Steam stopped taking photo ID as proof of age in Australia this week. Instead, Valve is asking players to hand over a credit card. Starting around September 23-24, 2026, Australian Steam users trying to open R18+ storefront pages or mature-content community hubs hit a wall: no card on file, no access. A driver’s licence or passport, the documents regulators usually associate with age checks, will not unlock anything.

The rollout makes Australia the second market where Steam has gated adult content behind a stored credit card rather than a government ID or a facial-age scan. The first was the United Kingdom, where Valve’s Age Assurance under the UK Online Safety Act support page was confirmed live by September 24, 2026. Australian outlet Nine.com.au and PC Gamer both reported the Australian version days later, and the method drew immediate criticism for excluding the millions of adults who simply don’t carry a credit card.

This is a steam age verification australia story with real regulatory teeth behind it, not a UI tweak. Two governments, two separate laws, and one company now running the same credit-card gate across both. Here’s what actually changed, why Valve picked a payment card over an ID document, and what it signals for every other storefront that sells games in regulated markets.

What Actually Triggered Steam’s Australian Age Check

It’s tempting to link this to Australia’s social-media minimum-age law, the one that forced under-16s off platforms like Instagram and TikTok starting December 10, 2025. That’s not the rule behind Steam’s change. Australian regulators classify Steam outside the social-media minimum-age framework entirely, since that law targets designated social networks and account-holding minors, not game storefronts.

The actual driver is Australia’s Age-Restricted Material Codes for app distribution services, which carried a compliance deadline of September 9, 2026. That rule applies to companies including Microsoft, Sony, and Valve, and it requires them to stop children from purchasing or downloading R18+-classified games. Steam’s credit-card gate is Valve’s answer to that specific deadline, not a response to the minimum-age law that grabbed most of the 2025 headlines.

Australia’s eSafety Commissioner draws a distinction that matters here: age inference, age estimation, and age verification are three different compliance tools, and the regulator’s own guidance says blanket verification may be unreasonable when a simpler signal can reliably infer someone is an adult. Valve appears to have built its Australian system around that middle option. A stored, successfully authorized credit card is treated as a reasonable proxy for adulthood, not proof of a specific birth date.

How the Credit-Card Check Works in Practice

Steam’s support documentation lays out the flow in plain terms. A user logs into their account, opens Account Details, and adds a payment method. They enter the card type, number, CVV, expiry date, cardholder name, and billing address. Steam then runs an authorization check through the card issuer, which in the UK version can trigger a nominal £1 test charge that is never actually collected. Some banks add a one-time password or an in-app approval step on top of that.

Once the card clears, the account is marked age-verified for as long as that card stays on file. Pull the card, and the verification lapses. Valve’s own language is direct about this: Steam’s help center states that “your Australian Steam user account is considered age verified for as long as a valid credit card is stored on the account.” The user then opts into mature-content categories through Store Preferences, and the previously blocked pages and community hubs open up.

Notice what’s missing from that list: no ID upload, no selfie, no facial-age scan, and no named third-party age-assurance vendor like Yoti, Persona, Veriff, or Onfido. Valve is running this entirely through its existing payment-processing pipe. That’s the cheapest possible way to comply, and it’s also the source of nearly every complaint that followed.

Why a Credit Card and Not a Debit Card or Photo ID

The detail that generated the most backlash isn’t that Steam wants payment info. It’s that a debit card, which the vast majority of Australian adults carry, doesn’t count. PC Gamer’s reporting put it bluntly, noting that “Steam now requires Australian users to have a credit card to purchase R18+ games, and no, a simple bank debit card won’t work.” Valve appears to be using credit-specific underwriting signals, tied to a card issuer’s own age and identity checks at account opening, as its proxy for adulthood. A debit card, which any bank customer of any age can typically obtain, doesn’t carry the same implicit signal.

Nine.com.au’s coverage framed the gap starkly: “Instead of allowing standard photo IDs such as driver’s licences or passports, Steam, which is operated by parent company Valve, is requiring players to use a credit card to prove their age, effectively locking out the millions of adult gamers who do not have one.” That “millions” figure is Nine’s own estimate of Australians who may lack a credit card, not a number Valve has published, and no authoritative source has confirmed a precise count of affected accounts.

