A number that flatters and indicts at once
On August 12, 2026, Meta disclosed that it removed access from 756,000 Australian accounts it assessed as belonging to under-16s — 462,000 on Instagram and 294,000 on Facebook — across the seven months from December 1, 2025 to June 30, 2026 (ppc.land). The company detects most of these accounts through AI-driven behavioural signals after signup, not at registration, and used the same disclosure to argue that reliable age assurance belongs at the operating-system or app-store layer: "There should be a single reliable age signal delivered at the operating system or app store level," verified once per device rather than repeatedly across dozens of apps (MediaNama).
Read generously, 756,000 removals is a serious enforcement effort under the Online Safety Amendment (Social Media Minimum Age) Act 2024, which took effect December 10, 2025 and bars Facebook, Instagram, Snapchat, TikTok, YouTube and several other named platforms from holding accounts for under-16 Australians. Read against the regulator's own data, it looks much smaller. The eSafety Commissioner's evaluation found that 85.9% of 10-15-year-olds used at least one restricted platform before the ban, falling to just 81.5% three months after it took effect — a 4.4-point drop, even as account-holding fell more sharply, from roughly 52% to 42% (The Conversation). More than half of surveyed children said platforms never even asked them to confirm their age, and 37% simply self-declared as 16 or older to keep access. Behavioural-signal detection is catching some accounts after the fact; it is not stopping most under-16s from getting in.
The case for the ban, stated fairly
The strongest argument for Australia's law is not that it is airtight but that it forces a cost onto platforms that previously had none. Before December 2025, age-gating was self-declared and essentially unenforced; a 12-year-old could open an Instagram account by typing a birthdate. The Act's civil penalty — doubled by the government to $99 million AUD in a June 28, 2026 announcement, explicitly to bring it in line with competition-law fines (Prime Minister of Australia) — gives platforms a genuine balance-sheet reason to build real detection rather than a checkbox. Meta's 756,000 removals, and the roughly 5 million accounts removed, deactivated or restricted industry-wide since the ban began, are evidence the incentive is doing something (Prime Minister of Australia). The law also builds in a real privacy backstop: under section 63F of the amended Online Safety Act, any personal information collected for age assurance must be ring-fenced and destroyed, and platforms cannot compel government ID as the sole verification method — a "waterfall" model the OAIC has been explicit about protecting (OAIC). That is a more careful design than blunt ID-mandate proposals elsewhere.
Why post-hoc detection was never going to close the gap
The design flaw is structural, not a matter of Meta trying harder. Behavioural-signal detection is inherently reactive: it catches a 13-year-old only after they have already created an account, posted, followed, and been recommended content — sometimes for months, given the disclosure window starts December 1, 2025, nine days before the law's own effective date. eSafety's finding that most affected children were never even asked to verify their age at signup confirms the gap is at the front door, not in Meta's trust-and-safety pipeline. No amount of downstream AI classification fixes an entry point that doesn't ask the question.
Meta's OS-level proposal deserves to be taken seriously rather than dismissed as lobbying. Apple's Declared Age Range API, already rolling out in Australia ahead of a September 9, 2026 deadline for age-restricted content controls, lets a device share an age band with any app on permissioned request — verified once, not per-service (Information Age). That is a genuinely better architecture: it centralises the privacy-sensitive verification step with the two companies (Apple, Google) that already gatekeep every download, instead of forcing dozens of social apps to each build, and each retain data for, their own imperfect estimation systems. It is also self-serving — it would let Meta outsource both liability and cost — but self-serving and correct are not mutually exclusive here.
The proportionate path
Australia's regulators should not read Meta's 756,000 figure as a victory lap, nor as proof the law failed. It is evidence the current architecture — per-platform, after-signup, behavioural detection — has a structural ceiling well below what the law promised voters. eSafety's move to compel more granular platform reporting, and its ongoing investigation of platforms including Instagram, Facebook and TikTok for suspected non-compliance, is the right next step: enforcement should follow the data, not the press release. But regulators should also use the leverage they now have — a doubled penalty and expanded information-gathering powers — to push Apple and Google toward exactly the OS-level signal Meta is asking for, with the OAIC's ring-fencing safeguards attached. A single, privacy-preserving age credential at the device layer, backed by real penalties for platforms that ignore it, would do more for Australian teenagers than another year of AI models guessing who is 15.