The spring 2027 under-16 ban — and why it reshapes accounts for the whole household
You don't have a 14-year-old. You still get reshaped by the new verification rules. A practical guide to compartmentalisation, recovery hygiene, and what changes once a platform holds your verified ID.
You don't have a 14-year-old. The new rules still find you.
The age checks platforms roll out for the under-16 ban don't stop at the kid's login. They reshape how every account in the house gets created, verified, recovered, and tied to a real name. A teenager lives with you, or visits and picks up the shared tablet, and your threat model shifts with theirs.
The UK government confirmed on 15 June 2026 that social media platforms must block under-16s from holding accounts. Regulations land in spring 2027. Prime Minister Keir Starmer told the BBC the government "hopes to pass regulation before Christmas." The legal authority sits in Part 3 of the Children's Wellbeing and Schools Act 2026, which inserted a new section 214A into the Online Safety Act 2023. Ministers can introduce the ban as secondary legislation. No fresh Act of Parliament needed.
This guide walks through what the ban does, why it reaches adults sharing the house, how to compartmentalise devices and profiles before the checks land, and what account recovery looks like once a platform holds your verified ID. There's also a section for parents who disagree with the ban but have to operate inside the law.
What is the spring 2027 under-16 ban?
A set of regulations forcing social media platforms to stop anyone under 16 from creating or holding an account while in the UK. The government announced it on 15 June 2026. Enforcement happens through secondary legislation under powers granted by the Children's Wellbeing and Schools Act 2026, which got Royal Assent on 29 April 2026.
- Oct 2023Online Safety Act receives Royal Assent
- 29 Apr 2026Children's Wellbeing and Schools Act gets Royal Assent
- 15 Jun 2026Government confirms under-16 ban; Ofcom flags 16-vs-18 problem next day
- Before Christmas 2026Secondary regulations expected to pass
- Spring 2027Ban enforced; platforms must verify ages
The confirmed banned platforms as of mid-June 2026 are Snapchat, TikTok, YouTube, Instagram, Facebook, and X. In Australia, Bluesky voluntarily designated itself as age-restricted. Whether it does the same here isn't confirmed. The government says it will follow Australia's model closely. Australia added Reddit, Threads, Twitch, and Kick to its age-restricted list when enforcement started on 10 December 2025. The UK Department for Science, Innovation and Technology hasn't published the final platform list. It says it will in July 2026.
Messaging apps look set to be excluded, at minimum WhatsApp and Signal. Messenger was excluded in Australia and will probably follow here, though that hasn't been confirmed. Gaming services like Roblox face restrictions on specific features (stranger contact, livestreaming) but no full ban. YouTube Kids stays.
- TikTok
- Snapchat
- YouTube (main)
- X
- Signal
- YouTube Kids
- Roblox (feature-restricted)
- Messenger (Australia precedent)
- Email, SMS, school platforms
Platforms have to verify ages using what the government calls "highly effective age assurance." That means facial age estimation, photo ID matched against a government document, or a digital identity service like Yoti. The checkbox you've been clicking for twenty years stops working. Each method carries a different privacy bill, broken down in our comparison of every Ofcom-permitted age verification method.
Ofcom's letter on 16 June 2026 flagged the central practical problem. As the BBC reported, verifying whether someone is under or over 16 is harder than verifying 18. Credit card checks and email-domain checks work at 18. They don't work at 16. The regulator said it has "more work to do to understand the effectiveness and accessibility of different methods" at this threshold.
Does the ban keep kids off social media?
It won't stop a determined 15-year-old.
Australia's ban has been live since December 2025. By February 2026, Guardian Australia reported teenagers under 16 were still on the banned platforms. The BBC separately found that six months in, parents told regulators 70% of children were still on them. A December 2025 Essential Research poll put support at 57%, with only 34% expecting it to actually work. 66% thought it would be at least somewhat effective.
In the UK, Ofcom's adult-content age verification rules kicked in during July 2025. VPN downloads spiked immediately. Some users bypassed photo-based verification services like Persona by submitting images of video game characters. Stupidly simple. Worked anyway.
None of which makes the ban irrelevant. It does shift the practical question from "will it stop my kid?" to "what does compliance look like on a device my kid might use, and what data am I handing over?"
Most privacy guides skip that second question. It's the one that matters for adult account holders.
How does the ban reach adults who share devices with kids?
Tablet passed around the family. One computer with one login. A living-room TV signed into YouTube on your account. That's how.
Platforms use device-level signals to associate accounts with users. Login cookies, app install IDs, IP addresses, device fingerprints. When a platform sees an adult's verified account being used from the same device as a child's account, it may flag both for review. When it sees a child using a service from a device with no child account, the enforcement path asks the obvious question: who's the adult here? Usually you.
Meta's Australian rollout makes this concrete. In November 2025, Meta announced that from 4 December its platforms would remove under-16 accounts ahead of the 10 December deadline. Users had to scan a face or upload an identity document to prove their age. Once that ID attaches to an account, it doesn't stay walled off from the account recovery flow, the advertising graph, or what the platform hands to law enforcement when served with a lawful request.
