Most social platforms require users to be at least 13 years old. That didn’t stop 1.3 million Australian kids, aged 8-12, from getting on social media. Since the platforms only asked users to self declare their age by checking a box at sign up, this requirement could be easily bypassed by even the youngest users. That’s the gap the under-16 law was designed to close.
Since December 10, 2025, Australia has enforced the world’s first social media age limit, requiring major platforms to take “reasonable steps” to prevent under-16s from holding accounts. By mid-December, age-restricted platforms had already removed access to 4.7 million under-16 accounts. Amended rules took effect in March 2026, and enforcement is now well underway. Here’s what the Australia social media ban actually requires, how platforms are expected to verify age, and what it means for the identity verification industry.
Key Takeaways
- Ten platforms are currently treated as age-restricted under the law, including Facebook, Instagram, Snapchat, TikTok, X, YouTube, Reddit, Threads, Kick, and Twitch.
- The law does not mandate a specific age assurance method, but platforms are expected to use a layered “waterfall” approach rather than relying on self-declaration alone.
- Government-issued ID cannot be required as the only verification option. Platforms may offer it, but a reasonable alternative must always be available.
- Penalties can reach 150,000 penalty units for corporations, currently equivalent to $54.6 million AUD, and a proposed bill would double that for systemic breaches.
- Existing accounts are covered too, not just new signups, meaning platforms had to identify and remove or deactivate under-16 accounts that predated the law.
Book a Demo Give your business the boost of a fully automated, KYC process. No geographical limits and fast, frictionless onboarding verification processes enhance customer’s experience.
What Is Australia’s Social Media Minimum Age Law?
The Online Safety Amendment (Social Media Minimum Age) Act 2024 added Part 4A to the Online Safety Act 2021, requiring age-restricted social media platforms to take reasonable steps to prevent Australians under 16 from creating or keeping accounts, effective December 10, 2025.
The law applies to electronic services where the significant purpose is enabling online social interaction between two or more users, where users can link to or interact with others, and where users can post material. Under the Online Safety (Age-Restricted Social Media Platforms) Rules 2025, made in July 2025 and amended in March 2026, certain categories are carved out, including messaging apps, online gaming, professional networking, and services primarily used for education or health.
eSafety, Australia’s independent online safety regulator, doesn’t maintain a fixed list of covered platforms, since it wants the law to keep pace with a changing industry. As of early 2026, it has formally identified 10 services as age-restricted: Facebook, Instagram, Snapchat, Threads, TikTok, X, YouTube, Kick, Reddit, and Twitch. This is a foundational piece of Australia’s online safety policy, and other countries are watching closely as they consider similar rules.
What ‘Reasonable Steps’ Actually Requires
The law itself doesn’t define a checklist of required actions, and eSafety has been explicit that it won’t mandate any single technology. Instead, its regulatory guidance, released in September 2025 and informed by the government’s Age Assurance Technology Trial, sets out expectations platforms are meant to meet.
The central concept is “successive validation,” often called a waterfall approach: combining two or more age assurance methods so that no single, potentially unreliable signal is the final word. Relying solely on self-declaration, simply asking a user to confirm their age, doesn’t meet the reasonable steps standard.
A few expectations stand out:
- Layering matters more than any one method. A platform might start with a lower friction check like age inference, then escalate to a stronger method if the result is uncertain or disputed.
- Existing accounts had to be reviewed, not just new signups. Platforms were expected to identify likely under-16 account holders among their existing user base and deactivate or remove those accounts.
- Ongoing monitoring is required, since reasonable steps isn’t a one-time compliance exercise. Platforms need to keep detecting underage accounts as circumvention attempts evolve, including duplicate accounts and re-registration.
- Privacy obligations apply in parallel. Steps taken under Part 4A won’t be considered reasonable unless they also comply with the Privacy Act 1988 and the Australian Privacy Principles.
eSafety’s March 2026 compliance update flagged specific weak practices, including platforms that let users who’d previously self-declared as under 16 simply revise their age using a low-confidence method like facial age estimation, and platforms allowing repeated attempts with the same method instead of escalating.
The Penalty Regime and Co-Regulation Framework
Enforcement sits primarily with eSafety, though it isn’t the only regulator involved. A court can impose civil penalties on platforms that fail to take reasonable steps, with corporate fines reaching up to 150,000 penalty units, currently equivalent to $54.6 million AUD. eSafety has already issued 23 information-gathering notices across the 10 age-restricted platforms, and a proposed bill would double the maximum penalty for systemic breaches.
