Australia's Parliament has doubled the stakes for social media platforms that fail to keep children under 16 off their services. The Online Safety Amendment (Strengthening Enforcement for the Social Media Minimum Age) Bill 2026 received royal assent on September 11, 2026, raising the maximum civil penalty for systemic non-compliance from 30,000 to 60,000 penalty units — roughly A$49.5 million to A$99 million (about US$71 million) — and giving eSafety Commissioner Julie Inman Grant compulsory document-production powers that extend beyond platforms to app stores and age-assurance vendors.
The Gap the Law Is Closing
The case for stronger enforcement is not hypothetical. The underlying ban — the Online Safety Amendment (Social Media Minimum Age) Act 2024 — took effect on December 10, 2025, requiring "age-restricted" platforms to take reasonable steps to remove and prevent under-16 accounts. Three months later, a study tracking more than 400 Australian teenagers found more than 85% of under-16 participants were still active on platforms covered by the law, and only about two-thirds had encountered any meaningful age-checking mechanism at all (The Conversation). eSafety's own March 2026 compliance review flagged platforms letting users who had self-declared as under 16 simply revise their age using low-confidence facial estimation — a loophole that let the ban's core mechanism defeat itself.
That matters because eSafety's existing toolkit was thin. Commissioner Inman Grant has said the regulator "do[es] not have a fine-issuing button"; systemic non-compliance has to be proven in court with solid evidence, and the old framework let her request information but not compel the underlying documents platforms used to substantiate their compliance claims. A regulator that can only ask nicely for the evidence needed to prosecute a breach is, in practice, a regulator that mostly can't prosecute. Extending document-compulsion to app stores and age-assurance providers also reflects a reasonable read of how the compliance chain actually works — platforms increasingly point to third-party vendors when explaining gaps, and a law that only reaches the platform leaves that chain unauditable.
Where the Bill Overshoots
But the remedy is broader than the diagnosis. Legal experts who reviewed the bill during the Senate inquiry — which reported its recommendations by August 25, 2026 — warned that its information-gathering powers, as drafted, could sweep in "any person, including end-users who are children and their parents," without the safeguards that typically accompany compulsory-disclosure regimes aimed at regulated entities rather than the public (ABC News). Industry groups separately pushed for public reporting on how and when compulsory notices are issued, arguing that a power this broad needs transparency to avoid becoming a standing surveillance tool aimed at ordinary users rather than the platforms Parliament actually intended to regulate. Those are not the objections of companies looking for an excuse to stall; they are the objections a well-drafted enforcement bill should have already answered.
The penalty design has its own gap. Critics who reviewed the final text noted it stops short of a global-turnover-based penalty structure — the model the EU's Digital Services Act uses and that several submissions to the Senate inquiry recommended — meaning a flat A$99 million cap could still register as a rounding error against the annual revenue of the largest platforms, even as it lands hard on smaller or regional services with genuinely thin compliance budgets (The Conversation).
The Deeper Problem This Doesn't Solve
There's also a more fundamental critique worth taking seriously: enforcement is a downstream fix. If the underlying age-verification methods are weak — self-declaration, easily gamed facial estimation — no amount of document compulsion changes what platforms are actually able to verify. Better evidence-gathering proves non-compliance more efficiently; it doesn't make compliance more achievable. A regime built around a genuinely reliable age-assurance standard, paired with proportionate penalties tied to actual harm and actual company scale, would do more for the law's credibility than expanded subpoena power alone.
What Should Happen Next
None of this means the bill was wrong to pass. An 85% failure rate three months into a flagship child-safety law is a real regulatory failure, and a commissioner unable to compel the evidence needed to prove breaches in court was never going to fix it. But Parliament should treat September 11 as a floor, not a finish line: the compulsory-powers language needs a narrowing amendment or clear regulatory guidance confirming it targets regulated entities, not end-users and parents; the transparency reporting industry asked for should be built into eSafety's standard practice regardless of whether it was mandated; and any future penalty revision should move toward turnover-scaled fines so the largest platforms feel A$99 million the way a mid-sized vendor already does. Proportionate enforcement of a genuinely popular child-safety law is good policy. An investigatory dragnet that nobody bothered to fence in is a different thing, and Australia still has time to tell the two apart before the powers get used.