The regulators responsible for enforcing Australia’s under-16 social media ban have argued they lack the legal power to do so as a flood of submissions to a Senate inquiry push for stronger discovery powers, while opponents warn such powers risk entrenching government overreach.
Consultation on the Online Safety Amendment (Strengthening Enforcement for the Social Media Minimum Age) Bill 2026 – which Prime Minister Anthony Albanese introduced in June – addressed shortcomings in the social media minimum age (SMMA) rules that took effect in December.
Despite early reports that around 5 million social media accounts had been affected by the ban, data from the eSafety Commissioner suggest many social media giants were making minimal efforts to comply, leading several to be closely investigated.
No company has yet been fined for breaches – with eSafety Commissioner Julie Inman Grant recently explaining that regulators “have not yet reached a final determination on whether platforms are taking reasonable steps” because they can’t gather the necessary evidence.
“Unfortunately,” she told a recent Senate hearing, “we do not have a fine-issuing button; rather, systemic non-compliance needs to be proven in court with solid evidence and complex legal proceedings.”
eSafety’s submission clarified the issue, noting Inman Grant’s powers to gather evidence are “significantly limited” because she can’t access internal documents or demand information or documents from third parties such as age assurance providers.
“Currently, having no ability to compel the production of documents, the Commissioner, in assessing whether ‘reasonable steps’ have been taken [to verify users’ ages], must rely on representations from providers about their own compliance with the SMMA obligation.”
“Without access to primary documents relevant to compliance with the SMMA obligation,” the submission continues, “the Commissioner would likely be unable to discharge the onus of proof required in any civil penalty proceeding bought to the courts.”
Big Tech finding its way towards compliance
Instead of accessing helpful internal documents, eSafety has had to rely on saccharine descriptions of a spectrum of compliance efforts.
“It is clear to me that social media platforms are adopting tricks straight out of the Big Tech playbook and doing the bare minimum to get by,” Minister for Communications Anika Wells said in alleging Big Tech is “doing the bare minimum and thinking they are above domestic law.”
TikTok, for one, feted a “multi-layered approach to age assurance” simply asks users to enter their birthdate – then uses AI and human moderators to monitor online activities for “signals… that the account owner may not meet the minimum age requirements.”
Age assurance methods are only available when monitoring leads to an account being suspended – in which case users can appeal using facial age estimation from Yoti, or verification using a credit card or government ID.
YouTube, for its part, said parent company Google “has significantly invested in product development in response to the SMMA” – with its systems already searching for users under 13 by analysing uploaded videos for voice tones and physical cues such as size.
Those systems have been adapted to detect under-16s for SMMA compliance – for example, by enabling users to verify their age with a government ID or selfie – but this had proved “novel and complex” because “clear signals about a user” are “more challenging at this age gate.”
X, by contrast, spent no time explaining its age verification services but raged against the reforms – which, it said, “should be abandoned entirely” and the burden of age verification shifted to operating system providers, app stores, and device manufacturers.
Legal professional privilege, X said, exempts providers from what it called “highly invasive powers of compulsion against a particular online service” that, it argues, would let eSafety “issue a notice to anyone… to hand over information and documents that show whether there is compliance.”
More powers needed all around?
Other submissions confirm there are still wide views about how the SMMA rules should operate – with the conservative Institute of Public Affairs (IPA) warning the new powers would amplify the government’s “aggressive enforcement posture”.
Those powers, it said, would let eSafety “trawl through documents for anything that might be interpreted as failing to take reasonable steps to comply…. regulated entities will also likely be obliged to document their operations more thoroughly, capturing more information about users.”
Other regulators believe not only that eSafety should be empowered to investigate SMMA breaches, but that it should also play an expanded role in the scheme going forward.
Some families, the Telecommunications Industry Ombudsman (TIO) reported, have had trouble restoring access where digital platforms “have incorrectly blocked accounts under the SMMA laws” – leading it to advocate for an SMMA ombudsman scheme to resolve disputes.
The Office of the Australian Information Commissioner (OAIC) “is currently assessing a modest number of privacy complaints relating to the SMMA obligation,” it confirmed in flagging a “lack of transparency regarding the technical implementation of age assurance obligations.”
And the OAIC currently lacks an “assessments power to determine whether entities are compliant with their privacy obligations,” that agency said in arguing for new powers including stronger information gathering and the ability to conduct “privacy sweeps specific to the SMMA”.
Even as providers argue over semantics, “unequivocally opposed” free speech advocates continue to push back, while others called for better analysis of the restrictions’ effectiveness – and children’s advocates just want to see real improvements.
Six months into the SMMA regime, Wells said, “I am not satisfied that tech companies are doing everything they can to keep under-16s off their platforms…. We will not back down [and] we are doubling down on our efforts to hold Big Tech to account.”