Quick Summary. Australia's under-16 ban removed about 4.7 million accounts in a month, yet roughly 70% of children with accounts were still active by March. The UK logged 69 million age checks in six months. The clearest commercial outcome visible so far in both countries is a growing verification industry, with Yoti's revenue up 62%. India's version could differ, because a national identity rail already exists. But one unanswered design question, who exactly has to prove age, decides whether the market is worth crores or hundreds of crores.
Australia gave the world its first live experiment in banning children from social media. On 10 December 2025, the Online Safety Amendment (Social Media Minimum Age) Act took effect, barring under-16s from Facebook, Instagram, Threads, TikTok, YouTube, Snapchat, X, Reddit, Twitch and Kick. Platforms faced penalties up to A$49.5 million. Within the first month, around 4.7 million under-16 accounts had been deactivated or removed by eight technology companies, a figure Meta partially confirmed with its own disclosure of 544,052 accounts shut between 4 and 11 December.
The UK ran a different design one step earlier. The Online Safety Act 2023 imposed child-safety duties from 25 July 2025, requiring platforms to use "highly effective age assurance" to keep children away from pornography and self-harm content. It did not ban children from social media; it made age checking unavoidable at the points where harm concentrates.
The instinct in Indian commentary is to read these as previews of what New Delhi may now do, after the Supreme Court in late September 2026 asked the Centre to examine rules preventing children below 18 from independently holding social-media accounts, and the government told the Court it would insert such a provision into the IT Intermediary Rules. That reading is half right. The account purges appear likely to repeat. Much of the economics will not, because the two experiments the world has already run were built on infrastructure India does not have to build. And one design choice India has not yet made, whether only minors get verified or every user does, matters more than any technology decision that follows.
The purges were real and fast. The departure was not.
eSafety's own survey by March 2026 found around 70% of Australian children who had held accounts on restricted platforms were still active. A parent survey of 898 respondents in April 2026 found 31.3% of children still had accounts. Qustodio's app-usage data from August 2026 showed TikTok use among 13 to 15-year-olds at 25.9%, barely one percentage point below the pre-ban level, and usage among 10 to 12-year-olds just 0.06 points below. Use of TikTok, Instagram and Snapchat was, if anything, rising among both bands.
The workarounds were predictable. Circumvention guides appeared on TikTok within a day. The most common methods, in observed order of prevalence, were a fake or older date of birth, then borrowing a parent's or older relative's credentials, then migrating to exempt or smaller apps. VPNs came last: only about one in twenty young users cited them as their workaround, per the Molly Rose Foundation's survey, even though VPN traffic ran 160 to 170% above baseline for months. WhatsApp use among children increased, because WhatsApp was exempt.
The UK shows the same pattern with sharper edges. Proton VPN reported UK registrations up over 1,400% in the hours after the law took effect. Ofcom's first statutory report, published in July 2026, documented over 69 million age checks across a sample of 32 regulated services between July and December 2025, a 23-fold increase on the prior six months. It also stated bluntly that "social media companies have failed to enforce their minimum age requirements properly."
Two follow-on observations matter for India. First, enforcement lagged in both countries: Australia's eSafety opened investigations into Facebook, Instagram, Snapchat, TikTok and YouTube only in March 2026, and by June the government had introduced draft legislation to double penalties, with the minister reportedly frustrated that improvements were not visible. Second, on the question everyone braced for, advertising, there is limited evidence so far of a large aggregate shock. Australian analysts noted teen users contribute cultural relevance but relatively little direct purchasing power, and the 4.7 million removed accounts were a small fraction of overall audiences. Aggregate platform advertising revenue appears less affected than user engagement. Some spending and attention do migrate to other platforms and to unregulated corners, but nothing in the retrieved evidence supports assuming a one-for-one transfer of either. One documented second-order effect: Australian teen creators shifted operations abroad.
The clearest commercial outcome visible so far in both regimes is that the fee for compliance flowed to a thin vendor layer, and it grew fast.
Yoti, the London-based facial age estimation specialist, reported 2025 revenue of £29 million, up 62% year on year, EBITDA profitability in every month since March 2025, and more than 1 billion cumulative age checks passed in November 2025. Its digital identity wallet crossed 21.5 million downloads. Instagram used its age estimation. Roblox and Reddit deployed Persona, another verification provider, for facial estimation and document checks. In the UK, over 6,000 adult-content sites adopted age assurance, and Ofcom found facial age estimation and photo-ID matching were the most commonly deployed methods across regulated services.
