Intimate Deepfakes

 

There is an awkward paradox at the centre of almost every serious proposal to keep children off unsuitable parts of the internet.

The State says:

“We do not want children entering this space.”

The platform replies:

“Then we need to know which users are children.”

And suddenly the adult who wanted nothing more than to scroll anonymously through a social-media feed is being asked to establish that he is old enough to be there.

That may involve a facial age-estimation system.

Or a digital identity provider.

Or information associated with a mobile-network account.

Or payment information.

Or another mechanism capable of establishing age with sufficient confidence.

A law intended to collect less information about children can therefore create pressure to collect more information about everybody.

This is the age-gate paradox.

Britain is about to test it at national scale.

On 15 June 2026, the UK Government announced that social-media companies would be prevented from offering specified social-media services to children under 16. The Government intends the restrictions to cover major services such as Instagram, Facebook, TikTok, Snapchat, YouTube and X, while standalone messaging services such as WhatsApp and Signal are not intended to fall within the core social-media prohibition. The first regulations are expected to be placed before Parliament before the end of 2026, with implementation envisaged for spring 2027.

This is therefore not yet correctly described as:

“Britain has banned social media for under-16s.”

The more accurate formulation, as of August 2026, is:

Britain has decided to do so, Parliament has already conferred substantial secondary-legislation powers enabling the Government to impose such restrictions, and the detailed regulatory architecture is now being prepared.

That distinction matters greatly to lawyers.

Political announcement is one thing.

Enabling legislation is another.

Secondary legislation identifying the actual regulated services, age thresholds, exceptions and compliance obligations is another still.

Regulatory guidance determining what compliance looks like in practice will add another layer.

And enforcement will ultimately tell us whether the prohibition changes behaviour or merely changes the technology through which teenagers reach the same places.

What Britain is attempting is therefore much more interesting than another debate about whether teenagers spend too much time on their phones.

It raises questions concerning privacy, freedom of expression, children’s autonomy, parental responsibility, platform design, biometric technology, regulatory proportionality, extraterritorial enforcement and the rapidly emerging law of digital age.

Most importantly, it asks a question governments around the world will increasingly have to answer:

How do you prove that someone is old enough without unnecessarily proving who they are?

Britain has gone beyond merely telling platforms to enforce their existing age limits

For years, major social-media services nominally imposed minimum ages—commonly 13—while enormous numbers of younger children nevertheless used them.

Ofcom said in March 2026 that its research indicated that 72 per cent of children aged 8 to 12 were accessing sites and applications carrying a nominal minimum age of 13. The regulator had already been pressing major services including Facebook, Instagram, Snapchat, TikTok and YouTube to demonstrate stronger age-assurance arrangements.

That failure helps explain the Government’s change in philosophy.

The older model effectively said:

The platform should state an appropriate minimum age and attempt to enforce it.

The new model is much stronger:

The law itself will establish that children below the statutory threshold should not have access to specified social-media services, and regulated businesses will have to prevent that access.

That transfers the matter from private contractual terms into public regulation.

A thirteen-year-old lying about a date of birth is no longer merely defeating an application’s terms of service.

The platform may itself be failing a statutory duty if its age-assurance architecture does not adequately prevent underage access once the new regime becomes operative.

The Government already has the primary legislative machinery

This is an important development which much press coverage has missed.

The Children’s Wellbeing and Schools Act 2026, which received Royal Assent on 29 April 2026, contains the legislative mechanism through which the Government can move quickly without waiting for another full Act of Parliament.

Section 70 inserts a new section 214A into the Online Safety Act 2023. The new power permits the Secretary of State, by secondary legislation, to require providers of specified internet services to prevent or restrict access by relevant children to those services, specified functionality or other features where that intervention is directed towards protecting children from a risk of harm.

This is broad regulatory machinery.

It allows government to regulate not merely whole services but potentially particular functionalities within them.

That distinction becomes important when one considers that the real danger associated with a platform may arise not from every aspect of the service, but from particular features:

algorithmic recommendation;

livestreaming;

stranger contact;

infinite scrolling;

autoplay;

public posting;

location functionality;

or personalised feeds.

The statute consequently permits a more granular model than simply maintaining a list headed:

“Websites prohibited to children.”

Parliament deliberately required further scrutiny

The power is not wholly unstructured.

The explanatory material for section 70 states that the Government must have regard to the national consultation on children and the online world, while Ofcom may be required to conduct research and provide advice relevant to regulations. The regulations are subject to the affirmative parliamentary procedure, meaning they cannot simply be made quietly by a department without approval by both Houses of Parliament.

That safeguard is important because the detail will determine almost everything.

There is an enormous legal difference between saying:

“Children under 16 should not be exposed to harmful social-media design.”

and drafting a legally administrable definition of:

“social media”.

Is YouTube social media?

The Government presently intends to include it within the relevant model.

Is WhatsApp?

Presently, no.

What about Discord?

Gaming forums?

Reddit?

Pinterest?

An educational site containing comments?

A news website permitting user discussion?

A professional network?

An AI chatbot allowing public personas?

A multiplayer game containing messaging, livestreaming and user-generated feeds?

The boundary between social media and “the internet” has become surprisingly difficult to draw.

The Government knows this—and intends exemptions

The June announcement recognised this definitional difficulty.

The Government indicated that it is studying the Australian model closely and intends narrowly framed exemptions so that dedicated educational services, e-commerce platforms and music-streaming services are not inadvertently swept into the social-media prohibition.

This is sensible.

A statute which simply says “no social media under 16” sounds clear in political language but becomes considerably more complicated in software architecture.

Amazon permits reviews.

Spotify contains social functionality.

YouTube contains educational material.

Gaming services can contain messaging, user profiles, livestreams and algorithmic recommendations.

Messaging applications increasingly offer channels and public communities.

Social networks offer private messaging.

The categories overlap.

The better legal question may therefore become:

What does the service enable the child to do?

rather than:

What does the company call itself?

Britain is therefore regulating functions as much as platforms

This may ultimately become one of the most important features of the British model.

The Government has announced that harmful functions such as children livestreaming themselves and communication from strangers will be restricted more broadly than the core social-media prohibition, including in some gaming environments.

That reflects a more sophisticated understanding of online harm.

The danger does not necessarily reside inside the corporate label.

A harmful recommender system does not become safe because it sits inside a gaming application.

An adult stranger attempting to contact a child does not become harmless because the communication occurs inside a virtual world rather than Instagram.

Regulation should follow the risk-generating functionality.

This is the same general movement we are seeing elsewhere in technology law.

Legal classification increasingly follows what software does rather than what the vendor calls the software.

Britain is also refusing to create a regulatory cliff-edge at 16

The Government does not intend the new framework to operate on the assumption that a person becomes digitally invulnerable at midnight on their sixteenth birthday.

In July 2026, it announced further measures for 16- and 17-year-olds.

The current plan includes default overnight social-media curfews between midnight and 6 a.m., with features associated with prolonged engagement—such as continuous personalised feeds and successive autoplaying videos—switched off by default for that age group. Older teenagers would remain capable of changing relevant settings themselves.

The Government has also indicated that livestreaming and stranger-contact functionality will receive heightened restrictions for older teenagers.

This reveals the deeper policy theory.

The concern is no longer merely harmful content.

It is increasingly harmful design.

The law has discovered that software architecture can influence behaviour

Traditional child-protection regulation focused heavily upon what children could see.

Pornography.

Violence.

Illegal material.

Drug content.

Self-harm material.

That remains important.

But modern platform regulation increasingly asks a second question:

What does the interface encourage the child to do?

Scroll again.

Watch one more video.

Refresh.

Check the notification.

Maintain the streak.

Stay awake.

Respond immediately.

Return because somebody has reacted.

Allow strangers to contact you.

Broadcast yourself live.

The Government’s July 2026 approach to curfews, autoplay and continuously personalised feeds expressly reflects concern about these engagement mechanisms.

This is a major conceptual movement in law.

Regulators are beginning to treat digital architecture as something capable of creating legally relevant risk.

An addictive design feature is not a packet of cigarettes—but the analogy is becoming tempting

One should resist crude comparisons.

