The short version
The Social Media Minimum Age obligation took effect on 10 December 2025. It does not ban anybody from anything. It puts a duty on a specific list of platforms to take “reasonable steps” to stop Australians under 16 from holding accounts, and it attaches a very large civil penalty to failing that duty. There is no offence, fine or obligation of any kind on a child or a parent.
Five numbers frame the first nine months:
- 4.7 million. Accounts assessed as belonging to under-16s that had been deactivated, removed or restricted as at mid-January 2026, on the government’s figures.
- 52.4 to 42.1 per cent. The fall in the proportion of Australian under-16s holding a social media account, measured three months after commencement in eSafety’s own longitudinal evaluation. Statistically significant, and about a tenth of the cohort.
- 85.9 to 81.5 per cent. The fall in the proportion of under-16s who reported using a social media platform, with or without an account. That is the number that says the law has moved account ownership much further than it has moved behaviour.
- Five platforms. Facebook, Instagram, Snapchat, TikTok and YouTube, all under active investigation since eSafety moved to what it calls “an enforcement stance” on 31 March 2026. No enforcement decision had been published as at the date of this article.
- $54.6 million. The maximum civil penalty a court can order against a corporation that fails to take reasonable steps — 150,000 penalty units — on eSafety’s current FAQ. The same maximum applies to a platform that compels an Australian to hand over government ID.
Everything else here is detail underneath those five numbers, and the detail is where most of the practical consequences live.
What the law actually says
The obligation sits in Part 4A of the Online Safety Act 2021, inserted by the Online Safety Amendment (Social Media Minimum Age) Act 2024, which passed Parliament on 29 November 2024 and commenced on 10 December 2025.
Three features of its design explain almost everything odd about how it has played out.
| The duty is on platforms, not people | An age-restricted platform must take reasonable steps to prevent under-16s ordinarily resident in Australia from having accounts. eSafety is explicit that there are no penalties for under-16s who get around the restrictions, or for their parents or carers. Any message demanding a fine for being under 16 or for an unverified account is a scam. |
|---|---|
| “Reasonable steps” is a systems test, not a headcount | To win a civil penalty case, eSafety must prove a platform failed to take reasonable steps — which, in the Commissioner’s words, “means more than simply demonstrating some children do still have accounts. Rather, the evidence must show the platform has not implemented appropriate systems and processes.” This is why a survey showing four in five kids still online is not, by itself, evidence of a breach. |
| It covers accounts, not viewing | The obligation is about holding an account. Content that is publicly viewable without logging in is not reached by it. A child who scrolls a public feed logged out is outside the scheme entirely. |
The Act also requires a statutory review within two years of commencement — so by December 2027 — and eSafety’s evaluation is designed to feed it.
Which platforms are in, and which are not
This is the part most people get wrong, and it is worth reading closely, because the list is not intuitive. eSafety published its assessment on 21 November 2025 and confirmed in March 2026 that a rule amendment had not changed it. The page was last updated on 30 March 2026.
| Assessed as age-restricted | Facebook, Instagram, Kick, Reddit, Snapchat, Threads, TikTok, Twitch, X and YouTube. |
|---|---|
| Assessed as not age-restricted | Discord, GitHub, Google Classroom, LEGO Play, Messenger, Pinterest, Roblox, Steam and Steam Chat, WhatsApp and YouTube Kids. |
| Self-assessed themselves in | BlueSky (16+ for Australian accounts), Lemon8 (ByteDance, 16+, eSafety notified 15 December 2025), Wizz (16+, notified 13 January 2026), and several services that already enforce 18+: Match’s Tinder, Hinge, OKCupid, Plenty of Fish, Match.com and Azar, plus Yubo and BigoLive. |
| Excluded by the rules | Services whose sole or primary purpose is messaging, email, voice calling, video calling or online gaming, among others. That exclusion is why WhatsApp, Messenger, Discord, Roblox and Steam are out. |
Two caveats sit on top of that table, and eSafety states both plainly. First, the lists are not exhaustive and are not a legal determination — eSafety says it “does not have a formal role in declaring which services are age-restricted social media platforms”, and in the absence of ministerial rules naming a service, that question is ultimately one for a court. Second, a service can move between the lists as it changes: a messaging app that grows a feed, or a game that becomes a place people mainly socialise, can fall into scope.
