The internet asks for ID
The under-16 ban was the wedge: within roughly a year, every layer of the Australian internet asks adults to prove who they are, an age-assurance industry holds a legislated market, and the enforcement that justified it all has issued ze…
On 10 December 2025, Australia's minimum-age obligation for social media came into force. It was presented as one rule for one cohort: children under 16, kept off the platforms. The measure was popular then and it is popular now. Most Australians understood they were getting a ban on kids. What they were getting was a timetable.
Watch the calendar. On 27 December 2025, the search-engine industry code commenced. Since 27 June 2026, age assurance for logged-in Google and Bing users has been in force. Six further industry codes, registered on 9 September 2025, took effect on 9 March 2026, with app-store age-check obligations arriving from 9 September 2026. Apple has blocked unverified 18+ app downloads in Australia since 24 February 2026. And at the end of 2026 the Australian Government Digital ID System, AGDIS, starts taking applications from private business: accredited private providers can join from 30 November, the Finance Minister says; private businesses can apply from December, on the system's own website.
No agency publishes that sequence in one place. THE RORT has assembled it, each rung checked against the primary source, and read together it stops looking like child protection and starts looking like architecture. Within roughly a year of the ban commencing, every layer of the Australian internet, the platform, the search box, the app store, will have asked an adult to prove something about who they are. Here is the mechanism to watch, because it is the whole story.
01One ban became a timetable
Take the rungs one at a time, because that is how they were announced, and each on its own sounded modest. The under-16 obligation of 10 December 2025 applied to social media platforms. On 27 December 2025, an industry code for search engines commenced. It sounded technical because it is technical. Its consequence was not. Since 27 June 2026, if you are signed in to Google or Bing in Australia, the service has been obliged to apply age assurance to your account. Not your child's account. Yours. You did not join a social platform. You typed a query into a search box, and the search box needed a view about your age before it decided what you were allowed to see.
The wider stack was already moving. Six Phase 2 industry codes were registered on 9 September 2025, before the ban itself commenced, and took effect on 9 March 2026. Their app-store age-check obligations arrive from 9 September 2026. Apple did not wait for the deadline: since 24 February 2026, its developer notice confirms, unverified accounts in Australia have been blocked from downloading 18+ apps.
None of these rungs was hidden. Each was published, consulted on and brought into force in the ordinary way. The point is not secrecy. The point is that nobody presented the ladder, only the rungs, and a rung at a time is how a ladder gets built without anyone voting on the ladder.
02The wedge works because no decent person argues with it
The first mechanism is the child-safety wedge. To keep a person under 16 off a platform, the platform must form a view about the age of everyone who arrives. There is no version of an age gate for children that does not become an age check for adults, because the system cannot know who the children are without assessing everybody. The engineering makes the politics: once the check exists for the hardest case, extending it to search engines and app stores is a matter of scheduling. The timetable above is that schedule, executed.
A protection nobody can oppose normalises an ID check nobody voted on for everyone else.
To keep this honest: the ban itself is popular, and the harms to children online are real. This article disputes neither. Its target is the architecture built on top of the ban, the layers that turn a gate for children into an identity reflex for everyone, and the industry and enforcement apparatus that architecture sustains.
Two limits on the check are real and belong in any honest account of it. The penalties fall on platforms, not families: eSafety's guidance says 'There are no penalties for under-16s who access an age-restricted social media platform, or for their parents or carers.' And a platform cannot make government ID the only door. Section 63DB of the Online Safety Act bars a platform from collecting government ID, or using an accredited digital ID service, for age checks unless it 'provides alternative means' for a person to show they are not under age, and section 63F requires information collected for age assurance to be destroyed after it has been used. Those are the rules of the check. They are not a reason it is not a check.
Note also what this series keeps saying: a rort is a mechanism, not a villain. No official or company named in this article is accused of misconduct. Each acted inside its mandate. The regulator registered codes. The companies complied, some ahead of schedule. The wedge does not need a schemer. It only needs nobody to be responsible for the whole.
