Malaysia’s law came into force on the first of this month, and the operative provision does not say that children may not use social media. It says that a platform must not permit a person under sixteen to hold an account, and attaches penalties of up to ten million ringgit, around two and a half million dollars, for failing to prevent it.
On Monday the British prime minister announced that the United Kingdom will do something similar. Australia legislated first and has been operating a version for some months.
If you have not followed this, the interesting question is not whether children should be on these services. It is how anybody proposes to know how old a person is, and that question has no comfortable answer.
Where the duty sits
Start with the drafting, because it determines everything downstream.
These laws do not criminalize the child, and they do not place the obligation on a parent. They place it on the service, and they make it a duty to prevent rather than a duty to try. That is deliberate: a duty to try is discharged by a checkbox, and a checkbox has been the state of the art since about 2004 and has never stopped anybody.
A duty to prevent, backed by a penalty large enough to matter, forces the service to actually determine the age of every person who opens an account. Not of the children. Of everybody, because you cannot identify which users are children without assessing all of them.
That is the single most important consequence of this design and it is almost never stated in the debate.
The four ways to check an age, and what is wrong with each
Ask. A date of birth field costs nothing, excludes nobody, and is defeated by arithmetic any eleven year old can do. It is what platforms have used for twenty years and it is why these laws exist.
Check a document. A passport or a national identity card gives a reliable answer. It also means every adult user hands identity documents to a social media company, or to a third party verifying on its behalf, creating a database of exactly the kind that gets breached. And it excludes the substantial number of adults in any country who do not hold current photographic identification, who skew poor, old and marginal.
Estimate from a face. Facial age estimation looks at a selfie and returns an estimate with an error band. It is genuinely quite good in the middle of the range and it is worst exactly where it is needed: distinguishing a fifteen year old from a seventeen year old is the hard case, because faces at that age vary enormously and the error band is wider than the decision. Performance also differs across demographic groups, which turns an error rate into a fairness problem.
Infer from behavior. Some services estimate age from how an account is used: who it connects to, what it watches, how it types. It requires no document and no photograph, and it works by profiling everybody continuously, which is a cure with a strong family resemblance to the disease.
What the regulators actually ask for
Not certainty. The standard in most of these regimes is some formulation of highly effective age assurance, which is a deliberate compromise: the service must use a method that works well, proportionate to the risk, and must be able to show its reasoning.
In practice that means a layered approach. A cheap signal for the obvious cases, a stronger check where the first is ambiguous, and a route to appeal for people wrongly excluded. It also means the regulator judges the system rather than the outcome, which is the same structure as the online safety duties discussed elsewhere: process regulation, assessed on whether you took reasonable steps.
What it does to the adults
This is the part worth being clear eyed about, because it is the actual cost and it falls on people who are not the subject of the law.
Any effective scheme ends the ability to use these services without establishing who you are, or at least what you are. Pseudonymity survives, in that the platform need not publish your name. Anonymity does not, because somebody now holds a document scan or a face estimate linked to your account.
For most people, most of the time, that is an inconvenience. For a domestic abuse survivor, a whistleblower, a person in a country where an opinion is dangerous, or a teenager whose identity would be revealed to a parent by the verification itself, it is a material change in what the internet is.
There are technical answers that reduce this. Double blind schemes, where a verifier confirms an age band to a platform without learning which platform and the platform never sees the document. Device held credentials that prove a band without transmitting an identity. Those exist and they are better, and they are harder to build and are not what most services will implement first.
Where the children go
One question these laws mostly do not address, and it is the one that determines whether they achieve anything.
A fifteen year old removed from a large platform does not stop using the internet. They move, and the available evidence from restriction regimes generally is that they move toward services that are smaller, less moderated and outside the scope of whatever rule displaced them.
The large platforms are, for all their faults, the ones with content moderation teams, reporting mechanisms, and regulators paying attention. A messaging group on a service nobody has heard of has none of that.
So the measure could plausibly reduce the harms specific to algorithmic feeds and increase the harms specific to unmoderated spaces, and the net of those two is an empirical question nobody has answered because no regime has run long enough.
What to watch
Three things, over the next year.
Whether Australia’s data gets published. It has the longest running scheme and is therefore the only source of evidence on the questions that matter: what proportion of under sixteens actually lost access, what proportion of adults were wrongly excluded, and where the children went instead. Every other country is legislating on the basis of expectation.
Whether the verification market consolidates. If three or four vendors end up doing age assurance for most of the world’s platforms, those companies become the most consequential identity infrastructure nobody voted for, and they will hold the breach risk for everybody.
Then there is the boundary of a covered service, and whether it holds. These laws name social media, and the definition is doing enormous work: a messaging app, a games platform with a chat function, a video site, a forum. Each of those will argue it is not covered, and the answers will be given case by case over several years, during which the rule means different things in different places.