Social media is not tobacco.

It produces genuine benefits.

Children communicate through it.

Learn through it.

Develop identities through it.

Participate culturally through it.

Maintain friendships through it.

Find information through it.

Indeed, the Government’s own consultation material noted that almost all surveyed 13- to 17-year-olds reported some benefit from being online, including assistance with schoolwork, maintaining friendships, finding help concerning problems and learning new skills.

That factual complexity matters.

The regulatory problem is not that social media has no value.

It is that commercially valuable digital products can combine genuine social utility with engagement mechanisms capable of imposing costs upon young users who are still developing behavioural self-regulation.

Law is therefore confronting the same question it encounters across consumer regulation:

When does persuasive product design become exploitative product design?

The Government actually tested different forms of restriction

The 2026 policy was accompanied by an unusually interesting qualitative pilot involving young people aged 13 to 17.

Participants experienced one of three interventions: a 15-minute daily limit, an overnight social-media curfew, or complete removal of social-media applications. The study expressly cautioned that it was exploratory and not statistically generalisable, but the findings are still instructive.

Young people and families reported perceived improvements in areas including sleep, concentration, mood and family interaction. The overnight curfew was generally regarded as the most manageable intervention and produced the most consistently reported sleep benefits. Full app removal generated some of the clearest reports of improved focus and calm—but also the greatest social disruption and was the model families were least inclined to retain in its original form. Workarounds occurred throughout the pilot.

That is almost a perfect miniature of the legal problem.

The stronger the prohibition, the larger the potential protective benefit.

But also, potentially, the larger the interference with ordinary social life.

Law must locate the proportionate point.

A social-media account is not merely entertainment to many teenagers

This point should be taken seriously even by those strongly supportive of restrictions.

For adults who grew up without social media, it is easy to say:

“Children managed perfectly well before Instagram.”

Historically true.

Socially incomplete.

A teenager’s peer network may now organise itself through digital infrastructure.

Plans.

Homework.

Friendship groups.

Sports teams.

Cultural participation.

School gossip.

Event invitations.

Class discussions.

Identity.

Romantic relationships.

The Government’s pilot found that complete removal could create a pronounced sense of exclusion where particular platforms formed part of everyday peer communication. It also found that messaging alternatives were important in making restrictions tolerable.

A nationwide prohibition may reduce some of this exclusion because everyone below the relevant age should theoretically face the same rule.

But implementation will never be perfectly uniform.

Some children will circumvent it.

Others will have older siblings.

Some will use foreign services.

Some parents may assist circumvention.

Some platforms will be more effective than others.

The social cost cannot simply be assumed away.

Children possess rights as well as vulnerabilities

This is where the legal debate becomes richer than ordinary political rhetoric.

The United Nations Convention on the Rights of the Child does not treat children merely as objects requiring adult protection.

Article 13 protects children’s freedom to seek, receive and impart information and ideas. Article 16 protects against arbitrary or unlawful interference with privacy. Article 17 recognises the significance of children’s access to information and material through mass media.

The UN Committee on the Rights of the Child has expressly recognised that children’s rights continue within the digital environment and has developed General Comment No. 25 around that proposition.

Child safety is therefore not the only right in the equation.

The law must consider:

protection;

privacy;

expression;

information;

participation;

development;

and the child’s evolving autonomy.

There is no contradiction in protecting all of them.

But the balance requires care.

“For the children” cannot end the legal analysis

Some of the weakest legislation in history has been defended through unanswerable moral propositions.

  • Protect children.
  • Prevent crime.
  • Protect national security.
  • Stop terrorism.
  • Prevent fraud.
  • Those are legitimate objectives.
  • They do not automatically establish that every mechanism adopted in pursuit of them is proportionate.
  • A mature legal system asks a second set of questions.
  • Does the measure actually work?
  • Is it broader than necessary?
  • What information must be collected?
  • Who receives that information?
  • How long is it retained?
  • What happens when the system makes mistakes?
  • Can affected people challenge those mistakes?
  • Are less intrusive alternatives available?
  • Will users be driven towards less regulated services?
  • Does the law disproportionately affect vulnerable groups?
  • These are not objections to child protection.
  • They are what responsible child protection looks like.

The European human-rights framework will remain relevant

The United Kingdom also remains subject to the European Convention on Human Rights.

Article 8 protects private and family life, while Article 10 protects freedom of expression, including receiving and imparting information. Both rights are qualified rather than absolute and may be restricted where the relevant legal and proportionality requirements are satisfied.

I would therefore be cautious about confidently predicting some future human-rights challenge to the social-media restrictions before the final regulations even exist.

But it is equally clear that implementation choices concerning universal age verification, data collection, anonymous speech and access to information will engage familiar Convention principles.

The constitutional question is not:

“Can government ever restrict children’s access to online services?”

Plainly it can.

The more difficult question is:

“How intrusive may the mechanism for doing so become before the protective measure creates a disproportionate burden upon everyone else’s privacy or expression?”

That is where age assurance becomes central.

A prohibition without age assurance is largely theatre

Suppose Parliament says:

“No social media under 16.”

A service asks:

“Are you 16?”

The thirteen-year-old clicks:

Yes.

The legal prohibition exists.

The practical prohibition does not.

The British Government has therefore made clear that the planned restrictions will be backed by stronger age-assurance requirements. Ofcom is conducting a rapid assessment of what “highly effective” age assurance for the over-16 threshold should look like and intends to report to Parliament by the end of October 2026.

The practical success of the entire policy may turn on that technical work.

Britain already possesses a laboratory for age verification

This is not the country’s first encounter with robust age checks.

The Online Safety Act has already required highly effective age assurance in connection with online pornography and certain child-safety obligations.

Ofcom’s existing guidance identifies several techniques capable, depending upon implementation, of satisfying its high-effectiveness standard, including open-banking checks, photo-ID matching, facial age estimation, mobile-network-operator checks, credit-card checks, digital identity services and email-based age estimation. It regards simple self-declaration as inadequate.

Those tools provide a technical vocabulary for the social-media debate.

They also reveal the privacy problem.

Every age check asks for information

Ofcom expressly states that age-assurance methods involve personal-data processing and should be implemented in a manner consistent with privacy and data-protection obligations.

That sounds obvious.

Its implications are not.

If the platform already knows everything about the user, estimating age may appear straightforward.

But perhaps the whole reason the user wishes to remain anonymous is that they do not want the platform to know very much.

A person may wish to read political discussions without linking them to legal identity.

A domestic-abuse survivor may use a pseudonym.

A whistleblower may want separation from employment identity.

A person exploring a sensitive health condition may not want a platform connecting that interest to a passport.

A teenager seeking confidential support may have legitimate reasons not to involve parents immediately.

Age-gating therefore sits awkwardly beside anonymity.

The legal objective should be proof of age—not proof of identity

This distinction should become one of the foundational principles of age-assurance law.

A platform ordinarily does not need to know:

“This user is Jane Smith, born in Manchester on 14 February 1985 and living at 22 Example Street.”

It needs to know:

“This user is over 16.”

Those are radically different informational claims.

If technology can provide reliable proof of the second without unnecessarily disclosing the first, law should generally prefer that architecture.

The regulatory concept should therefore be:

attribute verification rather than identity extraction.

Age is the relevant attribute.

Identity may be incidental—or, in some circumstances, unnecessary.

This is where privacy-enhancing age assurance becomes extremely important

The ideal age-verification system would tell the service:

This person satisfies the required age threshold.

It would not necessarily tell the service:

Here is the person’s complete identity document, home address, date of birth and legal name.

Modern digital-identity architectures can theoretically separate those functions.

A trusted intermediary could verify identity or age and return a simple credential establishing that the person satisfies a threshold.

The service itself would not necessarily require possession of the underlying documentary evidence.

That distinction should influence both procurement and regulation.

The Government should not measure success merely by asking whether children are excluded.

It should also ask how much additional personal information society had to expose in order to exclude them.

Otherwise child safety could accidentally create an identity infrastructure for everyone

This is the dystopian version of the policy.