03A guaranteed market is the quietest subsidy
The second mechanism is the guaranteed market. Every legislated check needs a vendor to perform it, and a check mandated across platforms, search engines and app stores is a customer base handed over by law. Age-assurance providers did not have to win Australian adults as customers, one by one, on the merits of their product. Parliament and the codes delivered those customers in bulk, with compliance deadlines attached.
The market did not start from nothing. The Attorney-General's Department's report for 2024-25, the year before the ban, records that its Document Verification Service 'was used 133,140,077 times by the Commonwealth, state and territory governments, and the private sector.' Of the 2,228 entities using it, 2,109 were private businesses and 119 were government users. The Face Verification Service was used 2,492,804 times, by a single government agency. The Face Identification Service recorded no transactions. Verifying Australians' identity documents was already a private-sector habit, on government rails, before the first child was kept off a platform.
So it is worth asking how good the product is. The government ran its own Age Assurance Technology Trial, and the final report is plain about the ceiling. Even the best systems' facial age estimation averaged 1.3-1.5 years of error. Typical vendors averaged 2.4-2.7 years. At a threshold of 16 or 18, an error band measured in years is not a rounding issue. It decides who gets waved through and who does not.
“'some [systems] exhibited reduced accuracy for non-Caucasian users, older adults or female-presenting users near age thresholds'”
Age Assurance Technology Trial, final report · ageassurance.com.auPrecision cuts both ways, so be careful what you attribute to that report. Its Part D claims no substantial difference in accuracy for First Nations users, and the trial never analysed socioeconomic status at all. The demographic finding it did make is the one quoted above, and no more. This masthead does not improve on the record to make a point, and the point does not need improving: the law has mandated, at national scale, a technology whose own commissioning trial measured its errors in years.
04The penalty doubled before the first fine was issued
The third mechanism is enforcement theatre. The under-16 obligation has been in force since 10 December 2025. On 31 March 2026 eSafety named five platforms, Facebook, Instagram, Snapchat, TikTok and YouTube, and said it 'is continuing to gather evidence necessary to inform potential enforcement action.' Among the practices it listed was 'Enabling children aged under 16 to repeatedly attempt the same age assurance method to ultimately obtain a 16+ outcome.' Clayton Utz, in May 2026, reported that eSafety's compliance update drew on '23 legally enforceable information-gathering notices issued to 10 platforms, five of which are now the subject of active investigations into potential non-compliance.' As of 25 September 2026, THE RORT has found no report of a fine, infringement notice, enforceable undertaking or public Platform Provider Notification against any platform under the minimum-age law.
Then, on 28 June 2026, the Prime Minister announced the maximum would double, 'from $49.5 million to $99 million'. Parliament made it law. The Online Safety Amendment (Strengthening Enforcement for the Social Media Minimum Age) Act 2026, Act No. 83, received assent on 11 September and took effect on 12 September. It lifts the penalty for failing to keep under-16s off a platform from 30,000 to 60,000 penalty units, and a company can be ordered to pay five times that: 300,000 units. At $364, the value of a penalty unit since 1 July 2026, that is $109.2 million, on our calculation; the announced $99 million is the same 300,000 units at the old value of $330. Sit with that sequence. A maximum that doubles while the count of actual fines holds at zero is not deterrence being sharpened. It is justification being maintained. The unenforced number does the political work of seriousness, while the checks rolling out across search boxes and app stores do the practical work of normalisation.
Update, 25 September 2026. This article first reported the doubled penalty as a plan announced 'around 30 June 2026' at 'about A$99 million'. The announcement was made on 28 June 2026 and the increase is now law, in force from 12 September 2026. The higher ceiling applies only to conduct on or after that day. Anything the five named platforms did before it is measured against the old ceiling of 150,000 penalty units for a company: $49.5 million for conduct before 1 July 2026, and $54.6 million for conduct from 1 July to 11 September 2026, after the penalty unit rose from $330 to $364. The Act also lets the Commissioner demand information from anyone who holds it, not only platforms, which the government says includes 'third parties, such as age assurance or app-store providers', and lets eSafety examine a person on oath about a platform's compliance.
