TL;DR: BleepingComputer (Ax Sharma, June 16, 2026, 10:38 AM, HN id area 48561300, 51 points and 85 comments at 19:45 UTC scan) published the operational-layer completion of the Starmer Australia-plus beat.[1] Prime Minister Keir Starmer set out the plan on June 15, after a national consultation that drew 116,000 responses from parents, children, and experts.[1] The mechanism: any new account will require an ID upload or a facial age scan. Long-standing accounts are largely exempt, but anyone opening a new account has to prove they are over 16. The piece is explicit: the rule "effectively end[s] anonymous account creation in the UK."[1]
- The Ofcom fact sheet says proving your age "could be as simple as a facial recognition check." The verification option is built into the same adult-content regime that has been in force since July 25, 2025 under the Online Safety Act. Adult sites serving UK visitors already prompt for a video selfie (for liveness) or a credit card for age checks.[1]
- Researchers at the Politecnico di Milano tested the verification methods already deployed on adult sites. The result, as quoted by Dr. Siamak Shahandashti of the University of York: mandated age verification currently functions as "compliance theatre." Most methods showed "low-to-medium robustness" and could be bypassed with tools within reach of "motivated minors." Credit-card checks were the lone exception.[1]
- The Open Rights Group warns that over-16s will now have to surrender identity documents or biometric data to "unregulated age-verification companies." The ORG pointed to Discord's age-check rollout as the precedent: a third-party provider was compromised, and 70,000 government-ID photos were exposed. James Baker, who runs ORG's Platform Power and Freedom of Expression programme, said the powers were "rushed through without proper time for political scrutiny."[1]
- The VPN gap is real and documented. When adult-site enforcement began in July 2025, some VPN providers reported signup spikes of up to 1,800%. The Starmer package inherits the same gap. Australia is the proof: more than 60% of children were still using social media months after that country's ban took effect. A blanket UK VPN ban was ruled out in October 2025.[1]
- The carve-out for long-standing accounts is the political fig leaf. The new-account rule is the operational reality. An account is treated as low-risk if it has been open for more than 16 years, has a credit card attached, or is linked to an email already age-verified elsewhere. Anyone verified under the existing Online Safety Act does not need to do it again. Fresh sign-ups get the ID upload or the facial scan.[1]
- The platforms in scope: Instagram, YouTube, TikTok, Snapchat, Facebook, X. Excluded: WhatsApp, Signal, YouTube Kids. Gaming platforms (Roblox is named) get high-risk features such as livestreaming and stranger contact locked down. AI "romantic companion" chatbots must enforce an 18+ minimum. The 16- and 17-year-old cohort gets the stranger-contact and livestreaming restrictions by default.[1]
- The wider direction of travel: a GOV.UK Wallet and a digital driving licence, in development since January 2025. The wallet is pitched partly as a way to prove your age online and in person using the facial-recognition features built into modern phones. The piece is direct: "proving your age is increasingly a precondition for being online in the UK."[1]
- Watch over the next 30 days: the Ofcom "highly effective" age-assurance study commissioned by the government (timing TBD), the first industry response from the named platforms (Meta and YouTube have already pushed back publicly), the first major civil-society coalition filing on the data-handling rules for the verification vendors, and the first contested enforcement action against a platform that uses an "insufficient" age-check method (the Politecnico di Milano study is now the public benchmark).
The Rule: New Accounts Have to Prove They Are Over 16. Long-Standing Accounts Do Not.
