The Australian age assurance debate has spent a year arguing about social media. While that ran, a second set of rules moved the age gate down a level, into the place every app comes from.
From today, 9 September 2026, app store age checks are enforceable in Australia under the age assurance requirements in the App Distribution Services Code. App distribution services must implement appropriate age assurance measures before letting a user download or purchase an app rated 18+.
The code says the check must happen. It does not say how. That gap is where this either works or turns into a nationwide document collection exercise.
The instrument: the App Distribution Services Code, one of nine Age-Restricted Material Codes registered under the Online Safety Act.
Code in force: 9 March 2026. Age assurance requirements inside it: 9 September 2026.
The obligation: implement appropriate age assurance before permitting users to download or purchase apps rated 18+, and keep age ratings accurate and clearly presented.
Penalty: breach of a direction to comply may attract civil penalties of up to A$49.5 million.
Separate regime: this is not the under-16 social media law. Different Act, different obligation.
What the public record shows.
There are nine Age-Restricted Material Codes, covering the industry sections defined in the Online Safety Act. They were registered in two tranches and came into effect six months after registration: 27 December 2025 for search, hosting and internet carriage, and 9 March 2026 for the rest, including app distribution.
The eSafety Commissioner gave two codes extra time on the age assurance measures specifically, in recognition of the product work involved. That extension is what expires today. In eSafety’s own framing, by 9 September 2026, six months after the code comes into effect, app distribution services must implement appropriate age assurance measures before permitting end users to download or purchase apps rated as 18+.
They must also ensure apps are appropriately rated, present that rating information clearly, and hold procedures to reconsider and change ratings where needed. The full detail sits in the eSafety register of industry codes and standards and the Age-Restricted Material Codes fact sheet.
Two things the coverage keeps getting wrong. The A$49.5 million figure attaches to breach of a direction to comply, not automatically to a code breach. And eSafety has published its regulatory priorities for the year, which include making sure large gatekeeper services like search engines and app stores enforce their own terms of service.
Three of the biggest storefronts moved before the date. Apple announced on 24 February 2026 that it would block users in Australia, Brazil and Singapore from downloading apps rated 18+ unless confirmed to be adults through reasonable methods, with the App Store performing that confirmation automatically. Microsoft announced age assurance across the Microsoft Store and Xbox storefronts in Australia on 10 August 2026, working with Yoti and VerifyMy, and is the only one of the three to name the codes directly. Google expanded a Play Age Signals API to developers in July, reaching Australia and Canada first, though that is a developer-facing signal rather than a storefront download gate.
App store age checks are mandatory. The method is not.
The code is technology neutral. eSafety’s guidance lists acceptable approaches, including document matching, facial age estimation, credit card checks, digital identity wallets and parental attestation. There is no government ID mandate and no requirement to hand data to government.
That neutrality is the right call and it is also the risk. When a regulator says the check must happen and leaves the method open, commercial gravity pulls towards whatever is cheapest to bolt on. Historically that has meant asking for a document, because document capture is a solved product with vendors queuing up to sell it.
Run that logic to its end. Every adult in Australia who wants to download an 18+ app uploads a licence or passport to a storefront. Multiply by the population. You have built the largest identity document collection in the country’s history, to answer a question with one bit of information in it. Over 18. Yes or no.
I wrote in Age Estimation is Everywhere about why the current generation of checks keeps failing users. The failure mode this time is different and worse. It is not that the check does not work. It is that it works and leaves a permanent deposit behind.
This is what privacy KYC fixes.
Age checks need to answer one question. Privacy KYC makes them answer only that question.
The person holds a credential in their own encrypted vault, issued and signed by an authority. When a storefront asks whether they are over 18, they present that single attribute and the storefront receives a signed yes or no. No name, no date of birth, no document number, no image. The storefront can evidence to eSafety that a compliant check occurred, because the signature proves it. It holds nothing that is worth stealing, and nothing it has to defend for the next seven years.
That is the version of an age gate adults will actually use, and the version that survives the first breach at a competitor. I set out how the levels work in How ShareRing Protects Your Identity.
Australia now runs three sets of age checks at once.
Today’s code sits alongside the Social Media Minimum Age obligation, which has been live since 10 December 2025 and which I covered in I Hate Digital ID, and the broader Age-Restricted Material Codes covering search, hosting and messaging.
They are different instruments with different tests, and a business running age checks across all three cannot solve them separately without collecting three times as much data as any of them needed. One credential, presented as an attribute, satisfies all three. Three bolt-on document capture flows satisfy all three too, and leave three honeypots behind.
Frequently asked questions.
Is 9 September when the code starts?
No. The App Distribution Services Code has been in force since 9 March 2026. Today is when the age assurance requirements inside it become enforceable, after a six-month transition.
Is this the under-16 social media ban?
No. That is the Social Media Minimum Age regime under a separate amendment Act, live since 10 December 2025. Today’s obligation is about 18+ rated apps in app stores.
Do I have to upload my ID to download an app?
That depends entirely on the storefront’s chosen method. The code does not require it, and privacy-preserving alternatives are explicitly acceptable.
What is the penalty for an app store that ignores this?
eSafety can issue a direction to comply, and breach of that direction may result in civil penalties of up to A$49.5 million.
Does a business outside app distribution need to care?
Yes, if it publishes 18+ apps, and yes if it runs any age-restricted service, because the same enforcement posture and the same public trust test apply. Our Precision Without Intrusion post covers the approach.
Where we sit.
ShareRing took part in the Australian Government’s Age Assurance Technology Trial, which we recapped in the Darwin trial recap, and we are certified under the United Kingdom’s DIATF. We have built privacy KYC technology since 2018 around proving an attribute without surrendering the document behind it.
We are not the storefront. We are the layer that lets a storefront prove someone is an adult without becoming responsible for their passport.
Age checks are mandatory. The honeypot is not.
Every business now running age checks gets to choose the method. That choice decides whether Australians end up with age gates they tolerate or a decade of breach notifications.
We are building the version people will accept. Come and look at sharering.network.
By Rohan Le Page, Founder and Co-CEO of ShareRing
#PrivacyKYC #AgeVerification #AgeAssurance #OnlineSafety #DigitalIdentity #Private #Secure #Verified
More from our Blog, The Privacy Stack
Thailand Post Just Launched Verifiable Credentials. This Is What National Adoption Looks Like.
A national postal service just started issuing verifiable credentials to the public. Not a pilot. Not a roadmap slide. A live service, in citizens' hands, right now. Thailand...
Learn moreWhen Birth Certificates Get Hacked, the Database Was Always the Problem
Pattaya Mail reported birth certificates being hacked in Thailand. The fix is not a bigger wall. It is removing the honey pot. Privacy KYC moves identity off central...
Learn moreThailand’s Digital ID Framework Is Already in Phase 2. Most of the World Hasn’t Noticed.
Most countries are still arguing about what a digital ID should look like. Thailand has stopped arguing. ETDA's Phase 2 Digital ID Framework runs 2025 to 2027 and...
Learn more