One precision the headlines routinely skip: a maximum is not a fine. The minimum-age penalty attaches directly to a platform's failure to take reasonable steps to keep under-16s off it; no prior direction is needed. But it is a ceiling a court may impose, not a sum anyone has been ordered to pay, and zero is a count for this law only. Under other parts of the Online Safety Act, eSafety has penalised platforms: Telegram received an infringement notice for $957,780 in February 2025, and on 21 May 2026 the Federal Court ordered X Corp, by consent, to pay $650,000 for not fully complying with a transparency notice about child sexual exploitation material. That notice was given to Twitter in February 2023. The judge said 'A penalty near the maximum is appropriate.' From notice to penalty took more than three years.
Correction, 25 September 2026. This article previously said the existing A$49.5 million code penalty attaches to breach of a direction to comply, not to the code breach itself. The A$49.5 million figure was the maximum for the under-16 obligation for conduct before 1 July 2026, and for that obligation the chain is wrong: the penalty in section 63D of the Online Safety Act attaches directly to a platform's failure to take reasonable steps, and eSafety lists civil penalties among its enforcement powers under that law without any direction step. The article also quoted eSafety as 'gathering evidence'; its words were that it 'is continuing to gather evidence necessary to inform potential enforcement action.'
05December 2026 closes the loop
The last date on the timetable is the one to sit with. At the end of 2026, AGDIS, the Australian Government Digital ID System, starts taking applications from private business, to join as a provider or as a relying party that asks you to prove who you are. The Finance Minister says 'from 30 November 2026'; the system's own website says 'from December 2026'. It arrives with scale already built: by the Minister's count in December 2025, there are '15 million myIDs', and verified transactions through AGDIS 'have more than tripled to reach 80 million'. Every rung before it built demand: platforms that must exclude under-16s, search engines that must assess logged-in users, app stores that must check ages from September. AGDIS supplies the other side of the market: the government's own way for private companies to have you prove who you are.
The Digital ID Act has its own safeguard for that moment, and its own gap. A business that joins the government system generally may not make a digital ID the only way to use its service. But the Digital ID Regulator may grant an exemption where the business 'provides services, or access to services, solely online', which describes every platform in this article. Until private businesses can join, the safeguard does not reach them at all.
Follow the sequence as a build order. September 2025, the codes are registered. December 2025, the ban lands and the search code commences. February 2026, Apple locks unverified 18+ downloads. March 2026, six codes take effect. June 2026, logged-in search users face age assurance. September 2026, the app stores, and a doubled penalty becomes law. November and December 2026, the government's own identity rails open to business applications. Demand first, supply last. That is not a conspiracy. It is a construction schedule, and it is on time.
So name the whole thing plainly. A protection nobody could oppose was the wedge. The wedge normalised checks that handed an age-assurance industry a legislated customer base, running technology whose own government trial measured error in years. And the enforcement that justified the entire structure has, on the public record to 25 September 2026, issued no fines under the ban, even as Parliament doubled its maximum penalty. Three mechanisms, one architecture, and no vote, at any point, on the architecture itself.
So when a service asks you to prove your age, or your identity, in the months after the end of 2026, remember the order of events, because the order is the story. The children were the reason. The adults were the market. And the fine that made it all sound like law enforcement has still, on the last verified count, never been issued.
If it's a rort, we cover it.
- eSafety Commissioner, search-engine industry code pages. esafety.gov.au. Supports the code's commencement (27 December 2025) and age assurance in force for logged-in Google and Bing users (since 27 June 2026).no link supplied
- eSafety Commissioner, Phase 2 industry codes fact sheet. esafety.gov.au. Supports the codes' registration (9 September 2025), commencement (9 March 2026) and app-store age-check obligations (from 9 September 2026).no link supplied
- Apple, developer notice (24 February 2026). developer.apple.com. Supports Apple blocking unverified 18+ app downloads in Australia from that date.no link supplied
- Minister for Finance, 'More than 15 million Australians choose simpler, safer Digital ID' (4 December 2025). https://ministers.finance.gov.au/financeminister/media-release/2025/12/04/more-15-million-australians-choose-simpler-safer-digital-id
- Digital ID System, 'The Australian Government Digital ID System (AGDIS)'. https://www.digitalidsystem.gov.au/the-australian-government-digital-id-system-agdis. Supports private-sector applications to the Digital ID Regulator from December 2026.
