My Feed, My Way: The Strategy Comes Into View — And So Does Its Theory of Change Problem

I want to be careful about what kind of post this is, because it isn’t the same kind of post as “Another Day, Another Declaration.” That one was about a newsletter dressed up as a victory lap for evidence that didn’t support it. This one is different. This is the moment the actual strategy becomes visible — not another announcement to catalogue, but the point where you can finally see the shape of the thing the government has been building toward, and ask whether it hangs together.

It doesn’t, and I want to show my working on why.

What actually landed

On 8 September, Anthony Albanese and Anika Wells announced the draft legislation for the Digital Duty of Care bill including an “Australian first” called My Feed, My Way.

Social media platforms will have to notify users of a choice, according to the press release: opt in to an algorithmically curated feed, or opt out and see only the accounts they follow, in order. That’s the government’s stated intent, not yet the law’s text. What the bill itself creates is a ministerial power to require “user empowerment tools” by legislative instrument — the notification, the two named options, the commitment to “respect that choice,” none of it is written into the Act. It’s a promise about how that power will eventually be used, made at the press conference rather than in the clause.

The parts that are actually drafted, and drafted specifically, are elsewhere. Under-18 protections extend into design features — addictive mechanics, self-esteem effects — and into content categories: eating disorder promotion, misogynistic material, pornography, crime glorification, content causing serious mental health distress. eSafety gets removal powers over nudify apps, a streamlined cyber-abuse scheme, and — this is the part with actual teeth — the power to use registered researchers and its own investigators to test, directly, what platforms are serving users, rather than relying on platforms to self-report. Penalties run to $109.2 million, per the government’s own figure. Legislation — still only an exposure draft, open for “targeted consultation” — is promised to be introduced before year’s end.

Read on its own, it’s a reasonable, even overdue, piece of platform accountability. Read in sequence, it’s the fourth or fifth distinct policy instrument Australia has produced on this issue in under two years, and each one was built to solve the problem the previous one created or failed to solve. That’s the part worth sitting with.

I wanted to ask a few questions even at this point so I’ll drop them in here as a by way and then get back in track with the analysis via the theory of change discussion.

Who the “registered/approved researchers” actually are — as far as anyone can currently say:

The bill’s own definition, once you read it rather than the press coverage of it, is narrower than “such as those from an Australian university” implies. Section 205B doesn’t offer university employment as an example of who might qualify — it’s a strict, three-part gate: to be an “approved researcher” you must (a) be employed by an Australian university, (b) be individually approved by the Commissioner under legislative rules, and (c) meet whatever other requirements those rules end up specifying. Independent researchers, journalists, and civil-society investigators are categorically excluded by definition, not just underrepresented in practice. The research itself has to clear a further bar too — approved by a university ethics committee and “of a kind prescribed by the legislative rules to be in the public interest,” a phrase that, like almost everything operational in this bill, is a placeholder for rules that don’t exist yet.

And the access itself is a power to create a scheme, not the scheme. Section 205C says the legislative rules “may” establish one or more “data access schemes” requiring platforms to hand data to approved researchers — what kinds of data, for what kinds of research, under what process, at what cost to the researcher, is all left to future rule-making. Nothing in the Bill as drafted actually obliges a platform to hand anything over yet. The sock-puppet power fares slightly better on specificity — sections 205G to 205L spell out clearly that both approved researchers and the Commissioner personally may assume false identities to create accounts, observe and download material, test platform features, and probe how a service responds to particular actions, with good-faith immunity from civil action built in. That’s genuinely detailed, operative law, not a placeholder — worth distinguishing from the data-access side, which is still almost entirely promissory.

This is functionally Australia’s version of the EU DSA’s Article 40 “vetted researcher” scheme, which is worth naming as a direct comparator, because that scheme’s actual track record is a caution, not a template to feel reassured by. EU vetted-researcher status is notoriously slow to grant. The Delegated Act specifies an 80-working-day decision window — and even well-prepared applicants routinely fail: a Dutch team with prior European Research Council pilot experience on Article 40 implementation, investigating TikTok’s role in Romania’s contested 2024 election, still failed on five of seven eligibility criteria. Eligibility is nominally broad, extending to universities, non-profits and civil society researchers, but studies of the first wave of applications found platforms rejecting requests via narrow readings of “systemic risk,” excluding non-academic applicants in practice, and handing over incomplete data even once access was granted.Australia’s version adds its own extra layer of narrowness on top — the university-employment requirement is tighter than anything explicit in Article 40 — while leaving the actual data-access obligation exactly as undefined as the EU’s was at the equivalent stage. If Australia copies the label without copying — or improving on — the implementation detail, “approved researcher” risks becoming exactly the kind of unresolved gap Josh Taylor flagged with the opt-out mechanism itself: real on paper, undefined in practice, left for platforms and regulators to fight out later.

On the AIO —parallel timing

A Conversation piece published back in July — “Australia wants a ‘digital duty of care’. But how will we check what Big Tech is doing?” — presented the argument from Australian Digital Media researchers that the duty of care needs an “ecosystem of observability” combining three things: regulatory powers to compel platform data, independent research infrastructure (data donation, browser/mobile measurement, secure research environments), and stronger individual rights for Australians to access, download and donate their own platform data. They named the AIO directly as “one model for this infrastructure.” So this isn’t two separate efforts converging by coincidence — it’s the same research network pushing on two levers at once: build the bottom-up data-donation infrastructure regardless of what parliament does, and publicly campaign for the top-down regulatory access powers that just showed up in the exposure draft two months later.

During the same week’s coverage: Chanel Contos’s National Press Club appearance and the NSW Government’s urgent September 4 roundtable following the Sydney schoolboy assault allegations are being cited directly by other commentary as part of the pressure that shaped this exposure draft — her “23 minutes to misogynistic content” statistic is functioning as the kind of concrete evidence the researcher-access provisions are explicitly meant to make independently verifiable going forward, rather than something advocates have to keep re-measuring themselves via burner-phone experiments.

And what does “harmful content” mean?

And while we’re here going down byways, there is another point worth pulling from the ADM+S policy brief , because it sharpens the “harmful content” categories in the bill in a way that matters beyond researcher access.

Back in June, before any of this had bill text, ADM+S and the University of Melbourne’s CAIDE published a policy brief responding to the government’s Issues Paper, arguing the duty of care should move “beyond specifying a set of narrowly defined risks to safety… to require platforms to address broader, systemic risks.” Their central worry, laid out as a named case study, was harm-reduction and public health communication — evidence-based outreach on HIV and drug use has a documented history of suppression, account restriction and rejected advertising on these platforms, not through deliberate policy but as “the inevitable by-product of automated content moderation systems trained to identify, suppress and remove adult or offensive content.” They predicted, in writing, that a narrowly-defined risk-based model wouldn’t fix this — “risk” captures potential harms, not the absence of legitimate positive content — and proposed concrete affirmative protections instead: moderation exemptions for government-funded health organisations, expedited review for wrongly suppressed public-health material, regular audits of moderation systems’ impact on health content.

None of that made it into the bill. What section 25C actually contains is a narrowly-defined categorical list — eating disorders, misogynistic content, terrorism, crime, and, among the entries the government didn’t put in its own press release, material that “encourages, promotes, urges or instructs illicit drug use.” That’s precisely the drafting style ADM+S told government, months earlier, wouldn’t protect the harm-reduction communication they were worried about — and the affirmative protections they proposed to fix it are nowhere in the draft. So this isn’t a hypothetical risk a colleague raised after the fact. It’s a predicted, documented harm, from the government’s own consulted research network, that the exposure draft appears to walk straight into

A theory of change that was available, and wasn’t used

Now, getting back to where we were in the chronological chain of events. Here’s the thing that gets lost every time this gets reported as a fresh initiative: the design-first version of this reform already existed, in 2024, before the account ban was legislated. Zoe Daniel’s private member’s bill on platform duty of care predates the Social Media Minimum Age Act. It was left to lapse. The government reached for the ban instead — a chain that started with a South Australian premier’s Mother’s Day 2024 social media announcement and a News Corp campaign the following week, gathered momentum through the year via other state premiers and an opposition election promise, and culminated in legislation drafted, introduced and passed in under two weeks, with a 24-hour public comment window, in the last sitting week before the federal election.