The fix is compartmentalisation. Separate OS-level user profiles, not separate accounts on the same device login.
Setting up separate adult and child profiles
Most families run every device on one account. One Apple ID. One Google account. One Windows login. Every app inherits that login. Every age check hits whoever set up the device.
You want the opposite. Each person who uses a device gets their own OS-level profile. No child profile touches a social media app.
Here's what that looks like on the three most common household platforms as of June 2026.
Android. Settings → System → Multiple users. Toggle it on. Create a profile per person. Android's "restricted profile" mode lets you control which apps each profile sees. Pull social media apps from child profiles entirely. Lock the adult profile behind a PIN or biometric. Android's multi-user implementation varies by manufacturer, and some budget devices don't support it. Imperfect. Also the minimum viable separation.
iOS and iPadOS. iPhones don't support multiple user profiles. At all. iPads do, but only for educational managed devices. So for an iPhone in a household with a child, your options narrow to two. The child gets their own device with parental controls and no social apps, or they don't touch a shared adult device for anything that hits a platform account. If the kid needs a device for school or communication, a dedicated handset with Apple Screen Time restrictions and zero social apps is the closest you'll get to compartmentalisation on iOS. Costs money. Annoying. Also what the ban implies.
Windows. Windows supports local user accounts with separate profiles. Settings → Accounts → Family & other users. Each user gets their own desktop, documents, and app data. Microsoft Family Safety lets you restrict app installs and set screen time per child account. If the family PC is where a child does homework, their profile should have no browser logged into social media and no social apps installed.
ChromeOS. First-class multi-user support. Profiles are sandboxed. Set up a supervised child account through Google Family Link. You can block app installs, manage site permissions, and enforce SafeSearch at the account level.
Shared streaming devices. YouTube is on the banned list. YouTube Kids isn't. If your living-room device is signed into your YouTube account, that account is subject to the age check. If a child uses the device, switch to a YouTube Kids profile or use a separate child-specific Google account signed into the YouTube app. Log your adult account out if children have uncontrolled access to the device.
What changes when a platform holds your verified government ID
This part matters for years after the ban lands.
To prove you're over 16, platforms need something checkable. The methods being deployed or tested as of mid-2026:
Facial age estimation uses an AI model to guess your age from a selfie. Yoti, a UK-based provider, has published accuracy benchmarks for its model. Ofcom has noted accuracy at the 16 threshold is lower than at 18, and the regulator is now tasked with evaluating which methods actually work at this cutoff. The model runs on-device, sends an "over 16" or "under 16" flag to the platform, and claims not to keep the image. You trust that claim or you don't.
Photo ID matching means uploading a passport, driving licence, or national ID card photo, then the platform checks it against a live selfie. The provider (Persona, KWS — Kids Web Services, an Epic Games subsidiary used by Bluesky for UK age checks — or Onfido) sees both the document and the selfie. The platform may or may not retain the verification result as account metadata.
Digital identity services, like the UK's GOV.UK One Login, exist. None has been confirmed as an approved method for the under-16 ban specifically. In theory these could let you prove your age without handing a passport photo to every platform individually. Adoption has been slow. Ofcom's June 2026 letter notes that "the availability of identity and age attributes at 16" is limited compared to the 18 threshold.
Once a platform holds a verified identity, three things change.
Account recovery routes through the ID. If you lose access, the platform's recovery flow may demand the same document you verified with. Sounds fine, right up to the moment your phone gets stolen, your email gets compromised, or someone socially engineers the recovery process with your details. A platform that holds a passport scan is a higher-stakes target than one that holds only an email address.
The verified identity becomes linkable across platforms. A digital ID provider serving multiple platforms knows which ones you've verified with. The platform may share verification status with advertising partners under terms of service you didn't read. The Online Safety Act 2023 mandates verification. Data-handling falls under UK GDPR. How these regimes interact hasn't been tested in court.
Law enforcement access is a matter of process, not theory. Under the Investigatory Powers Act 2016, UK authorities can compel a platform to disclose subscriber information through designated senior officer authorisation. Whether a verified ID uploaded for age checks falls within standard communications data requests or needs higher authorisation hasn't been tested. If the platform holds it, it holds it for anyone who can serve the right paperwork.
Account recovery hygiene after the ban
If a platform has your verified ID, you need a recovery setup someone else can't walk through. The standard advice (strong password, 2FA) doesn't address what happens when the recovery path is a photo of your passport. The same principle behind a calm, opinionated starter set of tools applies here: a small number of well-chosen defaults, set up once, then forgotten.
Five things to do before the checks land.
Register a recovery email that isn't your primary and isn't linked to any social account. A separate Proton Mail or Tutanota address used only for recovery. Don't give it out. If your primary email gets compromised, the attacker can't use it to reset accounts whose recovery address they don't know exists.
Use TOTP-based 2FA, not SMS. SMS is vulnerable to SIM-swapping. Use an authenticator app like Aegis on Android or Raivo on iOS. Time-based codes generated on-device. Back them up with encryption, not to a cloud account.