The scope was tightened, not widened, in March. The Online Safety (Age-Restricted Social Media Platforms) Amendment Rules 2026 were registered on 25 March 2026 and commenced the next day, adding a requirement that a service also have a “recommender feature” and/or a “logged-in feature” before it can be age-restricted. eSafety reconsidered its ten and did not change the list.
Being outside the minimum age scheme is not the same as being unregulated. eSafety issued enforceable transparency notices to Roblox, Minecraft, Fortnite and Steam in February 2026 under other parts of the Act, and Roblox has separately introduced its own age estimation. That is a different obligation with a different trigger — which is exactly why an age check on a game is not evidence that the game is age-restricted under this law.
What the regulator’s own evaluation found
On 31 July 2026 eSafety published Early days, early insights: Understanding experiences of social media age restrictions at the three-month follow-up, the first release from a two-year longitudinal study following more than 4,000 children and families, run with Stanford University’s Social Media Lab and an independent academic advisory group, with the protocol pre-registered on the Open Science Framework.
The data was collected in March 2026 — three months in, not nine. That timing matters more than any single finding.
| Under-16s holding a social media account | Fell from 52.4 per cent to 42.1 per cent. eSafety describes this as a modest but statistically significant decline. |
|---|---|
| Under-16s using a platform, account or not | Fell from 85.9 per cent to 81.5 per cent. |
| Children feeling they were missing out by not having social media | Fell from 43.3 per cent to 36.3 per cent — a statistically significant decline, and the finding that most directly supports the government’s “cultural reset” framing. |
| Parents | Reported feeling less pressure, and were less likely to see social media use as common among their children’s peer group. |
| The uncomfortable finding | Parental awareness of children’s social media use declined in some cohorts, particularly girls and children aged 10 to 12. |
| Why accounts survived | Most under-16s who had accounts before commencement were able to keep them or create new ones at the three-month mark, with platforms’ failure to implement effective age assurance cited as the main reason. |
eSafety attaches two caveats to its own report that are easy to lose in the coverage, and both cut against the “the ban has failed” headline that ran in early August. The report “do[es] not constitute an assessment of whether age-restricted platforms complied with their obligations”, and at three months “it is too early to meaningfully assess whether the policy’s intended outcomes have been achieved”. Findings are being released progressively across 2026, 2027 and 2028.
Reasoning beyond the sources: the two headline percentages measure different things and should not be collapsed into one. Account-holding fell 10.3 points; usage fell 4.4. The gap between them is the whole story of the scheme’s design — a law aimed at accounts will show its largest effect on accounts, and a child who loses an account but keeps watching logged out has complied with a law that never asked anything of them. Whether that gap is a failure or the expected first stage of a slower change is a judgement three-month data cannot settle, and eSafety does not claim it can. The declining parental awareness finding is the one we would watch hardest, because it points at a mechanism — use moving somewhere less visible — rather than a level.
Where compliance actually stands
eSafety published its first compliance update on 31 March 2026. It drew on platforms’ responses to legally enforceable information-gathering notices — 23 notices issued to the ten platforms, on Clayton Utz’s reading of the update — along with public reporting and eSafety’s own pulse survey. It credited large-scale account removals and more visible underage reporting pathways, then named four poor practices:
- Prompting children to attempt age assurance even where their declared age before 10 December 2025 was under 16.
- Letting under-16s repeatedly attempt the same age assurance method until they get a 16+ result.
- Failing to provide accessible or effective pathways for reporting age-restricted accounts.