I’ve written before about what that sequencing choice cost in evidentiary terms. What I want to name now is what it cost architecturally. Once the ban passed, an entire enforcement apparatus grew up around it: the Phase 2 industry codes, the age-assurance vendor contracts, the trusted-provider lists, eSafety’s document-demand powers reaching into third-party verification companies. That apparatus is not neutral scaffolding sitting empty, waiting for a better policy to move in. It has vendors with revenue tied to its continuation, a regulator whose newly expanded enforcement muscle (the Online Safety Amendment Bill, moving through parliament the same week) reaches further into that same verification paradigm, and a political constituency built around “world-first” account restriction as the signature achievement.

So when the duty of care — the reform actually aimed at design, not access — finally arrives, it doesn’t land in an empty room where design-first thinking can shape the whole architecture from scratch. The bill does sweep away one layer of the pre-existing apparatus — Schedule 3 repeals the general online content scheme codes entirely, folding content-classification into the unified duty of care. But the age-verification layer this apparatus was actually built around — the Phase 2 codes, the vendor contracts, the trusted-provider lists — survives untouched, with its penalties increased the same week. The duty of care has to be built around that surviving core, not replace it. This isn’t a coherent strategy unfolding in the right order. It’s a good instrument arriving after a worse one has already poured the foundation, and having to accommodate the foundation rather than correct it.

The mechanism undercuts its own justification

There’s a second problem, sitting inside the bill itself rather than in its timing. The government’s language around My Feed, My Way is explicitly universalist — Wells frames it as “basic standards for the online products we use every day,” alongside cars, toys, food. That’s inclusive-design logic: build the protection into the system for everyone, rather than trying to identify and specially protect a vulnerable subset. It’s good theory. Universal design works because the protected state is the automatic one — nobody has to find it, understand it, or activate it. Curb cuts don’t require a wheelchair user to request one.

But My Feed, My Way is an opt-out, not an opt-in. The algorithmically optimised, high-engagement default stays exactly where it is; the protective state is the thing a user has to notice, understand, and deliberately choose. We already know what that produces, because we’ve watched the experiment run. Under oath in the Oakland federal trial last August, Instagram’s Adam Mosseri confirmed an internal Meta document had put uptake of its “Take a Break” feature — designed to interrupt exactly the kind of compulsive scrolling this bill is meant to address — at 1.8%, a figure the company never disclosed even as it publicly touted a 90% retention rate among the small number who’d turned it on. Meta’s own internal research pointed the same direction on a related question: making teen accounts private by default, rather than opt-in, was projected to prevent 5.4 million unwanted daily message interactions. The lesson, from the company’s own numbers, is not subtle — default state decides outcomes; availability of a safer option barely moves anything at all

The EU has required platforms to offer a non-algorithmic feed option since February 2024 — and in October 2025, an Amsterdam court still had to order Meta to fix it, giving the company two weeks to comply under threat of a €5 million penalty. It turned not a multi-month enforcement fight, not just a quick fix. As Bits of Freedom’s Rejo Zenger, who brought the case, put it: “even if users can switch feeds, they cannot set a preferred feed that persists, and the platform continually nudges users back to the profile feed.” Meta disputed the ruling and appealed — and for now, the binding order applies only in the Netherlands, not EU-wide. If the justification for going broad rather than narrow is genuinely inclusive-design thinking, the logically consistent implementation is an opt-in default, which is what the Greens and Chanel Contos have been arguing for. The government chose the version that photographs the same way in a press release but almost certainly won’t behave the same way in practice.

Who this doesn’t reach, and who’s left holding it

And then there’s the population question, which is the one that should worry anyone thinking about this as a child-safety measure rather than a general consumer-choice one. The opt-out applies to users over 16. The government’s own account ban was supposed to mean under-16s aren’t the audience for this at all — they’re not meant to be logged in, so the question of their feed algorithm shouldn’t arise.

Except eSafety’s own evaluation data says otherwise. Three months in, account ownership among under-16s had fallen from 52.4% to 42.1% — real, but partial. Of the children who kept accounts, the platform-by-platform breakdown shows two distinct failure modes, both damning in their own way. On YouTube, nearly half never even got asked to verify their age — no prompt at all. On Facebook, the single most common reason was different and arguably worse: the age already listed on the account was 16 or above, meaning a check did happen and simply accepted a false answer. Instagram and Snapchat sit in between, with “never asked” narrowly ahead of “false age accepted” on both. Either way, “reasonable steps” is failing at more than one point in the process — not just an absent gate, but a gate that doesn’t hold. Independently, the University of Newcastle’s BMJ study found more than 85% of under-16s still using restricted platforms at the same three-month mark.

Meanwhile the adults meant to be managing all of this — parents and teachers — have less visibility than they had before, not more. eSafety’s own evaluation found parental awareness of children’s social media use actually declined after the ban took effect, concentrated among parents of girls and 10–12 year olds. Teachers, who inherit whatever happened in a student’s feed the moment it walks into a classroom the next morning, get no new tools at all in this bill — the digital literacy and relational-education infrastructure that would let schools and families actually build capability, rather than just manage fallout, isn’t part of the package. It’s the same gap Lisa Given flagged about the earlier duty of care consultation: real teeth on paper, aimed at platforms, with nothing resourced for the people standing between the platform and the child.

The generational bet nobody has actually defended

There’s a longer-run theory of change sitting underneath all of this that almost never gets said out loud, and I think it deserves to be dragged into the open, because I’m not convinced it survives contact with the evidence we already have.

The theory goes something like this: the ban won’t look like it’s working on the generation that’s already on these platforms, because they were socialised into algorithmic social media before the restriction existed, and restriction always looks like resistance in its first cohort. But the next generation — Gen Alpha, kids who are eight, nine, ten right now — will turn 16 having never legally held an account. For them, the age gate won’t be an imposition on an established habit. It’ll just be an unremarkable fact of childhood, the way not being allowed to drive at twelve is. Robinson, La Sala and Harrison named this directly in their 2025 title: is this a “seatbelt moment” — a restriction that looks costly and contested at first and becomes invisible, uncontested background norm within a generation — or a missed opportunity dressed up as one?

It’s a coherent theory. Seatbelts really did work that way: resistance was highest among drivers who’d learned to drive without them, and uptake became close to automatic once a full generation had never known driving any other way. If social media restriction follows the same curve, today’s dismal compliance numbers — 85%+ of under-16s still using restricted platforms, half of retained accounts never even prompted for age checks — aren’t a verdict on the policy. They’re what a first cohort always looks like, and the real test is what a fully Gen Alpha 15-year-old’s relationship to these platforms looks like in 2032.

But I want to push on two things before I let that theory do any work, because right now it’s operating as an unexamined assumption rather than something anyone has actually argued for or is measuring.

The first is empirical, and it’s sitting in plain sight in the argument over whether “brainrot” belongs to Gen Z or Gen Alpha. The honest answer is both, and how it belongs to both is the point: Gen Z, with full algorithmic platform access, generated and refined this content natively — the irony, the absurdist compression, the in-group signalling. Gen Alpha, meanwhile, absorbed an enormous amount of it into daily vocabulary and offline culture without needing platform accounts of their own to do it. Skibidi Toilet, sigma, rizz — this is a nine-year-old’s vocabulary now, transmitted through older siblings, playground repetition, YouTube (which sits partly outside the restriction architecture), and family devices, not through a personal, algorithmically curated feed. That’s a direct empirical challenge to the seatbelt theory’s core mechanism. Seatbelt norms shifted because the behaviour itself — driving unbelted — has no meaningful peer-transmission pathway once you’re not behind a wheel. Platform culture has an enormous one. Excluding a nine-year-old from an Instagram account doesn’t wall them off from the platform’s cultural output; it just changes the delivery mechanism from direct and individually curated to lateral and peer-mediated. If the goal was a generation genuinely insulated from what these platforms produce, the account ban may be solving the wrong layer of the problem entirely — the content diffuses regardless of who’s logged in.

