That legal design puts the compliance burden on companies. The eSafety Commissioner says the Social Media Minimum Age obligation took effect on 10 December 2025 and that its March 2026 compliance update drew on compulsory information-gathering notices sent to ten age-restricted platforms. In plain terms, the regulator is asking what platforms did, not what parents failed to do.

The design also avoids criminalising children. That choice is central to the law's legitimacy: the state is not threatening teenagers or parents with punishment for being online. It is threatening platforms with consequences if their systems allow under-16 accounts despite a statutory obligation to prevent them.

The next phase is penalties. The Guardian and Al Jazeera reported on 27 June that the Australian government planned to double maximum fines for breaches to A$99m and expand the eSafety Commissioner's investigatory powers after children continued to bypass the ban. The precise statutory mechanism still belongs in the bill text and explanatory materials, but the policy direction is clear: Canberra wants a larger sanction for platforms that cannot show effective prevention.

The size of the proposed fine is meant to change board-level incentives. A small penalty can be absorbed as a compliance cost; a maximum of A$99m is designed to make failure visible to executives and investors. Whether it works depends on the details: the evidentiary threshold for breach, the regulator's ability to obtain internal documents, and whether repeated non-compliance is treated differently from isolated failures.

"Reasonable steps" is a deliberately practical legal threshold. It does not require a perfect system; teenagers can route around account checks, use older credentials or move between services. It does require platforms to demonstrate that their design, verification, detection and enforcement systems are serious enough for the risk they create.