Join our Newsletter — 33% off our NHI Course

Australia’s under-1...
 
Notifications
Clear all

Australia’s under-16 social media law: what identity teams should take away


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18004
Topic starter  

TL;DR: Australia’s under-16 social media law replaces self-declared age with layered age assurance and has already driven platforms to remove 4.7 million under-16 accounts, according to AU10TIX. The shift matters because age verification is now a governance problem, not just a checkout step, and it will shape identity verification, privacy controls, and platform accountability.

NHIMG editorial — based on content published by AU10TIX: Australia’s social media minimum age law and what it means for age verification

Questions worth separating out

Q: How should identity teams implement interoperable age assurance without over-collecting data?

A: Start by separating the age claim from the underlying identity proof.

Q: Why do user-declared attributes fail as a governance control for age checks?

A: Because a user-declared attribute is not an independent proof of eligibility.

Q: What breaks when age verification is treated as a one-time control?

A: A one-time control assumes the trust decision persists.

Practitioner guidance

  • Replace standalone self-declaration with layered age assurance Use at least two methods in sequence so that a low-confidence result triggers escalation rather than acceptance.
  • Build a fallback path that does not require government ID alone Offer a non-ID route that still allows the platform to make a reasonable decision, because the law does not allow government-issued ID to be the only option.
  • Review existing accounts as part of the lifecycle Do not limit controls to new signups.

What's in the full article

AU10TIX's full article covers the operational detail this post intentionally leaves for the source:

  • The specific age assurance methods and how AU10TIX maps them to social platform workflows.
  • The legal and regulatory nuances behind reasonable steps, privacy obligations, and co-regulation.
  • The practical differences between Australia’s model and the UK and EU approaches.
  • The provider implications for identity verification vendors serving regulated platforms.

👉 Read AU10TIX’s analysis of Australia’s under-16 social media age law →

Australia’s under-16 social media law: what identity teams should take away?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 17593
 

Age assurance has become an identity governance problem, not a content policy problem. Australia’s law shows that the real control question is whether a platform can prove who is eligible to hold an account, not whether it can publish a rule. That distinction matters to identity teams because the enforcement burden sits on the assurance workflow, the evidence trail, and the lifecycle of the account. The practical conclusion is that eligibility checks now belong in governance design, not in product copy.

A question worth separating out:

Q: Who is accountable when age assurance decisions are challenged by regulators?

A: Accountability sits with the organisation that deploys the control, not with the model or the supplier alone. Legal, product, security and compliance teams should share ownership of the evidence set, because regulators judge the decision process as well as the outcome.

👉 Read our full editorial: Australia’s age assurance law shows why self-declaration fails



   
ReplyQuote
Share: