Australia Doubles Down: A$99M Penalties for Failed Age Checks
Australia passed a bill expanding eSafety powers and raising penalties to A$99 million for social media age verification failures. What platforms must do now.

Australia's world-first social media age law just grew teeth to match its ambition. On September 11, Parliament passed the Online Safety Amendment (Strengthening Enforcement for the Social Media Minimum Age) Bill 2026, expanding the eSafety Commissioner's investigative powers and lifting maximum civil penalties for noncompliance to A$99 million, roughly double the previous ceiling.
The amendment answers the enforcement gap critics identified when the under-16 minimum age framework launched in December 2025. Platforms self-reported their compliance; regulators had limited means to check. The new law flips that: the Commissioner gains expanded information-gathering and examination powers, and enforcement shifts from platform self-reporting to mandatory documentation disclosure. Platforms will no longer describe their age assurance; they will produce it.
For every business running age checks anywhere, not just social media, the Australian trajectory is the leading indicator: age assurance mandates arrive first, and evidence mandates follow.
What the amendment changes
Three things with hard edges. Penalties double, with the A$99 million ceiling putting age verification failures in the same financial category as major privacy breaches. Investigative powers expand, letting eSafety compel documents and examine platform systems rather than accepting attestations. And the burden of proof effectively moves: the operating question becomes whether a platform can demonstrate its age assurance works, with records, not whether it claims a program exists.
The first nine months of the regime explain the tightening. Enforcement results showed a 10 percent decline in under-16 account ownership, and Meta alone reportedly deactivated more than 750,000 accounts believed to belong to under-16 Australians. Yet more than half of surveyed children said platforms never asked their age at all, a gap between headline compliance and ground truth that the new examination powers are built to close.
The evidence era of age assurance
The amendment's deepest change is evidentiary. A platform facing an eSafety examination needs to show which age assurance methods it runs, their measured accuracy on its actual population, the decision trail for contested accounts, and the handling of circumvention. "We deployed a vendor" is a procurement record, not a defense.
That standard rewards age assurance built like a verification system rather than a checkbox. deepidv's approach pairs facial age estimation with deepeye's passive structural liveness inside one session on the core platform, so every age verdict is anchored to a live, present human and logged with its evidence: method, confidence band, liveness result, and device context. When the examiner asks how a fifteen-year-old passed, the answer is a record, not a shrug.
The global ripple
Australia's regime is the world's test case, and regulators are openly watching. The US House bill mandating facial age checks for sportsbooks and prediction markets, the Digital Age Assurance Act's OS-level signals, the UK's expanding age verification economy, and eIDAS 2.0's zero-knowledge age proofs all share the Australian premise: self-declared age is dead as a control. The Australian amendment adds the second premise: undocumented age assurance is next.
Platforms operating internationally should assume convergence. An age assurance architecture with measured accuracy, liveness under the estimate, privacy-preserving outputs, and examination-grade records satisfies Canberra today and its imitators tomorrow.
Australian Age Enforcement FAQ
- What did Australia's new online safety amendment change?
- Passed September 11, 2026, it expands the eSafety Commissioner's information-gathering and examination powers and raises maximum civil penalties for social media minimum age noncompliance to A$99 million. Enforcement moves from platform self-reporting to mandatory documentation disclosure.
- What is Australia's social media minimum age law?
- The Social Media Minimum Age framework, in force since December 2025, requires platforms to take reasonable steps to prevent Australians under 16 from holding accounts. It is the world's first national under-16 social media ban, and early enforcement drove a measured 10 percent decline in under-16 account ownership.
- How do platforms verify users are over 16?
- Through age assurance methods including facial age estimation, ID-based verification, and inference signals. The tightened regime pushes platforms toward measurable methods: biometric estimation with liveness, documented accuracy bands, and decision records an examiner can audit, rather than self-declared birthdates.
- Do the doubled penalties apply outside social media?
- Directly, no: the amendment targets the social media minimum age framework. Practically, it sets the evidentiary tone for Australian age regulation broadly, and businesses in gambling, alcohol, and adult content should expect the documentation standard to migrate.
- What should platforms do to prepare for eSafety examination?
- Inventory every age assurance method in production, measure accuracy on your real user population, ensure liveness protects the estimate from replay and borrowed-account attacks, and build the per-decision evidence trail now. Examinations reward records, and the new powers make records mandatory on request.
Relevant Articles
Sportsbook Age Verification: Congress Moves on Face Checks
America's parallel mandate track.
Sep 4, 2026
Digital ID Reaches the Pub: UK Approves It for Alcohol Sales
The credential path entering daily life.
Sep 14, 2026
AUSTRAC Turns Tranche 2 Paperwork Into Supervision Sweeps
Australia's other evidence-first enforcement push.
Sep 4, 2026
What is deepidv?
Not everyone loves compliance — but we do. deepidv is the AI-native verification engine and agentic compliance suite built from scratch. No third-party APIs, no legacy stack. We verify users across 211+ countries in under 150 milliseconds, catch deepfakes that liveness checks miss, and let honest users through while keeping bad actors out.
Learn More