its youth media protection treaty dating back to 2003, overseen by the KJM regulator working alongside self-regulatory bodies like the FSM. Self-declaration and simple age gates are explicitly rejected; providers must use a system the KJM has positively evaluated, such as document-plus-biometric checks or certified facial age estimation. The consequential change came on December 1, 2025: German media regulators gained the power to instruct banks and payment service providers directly to halt financial transactions to non-compliant platforms — regardless of where the platform is incorporated. Germany's youth-protection framework is also reaching further into infrastructure: by December 2026, regulators are expected to designate which operating-system providers fall within scope of these obligations too. Age verification enforcement in Germany now runs, in part, through the payment rail itself, not just through content-blocking.

Spain is a step behind both in terms of binding law, but signals where a meaningful bloc of member states may be heading. In February 2026, Prime Minister Pedro Sánchez announced a proposal to ban social media for under-16s entirely, paired with mandatory age verification, greater accountability for platform executives, and criminal liability for algorithmic manipulation aimed at minors. Sánchez described Spain as joining a "coalition of the digitally willing" — a group of member states pushing for coordinated cross-border rules outside the formal EU legislative process. The proposal still needs parliamentary approval, and the governing coalition doesn't currently hold a majority, so it isn't law yet. But it's a preview of the next wave, not an outlier.

Comparison of age verification approaches in France, Germany, and Spain, showing three different national rulebooks within the EU

Where This Is Headed Next

The fragmentation isn't a temporary phase the EU app will smooth over — if anything, Brussels is signaling it wants to build more rules on top of the same foundation. On May 12, 2026, von der Leyen indicated the Commission is actively assessing further steps: minimum age requirements for accessing certain platforms, and a possible "social media delay" that would restrict access for younger users EU-wide. No legislative proposal has been tabled, but she floated a potential initiative as early as summer 2026. Separately, the Audiovisual Media Services Directive — which already requires member states to protect minors through tools like content rating and parental controls — is under a Commission review due to report in 2026, with an update to the rules expected in the third quarter.

The pattern across all of this is consistent: the EU keeps building shared technical infrastructure while leaving the actual legal requirements to accumulate at the national level, one country at a time.

Why This Is Specifically a Payments Problem

Three consequences of this fragmentation land directly on the payment stack, not the legal team.

The first is that card-based age verification is no longer a safe default anywhere it was once tolerated. France explicitly discontinued it as a standalone compliance method in April 2025.

The second is that non-compliance can now cut off payment rails directly, not just trigger a fine sitting in a legal inbox. Germany's December 2025 shift turns an age-verification failure into an immediate processing problem.

The third is underwriting complexity. An acquirer assessing a merchant active across France, Germany, and Spain is weighing three different enforcement regimes, not one — exactly the kind of complexity covered in our piece on KYC/AML friction vs. conversion, except now multiplied by jurisdiction.

Three ways age verification fragmentation creates payments-specific risk: discontinued card-based verification, payment-blocking enforcement, and cross-border underwriting complexity

What to Build For

Track each active market's specific rules individually, rather than assuming DSA compliance or the EU app alone covers national requirements. Favor interoperable, certified verification methods over anything ad hoc or card-based. Treat payment continuity as part of the compliance conversation, not separate from it. And build monitoring for what's coming, not just what's already in force.

Four practices for merchants navigating fragmented EU age verification rules: per-market tracking, certified methods, payment continuity planning, and monitoring upcoming EU rules

Why the Fragmentation Is Legally Possible in the First Place

It's worth understanding the legal mechanism behind this, because it explains why the fragmentation isn't a temporary gap the EU app will eventually close. The DSA is generally built on a "country-of-origin" principle: a platform is primarily regulated by the member state where it's established, not by every state where its users happen to be. That's the harmonizing logic the Commission keeps pointing to when it says national measures should "stay compatible" with the DSA framework.

France's SREN Law doesn't work that way. It applies based on reachability — any site accessible from France that shows pornographic content falls under Arcom's authority, regardless of where the platform is established or hosted. That's a destination-based approach layered directly on top of a framework built around origin-based regulation, and it's precisely the kind of tension the Commission's own Recommendation acknowledges without resolving. Legal commentators tracking this describe the DSA as silent on what counts as illegal content in the first place — that's left to national law — which means the "harmonized" framework was never going to produce one rulebook. It was built to coexist with several.

That matters for payments because it means the fragmentation is structural, not a rollout delay.

What "Compliant" Actually Looks Like on the Ground

Germany's approval-list model is worth walking through in detail, because it shows how far "have an age gate" has moved from what regulators now expect. The KJM doesn't mandate a specific technology — the JMStV sets a functional requirement, not a technical one — but in practice, only systems that have gone through FSM assessment and received a positive KJM evaluation are treated as legally valid. On June 29, 2026, for example, the FSM Expert Commission certified a document-plus-biometric verification system as meeting the standard for establishing a "closed user group" under the JMStV: users capture a government ID for data extraction and authenticity checks, pass a real-time liveness and face-match step, and only then receive automatic age confirmation. Other KJM-accepted approaches include facial age estimation with a multi-year buffer built in above the 18+ threshold, and digital-wallet-based proof of age that a user completes once and then reuses across sites with a single click.

None of these are simple age gates, and none of them are a credit card number. That's the direction every enforcement regime covered here is moving in — toward methods that are independently assessed, privacy-preserving by design, and reusable across services.

A Fourth Consequence: Dispute Handling Gets Fragmented Too

The three payments consequences already covered have a natural extension into dispute handling itself. If a chargeback originates from a transaction where age verification is later found inadequate, the classification of that dispute, and which party bears responsibility for it, may depend on which country's rules applied to that specific transaction. A merchant operating in France, Germany, and Spain simultaneously isn't just running three verification flows — it's potentially running three different dispute-liability frameworks in parallel.

Age verification was never going to stay a legal team's problem once it started determining who gets to complete a purchase — and in Germany, it's now determining whether that purchase can be processed at all. The EU's December 31, 2026 target for a compliant solution in every member state is a real deadline, but it's a floor, not a ceiling. France, Germany, and Spain are each already operating past it in their own way, and the country-of-origin tension underneath the DSA means a fourth or fifth national approach is entirely possible before the year is out.

MMG Corporation works with high-risk merchants navigating exactly this kind of cross-border regulatory complexity across EU markets. If you're weighing how age verification fits into your payment setup market by market, we're glad to talk it through.

Get in touch

This article was researched and written with the help of AI tools as part of our content process, and reviewed and fact-checked by the MMG team before publication.