In the space of about a year, checking how old you are online has gone from a checkbox you clicked without thinking to a legal requirement backed by multimillion-dollar fines. On 10 December 2025, Australia switched on the world's first national ban on social media accounts for under-16s [source: eSafety Commissioner, 2025]. Five months earlier, on 25 July 2025, the United Kingdom began enforcing "highly effective age assurance" for adult and other high-risk content [source: Ofcom, 2025]. The European Commission has released a shared age-verification app blueprint [source: European Commission, 2025], and in the United States the Supreme Court has, for the first time in decades, upheld a state age-verification mandate [source: U.S. Supreme Court, 2025].
That is a remarkable amount of movement for something the internet spent thirty years avoiding. It is also a debate where it is easy to talk past one another, because two very different questions get blurred together: whether a law has passed, and whether it actually works; and whether protecting children justifies the privacy and free-expression costs of checking everyone's age. This article tries to keep those threads separate — what the new rules actually say, what the evidence shows so far, and how well the underlying technology really performs.
Here is what we will cover:
- A wall of new rules in barely a year
- Why "the law passed" is not the same as "the law works"
- The other side of the ledger: privacy, speech, and data
- Whether the technology can tell a 15-year-old from a 16-year-old
- What to watch next
A wall of new rules in barely a year
The striking thing about 2025–2026 is not that one country acted, but that several major jurisdictions moved at once — and chose noticeably different designs.
Australia: a world-first under-16 ban
Australia went furthest. Under the Online Safety Amendment (Social Media Minimum Age) Act 2024, "age-restricted social media platforms" must take "reasonable steps" to stop under-16s from creating or keeping accounts, effective 10 December 2025 [source: eSafety Commissioner, 2025]. The platforms named at launch include Facebook, Instagram, Threads, TikTok, Snapchat, Reddit, X, YouTube, Twitch and Kick [source: eSafety Commissioner, 2025]. Systemic non-compliance can draw penalties of up to AUD 50 million (about USD 33 million) [source: eSafety Commissioner, 2025].
Two design choices matter. First, the law does not fine children or their parents for getting around the ban — the obligation sits entirely on platforms [source: NPR, 2025]. Second, it explicitly forbids platforms from forcing users to hand over a government ID or an accredited digital ID as the only way to prove age; if ID is offered, a "reasonable alternative" must exist [source: eSafety Commissioner, 2026]. The regulator expects a layered "successive validation" or "waterfall" approach rather than either a single ID check or bare self-declaration [source: eSafety Commissioner, 2026].
The United Kingdom: "highly effective age assurance"
The UK took a content-based route. Since 25 July 2025, services hosting pornography or other content deemed harmful to children must apply "highly effective age assurance" under the Online Safety Act [source: Ofcom, 2025]. The regulator, Ofcom, does not mandate one method; instead it publishes a non-exhaustive list that can qualify — facial age estimation, photo-ID matching, open banking, mobile-network checks, credit-card checks and digital-identity services among them — and says any method must be technically accurate, robust, reliable and fair [source: Ofcom, 2025]. Ticking a self-declared "I am 18" box no longer counts. Penalties reach £18 million or 10% of global turnover, with court-ordered blocking as a backstop [source: Ofcom, 2025].
The European Union: a privacy-first blueprint
The EU's approach leans hardest on privacy engineering. On 14 July 2025 the European Commission released a white-label age-verification "blueprint" — sometimes called a mini-wallet — to support Article 28(1) of the Digital Services Act, which requires platforms accessible to minors to ensure a high level of privacy, safety and security [source: European Commission, 2025]. Its selling point is data minimisation: a user can prove they are over 18 without disclosing name, birth date or anything else, and the entity issuing that proof is not told which website it is used on [source: European Commission, 2025]. Built on the same specifications as the forthcoming EU Digital Identity Wallet, it is being piloted first by Denmark, France, Greece, Italy and Spain [source: European Commission, 2025].
The United States: the Supreme Court weighs in
The US shift came through the courts. On 27 June 2025, in Free Speech Coalition v. Paxton, the Supreme Court upheld a Texas law (H.B. 1181) requiring sites where more than a third of content is "sexual material harmful to minors" to verify visitors' ages, in a 6–3 ruling [source: U.S. Supreme Court, 2025]. Crucially, the majority applied intermediate rather than strict scrutiny — a lower constitutional bar that makes such laws easier to sustain, and a departure from earlier precedent [source: Congressional Research Service, 2025]. The dissent, written by Justice Kagan and joined by Justices Sotomayor and Jackson, argued the law is content-based and should face strict scrutiny, warning about burdens on adults' protected speech [source: U.S. Supreme Court, 2025]. Because more than twenty states have comparable laws, the decision reverberates well beyond Texas [source: Congressional Research Service, 2025].
"The law passed" is not the same as "the law works"
It is tempting to read this cluster of laws as proof that the problem is being solved. That is where care is needed. Passing a statute is a fact; reducing harm to children is a claim — and the two should not be collapsed.
On the evidence so far, the claim is unsettled. A group of researchers writing in a Frontiers journal in May 2026 argued that there is little direct evidence social-media age restrictions improve young people's wellbeing, and pointed out that not a single restriction experiment has actually included the under-16s these bans target [source: Frontiers, 2026]. Studies that do exist show weak and mixed effects, with a substantial share finding no benefit — or even harm, such as increased loneliness when connection is cut off. The authors' blunt summary: "we cannot ban our way out of a youth mental health crisis" [source: Frontiers, 2026].