For a market where credit card ownership skews toward higher-income, older demographics, the practical effect is that younger adults, students, and anyone who prefers debit banking can find themselves locked out of games they’re legally entitled to buy. That’s the proportionality argument critics keep coming back to: a credit card proves someone has a credit history, not that they’re 18.

UK Versus Australia: Two Laws, One Playbook

Valve didn’t build this system from scratch for Australia. It reused the credit-card architecture it had already stood up for the UK’s Online Safety Act, where Ofcom’s 2026 age-assurance report lists credit-card checks as one recognized form of “highly effective age assurance.” The mechanics are close to identical on both sides of the world, but the legal basis and the enforcement path differ enough to matter.

FactorUnited KingdomAustralia
Governing lawOnline Safety Act, Ofcom age-assurance guidanceAge-Restricted Material Codes for app distribution services
Compliance deadline referencedOfcom report published July 15, 2026September 9, 2026
Verification methodStored, authorized credit cardStored, authorized credit card
Debit cards acceptedNot established as accepted in Valve’s documentationExplicitly rejected per PC Gamer’s reporting
Content gatedMature-content store pages and community hubsR18+-classified games and associated hubs
Regulator framing“Highly effective age assurance” (Ofcom)“Age inference,” not full verification (eSafety)
First publicly confirmed operatingBy September 24, 2026September 23-24, 2026

The UK’s framing leans on Ofcom’s language of “highly effective” measures, a phrase drawn straight from the Online Safety Act’s compliance menu. Australia’s eSafety Commissioner uses a different vocabulary, treating a credit card as an inference tool rather than a verified fact about someone’s date of birth. Same mechanism, different regulatory justification, and Valve is applying it uniformly regardless of which framework technically applies.

The Backlash: Locked Out Without a Card

Criticism landed fast once Australian players started hitting the gate. The core objections split into three buckets. First, access: adults who pay by debit, cash, or buy-now-pay-later services can’t view or purchase gated content at all, regardless of age. Second, privacy: users are being asked to hand over payment-card details for a purpose that has nothing to do with completing a purchase, since the check runs even for free-to-view store pages and community hubs. Third, proportionality: a blanket card requirement is broader than eSafety’s own guidance calls for, given the regulator’s stated preference for the least invasive method that reliably does the job.

There’s also an open question the available reporting doesn’t answer: how long Valve or its payment partners retain the card data, and whether Valve sees the full card number or only a tokenized result from the issuer. Neither Valve’s support documentation nor the news coverage that followed addresses data retention in any detail, which leaves a real gap for a company processing sensitive payment information at scale for a compliance purpose rather than a transaction.

Online chatter about using a VPN to route around the check picked up alongside the complaints, but there’s no verified data showing a Steam-specific spike in VPN usage tied to this rollout, and changing your apparent location doesn’t necessarily clear an account-level card check tied to a specific country’s billing address. Treat any claim of a simple workaround with skepticism until a platform-level usage number surfaces.

What Regulators Actually Required, Versus What Valve Built

It’s worth separating what Australia’s rules demand from what Valve chose to ship. eSafety’s guidance explicitly states that platforms are not required to age-verify every user, and that blanket verification can be unreasonable if existing account data already provides a reliable signal. Nothing in the public guidance mandates a credit-card-only system, or rules out accepting debit cards, government ID, or a third-party estimation service alongside it.

That gap between the regulatory floor and Valve’s implementation is where most of the criticism concentrates. A company with Steam’s engineering resources and payment infrastructure had options beyond reusing its UK credit-card flow wholesale. Choosing the cheapest existing pipeline over a purpose-built, more inclusive age-assurance method reads as a cost decision dressed up as compliance, and that’s the framing several outlets, including BiometricUpdate, have leaned on in their coverage.

No Valve spokesperson has issued a dedicated press statement or named quote beyond the support-page language. Until Valve says more, the credit-card gate remains the company’s only public explanation for how it’s meeting both governments’ requirements.

How Other Storefronts Are Positioned

Australia’s app-distribution age-assurance code doesn’t single out Valve. It names Microsoft and Sony alongside Steam as companies required to keep R18+-classified games out of the hands of children shopping their storefronts. What’s not yet public is how Xbox and PlayStation plan to satisfy that requirement technically. Neither company has published a Steam-equivalent support page describing a credit-card gate, a facial-estimation tool, or an ID-upload flow for Australian accounts, and treating either company’s eventual method as settled would be premature.

