Skip to main content
Home/Blog/Australia's Under-16 Social Media Ban in 2026: What the Minimum-Age Law Means for Brands and Advertisers
Back to Intelligence Hub
kids-teensAustraliaRisk Level: high

Australia's Under-16 Social Media Ban in 2026: What the Minimum-Age Law Means for Brands and Advertisers

Australia now requires major platforms to take reasonable steps to keep under-16s off their services — reshaping teen audiences, age-assurance friction and brand-safety risk for advertisers.

Updated June 30, 2026· Originally published June 30, 202613 min readAuditSocials Research
TweetShare
Quick Answer

Australia's Online Safety Amendment (Social Media Minimum Age) Act 2024 requires designated 'age-restricted social media platforms' to take reasonable steps to prevent Australians under 16 from holding accounts, and the platform obligations took effect on 10 December 2025. According to the eSafety Commissioner, the law places the duty on the platform, not on the child or their parents, and it is not a mandate to age-verify every user — eSafety endorses a layered or 'waterfall' approach and the Act bars platforms from forcing government ID as the only option, so a reasonable alternative must always be available. The platforms eSafety has identified as age-restricted include Facebook, Instagram, Threads, Snapchat, TikTok, YouTube, X, Reddit, Twitch and Kick, while services such as Discord, Messenger, Pinterest, Roblox, Steam, WhatsApp and YouTube Kids are treated as not age-restricted, reflecting broad exemptions for messaging, online gaming and education or health services; under-16s can still view public YouTube content without an account because the restriction is on holding a logged-in account. The maximum penalty for a body corporate that systemically breaches the obligation is up to AUD $49.5 million, and penalties fall on platforms only. In March 2026 eSafety reported that account ownership on age-restricted platforms among children fell to 31.3% after the law took effect, and it placed several platforms under investigation. For advertisers, the practical effect is a structurally smaller and more legally sensitive under-16 audience on covered platforms in Australia, more age-assurance friction in signup funnels, and reputational risk in any creative that appears to court under-16s. Track changes on the Policy Change Tracker, map cross-border youth-marketing exposure with the Legal Compliance Scan, and compare the UK approach in the UK Online Safety Act age-assurance guide.

Australia's Under-16 Social Media Ban in 2026: What the Minimum-Age Law Means for Brands and Advertisers

What the Minimum-Age Law Requires

Australia's Online Safety Amendment (Social Media Minimum Age) Act 2024 amends the Online Safety Act 2021 to require designated "age-restricted social media platforms" to take reasonable steps to prevent Australians under 16 from creating or holding accounts. The Act received Royal Assent on 10 December 2024, and the platform obligations commenced a year later, on 10 December 2025.

The law is structured around responsibility, not punishment of young people. According to the eSafety Commissioner, the duty sits with the platform; under-16s and their parents face no penalty, and the obligation is to take reasonable steps rather than to guarantee a perfect outcome. That framing — a reasonable-steps duty on the platform — is what makes the regime workable and also what makes "what is reasonable" the central compliance question.

"The minimum age obligation places the onus on platforms — not children or their parents — to take reasonable steps to prevent under-16s from having an account.
— AuditSocials summary of eSafety Commissioner guidance"

For brands and advertisers, the law is not a content rule but an audience rule: it changes who is present and reachable on major platforms in Australia. This guide explains which platforms are covered, what "reasonable steps" and age assurance involve, the penalties and enforcement, and what the shift means for teen-facing campaigns. Define terms in the compliance glossary, and for the parallel UK regime see the UK Online Safety Act age-assurance guide.

Which Platforms Are Covered

The Act does not hard-code a list of platforms; instead it sets criteria for an "age-restricted social media platform" — broadly, a service whose sole or significant purpose is online social interaction that lets users link with and post material to others — with the specific in-scope services determined through rules and eSafety's self-assessment framework.

In Scope and Out of Scope

StatusServices (per eSafety)
Age-restricted (covered)Facebook, Instagram, Threads, Snapchat, TikTok, YouTube, X, Reddit, Twitch, Kick
Not age-restrictedDiscord, Messenger, Pinterest, Roblox, Steam and Steam Chat, WhatsApp, YouTube Kids, GitHub, Google Classroom

The exclusions reflect broad carve-outs for messaging, online gaming and services with a significant purpose of education or health. YouTube's status is worth noting: it was initially signalled for a possible carve-out but was ultimately included as age-restricted, with an important nuance — under-16s can still watch public YouTube content without an account, because the restriction is on holding a logged-in account, not on viewing public videos. Because eSafety can self-assess additional services as age-restricted over time, advertisers should treat the list as current guidance rather than a fixed boundary and monitor updates on the Policy Change Tracker.