Pricing, where visible, is enterprise and volume-driven rather than list-priced. High-volume machine-only checks settle at single-digit cents; general identity checks run from $0.15 to $1.89. That spread is the story of a market being pulled toward commodity pricing, a pressure reinforced when Apple and Google began supplying platform-level age signals free on mobile.
The Australian trial before the ban validated roughly 48 vendors, which suggests the barrier to entry is modest. So is the moat. Regulation created the demand, but nothing in either regime suggests the demand accrues to a durable oligopoly; it accrues to whoever is certified, integrated and cheap on the day the platform signs.
The large platforms did not outsource the core. Meta, TikTok and Snap deactivated accounts from day one using internally built facial age estimation and document matching, outsourcing at the edges only. Ofcom's framework makes this explicit: whether the check is built or bought, liability sits with the platform. No quantified compliance-cost disclosure emerged from Australia, and no quantified study of post-ban advertising shifts surfaced; on the money question, both regimes are louder about penalties, up to A$49.5 million in Australia, £18 million or 10% of global revenue in the UK, than about costs.
The asymmetry that did document itself is scale. In the UK, some smaller adult-content providers ceased operations rather than absorb the fixed cost of compliance. A fixed-cost wall of that kind falls hardest on the smallest platforms, and pushes their users either to the majors or to the unregulated fringe.
Read as a value chain, the regulation pays four layers:
| Layer | Who | How it earns | Economics |
|---|---|---|---|
| Social platforms | Meta, Google, ByteDance, Snap, X | Pays everyone below; bears penalties | Cost centre, plus advertising exposure |
| Age-assurance providers | Yoti, Persona, Signzy, HyperVerge, IDfy | Per-check fees, retail-priced | The layer with real pricing power, compressing fast |
| Identity and KYC infrastructure | KYC orchestration, document and liveness checks | Wholesale component fees | Commoditising |
| Government identity rails | Aadhaar, DigiLocker, or open banking | Statutory per-query fees | Choke point, near-zero fee |
The UK's 69 million checks in six months is what it looks like when this volume flows to commercial vendors at contract rates. Australia's trial-validated 48 vendors is what the supply side looks like before concentration. Neither country sent the volume through a state identity system, because neither could.
Here is the idea that should sit at the front of any India analysis, because it dominates every number that follows.
Australia's platforms could identify children because accounts carried declared ages, and the ban targeted those accounts. India's roughly 750 million social-media accounts carry no reliable age attribute at all. That fact splits India's possible regulation into two different markets.
A minors-only gate, built on the DPDP Act's Rule 10 parental-consent machinery, would require verification for roughly 24 to 47 million minors and the parents consenting for them. A flat Australia-style gate, because there is no reliable way to know who is an adult, would in principle drag around 455 million adult users through age assurance alongside them. The same law, applied to the same population, produces a verification volume an order of magnitude apart depending on that one drafting choice. On the scenario math below, it swings the vendor pool roughly seventeen-fold.
Neither the UK nor Australia faced this at Indian scale. Australia has about 26 million people and a declared-age starting point. The UK regulates content categories, not accounts. India's gate would be the first attempt at account-level age assurance across a population this size, which is why the unanswered design question deserves its own section.
Who actually has to prove age?
The promised IT Rules amendment, as reported, targets under-18s opening accounts. But implementing that sentence requires choosing a model: verify only users a platform flags as possible minors, verify every new account, re-verify every existing account, verify users of particular content categories, verify anyone whose declared age is uncertain, or apply universal age assurance to the whole user base. Each model implies a different volume, a different privacy footprint and a different vendor market. A minors-only design touches tens of millions. A universal design touches hundreds of millions of adults who have done nothing wrong except be unverifiable on paper.
This is not a technical detail. It is the single most important variable determining the size of India's verification market, and it maps directly onto the scenarios below: the Conservative case assumes a minors-only consent gate, while the Base and High cases assume a flat gate at different levels of enforcement. Nothing retrieved establishes which model the government will adopt.
