Digital MediaNews

Australia’s Social Media Age Restriction Laws: What Parents Need to Know in 2026

If you’ve got a teenager glued to TikTok, Instagram or Snapchat, you’ve probably already heard the headline: Australia now has a legal minimum age of 16 for social media accounts. The law came into force on 10 December 2025, and it’s the first of its kind anywhere in the world. Since then we’ve had a few months of it actually running in the real world, and the picture is a lot messier — and more interesting — than the initial headlines suggested.

We’ve had a steady stream of questions from parents since the law landed, and most of them boil down to the same handful of things: which apps are actually covered, how platforms are supposed to check anyone’s age in the first place, what happens to a platform that just doesn’t bother, and whether any of this actually stops a determined 14-year-old from getting an account anyway. We’ve pulled together what we know so far, in plain English, without the legal jargon.

What the law actually says

The obligation sits with the platforms, not with parents or kids. Under the Online Safety Amendment (Social Media Minimum Age) Act, “age-restricted social media platforms” have to take “reasonable steps” to stop Australians under 16 from creating or keeping an account. It’s not a ban on kids viewing social media content — a teenager can still watch YouTube videos or browse TikTok clips without logging in. What’s restricted is holding an account: posting, commenting, messaging, building a profile and a following.

The eSafety Commissioner and the Office of the Australian Information Commissioner (OAIC) are the two regulators sharing responsibility for this. eSafety enforces the age restriction itself and decides which platforms are covered, while the OAIC oversees how platforms handle the personal information collected during age checks. It’s worth reading eSafety’s own explainer on which platforms are age-restricted, because the list isn’t quite as obvious as “all social media” — some services are excluded, and eSafety has had to make individual calls on borderline cases.

Which platforms are covered

Instagram, TikTok, Snapchat, Facebook, X (formerly Twitter) and YouTube’s account features are all captured. So are newer entrants like Lemon8 and Wizz, both of which eSafety confirmed meet the definition of an age-restricted platform. The common thread eSafety uses to decide is whether a service’s “sole or significant purpose” is to enable online social interaction between users — think profiles, followers, feeds and the ability to post content for others to see.

What’s not covered tends to surprise people. Messaging apps like WhatsApp and Messenger are generally excluded, on the basis their primary purpose is private communication rather than public social networking. Gaming platforms, education and health services, and apps aimed at professional networking can also fall outside the definition, depending on how they’re built. If your kid is asking why they can have a Discord account but not an Instagram one, this distinction — social networking versus messaging or gaming — is usually the reason. It’s also exactly the kind of definitional grey area that regulators keep refining as new platforms launch, which is a theme we’ve touched on before when looking at how quickly Australian law tries to keep pace with new tech, including in our piece on how Australian law is scrambling to catch up with AI deepfakes.

How age verification is actually meant to work

This is the part that trips most parents up, because “reasonable steps” doesn’t mean every platform has to demand a passport scan from every new sign-up. eSafety’s regulatory guidance sets out a range of acceptable approaches, and platforms are expected to use a mix of them rather than relying on one method alone.

  • Self-declared age at sign-up, combined with checks that flag inconsistencies (an account claiming to be 25 but behaving, posting and connecting like a young teenager).
  • Age estimation using facial analysis on a selfie or short video, which estimates an age range without necessarily storing the image long-term.
  • Third-party digital identity or age-verification services that confirm a user is over 16 without the platform itself seeing the underlying ID document.
  • Behavioural and account-signal analysis — looking at existing account data, contacts and activity patterns to catch under-16 users who are already on the platform.
  • Parental confirmation or vouching in some limited circumstances, though this is generally treated as a weaker, supplementary signal rather than a stand-alone method.

In practice, most of the big platforms have leaned on a combination of self-declaration plus AI-based age estimation, because it’s the least friction for the vast majority of adult users while still catching obvious cases. None of these methods are perfect, and eSafety has been upfront that “reasonable steps” is a deliberately flexible standard — it’s not a single technical checklist, it’s a judgement call based on the size of the platform, the risk to children, and what technology is genuinely available and proportionate.

What happens if a platform doesn’t comply

eSafety can issue formal information-gathering notices requiring a platform to hand over data about how it’s assessing age and enforcing the restriction — and it’s already used that power, sending out more than twenty notices to a group of platforms in the months since the law started. If a platform is found to have failed to take reasonable steps, the penalties are steep: the legislation allows for civil penalties running into the tens of millions of dollars for systemic non-compliance.

That said, enforcement isn’t instant. eSafety has to build an evidence base showing a platform’s efforts fall short of “reasonable,” and that takes time — pulling account data, testing detection systems, and giving platforms a chance to respond. As of now, no platform has been fined; the current phase is squarely about information-gathering, monitoring, and a formal evaluation eSafety has begun into how the whole scheme is working in the real world, ahead of a scheduled review.

