The frontend source code of Persona, which Discord had used for age verification, was accidentally made public. Analysis of the code sparked controversy because, although it was supposedly being used for “age verification,” modules were found for checking facial images against watchlists and PEP lists and for reporting directly to governments.
What Was “Found”
What researchers and hacktivists found was Persona’s frontend (2,456 files) on a server authorized for use by the U.S. government (federal agencies). Reports say that the following can be inferred from it.
- Implementations of 269 types of verification checks.
- Functionality for checking facial images against watchlists and PEP lists.
- “Adverse media” screening functionality covering 14 categories, including terrorism and espionage.
- A design capable of retaining IP addresses, browser/device fingerprints, government ID numbers, phone numbers, names, facial images, and selfie analysis data (including age-discrepancy detection) for up to 3 years.
In addition, the following modules were reportedly confirmed within the same codebase.
- A module for submitting Suspicious Activity Reports (SARs) to FinCEN (implemented in accordance with the XML schema on the FinCEN website).
- A module for submitting Suspicious Transaction Reports (STRs) to Canada’s FINTRAC.
In other words, what had been exposed was not a “single-purpose library for age verification,” but an entire frontend for a fully featured KYC/AML platform. This has led to an outpouring of doubts and controversy over whether Discord’s “age verification” really was age verification.
What Discord’s Age Verification Can Actually Be Considered to Have Done
However, based on currently available public information, it is not known which functions were actually enabled.
- Discord initially claimed that facial images were processed on the device, but it was later reported to have explained that, in implementations using Persona, they were sent to a server and retained for up to 7 days.
- The leaked code shows that this was a “general-purpose KYC/AML engine” that included PEP, sanctions, adverse media, and FinCEN/FINTRAC reporting capabilities.
It is not surprising—in fact, it is to be expected—that Persona’s codebase includes such modules. That is because Persona’s customers include cryptocurrency exchanges and financial-institution-affiliated FinTech companies. However, the following points are merely inferred from the “existence of the code.”
- Whether PEP/sanctions screening was necessarily performed for every age-verification transaction.
- Whether SARs/STRs were automatically submitted to FinCEN, FINTRAC, or other bodies based on age-verification results or user behavior.
Reports and other information available at this stage do not reveal whether these functions were enabled in the configuration used for Discord.
Therefore,
- “Age verification was performed on the same platform, on which PEP, sanctions, and FinCEN compliance functions were also implemented and available for use.”
- However, the evidence does not support going so far as to say that “PEP checks or FinCEN reports were necessarily run for every age-verification transaction” (this remains a concern or suspicion).
This would be a reasonable understanding.
Even So, What Is Being Seen as the Problem?
The technical and legal facts are still at the “under investigation” stage, but the matter is attracting criticism for the following reasons.
- Excessive design seemingly unrelated to the stated purpose
Although it was supposedly “only determining whether someone was at least 18 years old,” the underlying stack was a massive KYC/AML suite capable of PEP, sanctions, adverse-media checks, and regulatory reporting. - Lack of transparency
Users were told it was merely “age verification,” while the fact that their data was actually being processed on a full financial-surveillance stack was not disclosed in advance. - Concerns over data retention and “sharing”
There is a gap between Discord’s promises (short-term retention/minimal use) and the design shown in Persona’s codebase, which can retain data for up to 3 years and includes modules for working with government agencies.
In particular, because code for SAR/STR integration with regulators emerged, suspicions that users might be reported to FinCEN and other bodies have spread rapidly.
How Discord and Persona Could Dispel Suspicions in This Situation
It is nearly impossible to prove that something was not done, but to demonstrate with some credibility that it was not done would require the following.
- A design in which the function cannot be reached or used due to the configuration and architecture.
- No traces of the function’s use in operational logs (KYC event logs, external-integration logs, and SAR management logs).
- Evidence that the data was not retained long-term or used for secondary purposes (retention and deletion logs).
- An audit report in which a third party verified these points.
These 4 layers would need to be in place before experts could conclude that, at the very least, it is unlikely that the functions “had been used.”
At present, based on public information, the only country where Discord’s use of Persona can be explicitly confirmed is effectively the United Kingdom (UK). Attention is therefore focused on how the UK’s data protection regulator (ICO) will respond…
Discord Has Already Ended Its Contract with Persona
