Lessons Learned from the Social Media Minimum Age Act: KJR & AVPA Report
The introduction of Australia’s Online Safety Amendment (Social Media Minimum Age) Act 2024 on 10 December 2025 marked a major regulatory shift in how online platforms are expected to protect young users. The initial phase of implementation, while still evolving, has already provided a meaningful evidence base for understanding what is working, where gaps remain, and what needs to happen next.
A central conclusion from the joint work led by the Age Verification Providers Association, with contributions from KJR, is clear: this is not a question of whether age assurance technology works. The Australian Age Assurance Technology Trial demonstrated that multiple approaches could deliver accurate, scalable, and privacy-preserving outcomes. What the current phase reveals instead is that effectiveness depends far more on how these capabilities are implemented, governed, and enforced in practice.
This challenge is explored further in Episode 25 of the KJR podcast, where Andrew Hammond and Iain Corby discuss the realities of AI-driven age assurance in practice.
From Technical Feasibility to Operational Reality
The Age Assurance Technology Trial already established that age assurance is technically viable across a range of methods. As a result, the early implementation of the Act should not be interpreted as a further test of technology itself. Rather, it should be understood as a test of operational execution and regulatory alignment.
Initial deployment across platforms has been progressive, reflecting the scale and complexity of implementation. There are positive indicators, including the suspension of hundreds of thousands of underage accounts and clear regulatory expectations set by the eSafety Commissioner. These outcomes suggest that platforms are capable of taking action when required.
However, more recent independent testing and industry observations indicate that this progress is not yet consistent or comprehensive. In particular, many platforms are still not systematically verifying age at critical points such as account creation, and instead rely on weaker signals such as self-declared age or internal inference models. This creates a gap between compliance in principle and effectiveness in practice.
The Real Issue: Inconsistent Application of Controls
The report highlights that the current challenge lies in the inconsistent application of age assurance controls across the user journey. While some platforms have taken meaningful steps to identify and remove underage users, others continue to allow new accounts to be created with minimal verification.
This inconsistency is significant because the legislation is outcome-based. Platforms are not simply required to deploy age assurance tools; they are required to take reasonable steps to prevent underage access. Where age checks are not routinely applied, or are applied too selectively, the intended policy outcomes cannot be achieved.
For professionals in testing, quality engineering, and digital delivery, this reflects a familiar pattern. Systems may be technically sound, but without clear enforcement points, robust governance, and continuous validation, they fail to deliver reliable outcomes in real-world conditions.
Why Assurance, Not Technology, Determines Outcomes
One of the most important lessons from this phase is that governance frameworks, assurance standards, and operational controls are now the primary determinants of effectiveness. The question is no longer whether age assurance can work, but whether it is being deployed in a way that meets the intent of the law.
This has several implications. First, minimum expectations for effectiveness need to be more clearly defined. The current principles-based “reasonable steps” guidance provides flexibility, but it has also led to variations in how platforms interpret their obligations. Establishing a baseline for what constitutes “Reasonably Effective Age Assurance” would help create consistency while still allowing for different technical approaches.
Second, assurance must extend across the full lifecycle of an account. This includes not only initial verification, but also ongoing monitoring, re-validation, and controls to prevent reuse or circumvention. Without these elements, even well-designed systems can degrade over time or be bypassed in practice.
Third, independent testing and conformity assessment play a critical role in building trust and accountability. As demonstrated through recent testing activities, including those conducted by KJR, independent evaluation helps identify gaps that may not be visible through internal platform assessments alone.
Strengthening the Next Phase of Implementation
As the regulatory framework evolves, the focus should shift toward strengthening operational expectations and ensuring that platforms deliver consistent outcomes. This includes introducing clearer benchmarks for effectiveness, increasing the frequency and coverage of age checks, and reinforcing requirements for audit, certification, and ongoing assurance.
It is also important to recognise that maintaining resilience against circumvention is an ongoing process. This requires continuous monitoring, adaptive controls, and participation in benchmarking and testing programmes. These practices are already well understood within the quality engineering and assurance community and can be applied directly to this domain.
At the same time, the broader ecosystem must be considered. As regulation expands to adjacent environments such as online gaming, maintaining consistent assurance expectations across similar services will be essential to avoid displacement effects and ensure that protections remain effective.
Moving from Early Progress to Sustained Effectiveness
The early implementation of the Act should be seen as a foundation rather than a final state. It has demonstrated that progress is possible and that platforms can act at scale when required. However, it has also highlighted that without stronger and more consistent application of age assurance, the intended outcomes will not be fully realised.
Ultimately, the lesson is straightforward. The challenge facing Australia is not that age assurance technology is insufficient, but that it is not yet being used to its full potential. Bridging that gap will require clearer expectations, stronger assurance practices, and a continued focus on operational execution.
KJR led the efforts in the technology evaluation in aspects of the trial to ensure solutions are robust, scalable, and aligned with industry standards and user expectations.