Prime Minister Keir Starmer set out the under-16 ban on June 15, 2026, after a national consultation that drew more than 116,000 responses from parents, children, and experts.[1] The government says nine in ten parents backed the ban and two-thirds of young people agreed that under-16s should be kept off at least some platforms. Starmer's framing was direct: "We're going further than any country in the world by banning social media for under-16s and putting wider protections in place to give kids their childhood back."[1] Technology Secretary Liz Kendall framed it as a fight with the platforms: "Tech companies have had countless opportunities to keep children safe, yet they have failed to act."[1]
The Starmer announcement was the political headline. The BleepingComputer piece is the operational layer underneath it. The mechanism is the part the political coverage skipped. New accounts will have to prove the user is over 16. The government fact sheet lays out the options: an ID upload, or a facial age scan. Both have been in production since July 25, 2025 for adult sites serving UK visitors under the Online Safety Act. The social-media regime imports the same plumbing.[1]
The carve-out is the political fig leaf. An account is treated as low-risk if it has been open for more than 16 years, has a credit card attached, or is linked to an email already age-verified elsewhere. Anyone who is already verified under the existing Online Safety Act does not need to do it again. The grandfather clause protects anyone whose account was opened before the rules land. The carve-out does nothing for anyone opening a new account, and "anyone opening a new account" includes adults who want a fresh, pseudonymous handle, anyone who has not previously tied a credit card to a social profile, and the next generation of UK teenagers who have never had an account at all.[1]
The BleepingComputer piece is explicit on what the new-account rule means in practice. The piece quotes the government fact sheet directly: proving your age "could be as simple as a facial recognition check." The "simple" is the government's framing. The "facial recognition" is the operational mechanism. The two together are the part of the package that the political coverage has not yet grappled with. The piece's read is the right one: "the regime quietly converts what's billed as child protection into a rule that no adult can open a new account without proving their age."[1]
What the Rule Covers: Instagram, YouTube, TikTok, Snapchat, Facebook, X. WhatsApp and Signal Are Out. Roblox Is In.
The piece is specific on the platforms. The ban covers "user-to-user platforms whose purpose is to enable social interaction and that run algorithmic feeds." The government names six: Instagram, YouTube, TikTok, Snapchat, Facebook, and X. Messaging services such as WhatsApp and Signal are explicitly excluded. YouTube Kids is excluded. There is a "narrowly defined" exemption list for educational services, e-commerce, and music streaming.[1]
The UK is going further than Australia on the high-risk features. Livestreaming and stranger-to-child contact will be restricted across a wider range of services, including gaming platforms. Roblox is named in the piece: the platform stays, but features such as in-game chat get locked down for under-16s. To avoid a "cliff-edge at 16," the stranger-contact and livestreaming restrictions will be on by default for 16- and 17-year-olds as well. AI "romantic companion" chatbots that simulate sexual or roleplay relationships must enforce an 18+ minimum, with intimate functions restricted for under-18s on AI chatbots more broadly. The government is consulting on overnight curfews and breaks in infinite scrolling for under-18s, with detail promised in July.[1]
Ofcom has been asked to run a rapid study on how to verify whether someone is over 16. The "highly effective" age-assurance language is the same one already in force under the Online Safety Act for adult content. The study will revisit the four main verification approaches: biometric facial-age estimation, live selfie verification, AI-based behavioural inference, and government-issued identity document uploads. The Proton piece from the same week covers the Australia-failure track on these methods. The BleepingComputer piece adds the academic track.[1][2]
The "Compliance Theatre" Finding: Politecnico di Milano Tested the Methods. Most Fail.
The academic track is the part of the BleepingComputer piece that the political coverage has not caught up to. Dr. Siamak Shahandashti, a senior lecturer in cyber security and privacy at the University of York, pointed the piece at fresh empirical work from the Politecnico di Milano testing the age-verification methods deployed on UK adult sites. The researchers ran the methods in a controlled environment. The result, in Shahandashti's own quote, is that mandated age verification currently functions as "compliance theatre."[1]
The empirical result is sharper than the quote. The researchers found "low-to-medium robustness for nearly every method except credit-card checks." Most could be bypassed with tools and know-how within reach of "motivated minors." The credit-card check is the lone exception, and the credit-card check is the one method that brings its own privacy problem: it requires a payment instrument on file, which is also the mechanism platforms already use to track spending, link accounts, and lock users in. Shahandashti added that checks linked to real, physical ID could be made strong enough if clear standards were set. The clear-standards caveat is the part that the Ofcom study is being asked to fill in.[1]