Every adult wishing to speak online must prove identity.

Every social-media account becomes connected to government documentation.

Every political comment becomes potentially attributable.

Every user loses meaningful anonymity.

Platforms accumulate more sensitive information.

A data breach becomes vastly more dangerous because hacked social-media records contain identity documents or biometric materials.

That outcome is not inevitable.

But it illustrates why privacy safeguards must be designed at the beginning.

It would be a bitter irony if legislation designed to make children safer created unnecessarily powerful databases of adults.

The ICO is already making precisely this point

The Information Commissioner’s Office has supported stronger age assurance while simultaneously insisting that data-protection obligations continue to apply.

Following the June announcement, the ICO emphasised that online services remain subject to existing data-protection law and the Children’s Code while the Government develops its new legislation. It has also been working with Ofcom on the forthcoming assessment of highly effective age assurance for the age-16 threshold.

Earlier in March 2026, the ICO called upon major social-media and video-sharing platforms to move beyond easily circumvented self-declared ages while remaining accountable for their processing of children’s information.

This is the correct regulatory posture.

Safety and privacy should not be presented as rival bureaucracies fighting over the same website.

Good age assurance should attempt to advance both.

The more dangerous the service, the stronger the permissible check may be

Proportionality should also matter.

Accessing an adult pornography service creates one kind of age-assurance problem.

Reading a newspaper creates another.

Opening a bank account creates another.

Joining a gaming platform creates another.

Using a private messaging application creates another.

The degree of identity assurance reasonably required should correspond with the nature and seriousness of the risk.

The ICO’s age-assurance materials similarly emphasise risk-based implementation rather than insisting upon the same intrusive proof for every online activity.

That principle becomes crucial if age checks spread across the internet.

Britain must avoid turning every website into a passport checkpoint

This is one of the dangers of regulatory expansion.

A social-media ban for under-16s may be politically popular.

Then gaming receives age verification.

Then AI chatbots.

Then forums.

Then news comment sections.

Then marketplaces with community features.

Then another category.

Eventually the user confronts repeated age checks everywhere.

The individual privacy burden may become substantial even where each intervention considered separately appears justified.

Regulators therefore need to think not merely about individual compliance systems but about cumulative digital identification.

Ofcom itself recognises that no age-assurance method is perfect

In July 2026, Ofcom expressly acknowledged that no single age-assurance process eliminates circumvention risk.

It suggested that stronger protection may require multiple layers across the ecosystem—including platforms, app stores, operating systems and devices.

That may prove correct.

It also changes the character of the internet.

If the platform checks age, the app store knows age, the operating system knows age and the device carries an age credential, the architecture may become more effective.

It may also become much more structurally capable of controlling access.

Again, power created for good purposes requires governance.

Device-level age assurance could be transformative

Consider an alternative architecture.

A parent establishes a child’s age when the device is initially configured.

The operating system holds an age credential.

Applications receive only the information necessary to determine which version of a service should operate.

The social network never needs a passport.

The application store can restrict age-inappropriate downloads.

The device can apply age-sensitive defaults.

This may reduce repetitive identity verification.

It could also create a very powerful centralised control point.

Who governs the credential?

Can parents override it?

Can older teenagers correct errors?

What happens to shared household devices?

What happens if the device is second-hand?

Can government require additional services to consult the credential later?

There are no purely technical answers.

Architecture distributes legal power.

Facial age estimation presents its own difficulties

Facial age estimation is attractive because it may avoid formal identity documentation.

A user provides an image.

Software estimates whether the face is likely to belong to someone above the required threshold.

But the apparent simplicity conceals legal questions.

How accurate is the model?

Does accuracy vary between demographic groups?

How close to 16 can it reliably distinguish?

What happens to the image afterwards?

Is it retained?

Does it create biometric information?

Can the user challenge a false classification?

What alternative exists for somebody unwilling or unable to use the method?

Is a teenager who looks older incorrectly permitted?

Is a 25-year-old with youthful features repeatedly blocked?

Age assurance must be fair as well as effective.

Ofcom’s existing standard expressly describes effective methods in terms of technical accuracy, robustness, reliability and fairness.

Sixteen is much harder to verify than eighteen

There is also a practical problem which Ofcom has specifically recognised.

Some existing age-assurance techniques designed to determine adulthood work poorly for a 16-year threshold.

A credit card, for example, may help establish that a person is an adult because conventional cards are associated with adult eligibility.

It does not efficiently distinguish a 16-year-old from a 15-year-old.

Ofcom’s July 2026 report therefore noted that some techniques used for adult age gates will not work for distinguishing 16- and 17-year-olds and that other methods will be required.

The proposed social-media restriction is therefore technically more difficult than an ordinary “18+” gate.

Age inference is also being treated with caution

Some platforms attempt to infer age from behaviour.

What content does the account watch?

How long has it existed?

Who are the user’s friends?

What language is used?

What signals emerge from activity?

Ofcom has expressed serious reservations about relying upon age inference for access prohibition because inference may require the child to have joined and used the service long enough for the system to develop a view—by which point the prohibited access has already occurred.

This is a revealing example of the difference between:

identifying children once they are inside;

and

keeping children outside in the first place.

The new British model requires the latter.

Circumvention will become the inevitable political test

Within days of any effective restriction, tutorials will circulate.

VPNs.

Borrowed accounts.

Older siblings.

False photographs.

Alternative app stores.

Foreign services.

Modified clients.

Shared devices.

Proxy websites.

Children are inventive.

The Government explicitly recognises concerns surrounding VPN circumvention and has been researching children’s use of VPNs while noting that VPN technology also has legitimate privacy and freedom-of-expression uses.

This is exactly the right concern.

Do not criminalise the VPN because a teenager discovered one

Virtual private networks have legitimate functions.

Cybersecurity.

Remote working.

Privacy.

Travel.

Research.

Accessing corporate networks.

Protecting communications on untrusted Wi-Fi.

Avoiding certain forms of surveillance.

The fact that a technology can circumvent geographic or age restrictions does not make the technology intrinsically unlawful.

Governments should be extremely cautious about solving one regulatory problem by attacking general-purpose privacy tools.

This is the same principle discussed in our analysis of intimate deepfake generators.

Law should distinguish between technology capable of misuse and technology designed substantially around misuse.

Perfect compliance is not the correct measure

A law does not fail merely because some people evade it.

Speed limits remain useful despite speeding.

Tax law remains useful despite evasion.

Alcohol-age restrictions remain useful despite false identification.

Australia’s eSafety Commissioner has made essentially this point in defending its own social-media minimum-age framework.

The proper questions are empirical.

Does access meaningfully decline?

Does harm decline?

Do children migrate somewhere worse?

Do age checks create unacceptable privacy costs?

How often do adults suffer false blocks?

Do vulnerable children lose beneficial support networks?

Does circumvention become widespread enough to defeat the policy’s objective?

Success should be measured against outcomes rather than regulatory perfection.

Australia is the obvious comparison because Britain is deliberately copying parts of its model

Australia’s social-media minimum-age obligation took effect on 10 December 2025.

Age-restricted platforms must take reasonable steps to prevent Australians under 16 from creating or retaining accounts. The regulatory obligation falls principally upon the platforms; under-16 users and their parents are not themselves subjected to penalties merely because a child accesses an account.

The Australian framework currently treats services including Facebook, Instagram, Snapchat, Threads, TikTok, Twitch, X, YouTube, Kick and Reddit as age-restricted, while standalone messaging and many gaming services fall outside the central restriction.

Corporate penalties can reach AUD 54.6 million for failure to take the reasonable steps required by the regime.

That is the model Britain is now openly studying.

Australia wisely places responsibility on the platform rather than criminalising the child

This is an important design choice.

The fourteen-year-old should not become an offender because she managed to open Instagram.

Nor should parents generally face criminal penalties because their child circumvented the technology.

The party possessing the engineering capability, user data and commercial control is the platform.

That allocation follows practical capacity.

The regulator asks the company:

What reasonable steps did you take?

That is more sensible than creating a new class of teenage cyber-offenders.

Britain should retain the same philosophy.

