Steam Locks Australians Behind Credit-Card-Only Age Checks
Steam now gates R18+ games in Australia behind credit card checks alone, and the eSafety Commissioner says the single-method approach likely fails fairness.

Australia's new age assurance regime has produced its first cautionary tale, and it is one of the world's biggest gaming platforms. Steam has begun gating R18+ games and their community hubs behind age checks that run only through its own payment system: hold a credit card on file and you are treated as an adult, lack one and the content disappears, with no estimation, no document option, and no third-party provider involved.
The trigger is the Age-Restricted Material Codes for app distribution services, which took effect on September 9, 2026. Under the ISO/IEC 27566-1 framework the codes reference, credit card possession is classed as age inference, an indirect indicator rather than age verification, and it is a weak inference with a hard edge: only 26 percent of Australians aged 18 to 24 hold a credit card, rising to 42 percent for 25 to 34. A method that misses most of the youngest adults it exists to clear is doing its filtering by demographics, not by age.
The regulator's response
The eSafety Commissioner's office is already engaging with Valve, and its early language is pointed. The single-method design likely fails to meet the regulatory requirement of fairness, the office noted, adding that providers should offer a choice of a range of age assurance methods, giving end-users flexibility and agency in choosing methods that best suit their circumstances. The comparison the regulator reached for makes the standard concrete: other major storefronts offer several routes, with Microsoft accepting email-based signals, facial age estimation, document scans, and cards.
Users have their own reading: forums quickly labeled the design malicious compliance, a system built to satisfy the letter of the codes while making the experience poor enough to blame the regulation. Whatever the intent, the effect is measurable: paying adult customers locked out of content they own the right to see, on the basis of a payment product they never needed before.
Why single-method compliance keeps failing
Steam's build fails in both directions at once. As a child-safety control it is thin, since a teenager with access to a parent's saved card clears it silently. As an adult-access control it is exclusionary, since the card-ownership numbers guarantee false lockouts at scale. That is the general shape of every single-method program: each method has a coverage hole and an evasion hole, and only layering fills both.
A layered build does what the regulator is describing: facial age estimation for users who want a ten-second check with nothing on file, credential or document routes for those who prefer them, payment or device signals where they already exist, and every route producing the same evidence record. That is the architecture the deepidv platform ships as one policy, and it is becoming the only design that satisfies regulators who now grade on fairness as well as effectiveness.
Steam Australia Age Check FAQ
- Why is Steam asking Australians for a credit card?
- Australia's Age-Restricted Material Codes, in force since September 9, 2026, require platforms to keep R18+ content from minors, and Steam chose to meet the duty with a single method: treating a credit card on file as proof of adulthood.
- Is a credit card check real age verification?
- Under ISO/IEC 27566-1 it is age inference, not verification: card possession indirectly suggests adulthood but proves neither the holder's age nor who is using the account, and a minor with access to a parent's saved card passes it.
- What did Australia's eSafety Commissioner say about Steam's approach?
- That a single-method design likely fails the regulatory requirement of fairness, and that providers should offer a range of age assurance methods so users can choose one that suits their circumstances.
- How many young Australian adults have credit cards?
- Roughly 26 percent of Australians aged 18 to 24 and 42 percent of those 25 to 34, which means a credit-card-only gate wrongly excludes most of the youngest adults it is supposed to clear.
- What should platforms use instead of a single age check method?
- A layered stack: facial age estimation for a fast no-documents route, credential and document options for users who prefer them, existing payment and device signals as supporting evidence, and one evidence record across every route.
Relevant Articles
Australia Doubles Down: A$99M Penalties for Failed Age Checks
The enforcement regime Steam is testing.
Sep 14, 2026
Ofcom Probes Device-Level Age Checks at Pornhub's Owner
The other single-signal age gate on trial.
Sep 25, 2026
Sportsbook Age Verification: Congress Moves on Face Checks
The method-mandate direction of travel.
Sep 4, 2026
What is deepidv?
Not everyone loves compliance — but we do. deepidv is the AI-native verification engine and agentic compliance suite built from scratch. No third-party APIs, no legacy stack. We verify users across 211+ countries in under 150 milliseconds, catch deepfakes that liveness checks miss, and let honest users through while keeping bad actors out.
Learn More