On 30 June 2026, Australian Prime Minister Anthony Albanese stood up to claim a win and announce a crackdown in the same breath. The country’s world-first ban on social media accounts for under-16s had, he said, led to the deletion of more than five million accounts. In the next sentence he conceded the problem: “big tech are not doing enough to comply with the law and there are still too many children on social media.” So the government would double the fines and hand the regulator “world leading powers to compel them to comply.”
Read those two claims together and you have the whole story of the ban’s first seven months. Five million accounts deleted is a real number. It is also the wrong number to celebrate, because it measures the wrong thing. Deleting the account of a child you already identified is not the same as stopping the next child from making one. And on that second measure — the one that actually determines whether under-16s can get onto a platform — Australia’s ban has been quietly failing since the day it took effect.
“Not once have we been asked to verify our age”
The most damaging finding did not come from an activist group or a platform lobbyist. It came from the firm the government hired to test its own scheme.
After the law took effect on 10 December 2025, KJR — the testing firm that ran Australia’s original age-assurance technology trial in 2025 — opened 50 fresh accounts across nine of the ten age-restricted platforms, including Instagram, Snapchat, TikTok and YouTube. Each time, the tester declared an age of 16. Not once were they asked to prove it. Only one service — the Australian live-streaming platform Kick — refused to create an account without proof of age; a Kick spokesperson said age inference was not workable for a newer platform that lacked the data to estimate ages reliably.
“You should be asked to demonstrate how old you are,” KJR director Andrew Hammond told reporters, “and not once have we been asked to verify our age or use age-assurance measures.” A ban whose entire premise is a minimum age had, in field testing, no functioning check at the front door of nine of the ten services it governs.
This is the failure that account-deletion statistics are engineered to hide. A platform can dutifully remove five million accounts it has already flagged as under-16 — through behavioural signals, reports, or a birthday on file — and simultaneously wave through every new sign-up that types “16” into a box. The first action generates a headline. The second is the one that decides whether the ban works.
What five million deletions actually measured
Strip the number down and it describes a cleanup, not a gate.
eSafety’s own first compliance report, published in March 2026 and built on 23 legally enforceable information-gathering notices to the ten platforms, put a sharper figure on it. In a parent survey, 49.7% of children were reported to have had their own account on at least one platform before the restrictions; after implementation, that fell to 31.3%. A meaningful drop — but nearly a third of children still had accounts, three months into a “ban.”
The independent research is bleaker still. A study published in The BMJ by researchers at the University of Newcastle surveyed 408 adolescents aged 12 to 17 shortly before and three months after the restrictions began. More than 85% of the under-16s were still using social media. Most of them were not sneaking in on a sibling’s login; they remained active through their own accounts. About two-thirds said they had encountered a platform age-verification check — and that the check was usually a self-declaration of age or “an acceptable selfie.”
Put the three data points in a row and the mechanism is obvious. Accounts get deleted. New ones get created just as fast, because the “check” a teenager meets is a checkbox or a soft selfie estimate they can retry until it passes. The deletion sweep and the sign-up funnel are two different doors, and the ban only ever locked the first one.
Self-declaration and passive inference are the failure mode
Nothing in the Australian numbers is surprising if you have watched the same methods fail everywhere else. The two “checks” the BMJ subjects encountered — a self-declared age and a lenient selfie estimate — are precisely the two approaches that produce a green tick without producing assurance.
Self-declaration is the one the regulators have already ruled on. When the UK’s ICO fined Reddit £14.47M, the finding was not that Reddit lacked a check but that it over-relied on users stating their own age while collecting children’s data anyway. Asking an age is not assuring it. Australia’s field data is the same conclusion arriving through a different door: a self-declaration prompt in front of a determined 14-year-old is decorative.
Passive age estimation fails for a subtler reason: it is only as strong as its weakest retry. eSafety’s April update flagged that platforms were letting minors repeatedly retry age-assurance and failing to stop under-16 account creation. We have written before about the retry loophole that quietly defeats age estimation: a single facial-age model with a borderline threshold and unlimited attempts is a slot machine, and the user pulls the lever until the estimate lands over 16. An “acceptable selfie” that can be re-shot ten times is not a control; it is a delay measured in seconds.
The deeper problem is that both methods verify a moment rather than a person. Even a strong check at sign-up means little if the result is never bound to the account that keeps using the service — the binding problem that separates verifying an event from verifying the human behind subsequent logins.
The enforcement pivot: from “did you remove accounts?” to “do you check the door?”