The criticisms — and they’re real

We’d be doing parents a disservice if we pretended the law is airtight. It isn’t, and even the regulators openly acknowledge the gaps.

The most obvious workaround is a VPN. Point your device at a server in another country, and depending on the platform’s implementation, sign-up flows and age checks can behave differently, or geographic assumptions the platform relies on simply don’t apply. Plenty of tech-savvy teenagers already know how to install a VPN app from an app store in under a minute, and no amount of platform-side age assurance stops that at the network level — it’s a policy law aimed at platform behaviour, not a technical firewall around Australian internet connections.

There’s also a hand-me-down problem: an older sibling’s or parent’s already-verified account, a fake birth year at sign-up, or a borrowed identity for a facial age-estimation check. None of the current verification methods can fully close these loopholes, and eSafety has said as much in its own guidance — “reasonable steps” is explicitly not the same as “foolproof.”

Then there’s the privacy trade-off, which is arguably the more interesting long-term issue. Every age-verification method — a selfie for facial estimation, a scanned ID, a third-party identity check — means a platform, or a company working for it, is collecting and processing sensitive personal data purely to prove someone is old enough to have an account. The OAIC’s guidance on this is worth reading precisely because it sets out what platforms are and aren’t allowed to do with that data: how long it can be retained, whether it can be used for anything beyond the age check itself, and what happens if there’s a breach. For a household already thinking about how much personal data ends up floating around connected devices, it sits alongside the same worries we’ve raised about smart home gadgets quietly collecting more than people realise, which we covered in our look at whether your smart home is spying on you.

Finally, there’s a broader debate about whether restricting under-16s from having accounts pushes them toward less regulated, less moderated corners of the internet instead — forums, fringe apps, or overseas platforms with no Australian obligations at all. Child safety advocates are largely supportive of the intent, but several have flagged this displacement risk as something the promised evaluation needs to actually measure, not assume away.

What this means for platforms and their incentives

It’s also worth remembering that platforms don’t operate in a vacuum — they respond to whatever regulatory and commercial pressure is pointed at them, and not always in the direction regulators intend. We’ve written before about how platforms like Meta have pushed back hard against other Australian regulatory obligations they see as commercially unfair, including in our coverage of Meta’s objections to the news bargaining incentive. The minimum age law is a different piece of regulation entirely, but the same dynamic applies: how enthusiastically a platform implements “reasonable steps” often tracks how much genuine cost or reputational risk it faces for getting it wrong, not just what the letter of the law requires.

Practical guidance for parents right now

None of the above means parents are powerless while the law and the platforms sort themselves out. A few things we’d actually suggest doing:

  • Have the conversation directly, rather than relying on the law to do the parenting for you. If your under-16 already has an account, or wants one, talk through why the age limit exists — it’s about algorithmic exposure, contact from strangers and mental health, not just an arbitrary number.
  • Check what’s already installed. Family sharing and device-level parental controls (built into iOS, Android and most routers) will tell you more about what your kid is actually using than any platform’s own age-gate ever will.
  • Don’t assume a VPN on the family iPad is innocent. It’s not automatically a red flag, but if one appears alongside a sudden new social app, it’s worth asking about.
  • Use the platforms’ own family tools where they exist — supervised accounts, screen time limits, and content restrictions are still available and still useful, independent of the age-restriction law.
  • If your child is under 16 and using a platform that’s supposed to be enforcing the restriction, you can report the account directly to eSafety, who have a process for exactly this.
  • Keep an eye on how your own data, and your kid’s, gets used if you go through an age-verification step yourself — the OAIC’s guidance is the reference point if you want to understand what a platform is and isn’t allowed to keep.

The law is genuinely new — still well under a year old at the time of writing — and both regulators have been clear that the current approach will be reviewed and adjusted based on how it performs. We’d expect enforcement action, platform workarounds and parental habits to all keep shifting over the next year or two, so this isn’t a “set and forget” situation for any household with a teenager anywhere near social media.

Final thoughts

Australia’s social media minimum age is a genuinely significant piece of regulation, and it’s still finding its feet. The intent is straightforward — keep younger teenagers away from the account-based, algorithm-driven side of social media until they’re a bit older — but the execution is inevitably imperfect, built on age-estimation technology and platform goodwill rather than anything airtight. VPNs, fake birth years and borrowed accounts mean determined kids can still get around it, and the privacy cost of age verification itself is a legitimate trade-off that regulators are still working through.

For parents, the practical takeaway isn’t to treat the law as a solved problem. It’s one more tool alongside the conversations, the device settings and the ordinary parenting judgement calls that were already doing most of the work before 10 December 2025 came along. We’ll keep tracking how enforcement plays out as eSafety’s evaluation progresses, and we’ll update our coverage as the platforms — and the workarounds — inevitably keep evolving.

Em Castellano

Em Castellano covers security and tech news for Tech Geek. She turns breaches, scams and privacy stories into advice readers can act on the same afternoon, and believes good security writing should never need a dictionary.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Back to top button