The table below is a set of scenario estimates, not forecasts. The results are driven mainly by five assumptions: whether only minors or all users need verification, the number of annual verification events per user, the assumed cost per verification, the intensity of enforcement, and the assumed share of advertising value attached to young users. The verification events, per-check costs and the 5 to 15% youth-ad-share band are stated assumptions anchored to Indian KYC pricing (₹1-10 for eKYC-style checks, up to ₹3-200 for digital KYC products), not measured market outcomes.
| Line | Conservative: DPDP consent gate only | Base: flat gate, partial enforcement | High: flat gate, strict enforcement |
|---|---|---|---|
| Annual verification events | 61.5 million | 523 million | 592 million |
| Cost per verification | ₹5 | ₹10 | ₹20 |
| Total verification spend | ₹0.3 billion | ₹5.2 billion | ₹11.8 billion |
| Vendor revenue pool | ₹0.3 billion | ₹5.0 billion | ₹11.5 billion |
| Government DPI fee leg | ₹0.03 billion | ₹0.26 billion | ₹0.30 billion |
| Under-18 ad value at stake | ₹21 billion | ₹42 billion | ₹64 billion |
| Ad value captured by alternatives | ₹0.8 billion | ₹8.5 billion | ₹33.5 billion |
| Parent-paid subscription pool | ₹60 crore | ₹400 crore | ₹750 crore |
The vendor revenue pool is a scenario estimate driven by scope and enforcement assumptions, not a forecast: a minors-only consent gate yields ₹0.3 billion a year, a flat gate with strict enforcement ₹11.5 billion.
Context makes these numbers honest. A vendor pool of ₹5 billion a year, the base case, is meaningful against Signzy's roughly $18 million in revenue or Digio's roughly $15 million; a 25% share would add about $15 million a year to one vendor. It is a rounding error against Airtel's ₹2,20,049 crore trailing revenue or Reliance's ₹11,38,865 crore. The DPI layer, at ₹0.50 a check, sets the design and captures almost none of the money.
Two caveats belong beside any reading of this table. The displaced advertising value assumes youth represent 5 to 15% of a roughly $5 billion digital ad market, a band, not a measurement. And the enforcement realisation is discounted by the Australian experience, where most of the removed usage never actually left.
India begins with infrastructure neither benchmark had, and the distinction between what exists and what must be built is where the honest analysis lives.
What exists today is authentication and credentialing infrastructure. UIDAI's regime prices a Yes/No authentication check at ₹0.50 against ₹20 for full eKYC, and it ran 231 crore authentication transactions in November 2025 alone, with 2,457.95 crore eKYC transactions in FY2025-26. DigiLocker issues document credentials and its design contemplates an age token that returns a yes-or-no answer on an age bracket without transmitting the Aadhaar number; document fetches are priced around ₹10.
That is a cheap identity rail. It is not a working age-verification system, and the gap between the two is where the engineering and the law sit. A Yes/No authentication confirms that a person exists and authenticates, not how old they are. The DigiLocker age token is a design for privacy-preserving age assertion, not a notified service that social-media platforms are authorised to call for onboarding. For the rail to carry social-media age checks, several things would still need to happen: a legal authorisation letting platforms make age queries for this purpose, a published token or age-assertion API specification, a pricing schedule for the social-media use case, and rules defining what satisfies the platform's compliance obligation. The rail makes the check potentially cheap. It does not make the system built.
This is the inverse of Australia's design choice, which explicitly excluded government-ID verification, and of the UK's, which permitted photo-ID but has no national identity layer. On India's rail, 200 million checks a year would cost about ₹10 crore in government fees, against roughly ₹2,000 crore at Western facial-estimation pricing, if the authorisation and plumbing are actually created.
The telco layer sits in the same posture. Indian operators hold over 1.14 billion KYC'd subscribers enrolled through Aadhaar eKYC, and Ofcom rates mobile-network-operator age checks as capable of being highly effective. Whether a verified date of birth exists per subscriber is not established, and no authorisation framework for a telco age query has been notified. The raw material exists; the product does not.
The vendor base is ready on capability, short on order book. Signzy, with roughly $18 million in revenue and more than 240 APIs, has already productised an age-verification API against the Australian and UK regimes. HyperVerge, with 750 million-plus users onboarded and revenue in the ₹100-500 crore band, has the volume infrastructure. IDfy, at about $25 million ARR, has face-match technology used against gaming age fraud, though facial age estimation itself was not among its retrieved products. Digio, with 100 million individual users, sits adjacent through DigiLocker integration rather than in assurance itself. None of them has a disclosed social-media age-assurance contract in any jurisdiction, which is the gap between capability and revenue.
