There are policies that are designed to be seen rather than to work, and the under-16 social media bans now rolled out in Australia and soon in the UK, are starting to look like the purest examples of the genre. Both governments have reached for the same instrument and sold the same promise; that the state can build walls to prevent social media platforms from harming under-16s. In both cases the wall has an entrance gate, but the gate has no lock and everyone involved appears to have known this from the beginning.
I want to be careful about the charge I am making, because it is easy to overstate. The complaint is not that these laws target the wrong platforms out of some political bias (a claim doing the rounds at the moment). My criticism is narrower: that both regimes select what they cover by size and feature-type rather than by any coherent principle, both build circumvention markets into their own design and focus on enforcement that’s reactive, discretionary and quite trivially gamed. The Australian experiment is now six-months old and we can see the results, yet the UK version, announced on 15 June, chose to ignore them.
The Australian evidence is not good
Australia switched on its ban on 10 December 2025, the first country in the world to bar under-16s from holding social media accounts. The covered list is ten platforms; Facebook, Instagram, Threads, Snapchat, YouTube, TikTok, X, Reddit, Twitch and Kick, with messaging apps, gaming services and education and health tools exempted. These big ten face fines of up to A$50m/£26.5m for failing to take “reasonable steps” to keep under 16s off them.
Six months on, Australia’s eSafety Commission’s own findings undercut the entire scheme with a recent report which states that roughly 70% of under-16s are still using the banned platforms, a figure supported by independent surveys, including a Molly Rose Foundation study of 12-to-15-year-olds in which more than 60% of those who held accounts before the ban still had access to at least one account. Similarly, parental-control data analysed by media outlet Crikey, showed under-16 social media usage falling only marginally across the first three months. Whatever the ban has achieved, it has not removed children from these platforms in the numbers its architects, lobbyists and politicians promised.
The how matters more than the headline. When eSafety Australia opened formal investigations into Facebook, Instagram, TikTok, Snapchat and YouTube, it found platforms had let children who declared an age below 16 simply repeat the age check until they passed. That isn’t authentication, it’s a compliance joke akin to the old US military position on gay service people of, ‘don;’t ask, don’t tell’. Alongside this sits a familiar toolkit of workarounds; borrowing a parent or friends’s face for the biometric scan and using VPNs to spoof location. The Australian Communications Minister, when asked about the parent’s-face problem, offered the remarkable reassurance that scanning an older person’s face to defeat the check “will not work forever” thereby confirming it works right now!
I would add two caveats here, firstly the much-touted cheap 3D masks available from sites like Temu won’t defeat the current generation of facial recognition systems used by major platforms. Similarly the use of VPNs is contested. In the UK, when verification for adult/porn sites started, VPN use jumped by between 1000% (Nord) and 1400% (Proton) immediately pushing these to the top of app download charts. When a similar legal regime came into force in March 2026 in Australia, the results were the same. For social media Australia’s eSafety Commissioner, Julie Inman-Grant, claimed that VPNs aren’t impacting access by under-16s to social media because, “the costs are in the thousands of dollars”. While contested, in the real word outside parliaments, thinktanks and quangos, any kid can buy a VPN for less than $4/£2 per month. To access the Mulvad VPN,a kid doesn’t need a bank account or crypto currency, they can pay with good old cash for complete online anonymity. It’s worth noting the UK is now debating age verification for VPNs. Good luck putting that cat back in the bag.
A list that grows by reaction, not principle
The deeper issue with these bans is conceptual. Neither regime can tell you, in advance and on principle, what counts as a banned platform. Australia’s list “reflects eSafety’s views” as at particular dates and is explicitly subject to change as services emerge or evolve. Several platforms like Bluesky, Wizz, Lemon8, BigoLive ended up on the list not through any legislative requirement, but by notifying the regulator themselves that they ‘probably qualified’. That’s governance by self-declaration and ministerial reassessment, which is about as reactive and weak as any regulation gets.
It also disposes of the politically convenient myth that these bans spare progressive platforms and punish the right. Bluesky, the network most often cited as the archetypal exempt left-leaning space, is squarely inside the Australian regime, having adopted a minimum user age of 16 in November 2025. In Britain, Ofcom’s existing Online Safety Act enforcement has already stretched to Reddit, X, Discord and Bluesky. There doesn’t seem to be any overt political viewpoint filter here, there is a bigness-and-features filter, and it catches whatever is large and social, regardless of which way its users or owners lean politically.
Britain decides to repeat the experiment
Which brings us to 15 June, when Sir Keir Starmer announced that the UK will ban under-16s from TikTok, Instagram, YouTube, Snapchat, Facebook and X, with legislation due before the end of 2026 and enforcement expected in spring 2027. Britain says it will go further than Australia with nightly curfews for older teens, restrictions on companion AI chatbots, limits on infinite scrolling. The model, though, is explicitly Australian, complete with the same messaging and gaming exemptions, For example, WhatsApp, Signal,YouTube Kids and many more will sit outside the ban.
The UK government had Australia’s results in hand when it wrote its own legislation, with the eSafety compliance report and the various surveys all in the public domain. Britain looked at a live demonstration of the mechanism failing and chose to install the same structure, based on the same logic, with the same type of enforcement architecture. Isn’t the definition of madness; doing the same thing and expecting different results?
The workaround Britain is building on purpose
Here is where the UK version becomes more troubling. To enforce an under-16 ban you must age-check users at sign-up. In practice that means anyone opening a new account proves they are over 16 by uploading ID or passing a facial-age scan, the same checks adult/porn sites have run since July 2025. Crucially, long-standing, pre-existing accounts are largely grandfathered; it is fresh signups that trigger verification. The UK is, in effect, ending anonymous account creation for all adults, while leaving every existing adult/porn account untouched.
Think through the incentives that creates. If an established, already-verified account is worth more than a new one, and if there is no apparent cap on how many accounts a verified adult may hold across most platforms, then the predictable result is a market in lent and/or sold credentials, i.e. adults selling or renting their verified status to the under-16s the law is meant to exclude. This is not speculation about some distant potential failure, it’s the Australian experience, with the law manufacturing the very black market that defeats it.
And it does something else, which critics across the political spectrum have been quick to name. By requiring the bulk of the adult population to prove identity to use everyday platforms, the ban delivers, through the back-door, the very thing Britain rejected when it was proposed through the front door; a de-facto digital identity layer for the internet (Sir Kier’s government tried and failed to introduce mandatory digital ID in 2025). An under-16 ban that obliges 90% of British adults (who use at least one social media platform) to verify themselves achieves a remarkably similar end while hiding behind the shield of child protection (I always think of Mrs Flanders in the Simpsons screaming, “Will someone think of the children?”).
What “subjective and reactive” actually means
Strip away the politics and piffle and a clear pattern emerges. These are laws whose scope is set by regulators like OFCOM after the fact, then revised as services “evolve”. They are enforced through checks that we know don’t and probably can’t work or really protect children while at the same time removing the digital anonymity of most adults. A government genuinely interested in the harm that algorithmic amplification and engagement-at-all-costs design that injures adults and children alike, would have to confront the platforms’ business models, not rushed measures that will leak worse than the Number 10 press office.
Addressing the underlying business models is hard, slow and politically unpopular and at best delivers a quick sugar-high fix. An age-gate is simple, visible, and lets Prime Minister Starmer stand at the dispatch box and say he refused to be a bystander and let children suffer. The trouble is that the children can see the gate has no lock and the only people reliably stopped at the gate are the adults who were never the point