Privacy compliance is handled separately. The Office of the Australian Information Commissioner (OAIC) independently monitors and enforces the privacy provisions built into the law, alongside its existing role under the Privacy Act. This dual structure, eSafety for the age assurance obligation and OAIC for privacy, is a form of co-regulation: government sets the outcome platforms must achieve, while industry codes fill in the operational detail.
Six industry codes registered in September 2025 came into effect in March 2026, covering app distribution platforms, equipment providers, social media services’ core and messaging features, relevant electronic services, and designated internet services. Within two years of the law’s commencement, the government must also complete an independent review of how it’s operating, including its privacy protections.
Age Assurance Technology Options Under the Australian Framework
Much of what counts as a “reasonable step” traces back to the government’s Age Assurance Technology Trial, which tested more than 60 solutions from 48 providers. The trial grouped approaches into a few broad categories:
- Age verification, calculating the gap between a confirmed date of birth and the current date, typically using a government-issued document. This was the most accurate approach, but the law prevents platforms from making it the only option available.
- Age estimation, using facial analysis or other biological signals to predict an age range. The trial found this feasible and already in use across social media and retail, though with an average error of roughly 1.3 to 1.5 years and particular challenges for users aged 16 to 20 and for users with darker skin tones.
- Age inference, drawing on signals other than date of birth, such as account activity or information from another service, to indicate whether someone is likely over or under a threshold.
- Parental consent and controls, found technically workable but limited on their own, since they can be static and don’t always adapt as a child matures.
None of these methods was judged sufficient in isolation, which is exactly why the waterfall model exists. For background on how age verification methods are typically categorized, see our guide on what age verification is.
What This Means for Identity and Age Verification Providers
For identity verification providers, Australia’s approach creates a distinctly different market than the UK’s. The UK’s Online Safety Act leans on Ofcom’s “highly effective age assurance” standard, which explicitly includes photo ID matching as an accepted method. Australia’s framework treats government ID as something platforms can offer but never require exclusively, pushing more weight onto estimation, inference, and layered verification working together. See our breakdown of the UK Online Safety Act and age assurance, and for how the EU is approaching the same problem with a device-based credential, our piece on the EU age verification mini-wallet.
This creates real demand for age verification social media platforms can point to as evidence of genuine, layered effort rather than a single brittle check. Providers have a few clear opportunities:
- Build for layering, not a single method. Platforms need partners who can offer estimation, inference, and optional document verification within one workflow, escalating between them automatically.
- Design around the government ID restriction. Since ID can never be the sole option, providers need a credible non-ID pathway that still meets the reasonable steps bar on its own.
- Document everything. With eSafety already issuing information-gathering notices and a stricter penalty bill in progress, platforms increasingly need partners who can produce clear evidence of testing, accuracy, and escalation logic.
- Prepare for scale beyond social media, since the same waterfall logic is likely to spread into gaming, marketplaces, and other services children can access.
Book a Demo Give your business the boost of a fully automated, KYC process. No geographical limits and fast, frictionless onboarding verification processes enhance customer’s experience.
FAQ
Which social media platforms are covered by Australia's under-16 law?
eSafety has identified 10 platforms as age-restricted: Facebook, Instagram, Snapchat, Threads, TikTok, X, YouTube, Kick, Reddit, and Twitch. The list isn't fixed, since eSafety assesses services against the law's criteria on an ongoing basis rather than maintaining a permanent register.
Can platforms ask users for government ID to verify age in Australia?
Yes, but only as one option among several. The law prohibits platforms from compelling users to provide government-issued ID, including Digital ID, as the sole method of proving their age. A reasonable alternative that doesn't require government ID must always be available.
What is a 'waterfall' of age assurance methods?
Also called successive validation, it means combining two or more age assurance methods in sequence rather than relying on just one. If an initial check like age estimation is uncertain or disputed, the platform escalates to a stronger method instead of accepting a single result.
How does Australia's social media age law compare to the UK Online Safety Act?
Both require platforms to move beyond self-declaration, but the UK's Ofcom standard explicitly accepts photo ID matching as valid. Australia's law prevents platforms from ever making government ID the only option, pushing more weight onto estimation, inference, and layered non-ID verification.
What happens to existing under-16 accounts when the law is enforced?
They're covered by the same obligation as new signups. Platforms were expected to identify likely under-16 account holders among existing users and deactivate or remove those accounts, with eSafety reporting 4.7 million such accounts had already lost access by mid-December 2025.