The second problem is normative, and it’s the sharper one: even if the seatbelt theory worked exactly as advertised, is a childhood spent in what we might call a stigmatised relationship to social media — access as illicit, policed, something you get around rather than something you’re taught to navigate — actually the outcome we want? We have a template for what stigma-based restriction does to adolescent behaviour, from decades of underage drinking and smoking policy, and it isn’t uncomplicated normalisation. It’s secrecy from the adults meant to be guiding you — which is precisely what eSafety’s own data already shows happening, with parental awareness of children’s social media use declining, not rising, since the ban took effect. It’s status economies built around successful circumvention rather than around competent use — TikTok how-to guides on evading TikTok’s own age gate, published on the platform being regulated, are not a normalisation success story, they’re the underground-economy version of the same dynamic. And it forecloses exactly the capability-building the digital literacy argument I made above is trying to protect. A generation that grows up treating platform access as contraband to be smuggled rather than a tool to be taught isn’t obviously better prepared for the platforms they’ll use as adults — a cliff-edge from total exclusion to unrestricted access at 16, with no graduated exposure and no explicit skill-building in between, is a pedagogy problem dressed up as a public health win.

And here’s what makes this a genuine theory-of-change problem rather than just a debate to have later: nobody is actually measuring which of these dynamics is occurring. eSafety’s longitudinal evaluation tracks account status, usage duration, and self-reported wellbeing. It isn’t set up to track cultural diffusion, peer-transmission of platform content among excluded users, or whether the relationship young people have to these platforms is becoming one of literacy or one of stigma. We’re running a generational bet — quietly assuming the seatbelt curve will apply, structuring policy timelines around a 2027–2028 review window that presumes it — without building the instruments that would tell us, a decade from now, whether we bet on the right mechanism at all.

A brief detour through brain rot, because it’s not really a detour

I want to pause on something that looks like a side issue and isn’t, because it’s sitting in the same water as everything above it, and because I keep watching it get used as if it settles an argument it can’t actually settle.

“Brain rot” was Oxford’s word of the year for 2024, and since then it’s been doing an enormous amount of unexamined work in exactly this debate. The trouble is that nobody using the term is using it to mean the same thing. Pull apart the ways it’s actually deployed and you get at least four distinct referents wearing one label: a content genre (the singing toilets, the AI-slop, the absurdist short-form video); a slang register that circulates alongside that genre and, tellingly, migrates into offline speech among children who’ve never held a personal account — which is itself a data point against the idea that account restriction meaningfully insulates a generation from platform culture, since the vocabulary clearly doesn’t need an account to travel; a subjective experiential state, the “fogged-out, low-selectivity” feeling Maxi Heitmayer’s Gen Z interview subjects describe, in which the content is a response to an already-depleted state rather than its cause; and, most recently, a proposed clinical construct — a psychometric “Brain Rot Scale,” explicitly modelled on substance-addiction neurobiology, complete with subscales for Attention Dysregulation, Digital Compulsivity and Cognitive Dependency, tested on an Egyptian convenience sample and explaining a modest 35% of variance, with the authors themselves conceding it hasn’t been validated against any existing measure of problematic internet use. Thoreau, who coined the term in Walden in 1854 “will not any endeavor to cure the brain-rot, which prevails so much more widely and fatally?” meant something different again: not an individual affliction at all, but a society choosing simple ideas over complex ones.

What’s genuinely funny, once you go looking, is that Thoreau didn’t stop at the diagnosis, he named the genre. A chapter later, in “Reading,” he takes aim at the popular fiction of his day, cheap, serialised, mass-produced, and devoured compulsively by readers (TikTok rabbit holes anyone?) he compares to cormorants, “who can digest all sorts of this, even after the fullest dinner.” He even mocks the marketing copy, inventing a title that reads uncannily like a lost brainrot video: “The Skip of the Tip-Toe-Hop, a Romance of the Middle Ages… to appear in monthly parts; a great rush; don’t all come together.” And his diagnosis of what this content does to its readers could be lifted whole into any 2026 op-ed: “dulness of sight, a stagnation of the vital circulations, and a general deliquium and sloughing off of all the intellectual faculties.” Deliquium and sloughing off of the intellectual faculties. Nineteenth-century Thoreau just described the brain-rot feeling, named its genre, mocked its marketing, and diagnosed its symptoms, a hundred and seventy years before anyone thought to build a psychometric scale for it. He even had a theory of supply: “this sort of gingerbread is baked daily and more sedulously than pure wheat or rye-and-Indian in almost every oven, and finds a surer market” — which is just the engagement economy, minus the engagement.

All of which is a nice bit of trivia (and it’s my blog, so good times), but it’s also a useful check on where the seriousness actually lives in this debate. Thoreau could name the genre, mock the marketing, and diagnose the feeling — but he never mistook any of that for a discovered fact about the brain. That’s the distinction the current moment keeps losing. This is Ferguson’s construct balkanization problem, which I cited earlier in relation to Rausch and Haidt, showing up again in a completely different corner of the same debate: a folk category getting formalised into something that reads as diagnostic before anyone has established it’s distinct from constructs we already have names for. A scale with excellent internal reliability tells you the instrument is internally consistent. It doesn’t tell you “brain rot” is a real, discrete thing rather than a relabelling of attention difficulties, compulsive checking and existing problematic-use patterns that already have measures.

And it matters which definition is doing the work, because they don’t point toward the same account of what’s happening, let alone the same fix. Compare three recent, more careful pieces of evidence side by side. The passive-sensing study on adolescent phone use I wrote about last week found that low mood predicts more scrolling the next day — a general, content-agnostic disengagement response, consistent with mood management theory: feeling bad, reach for something that costs nothing. Doomscrolling, the pandemic-era construct, is narrower and arguably runs on a different engine entirely — purposeful seeking of threat-relevant, distressing content, closer to anxious vigilance than numbing, a coping strategy that backfires by compounding the very anxiety it’s trying to manage. And Heitmayer’s brain rot, on his own account, sits closer to the first mechanism than the second: his participants describe seeking out content that makes no demand and carries no threat, the near-opposite of doomscrolling’s compulsive checking of bad news. Three different psychological stories, three different underlying mechanisms, one increasingly interchangeable vocabulary — and each new content cycle seems to arrive with a fresh label rather than a resolved question about whether the last one was even right.

Here’s the useful, if slightly deflating, thing this detour actually tells us. Ask what any of this changes about the case for something like My Feed, My Way, and the honest answer is: less than the discourse implies. The strongest evidence for regulating engagement-optimised feeds doesn’t need brain rot, in any of its four senses, to be real. It’s sitting in independent, peer-reviewed research conducted with Meta’s cooperation: when Facebook and Instagram users were switched to chronological feeds for three months in 2020, as part of Meta’s own Election Study with outside academics, they spent measurably less time on the platforms, “suggesting they had become less compelling” — about as clean a demonstration as exists that the algorithmic ranking isn’t neutral scaffolding, it’s the thing actively manufacturing the engagement everyone is worried about. (The same study found the changed feed didn’t measurably shift polarization or political attitudes — a different question from the one this section is asking.)

