Australia strengthens enforcement of its social-media minimum-age law
Australia has passed amendments giving the eSafety Commissioner stronger powers to investigate whether social-media platforms comply with the country’s minimum-age law. The changes increase penalties and require platforms to offer an age-assurance option that does not depend solely on government identification.
What it could improve
The amendments strengthen the regulator’s ability to demand documents and evidence from platforms, age-assurance providers and app stores, and to summon people—including company executives—to answer questions. Maximum penalties rise to AUD 109.2 million, while substantial infringement notices can apply to breaches of the minimum-age obligation or failure to offer an alternative to government ID.
What remains unresolved
Stronger enforcement can improve compliance, but it does not by itself make age assurance accurate, privacy-preserving or consistent across the wider digital environment.
- A minimum-age rule still depends on recognising children reliably when accounts, devices and declared ages may not reflect the actual user.
- Offering an alternative to government ID is important, but alternative methods can still collect facial, behavioural or device data unless privacy and data-minimisation standards are explicit.
- Each platform may continue to make its own assurance decision, producing repeated checks and inconsistent outcomes across services.
- The amendments improve oversight of regulated social-media platforms; they do not automatically extend age-appropriate protection to games, messaging, websites, AI services or signed-out use.
- Penalties measure non-compliance, but evaluation must also test whether children experience less harm and retain access to beneficial, rights-respecting digital participation.
The Child-Friendly Internet perspective
Enforcement and meaningful penalties are necessary when platforms fail to meet child-safety duties. The next design question is whether compliance can operate through a shared, privacy-preserving assurance foundation rather than requiring every service to identify the child independently.
- Require assurance methods to reveal only the minimum necessary age or developmental category—not identity documents or a persistent child profile.
- Develop interoperable signals so participating services can recognise the appropriate child context without repeating verification.
- Measure real safety and wellbeing outcomes alongside platform documentation and procedural compliance.
- Connect minimum-age enforcement with safer design and positive age-appropriate alternatives across the broader ecosystem.
The central question
Can stronger enforcement support reliable child assurance without normalising repeated identity checks across every digital service?