Reasonable Steps and Age Assurance

The compliance standard is "reasonable steps," and eSafety's guidance, published in September 2025 ahead of the December start, sets out how to read it. The central message is that the law does not require platforms to verify the age of every single user, and that blanket verification of the entire user base may itself be unreasonable.

How Age Assurance Is Expected to Work

  • Layered approach: eSafety endorses a layered or "waterfall" model that combines multiple age-assurance methods rather than relying on a single check.
  • No government-ID-only requirement: the Act prohibits platforms from forcing users to use government ID or accredited digital ID as the only option; a reasonable alternative must always be offered.
  • Accessible review and appeal: guidance expects accessible mechanisms for users wrongly caught by an age check to seek review.
  • Proven feasibility: the government's Age Assurance Technology Trial, whose final report was released in September 2025, concluded that age assurance can be done in Australia and that multiple viable approaches exist, with no single mandated solution.

The practical upshot is that age assurance becomes a gateway layer on covered platforms in Australia — estimation, inference and verification methods applied in combination, with privacy-protective alternatives to ID. For advertisers this matters because the same friction that gates under-16s also adds steps to signup and account flows generally, and because age-assurance signals shape how teen audiences are defined for targeting. To map how youth-marketing rules interact across jurisdictions, use the Legal Compliance Scan.

Penalties, eSafety and Investigations

The eSafety Commissioner administers and enforces the obligation, with powers to issue regulatory guidance, compel information through legally enforceable notices, and investigate suspected non-compliance.

The Enforcement Picture

  • Maximum penalty: a body corporate that systemically breaches the minimum-age obligation faces a maximum civil penalty of up to AUD $49.5 million.
  • Platforms only: penalties apply to platforms, not to under-16 users or their parents.
  • Active investigations: in its first compliance update in March 2026, eSafety reported using numerous information-gathering notices and placing several platforms under active investigation for potential non-compliance.
  • Announced increase: in June 2026 the government announced an intention to roughly double the maximum penalty and expand eSafety's powers; treat this as announced rather than enacted until it passes.

As of mid-2026, the picture is one of investigations underway rather than completed prosecutions, with eSafety signalling it expects to make enforcement decisions on at least some matters. The $49.5 million figure is the operative maximum; the larger proposed figure should be cited only as a pending change. The practical signal for the market is that the regulator is actively testing platform compliance, which keeps audience availability and platform behaviour in flux. Track these developments on the Policy Change Tracker, and for how an age-assurance regime can disrupt advertising operations see the UK Online Safety Act analysis.

What It Means for Brands and Teen Audiences

The law is, in effect, an audience-reshaping measure, and its consequences for advertisers flow from that. The under-16 audience on covered platforms in Australia has structurally contracted, which changes both what is reachable and what is appropriate to attempt.

The Advertiser Implications

  • Smaller addressable teen pool: eSafety reported child account ownership on age-restricted platforms falling to 31.3% after the law took effect, so the genuine under-16 presence on these platforms in Australia is materially reduced.
  • "13–17" effectively shifts: on compliant covered platforms, the youngest available account-holders are 16, so teen-segment targeting in Australia trends toward 16–17 rather than 13–17.
  • Do not assume zero under-16 presence: independent research found some under-16s retained or regained access via existing, shared or alternative accounts, so leakage exists and creative should not rely on the audience being perfectly age-gated.
  • Reputational risk: campaigns that appear to court under-16s on covered platforms carry heightened scrutiny in the current enforcement climate.

The disciplined posture for brands running youth-adjacent campaigns in Australia is to plan for a smaller, older and more uncertain teen audience on covered platforms, to expect more age-assurance friction in funnels, and to keep creative clear of anything that reads as targeting under-16s. For the broader patchwork of minor-targeting restrictions advertisers must track, see the state age-verification and minor-targeting guide, and for platform-side teen defaults the Meta Teen Accounts rollout.