Australia’s early figures are striking—but should not be overinterpreted

In January 2026, Australia’s eSafety Commissioner reported that major platforms had restricted access to approximately 4.7 million accounts identified as belonging to under-16s in the early implementation period. The regulator simultaneously cautioned that it was far too early to determine full compliance or the policy’s long-term impact.

That caveat is essential.

An account-removal number proves that platforms took action.

It does not prove that:

children stopped using social media;

mental health improved;

bullying declined;

sleep improved;

children became safer;

or no displacement occurred.

Policy evaluation must distinguish output from outcome.

Deleting an account is an output.

Improving childhood is an outcome.

Australia’s own regulator calls it a delay rather than an absolute ban

There is an interesting linguistic distinction in the Australian implementation.

eSafety describes the policy as a delay to having social-media accounts rather than a complete prohibition on children accessing every piece of social-media content.

Under-16s may still encounter publicly available material which does not require an account, depending upon the service.

This distinction may become relevant in Britain.

Does “social-media ban” mean:

no account?

No personalised feed?

No posting?

No interaction?

No viewing?

No recommendation?

No logged-in access?

The legal answer should come from the final regulations, not political shorthand.

Britain presently appears to contemplate something stronger than a simple Australian copy

The June announcement described the British package as extending beyond the core social-media restriction by targeting harmful functionality across other services, including livestreaming and stranger communication.

By July, the Government had also announced default curfews and restrictions upon engagement features for 16- and 17-year-olds.

Britain is therefore using Australia as a starting point rather than merely photocopying its statute.

That is prudent.

Comparative law works best when jurisdictions borrow principles rather than text.

The strongest argument for the restriction may actually be collective-action failure

Parents frequently face an impossible coordination problem.

One parent may think:

My thirteen-year-old should not use this service.

The child replies:

Everyone at school is on it.

The parent can prohibit access.

But that decision may impose social exclusion uniquely upon their child while everyone else’s parents continue permitting use.

Even parents who privately dislike the platform may therefore allow it because unilateral restraint appears costly.

A nationwide age floor changes the social expectation.

Nobody is supposed to be there.

This is precisely why the Government repeatedly refers to creating a new social norm.

The legal intervention can therefore be understood not merely as paternalism but as solving a coordination problem families cannot easily solve alone.

That argument is stronger than “parents should simply parent”

The phrase sounds attractive.

Parents should indeed take responsibility.

But parental responsibility does not eliminate corporate responsibility.

A parent cannot inspect a platform’s recommender algorithm.

Cannot redesign the infinite scroll.

Cannot remove predatory users globally.

Cannot know every piece of data processed.

Cannot control advertising architecture.

Cannot enforce age limits across an entire school peer group.

Cannot independently audit content moderation.

Parental authority operates at household level.

Platform architecture operates at population level.

Both matter.

Yet government should not use corporate responsibility to erase family judgment entirely

There is also a legitimate counterargument.

A mature fifteen-year-old may use a social network carefully.

Another may depend upon online communities for cultural, educational or disability-related support.

A parent may reasonably believe supervised access is beneficial.

A blanket prohibition removes some of that parental discretion.

The Government’s consultation itself recorded concerns about social isolation, digital literacy, access to supportive communities, privacy and children’s autonomy, as well as strong support for greater protection.

That is why the debate should resist absolutism.

The existence of real harm does not mean every child experiences identical harm.

Vulnerable children may be affected differently

This is one of the most serious concerns.

Some children possess abundant offline support.

Stable families.

Friends nearby.

Sport.

Schools.

Safe communities.

Others do not.

For a socially isolated, disabled or otherwise vulnerable young person, an online community can sometimes provide information and connection which may be difficult to obtain locally.

The Government’s consultation acknowledged concerns that restrictions could have disproportionate consequences for marginalised children who rely upon online communities for support and social connection.

A serious regulatory framework should therefore ask what safe alternatives remain.

Protection should not become isolation.

Messaging exemptions may prove critical

This explains why excluding services such as WhatsApp and Signal from the intended core prohibition may be more important than it first appears.

Young people denied public social-media accounts would retain channels for communicating with known friends and family.

The Government’s own trial suggested that removal of social-media applications was much more tolerable where ordinary messaging remained available.

That points towards an important regulatory distinction:

public algorithmic sociality is not the same thing as private communication.

A law may restrict the former without necessarily severing the latter.

The internet should not become legally “adult only”

This is another vital boundary.

The Government states that children will retain access to online learning, news, games and means of staying in contact, and that dedicated educational services are not intended to be captured by the social-media prohibition.

That is essential.

The internet is now part of civic, educational and cultural life.

A child-safety regime should distinguish:

protecting children online

from

removing children from online life.

Those are not synonymous policies.

The UN children’s-rights framework similarly recognises that digital protection should coexist with children’s access to information, expression and participation.

Age assurance may become a new regulated industry of its own

If governments across the world begin requiring reliable age gates, specialist providers will emerge at scale.

They may offer:

  • age estimation;
  • digital credentials;
  • identity verification;
  • device-level age signals;
  • mobile-network confirmation;
  • bank-based verification;
  • or privacy-preserving age tokens.

This could become a substantial global compliance industry.

And whenever a new compliance intermediary appears, lawyers should ask:

Who regulates the verifier?

What accuracy standard applies?

What happens when it is wrong?

Who is liable for a breach?

Can information be reused?

Can the verifier profile users?

How long may it retain records?

Can law enforcement obtain the data?

Can the provider sell behavioural information?

Does the social-media company receive raw identity evidence or merely an age result?

The age verifier can itself become a powerful data controller.

Outsourcing age verification does not outsource legal responsibility completely

Ofcom has already stated in the context of existing age assurance that a regulated service remains responsible for ensuring the process is sufficiently effective even where the mechanics are outsourced to a third-party provider.

That is an important commercial point.

A platform cannot simply say:

“Vendor X checked the age; any mistake belongs to them.”

The contract between platform and verification provider may allocate liability privately.

It does not necessarily alter the platform’s public-law obligation to comply with the regulatory regime.

Procurement becomes part of compliance.

Contracts for age assurance will therefore become unusually important

International platforms procuring these services should examine much more than price.

Accuracy.

False-positive rates.

False-negative rates.

Demographic performance.

Data location.

Retention.

Security.

Audit rights.

Sub-processors.

Biometric processing.

Incident notification.

Algorithm changes.

Regulatory cooperation.

Deletion.

User appeals.

Service availability.

Circumvention detection.

The age-assurance provider may become a critical regulatory supplier.

If the provider fails, the platform’s statutory compliance may fail with it.

There will be discrimination questions

Age-estimation systems inevitably classify people.

Classification creates error.

Error may not distribute evenly.

If one demographic group is systematically judged younger or older than another, access rights may vary by appearance.

That becomes more troubling close to the threshold.

Imagine two seventeen-year-olds.

One is correctly recognised as over 16.

The other is repeatedly estimated at 15.

What appeal exists?

Must the second person then submit more intrusive identity documents?

Does the burden of proving adulthood fall disproportionately upon particular groups?

The legal concept of “fair” age assurance must therefore include more than aggregate accuracy.

False positives matter even if child protection is the principal objective

Regulators understandably focus upon the dangerous error:

a thirteen-year-old incorrectly classified as sixteen.

But there is another error:

a twenty-year-old incorrectly classified as fifteen.

That adult loses access to lawful communication because the system made a mistake.

At scale, even a small error rate can affect many people.

Procedural justice therefore matters.

Users need practical routes to correct classification without enduring absurd bureaucratic burdens.

Safety systems themselves require due process.

Anonymous political speech deserves particular sensitivity

Consider a sixteen-plus user participating anonymously in political debate.

If access requires providing government identity to the platform, the nature of the speech environment changes.

A person may reasonably fear employers, governments, family members or political opponents discovering their identity.

Article 10 of the European Convention protects receiving and imparting information, and privacy interests under Article 8 can also become relevant to online identification structures.

This does not mean an age gate is automatically unlawful.

It means the method chosen matters constitutionally.

An age token saying “over 16” interferes differently from mandatory passport-linked social media.

