Australia was the first country to legislate a minimum age for social media accounts. The Online Safety Amendment (Social Media Minimum Age) Act 2024 passed the Parliament in November 2024, received Royal Assent on 10 December 2024 and inserted a new Part 4A into the Online Safety Act 2021. Its obligations took effect on 10 December 2025. From that date, providers of age-restricted social media platforms must take reasonable steps to prevent Australians under 16 from having accounts. This article explains what the law requires, which services it reaches, what reasonable steps means, and the role of the eSafety Commissioner, for product and trust-and-safety leads deciding what to build. The list of services in scope has moved as eSafety has issued assessments, and the reader should check the current position before relying on any name in this article.
The obligation
The core duty is short. A provider of an age-restricted social media platform must take reasonable steps to prevent age-restricted users from having accounts on the platform. An age-restricted user is an Australian child under 16. The duty is about accounts, not access: the law does not require a platform to stop a child viewing public content without an account, and it does not penalise the child, the parent or anyone who helps a child on. Enforcement is against the provider, with civil penalties for bodies corporate of up to 150,000 penalty units, which at the time of writing is in the region of 49.5 million Australian dollars. The reader should check the current penalty unit value.
The duty is expressed as reasonable steps rather than as a guarantee. A platform that has a well-designed system and still has some under-16 accounts has not necessarily breached the law; a platform that has no system, or a system it knows does not work, has.
Which services are in scope
The Act defines an age-restricted social media platform by purpose and function rather than by name. The definition covers an electronic service whose sole or significant purpose is to enable online social interaction between two or more end users, which allows users to link to or interact with some or all other users, and which allows users to post material, subject to conditions and exclusions set in legislative rules. The Online Safety (Age-Restricted Social Media Platforms) Rules 2025 exclude classes of service, and the government has described the intended exclusions as covering messaging services, online games, and services whose primary purpose is education, health or professional networking, among others. The reader should read the current rules for the exact wording.
eSafety has published its assessments of which services it considers age-restricted. Its announcements in the run-up to commencement named the major social networks and video platforms most people would expect, and eSafety has been clear that the list is not closed and that it will keep assessing services. A provider should not assume it is out of scope because it was not named; it should apply the definition to its own service, and it can seek eSafety's view.
What "reasonable steps" means
The Act does not list the steps. It gives eSafety the role of issuing regulatory guidance, and the government commissioned an independent Age Assurance Technology Trial, which reported in 2025 on the accuracy, privacy and usability of available methods. eSafety's guidance on reasonable steps, published in 2025, describes a systems-based approach rather than a single check at sign-up. The themes, as eSafety has described them, include finding and removing existing under-16 accounts, preventing new ones, using age assurance methods that are effective for the platform's risk, offering more than one method, handling errors and appeals fairly, and monitoring and improving the system over time. The reader should check the guidance directly for its current terms.
Two constraints on method come from the Act itself. A provider must not rely on government-issued identification, or on an accredited service under the Digital ID Act, as the only means of age assurance; it must offer a reasonable alternative. And personal information collected for the purpose of the age restriction must not be used for any other purpose without consent, and must be destroyed once it is no longer needed. Both constraints point the same way as the data minimisation principles in the UK and EU regimes: prove the threshold, keep the result, delete the evidence. The age assurance comparison sets out the methods and their trade-offs.
eSafety's role
The eSafety Commissioner administers and enforces the minimum age, alongside its existing powers under the Online Safety Act 2021 covering cyberbullying material, image-based abuse, the online content scheme, the Basic Online Safety Expectations and the industry codes. eSafety can require information from providers, publish assessments of which services are in scope, issue formal warnings and infringement notices, and seek civil penalties in court. It has also said that its focus in the early period is on whether providers have systems in place and are working in good faith, rather than on individual accounts. The Act requires an independent review of the minimum age provisions within two years of commencement, so the settled shape of the regime is still ahead.
What this means for a global product
A platform that is in scope in Australia now has to solve, for one market, a problem that other regimes describe in softer terms. The UK Online Safety Act asks for highly effective age assurance where the most harmful content is involved, and the EU Digital Services Act asks for proportionate measures with age verification only where the risk is high. Australia sets a hard threshold at the account itself. The engineering answer that satisfies all three is the same infrastructure applied at different thresholds: a reliable age signal, more than one method, a result-only data model, and a record of accuracy. A team that builds it for Australia should build it once.
A worked example
Fennelbrook, a fictional company, runs a video sharing platform with comments, direct messages and follower graphs, with a meaningful Australian audience. Its own reading of the definition puts it in scope, and eSafety's assessments agree. The team designs a layered system: for existing accounts, a model that flags likely under-16 users from declared birth dates, account age and signals such as school-related content, followed by a facial age estimation check with an alternative route through a third-party verification provider that returns only a pass or fail. New sign-ups from Australian users go through the same check before an account is created. Government ID is one route but never the only one. Verification data is deleted on completion; the platform keeps a flag and a date. An appeal path lets a wrongly flagged adult re-verify. The team publishes a plain-language explanation and records the accuracy figures from its vendor and its own audits, so that it can show eSafety a working system rather than a policy.
How Landfall helps
Landfall holds the Australian Online Safety Act's obligations, including the minimum age duty, the age assurance constraints and the Basic Online Safety Expectations, as structured entries with their citations, and maps them onto a project once the questionnaire establishes an Australian audience and the social interaction features the definition turns on. The age assurance answers decide which items fire, and the same answers feed the UK and EU items, so the backlog shows one age assurance decision with three sets of citations. Regulatory events, such as a new eSafety assessment or a change to the rules, trigger re-evaluation of affected mappings. Browse the obligations in the Australia Online Safety Act explorer.