The second-order risk is the one Dr. Richard Gomer, a lecturer in computer science at the University of Southampton, surfaced for the piece. Gomer zeroed in on what happens to the ID and biometric data once it is collected. Handing a passport or driving licence to platforms, he warned, exposes people to identity theft or blackmail when those records inevitably leak. The piece is explicit that the data-breach risk is not hypothetical. The Discord age-check rollout of 2025 ended with a third-party provider compromised and 70,000 government-ID photos exposed. The Yoti GrapheneOS case from the same regulatory family is the second-order precedent.[1][3]
Gomer also flagged the quieter cost of the regulation: it pushes the web further from its original ideals of anonymous, open communication. The "quiet cost" framing is the structural critique. The Online Safety Act age-assurance regime for adult content has been live since July 25, 2025. The social-media regime is the next layer of the same architecture. The Proton piece from the same week is direct on the political-economy read: every age-verification system, however it works, requires platforms to collect more personal data than they do today, and the data goes to vendors the user has no direct relationship with and no negotiating power with.[1][2]
The Open Rights Group Warning: The Data Goes to "Unregulated Age-Verification Companies"
The Open Rights Group (ORG) was the most-quoted civil-society voice in the piece. The group's response to the announcement was direct: over-16s will now have to surrender identity documents or biometric data to unregulated age-verification companies. The Discord compromise is the precedent. The ORG also pointed at the regulatory gap. The age-verification vendors are not regulated under the Online Safety Act. They are not regulated under data-protection law in the way that platforms are. The ID and biometric data they collect is held by vendors that the user has never heard of, on retention schedules the user has never seen, with security postures the user cannot audit.[1]
James Baker, who runs ORG's Platform Power and Freedom of Expression programme, argued the measures chase symptoms rather than the cause. The cause, in his framing, is "the engagement-driven business models that reward harmful content." The symptom is the platform. The age-verification regime does not touch the engagement-driven business model. It touches the user, by forcing the user to disclose identity and biometric data to a verification vendor on every new sign-up. Baker has previously warned that the underlying powers were "rushed through without proper time for political scrutiny."[1]
The platforms are not on side either. The piece reports that Meta and YouTube both argue that bans push teenagers toward less-regulated spaces rather than making them safer. Meta's specific argument is the structural one: age checks should sit on the device so users aren't handing ID to every service separately. The device-side argument is the privacy-friendly path that the government has not chosen. The government's choice is the verification-vendor path, which is the path that builds the verification-vendor data-collection infrastructure.[1]
The VPN Loophole: 1,800% Signup Spikes, 60% Bypass Rates, and a Blanket Ban That Was Ruled Out
The structural weakness is the one the Australia track already documented. VPNs defeat age verification, because the verification runs on the platform, not on the user. Connecting through a server outside the UK sidesteps the check. When adult-site enforcement began in July 2025, some VPN providers reported signup spikes of up to 1,800%. The signup-spike number is the empirical record of how the user base actually responded to the existing Online Safety Act age-assurance regime.[1]
Australia is the proof of concept for the social-media regime. Research there found more than 60% of children were still using social media months after the country's ban took effect. The Proton piece cites a parallel Australian figure of 70% still using banned platforms from the eSafety regulator. The two numbers triangulate to the same point: the bypass rate is high, and the age-verification regime does not actually catch the target cohort.[1][2]
The UK government has limited room to close the loophole. A blanket VPN ban for the whole population has been ruled out. In October 2025, tech minister Baroness Lloyd told the Lords there were "no current plans to ban the use of VPNs," citing their legitimate uses. A children-specific clampdown is a different story. In February 2026, the government said its wellbeing consultation would examine "options to age restrict or limit children's VPN use." In January 2026, the House of Lords voted 207 to 159 for an amendment to the Children's Wellbeing and Schools Bill that would require ministers to prohibit VPN providers from serving UK children. The Commons rejected the amendment across several rounds of parliamentary ping-pong. The Act that received Royal Assent in April 2026 instead handed ministers a broad power to restrict children's online access by regulation.[1]
For now, nothing stops a determined adult, or a determined 15-year-old, from getting around it. The BleepingComputer piece is direct on this. The verification regime is the policy instrument. The bypass rate is the empirical record. The two together are the part that the consultation responses did not have to weigh in on, because the consultation asked about child safety, not about what happens to adult anonymity or to the data flow that the verification regime creates.[1]