- eSafety Commissioner, social media age restrictions FAQs. https://www.esafety.gov.au/about-us/industry-regulation/social-media-age-restrictions/faqs. No penalties for under-16s or parents; reasonable alternative to government ID; $54.6m / 150,000 units.
- Online Safety Act 2021, compilation in force 12 September 2026. https://www.legislation.gov.au/C2021A00076/2026-09-12/2026-09-12/text/original/epub/OEBPS/document_1/document_1.html. ss63D, 63DB, 63F.
- Attorney-General's Department, Identity Verification Services Act 2023 Annual Report 2024-25 (3 March 2026). https://www.ag.gov.au/national-security/publications/identity-verification-services-act-2023-annual-report-2024-25
- Age Assurance Technology Trial, final report. ageassurance.com.au (also via infrastructure.gov.au). Supports the 1.3-1.5 and 2.4-2.7 year error figures, the verbatim demographic-accuracy finding, and Part D's claim of no substantial First Nations difference.no link supplied
- eSafety Commissioner, 'Five social media platforms flagged for compliance issues' (31 March 2026). https://www.esafety.gov.au/newsroom/media-releases/five-social-media-platforms-flagged-for-compliance-issues
- Clayton Utz, 'Social media minimum age restrictions: the net widens, enforcement begins and gaming platforms in the frame' (May 2026). https://www.claytonutz.com/insights/2026/may/social-media-minimum-age-restrictions-the-net-widens-enforcement-begins-and-gaming-platforms-in-the-frame. Supports no penalties imposed by May 2026 and the 23 notices to 10 platforms, five under active investigation.
- Prime Minister of Australia, 'Stronger powers and double penalties for world-leading social media law' (28 June 2026). https://www.pm.gov.au/media/stronger-powers-and-double-penalties-world-leading-social-media-law. Supports the announced increase from $49.5 million to $99 million and the third-party information power.
- Online Safety Amendment (Strengthening Enforcement for the Social Media Minimum Age) Act 2026, No. 83, as made. https://www.legislation.gov.au/C2026A00083/asmade/2026-09-11/text/original/pdf. Assent 11 Sep 2026, commencement 12 Sep 2026, 30,000 to 60,000 units in ss63D, 63DA(1), 63DB(1), conduct-date application rule, new s63G, examination on oath.
- Regulatory Powers (Standard Provisions) Act 2014, s82(5)(a). https://www.legislation.gov.au/C2014A00093/2024-03-20/2024-03-20/text/original/epub/OEBPS/document_1/document_1.html. Company cap five times the specified penalty.
- ASIC, 'Fines and penalties' (penalty unit values). https://www.asic.gov.au/about-asic/asic-investigations-and-enforcement/fines-and-penalties. $330 to 30 June 2026, $364 from 1 July 2026.
- eSafety Commissioner, Telegram infringement notice (February 2025). https://www.esafety.gov.au/newsroom/media-releases/australia-takes-enforcement-action-against-telegram-for-serious-delay-in-terror-and-child-sexual-abuse-transparency
- eSafety Commissioner, X Corp penalised after failing to fully comply with transparency notice (21 May 2026). https://www.esafety.gov.au/newsroom/media-releases/x-corp-penalised-after-failing-to-fully-comply-with-transparency-notice-about-child-sexual-exploitation-material
- Digital ID Act 2024, s74 and s61(d). https://www.legislation.gov.au/C2024A00025/2025-02-21/2025-02-21/text/original/epub/OEBPS/document_1/document_1.html