
Utah has passed SB 73, requiring adult websites to verify the age of visitors physically located in the state even if they use VPNs or proxies to conceal their location, with penalties up to $2,500 per violation and restrictions on providing instructions to bypass age checks.
AI-generated summary
Utah is the first U.S. state to directly regulate VPN use in the context of age verification for adult content, building on prior efforts in Brazil and the UK to counter VPN-enabled evasion of age restrictions and platform bans.
Utah is testing new ground in the digital rights battle, becoming the first state to directly target VPN use for age verification.
The state will now require websites that host adult material to verify visitors’ ages even when VPNs hide their location, putting operators on the hook for determining whether users are physically inside the state.
Utah’s SB 73 requires commercial websites that “knowingly and intentionally publish or distribute material harmful to minors” to verify Utah visitors’ ages when that material exceeds one-third of their content—even if visitors conceal their location with VPNs or proxies.
“A commercial entity that operates a website that contains a substantial portion of material harmful to minors may not facilitate or encourage the use of a virtual private network, proxy server, or other means to circumvent age verification requirements,” the bill said.
Under the law, visitors physically in Utah count as Utah users regardless of whether they use a virtual private network, proxy server, or another tool to disguise their location. VPNs route traffic through remote servers, concealing the IP address a website would otherwise see.
The bill also restricts operators from helping visitors bypass age checks, including by providing instructions for accessing their websites through VPNs or evading geographic blocks.
The Division of Consumer Protection can impose administrative fines of up to $2,500 per violation. Courts can impose civil penalties of up to $2,500 per violation, alongside other remedies.
The statute also prohibits verification providers from retaining identifying information after granting access. Operators using verification methods that meet standards established by division rules are deemed compliant with the age-verification requirements.
Privacy company Nym argued on X that SB 73’s prohibition on covered websites providing VPN instructions to bypass age checks restricts speech about privacy tools.
“The law restricts speech about a privacy tool,” the company wrote. “That is a First Amendment question the courts have not answered yet.”
SB 73 is the latest action by regulators targeting VPNs both to enforce platform bans and to stop users bypassing age checks.
In September 2024, Brazilian authorities began investigating users suspected of using VPNs to evade the country’s temporary ban on X, with potential fines approaching $9,000 a day.
In July 2025, UK VPN demand surged more than 6,000% as age checks took effect.
“The reason there's an increase is because the UK passed an ill-thought-out Online Safety Bill,” Nym CEO and co-founder Harry Halpin told Decrypt at the time.
Nym, which operates a decentralized VPN service, saw its NYM token climb 12% during the surge, a day after launching its iOS app.
AI outlook — possibilities, not facts
The law will face legal challenges based on First Amendment grounds regarding speech about privacy tools
Likely · Within months
Other states may consider similar legislation targeting VPN use for age verification
Possible · Within months

Sen. Bernie Sanders and Rep. Greg Casar introduced legislation to ban artificial superintelligence and temporarily halt advanced AI development, citing safety concerns and proposing prison sentences up to 20 years for violations, following recent AI security breaches by OpenAI and Anthropic models.

Solana's SGP-0003 fee reform vote received majority support but failed due to a two-thirds supermajority requirement that counted abstentions, exposing a conflict between founder Anatoly Yakovenko's influence and validator/staker authority over network economic policy.

OpenAI unveiled GPT-6 Astra, with President Greg Brockman declaring it a generational leap and the arrival of artificial general intelligence. The model autonomously discovers and exploits zero-day vulnerabilities, scored 100% on ExploitBench, and outperforms predecessors in scientific and cybersecurity benchmarks. Its capabilities are initially restricted to cybersecurity defenders via the Daybreak Blue program due to safety concerns.

Major AI platforms ChatGPT, Claude, and Grok experienced simultaneous service disruptions on Thursday morning, affecting millions of users worldwide. OpenAI, Anthropic, and xAI acknowledged the outages, with OpenAI citing a routing error, Anthropic reporting two separate incidents affecting Claude models, and xAI confirming issues with Grok's web, mobile, and API services. Service was restored by early afternoon EST, marking another chapter in the ongoing reliability challenges faced by leading AI assistants amid intensifying competition.

Crypto recovery specialist Chris Brooks recounts a 2021 case where client Rusty claimed $53M in Bitcoin, but the recovery revealed only $10 and raised suspicions of scam.

A hacker linked to the third wave of Coldcard wallet thefts has begun swapping stolen Bitcoin for Ether via THORChain, moving roughly 10% of the stolen funds while facing technical hurdles.