Brand Compliance Checklist

  • [ ] Identified which of your active Australian platforms are age-restricted under the law
  • [ ] Adjusted teen targeting on covered platforms to reflect a 16-and-over account base
  • [ ] Removed creative or messaging that could be read as courting under-16s on covered platforms
  • [ ] Accounted for age-assurance friction in signup and account-linked campaign funnels
  • [ ] Avoided assuming zero under-16 presence given documented account leakage
  • [ ] Reviewed youth campaigns against the current enforcement and reputational climate
  • [ ] Confirmed platform-specific age-assurance flows do not force government ID as the only option
  • [ ] Monitored eSafety investigations and any penalty-increase legislation for changes
  • [ ] Mapped how the Australian rule interacts with other youth-marketing jurisdictions
  • [ ] Confirmed current scope and guidance against eSafety's published materials

Frequently Asked Questions

What does Australia's under-16 social media law actually require platforms to do?
Australia's Online Safety Amendment (Social Media Minimum Age) Act 2024 requires designated 'age-restricted social media platforms' to take reasonable steps to prevent Australians under 16 from creating or holding an account on the service, and that obligation took effect on 10 December 2025, a year after the Act received Royal Assent. The crucial features of the requirement are who it falls on, what standard it sets, and what it does not demand. On who it falls on: according to the eSafety Commissioner, the duty is placed squarely on the platform, and neither the under-16 user nor their parents face any penalty under the law — this is a platform-obligation regime, not a measure that criminalises young people or families for circumventing it. On the standard: the obligation is to take 'reasonable steps,' which is a calibrated standard rather than an absolute guarantee. A platform is not automatically in breach simply because some under-16 manages to retain or create an account; the question is whether the platform took reasonable steps to prevent it. That makes 'what is reasonable' the central interpretive question, and eSafety's guidance, published in September 2025 ahead of the start date, is the primary source for how to read it. On what it does not demand: eSafety has been explicit that the law does not require platforms to verify the age of every single user, and that imposing blanket verification on the entire user base may itself be unreasonable. Instead the expectation is a layered or 'waterfall' approach that combines multiple age-assurance methods proportionately, with accessible review mechanisms for people wrongly caught by a check. The Act also constrains how age assurance can be done in one important way: platforms cannot force users to use government ID or accredited digital ID as the only option to satisfy an age check, so a reasonable alternative must always be available — a privacy-protective design choice that prevents the law from becoming a de facto ID mandate. The combined effect is a regime that asks covered platforms to build a proportionate, multi-method age-assurance gateway that meaningfully reduces under-16 account-holding without resorting to universal ID verification. For advertisers, understanding this structure matters because it explains both why the under-16 audience has shrunk on covered platforms and why some under-16 presence persists despite the law. Define the key terms in the compliance glossary, and confirm the current obligations against eSafety's published guidance because the detail of 'reasonable steps' governs. The organizing principle is that the law requires platforms — not children or parents — to take reasonable, layered steps to keep under-16s from holding accounts, without mandating universal age verification or government ID.
Which platforms are covered by the Australian minimum-age law, and is YouTube included?
The Australian minimum-age law applies to services that meet the criteria for an 'age-restricted social media platform,' and rather than fixing a permanent statutory list, scope is determined through rules and the eSafety Commissioner's self-assessment framework — but eSafety has published which major services it treats as age-restricted, and YouTube is included, after an earlier signal that it might be carved out. The services eSafety has identified as age-restricted include Facebook, Instagram, Threads, Snapchat, TikTok, YouTube, X, Reddit, Twitch and Kick, with additional services such as Bluesky, Lemon8, Wizz, Yubo and BigoLive self-assessing into scope. On the other side, eSafety treats a range of services as not age-restricted, including Discord, Messenger, Pinterest, Roblox, Steam and Steam Chat, WhatsApp, YouTube Kids, GitHub and Google Classroom. The reason for the exclusions is that the law contains broad carve-outs for categories whose primary purpose is messaging, online gaming, or education or health, and for services aimed at younger children with appropriate protections — which is why messaging apps, gaming platforms and classroom tools sit outside the age-restricted set even though some involve social interaction. YouTube's inclusion is the most discussed point and worth stating precisely. Under an earlier government position YouTube had been signalled for a possible exemption, but it was ultimately included as an age-restricted platform. The nuance that advertisers should understand is that the restriction concerns holding a logged-in account, not viewing content: