This series has spent nine parts mostly looking outward and forward — at Australia's ban, at the circumvention routes no statute closes, and most recently at France going first in Europe. Throughout, I kept referring to Britain's own plans as something coming "next spring," a shape on the horizon. It is time to stop doing that, because the shape has resolved into a specific thing with a specific history, and the history is as instructive as the policy.

On 15 June, the government announced that it will ban under-16s from social media. And the most revealing fact about that announcement is that the House of Commons had voted the same idea down thirteen weeks earlier.

The vote, and the reversal

The story does not start in June. In January, the House of Lords approved — by 261 to 150 — a cross-party amendment to the Children's Wellbeing and Schools Bill, led by the Conservative former schools minister Lord Nash, that would have required social media platforms to bring in age verification within twelve months of the bill becoming law. It went to the Commons, and on 9 March MPs rejected it, 307 to 173.

The government's stated reason for opposing it is the part every reader of this series should sit up for. Ministers argued that a blanket ban could drive teenagers into the less-regulated corners of the internet — and the NSPCC, then, shared the concern. That is not a paraphrase I am massaging to fit my case. It is, almost word for word, the argument I made in part three and returned to throughout: that a ban enforced at the mainstream platforms pushes the determined user toward the places with no safety infrastructure at all, and so can worsen the very harm it targets. In March, His Majesty's Government made my argument on the floor of the Commons, and won.

What it won was not the end of the matter but a different instrument. Rather than accept the Nash ban as written, the government secured its own amendment — one handing the Technology Secretary broad powers to restrict or ban children's access to social media through secondary legislation, without returning for fresh primary legislation, if a consultation recommended it. That consultation ran from 2 March to 26 May. Three weeks after it closed, the government used the power it had given itself and announced the ban.

So the sequence is this: the elected chamber declined to legislate a ban; the government took a delegated power to impose one by regulation; and it then imposed the very thing the chamber had declined, using the reasoning it had itself rejected in March as no longer decisive. I want to be fair about how to read that. The innocent reading is that a three-month consultation genuinely changed the government's mind — that it weighed the circumvention risk, decided the protection was worth it anyway, and is entitled to update its view. The less innocent reading is that a ban which could not pass as primary law is arriving as a statutory instrument precisely because that route needs no vote. Both readings are available on the public record, and a citizen is entitled to hold whichever the evidence supports. What is not available is the pretence that the circumvention objection was answered. It was not answered. It was set aside.

What the package actually contains

Set the process aside and look at the design, because it is more interesting than "Britain copies Australia," and in one respect it is better than anything the series has scored so far.

The core is a destination-level ban: from spring 2027, platforms including Snapchat, TikTok, YouTube, Instagram, Facebook and X must stop offering accounts to under-16s, on the Australian model of holding the platform liable for taking "reasonable steps" to keep them out. Messaging services such as WhatsApp are excluded. Sitting above the ban is the switch-off curfew I took apart in part one — default-on restrictions for 16- and 17-year-olds, which remain a default dressed as a control.

Then there are the parts that target functions rather than brands, and here I have to give real credit, because this is the thing part seven asked for. Livestreaming to under-16s is to be restricted across services, not just on the named platforms. Strangers contacting children is to be blocked, including in the gaming spaces that part two argued the brand-based approach kept missing. And — genuinely new to this series — "romantic companion" AI chatbots are to carry a minimum age of 18, with intimate functionality restricted for under-18s across the board. That last measure is the best-designed thing in the package. It does not ban an app; it regulates a harmful function wherever it appears. It is what honest, function-first regulation looks like, and it shows the drafters can do it when they choose to. Which makes the decision to enforce the headline measure at the brand-and-destination layer a choice, not an inevitability.

Age assurance is the hinge, and its detail is still being written: Ofcom has been told to define "highly effective age assurance" — HEAA, the acronym to watch — with a rapid study due to report by October.

The layer, again — and this time we have the number

The ban is enforced at the destination: every account, on every named platform, gated by age checks the platform is liable for. That is the app-and-network layer, which part five and part seven identified as having the largest circumvention surface of any option on the table. It sits above every VPN a fifteen-year-old can install in ninety seconds.

And here Britain is not speculating, because Britain has already run the experiment once this year. When the Online Safety Act's age checks for adult content came into force, UK VPN sign-ups reportedly surged by around 1,400% within days. That is the circumvention response, measured, at home, against a live age gate — before this larger one is even built. Whatever HEAA turns out to mean, it will sit at the one layer we have direct, recent, domestic evidence that a determined user steps around by lunchtime.

The honeypot, again — with a British tell

To check an age you must collect an identity; to check everyone's age you must collect everyone's. HEAA is universal age assurance by another name, and it builds the same national identity store I described in part six and in the France piece.

The British tell is in the exemptions. To spare adults the friction of proving themselves constantly, an existing account can be treated as an adult's if it has been open more than sixteen years, or has a credit card attached, or is linked to an email already age-verified elsewhere — with facial age-estimation as a fallback. Sit with the first of those. "The account has existed for sixteen years" is being used as a proxy for "the holder is an adult," which is an open admission that verifying everyone properly is too costly to do, so the system will guess where it can. It misfires in both directions: the twenty-four-year-old who opened the account at nine sails through unverified, while the adult who joined last month must hand over documents. And every exemption that is not a guess is an identity collected and held. The age-check vendor that leaked around 70,000 government ID photographs was operating under exactly this kind of regime. The Information Commissioner's Office is involved in the design, which is welcome and is not the same as immunity — the same caveat I gave CNIL in France applies here.

The age line, still a settlement

Britain has drawn the line at sixteen. Australia at sixteen. France at fifteen. In part seven I argued that any line drawn below adulthood is the tell of a policy reasoned to a number that would pass rather than to the underlying harm — if the harm is real enough to forbid the product to a fifteen-year-old, it does not vanish on their sixteenth birthday. Britain lining up with Australia at sixteen makes the number look less arbitrary than three different figures did, but it does not make it a threat-model output. It makes it a more popular settlement. And the 16-to-17 tier, governed by a curfew a teenager can switch off, is the same soft default I dismantled in part one, now stapled to the harder ban beneath it.

What changes for you

The practical read for a British household is that universal age assurance is now coming to the mainstream internet you use, and — through HEAA — you, the adult, are inside its scope, not watching from outside it. That does not change a word of the advice at the end of part eight, because that advice never depended on any statute. Keep doing the unglamorous, device-level things that travel with the child rather than sitting at a platform they can route around, and keep having the conversation that travels further than any control. And when you are asked to prove your age — which, across more of the internet, you increasingly will be — treat your identity documents as the precious things they are, and prefer the verifiers that check and delete over the ones that check and keep.

The dates to watch are close now. Ofcom's HEAA study is due by October; the legislation is promised before Christmas; the protections are meant to be live by spring 2027. I will report back here as the regulations are actually laid, because a power exercised by statutory instrument is a power whose detail arrives quietly, and the detail is where this either works or leaks.

France ran the experiment abroad. Now Britain runs it at home — having first stood up in Parliament, explained clearly why it might not work, and then decided to run it anyway. I said in the France piece that the number I would watch most closely was not how many children the ban keeps off the platforms, but how long the national identity store holds before something leaks out of it. That number is now a British one too. I would still rather be proved wrong than right.

This is part ten of Regulating the Teen Internet. If you have arrived here first, the practical, do-it-this-weekend guide for parents is part eight, and it holds whatever any parliament, or any minister with a delegated power, does next.