Why Utah’s VPN Law Hit a Technical Wall
The internet does not carry a physical address
Picture a website trying to enforce an invisible state border. A person in Salt Lake City opens a virtual private network, or VPN, and sends traffic through a server in Chicago. The website receives a request that appears to come from Chicago. The network has not malfunctioned; it has done what a VPN is designed to do.
That is the technical fault line behind Utah’s VPN law and the federal court’s September 24, 2026 order. The law treated a visitor’s hidden physical location as something a website could determine with certainty, even though the underlying network signals do not provide that certainty. (law.justia.com)
What a VPN changes
An Internet Protocol address, usually called an IP address, is the network address used to route internet traffic. Websites can use IP addresses for geolocation, which means estimating where a connection originates. For ordinary home broadband or mobile connections, that estimate can often identify a country, state, or metro area.
An IP address is not a GPS coordinate, though. With a VPN, your device creates an encrypted connection to an intermediary server operated by the VPN provider. The destination website normally sees the VPN server’s public IP address instead of the address assigned to your home or phone connection.
No VPN:
device in Salt Lake City → internet provider → website
website sees: Utah-associated IP address
VPN:
device in Salt Lake City → encrypted tunnel → VPN server in Chicago → website
website sees: Chicago-associated IP address
The VPN provider may have its own information about the original connection, depending on how the service operates. The destination website, however, has lost the most direct location signal. A proxy server creates a similar problem by relaying requests through another network location. Location obfuscation is the broad term for techniques that hide or distort these signals. (law.justia.com)
Why can’t a website tell where a VPN user really is?
A website can look for clues. It might compare the connecting IP address against lists of known VPN servers, examine connection latency—the time data takes to travel back and forth—or inspect a browser’s time-zone setting. It may receive other device or account information, too.
Those clues can improve an estimate, but they do not turn the estimate into proof. A known VPN address may reveal that traffic is being relayed, yet it cannot reliably reveal whether the person began in Utah, another state, or another country. A browser time zone can be changed or left unchanged while traveling. GPS data may not be available at all, and collecting precise location data creates its own privacy and security concerns.
This distinction is easy to miss because modern geolocation often feels precise. Maps can place a phone on a street corner, and delivery apps can estimate arrival times down to a few minutes. A website receiving a remote network connection is working with a different and thinner set of evidence.
The legal switch from reasonable to perfect
Utah Senate Bill 73, which took effect for the relevant provisions on May 6, 2026, continued the state’s requirement that certain websites use age-verification methods before showing material considered harmful to minors. Age verification means using a process to determine whether a person is at least 18, such as a digital identification card, a third-party service, or another approved method.
The amendment added a separate actual-location provision. It said a person should be treated as accessing a website from Utah when physically located there, even while using a VPN, proxy server, or another tool that makes the connection appear to come from elsewhere. The law also barred covered websites from facilitating or encouraging VPN-based circumvention of the age check. (le.utah.gov)
The wording mattered. The statute described age-verification methods as reasonable, but it did not add the same qualifier to the job of determining physical location. Utah argued that officials would still expect only reasonable efforts. The court responded that judges must interpret the law that lawmakers enacted, not insert a limitation that the text does not contain.
The impossible branch in the code
The problem becomes clearer when expressed as a small piece of logic:
if visitor_is_physically_in_utah:
require_age_verification
else:
allow_access
The application needs a fact: where the visitor is physically located. In practice, it receives a confidence estimate. That might be strong enough for ordinary business decisions, but it is not perfect.
Under a normal engineering model, a company might choose a threshold. For example, it could treat a visitor as probably being in Utah when several signals agree. Under a rule that creates liability whenever even one Utah user slips through, the remaining uncertainty becomes the whole problem. To eliminate that risk, a platform could verify every visitor, block all traffic that looks like it uses a VPN, or stop serving the affected users altogether.
The court’s record described Aylo’s sites as receiving about 28 million active visitors each month from the United States. The judge reasoned that, without perfect geolocation, the company could be pushed to verify users in Salt Lake City, Boston, New Orleans, Anchorage, and Honolulu alike. That is how a law aimed at one state can impose a large burden on activity taking place everywhere else. (law.justia.com)
A 95% rule still reveals the privacy tradeoff
Utah’s proposed administrative rules showed what a more practical system might look like. Published on September 1, 2026, the proposal described a commercially reasonable geolocation-obfuscation detection system as one designed to identify whether a person was in Utah with at least 95% accuracy. It listed connection latency, browser or device time zone, and other transmitted signals as possible inputs.
The proposal also described several responses when a user appeared to be hiding their location: ask the person to share their location, require them to disable the privacy tool and complete age verification if they were in Utah, or require age verification anyway. These choices acknowledge that the system is making a prediction rather than observing an undeniable fact. They also show the privacy cost. Someone who used a VPN for security or anonymity could be pushed toward sharing more personal information. (rules.utah.gov)
What the court actually blocked
On September 24, Judge David Barlow issued a preliminary injunction, which is a temporary court order meant to prevent harm while a lawsuit continues. The ruling blocked enforcement of the actual-location provision, Utah Code section 78B-3-1002(3). It did not invalidate Utah’s broader age-verification requirement, which Aylo had not challenged in the same way.
The court focused on the dormant Commerce Clause, a constitutional principle that limits states from placing excessive burdens on interstate commerce. The judge found that the law likely imposed a nationwide burden because perfect detection was impossible, while Utah’s goal could be pursued through less burdensome and more realistic standards. The lawsuit was still ongoing as of October 2, 2026.
The larger lesson is not that geolocation is useless. It is that geolocation is probabilistic. A law can ask a service to make a reasonable effort and define a safe harbor around that effort. It cannot make an estimate become certainty by writing the word actually into a statute. The internet’s borders are built from signals, not physical walls.
Comments (0)
No comments yet. Be the first to respond!
Leave a Comment
Your comment will be visible after review.