Age verification can restrict entry to a service, but it cannot prevent abuse within or beyond it. South Korea’s enforcement data and Europe’s developing regulatory framework show why protection must combine age assurance with safety-by-design, rapid reporting, evidence preservation, victim support and measurable platform accountability.

Europe is betting heavily on age verification. South Korea has strengthened its laws against sexually explicit deepfakes. Neither approach, by itself, can protect a girl once abuse begins.
An age gate may determine whether someone is old enough to enter a platform. It cannot stop an abusive image from being created, circulated and repeatedly uploaded. It cannot preserve evidence, connect a victim to trained support or ensure that police receive usable information. Age verification is a gate. It is not a safety system.
“Age verification can restrict access to a platform, but it cannot function as a complete safety system. It does not independently prevent sexual deepfakes, cyberstalking, grooming or the redistribution of abusive material.”
Jessica Ingrid, lead author and Director of Institutum Lex Feminae
That distinction is being lost as governments search for a visible response to online harm. Across the European Union, policymakers are debating common age thresholds for social media. The European Commission has also developed a privacy-preserving age-verification solution that became feature-ready in April 2026. These measures may reduce access to adult content and help platforms distinguish adults from minors. They do not answer the harder question: what happens after a girl is targeted?
A girl who passes an age check can still be groomed, harassed, stalked or impersonated. A sexual deepfake can be created from an ordinary photograph, circulated through a private group and uploaded again after the first copy is removed. The platform may know her age while still failing to stop the abuse. The relevant test is not whether the platform identified a minor. It is whether the system protected her.
South Korea shows what happens when the law expands faster than the protection system surrounding it. Article 14-2 of the Act on Special Cases Concerning the Punishment of Sexual Crimes criminalizes the creation and distribution of sexually exploitative fabricated or altered material without the subject’s consent. Amendments adopted in October 2024 increased the maximum punishment for creation and distribution to seven years’ imprisonment or a fine of up to KRW 50 million. Possessing, purchasing, storing or viewing covered material is also punishable.
The criminal law is clear. The operational pressure is equally clear. During the 2025 cyber-sexual-violence enforcement period, Korean police recorded 4,413 cases, an increase of 35 percent. Sexual deepfake offences accounted for 35.2 percent of those cases. Child and adolescent sexual-abuse material accounted for another 34.3 percent. Police arrested 3,557 suspects. In the first phase of the 2026 intensive crackdown, police reported 1,446 cyber-sexual-violence cases.
Those numbers show enforcement activity. They do not show whether the protection system worked from the victim’s perspective. Publicly reported totals do not establish how quickly harmful material was removed, how often it returned, whether platforms preserved the evidence or how many victims received continuing support. An arrest figure cannot answer those questions.
This is the central weakness of a law-first response. Criminalization defines prohibited conduct and gives investigators a basis for action. It does not automatically create fast reporting channels, coordinated referrals or reliable evidence preservation. A legal offence is necessary. It is not the same thing as an operating safety system.
The EU has taken a different route, but it faces the same underlying weakness. The Digital Services Act requires platforms accessible to minors to provide a high level of privacy, safety and security. It also prohibits targeted advertising based on profiling when a platform knows with reasonable certainty that the recipient is a minor. The Commission’s guidelines add measures addressing recommender systems, default settings, addictive design, unwanted contact and age assurance.
The EU’s age-verification tool allows a person to prove that they are over 18 without disclosing other identity information. That is a meaningful privacy safeguard. It still proves only one thing: age. It does not prove that the service is safe, that abusive material will be found quickly or that a victim will receive help.
The Commission’s July 2026 Special Panel on Child Safety Online reached much the same conclusion. It recommended a harmonized restriction below age 13 and left Member States room to consider higher thresholds. It also reported that early experience with blanket age bans showed that many minors found ways around them. Its wider recommendations therefore addressed safe-by-design services, protective defaults, complaint mechanisms, support services, duties concerning child sexual abuse, researcher access to platform data and continuing evaluation.
That broader approach is important because children do not face identical risks. Rules written in gender-neutral language may protect everyone in theory while hiding who experiences particular forms of harm in practice. Girls can face sexualized image abuse, coercive demands for intimate material, impersonation and threats of disclosure. A platform may correctly verify that a user is 15 while failing to stop an adult from contacting her or a peer from generating a sexual deepfake.
This is why the number of completed age checks cannot be treated as proof of safety. Regulators need sex- and age-disaggregated information on reports, response times, removals, repeat uploads, account sanctions, evidence-preservation requests, referrals to police and access to victim services. Without those measures, a platform can appear compliant while the underlying abuse remains difficult to trace.
The same problem affects public accountability. Police may count cases, prosecutors may count defendants and platforms may count removed posts. If those datasets cannot be connected, no institution can show what happened to a victim from her first report to the final outcome. Fragmented statistics produce fragmented responsibility.
A genuine safety system must work before, during and after abuse. Before abuse, platforms need proportionate age assurance, protective default settings and product design that limits unwanted contact. When abuse occurs, users need visible reporting routes, trained escalation and rapid action against high-risk sexual content. Afterward, the system must preserve evidence, prevent repeat uploads where lawful and connect victims to specialist support and public authorities.
Each part must be measured separately. Removing one post is not the same as preventing its return. Closing an account is not the same as preserving evidence. Sending a child to a generic help page is not the same as providing trained assistance. Compliance should be judged by outcomes, not by the existence of a button or the number of identities checked.
This is also the gap JEMINAE® is being developed to address. Institutum Lex Feminae is designing the women-focused digital safety initiative around functions that an age gate cannot provide by itself, including secure evidence storage, guided access to support, safety check-ins and moderated community connection. JEMINAE is not a substitute for platform regulation, police action or specialist victim services. It reflects a different starting point: protection must continue after age or identity has been established.
That continuation is practical. A woman or girl facing harassment, stalking, coercion or image-based abuse may need to preserve material before it disappears, record a pattern over time, seek assistance and understand when escalation is necessary. A system that stops at verification leaves that work to the person already experiencing the harm.
South Korea demonstrates the urgency of enforcing laws against sexual deepfakes. The EU demonstrates the value of privacy-preserving age assurance and wider platform duties. Both show why governments should stop presenting entry controls as a complete answer.
The measure of online safety is not how many users were checked at the door. It is whether girls were protected once they entered, whether abuse was stopped, whether evidence survived and whether victims could reach help. Age gates were never going to do that alone. They were never safety systems.

Sources
• Korean National Police Agency, 2026 Cyber Sexual Violence Intensive Crackdown materials
• European Commission, Guidelines on the protection of minors under the Digital Services Act