Australia moved the age check into the app store

10.09.2026 8 min 4

From 9 September an app store in Australia has to know whether you are an adult before it lets you download an app rated R18+. Apple, Google, Microsoft and anyone else running a marketplace are covered. The check has moved off the adult website and onto the shelf you buy from, and that is a bigger shift than the date suggests.

In short

  • Age assurance for R18+ downloads became mandatory for app stores in Australia on 9 September 2026, the last piece of the Age-Restricted Material Codes to take effect.
  • Ignoring a formal direction from the eSafety Commissioner can cost up to A$49.5 million.
  • The codes set the outcome, not the method. Parental confirmation, a card check, facial age estimation, a digital ID wallet or a third-party provider all qualify, and government ID is not mandatory.
  • A VPN does nothing here. The store reads your account, not your IP address.

What actually changed

Australia's Age-Restricted Material Codes cover nine slices of the industry, from search and hosting to messaging, gaming and app distribution. Most of them took effect on 9 March 2026. App stores were given six extra months to build the plumbing, and that grace period ran out on 9 September. From that date a marketplace has to take appropriate steps to stop under-18s buying or downloading apps rated R18+, and to keep those ratings accurate and visible.

9 Sep 2026the day app stores lost their grace period
A$49.5mmaximum civil penalty for ignoring an eSafety direction
6 monthsextra time app stores got over the rest of the codes

The penalty is worth reading carefully, because it is not a fine for a single missed download. eSafety first has to find a service non-compliant and issue a formal direction. Ignoring that direction is what can trigger a civil penalty of up to A$49.5 million.

How the three big stores do it

StoreWhat it reads
Apple App StoreSignals already attached to the Apple Account: the age on the profile, payment history, Family Sharing status. The Declared Age Range API hands an age band to apps without giving them a date of birth.
Google PlayThe Play Age Signals API, fed by what a parent has already set in Family Link. Developers get a band, not a birthday: 0-12, 13-15, 16-17 or 18+ verified. Nothing is shared by default, and the data may not be used for advertising, analytics or profiling.
Microsoft StoreThird-party verifiers Yoti and Verifymy: email confirmation, facial age estimation, an ID scan or a credit card check.

Apple did not wait for the deadline. It began blocking 18+ downloads in Australia, Brazil and Singapore back in February 2026 until the user confirms they are an adult, and rolled the same machinery out for Utah and Louisiana. In other words, for a large share of Australians the change already happened months ago and the September date only made it compulsory for everyone else.

What the rules do not demand

Three things are easy to get wrong here. The codes do not name a specific technology. They do not require a government-issued document. And they do not send your information to the regulator or to any other part of the state. The company running the store picks the method and has to be able to defend it.

That freedom cuts both ways. A store that already knows your age from years of purchases can answer the question quietly, from data it holds anyway. A store that knows nothing about you reaches for whatever is cheapest and most defensible, and in practice that means a face scan or a card. The regulation does not ask for your face. The economics of compliance do.

The trade-off nobody puts on the label: moving the check to the gatekeeper is genuinely better than a separate age wall on every adult site, because your identity stops being scattered across dozens of small operators. The price is concentration. The one company that already knows your device, your purchases and your location now has a firm claim on your age as well, and a third-party verifier joins the chain whenever the store cannot answer from its own records.

Does a VPN get you around it?

No, and the reason matters more than the answer. A VPN changes the address your traffic comes from. This check never looks at that address. It looks at the country of your store account, the payment method attached to it, whether the account sits in a family group, and what the store already recorded about your age. Move your connection to Auckland and your Apple Account is still Australian, still holding an Australian card, still carrying whatever age signal it carried yesterday.

Switching an App Store or Play country is a separate operation that needs a payment method and address in the new country, and it does not erase the age attached to the account. A VPN is a tool for keeping your traffic private on the network you are using. It is not a costume, and treating it as one against a shop that has your card on file mostly ends in a locked account.

The same logic answers the traveller's question. If you land in Sydney with a US Apple Account, the Australian codes do not follow you, because the obligation attaches to the storefront your account belongs to, not to where your phone happens to be. An Australian account keeps the check when you fly out. Geography of the device is not what is being measured here.

  1. Check what your store already knows. Open the Apple Account or Google account settings and look at the date of birth on file. If it is wrong, that single field is what the store will act on.
  2. Set up children through Family Sharing or Family Link rather than letting them face a verifier. A parent-confirmed age band is the least invasive route the codes allow.
  3. Prefer the method that hands over least. An account signal or a card check beats uploading a passport photo, and stores usually offer more than one option.
  4. If a third-party verifier appears, read its retention terms, not the store's. A face scan or a document scan leaves your device and lands with a company you did not choose, so how long that image is kept, and whether it is deleted after the estimate, is the number that matters. Yoti and Verifymy publish theirs.

Why this is not only an Australian story

Australia is the first country to put the age gate at the level of the app store rather than the individual service, but the direction of travel is not unique to it. Windows 11 now hands apps an age bracket through its own API. Britain has moved to accept digital ID for buying alcohol. The Philippines requires a national ID to play Roblox, and a bill in Illinois would make the operating system itself check your age. Our running list of countries that restrict social media by age gets longer every month.

The pattern is consistent. Regulators have concluded that asking each website to check ages does not work, and they are moving the checkpoint down the stack towards the platform, the store and eventually the device. That makes enforcement simpler and it makes the checkpoint far harder to route around, which is the point.

Does this apply to every app, or only to adult ones?
Only to apps rated R18+ under Australian classification. Ordinary apps are unaffected, though stores also have to keep their ratings accurate, so some apps may be reclassified upward.
Will I have to upload a passport to download an app?
Not necessarily. The codes do not require government ID. Most people will be cleared by signals the store already holds, and where a check is needed the store usually offers a card check or facial age estimation as well as a document.
Does eSafety see my age data?
No. The codes do not require user information to be shared with any government body. The obligation sits on the company running the store, and the regulator checks compliance, not individual records.
What happens if a store ignores the rules?
eSafety has to find the service non-compliant and issue a formal direction first. A civil penalty of up to A$49.5 million applies to ignoring that direction, not to a single failed check.

age verificationprivacylegislationapplegooglemicrosoftgoogle playdigital idaustralia

Read also