That evidence stands regardless of whether “brain rot” turns out to be attention dysregulation, mood-driven disengagement, cultural slang, or nothing distinct at all. Which means that when brain rot gets invoked as the reason we need to act — rather than the algorithmic economics standing on their own — it isn’t adding evidentiary weight, it’s borrowing urgency from a construct nobody has actually pinned down. That’s precisely the move I flagged at the top of this post: evidence handled like a fridge magnet, taken out of the room it lives in and put somewhere it can do a different job. The tobacco analogy one of Heitmayer’s own interview subjects reached for — regulate the industry, don’t just tell the individual to smoke less — doesn’t require anyone to have first proven brain rot is a diagnosable condition. It only requires the engagement economics to be what they demonstrably already are.

All over the shop, precisely

So: is this a coherent theory of change finally showing its hand? I don’t think that’s quite right either, and I want to be precise about the claim I’m making, because “incoherent” undersells it. There have been several theories of change here, each internally sensible on its own terms, arriving in the wrong order and now stacked on top of each other rather than replacing one another. The ban’s theory: exclude the population, protect by absence. The industry codes’ theory: verify identity, gate by age. The duty of care’s theory: fix the system, protect by design, regardless of who’s in it. And running underneath all three, unstated and untested: the seatbelt theory, betting that generational turnover will eventually make the first three retroactively look right, on a timeline nobody has committed to actually measuring. Each of these is individually defensible. None of them were built with the others in mind, because none of them were legislated — or even articulated — in the order a single coherent strategy would have chosen. Design-first was available, and shelved, in 2024.

What we’re watching now isn’t a strategy unfolding. It’s a government retrofitting the reform it should have started with onto infrastructure built by the reform it reached for instead, while badging the least structurally demanding piece of the retrofit — a toggle most users won’t find and Meta’s own numbers suggest they wouldn’t use if they did — as the headline. The eSafety document-demand powers, the researcher testing authority, the requirement that platforms document and maintain their harm-mitigation measures: that’s the part of this bill actually shaped by lessons learned, including from the EU’s own enforcement failures. It’s riding into parliament on the opt-out’s press cycle because it isn’t sellable on its own.

Even that’s only half true, though — the same research network likely got the researcher-access and data-scheme provisions largely adopted, while their central structural recommendation, an outcomes-based duty capable of protecting legitimate content like harm-reduction communication from algorithmic over-suppression, was not. Expert input didn’t fail to shape this bill. It shaped the parts that were easiest to say yes to.

I said in July that it was too early to call the ban a failure, and that cuts both ways — too early to call it a success, too. I’ll say something similar here: it’s too early to know whether the duty of care’s substantive parts survive Senate negotiation intact, or get diluted the way the penalty language already seems to have moved between May’s turnover-linked formula and September’s flat cap. That’s not just a hedge — it’s built into the bill’s own timeline. Schedules 2 and 3, the duty of care itself and the repeal of the old content-scheme codes, don’t commence until twelve months after Royal Assent; only the takedown-notice powers in Schedule 1 take effect immediately. But it isn’t too early to say the sequencing was a choice, not an accident, and that the bill in front of parliament right now is being asked to do the work of correcting an architecture it had no hand in designing.

The social media age ban saga: Another Day, Another Declaration

I’m writing this post because Australia’s social media ban has become a case study in how evidence gets bent to fit a conclusion that was decided before the data arrived — and every time someone with a platform declares victory, that framing hardens a little further into public memory, whether it holds up or not. Documenting it as it happens is the only way I can see, from my skill set, to keep the record straight before it sets.

[sigh] So here I go. I’m really trying not to harp on here, and I do try to progress the discussion, but there are a lot of recursive loops and logics to navigate.

I opened Jon Haidt, Ravi Iyer and Zach Rausch’s latest newsletter and there it was, sitting right under the headline like a benediction: “A journey of a thousand miles begins with a single step.” Lao Tzu, they tell us — though they can’t resist a little joke first, attributing an invented second sentence (“But if that first step is hard, then you should quit”) to unnamed critics, as if anyone doubting six months of shaky data is the one being glib here.

So I went back to Chapter 64 itself, instead of the fridge-magnet version. It’s a strange passage to reach for if you’re trying to defend a law that was drafted, introduced and passed in under two weeks with a 24-hour public comment window. The chapter gives two pieces of advice that I want to pick up here, and the ban’s defenders have managed to miss both of them. The first: deal with problems while they’re small. “That which is at rest is easy to be kept hold of… break it while it is feeble, scatter it while it is small. Act before it exists, regulate before disorder.” Platform design harms didn’t arrive last December — they’ve been documented, litigated and written about for the better part of a decade, and the instrument built to address them at the design level, the Digital Duty of Care, was left to lapse while the government reached for the bluntest tool available instead. The second argument: be as careful at the end as you were at the beginning. “The common people, in their undertakings, fail on the eve of success,” the same chapter says. “If they were as prudent at the end as they are at the beginning, there would be no such failures.” That’s not an argument for patience — it’s a warning against declaring success early and getting careless right as the real test arrives. Lao Tzu, I suspect, would have had more to say about a government that let the problem grow large before acting, and commentators that want to call an unfinished job a win, than he would about critics being impatient.

That’s the kind of move I kept running into working through this. Not lies, exactly — just evidence handled the way you’d handle a fridge magnet: taken out of the room it lives in, polished up, and put somewhere it can do a different job than the one it was built for. And once I saw Haidt’s name at the top, I knew what kind of piece this was going to be…

Here’s what got me. Not that Haidt is optimistic — optimism isn’t a crime. It’s that he’s declaring victory using studies that, when you actually open them up, say close to the opposite of what he’s implying. That’s not interpretation. That’s not “reasonable people reading the same data differently.” That’s citing a source for a conclusion the source itself explicitly rejects.

I’m not going to refute this newsletter line by line. That’s not the point of this post, and honestly, it gives the piece more structural respect than it’s earned. What I want to do instead is lay out the tensions this whole saga has surfaced — the ones sitting underneath the “it’s working” narrative, that I don’t think most readers following this story casually may have had the opportunity to piece together.

The pattern isn’t new

This isn’t the first time Haidt’s relationship with evidence has been flagged. Candice Odgers, reviewing The Anxious Generation in Nature back in 2024, called him “a gifted storyteller” whose “tale is currently one searching for evidence” — noting that hundreds of researchers looking for the effects he describes have found “a mix of no, small and mixed associations.” She pointed to a 72-country analysis of nearly a million people, which found no evidence that the global rollout of social media was associated with widespread psychological harm — if anything, the associations ran mildly the other way, with higher adoption linked to slightly better wellbeing, particularly among younger users. The study’s own authors are careful about what this does and doesn’t show: the associations were small, descriptive rather than causal, and drawn from a single platform’s data at a national level — not proof that social media is good for people, just an absence of the widespread harm signal a precautionary ban would presume. Odgers still specifically flagged that age-based restrictions and device bans were “unlikely to be effective in practice — or worse, could backfire.”

Haidt was flown in anyway, as the scientific keynote. Axel Bruns — an Australian Research Council Laureate Fellow at QUT and a past president of the International Association of Internet Researchers, who attended the Sydney leg in person — called it “a curious event.” The SA premier opened proceedings by declaring “the results are in and the science is settled,” which, Bruns notes dryly, “immediately undermined the summit’s stated consultative intent.” The keynotes bore that out: Jean Twenge delivering what Bruns calls “a masterclass in casually sliding from mere appearances of vague correlation to strongly suggesting but not explicitly claiming causation,” followed by Haidt. Meanwhile, the small number of Australian scholars actually invited — from a country Bruns notes is home to some of the field’s world leaders — were relegated to breakout sessions that, unlike the keynotes, weren’t included in the livestream. His verdict: “It was a petty slap in the face of our world-leading, home-grown digital media expertise… taxpayer money was wasted on flying out professional manufacturers of concern from the United States, just because their narrative suited the predetermined policy outcomes.” Two years on, watching Haidt mark his own homework on the policy his book helped inspire, it’s hard not to see the same move happening again, just with a different dataset.