under-16s in Australia can still watch public YouTube videos without an account, so YouTube content remains accessible to them even though they are not meant to hold accounts. That distinction has practical consequences for media planning, because it means YouTube's logged-out reach to under-16s persists while the logged-in, account-based audience contracts. Because eSafety can self-assess further services into the age-restricted category over time, the list is best treated as authoritative current guidance rather than a closed boundary, and advertisers operating in Australia should periodically reconfirm the status of each platform they use. The composition of the covered set also shapes where the audience effect is concentrated: the contraction of under-16 account-holding is felt on the major social platforms in scope, while gaming, messaging and education services are largely unaffected. Monitor scope changes on the Policy Change Tracker, and reconcile this with platform-side teen defaults such as the Meta Teen Accounts rollout. The organizing principle is that the law covers the major social platforms — including YouTube for account-holding, though under-16s can still view public YouTube without an account — while messaging, gaming and education services are excluded.
What are the penalties, and has any platform been fined yet?
The maximum penalty under the Australian minimum-age law for a body corporate that systemically breaches the obligation to take reasonable steps is up to AUD $49.5 million, and those penalties apply to platforms only — not to under-16 users or their parents — but as of mid-2026 the enforcement picture is one of active investigations rather than completed prosecutions or court-imposed fines. The $49.5 million figure is the operative maximum civil penalty for a serious, systemic failure, and it is the number advertisers and platforms should treat as the current ceiling. It is worth being precise about a related development: in June 2026 the government announced an intention to roughly double the maximum penalty and to strengthen the eSafety Commissioner's information-gathering powers. That announced increase, however, was a proposal as of late June 2026 and had not been enacted into law, so the correct posture is to cite $49.5 million as the operative cap and to describe the higher figure only as a pending, announced change rather than as the current maximum. On enforcement activity, the eSafety Commissioner administers and enforces the regime and has been visibly active. In its first compliance update, published in March 2026 covering the initial period after the December 2025 start, eSafety reported drawing on numerous legally enforceable information-gathering notices issued to the covered platforms and placing several of them under active investigation for potential non-compliance — with public reporting identifying major platforms among those being examined over issues such as allowing repeated re-verification attempts by self-declared under-16s and weak prevention of new under-16 sign-ups. The Commissioner indicated an expectation of reaching enforcement decisions on at least some matters around mid-2026. What had not occurred, as of the research underpinning this guide, was a completed prosecution or a published court-imposed penalty against any platform, so it would be inaccurate to say any platform has been 'fined' under the law to date; the accurate statement is that investigations are underway. For advertisers, the enforcement signal matters more than any single number: an actively investigating regulator keeps platform behaviour and audience availability in flux, and the prospect of substantial penalties incentivises platforms to tighten age assurance further, which can change signup friction and audience definitions during a campaign. Track enforcement actions and any penalty-increase legislation on the Policy Change Tracker, and stress-test youth-campaign exposure with the Legal Compliance Scan. The organizing principle is that the operative maximum is AUD $49.5 million on platforms only, a larger penalty has been announced but not enacted, and as of mid-2026 platforms are under investigation rather than fined.
How does the law affect advertisers targeting teen audiences in Australia?
The law affects advertisers principally by reshaping the audience: it materially reduces the genuine under-16 presence on covered platforms in Australia, shifts the youngest available account-holders on those platforms to 16, adds age-assurance friction to signup funnels, and raises the reputational stakes of any creative that appears to court under-16s — so teen-facing campaigns on covered platforms must be replanned around a smaller, older and more uncertain audience. The most concrete data point is the contraction in account ownership. eSafety reported that account ownership on age-restricted platforms among children fell to 31.3% following the December 2025 start, which means the genuine under-16 audience on those platforms in Australia is substantially smaller than before the law. For media planning, the direct consequence is that segments which previously addressed 13-to-17-year-olds on these platforms now effectively reach 16-to-17-year-olds among compliant account-holders, because under-16s are not meant to hold accounts. Advertisers should therefore expect smaller addressable teen pools on covered platforms and adjust reach and frequency assumptions accordingly. A second, important nuance is that the audience is not perfectly age-gated. Independent