In fact, Discord has already ended its contract with Persona. This was due to a combination of suspicions that data was being handled more extensively than had been explained and distrust of the vendor’s nature and political background, which prompted a major backlash.
The main points at issue can largely be summarized in the following 3 categories.
- Server-side processing and retention periods that differed from the explanation
- Discord initially told users that “facial scans are processed on the device,” but its UK FAQ stated that the trial using Persona would “store submitted information on the server for up to 7 days.”
- After this notice in the FAQ was published, Discord quickly removed it, raising suspicions that it may have been trying to conceal the information.
- The Vendor’s Ties to Surveillance and Government Interests
- Persona has received investment from Peter Thiel’s Founders Fund. Because Thiel, as a co-founder of Palantir, has been deeply involved in government surveillance infrastructure, critics said they did not want to hand biometric information to a vendor connected to actors associated with a surveillance state.
- Lack of Transparency and the Treatment of the “Trial”
- Persona was not initially included on Discord’s “official partner list” or similar materials, and the trial appeared to have been conducted quietly and only with UK users.
- Explanations of the trial’s scope, the specific processing performed, and who could access the data came only afterward and were fragmentary, leading to criticism that users had been treated as test subjects and that the quality of consent was inadequate.
According to an investigative article by Redact, “a few days” after the backlash against the announcement of global age verification, the Persona trial began to be observed among UK users. This suggests that it was a very brief test conducted from early to mid-February 2026.
So What Will Discord Use?
At present, Discord is moving toward using Singapore’s k-ID and the UK’s Yoti (in Europe and some other regions) for age verification (age assurance). Both estimate age from facial images captured by a camera (Age estimation) and, when there is doubt, cross-check the result against other evidence. This resembles ISO/IEC 27566-1 Age assurance systems — Part 1: Framework (Age assurance systems—Part 1: Framework, available free of charge). However, each has its own characteristics.
Age estimation through facial scans
- k-ID: Facial scans can be processed entirely on the device, with an implementation in which facial information never leaves the device (server-side verification functionality is also offered).
- Yoti: Facial images are sent to a server, where age is estimated, and then immediately deleted.
Other age-verification methods
- k-ID: Parental consent/guardian verification (using email verification, credit-card payments, national IDs, and other means), and checks against trusted third-party data sources.
- Yoti: A digital identity wallet, or identity document (ID) plus selfie matching.
It appears that k-ID will be used globally, but the name k-ID alone does not reveal whether processing will take place on the device or on the server. Discord appears to have stated in some contexts that it will be “on-device.” To ensure transparency, it is desirable that Discord publish third-party certification or verification results that would allow this claim to be checked.
(References)
- Redact. (2026). Discord Tested Age Verification Vendor Persona: What Users Should Know. 2026-02-16. https://redact.dev/blog/discord-persona-age-verification-experiment
- Bernier, Rony. (2026). Discord ends Persona Age Verification test activity. LinkedIn. 2026-02-16. https://www.linkedin.com/posts/rorybernier_discord-ends-persona-age-verification-test-activity-7428905652959358977-CTB2/
- Cress, Laura. (2026). ‘I do not trust them’ – top streamers left concerned by Discord age checks. BBC. 2026-02-17. https://www.bbc.com/news/articles/cn4g8ynpwl8o
- Naprys, Ernestas. (2026). Firm that verifies mugshots for ChatGPT and Roblox feeds US surveillance apparatus with 269 distinct checks. Cybernews. 2026-02-19. https://cybernews.com/privacy/persona-leak-exposes-global-surveillance-capabilities/
- Alajaji, R and S. Baldwin. (2026). Discord Voluntarily Pushes Mandatory Age Verification Despite Recent Data Breach. 2026-02-12. https://www.eff.org/deeplinks/2026/02/discord-voluntarily-pushes-mandatory-age-verification-despite-recent-data-breach
- L0la L33tz. (2026). Hackers Expose Age-Verification Software Powering Surveillance Web. 2026-02-19. https://www.therage.co/persona-age-verification/
- ISO/IEC 27566-1. (2025). Information security, cybersecurity and privacy protection — Age assurance systems — Part 1: Framework. 2025-12. https://www.iso.org/standard/88143.html
Related posts

Data Sustains Lives—MyDataConference 2026 Opening Address
The following is the opening address for the MyData Japan Conference 2026, delivered by Nat Sakimura in his capacity as Chair of the General Incorporated Association…

The MyData Conference 2026 Is This Wednesday. See You at Hitotsubashi Hall!
I have been posting announcements on X every few days, and the MyDataJapan Conference 2026 is this Wednesday. There are many highlights: Naohiro Fujie, Representative Director…

Unsubmitted Public Comment on the Call for Comments on the Draft First Report of the Youth Protection Working Group on Information Distribution in the Digital Space
July 823:59 was the deadline for the call for comments on the draft first report. I ended the FAPI WG early and23:40 began the submission process…