- Insufficient measures to prevent new under-16 accounts being created.
Commissioner Julie Inman Grant’s framing on the day: “While social media platforms have taken some initial action, I am concerned through our compliance monitoring that some may not be doing enough to comply with Australian law. As a result, we are now moving into an enforcement stance.” She added that the reform “is unwinding 20 years of entrenched social media practices” and that the platforms “have the capability to comply today”.
eSafety aimed to make decisions on at least some investigations by the middle of 2026. As at 31 July it said concerns remained about all five named platforms, that the investigations were ongoing, and that a second compliance update would come “in the coming weeks”. We could not find that second update published as at the date of this article.
Of the platforms, Meta has been the most public. In a newsroom post dated 12 August 2026 it said that as at 30 June 2026 it had removed access to more than 750,000 Facebook and Instagram accounts in Australia assessed as belonging to under-16s, including more than 500,000 removed before the law took effect. Notably, it says it is doing this without video selfies or ID checks — using AI analysis of profile signals including posts, comments, bios and captions, plus community reporting and a 16+ app store rating. Meta also argues the industry approach is inconsistent, and presses for “a single reliable age signal delivered at the operating system or app store level” instead of every app checking separately.
Reasoning beyond the sources: that argument is not neutral. Moving the age signal to the operating system or app store would move the compliance burden, the cost and the liability from the platform that profits from the account to Apple and Google — and it would also, in fairness, mean one check instead of dozens, with less identity data spread across fewer companies. Both things are true at once. It is worth knowing whose problem a proposal solves before deciding what you think of it.
How a platform decides how old you are
Nothing in the law requires everyone to prove their age. eSafety does not expect a platform to age-check an account it already has good reason to believe belongs to an adult — its own example is an account continuously held since Facebook launched here in 2006.
What platforms may no longer do is rely on a birthdate typed at sign-up. eSafety expects them to use age-related signals to decide who to check, and it publishes the list:
- How long an account has been active.
- Whether the account interacts with content aimed at under-16s.
- Analysis of the language level and style used by the account holder and the people they interact with.
- Visual checks, such as facial age analysis of photos and videos.
- Audio analysis, such as age estimation from the account holder’s voice.
- Activity patterns consistent with school schedules.
- Connections with other users who appear to be under 16, and membership of youth-focused groups or communities.
A parallel list of location signals decides whether you are ordinarily resident here: IP addresses, GPS and location services, device language and time settings, device identifiers, an Australian phone number, app store and operating system account settings, and photos, tags, connections and activity. Platforms are expected to try to stop under-16s using a VPN to pretend to be offshore, and to resist fake IDs, AI tools and deepfakes.
Reasoning beyond the sources: read that list as a consumer rather than as a compliance officer and it describes something broader than an age check. Style-of-language analysis, school-schedule pattern matching and social-graph inference are behavioural profiling techniques, applied across a whole country’s user base, to answer a binary question about a minority of accounts. The law responds to that with strict limits on what the resulting data may be used for, which is the next section — but the profiling itself is the price of an accounts-based rule that platforms were asked to enforce with the tools they already had.
Your data, and the two rules worth knowing
If you are asked to prove your age, two protections apply, and they are stronger than most people realise.