research found that some under-16s retained or regained access through existing, shared or alternative accounts, so leakage exists, and the on-paper account drop overstates the real reduction in under-16 reach. The practical implication cuts both ways: advertisers cannot assume that covered platforms are entirely free of under-16s, which means creative and targeting should not rely on a perfect age gate, and any campaign that would be inappropriate or risky in front of under-16s should not be run on the assumption that none will see it. A third consequence is operational friction. The age-assurance gateways that platforms have implemented to comply add steps to signup and account-linked flows, which can affect conversion in funnels that depend on account creation. A fourth consequence is reputational: in an environment where the regulator is actively investigating platforms and the policy is high-profile, brands face heightened scrutiny if their creative reads as targeting under-16s on covered platforms, so the safe posture is to keep youth-adjacent creative clearly aimed at of-age audiences. The disciplined approach for brands running youth campaigns in Australia is to plan for a smaller and older teen audience on covered platforms, to account for leakage rather than assume a clean gate, to build age-assurance friction into funnel expectations, and to keep creative unambiguously clear of under-16 targeting. For the wider set of minor-targeting restrictions to track, see the state age-verification and minor-targeting guide, and map cross-jurisdiction youth-marketing exposure with the Legal Compliance Scan. The organizing principle is that the law shrinks and ages-up the under-16 audience on covered platforms while leaving some leakage, so teen campaigns must be replanned for a smaller, older, imperfectly gated audience with greater reputational sensitivity.
How does the Australian law compare with age rules in the UK, EU and US?
Australia's under-16 minimum-age law is the most direct of the major regimes in that it targets account-holding itself — barring under-16s from holding accounts on covered platforms and putting the onus on platforms to prevent it — whereas the UK, EU and US approaches focus more on age-appropriate design, age assurance for specific content, profiling restrictions and targeted-advertising limits rather than a blanket account ban, so advertisers operating across these markets face a patchwork of differently-shaped obligations rather than one harmonised rule. Australia's design is distinctive: the operative concept is that a child under 16 should not have an account on an age-restricted social media platform, and the platform must take reasonable steps to achieve that, backed by penalties up to AUD $49.5 million. It is an audience-exclusion model. The United Kingdom, by contrast, operates through the Online Safety Act and Ofcom's regime, which emphasises age assurance to protect children from specific categories of harmful content and imposes duties on platforms to assess and mitigate risks to children, rather than excluding under-16s from holding accounts wholesale; the practical effect is heavy age-assurance friction and content-gating rather than an account ban. The European Union approaches the question through several instruments rather than a single age-ban: the Digital Services Act restricts targeted advertising to minors based on profiling and imposes systemic-risk and minor-protection duties on large platforms, while data-protection law governs children's data and consent — again a design-and-targeting model rather than an account prohibition. The United States has no single federal age-ban either; instead it combines COPPA's rules on under-13 data, a growing set of state laws restricting targeted advertising to minors and imposing age-verification or age-appropriate-design duties, and ongoing litigation over several of those state measures, producing a fragmented state-by-state patchwork. For an advertiser, the strategic implication of this divergence is that there is no single global 'minor' rule to comply with: Australia narrows the addressable under-16 audience on covered platforms outright; the UK and EU constrain how minors are reached, profiled and protected; and the US varies by state. The defensible approach is to design youth-adjacent campaigns to the strictest applicable standard in each market — treating covered Australian platforms as effectively 16-and-over, honouring UK and EU age-assurance and profiling limits, and tracking the US state patchwork — rather than porting one market's assumptions to another. For the UK detail see the UK Online Safety Act age-assurance guide, for the US picture the state age-verification guide, and map the combined exposure with the Legal Compliance Scan. The organizing principle is that Australia uniquely bans under-16 account-holding while the UK, EU and US regulate design, age assurance, profiling and targeting — so advertisers must comply with differently-shaped rules market by market.

Don't miss the next policy change.

Create a free account — track every policy change across 8 platforms, get instant alerts, and access every free compliance tool. Or try our Meta Rejection Predictor first.

Create Free Account

Report Keywords — Run AI Compliance Audit

#Australia#Social Media Age Ban#Minimum Age#eSafety#Age Assurance#Teen Audiences#Brand Safety#Online Safety Act#Kids and Teens#2026 Policy#Advertisers#Compliance Guide 2026

Share This Report

TweetShare

Related Posts

Related Resources