The least-data principle should therefore sit at the heart of implementation

For each age-checking method, the question should be:

What is the minimum information genuinely required to achieve the protective purpose?

If a face can be analysed locally and discarded, why retain it?

If a digital-identity service can communicate only the age threshold, why disclose the date of birth?

If a mobile operator can return “over 16”, why transmit the subscriber’s address?

If an account has existed demonstrably for longer than sixteen years, what additional proof is necessary?

The Government’s own fact sheet already contemplates that some longstanding adult accounts or accounts carrying other reliable age signals may not require entirely fresh verification.

That is a good direction.

The legal objective is age assurance, not data accumulation.

Data breaches could otherwise become much more damaging

Imagine a social network which previously stored:

email address;

password;

posts;

and behavioural data.

Now add:

passport;

date of birth;

facial imagery;

government ID number;

or verification records.

The platform has become a richer target.

Cybersecurity consequences should therefore form part of regulatory proportionality.

Every additional item of identity evidence collected for safety purposes becomes another item which must itself be kept safe.

Law should not solve a child-protection problem by creating an avoidable identity-theft problem.

There is also a competition-law dimension

Large platforms can absorb expensive age-assurance systems.

A start-up may struggle.

If compliance requires sophisticated third-party verification, extensive auditing and regulatory reporting, new entrants may face higher barriers.

This does not mean safety requirements should be abandoned.

It means regulators should ensure requirements are proportionate to risk and that compliant technologies are accessible to smaller companies.

Otherwise legislation designed to discipline Big Tech may accidentally strengthen Big Tech by making entry more expensive.

This issue connects directly with the broader competition concerns examined in our earlier commentary on European digital gatekeepers.

App stores and operating systems may eventually become enforcement points

Ofcom’s July report expressly contemplated layered protection involving not only individual services but app stores, operating systems and devices.

This is potentially transformative.

Apple and Google could become part of the practical enforcement architecture.

An age-aware app store might refuse downloads.

A device could block certain functionality.

An operating system could transmit age credentials.

That could reduce repetitive checks.

But it also concentrates control.

The companies operating the basic smartphone infrastructure may become quasi-regulators deciding which digital spaces a user can reach.

Competition, privacy and child safety would then converge.

The age-gate debate is therefore also a debate about who governs the device

Parent?

Platform?

Operating-system provider?

App store?

Government?

Age-verification vendor?

Child?

Each has some legitimate interest.

The difficult work of legislation lies in defining their respective authority.

A thirteen-year-old should not possess absolute autonomy over exposure to every online risk.

A government should not possess unlimited authority over every adult’s digital identity merely because some users are thirteen.

The device itself becomes the battleground where these claims meet.

Pakistan should watch this debate extremely carefully

Pakistan has not adopted a comparable national prohibition preventing under-16s from holding social-media accounts.

Its current approach is materially different.

The Pakistan Telecommunication Authority has emphasised child online protection, parental guidance, digital literacy and cooperation with major platforms. PTA maintains child-online-safety guidance and parental resources, and in October 2025 collaborated with Meta on the introduction of Instagram Teen Accounts in Pakistan, under which under-16 users receive stronger default protections.

In July 2026, PTA and Meta signed a further Letter of Intent directed towards youth online safety, digital literacy, policy dialogue and exchange of international good practice.

That is a softer regulatory model than Britain or Australia.

At present, it relies substantially upon platform design, awareness, parental controls and existing online-content regulation rather than a statutory under-16 social-media exclusion.

Pakistan should not rush into a ban simply because richer jurisdictions are doing so

There will inevitably be calls for imitation.

Australia has done it.

Britain is doing it.

Therefore Pakistan should do it.

That reasoning is insufficient.

Pakistan should study the experiment first.

Its digital circumstances differ substantially.

Device sharing may be more common.

Formal identity systems operate differently.

Payment-card penetration differs.

Digital literacy varies.

Children use phones for education as well as entertainment.

Households may share accounts.

Internet access itself remains uneven.

Enforcement capacity differs.

Pakistan also remains without the same comprehensive mature personal-data-protection framework that surrounds British age-assurance deployment.

The privacy cost of mandatory age verification therefore requires especially careful thought.

Pakistan’s CNIC infrastructure makes one tempting solution particularly dangerous

A policymaker might say:

“Easy. Link every social-media account to CNIC.”

That would certainly simplify age verification.

It would also fundamentally alter the character of online anonymity in Pakistan.

Every political discussion.

Every whistleblower.

Every person discussing sensitive social matters.

Every anonymous critic.

Every survivor seeking advice.

Every user who simply does not wish a commercial platform to know their legal identity.

The cure would therefore extend far beyond the disease.

A national identity card may prove that somebody is over 16.

That does not mean a social-media platform should necessarily receive or store the national identity number.

The distinction between verifying an attribute and disclosing identity is particularly important in Pakistan.

Pakistan could use age tokens rather than identity disclosure

A more sophisticated future model would allow a trusted service to confirm age and transmit only:

under 16

or

16+

or perhaps:

18+

The receiving platform would not need the underlying identity document.

This is exactly the type of privacy-preserving regulatory architecture Pakistan should investigate before adopting any statutory age requirement.

Pakistan has an opportunity to avoid mistakes made elsewhere because it is not first.

That is an advantage.

Pakistan should also examine platform design before considering platform prohibition

The British policy itself contains an important clue.

Much of the concern concerns features:

stranger contact;

livestreaming;

autoplay;

personalised feeds;

overnight use;

and addictive engagement patterns.

Pakistan might therefore obtain substantial benefit from requiring stronger child defaults without immediately imposing a universal account prohibition.

An under-16 account could potentially have:

private-by-default settings;

no adult stranger messaging;

restricted livestreaming;

reduced algorithmic profiling;

no personalised advertising;

sensitive-content filtering;

night-time limits;

and parental or age-appropriate controls.

Meta’s Teen Accounts initiative in Pakistan already demonstrates the beginnings of this philosophy.

Regulation can shape the environment without necessarily excluding the child entirely.

There is a profound difference between “social media for children” and “adult social media accessed by children”

This distinction deserves much more attention.

Much existing social media was designed around adult commercial incentives and then retrospectively modified because children used it.

Perhaps the better question is:

What would a social platform look like if its architecture had genuinely been designed for fourteen-year-olds from the beginning?

No behavioural advertising.

No stranger contact by default.

No public follower counts.

No endless autoplay.

No manipulative notifications.

Limited data collection.

Strong reporting.

Age-appropriate recommendation.

Restricted livestreaming.

Transparent moderation.

Time-aware design.

If industry cannot build such environments voluntarily, regulation may eventually demand them.

The future may not be “children on social media” versus “children banned from social media”.

It may be different social media for different stages of development.

Britain’s approach to 16- and 17-year-olds already points towards graduated digital adulthood

The July 2026 proposals are particularly interesting because older teenagers are not simply placed into the adult internet.

They receive more autonomy but continue with protective defaults.

That resembles other areas of law where capacity develops progressively rather than appearing instantaneously.

A seventeen-year-old can understand more than a thirteen-year-old.

A fifteen-year-old may understand more than a nine-year-old.

Regulation which treats everyone below eighteen identically risks ignoring developmental reality.

The concept of graduated digital adulthood may eventually become far more important than one fixed age.

We should also ask whether age sixteen is scientifically or legally magical

It is not.

Every age threshold is necessarily somewhat artificial.

Different legal systems assign different ages to:

criminal responsibility;

sexual consent;

marriage;

driving;

voting;

alcohol;

employment;

medical decision-making;

and contractual capacity.

The Government’s consultation revealed debate over whether 16 was the correct social-media threshold, although substantial public support existed for a higher minimum age.

The relevant policy question should therefore be functional.

What level of development is necessary for the risks created by this type of service?

A single universal age may be administratively convenient.

Different features may justify different thresholds.

There may eventually be an age-rating system for digital functionality

We already accept age classifications for films and games.

Why should every social-media function have the same digital age?

Perhaps:

private messaging with known contacts is suitable earlier;

public livestreaming later;

direct messages from unknown adults later still;

commercial behavioural profiling later;

certain AI companion functionality adult only.

