Australian Age Assurance Experience

Published September 21, 2026

A long journey starts with a single step (often in the dark!)

By Thomas Ludot (and co), Senior Consultant at ID Partners

A long journey starts with a single step 

-- Lao Tzu, The Tao Te Ching

We know. It is obvious.

We often know we have to go, but we wait until we have the entire journey mapped out before taking the first step.

We want everything perfectly worked out, and only then do we move.

Social media has been around for more than 20 years now, and despite the fantastic promise of hyperconnectedness, breaking down the physical barrier of presence to build rapport, a more contrasted truth has emerged. Corporate networks now manage the feeds of billions of people, engineered for continuous dopamine hits. It is already hard for balanced adults to manage, but the most concerning impact is on our youngest and dearest human beings, who have now been “boxed” as “under 16” here in the land down under.

Within the OpenID Foundation’s at the Australian Digital Trust Community Group (ADT CG), our mission is to instill conversations on trust ecosystems, and raise awareness around initiatives, frameworks, and standards — with a strong intent to promote standards-based digital trust services. In a nutshell, we believe in the power of digital trust, and we are doing our best to push towards a more “fair-trade” ecosystem.

The Australian first step

The "social media minimum age restrictions", ie. The restriction for under‑16s, that took effect on 10 December 2025, has been — at the very least — an animated topic. And for good reason: it brings together all the core ingredients of digital trust — technology, legal, ethics, privacy, and adoption.

Let’s go back to Lao Tzu. This is the first step of a long journey.

Despite the disagreements and agitation around this measure, one thing is clearly emerging beneath the noise: It was time to press the brakes.

Something needed to be done to protect our most vulnerable cohort — those trying to make sense of a system where “if it is free, you are the product.”

By legislating to restrict under‑16s from major social media platforms, Australia made a global statement: these platforms carry real risks for our young people. Everyone knew it. It was simply time to act.

Now, only months later, others are moving. The UK, France, Spain — and beyond Europe, Canada and New Zealand — are following. Even the platforms and device manufacturers themselves are starting to adjust.

It does make you think of plastic bags in retail. For decades, they were handed out freely by supermarkets. Over time, the impact became undeniable, and suddenly, those same players became the first to champion environmental responsibility.

This firm stance has triggered awareness conversations at multiple levels around the real impacts of social media: “anxiety, insomnia, depression, cyberbullying, echo chambers, algorithmic exposure…”

  • Between children and parents
  • Between children themselves
  • Between platform owners and regulators
  • Between researchers and the general public
  • Between technology providers and platforms

This is positive. It breaks a 20‑year status quo where platforms enjoyed a “red carpet”, offering unlimited access to unregulated, algorithm-driven environments. Australia has forced a reset. Australia has raised global awareness.

The Australian half‑baked cake

But then comes the other side of the story. That feeling when you open the oven and the cake doesn’t look like the picture in your fancy cookbook. Disappointment. The expectation of something great disappears. Troubleshooting begins.

The Online Safety Amendment (Social Media Minimum Age) Act 2024 is not a direct ban on children. It is an obligation on platforms. And importantly, enforcement is intentionally technology-neutral. Platforms must take “reasonable steps” to prevent under‑16s from having accounts. That sounds pragmatic. In reality, it creates ambiguity. We know kids won’t delete their accounts overnight, so how does this actually work?

Regulators explicitly prohibited platforms from relying solely on government IDs to protect privacy, platforms heavily biased their compliance towards low-friction age estimation (such as facial AI scans) and in-house age inference (behavioral patterns and account history), instead of investing or encouraging privacy preserving solutions such as device-level credentials, anonymous cryptographic age tokens or decentralised identity approaches. Platforms have been doing the bare minimum rushing through implementations to fulfill their legal burden and avoid fines.

Unsurprisingly, this reliance on statistical estimation falls far short of expectations. Youth quickly exploit these soft barriers through basic workarounds by manipulating selfie-scan angles, altering device settings, pooling behavioral signals on shared devices,...or any other creative bypass they can imagine (and they are getting better and better at it)!

This gap triggers a legal paradox:

  • Regulators measure compliance via audit trails, warning notices, and raw volume of banned accounts.
  • Platforms optimise for low-friction compliance checkmarks rather than unhackable barriers.

The result is a reliance on half-baked technologies that generates weak enforcement and fails to meet core policy objectives. Because statistical estimation inevitably fails to withstand persistent youth evasion, regulators will eventually be compelled to implement stricter compliance standards. This progressive regulatory escalation will push the market away from soft in-house behavioral signals and toward mandatory, higher-assurance cryptographic solutions.

