Technology · Digital regulation
Europe follows Australia in tightening children's social media rules
Australia's under-16 ban has accelerated EU and national moves on age verification, while Meta's $18 billion US settlement sharpens the legal pressure on platforms.
When Australia passed its Online Safety Amendment in late November 2024, it did something no other democracy had done: it made it illegal for children under 16 to hold an account on TikTok, YouTube, Instagram, Facebook or Snapchat. The law, which takes effect in December 2025, imposes fines of up to 49.5 million Australian dollars on platforms that fail to take "reasonable steps" to prevent underage sign-ups. It also bars platforms from demanding government-issued identity documents as the sole verification method, a concession to privacy advocates that leaves the technical solution deliberately open.
The Australian precedent and its immediate ripple
The Australian move was not taken in isolation. It followed a year of intensifying parliamentary inquiries, a coronial inquest into the suicide of a 14-year-old girl who had been exposed to self-harm content on Instagram, and a public campaign led by the parents of another teenager who died after participating in a TikTok "blackout challenge". The legislation passed the Senate 34 to 19 with support from the centre-left government and the conservative opposition, a rare consensus that signalled the political salience of the issue.
Within weeks, the European Commission indicated it would examine whether the Australian model could inform enforcement of the Digital Services Act (DSA), which since February 2024 has required very large online platforms, those with more than 45 million monthly active users in the EU, to conduct annual systemic risk assessments that explicitly include risks to minors. A Commission spokesperson said the Australian law "provides a useful reference point for what effective age assurance might look like in practice" but stressed that any EU approach must comply with the GDPR and the ePrivacy Directive.
Meta's US settlement sharpens the regulatory calculus
The Australian ban coincided with a development that may prove more consequential for platform behaviour globally. In October 2024, Meta agreed to pay up to $18 billion to resolve lawsuits brought by 33 US state attorneys general alleging that Facebook and Instagram were engineered to maximise time spent by young users through infinite scroll, algorithmic recommendation, and variable reward mechanics. The settlement, which awaits final court approval, includes commitments to change certain product features for teen accounts and to fund independent research on mental health impacts.
Meta denied the allegations but characterised the settlement as a way to "move forward" and "focus on building safe experiences". The company has since rolled out "Teen Accounts" on Instagram with default private settings, sleep mode notifications, and stricter messaging controls in the US, UK, Canada and Australia. Critics argue the changes are incremental and do not address the core business model that incentivises engagement maximisation.
Europe's patchwork of national responses
While the DSA sets a horizontal floor, several member states have moved faster. France enacted a law in July 2023 requiring social media platforms to verify the age of users and obtain parental consent for those under 15. The French regulator, Arcom, has the power to order ISPs to block non-compliant services, though no blocking order has yet been issued. Germany's Youth Protection Act was amended in 2024 to mandate age verification for platforms accessible to minors, with the federal agency KJM overseeing compliance. The UK's Online Safety Act, which received royal assent in October 2023, imposes a duty of care on platforms to protect children from harmful content and requires "age assurance" technologies that go beyond self-declaration.
These national laws create a complex compliance landscape. A platform operating across the EU must now navigate an Australian ban at 16, a French threshold at 15 with parental consent, a German regime tied to the KJM's approved verification methods, and a UK framework that Ofcom is still fleshing out through codes of practice. The European Commission has opened a dialogue with national regulators to avoid fragmentation, but the direction of travel is clearly toward stricter, technically enforced age gates.
The evidence gap on underage usage
Official data underscores why regulators have lost faith in self-declaration. A 2023 survey by France's CNIL found that 63% of children aged 11 to 12 had at least one social media account, despite the platforms' nominal 13-year minimum. In Germany, the Media Authority of North Rhine-Westphalia reported that 58% of 10-to-12-year-olds used TikTok regularly. The UK's Ofcom estimated in its 2024 Media Use and Attitudes report that 38% of 8-to-11-year-olds had a social media profile. These figures are broadly consistent across the EU and suggest that the industry's current age gate, a checkbox asking users to confirm they are 13, is functionally meaningless.