What the actual evidence says

I went back through the studies they drew on to support their position on the “misconceptions” of the critics of the ban. Here’s the shape of it:

Barnes et al., BMJ — the most methodologically rigorous thing in this entire debate: preregistered, regression discontinuity design, STROBE-compliant. Their conclusion, verbatim: “little evidence was found of immediate substantive reductions in reported social media use by adolescents under 16 years.” Their causal estimate was a statistical null (P=0.92 and P=0.60). Their own follow-up opinion piece went further, warning that “policy decisions will continue to outpace the evidence needed to inform them,” and calling explicitly for evaluations “free from industry influence.”

Bursztyn et al. — a working paper, not peer reviewed, titled, with admirable bluntness, “Why Bans Fail.” Their model finds the only stable equilibrium for compliance sits around 18%, below the 27% currently observed — meaning their own math says things are more likely to get worse, not better. Worth noting: two of the authors hold equity in a digital-wellness company whose product category is exactly what they recommend as the fix.

The eSafety Commissioner’s own parent survey — found that the single biggest reason kids retained their accounts was that the platform simply hadn’t gotten around to checking their age yet. Not sophisticated evasion. Not circumvention. Nobody asked.

Molly Rose Foundation — 61% of previously-active 12-15 year olds still had an account four months in, 70% said it was “easy,” and 60-64% said the platform had taken no action at all. Their analysis is blunt about what this means: it gives parents “a false sense of safety” while letting platforms “off the hook” for the safety-by-design work that might have actually helped.

None of this is ambiguous. None of it requires charitable reading to arrive at “not working yet, and possibly not built to work at all.”

The bit that actually made me sigh

Haidt’s newsletter lists “companies are making their products safer” as one of five reasons for optimism. I went looking for what backs that up. There isn’t anything. Not in what I could find, not in any of the studies cited alongside it. And the reason is structural, not incidental: the ban doesn’t ask platforms to change anything about how they’re built. It asks them to remove a demographic. Design, algorithms, engagement mechanics — completely untouched, for whoever remains on the platform, child or adult.

Lisa Given put this more precisely than I have: the law “does not hold technology companies to account for the content they present, or the potential harm posed by their algorithmic designs.” What has reappeared, in May 2026, is a likely to be a zombie version of the idea — a consultation paper, not legislation, reanimating some of the same design-based principles Zoe Daniel’s original bill contained, but stripped of urgency and arriving into a regulatory landscape the ban and its industry codes have already reshaped. It proposes real teeth on paper — penalties of the greater of 5% of global turnover or $50 million, risk assessments, researcher data access — but it’s still pre-drafting, with a 12-month transition period built in even after it passes, if it passes. Which puts genuine operation, at the earliest, years away.

Sequencing, not just failure

This is the part I think gets missed in the “is it working / isn’t it working” framing entirely, and it’s the point I keep circling back to. It’s not just that the ban hasn’t reduced access. It’s that while everyone argues about that, an entire age-assurance and identity-verification architecture is being built and commercially entrenched underneath it — through the ban’s enforcement apparatus, and through the Phase 2 industry codes running in parallel, developed by industry associations rather than debated in Parliament. Vendors are signing multi-year contracts. Trusted-provider lists are being drawn up. The age-verification industry itself is now lobbying eSafety for stronger powers, because a bigger, more entrenched enforcement regime is a bigger market for them.

By the time the Digital Duty of Care — the thing that would actually regulate design rather than access — arrives, if it arrives, it walks into a room where the surveillance infrastructure is already the established baseline. It doesn’t replace that infrastructure. It accommodates it.

And nobody who matters has weighed in yet

Here’s the thing that undercuts Haidt’s “it’s succeeding” framing more than any single study: the actual evaluation hasn’t happened. The government’s own assessment — led by Stanford’s Social Media Lab with an eleven-member international Academic Advisory Group — is still underway, feeding into a legislative review that doesn’t even start until 2027. Design and analysis sit with eSafety and Stanford; the advisory group’s own statement is careful to note it “does not represent the government, nor does our work constitute either endorsement or opposition to the legislation” — real independence, but advisory independence, with no lever to act on what it finds. The panel includes Amy Orben, the Cambridge researcher who co-authored the ABCD brain-imaging study that Candice Odgers cited against Haidt’s “great rewiring” thesis in her original Nature review — a preregistered study of over 10,000 children that found no meaningful relationship between screen engagement, including social media specifically, and neurodevelopment, cognition or wellbeing, “even if we set the evidential threshold very low.” Haidt is nowhere in that process. Not on the Stanford team, not on the advisory panel, not named anywhere in eSafety’s evaluation documentation. He’s commenting from outside it, ahead of it, using a working paper called “Why Bans Fail” — whose own modelling puts the stable compliance equilibrium below the rate currently observed — as evidence that it’s succeeding, while the scientists actually tasked with finding out are still years from reporting.

And in among all of it — the industry lobbying, the compliance updates, the newsletter victory laps — the people this law is actually about are almost entirely absent. When researchers did ask them: 72% of under-16s told Bursztyn’s team they’d prefer a self-limiting app to an outright ban. Molly Rose found only 31% of affected kids felt safer; 14% felt less safe. That’s not nothing. That’s the population the law claims to protect, telling anyone who’ll listen that the thing built for them wasn’t built with them.

It’s too early to call this a failure. I want to be careful about that, because “too early to tell” cuts both ways — it’s also too early to call it a success, which is exactly what Haidt did anyway. That’s the thing about being careless at the end instead of the beginning: the government rushed the law through in eight days, and now its loudest defender is rushing the verdict, declaring the journey is on the path to success if we just give it time… before the first proper measurement has even been taken. Lao Tzu had a word for that too, a few lines further into the same chapter: whoever grasps, loses.

When a Digital Duty of Care Becomes Lipstick on a Pig: Policy Sequencing, Market Logic, and the Importance of a Theory of Change

We want the internet to be safer. For our kids. For ourselves. We want to communicate, find information, collaborate, create, share, engage, participate and have fun. We want to seek out what we need — including the full range of adult content that adults have always sought — in ways that are appropriate to who we are and where we are in our lives. We want age-appropriate access that doesn’t require us to hand over our passports to every platform we visit. We want the architectural conditions of digital life to be designed for human flourishing rather than engineered for compulsive use. And we don’t want the solution to these problems to be a surveillance infrastructure that violates the privacy rights it claims to protect.

These are not unreasonable things to want. They are, in fact, the things that good digital regulation should deliver.

But there is something more specific underneath all of this. We want digital environments that lean toward a caring orientation. Spaces where the default assumption is that users are people with complex needs, relationships, vulnerabilities and capacities — not attention units to be harvested. Where the architecture of the platform supports human connection rather than exploiting it. Where the experience of being online doesn’t require constant vigilance against the system that is supposed to be serving you.

That is the design brief. And almost nothing about the regulatory choices being made right now — in Australia, in Europe, in the UK, and across the globe — is actually building toward it.

Person wearing pig mask applying red lipstick and taking a selfie in office cubicle
Image: AI generated image riffing off the lipstick on a pig concept. No animals were harmed in the making.

The Market Logic Nobody Wants to Name

Before getting to the policy failures, it is worth being precise about why they keep happening. The answer lies in market logic that is so entrenched, so global, and so structurally opposed to a caring orientation that no single national regulatory instrument can adequately address it.

The incumbent platforms — Meta, TikTok, Google, Snap — are not primarily communication services that have some problematic features. They are attention extraction machines that have communication as a byproduct. The product is engagement. The inventory is human time and psychological state. The business model optimises for the time users spend in states of arousal, comparison, compulsive return, and social anxiety — because those states generate the engagement signals that drive advertising revenue.