| No one can be forced to use government ID | The legislation specifically prohibits an age-restricted platform from compelling you to provide government-issued identification or to use an accredited Digital ID service. A platform may offer ID as an option, but it must also offer a reasonable alternative — including where another method returns a result you do not accept. eSafety can seek penalties of up to $54.6 million against a platform that breaches this. |
|---|---|
| The data must be ringfenced and destroyed | Under section 63F, platforms and age assurance providers must ringfence and destroy personal information collected for age assurance, and must not use or disclose it for another purpose. Compliance with the minimum age obligation will not be considered reasonable unless the platform also complies with its Part 4A privacy obligations, the Privacy Act 1988 and the Australian Privacy Principles. |
| If it is misused | Complain to the platform or the age assurance provider first. If that does not resolve it, escalate to the OAIC — mishandling this information is an interference with privacy that engages the OAIC’s complaint function. |
The scam surface this creates is large, and eSafety has documented it in unusual detail. Nobody will ever fine you for being under 16 or for having an unverified account — there is no such penalty in the law, so any demand for payment is fraud. Treat any unsolicited text or email asking you to verify your age as hostile: go to the app or site’s own help section directly rather than following a link. Offers to sell a fake ID or access to an age-verified account are variously theft, sextortion setups and grooming approaches. And not every age check you meet in 2026 comes from this law — the online safety codes, overseas rules and platforms’ own anti-fraud measures all generate them too.
If it goes wrong: the practical part
Four situations account for most of the real-world friction, and the published expectations are clear on all four.
| You are 16 or over and got locked out | Platforms are expected to have a review process and to give clear instructions for requesting one. This covers both bad age estimates and false reports by other users. If a platform makes ID the only way back in, that is the conduct the law prohibits — and it is worth reporting to eSafety through its implementation feedback form. |
|---|---|
| An under-16 account is about to go | Download the data first. Platforms are expected to explain how to download account information before deactivation or removal, in a portable format, and to allow access within a reasonable period afterwards. Do not rely on it: eSafety’s own advice is to save posts, photos, chats and contacts as soon as possible. |
| Turning 16 later | Some platforms may allow deactivation rather than deletion, so an account can resume with its data at 16. eSafety says young people should not count on this. If the content matters, export it now. |
| Visiting or studying here | The Act does not define “ordinarily resident in Australia” and sets no time threshold. Under-16 international students living here should expect accounts to be flagged, and should use the appeal path if residence or age is assessed wrongly. |
One more, for parents specifically: reporting an under-16 account is possible but not required. There is no mandatory reporting for parents, educators or police, and no legal consequence for a child who is on a platform. eSafety’s stated reason for offering the pathway at all is that reports help platforms see how the checks are being beaten.
What we could not establish
Four things, and they bear on how much weight to put on the rest.
We could not reconcile the two maximum penalty figures eSafety itself publishes: the FAQ states 150,000 penalty units “currently equivalent to a total of $54.6 million”, while the March 2026 media release refers to civil penalties of up to $49.5 million. The maximum is set in penalty units, whose dollar value is indexed, so both can be correct for different dates — but we could not confirm from a primary source which figure applies to conduct at a given time, and we have not attempted to calculate it.
We could not find eSafety’s second compliance update, promised on 31 July for “the coming weeks”, published as at 31 August 2026. Nor could we find any published enforcement decision against the five investigated platforms, despite the mid-2026 target. Absence from our search is not proof of absence.
We could not verify the content of the “proposed legislation” eSafety referred to on 31 July, when it said it “stands ready to deploy any new regulatory tools should proposed legislation be passed by Parliament”. Treat any claim about what new powers are coming as unconfirmed until a bill is in front of Parliament.
And we have not independently verified any platform’s account of its own compliance. Meta’s 750,000 figure is Meta’s figure. The 4.7 million total is the government’s. Neither has been audited in anything we could read.
The bottom line
Nine months in, the honest summary is narrower than either side’s headline. The law has clearly removed millions of accounts and shifted the social expectation around them — the drop in children feeling they are missing out is the finding that would be hardest to buy any other way. It has not made under-16s stop using social media, and at three months it had barely dented usage at all. The regulator says that is too early to judge; the platforms say they are complying; the evaluation runs until 2028 and the statutory review lands by December 2027.
What is worth acting on now is the smaller print. You cannot be made to hand over government ID, and a platform that insists is exposed to the largest penalty in the scheme. Anything collected to check your age must be ringfenced and destroyed. No child or parent can be fined, so every demand for payment is a scam. And if an account is coming down, the data goes with it unless somebody exports it first. Those four facts are settled, published, and considerably more useful than another round of argument about whether the ban works.
