A new Australian law has been widely described as forcing every social media user to submit government ID to open an account, in order to protect children. That is not what the law says. Getting this wrong matters, because it changes how millions of people understand a world-first scheme, and because the real design contains safeguards the dramatic version erases entirely.
What Is Actually True
The report describes Australia's Social Media Minimum Age scheme, added as Part 4A of the Online Safety Act 2021 and in force from 10 December 2025. The claim that the law requires all users to submit government ID before creating an account does not hold up. The law is deliberately technology-neutral. It requires designated platforms to take reasonable steps to stop under-16s holding accounts, and it does not prescribe any single method to do that. Government ID is one permitted option among several, alongside facial age estimation, age inference from account activity, and linked signals like bank details.
On the ID question specifically, the law does close to the opposite of what the dramatic framing suggests. Under the privacy provisions the OAIC enforces, platforms must not require government-issued identification, including Digital ID, as the only method of age assurance. A reasonable alternative must always be offered. The government's own fact sheet states plainly that no Australian will be compelled to use government ID for age assurance on social media. Data collected for age checks must also be ring-fenced from the rest of the platform's business and destroyed, not stored or repurposed.
The onus sits on platforms, not on users or parents. There are no penalties for an under-16 who gets around the system, and none for their family. Platforms face civil penalties, up to 49.5 million Australian dollars, for failing to take reasonable steps. The government has openly said the system will not be airtight from day one, and there is already evidence of teenagers finding ways around the checks.
So the shape of the distortion is clear. The dramatic version collapsed a menu of age-assurance methods into the single most alarming one, government ID, and dropped the legal safeguards built around it. What is actually true is narrower: a platform-facing obligation with an explicit ban on ID-only verification and mandatory data destruction. Both the surveillance fear and the child-safety complaint describe real tensions in this law. The specific claim that everyone must hand over ID is wrong.
What Was Left Out
Six things dropped out of the picture as it was reported. First, the legal prohibition on requiring government ID as the only method, and the guarantee that platforms must always offer an alternative. Second, that the obligation targets under-16 accounts specifically, not every internet user in the country. Third, that the onus and the penalties fall on platforms, with no legal consequence for children or parents who work around it. Fourth, the mandatory ring-fencing and destruction of any data collected for age checks. Fifth, that the independent Age Assurance Technology Trial, commissioned by the government itself, found no single reliable and universal verification method, and that every method carries error rates. Sixth, the list of exempt services, which currently includes messaging, gaming, education and health platforms, along with specific carve-outs for YouTube-adjacent services, WhatsApp, Roblox and Pinterest.
Each omission pushes the story toward maximum alarm and away from the actual compliance mechanics that determine how this law will function in practice.
Across The Spectrum
The ABC reported the on-the-ground detail that under-16 users were already circumventing age verification at rollout, a fact that undercuts any "total control" framing. Time clarified that platforms have discretion over methods, that ID upload is only one option, and noted the law had roughly 77 percent public support when it passed. CNBC listed the actual range of verification methods available, including inference, facial estimation, uploaded ID and linked bank details, and quoted experts predicting a rollout defined by trial and error. Al Jazeera named the ten designated platforms and the exemptions, and reported legal challenges brought by a digital rights group.
On the regulatory side, the OAIC and eSafety Commissioner confirmed the ID-only prohibition, the ring-fence-and-destroy data rule, and that the onus rests on platforms rather than families. The International Bar Association confirmed the technology-neutral "reasonable steps" standard and the trial finding that no single method suits every case. Amnesty Tech took a different angle, arguing the whole approach is an ineffective fix and that stronger data protection and better platform design would protect all users more effectively than an age gate.
The Evidence
The verified facts are consistent across government and independent sources. From 10 December 2025, age-restricted platforms must take reasonable steps to stop Australians under 16 creating or keeping accounts, per the OAIC and the Department of Infrastructure. The law is technology-neutral and does not require government ID, confirmed by the International Bar Association, CNBC and eSafety guidance. Platforms must not require ID as the only method, and a reasonable alternative must always be offered, per OAIC guidance, legal advisory MinterEllison and the government's own fact sheet. Data collected for age assurance must be ring-fenced and destroyed, with X stating it destroys such data within 31 days. There are no penalties for under-16s or parents, with penalties of up to 49.5 million dollars falling on platforms instead. The government-commissioned trial found no single reliable, universal method exists, and all carry error rates. And, rated as strong rather than fully verified, some under-16 users were already evading the checks at launch, something the government had acknowledged in advance.
Prime Minister Anthony Albanese said, "The fact that teenagers occasionally find a way to have a drink doesn't diminish the value of having a clear national standard." That is the government conceding the scheme isn't airtight, which cuts against both the "total control" framing and the surveillance-state reading at once. Amnesty Tech's Damini Satija said the most effective way to protect children online is "by protecting all social media users through better regulation, stronger data protection laws and better platform design," reframing the debate away from ID checks and toward systemic design. And the Age Assurance Technology Trial itself found "there wasn't a single ubiquitous solution that would suit all use cases," the core technical reality behind why the law refuses to mandate any one method.
The Honesty Check
The critics are not wholly wrong. Facial estimation and behavioural inference are still forms of surveillance, and platforms may in practice steer users toward ID because it's simpler, which erodes the "alternative always offered" safeguard in daily use. The child-safety complaint also has real force: a parent's ID or a verified adult account can defeat the system, and evasion was visible on day one. The enforcement standard itself is vague, so how intrusive this actually becomes depends on how the eSafety Commissioner interprets "reasonable steps" over time. The specific claim of compulsory ID for all users is false. The underlying privacy risk is not imaginary.
What Remains Unknown
How platforms will implement age assurance in practice, and whether they default to ID checks despite the ban on making ID the only option, remains to be seen. Whether the ring-fence-and-destroy rules hold up against real data breaches is untested. How effective the scheme actually is at reducing under-16 access over months, rather than on launch day, is not yet known. And the pending legal challenges have not been resolved.
Where This Leaves Us
The headline claim, that everyone must hand over government ID to use social media, is wrong. Australia's law targets under-16 accounts, is technology-neutral, and specifically forbids platforms from making government ID the only way to verify age, while forcing any data collected in the process to be destroyed. The real story is quieter and messier than either side's version: a platform-facing obligation with genuine privacy trade-offs, no perfect verification method available to anyone, and workarounds the government has already admitted exist. Watch how "reasonable steps" gets enforced in practice, and whether platforms quietly default to ID anyway despite the rule against it. The aim of protecting kids online is sound. The surveillance fear, as described in the dramatic version, is overstated but not baseless. The truth sits in a more precise place than either headline allows.