Every design feature that has been identified as harmful — infinite scroll, algorithmic recommendation, social feedback loops, disappearing content, notification systems, engagement-maximising AI — is not incidental to how these platforms make money. It is how they make money. The harm is the business model. The architecture that exploits developing brains is the same architecture that generates billions in revenue. Internal corporate communications — made visible through litigation processes rather than through corporate transparency — show that companies knew this and chose not to adequately address it. This is evidence of deliberate design intent, not corporate negligence.

Regulation that doesn’t change this underlying market logic doesn’t address the problem. An age ban doesn’t change the market logic — it removes a demographic without reforming the architecture that exploits them. Age verification doesn’t change the market logic — it adds a compliance cost that large platforms absorb and small competitors cannot. Even design obligations only change the market logic if the penalties make harmful features more expensive than the revenue they generate. For Meta, whose annual global revenue exceeded USD200 billion in 2025, a flat AUD49.5 million fine — Australia’s maximum penalty — is a rounding error. It does not change the calculation.

This is why the financial structure of regulation is not a technical detail. It is the mechanism by which regulation actually changes what the market produces. Penalties proportionate to global turnover — 5% to 10% — make the cost of harmful architecture real in a way that flat caps never can. Design obligations without proportionate penalties are aspirations. Design obligations with proportionate penalties are market signals.

The global reach of these platforms makes this harder still. TikTok’s recommendation algorithm is trained on engagement data from over a billion users across every jurisdiction. Meta’s systems don’t differentiate by country. A platform regulated to remove infinite scroll in Germany still has infinite scroll optimised on data from 3 billion users elsewhere. A national design obligation is a local intervention in a global architecture. This is why harmonisation matters — not just for legal coherence, but for actual effectiveness. The European Digital Services Act‘s harmonised framework, with Commission-level enforcement against Very Large Online Platforms, is structurally more capable of changing the market logic than any national ban. But only if it is designed with the financial penalties and design obligations that make compliance cheaper than non-compliance, and only if it is consistently enforced.

The attention extraction economy also produces a specific kind of competitive moat. The more data a platform has, the better its recommendation system. The better its recommendation system, the more engaging the platform. The more engaging the platform, the more users it attracts. The more users it attracts, the more data it has. This is a self-reinforcing loop that incumbents have been running for fifteen years. Regulation that adds compliance costs without breaking that loop entrenches incumbents rather than challenging them — because large platforms can absorb the compliance cost while smaller competitors cannot build the alternative at scale.

What the Australian Social Media Age Ban Has Taught Us

Australia’s Social Media Minimum Age Act came into force on 10 December 2025, banning children under 16 from holding accounts on designated social media platforms. It was the world’s first such ban. It passed in the last sitting week of 2024, introduced and passed within eight days, with a 24-hour public submission period that received 15,000 submissions, of which only 107 were published. This expedited process occurred shortly before a federal election that was called four months later in March 2025. FOI correspondence reported by Crikey and analysed by researcher Amanda Third showed the national Social Media Summit was designed to “build momentum for a decision already made,” not to deliberate on evidence. The political momentum was performative — the instrument was chosen for its communicative power rather than its causal effectiveness.

Six months in, the picture is clear.

The ban is not working on its own terms. The Molly Rose Foundation’s survey of 1,050 Australian 12-15 year-olds found 61% of those who previously had accounts on restricted platforms still have access to at least one active account. Among those still accessing banned platforms, 60-64% said the platform had taken no action to remove their account. The dominant story is not children cleverly circumventing the ban. It is platforms failing to comply.

The harm measures haven’t moved. The eSafety Commissioner’s own compliance report found no measurable drop in cyberbullying or image-based abuse complaints from children under 16 in the first three months of enforcement. These are the direct harm measures the ban was designed to move. They haven’t moved. Because the harm is in the architecture. And the architecture hasn’t changed.

Children were not consulted. The policy was designed by adults, about children, driven by adult anxieties, in a process that made meaningful child participation structurally impossible. A FOSI survey conducted in December 2025 found 65% of Australian parents support the ban — but only 38% of Australian children did. 56% of children said they feared losing important connections and support. The recent EU Kids Online network’s survey of 29,169 children across 19 European countries found 45% disagree that an age ban would make them safer online. Children knew this wouldn’t work. Nobody adequately asked them. They just became media soundbites.

Vulnerable children have been made less safe. Teenagers who bypassed the ban by appearing as adults lost the safety features platforms built specifically for teen accounts. The children most likely to circumvent the ban — the most determined, often the most vulnerable — have been stripped of the protections designed for them.

The ban was built on the wrong argument. It was passed on a mental health narrative — the claim that social media is the primary driver of the youth mental health crisis. That causal claim was contested in the peer-reviewed literature at the time of enactment and remains contested. The government has since quietly shifted the rationale — writing recommender algorithms and endless-feed features into the legal definition of a harmful platform — without acknowledging it. The shift is correct: the harm is in the design architecture. But arriving at the right argument after passing the wrong instrument doesn’t fix the instrument.

The Social Adoption Curve and the Workaround Economy

Regulation that ignores how people actually behave in response to restrictions will consistently produce outcomes it didn’t intend. The social adoption curve — how technologies spread through populations, become embedded in social norms, and resist displacement — is not a peripheral consideration for digital regulation. It is central to whether regulation achieves anything.

The NBER working paper surveying 835 Australian teenagers four months after the ban found that only about one in four 14-15 year-olds comply. Most banned teens believe their peers are still using platforms and cite social reasons for continuing. Teenagers reported they would need roughly two-thirds of their peers to stop using social media before they themselves would stop — far above the share currently complying. The more influential teenagers disproportionately stay on the platforms. The ban hasn’t shifted the social norm, and without that shift, legal prohibition alone cannot move behaviour.

This is not a failure of enforcement. It is a failure to understand how social technologies become embedded in the texture of everyday life. Social media is not a product that teenagers chose from a range of alternatives. For many, it is the primary infrastructure of peer connection, social identity, cultural participation, and information access. Removing it without providing alternatives — without investing in digital literacy, without creating safer spaces, without engaging with the social dynamics that make these platforms so central — is like removing a road and expecting people not to find another route.

The workarounds don’t just circumvent the regulation. They route around the safety infrastructure too. When teenagers bypass the ban they don’t find a safer internet. They find Discord servers, Reddit threads, private WhatsApp groups, and gaming platforms — all less moderated, less visible to adults, and more opaque to regulatory oversight. The Molly Rose Foundation data shows 43% of children are using gaming platforms more and 39% are using messaging apps more since the ban. These spaces are not covered by the ban, have weaker safety systems, and are harder for researchers, regulators, and parents to monitor. The unintended consequence of the ban has been to push children’s online activity into less regulated environments while maintaining the fiction that they are protected.

Social norm change does happen — and when it does, it can be powerful. But the evidence from decades of public health research suggests that norm change is produced by education, social modelling, environmental design, and cultural shift — not by prohibition that lacks meaningful enforcement and ignores the social dynamics that make the prohibited behaviour attractive. The ban cannot shift the norm because it doesn’t address why the platforms are so central to teenagers’ social lives in the first place. That is a design problem. And design is what the ban doesn’t touch.

The Age Verification Architecture: Surveillance by Another Name

The ban’s enforcement depends on platforms verifying users’ ages. Australia’s law requires “reasonable steps” without specifying what those steps must be, and mandates that verification data be deleted once its purpose is served.

In practice, platforms deployed a patchwork of unreliable methods. Facial recognition proved wildly inaccurate near the 16-year threshold. The government’s own age assurance technology trial found that no single solution suits all use cases — and that some vendors were proactively retaining biometric and identity data beyond legal requirements, anticipating future law enforcement or regulatory requests that didn’t yet exist. This is surveillance creep in documented, real-world form. The legislation required deletion. Vendors were building retention infrastructure instead.