The Direction of Travel: A GOV.UK Wallet, a Digital Driving Licence, and a Future Where Age Is a Precondition for Being Online
The piece closes with the structural reading. Since January 2025, the UK government has been building a GOV.UK Wallet and a digital driving licence. The wallet is pitched partly as a way to prove your age online and in person, using the facial-recognition features built into modern phones. The wallet predates the Starmer package and is officially separate from it. Together, the two pieces of architecture sketch a direction of travel. The piece is direct: "proving your age is increasingly a precondition for being online in the UK."[1]
The wallet-and-social-media combination is the surveillance-architecture frame. The wallet is the identity-verified credential. The social-media rule is the choke point that makes the credential useful. The facial-recognition feature on the phone is the verification primitive. The age-verification vendor is the data-collection layer. The Online Safety Act enforcement regime is the regulatory backbone. The five layers are not the same. They are built by different vendors, on different compliance deadlines. They are also the same regulatory continuum, and they are designed to interoperate.[1]
The earlier SOS coverage on the Starmer Australia-plus beat has tracked the three layers separately. The announcement piece covers the under-16 ban and the CSAR encrypted-device-scanning component. The Proton piece covers the Australia failure track and the privacy angle. The BleepingComputer piece is the third layer: the verification mechanism, the compliance-theatre finding, the regulatory gap, and the wallet direction of travel. The three pieces are the same regulatory continuum, tracked at three layers.[4][2]
What It Means for You
The Starmer package is expected to be unveiled in the King's Speech in the autumn, with regulations before Christmas and enforcement from spring 2027. The BleepingComputer piece confirms the operational shape. If you are an adult with an existing social media account that is more than 16 years old, has a credit card attached, or is linked to an email already age-verified elsewhere, the rule is unlikely to require anything new from you. If you are an adult opening a new social media account, you will need to upload an ID or pass a facial age scan, and the data will go to a verification vendor you have no direct relationship with.[1]
If you are a teenager under 16, the platform-level block is the front line. If you are a teenager between 16 and 18, you inherit the stranger-contact and livestreaming restrictions by default, plus the AI-chatbot restrictions on intimate functions. If you are a parent, the 116,000-response consultation is the political record of where public opinion landed, and the 9-in-10 parental support figure is the political cover for the package.[1]
The privacy cost is the part the consultation was not asked to weigh in on. The age-verification regime builds a data-collection layer that did not exist before. The verification vendors are unregulated under the Online Safety Act. The data they collect is held on retention schedules you will not see, with security postures you cannot audit. The Politecnico di Milano study is the public benchmark for how well the verification methods actually work, and the answer is "compliance theatre" for every method except credit-card checks. The Open Rights Group's data-handling warning is the public critique of the data-collection layer. The GOV.UK Wallet is the direction of travel. The next twelve months are when the operational shape of the regime gets set, and the next twelve months are when the civil-society pushback has to land.[1]
Sources
- BleepingComputer: "UK to require ID or face scan before you can make social media accounts" (Ax Sharma, June 16, 2026, 10:38 AM, primary source for the UK under-16 social media ban operational details, the ID/face-scan verification mechanism, the grandfather clause carve-out, the consultation numbers, the Starmer "line in the sand" quote, the Liz Kendall quote, the named-platform scope, the AI romantic-companion 18+ restriction, and the July overnight-curfew/infinite-scroll-break consultation)
- State of Surveillance: "UK's Under-16 Ban Copies Australia's 70% Failure: Proton Shows What That Means" (June 16, 2026, the Australian under-16 ban failure rate data that contextualizes the UK carve-out grandfather clause; 70% under-16 detection failure rate on the Australian verification system as of late 2025)
- State of Surveillance: "Yoti Reports GrapheneOS Users to Authorities for Alleged Age-Verification Bypass" (June 12, 2026, the prior UK age-verification infrastructure coverage showing the Yoti biometric age-estimation vendor has reported device-fingerprint-identified bypass attempts to UK authorities; directly relevant to the operational risk that ID/face-scan verification will produce a parallel reporting channel from age-verification vendors to Ofcom/police)
- State of Surveillance: "UK's 'Australia Plus' Ban: Under-16 Social Media, Chatbots, Encrypted Phone Scans" (June 15, 2026, the companion piece covering the policy announcement; this article covers the operational verification mechanism, the grandfather clause, and the expert risk assessment that follows the announcement)