Store backup codes offline. Every platform that does 2FA gives you one-time backup codes. Print them. Put them somewhere physical. If the platform also holds your verified identity, those codes are the only recovery path that doesn't route through the ID document.
Disable trusted-contact recovery where possible. Facebook and Google let you designate friends or family to help recover a locked account. If a platform holds your verified ID, that path gives someone else a way to trigger a recovery flow that might expose your verification status. Turn it off unless you have a specific, documented need for it.
Check what the platform already knows. Before the ban forces you to upload an ID, download your data from each major platform. Instagram, Facebook, Google, TikTok, X. Use each platform's own data export tool. You want a baseline of what they held before the ban so you can audit what changed.
What if you disagree with the ban?
You don't have to agree with a law to comply with it. You also don't have to hand over more than the law demands.
Based on the text of the Act, the Children's Wellbeing and Schools Act 2026 doesn't create a criminal offence for parents who help a child get around the ban. The penalties in the Online Safety Act 2023 framework hit platforms. Fines of up to £18 million or 10% of global annual turnover for non-compliance. Parents and children face no direct legal penalty under the current framework.
That said, three things you shouldn't do.
Don't create an account in your name and hand it to a child. It links their activity to your verified identity, your account history, your recovery path. If they post something that triggers platform moderation or law enforcement interest, the account is yours.
Don't use a commercial VPN that logs. A lot of VPNs marketed at families log connection timestamps, IP addresses, bandwidth usage. If a child uses the VPN to access a banned platform and the provider gets compelled to produce records by a UK authority or a foreign one, those records trace back to the billing account. Which traces back to you. Use a provider that's been through a public, independent no-logs audit, and read what "no logs" actually means under a UK production order before relying on the phrase. Even then, the VPN masks your network path, not the platform-level identity check. A platform asking for age verification at signup doesn't care what country your IP appears to be in if the check happens at the account level.
Don't use a fake or borrowed ID document. That's fraud. It's a criminal offence under the Identity Documents Act 2010. The penalty is up to 10 years in custody for possessing false identity documents with improper intention. The ban isn't worth a criminal record.
A realistic posture for a parent who disagrees with the ban: don't help a child evade it, and don't hand them your accounts. Choose communication tools for your household that aren't banned. WhatsApp and Signal are likely to be excluded. They do group chat, voice, and video without a feed, an algorithm, or an age check. If the goal is keeping a teenager connected to friends, they do the job. Whether that's adequate depends on your household, your kid, and your read of the social dynamics. That's your call, not the government's.
FAQ
Will VPNs be age-gated too?
Children's Minister Josh MacAlister told the BBC the government is considering "options there about whether we could age-gate VPN use." No legislation has been proposed. The technical problem is that age-gating a VPN defeats its privacy purpose. The provider would have to hold identity data. The opposite of what a no-logs VPN is built to do. Expect more in the July 2026 policy announcement.
What happens to existing accounts held by under-16s?
Based on how Australia handled it, platforms will either suspend accounts outright or require age verification on next login. In Australia, Meta started removing under-16 accounts on 4 December 2025, ahead of the 10 December deadline. Accounts that fail verification get locked. Some platforms offer data export before deletion. If your child has an account with irreplaceable content (photos, messages, creative work), back it up now.
Does the ban apply to visitors?
Yes. It applies to anyone physically in the UK, regardless of nationality or where their account was created. A 15-year-old tourist from France can't legally use TikTok in London, even if the account was registered at a French address. How platforms enforce this against short-term visitors is unclear. Ofcom's June 2026 letter flagged it as unresolved.
What if I already verified my age for adult content checks?
The Ofcom adult-content rules have been in force since July 2025. Those checks are at the 18 threshold. The under-16 ban needs a different threshold using different methods. A verification that passed at 18 doesn't automatically transfer. But if you used the same digital ID provider for both, that provider knows you checked in twice, for two platforms, at two thresholds. The data exists. Whether it's retained, shared, or deleted depends on the provider's policy and your data protection enforcement. In the UK, that's the Information Commissioner's Office.
Who enforces this?
Ofcom. It can fine platforms, issue service restriction orders, and (if a court agrees) block services entirely. It can't fine parents, children, or individual users. The Australian model is different: the eSafety Commissioner takes platforms to court for non-compliance. The UK routes everything through Ofcom as the designated regulator under the OSA 2023.
Last reviewed 17 June 2026. The Children's Wellbeing and Schools Act 2026 (c. 21) and Online Safety Act 2023 (c. 50) are at legislation.gov.uk. The government announcement was published at gov.uk on 15 June 2026. Ofcom's advice letter was published 16 June 2026; contents verified via BBC News reporting. Age verification descriptions drawn from the BBC, the Yoti Facial Age Estimation white paper, and the Bluesky KWS announcement. Australian data from the Wikipedia article on the Online Safety Amendment (Social Media Minimum Age) Act 2024, sourcing Essential Research polling (December 2025) and Guardian Australia (February 2026). Identity Documents Act 2010 s.4 confirms the 10-year maximum. Meta's November 2025 Australian account removal is sourced from the same Wikipedia article.
How exposed are you? Take the Tracking Audit (≈5 min) →