The attack surface problem is structural. Every mandatory age verification requirement creates a chain of custody for sensitive identity information. Every link in that chain is vulnerable. The Discord breach of September 2025 — in which government identity documents submitted for age verification were accessed through a compromised third-party provider — illustrated exactly what mandatory verification creates. Third-party age assurance providers don’t just become attack vectors. They become commercially entrenched ones, with incentives to retain rather than delete the data they process.

There is also a fundamental confusion in the verification approach between identification and safety. Safety is a property of environments. Identification is a property of users. Making an environment safe does not require knowing who is in it. Article 28(3) of the EU’s Digital Services Act makes this explicit: compliance with child safety obligations “shall not oblige providers of online platforms to process additional personal data in order to assess whether the recipient of the service is a minor.” Europe’s primary platform safety instrument explicitly says you do not need identity verification infrastructure to protect children. The design obligation can be met through architecture, not identification.

The identification-surveillance-rights tension cannot be resolved within the verification framework. It can only be dissolved by the design framework, which doesn’t require it. If platforms are required to make their services safe by design for everyone, the question of who users are becomes largely irrelevant to the regulatory obligation.

The Kitchen Sink Problem: Two Instruments in Operation, One Horse Being Backed

Australia has two regulatory instruments already in operation that are pulling in opposite directions — and a third that the government is now hastily backing as the evidence mounts that the first two are seemingly in conflict with their desired outcomes, but rapidly servicing an economic boon in age assurance technologies.

The age ban says under-16s should not be on restricted platforms — access control through exclusion. It is being enforced now, with formal investigations underway against five major platforms.

The Phase 2 industry codes extend age assurance obligations across the commercial internet infrastructure that most Australians use daily — social media, messaging, gaming, search engines, hosting platforms, app stores, and operating systems. Surveillance architecture through identity verification at every layer of digital life. Already being implemented. Commercial infrastructure being built around it now.

These two instruments share a theory of change: identify users → gate by age → safety through exclusion and verification. They are the horses that won the race to be saddled first.

The Digital Duty of Care is the horse now being backed after the race has started. Released as an issues paper for consultation in May 2026 — eighteen months after the ban passed — it proposes that platforms must maintain safe environments through effective systems and processes, covering the entire commercial internet infrastructure that most Australians use daily: social media, messaging, gaming, search engines, hosting services, app stores, internet service providers, equipment and operating systems, and generative AI capabilities embedded in service provision. It has a fundamentally different theory of change: design safe environments → safety through architecture.

It is not legislation. It is not law. It is a consultation document that may or may not become legislation, that if it becomes legislation will commence no earlier than 2028, into a regulatory environment where the surveillance architecture will have had three or four years of commercial entrenchment. Whether it actually passes is uncertain. Whether it retains its ambition through consultation, drafting, parliamentary debate, and an election cycle is more uncertain still. The government that releases issues papers is not the same thing as a government that passes legislation — as Australia’s stalled gambling reform, its undelivered media bargaining code amendments, and a dozen other promised instruments demonstrate.

What is certain is that the Safety-by-Design angle of the Duty of Care cannot be coherent alongside the instruments that arrived before it. The ban removed under-16s as a regulatory lever — platforms no longer have a commercial relationship with that demographic, so design obligations for that age group have no market teeth. The industry codes built identity verification infrastructure across the entire internet stack before the design obligation existed to challenge it. By the time the Duty of Care arrives — if it arrives — the surveillance architecture will be the established compliance baseline and the design obligation will accommodate itself to that baseline rather than replacing it.

The first two instruments share a theory of change that is incompatible with the third. No amount of drafting ingenuity can resolve that incompatibility because it is not a drafting problem. It is a sequencing problem. And sequencing problems cannot be fixed retroactively.

This is what happens when policy is made reactively, under political pressure, without a coherent theory of change. The ban for electoral momentum. The industry codes for the enforcement gap the ban couldn’t address. The Duty of Care for the evidence gap the ban made visible — a gap that the evidence predicted before the ban passed and that the compliance data has since confirmed. Each instrument designed in response to a different political moment, without knowledge of the others, building infrastructure that points in opposite directions.

The kitchen sink approach feels comprehensive. It is, in fact, incoherent — and nobody in the political process is stepping back to ask what theory of change actually connects any of this to children being safer.

The Senate committee that passed the ban knew it was insufficient. In the same report, it recommended a Digital Duty of Care, meaningful engagement with young people, and an independent review within 18 months. Eighteen months later, the Duty of Care is still only an issues paper, children were not meaningfully consulted, and the compliance data has confirmed what the committee already knew: the ban alone was not enough.

First Mover Entrenchment: Why the Wrong Instrument Wins

The sequencing problem is worse than a policy mistake. It is a policy mistake that forecloses correction.

Regulatory infrastructure creates commercial ecosystems. Commercial ecosystems create incumbents. Incumbents invest in maintaining their position. Regulators incorporate incumbent frameworks into compliance standards. Compliance standards become the definition of reasonable steps. The alternative has to fight the established definition rather than starting from first principles.

The age assurance industry had a structural commercial interest in the Australian ban passing. Without mandatory verification requirements their market is voluntary and limited. With mandatory requirements — extended through Phase 2 industry codes across the entire internet stack — they have a legislatively mandated, expanding global market. The cascade of age ban legislation following Australia is, from their perspective, a commercial opportunity of extraordinary scale. Every new jurisdiction that follows Australia is a new market.

The trial dynamic illustrates the problem precisely. The Australian age assurance technology trial was run by the Age Check Certification Scheme — a UK-based company that specialises in certifying identity verification systems. The 53 vendors who participated were hoping to win contracts. Yoti — one of those vendors — was simultaneously already operating as Meta’s age verification provider for Instagram and Facebook in Australia. The trial was partly evaluating a vendor that was already commercially embedded in the platform being regulated.

Meta’s participation in the trial was not a technology submission — it was a policy position paper arguing that Apple and Google should bear the age verification infrastructure burden at the operating system level. A platform being regulated used a technology evaluation process to argue someone else should build the infrastructure.

By the time the Digital Duty of Care might commence — 2028 at the absolute earliest — the age assurance industry will have had three or four years of commercial entrenchment. The ACCS accreditation framework will be established. Trusted provider lists will be published. Yoti, k-ID, and whoever else made the cut will have multi-year contracts with major platforms. The regulatory definition of “reasonable steps” will have been shaped by the infrastructure that already exists — which is surveillance-based, not design-based.

The Duty of Care arriving into that environment does not displace the surveillance architecture. It layers design obligations on top of it. Platforms satisfy their risk assessments by pointing to their age assurance compliance. Design-based safety becomes an aspiration accommodated within the surveillance infrastructure it was supposed to replace.

This is the lipstick. The pig is already there.

The Market Foreclosure Nobody Is Talking About

Building expensive surveillance infrastructure as the baseline compliance requirement for operating digital services locks out the competitive innovation ecosystem that could produce the alternatives we actually need.

Age verification at scale requires technical capability, regulatory accreditation, legal compliance across jurisdictions, and ongoing operational infrastructure. These requirements favour large, well-resourced incumbents who can absorb compliance costs. They disadvantage smaller players who might otherwise develop genuinely safer localised alternatives — platforms designed from first principles around user wellbeing rather than engagement maximisation, community-governed spaces, federated architectures, open-source tools, cooperative models.

A small company building a genuinely caring social platform for young people cannot afford the age verification infrastructure required to operate legally under the industry codes. The incumbent platforms — Meta, TikTok, Google — can. The regulatory requirement that was supposed to hold them accountable instead reinforces their monopoly position. This is not an incidental side effect. It is a predictable consequence of designing compliance infrastructure around the capabilities of the largest players.

The attention extraction economy already has a massive first-mover advantage built on fifteen years of engagement data, network effects, and platform lock-in. Surveillance-based compliance requirements compound that advantage. They create regulatory moats around incumbents that make it structurally harder for new entrants to compete — even new entrants with better, safer, more caring designs.

