Australia’s social media minimum age law turned six months old this month, and the law was never a hard wall. It asked platforms to take reasonable steps to keep under-16s off their services, and eSafety’s own compliance findings now show what “reasonable” has actually meant in practice.
Six months of data beats six months of talking points.
The gap between the policy and the platforms hasn’t closed. It’s been measured, priced, and is now getting a second, much larger fine attached to it.
Law took effect 10 December 2025. Government figures put account removals between 4.7 and 5 million by mid-2026. A University of Newcastle study of 408 adolescents aged 12 to 17 found more than 85% of under-16 participants still using restricted platforms three months after the ban started. Maximum penalties for systemic breaches are doubling from A$49.5 million to A$99 million.
What the Public Record Shows on Social Media Minimum Age Compliance
eSafety’s compliance reporting through the first two quarters of enforcement flagged poor compliance practices at several major platforms, and the failure mode was specific.
A user under 16 would self-declare their age, get knocked back, and then be prompted to “correct” it: try again, enter a different birth year, and the account goes through. Existing accounts created before the law took effect were, in many cases, left untouched, because age checks hadn’t been rolled out to them yet. New sign-ups got scrutiny. Old accounts didn’t.
The independent research lines up with eSafety’s own findings. The University of Newcastle’s 408-adolescent study found roughly two-thirds of participants had hit an age check at some point, and most of those checks were self-declared age or a selfie, both of which are easy to route around with a fake birth year, a borrowed account, or private browsing.
Full details of eSafety’s regulatory position and compliance reporting are published at esafety.gov.au. The government’s response to the compliance gap, doubling penalties to A$99 million, is covered by Al Jazeera.
The Failure Mode Nobody Priced In
Retry-until-you-pass isn’t age assurance. It’s a form field with no consequence for lying, and it produces exactly the outcome you’d expect: a determined 13-year-old gets three attempts at a birthday and eventually finds one the system accepts. We flagged this exact pattern back in March, before eSafety’s own reporting confirmed it: Age Estimation is Everywhere. It’s Not Working. Selfie-based age estimation gets shakier the closer someone sits to the 16-year threshold, which is exactly where all the pressure in this system sits.
The deeper problem is that self-declaration and one-off selfies were never designed to be a compliance control. They were designed to be low-friction. Low friction and low integrity turned out to be the same thing here.
This Is What Privacy KYC Fixes
Privacy KYC technology exists to solve exactly this problem: prove a fact about a person, in this case age, without exposing the rest of their identity and without giving them a form field they can quietly re-enter. ShareRing joined Australia’s national Age Assurance Technology Trial in 2025, including a field test with school students in Darwin, because self-declared age and one-off selfie checks were always going to produce the failure mode eSafety just documented. See our recap of that trial: Age Assurance Technology Trial Darwin Recap.
Through the ShareRing Me app, a user verifies once against a real document with a biometric check, and that verification becomes a reusable, privacy-preserving credential.
No platform holds a birth date or a copy of an ID, and no user gets a second attempt at a birth year until one sticks. The check happens once and it’s portable across services. We built the verification model this way on purpose: read more in Precision Without Intrusion, How ShareRing Redefines Age Verification.
Australia Is Not the Only Regulator Watching This Data
Other jurisdictions are shaping their own social media minimum age rules around what Australia’s six months of enforcement data actually shows, not around what a policy document promised. The UK is already running its own under-16 trial with hundreds of teenagers, and regulators across Europe are watching the same “reasonable steps” question play out here first. Australia’s compliance data is becoming the reference case, the same way AUSTRAC’s Tranche 2 rollout became the reference case for how “reasonable steps” gets tested and enforced domestically: see AUSTRAC Tranche 2 compliance: what 1 July 2026 means for Australian businesses.
Frequently Asked Questions
What does “reasonable steps” actually require under the law?
Under Australia’s social media minimum age law, platforms have to take reasonable steps to prevent under-16s from holding accounts. eSafety Commissioner Julie Inman Grant has been consistent that it’s a delay to having an account, not an absolute ban, and enforcement is now built around proof of those steps rather than a policy statement alone.
Why did fines double to A$99 million?
Because self-declared age and one-off selfie checks weren’t stopping account creation or catching legacy accounts. The government’s response was to raise the cost of getting it wrong and give eSafety stronger powers to demand evidence from platforms, age-checking vendors, and app stores.
What is “retry-until-you-pass” and why does it matter?
It’s the pattern eSafety documented where a user knocked back on an age check gets prompted to re-enter their birth year until one is accepted. It turns an age check into a guessing game with no penalty for lying, which is why the compliance numbers stayed weak even as account-removal totals climbed.
How is ShareRing’s approach different from a selfie check?
Verification happens once, against a real document with a biometric check, and produces a reusable credential rather than a one-time answer a platform can’t audit later. The credential proves the fact of age without handing over a birth date or an ID copy.
Is Australia’s under-16 law an outlier or part of a wider trend?
Part of a wider trend. The UK is trialling its own under-16 restrictions, and regulators elsewhere are watching Australia’s six months of enforcement data to decide how they build their own age-assurance requirements.
Where can I see ShareRing’s age verification in practice?
Our Me Modules page covers how the verify-once, reusable credential model works inside the ShareRing Me app.
Where We Sit
We are not waiting for platforms to close this gap before we build the fix. ShareRing’s identity infrastructure exists specifically to answer the social media minimum age question with proof, replacing the self-declared, one-shot age check with a verification model that only has to be done properly once.
We Are Fixing Age Verification Right Now
We are running social media minimum age verification that a birthday field can’t beat, built on the same reusable credential model we tested in the national Age Assurance Technology Trial and deployed through ShareRing Me. This is not a policy position. It is the product.
If your platform, school, or organisation is facing the same “reasonable steps” question, reach out to me directly. Better to build verification that holds up the first time than to wait for the fine.
By Rohan Le Page, Founder and Co-CEO of ShareRing
#PrivacyKYC #DigitalIdentity #AgeVerification #OnlineSafety #ReusableKYC #Private #Secure #Verified
More from our Blog, The Privacy Stack
Digital Me Is Here: The World’s Only Private AI Assistant Opens Its Waitlist
Digital Me is the world's only private agentic AI assistant. Every user gets their own private AI server, credentials stay in an on-device Vault, and 13 real, executable...
Learn moreThailand Post Just Launched Verifiable Credentials. This Is What National Adoption Looks Like.
A national postal service just started issuing verifiable credentials to the public. Not a pilot. Not a roadmap slide. A live service, in citizens' hands, right now. Thailand...
Learn moreWhen Birth Certificates Get Hacked, the Database Was Always the Problem
Pattaya Mail reported birth certificates being hacked in Thailand. The fix is not a bigger wall. It is removing the honey pot. Privacy KYC moves identity off central...
Learn more