This week’s Senate committee hearing into the social media minimum age ban confirmed what AVPA documented in our Lessons Learned report published in April: the platforms are not using the wide range of age assurance options they could adopt. So this news of a gap between capability and deployment is not new. But the Senate hearing provided remarkably consistent testimony that makes it undeniable.
The claim: “We’re doing our best”
When asked by Senators directly about their approach to age verification, the platforms described these current practices:
- Meta: “We have an age-neutral gate where you have to input your date of birth,” but acknowledge they rely on stated age plus behavioral inference and post-hoc account monitoring. They are “working on” the Apple API but have not deployed it, claiming the signal is “weaker than stated age.”
- Google: “When you try to create an account on YouTube, you get asked to input your date of birth.” They use stated age and age inference models, but no universal verification requirement. They have not implemented universal deployment of available verification tools.
- TikTok: An “age-neutral gate” where users declare their age. They use behavioral monitoring (profile pictures, engagement patterns, messages like “happy 15th birthday”) to flag potential underage users after account creation. No upfront verification requirement.
- Snap: Uses facial age estimation as one option, plus Connect ID (bank verification) and AgeKeys (which allows the use of government ID). But these are options, not universal requirements.
The pattern is consistent: self-attestation on account creation, followed by post-hoc monitoring and removal. None of these platforms has implemented a requirement for age assurance as a condition of account access, or even just to open a new account. No platform has universally deployed the verification tools they acknowledge exist. Nor could they offer any evaluation of how effective their process is – only offering the numerator of the equation, how many accounts they have closed, while claiming ignorance of the denominator, now many under 16s remain on their platform. Perhaps a figure they decided early on should never be discoverable anywhere on their systems – dont’ ask, can’t tell.
The obvious failure:
The Age Assurance Technology Trial tested a range of age assurance methods across different approaches and technologies. Facial age estimation is one option, and as AVPA has repeatedly advised since even before the trial began, suitable only for older users after applying an appropriate buffer thresholds – usually 2-3 years. The AATT examined multiple other methods, which are then able to distinguish a 15-year-old from a 16-year-old.
A proportionate, “waterfall” approach, as clearly recommended by the trial is technically and economically feasible. One example of how to apply this would be:
- Account age and data inference first (e.g. metadata linked to an email address or mobile number the user proves they can access). This catches the majority with no more friction than a standard two-factor authentication.
- Age assurance methods appropriate to the user (hand movement, voice or facial estimation with buffer for some. Most users experience minimal inconvenience; a single extra step perhaps once a year. This approach limits cost and user friction while capturing the bulk of non-compliant accounts.
- Specific age verification (physical or digital ID, bank or school records, or if all else fails, professional attestation) only for those who fail prior steps. A small final cohort where proof is needed.
This is not demanding the impossible. It is pragmatic, cost-effective, and proportionate. It limits both inconvenience to legitimate users and implementation costs to platforms. Yet none of these four major platforms has implemented it.
The refusal to comply in good faith
The Senate heard remarkably consistent explanations from the platforms: the 16 age boundary is novel and complex; detection is therefore extraordinarily difficult; they are doing what they can with post-hoc monitoring, reacting to reports and continued account removal.
But they offered no explanation for why they have not implemented available age assurance systems, at least as a condition of account creation where there is no user data record to analyse, by definition.
The platforms’ own testimony, when examined carefully, shows a consistent pattern: knowing what could be done, choosing not to do it. Or at least quite evidently not doing what they could to deliver the policy effectively, despite having the tools, the capability, and the resources to do so.
The regulator cannot enforce what she cannot prove
The eSafety Commissioner’s frustration is evident in her request for expanded investigatory powers. “To establish a breach,” she explained, “we must demonstrate that the platform failed to take reasonable steps to prevent underage users from having accounts. This will require eSafety to provide evidence in court likely found in internal documents such as policies, technical documentation of capabilities, strategic deployment decisions, and compliance records.”
Without access to these documents, the Commissioner stated plainly: “eSafety cannot obtain these documents, which are vital to making our cases.”
The judgment against Meta in New Mexico succeeded because “the smoking guns were found in the company’s own emails, research, planning, and strategy documents.” The case was not won by notice-based responses (the Commissioner’s current tool). It was won by exposing what internal documents revealed about the company’s actual choices.
Australia is not yet the place to look for insights into social media age restrictions
There is a legitimate debate to be had about whether social media should be age-restricted for under-16s. The AVPA takes no position on that question – it is a matter for elected politicians to decide. However, the evidence presented to the Senate does not yet allow that debate to be informed meaningfully by Australia’s experiment.
The outcome so far (80% of under-16s can still access social media) cannot tell us whether the policy itself is sound or flawed. It tells us only that the policy has not yet been substantively implemented. What we are measuring is not the effectiveness of the age restriction policy. We are measuring only the ineffectiveness of self-attestation plus ineffective account monitoring. If you want to learn if reducing access to social media makes children happier or more vulnerable, you will not yet find the answer from Australia.
The eSafety Commissioner remains sanguine, citing historical precedent: “When the U.S. mandated seatbelts, compliance was reportedly around 15%… A profound change in behavior does not happen overnight.” She cited Victorian seatbelt laws: “It took 19 years for driver wearing rates to reach 95%.”
Australia cannot yet contribute useful evidence to the global policy debate because most Australian social media platforms have not yet tried the policy in good faith. That is the opportunity cost of the current situation.
The global impact
Other jurisdictions are watching Australia closely. But they are asking two questions: not only is an age restriction beneficial but also, how does one regulate it effectively?
The eSafety Commissioner offered the platforms genuine latitude without stringent minimum accuracy levels, tested and certified against international standards. But whatever local management may have preferred, global strategic imperatives appear to have overridden them. Even the new $99m AUD maximum penalty will not shift valuations the way a successful Australian case study inspiring other countries would threaten them materially.
That latitude will not be replicated elsewhere. As other countries implement their own age restrictions (and many are still following Australia’s lead), they will point to the Australian implementation and ask: if self-attestation plus post-hoc monitoring does not work, why did regulators accept it? If the platforms had the capability to deploy age assurance systems, why did regulators not require them?
Australia’s social media platforms missed an opportunity to set a precedent for how age restrictions can be regulated pragmatically with both effectiveness and reasonable accommodation. Other jurisdictions will now be considerably less forgiving. They will be less willing to accept explanations about difficulty, and offer some margin for error and more insistent on requirements about deployment. We’ve already seen the state of New York draw a very clear line – no more than 15% of 15 year olds should wrongly pass the test. The regulatory window that exists, for now, in Australia will close elsewhere, tighter and less flexible.
The Choice Before Platforms
The Senate hearing made clear that platforms have a choice: deploy age assurance systems proportionately and pragmatically, or face expanded regulatory powers and enforcement action based on internal documents exposing their design decisions. We always advise regulated to sectors to take the initiative, shape the solution and not wait for regulators to impose what will almost always be far more difficult and often less well designed requirements. We did so in Australia and had a sympathetic response from senior management at many platfoms on the ground – but it appears Sydney was not calling the shots.
The evidence suggests they know how to make accounts safer. The question is not capability. The question is will.

Author: Iain Corby, Executive Director