Britain’s current package is already moving in this direction by distinguishing whole services from specific functions and by proposing different rules for under-16s and 16- to 17-year-olds.

The long-term future may therefore be more granular than “social media: 16”.

AI companions are already entering the same regulatory field

The June announcement also addressed AI “romantic companion” services, with the Government proposing an 18+ threshold for systems designed to simulate sexual or intimate relationships and restrictions upon comparable functionality for minors more generally.

This matters because children’s digital lives are already moving beyond traditional social networks.

A future teenager may spend more time interacting with an AI companion than posting on Instagram.

A social-media law written only around 2020-era platforms will age quickly.

The statutory power to regulate specified internet services and functions is therefore strategically important.

Technology evolves faster than legislative labels.

Pakistan should likewise avoid writing yesterday’s internet into tomorrow’s statute

If Pakistan ever legislates specifically on child access, the law should not consist of a list:

Facebook.

TikTok.

Instagram.

X.

By the time litigation concludes, children may have moved elsewhere.

The statute should define relevant services by function and risk.

Social interaction.

Public posting.

Algorithmic recommendation.

Stranger contact.

Livestreaming.

Commercial profiling.

Synthetic companions.

The law should remain capable of applying even when the next popular platform has a name nobody currently knows.

The enforcement question will become international immediately

Most major platforms affected by the British proposal are headquartered outside Britain.

That is ordinary digital regulation now.

National law imposes duties upon multinational systems.

Regulators must then possess practical leverage.

Ofcom already operates an extensive enforcement framework under the Online Safety Act.

The new restrictions will sit within that broader regulatory ecosystem rather than depending solely upon voluntary cooperation.

Pakistan faces the same structural problem whenever it regulates foreign platforms.

Domestic legislation is useful only if there exists a credible method for obtaining compliance.

Blocking should remain the last rather than first regulatory instinct

Countries with weaker enforcement capacity sometimes reach quickly for blocking powers.

The attraction is obvious.

Platform refuses.

State blocks platform.

But blocking is a crude instrument.

Millions of lawful users are affected.

Businesses relying upon the service suffer.

Journalists lose distribution.

Political speech may be restricted.

VPN use rises.

Technical circumvention follows.

Diplomatic and commercial consequences arise.

A mature online-safety regime should therefore prioritise structured compliance obligations, financial penalties, regulatory engagement, transparency duties and targeted remedies before whole-service blocking wherever practicable.

Digital regulation is stronger when it can govern a service rather than merely switch it off.

Schools also need a role

No statute can teach digital judgment by itself.

Children eventually become adults.

At sixteen, seventeen or eighteen they enter the digital environment the law previously restricted.

If regulation merely postpones exposure without building digital literacy, the young person arrives later but not necessarily wiser.

The British consultation itself recognises education and digital skills as important complements to regulation.

Pakistan should take this particularly seriously.

Media literacy.

Scam recognition.

Privacy.

Consent.

Deepfake awareness.

Online grooming.

Cyberbullying.

Advertising literacy.

Algorithmic manipulation.

Digital reputation.

These belong increasingly within education.

A ban cannot teach a child what an algorithm is doing

That is one limitation of access restrictions.

At some point the teenager will encounter recommendation systems.

They should understand:

why outrage appears repeatedly;

why engagement changes the feed;

why advertisements feel personally targeted;

why influencer content may be commercial;

why viral claims are not necessarily true;

why screenshots persist;

why strangers are not always who they claim to be;

why artificial intelligence can fabricate photographs and voices.

Regulation may create breathing room.

Education must use it.

Parents need digital literacy too

Children are not the only people confused by platform design.

Many parents do not understand:

privacy settings;

age controls;

recommendation systems;

vanishing messages;

location sharing;

AI companions;

encrypted messaging;

or the difference between deleting an application and deleting an account.

A policy which tells parents:

“We banned social media for your child”

may create false confidence if the child simply migrates to another service the parent understands even less.

Public education should therefore accompany prohibition.

The policy should be assessed for displacement, not merely compliance

This is perhaps the most important empirical question after implementation.

Where do children go?

If they leave Instagram and spend more time playing football, wonderful.

If they move from a heavily regulated service to an obscure encrypted platform full of strangers, the risk may increase.

If they shift from social media to addictive gaming, the behavioural problem may remain.

If they migrate into unregulated AI companion services, a new harm may emerge.

If they simply consume social content without accounts, some risks diminish while others persist.

Australian regulators are expressly monitoring migration and circumvention as part of implementation.

Britain should do the same.

Regulation should follow the child, not celebrate the deleted account

A government can announce:

Ten million accounts removed.

That sounds impressive.

But suppose most users reappear elsewhere.

The number has political value and limited regulatory meaning.

The real measurements should concern:

sleep;

bullying;

grooming;

sexual exploitation;

harmful content exposure;

social isolation;

school concentration;

privacy;

mental wellbeing;

fraud;

and the use of replacement services.

Child protection should measure children.

Not dashboards.

Australia’s two-year evaluation is therefore particularly valuable

Australia’s eSafety regulator is conducting longitudinal evaluation rather than claiming that early account restrictions already establish success. Its first 2026 research expressly described itself as an early snapshot incapable of establishing the policy’s long-term effectiveness.

That intellectual humility is important.

Technology policy is full of confident claims based upon inadequate evidence.

Britain should treat Australia as a live experiment, not a political slogan.

Pakistan has even greater reason to wait for evidence.

The British pilot contains one particularly useful lesson: moderate interventions may sometimes work better

The Government’s own exploratory study found the overnight curfew comparatively manageable, widely accepted and associated with consistent perceived sleep benefits, whereas complete removal generated greater social disruption.

That does not prove that a nationwide prohibition is wrong.

The intervention settings are not directly comparable.

But it raises a serious regulatory question:

Could targeted design restrictions achieve a substantial proportion of the protective benefit at lower social and privacy cost?

That question should remain alive even after a policy announcement.

Good government can revise means while retaining objectives.

The strongest version of the British policy is therefore not “ban children from the internet”

It is something more defensible:

delay access to the highest-risk forms of algorithmic social networking while redesigning the wider online environment around children’s developmental needs.

The June and July 2026 announcements contain elements of precisely that broader architecture.

Whether implementation ultimately achieves that subtlety remains to be seen.

What should social-media businesses be doing now?

Businesses potentially affected by the British regime should not wait until the first regulations appear and then begin thinking about age.

They already operate within the Online Safety Act and UK data-protection environment.

The prudent exercise now is to understand where age signals enter the product, how reliable they are, what information is collected, where that information is stored, which age-assurance vendors are used, how false classifications are challenged, how child accounts are identified, which features can be disabled by age, how existing underage accounts would be treated and what evidence the company can provide to Ofcom concerning effectiveness. Existing child-safety and data-protection duties remain applicable while the new regime is being developed.

The engineering team should already be speaking to the legal team.

What should age-assurance providers be doing?

This is a major commercial opportunity—but also a regulatory responsibility.

Providers should be capable of demonstrating accuracy rather than merely marketing it.

They should understand UK GDPR.

Data minimisation.

Security.

Deletion.

Biometric implications.

False positives.

False negatives.

Demographic fairness.

Accessibility.

Auditability.

Sub-processors.

Cross-border transfers.

A company selling age assurance is not merely selling software.

It may become part of national child-protection infrastructure.

That carries a different standard of responsibility.

What should international businesses outside Britain consider?

Extraterritorial online-safety regulation increasingly follows users rather than headquarters.

A technology business operating from the United States, Pakistan, the Gulf or Asia should therefore not assume that British child-safety law is irrelevant merely because the company has no London office.

If the service reaches UK users and falls within the relevant statutory scope, British regulatory obligations may become commercially significant.

Companies should assess territorial scope before launch rather than after receiving regulatory correspondence.

This is a recurring lesson across our international digital-law series.

What should Pakistani technology companies consider?

A Pakistani company providing software, moderation, age-assurance technology, AI services or outsourced compliance functions to British platforms may encounter these requirements contractually even where it is not itself the primary regulated service.