The regulator has clearly read its own data the same way. eSafety Commissioner Julie Inman Grant has been careful to describe the regime not as an outright ban but as a delay to having accounts, with platforms — not children or parents — bearing responsibility to take reasonable steps. In March she moved the office from compliance monitoring to an enforcement stance, and five platforms — Facebook, Instagram, Snapchat, TikTok and YouTube — are now the subject of active investigations into potential non-compliance, each systemic failure carrying penalties of up to AUD 49.5 million.
That is the pivot every operator should notice. Year one of any age-assurance regime grades adoption and cleanup: did you remove the accounts you could identify? Year two grades the thing that actually matters: can you show the front door keeps the right users out? It is the same shift the UK is making as Ofcom moves from “did you deploy a gate?” to can you prove it works. Deletion counts are becoming a vanity metric; the real question is your sign-up funnel’s pass rate against under-age testers.
What the strengthening bill changes — and who it drags into scope
Albanese’s 30 June package is designed to close exactly the gap the KJR test exposed. Three moves matter for anyone building in this space.
First, the penalties roughly double, from AUD 49.5M to a reported AUD 99M per systemic breach, with the eSafety Commissioner given stronger powers to compel compliance. Second, and more consequential structurally, those powers are being extended beyond the platforms to reach app stores and age-assurance providers themselves — the government is pulling the whole verification supply chain into the accountability perimeter, not just the consumer-facing app. Third, the monthly reporting of removed under-age accounts stays, but it is no longer the finish line; it is baseline hygiene alongside a demand to show the check actually functions.
Two live pressures sit on top. Reddit is challenging the law in the High Court as overbroad and an infringement of privacy and free expression, arguing it is not a traditional social network — a reminder that a maximalist “ban everyone under 16” framing invites constitutional attack in a way a proportionate, data-minimising age check does not. And the model is spreading regardless: Malaysia’s Child Protection Code already runs an eKYC-first under-16 regime, and the UK’s government has signalled its own under-16 restrictions for spring 2027, promising to go further than Australia. The operators who treat Australia as a preview rather than a one-off will not be rebuilding this twice.
The transferable lesson: verify at the door, not in the cleanup
The Australian result is not an argument against age assurance. It is an argument against confusing account deletion with age assurance — and it generalises well beyond one country’s law. Four principles fall directly out of the data:
Verification belongs at account creation, not in a monthly sweep. A deletion pipeline that removes flagged accounts while the sign-up form accepts a typed “16” is a locked back door next to an open front one. The control that counts is the one a new user meets before the account exists.
The method has to match the risk, and it has to survive retries. A self-declaration checkbox clears no bar the regulators still recognise. A single facial-age estimate with an unlimited retry counter clears almost as little. Effective assurance layers methods — document and NFC-chip checks, liveness, and age estimation with a budgeted, rate-limited retry policy — so that no single soft signal is the whole gate.
The result has to bind to the account. Verifying a face at sign-up is pointless if the pass is never tied to the identity that logs in tomorrow. Binding the outcome to the session is what turns a one-time check into an ongoing property of the account.
And you have to keep the evidence without hoarding the identity. The Reddit and Newcastle findings both point the same way: regulators now want proof the check works, not proof you collected everyone’s ID. A privacy-first architecture that stores the assurance decision and its audit trail — while discarding the underlying document — satisfies the safety regulator and the data-protection regulator at once, exactly the dual standard Australia’s strengthened regime now expects.
How Xident fits
Xident was built for the door, not the cleanup. Age is classified at the point of account creation with a layered flow — client- and server-side liveness, document and face match, and age-threshold estimation — rather than a single soft signal a user can retry into a pass. Retry abuse is budgeted and rate-limited by design, so “roll until you pass” stops being a strategy. Verified results are bound to the user and reusable through a token, so the assurance is a persistent property of the account instead of a moment that expires the instant the page reloads. And the architecture keeps the decision and its audit evidence while minimising the identity data behind it — the posture Australia’s own regulator, and the ICO before it, has made the price of admission. If you operate in Australia specifically, our guide on meeting the eSafety “reasonable steps” standard walks through the waterfall in detail.
Five million deleted accounts made a good press conference. The number that will decide year two is quieter: of the next hundred under-16s who try to sign up, how many get in? Australia has spent seven months proving that if the answer is “most of them,” no amount of deletion afterward makes the ban work.
Building age assurance that holds up at the door — and under a regulator’s audit? Talk to Xident about verification that checks before the account exists, not after.