Threat modeling age-based content restrictions: what we learned at EIC 2026

Imported from official source

Announcement

Cybersecurity Classified by Officially

Several stages of the threat modeling workshop

At the European Identity and Cloud Conference (EIC 2026) in Berlin, we ran a hands-on threat modeling workshop using LEGO® SERIOUS PLAY® as a facilitation method. The session built on the approach described in our earlier W3C post on threat modeling with LEGO® SERIOUS PLAY®, but used a more specific case: age-based content restrictions.

The choice was deliberate. EIC is one of the places where the digital identity market is visible while it is still taking shape. At EIC 2025, much of the conversation was about personal wallets: how to build them, distribute them, and get them adopted by relying parties, governments, and users. At EIC 2026, the discussion had shifted. AI was everywhere, and in identity that meant agent identity, non-human identities, workload identity, delegation, and intent verification in agentic scenarios.

The age-based content restriction use case

That does not mean human identity has disappeared from the agenda. It means the harder questions are now tied to concrete uses. Age-based content restrictions are one of those cases.

They are difficult because regulators are asking for operational solutions now, while the technical architecture is still unsettled. A design that affects access, privacy, anonymity, and interoperability can also create exclusion, surveillance, censorship, or reuse of the same infrastructure for other purposes.

This was also reflected in October 2025, when W3C and IAB organized a joint workshop on age-based restrictions for access to online content. That workshop focused on technical and architectural choices without assuming that there is a single correct solution.

This is an extract. The publication continues at the source.

Read the original at the source: https://www.w3.org/blog/2026/threat-modeling-age-based-content-restrictions-what-we-learned-at-eic-2026/

Officially imported this from World Wide Web Consortium’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

This publication has changed since it was first published

2 versions recorded. The original is kept in full — nothing is overwritten.

  1. v2 imported change on current
  2. v1 as first published on

Provenance

Organization
World Wide Web Consortium — imported from official source
Official source
https://www.w3.org/blog/feed/ RSS
Imported
September 15, 2026 20:43
Versions
2 recorded
Identity
https://www.w3.org/blog/2026/threat-modeling-age-based-content-restrictions-what-we-lea...

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.