Child protection organisations argue that the problem is not merely technical but structural. Platforms optimise for user growth and engagement; frictionless onboarding is a feature, not a bug. "The business model depends on acquiring users early and keeping them," said a senior policy adviser at a European children's rights NGO who asked not to be named because of ongoing dialogue with the Commission. "Any verification system that materially reduces sign-ups will be resisted unless mandated by law."
Age assurance technologies and the privacy trade-off
The technical debate centres on how to verify age without creating a surveillance infrastructure. The Australian law explicitly prohibits requiring government ID as the only method, pushing platforms toward alternatives: facial age estimation, behavioural analysis, device-level signals, or third-party credential verification. The EU's European Digital Identity Wallet, currently in large-scale pilots, could eventually provide a privacy-preserving way to prove age without revealing identity. But the wallet is not yet operational at scale, and its adoption by private platforms is voluntary.
Facial age estimation, offered by companies such as Yoti and VerifyMyAge, claims accuracy within 1.3 years for 13-to-17-year-olds. Critics, including the European Data Protection Board, warn that biometric processing at scale raises GDPR Article 9 concerns and could normalise face scanning for routine access. Behavioural analysis, inferring age from usage patterns, avoids biometrics but requires continuous monitoring, which many privacy experts find equally problematic. The Commission's forthcoming guidelines on age assurance under the DSA, expected in late 2025, will attempt to chart a compliant path.
Industry lobbying and the "risk-based" framing
Platforms have coalesced around a "risk-based" argument: they contend that blanket age bans are disproportionate and that resources should target high-risk features, live streaming, direct messaging, algorithmic amplification, rather than exclude all minors. Meta, Google and TikTok have funded a joint industry initiative, the Age Assurance Standards Project, to develop interoperable technical standards. They also point to the US Kids Online Safety Act (KOSA), which passed the Senate in July 2024 but stalled in the House, as evidence that even the US is moving toward a duty-of-care model rather than age prohibition.
European regulators are sceptical. The DSA's risk assessment obligation is explicitly systemic: platforms must evaluate how their design, algorithms and business model create risks for children as a group, not merely react to individual harms. A Commission official involved in DSA enforcement said privately that "risk-based" cannot become a loophole: "If your risk assessment concludes that the core product is unsafe for under-16s, the mitigation may well be exclusion."
The legal frontier: fundamental rights challenges
Any EU-wide move toward an Australian-style ban would face immediate legal challenge on fundamental rights grounds. The Charter of Fundamental Rights protects children's right to participate in cultural and social life (Article 24) and everyone's freedom of expression and information (Article 11). A blanket exclusion of under-16s from major communication platforms would be a severe restriction requiring strict proportionality. The European Court of Justice has not yet ruled on a case directly analogous, but its jurisprudence on data retention and platform liability suggests it would demand evidence that less intrusive measures have been tried and failed.
This legal uncertainty explains why the Commission has so far preferred enforcement of the DSA's risk mitigation toolkit over a legislative age ban. But the Australian precedent, combined with the Meta settlement and mounting national laws, shifts the Overton window. A European Parliament report adopted in March 2025 called on the Commission to "assess the feasibility and proportionality of a harmonised minimum age for social media access, not excluding the possibility of a Union-wide threshold of 16 years." The report is non-binding but signals parliamentary appetite.
The next flashpoint may be the European Digital Identity Wallet. If the wallet achieves mass adoption across member states by 2026, it could provide the technical substrate for a harmonised EU age verification system that satisfies both the DSA and the GDPR. But that depends on political will in the Council, where member states remain divided on whether digital identity should be a tool for platform regulation or a citizen service. The Commission's 2025 work programme lists a "comprehensive review of the protection of minors online" for the fourth quarter, which could be the vehicle for a legislative proposal, or a decision to stick with DSA enforcement.
Meanwhile, the platforms are running a real-world experiment. Meta's Teen Accounts, TikTok's Family Pairing, and YouTube's supervised experiences are being deployed at scale in Australia, the UK and the EU. Their uptake, effectiveness, and impact on user growth will be closely watched by regulators. If the industry can demonstrate that voluntary product changes materially reduce harm without excluding teenagers, the case for a ban weakens. If not, the Australian model, or something like it, will look increasingly inevitable in Brussels, Paris and Berlin.
Sources
Organisations
European Commission · European Parliament · Meta Platforms · Alphabet · TikTok