This shift from flexible, technology-neutral guidelines to mandatory strong identity verification risks displacing determined young users from regulated platforms altogether, driving them into darker, unmonitored online environments beyond the jurisdictional reach of the eSafety Commissioner.

What’s next for Australia (and lessons for others?)

The journey has officially started, and the hard part begins now. Moving beyond the initial wave of compliance requires a fundamental shift in how we approach online identity, regulation, and education.

Key strategic directions ahead:

Invest in privacy-preserving age tech
Move away from reactive, surface-level fixes and focus on standards-based architectures.The priority must be supporting scalable, privacy-first technologies rather than rushed compliance measures that compromise user trust.

Think identity much earlier
As the need for proof of age expands across digital services, we need trusted, minimal digital credentials that could exist from a young age without exposing full identity details. The goal is to establish systems that enable selective disclosure, allowing users to prove they meet an age threshold without handing over extraneous personal data.

Engaging well beyond regulation
Parents, educators, and young people must be central to this transition. Comprehensive public education campaigns are needed so parents and teachers can confidently guide children through these changes. With social media restrictions now encoded in law, topics like digital identity, online privacy and social media risks should belong in school technology curricula.

Shift from punishment to co-design
Move from a rigid "figure it out or face massive fines" posture toward genuine co-design between regulators, platforms, technology providers, and even education or technology departments. Leveraging creativity and ingenuity used against current systems to enable systems that kids want to use because they understand the risks.

Prepare for regulatory expectations to dial up
Heavy reliance on low-assurance age estimation will inevitably face growing scrutiny from regulators. As workarounds proliferate, policy expectations will shift toward higher-assurance alternatives. Organisations with compliance obligations should actively evaluate and test robust, privacy-preserving solutions before stricter regulatory standards take effect.

Conclusion

The journey has begun, and there are thousands of steps ahead. Like smoking regulations before it, systemic change starts with awareness before building into global momentum. Australia has succeeded in raising national awareness, triggering fierce local and international debate, and forcing major global platforms to take action.

However, the government has struggled, so far, to define the technical standards and infrastructure needed to support this monumental shift. Without a clear foundation, we risk imposing a drastic regulatory shift on millions of digitally dependent young people without giving the wider ecosystem the tools required to do it safely, fairly, and sustainably.

Calls to Action

Join the ADT CG Age Assurance subgroup. Those focused on age assurance in Australia are encouraged to join the ADT CG Age Assurance subgroup; sign the participation agreement here and Join the new OIDF Community Group on Age Assurance. Those who want to share Australia's experience with the global community, and work on age assurance more broadly, are encouraged to take part. The OpenID Foundation Board approved this new community group in June 2026, and it is expected to launch soon in partnership with leading countries working on age assurance and partner organisations, including the SIROS Foundation. Stay tuned for further information on the launch.

Give feedback on the whitepaper blog series. The OpenID Foundation Board has also approved a whitepaper on age assurance, launching as a series of blog posts. We welcome community feedback, which will be shared with the ADT CG’s Age Assurance subgroup.

Follow the discussion at GDC 2026. Policy and solution design discussions are accelerating in numerous jurisdictions, including the UK, France, Denmark, Spain, Brazil, and across several US states. Age assurance was a central topic at the Global Digital Collaboration (GDC) conference in Geneva (September 1–3, 2026), where the OpenID Foundation co-led multiple sessions. To stay connected with the global discourse, explore the event outcomes on the GDC website, and take note of the upcoming book of proceedings covering the 8+ dedicated sessions on age assurance.

About the author: Thomas Ludot is a senior identity consultant specialising in the full spectrum of digital identity technologies. A member of the Australian Digital Trust Community Group (ADT CG) since 2025, he is deeply passionate about digital trust, identity standards, and what truly defines us in the modern digital world. He is also the proud father of a five-year-old daughter. 

About the OpenID Foundation

The OpenID Foundation (OIDF) is a global open standards body committed to building trusted identity ecosystems. Our mission is to lead the global community in identity standards that are secure, interoperable, and privacy respecting. Founded in 2007, we are a community of technical experts. The Foundation's OpenID Connect standard is now used by billions of people across millions of applications. More recently, the FAPI security profile - built on OAuth 2.0 - has become the standard of choice for interoperable Open Banking and Open Data implementations, while OpenID for Verifiable Credentials specifications are underpinning a new generation of digital wallets. Today, the OpenID Foundation's standards are the connective tissue that enable people to assert their identity and access their data at scale, the scale of the internet, enabling "networks of networks" to interoperate globally. Individuals, companies, governments and non-profits are encouraged to join or participate. Find out more at openid.net.

Tagged