This matters because market competition, properly structured, is a more powerful mechanism for improving platform safety than any single regulatory instrument. If a platform with a genuinely caring orientation — one that doesn’t exploit users, builds in natural stopping points, recommends content for user want rather than engagement maximisation — can compete effectively with Meta and TikTok, the incumbents face pressure to match it. If the regulatory architecture makes it impossible for that platform to exist, the pressure disappears and the incumbents have no incentive to change.

The caring orientation we want from digital environments is more likely to emerge from a diverse, competitive innovation ecosystem than from regulatory mandates on entrenched monopolists. Mandates matter — but they work best when they operate alongside competitive pressure that makes compliance in the spirit of the regulation commercially rational, not just legally required.

What the Duty of Care Gets Right — And Why It Arrived Too Late

The Australian Digital Duty of Care issues paper is, on its own terms, a well-designed framework. It is worth being clear about what it gets right, because the argument here is not that the Duty of Care is wrong. It is that it arrived too late, in the wrong sequence, into an environment that has already foreclosed much of its potential.

It proposes design obligations covering the commercial internet infrastructure Australian’s access — including generative AI capabilities embedded in service provision. This is genuinely forward-looking. Generative AI is no longer just a discrete tool that users consciously choose to engage with. It is disappearing into the infrastructure of everyday digital experience — embedded in recommendation systems, content generation, conversational interfaces, image manipulation, synthetic social interaction. The harm is becoming invisible precisely as it becomes more pervasive. A regulatory framework that covers AI as it is actually deployed, rather than as a separate product category, is the only framework that can keep pace with that technological shift.

It proposes penalties of up to 5% of global annual turnover, with a floor of AUD50 million — proportionate, not performative. For Meta, 5% of global turnover would be in USD billions. That is a different conversation entirely from the ban’s maximum penalty — currently equivalent to approximately AUD $49.5 million — which for the largest platforms amounts to a calculable cost of doing business rather than a genuine deterrent.

It proposes researcher data access, independent audit powers, transparency requirements, and executive accountability. These are the instruments of ongoing accountability rather than one-time compliance. They create the evidence base that regulatory decisions require and the governance structure that makes accountability real rather than performative.

This is, essentially, what Australia should have passed instead of the ban. It is what Zoe Daniel’s Digital Duty of Care Bill introduced on 25 November 2024 — four days after the social media ban was tabled, lapsing when Daniel lost her seat in the federal election. The right framework existed. The wrong instrument passed instead.

But the Duty of Care is still only an issues paper. Not legislation. Not law. Pre-consultation, with no timetable for introduction, no guarantee of passage, and a 12-month commencement period after passage. It will not be operational before 2028 — into a regulatory environment where the surveillance architecture will have had three or four years of commercial entrenchment, where the age assurance industry’s trusted provider lists will have defined what compliance looks like, and where the market foreclosure of smaller competitors will have narrowed the innovation ecosystem that the Duty of Care depends on to work.

The right framework. The wrong sequence. And by the time it arrives, the pig will be so thoroughly established that the lipstick is all that’s visible.

Toward a Caring Digital Environment: What the Theory of Change Actually Looks Like

The alternative starts with a different question. Not “how do we stop harm” — a defensive, prohibitionist frame that produces bans and verification infrastructure. But “how do we cultivate environments that lean toward care” — a constructive frame that produces design obligations, competitive innovation, and genuine safety.

A caring orientation in platform design means: recommendation systems that notice when a user is in distress and surface support rather than amplifying distress content. Interfaces that create natural stopping points rather than eliminating them. Social feedback mechanisms that may reinforce connection and mutual support rather than performance and comparison. Defaults that create safe conditions rather than expose. Design that treats users as people with complex needs rather than attention units to be harvested. GenAI capabilities that are designed to support rather than exploit the people they interact with. Architecture that serves the user’s actual interests rather than the platform’s engagement metrics.

This is achievable. Elements of it already exist. The question is whether regulation mandates it as the default or leaves it as an optional add-on to engagement-maximising architecture.

The coherent theory of change — the one that actually delivers what we said we wanted — follows this sequence:

Enforce existing obligations first. Platforms already prohibit under-13s. Make them prove it, with turnover-linked penalties for failure. The EU’s DSA enforcement is already doing this. Start where the law already is.

Design obligations with proportionate penalties. Risk assessments of harmful features, required mitigation, mandatory transparency, researcher data access, audit powers, executive accountability. Article 28 of the DSA with teeth. Financial penalties that make the harmful architecture more expensive than the safe one.

Protect the innovation ecosystem. Proportionate requirements for smaller platforms. Safe harbours for open-source, federated, and community-governed architectures. Active support for alternatives that don’t rely on engagement maximisation. The competitive pressure that makes market incentives work alongside regulatory mandates.

Age-appropriate spaces by design — not by identity. Default-safe architecture for younger users that adapts to developmental needs without requiring biometric data or government identity documents. Opt-in to higher-risk features rather than opt-out of safety. Design that serves the whole arc of young users’ digital lives.

Graduated access rather than cliff edges. If age-differentiated access to specific features is warranted, implement it gradually with digital literacy scaffolding, parental engagement, and design safeguards. No binary exclusion followed by unrestricted access at an arbitrary threshold.

Children’s voices throughout. The UN Convention on the Rights of the Child gives children the right to be heard in decisions that affect them. That right was not honoured in Australia’s ban. It must be built into any regulatory process that claims to act in children’s interests.

International coordination. Design obligations without international coordination are local interventions in a global architecture. Harmonised standards, mutual recognition of regulatory findings, and coordinated enforcement against platforms that arbitrage regulatory differences are prerequisites for regulation that actually changes global market logic rather than just shifting harm between jurisdictions.

This sequence puts design obligation first, surveillance infrastructure never, competitive innovation throughout, and children’s voices in the room from the beginning.

What Europe and the UK Can Still Do

Europe is not Australia. It has better foundational regulatory architecture, stronger privacy law, and a procedural framework — the DSA’s notification requirement — that is actively slowing the race of national ban legislation while the Commission builds harmonised alternatives.

Article 28 of the DSA already exists. It requires design-based safety obligations. It explicitly says compliance does not require processing additional personal data to identify minors. The EU Kids Online network — 29,169 children across 19 European countries — has told European policymakers to implement it. The Digital Fairness Act, expected Q4 2026, can extend design harm obligations with proportionate penalties and cover the emerging architecture of generative AI harm.

But Europe is not immune to the same political dynamics. France has passed its ban through the National Assembly. Germany’s governing coalition is calling for an under-14 ban. The age verification industry is positioning for the European market. The EUDI Wallet is being deployed. The trusted provider lists are being established.

The window closes when national bans become entrenched political commitments. When age verification industry codes are written into DSA compliance frameworks. When first mover entrenchment forecloses the design-based alternative. When the competitive innovation ecosystem is locked out by compliance infrastructure it cannot afford.

Once age bans pass, they cannot be repealed. Australia’s ban will stay on the books while the evidence continues to show it isn’t working, while the Duty of Care is quietly developed around it, and while the surveillance architecture it generated becomes the default condition of Australian digital life. No government repeals a signature child protection measure. The political ratchet only goes one way.

The lesson is not that child online safety doesn’t matter. It matters enormously. The lesson is that the instrument chosen determines what kind of safety is built — and what kind of digital future everyone inherits. An internet that leans toward care is achievable. It requires design obligations, proportionate penalties, competitive innovation, international coordination, and children’s voices in the room. It does not require surveillance infrastructure, biometric data, identity verification at every layer of the stack, or the foreclosure of the competitive ecosystem that could build the alternatives we need.

Australia chose the instrument that was easier to communicate. Europe still has the chance to choose the one that works.

But the window is open, not indefinitely. And the pig is already being prepared for its close-up.

Updated 9 June 2026: Legislative timeline corrected, currency notations clarified, and primary source links added throughout