Parental consent comes for Big Social, and the platforms were warned
Australia's High Court has cleared the country's landmark under-16 social media law, closing a two-and-a-half-year chapter in which the platforms were offered the room to design age assurance themselves and declined. The interesting question is now what they build, on what timeline, and at whose exp

Australia's eSafety Commissioner handed the country's largest social platforms a choice in late 2023: design a credible age-verification regime for under-16 users, or watch the state do it for them. The platforms picked delay, litigation and selective compliance. Two and a half years on, the parliament has decided the choice for them, and the High Court has refused to intervene.
What just happened is less a constitutional drama than a quiet institutional settling of accounts. The legislation, passed by both houses with bipartisan support, places the burden of age assurance squarely on the platforms rather than on minors or their parents. It is the first Western democracy to put parental-consent-style obligations for under-16 users on a statutory footing, with criminal liability for non-compliance. The platforms were warned. They were consulted. They were offered the room to build a system they could live with. They declined, repeatedly, in public submissions that read more like negotiating positions than engineering proposals. Parliament has now answered.
The bill that survived the court
The basic architecture is straightforward. Services likely to be accessed by under-16 Australians must take "reasonable steps" to verify age and, where a user is a minor, obtain parental consent before processing personal data for account creation, content personalisation or direct messaging. The threshold is not "best efforts." It is a duty of care backed by civil penalties and, in cases of wilful or systematic non-compliance, criminal exposure for senior officers. The eSafety Commissioner retains investigatory and enforcement powers; a new industry code sits underneath the statute to handle edge cases.
The High Court's refusal to grant interim relief on Wednesday, 18 June 2026, closes the door on the most aggressive legal challenge. The platforms had argued the regime amounted to effective age-gating, that it would force data collection the legislation purported to prohibit, and that it imposed a constructive exclusion of minors from public discourse online. None of those arguments carried the bench. The majority found the law proportionate, the data-minimisation framework workable, and the policy objective, protecting minors from commercial data extraction, squarely within the Commonwealth's constitutional remit.
What the platforms actually built
The platforms' conduct during the consultation phase is the part of the story most coverage has underplayed. Industry submissions to the parliamentary committee in 2024 proposed a tiered system that would have let minors self-declare age, with platform-side estimation as a backstop. In effect: trust the user. Independent reviewers pointed out the obvious problem: the same platforms monetising attention from 13-year-olds had every commercial incentive to under-enforce.
A second round of submissions in early 2025 floated device-level signals and platform-side machine-learning estimates, again without third-party verification. The government asked for a pilot. The pilot never came. By the time the bill was introduced in the Senate, the only working age-verification systems in production anywhere were third-party providers, Yoti, AgeID, Veriff, whose business model depends on charging the platforms per check. The platforms did not want to pay, and they did not want to be told they had to.
The structural point
Strip away the courtroom theatrics and the question is who designs the operating environment for minors online: the platforms that harvest the data, or the state that grants them the licence to operate. Australia has now answered that question in favour of the state, and the answer will travel.
Two reasons. First, the technical stack for age assurance exists and is mature. The platforms' argument that verification is impractical collapsed the moment third-party providers demonstrated sub-second biometric checks with on-device processing. What was being contested was not feasibility but commercial preference.
Second, the platforms have spent two and a half years publicly committing to child safety while privately lobbying against every legislative mechanism that would make those commitments enforceable. The result is a credibility deficit that the major parties, including the opposition, decided they could no longer ignore. The political risk of appearing soft on minor protection now exceeds the political risk of antagonising Silicon Valley.
What to watch next
The compliance clock starts on the day the bill receives Royal Assent. Services have nine months to implement age-assurance measures and a further three months to integrate parental-consent flows for new accounts. Existing accounts held by minors are subject to a wind-down regime: platforms must notify users, offer a consent pathway, and deactivate accounts where consent is withheld or not sought.
Three questions will define the rollout. Whether the third-party verification providers can scale to handle a national cohort on launch day. Whether the platforms seek to comply by geofencing Australia, as some have done with European regulation, rather than building tools for global deployment. And whether the eSafety Commissioner moves early against a high-profile holdout to set the cost of non-compliance before the market normalises around the new rules.
The platforms were warned. They have the tools. They have the deadline. What they build next, and how quickly, will tell the rest of the story.