Sources
Figures, quotes and dates above are drawn from these sources, captured 31 August 2026:
- eSafety Commissioner — Early insights from eSafety’s comprehensive evaluation project (31 July 2026): the 52.4 to 42.1 per cent fall in account-holding, 85.9 to 81.5 per cent in usage, 43.3 to 36.3 per cent on missing out, the 4,000-plus family longitudinal design with Stanford University’s Social Media Lab, the March 2026 collection date, declining parental awareness among girls and 10 to 12 year olds, the caveats that this is not a compliance assessment and is too early to judge outcomes, the reference to proposed legislation, and the promise of a second compliance update.
- eSafety Commissioner — Five social media platforms flagged for compliance issues (31 March 2026): the concerns about Facebook, Instagram, Snapchat, TikTok and YouTube, the four named poor practices, Commissioner Julie Inman Grant’s quoted remarks including the enforcement stance and the reasonable-steps evidentiary test, and the reference to civil penalties of up to $49.5 million.
- eSafety Commissioner — Which social media platforms are age-restricted? (last updated 30 March 2026): the 21 November 2025 lists of ten age-restricted and ten non-age-restricted services, the self-assessment notifications from BlueSky, Match, Yubo, Wizz, Lemon8 and BigoLive with their notification dates, the confirmation that the March 2026 rule amendment did not change the assessment, and the statement that determining the status of a service is ultimately a matter for a court.
- eSafety Commissioner — Social media ‘ban’ or delay FAQs: the 150,000 penalty unit maximum stated as $54.6 million, the prohibition on compelling government ID and the penalty attached to it, the age and location signal lists, the VPN and deepfake expectations, the absence of any penalty for under-16s or their families, the appeal expectations for wrongly removed 16+ accounts, the data download and reactivation advice, the exclusions for messaging and gaming services, the four compliance expectations on platforms, the “ordinarily resident” position for international students, and the scam guidance.
- OAIC — Social Media Minimum Age: the section 63F ringfence-and-destroy obligation, the requirement that privacy compliance under Part 4A, the Privacy Act 1988 and the Australian Privacy Principles forms part of reasonable steps, the prohibition on compelled government ID with a reasonable alternative required, the complaint path from platform to OAIC, and the statutory review within two years.
- Meta — Meta’s compliance with Australia’s social media ban (12 August 2026): more than 750,000 Facebook and Instagram accounts removed as at 30 June 2026 including more than 500,000 before commencement, the use of AI profile analysis rather than video selfies or ID, community reporting, the 16+ app store rating, and the call for a single age signal at the operating system or app store level. A company statement about its own conduct, cited as such.
- Clayton Utz — Social media minimum age restrictions: the net widens, enforcement begins, and gaming platforms in the frame (May 2026): the Amendment Rules 2026 registered 25 March and commencing 26 March, the new recommender-feature and logged-in-feature criteria, the count of 23 information-gathering notices issued to ten platforms, the mid-2026 enforcement decision target, the $49.5 million maximum and $825,000 daily transparency-notice penalties, and the February 2026 transparency notices to Roblox, Minecraft, Fortnite and Steam.
- Online Safety Amendment (Social Media Minimum Age) Act 2024: the 29 November 2024 passage date and the structure of the amendment into Part 4A of the Online Safety Act 2021. A tertiary source, used only for legislative chronology.
- Al Jazeera — Australia’s under-16 social media ban failing, study shows (3 August 2026): the 4.7 million accounts figure as at mid-January 2026, Assistant Minister Andrew Leigh’s comparison with minimum drinking age laws, and the international picture — the United Kingdom planning for 2027, Denmark’s under-15 rules, Malaysia’s under-16 ban and Greece’s proposed 1 January 2027 start. We have relied on this report for the 4.7 million total and the overseas timelines, neither of which we could confirm from a primary source.