British clients may demand:

security commitments;

age-assurance performance warranties;

data-protection clauses;

audit rights;

regulatory cooperation;

incident reporting;

and restrictions upon use of verification information.

Foreign regulation often arrives in Pakistan through a contract before it arrives through Pakistani legislation.

That is why international regulatory literacy increasingly becomes a competitive advantage for Pakistani technology businesses.

What should PTA examine?

Pakistan’s regulator should watch at least three aspects of the British and Australian experiments.

First, effectiveness: whether age restrictions actually reduce the identified harms.

Secondly, privacy architecture: whether reliable age assurance can operate without pervasive identity disclosure.

Thirdly, displacement: whether children move towards safer or more dangerous alternatives.

PTA’s existing collaboration with platforms on youth safety gives Pakistan an institutional base from which to observe those developments.

There is no prize for becoming the third country to copy a policy before the first two countries know whether it works.

Pakistan also needs a serious conversation about children’s digital rights

The domestic debate too often oscillates between two extremes.

Block the platform.

Or:

Leave the internet alone.

Neither is sophisticated enough.

Children need protection from:

sexual exploitation;

harassment;

predatory contact;

violent content;

deepfakes;

fraud;

addictive design;

commercial manipulation;

and inappropriate profiling.

They also benefit from:

education;

communication;

creativity;

information;

community;

and technological competence.

The regulatory task is not choosing between childhood and technology.

Children are already growing up inside technological society.

The task is making that society fit for them.

Frequently Asked Questions

Has Britain already banned social media for everyone under 16?

Not yet. The Government announced the policy on 15 June 2026 and has statutory regulation-making powers available under the Children’s Wellbeing and Schools Act 2026. The first regulations are expected before the end of 2026, with implementation currently envisaged for spring 2027.

What law gives the Government power to impose the restrictions?

Section 70 of the Children’s Wellbeing and Schools Act 2026 inserts a new section 214A into the Online Safety Act 2023, allowing regulations requiring specified internet-service providers to prevent or restrict relevant children’s access to services, functionalities or features for child-protection purposes.

Does Parliament have to approve the regulations?

The statutory architecture requires the affirmative procedure for regulations made under the relevant new power, involving parliamentary approval.

Which platforms are expected to be covered?

The Government has specifically indicated an intended model encompassing services such as Snapchat, TikTok, YouTube, Instagram, Facebook and X. The final legal scope will depend upon the regulations and associated definitions.

Will WhatsApp and Signal be banned for under-16s?

The Government has stated that standalone messaging services such as WhatsApp and Signal are not intended to fall within the core social-media prohibition.

Will children still be able to use the internet for education?

Yes. The Government says dedicated educational platforms are not intended to fall within the prohibition and that children should remain capable of using the internet for learning, news, gaming and communication through permitted services.

What happens at age 16?

Sixteen- and seventeen-year-olds will remain capable of using social media, but the Government has announced continuing protective defaults, including a proposed midnight-to-6 a.m. curfew and automatic disabling of certain engagement features, with older teenagers capable of changing relevant settings.

How will platforms know whether somebody is under 16?

The precise 16+ standard is still being developed. Ofcom is due to provide Parliament with a rapid assessment of highly effective age assurance for this purpose. Existing Ofcom guidance in other Online Safety Act contexts recognises techniques including facial age estimation, digital identity, mobile-network checks, photo-ID matching, open banking and other approaches.

Will every adult have to upload a passport?

Not necessarily. The Government expressly contemplates multiple possible age signals and says some existing adults may not need fresh verification where reliable information already establishes that an account must belong to an adult. Final requirements remain under development.

Is self-declaring a date of birth sufficient?

Ofcom’s existing highly effective age-assurance framework does not regard simple self-declaration as sufficient for high-effectiveness requirements.

Does age verification create privacy issues?

Yes. Ofcom expressly recognises that age assurance involves personal-data processing and requires privacy and data-protection obligations to be respected. The ICO is working with Ofcom as the new age-16 framework is developed.

Can children simply use a VPN?

Circumvention is one of the major implementation concerns. The Government has commissioned research into children’s use of VPNs while recognising that VPNs also have legitimate privacy and freedom-of-expression functions.

Has Australia already implemented an under-16 rule?

Yes. Australia’s minimum-age obligation came into force on 10 December 2025. Covered platforms must take reasonable steps to prevent under-16 Australians from maintaining accounts.

Are Australian children punished if they circumvent the restriction?

No. The Australian framework places the principal legal obligation on covered platforms rather than imposing penalties upon children or parents merely because an under-16 accesses an account.

How large are Australian penalties?

Corporate penalties can reach up to AUD 54.6 million under the current framework.

Has Australia’s policy already been proved successful?

No. Early implementation figures show substantial account restrictions—including approximately 4.7 million under-16 accounts identified and restricted in the initial period—but Australia’s regulator has expressly cautioned that longer-term effectiveness requires continuing evaluation.

Does Pakistan currently have the same type of under-16 social-media prohibition?

Pakistan currently follows a different model emphasising online-safety guidance, parental awareness, platform cooperation and safety features such as Instagram Teen Accounts rather than an Australian-style statutory account prohibition.

Should Pakistan introduce the same prohibition?

That deserves evidence-based study rather than automatic transplantation. Pakistan should examine effectiveness, privacy, enforcement capacity, the availability of age-assurance technology, children’s access to educational and social resources and the experiences emerging from Australia and Britain before adopting a comparable model.

The most important distinction may be between identification and assurance

Much of this debate will become needlessly polarised.

One side will say:

“Protect children at any cost.”

The other:

“Age verification means government ID for the internet.”

Neither proposition needs to be correct.

A well-designed system should aim to establish enough information to enforce the relevant age rule and no more.

That is the architecture worth demanding.

The internet does not necessarily need your name.

It may merely need credible proof that you satisfy the legal threshold.

If governments can preserve that distinction, strong child protection and meaningful adult privacy need not be enemies.

If they fail to preserve it, age verification could become something much larger than child-safety policy.

It could become identity infrastructure.

This is why seemingly boring technical standards matter enormously

How long may an age-verification provider retain a selfie?

May it use the image to train another model?

Does the platform receive the photograph?

Can identity information be linked with browsing behaviour?

Can a person use a pseudonym after age verification?

What accuracy rate is expected?

Who audits bias?

Can the service be used without a smartphone?

What happens after a data breach?

Can police obtain the verification record?

Does an age token reveal exact age or merely threshold status?

These details will never receive the attention given to the political announcement.

Yet they determine whether the law protects children with dignity or protects them by building unnecessarily intrusive surveillance.

The legislation should also be judged by what happens to adults

This sounds counterintuitive.

The law exists for children.

But the regulatory system must distinguish adults from children.

Its implementation therefore changes the experience of adults too.

Every protective gate has people standing on both sides.

That is why adult privacy belongs within a child-safety analysis.

The rights are not competing moral claims.

They are consequences of the same architecture.

And the legislation should be judged by what happens to the children it excludes

Do they sleep better?

Learn better?

Feel calmer?

See fewer harmful recommendations?

Experience less bullying?

Encounter fewer predators?

Spend more time with friends physically?

Or do they simply move to anonymous foreign platforms?

Do socially vulnerable teenagers become more isolated?

Does digital literacy decline?

Do VPN downloads explode?

Do AI companions replace human social networks?

Those are the questions which should determine whether the policy is celebrated.

Not whether the press release was popular.

Britain is attempting something more ambitious than a website ban

Read together, the June and July 2026 announcements suggest an emerging philosophy of age-structured digital environments.

Under sixteen: exclusion from specified social-media environments.

Sixteen and seventeen: access, but with heightened protective defaults.

Other services: functional restrictions where risks such as livestreaming and stranger communication arise.

AI companionship: potentially higher age thresholds for intimate functionality.

Platforms: stronger age assurance.

Regulators: greater involvement in technical implementation.

That begins to resemble a legal theory of digital childhood.

The traditional internet assumed one user: the adult

For years, online products were often designed around an imaginary generic user.

Legally competent.

Commercially persuadable.

Able to consent.