Australia's evidence says the displaced time does not vanish, and mostly does not monetise where it lands. The largest migration lane was exempt messaging, which carries essentially no advertising. Gaming is the strongest monetisable lane in India: a market projected to grow from $3.8 billion to $9.2 billion by FY29, with in-app purchases up 41% year on year and 488 million players. EdTech sits on a projected path from $12.75 billion toward $61.25 billion, and OTT at $4.96 billion growing 10.8%.
The listed-market transmission, though, is thin. Nazara's Kiddopia, the obvious kids'-app asset, earned ₹189.6 crore in FY26 revenue with about 80% of its market in the US, so an Indian ban barely touches it. PhysicsWallah, at ₹1,082 crore of Q3 FY26 revenue, is private. The parental-control and kids'-safety software layer is overwhelmingly private as well. India's listed market offers almost no clean vehicle for the displaced-attention theme, and the verification theme is entirely private-market.
Five effects appear particularly likely to repeat. Fast formal compliance, then leaky substance. The circumvention hierarchy of fake birthdays, parental credentials, exempt apps and finally VPNs. Facial age estimation as the default method wherever no age attribute exists. Vendor-layer growth at enterprise pricing that compresses toward commodity rates. And enforcement that arrives late and escalates: Australia's five investigations, its penalty-doubling bill, Ofcom's own criticism of platform enforcement.
Five will not, or not in the same shape. India's VPN spike is pre-empted by saturation: 43% of residents already use VPNs, an estimated 364 million people, so evasion infrastructure exists at population scale before the first rule is notified. The shared-device household, where usage skews young and rural, undermines account-level gates at the root in a way neither benchmark faced. The vernacular grey tier, with 98% of Indian users consuming Indic-language content and over 60% of YouTube watch time regional, gives migration lanes that English-first Australia never had to police. The breach risk at the verification layer, already documented abroad in Discord's ID-appeal data breach and the Au10tix hack, carries far higher stakes in an Aadhaar-linked design. And enforcement itself runs through an untested Data Protection Board with ₹200-250 crore penalties, without Australia's dedicated, resourced eSafety apparatus, while the courts rather than parliament sit at the centre of the design.
Then there is the part of the comparison nobody in Delhi is discussing: cost recovery. Australia spent $6.5 million on its trial within a $76 million package, and the UK funds Ofcom through industry fees. The IT Rules route carries no cost-recovery regime at all.
The honest summary of the two completed experiments is that they changed accounts more than behaviour, generated a real but modest verification industry, and so far show limited evidence of a large aggregate advertising shock. If India copies the gate, it should expect the same.
But India is not copying the plumbing. The UK and Australia asked how to verify people expensively at the platform edge, with vendors, facial estimation and ID uploads, while protecting thin privacy regimes. India, running the world's largest identity DPI with a legislated token design that answers one binary question without disclosing identity, could ask the opposite question: how to let platforms ask that question cheaply, at 455 million scale, without ever learning who the answer belongs to. If that design is adopted, it inverts the economics twice. The per-check price collapses by up to forty-fold, shrinking the vendor pool relative to any Western analogue while multiplying volume by orders of magnitude. And the strategic value concentrates in whoever holds the consent and token relationship, the government DPI by default, telcos and consent managers if authorised, rather than in the estimation specialists who captured the UK's fees.
Australia and the UK demonstrated the behavioural limits of age restriction. India could produce a different economic model, because its age assurance may be connected to an existing national digital identity infrastructure rather than bolted on at the platform edge. The open question is whether India can turn age assurance from a platform-level compliance problem into a piece of digital infrastructure in its own right.
The sequence of signals over the next two years, roughly in order of leverage:
This article is a historical and descriptive analysis of regulatory developments, market structures and publicly reported data. It is not investment advice, a research report, or a recommendation to buy, sell or hold any security, and it should not be treated as one. No investment recommendations, rankings, scores or price targets are expressed or implied. Company mentions illustrate documented or potential exposure to a regulatory theme; they do not constitute an assessment of investment merit. Market-size figures and scenario estimates are analytical constructions based on stated assumptions, not forecasts, and actual outcomes may differ materially. The Indian regulation discussed is proposed, not enacted, and its final design is unknown. Figures relating to private companies, international providers and third-party surveys are drawn from publicly available sources at the time of writing and have not been independently audited. Readers should consult primary filings, official regulator documents and qualified professional advisers before acting on anything here.