what's the current solution that's impossible for kids to bypass with a borrowed or stolen id, say?
I don't see any proposals yet that will actually work for what they say they'll do.
You have to stop thinking like an engineer and start thinking like a public health official.
'Something impossible for kids to bypass' is not the goal. It's akin to evaluating a flu vaccine on the standard of zero breakthrough cases. Such a standard has no relevance on the efficacy of the vaccine.
Likewise for underage internet access. Proponents would be happily satisfied with 90% compliance. They really don't care that coverage isn't complete or circumvention is complete. Once you realize that, you can start constructing counterarguments that dismantle the claim that digital IDs would solve the problems they're supposed to.
You want a proposal? Make a kids-only set of sites. And then make hardware/software that can access only those sites. Make sure existing and future "non-kid" hardware can't access those kids-only sites. You can allow companies to register that they are one of these kid friendly sites with the additional regulation that would entail. Then make a kid having hardware that can access the normal Internet like having a beer in the US. Now perhaps you can find a hole in this, but it can be patched with technology and the right regulation.
That we aren't doing something like this gives the game away. How the EU is going about this means the point of all of this has nothing to do with children and everything to do with controlling political speech.
PS Yea, I know its a very vague suggestion, it can still be implemented