Able to understand privacy policies.

Able to recognise manipulation.

Able to manage contacts.

Then children entered the same architecture.

Regulation is finally admitting that a twelve-year-old is not simply a smaller thirty-year-old.

That is progress.

The challenge is making the correction without transforming the adult internet into a compulsory identity system.

Pakistan should recognise the same basic principle

Children require different digital architecture.

That does not necessarily mean Pakistan should prohibit every child below sixteen from every social platform.

It does mean government, PTA, schools, families and technology companies should stop treating age as somebody else’s problem.

Platform design should know whether the user is a child where that distinction materially affects safety.

But Pakistan should equally insist that age assurance itself respect privacy and proportionality.

There is little virtue in protecting a child from an algorithm while normalising unnecessary identification of an entire population.

Child protection and privacy share a common value

At first glance they pull in opposite directions.

Child protection says:

Know the user’s age.

Privacy says:

Do not know more than necessary.

But beneath them lies the same principle:

human beings should not be unnecessarily exposed to power they cannot reasonably control.

A child should not be exposed to manipulative digital architecture simply because a technology company profits from attention.

An adult should not be required to surrender unnecessary identity information simply because a technology company must determine age.

Fairness lies in designing systems which respect both.

The great test will come in spring 2027

If the Government’s timetable holds, Britain’s experiment will move from announcement to implementation next spring.

At that point, political language will meet engineering reality.

Thirteen-year-olds will meet age gates.

Adults will meet verification systems.

Platforms will meet Ofcom.

Privacy law will meet child-safety law.

Parents will discover whether the new rules make family life easier.

And lawyers will begin discovering what phrases such as “highly effective”, “reasonable”, “proportionate” and “social media” actually mean when disputes arise.

That is when the law becomes real.

Perhaps the most important question is not whether Britain can keep a fourteen-year-old off Instagram

It probably can make access considerably more difficult.

The harder question is whether Britain can do so without requiring every innocent adult to become unnecessarily identifiable in the process.

That is the regulatory standard worth setting.

Protect the child.

Preserve legitimate anonymity.

Collect the minimum data.

Keep the architecture accountable.

Permit challenge when technology is wrong.

Measure actual harm rather than political theatre.

And keep the law flexible enough to follow children when technology changes.

If Britain achieves that, the under-16 social-media regime may become an important international model.

If it does not, the world may learn an equally valuable lesson:

a digital gate designed to keep children out can also become a checkpoint through which everyone else must pass.

That is why the debate matters far beyond teenagers, TikTok and parental frustration.

It is ultimately a debate about the infrastructure of identity on the future internet.

About the Author

Barrister Aemen Zulfikar Maluka is the founder of Josh and Mak International, an Islamabad-based legal practice advising Pakistani, overseas and international clients on cross-border commercial, regulatory, technology and public-law matters.

Her international legal commentary examines the growing body of regulation governing artificial intelligence, digital platforms, privacy, competition, online safety and emerging technologies across the United Kingdom, European Union, United States, Australia, Asia and other jurisdictions, with particular emphasis upon how those developments may affect businesses, technology companies and investors connected with Pakistan.

The regulation of children’s digital lives is a particularly important international subject because the legal problem ignores borders. A social-media company may be headquartered in California, regulated in London, operate age-assurance technology supplied from another jurisdiction and provide services to children in Islamabad. International legal advisory work increasingly requires lawyers to understand not merely separate national laws but the technological architecture through which those laws interact.

Barrister Aemen’s approach is deliberately practical and comparative: identifying not only what a foreign government has announced, but the statutory power beneath the announcement, the implementation risks, the competing rights involved, the commercial consequences for regulated businesses and the lessons Pakistan can draw before confronting similar questions domestically.

For further insights, international online-safety and technology regulation advice, UK-Pakistan regulatory analysis, cross-border digital compliance or legal advice concerning businesses connected with Pakistan, contact Barrister Aemen at Aemen@joshandmak.com.

Josh and Mak International
www.joshandmakinternational.com

This article is intended as general international legal and regulatory commentary. It does not constitute legal advice concerning any particular platform, child, family, technology provider or jurisdiction. The detailed UK under-16 social-media requirements remain subject to the secondary legislation and regulatory arrangements still under development as at August 2026.

Filed Under:
UK social media ban under 16, UK under 16 social media law 2026, Britain social media ban children, UK social media age verification, social media ban spring 2027, Children’s Wellbeing and Schools Act 2026 social media, section 70 Children’s Wellbeing and Schools Act, section 214A Online Safety Act 2023, UK child online safety law, Online Safety Act children social media, Ofcom age assurance 16, highly effective age assurance UK, UK age verification law, social media age check law, facial age estimation social media, digital identity age verification, privacy preserving age assurance, age assurance privacy law, age verification data protection, UK GDPR age verification, ICO age assurance children, Children’s Code age assurance, anonymous social media UK law, social media anonymity age verification, age gate privacy, child safety versus privacy, social media age restrictions Britain, TikTok under 16 UK, Instagram under 16 UK, YouTube under 16 UK, Snapchat under 16 UK, Facebook under 16 UK, X under 16 UK, WhatsApp exemption under 16, social media curfew 16 17 UK, midnight social media curfew UK, addictive social media features law, infinite scroll children law, autoplay children social media law, stranger contact children online, livestreaming children UK law, social media design regulation, algorithmic harm children, children’s digital rights UK, Article 8 social media age verification, Article 10 social media restriction, Convention Rights Child digital environment, children’s right to privacy internet, children’s freedom expression online, Australia social media minimum age, Australian under 16 social media law, eSafety minimum age, Australia 4.7 million accounts, social media ban comparison UK Australia, Pakistan social media children law, Pakistan child online protection, PTA child online safety, PTA Meta Teen Accounts, Instagram Teen Accounts Pakistan, Pakistan under 16 social media, age verification Pakistan, CNIC social media age verification, digital identity privacy Pakistan, child online protection Pakistan, PECA children social media, PTA social media regulation, social media lawyer Pakistan, international technology lawyer Pakistan, online safety legal advice Pakistan, cross border technology regulation, social media compliance Pakistan, age assurance provider legal advice, age verification contracts, biometric age estimation law, AI age verification regulation, digital platform child safety, child safety by design, age appropriate design UK, international social media regulation, online platform regulation Pakistan, digital rights Pakistan, privacy lawyer Pakistan, technology regulatory advisory Pakistan.

By The Josh and Mak Team

Josh and Mak International is a distinguished law firm with a rich legacy that sets us apart in the legal profession. With years of experience and expertise, we have earned a reputation as a trusted and reputable name in the field. Our firm is built on the pillars of professionalism, integrity, and an unwavering commitment to providing excellent legal services. We have a profound understanding of the law and its complexities, enabling us to deliver tailored legal solutions to meet the unique needs of each client. As a virtual law firm, we offer affordable, high-quality legal advice delivered with the same dedication and work ethic as traditional firms. Choose Josh and Mak International as your legal partner and gain an unfair strategic advantage over your competitors.

error: Content is Copyright protected !!
Josh and Mak International
Privacy Overview

Dear website visitor,

We use third-party cookies on our law firm website to enhance your browsing experience and provide you with relevant content and services. Third-party cookies are created by domains other than our website and are used for various purposes, such as tracking website analytics and serving targeted ads. The third-party cookies we use on our website are provided by Google Analytics, a web analytics service provided by Google, Inc. Google Analytics uses cookies to analyze how visitors use our website and provide us with reports on website activity. The information generated by these cookies is transmitted to and stored by Google on servers in the United States. We also use third-party cookies to serve targeted advertisements to website visitors. These cookies are provided by advertising networks and allow us to deliver advertisements that are relevant to your interests. By using our website, you consent to our use of third-party cookies as described in this policy. If you do not wish to accept cookies from our website, you can disable or delete them through your browser settings. However, please note that disabling or deleting cookies may affect your browsing experience and prevent you from accessing certain features of our website. If you have any questions or concerns about our use of cookies, please contact us using the contact details provided on our website. Thank you for visiting our website.

Best regards,

The Josh and Mak Team