Early real-world signals are similarly cautious. Analysts examining Australia's rollout reported that a large majority of children — one widely cited figure is around 85% — appeared to still be reaching restricted platforms shortly after the December 2025 ban, and found little sign that young users had actually stopped [source: The Conversation, 2026]. None of this proves the laws are useless; enforcement is young, and behaviour may shift. But it does mean that "millions of accounts removed" — Australian platforms restricted access to roughly 4.7 million under-16 accounts in the first weeks [source: eSafety Commissioner, 2026] — measures activity, not outcomes. An account removed is not the same as a child made safer or a harm avoided, and honest assessment has to keep those apart.
None of this settles the underlying worry that motivates the laws. Parents' concern about social media's effect on sleep, attention and mental health is real and widely shared, and public support for action is rising, as the next section shows. The point is narrower: a law taking effect is the beginning of the evidence, not the end of it.
The other side of the ledger: privacy, speech, and data
Support for doing something is broad. In a Pew Research Center survey of 9,750 US adults conducted 26 May–1 June 2026, 56% backed banning under-16s from social media outright; 85% supported requiring parental consent for minors (up from 81% in 2023), and 78% supported age verification before using platforms (up from 71%) [source: Pew Research Center, 2026]. That is a genuine popular mandate, and it is why this debate is not a fringe concern.
But verifying everyone's age has costs that fall on adults and children alike, and civil-liberties groups argue they are being undercounted. The Electronic Frontier Foundation puts it bluntly: "every age-verification system is, at its core, a surveillance system," because a mechanism that confirms who is old enough can also become a mechanism that records who visited what [source: Electronic Frontier Foundation, 2025]. Anonymous reading and speech — long protected precisely because they let people seek information without being watched — become harder when a gate demands proof of identity first.
The data-security risk is not hypothetical. A breach tied to an age-verification process exposed roughly 70,000 government-ID images, part of a much larger trove of stolen data [source: Electronic Frontier Foundation, 2026]. The logic is uncomfortable but simple: the more sensitive identity data a service is required to collect, the larger and more attractive the target it becomes. This is exactly why the EU blueprint's data-minimising design — prove-your-age-only — and Australia's ban on mandatory government ID are notable; they are attempts to get the safety benefit without building a honeypot. Whether every implementation lives up to that standard is the open question.
There is also the free-expression dimension the Paxton dissent flagged: age gates on lawful-for-adults content can chill adults from accessing it at all. The fair way to hold these positions together is to accept that both are real — the child-protection interest and the privacy-and-speech cost — and to judge each system by how well it minimises the second while delivering the first, rather than pretending either side is imaginary.
Can the technology tell a 15-year-old from a 16-year-old?
Underneath the policy sits an engineering question that often gets waved away: how accurately can a system actually estimate someone's age? Here, marketing claims and measured performance diverge, so it helps to look at independent testing rather than vendor brochures.
The US National Institute of Standards and Technology (NIST) runs an ongoing benchmark, the Face Analysis Technology Evaluation (FATE), for age estimation and verification [source: NIST, 2026]. The results are improving, but they come with an important caveat for this debate: NIST flags mean-absolute-error above roughly 3.5 years as a level warranting attention, and even leading algorithms carry error margins of a few years that widen near the threshold ages and differ across demographic groups by region and sex [source: NIST, 2026]. An error band of a couple of years is minor when you are guessing whether someone is 8 or 40; it is decisive when the legal line is exactly 16 or 18. That is precisely where these laws draw it.
The practical consequences run both ways. A margin of error means some under-age users are waved through (false accepts) while some adults are wrongly blocked (false rejects) — which is why regulators such as Ofcom and Australia's eSafety push layered "waterfall" checks rather than trusting any single method [source: eSafety Commissioner, 2026]. And then there is deliberate circumvention. Within hours of the UK's July 2025 rules taking effect, the privacy company Proton reported a surge of more than 1,400% in UK VPN sign-ups, as users adopted tools that make them appear to browse from another country [source: Proton, 2025]. A VPN does not defeat age estimation directly, but it sidesteps geographically scoped rules entirely — a reminder that a check strong on paper can be routed around in practice.
None of this means age assurance is worthless; a well-designed layered system raises friction meaningfully. It means the honest framing is probabilistic: these tools shift the odds, they do not draw a clean line at a birthday, and any policy that assumes otherwise will over-promise.
What to watch
The next two years should turn a lot of theory into data. A few things are worth tracking:
- Outcomes, not account counts. Watch for independent, longitudinal studies that measure youth wellbeing and actual access — not just how many accounts platforms removed. Australia's monthly reporting to eSafety is an early test case.
- Whether privacy-preserving designs win. The EU mini-wallet and Australia's no-mandatory-ID rule are bets that you can verify age without hoarding identity data. If breaches keep happening at services that took the easier, data-heavy path, expect pressure to standardise on data-minimising methods.
- Where the legal line settles in the US. After Paxton, the fight moves to how far intermediate scrutiny stretches — whether it stays confined to adult content or is extended to general social media, and how lower courts handle the twenty-plus state laws already on the books.
- Circumvention as a metric. VPN adoption, age-estimation false-accept rates, and the persistence of underage use are all measurable. If they stay high, "the law passed" and "the law works" will remain two different sentences.
The direction of travel is clear: checking age online is becoming a default expectation rather than an exception, across democracies that rarely regulate the internet in lockstep. What is not yet clear is whether this generation of rules will protect children meaningfully, at a privacy and speech cost societies decide is acceptable — or whether it will mostly move the problem around. Keeping the facts, the effectiveness evidence and the trade-offs in separate columns is the only way to tell which.