That silence matters competitively. If Xbox or PlayStation land on a less restrictive method, a debit card accepted, an ID-document option offered, a facial-estimation fallback, Steam’s credit-card-only approach starts to look like an outlier rather than an industry standard. If they converge on the same mechanism Valve already built, it suggests card-based age inference is becoming the default cross-industry answer to this specific slice of Australian and UK law, mostly because it’s the cheapest thing to build on existing payment rails.

Smaller storefronts face a harder version of the same problem. A digital storefront without Steam’s payment infrastructure and legal budget has fewer easy paths to compliance, and consolidation pressure toward the two or three biggest PC storefronts is a plausible side effect of age-assurance rules that are expensive to build correctly.

The Privacy Trade-Off Nobody Fully Answered Yet

Age assurance sits at an uncomfortable intersection of child-safety law and payment-data privacy. Handing over a credit card number to unlock a video game store page is a different risk profile than handing over a driver’s licence scan to a dedicated identity vendor, and neither option is obviously safer for the user. A breached identity-verification vendor exposes government ID scans. A breached payment-authorization pipeline exposes financial account data instead. Shattered.io covered exactly that first scenario in detail after IDScan.net confirmed a breach affecting 153 million ID records, a reminder that centralizing identity documents for age checks carries its own catastrophic-failure mode.

Valve’s approach avoids building a new honeypot of scanned government documents, which is a genuine point in its favor next to ID-upload systems. But it does so by leaning harder on payment infrastructure for a purpose payment infrastructure wasn’t originally built for, and the public record currently has no answer on data retention, storage location, or whether Valve’s payment partners are contractually limited from using the age-check transaction for anything beyond the authorization itself.

Historical Context: From ESRB Stickers to Payment-Card Gates

Game-industry age controls have gone through three distinct eras. The first was self-regulatory labeling, the ESRB and PEGI ratings systems that retailers were trusted to enforce at the till with essentially no digital check at all. The second was the checkbox era of early digital storefronts, where clicking “I am 18” satisfied the letter of most laws without verifying anything. The third era, the one Steam’s Australian rollout belongs to, is regulator-mandated technical enforcement, where lawmakers no longer accept a self-reported birthdate as sufficient and platforms have to prove they built an actual gate.

Australia’s own path here runs through its broader push on youth online safety, starting with the Online Safety Amendment (Social Media Minimum Age) Act passed in November 2024 and taking effect for social platforms on December 10, 2025. Steam’s app-distribution obligations arrived on a separate, later track, with the September 9, 2026 compliance deadline. The UK moved earlier and, per Ofcom’s July 2026 report, has already begun evaluating which age-assurance methods actually qualify as “highly effective” under its Online Safety Act framework, giving companies like Valve a template to reuse when a second country’s deadline arrived.

Market and Industry Impact

The commercial stakes are real even without a published revenue figure from Valve. R18+-classified games are a meaningful slice of any mature-audience storefront’s mature-rated catalog, and any friction that keeps a subset of adult customers from completing a purchase is lost revenue, not just an inconvenience. Publishers selling R18+ titles into the Australian market now have a direct interest in how many of their potential buyers actually clear Steam’s card check, though no publisher or Valve has released conversion data on that specific funnel.

There’s a second-order effect worth tracking too. Australia’s rule explicitly covers Microsoft and Sony as well as Valve, so whichever company ships the most permissive compliant method first sets a competitive baseline the others will be measured against. A storefront that lets adults verify with an ID document or a debit card, in addition to a credit card, has a real argument for being the more accessible option in a market where credit card ownership isn’t universal. That’s a lever none of the three companies has pulled publicly yet.

What Valve, Regulators, and Reporters Are Actually Saying

Beyond the support-page language already covered, Valve’s official documentation is consistent on the mechanics. Per Steam’s help center, the company states: “Valve is required by the Age-Restricted Material App Distribution Services Code to verify that you are 18 or older before accessing mature content. If you wish to do so, please add a valid Australian credit card to your account and afterwards update the Mature Content Preferences.” A separate line on the same page adds: “For Australian users, this opt-in process requires age verification.”

Australian reporting has been the loudest independent voice on the rollout’s downsides. Nine.com.au’s framing of the credit-card requirement as effectively excluding “the millions of adult gamers who do not have one” set the tone for follow-up coverage, and PC Gamer’s confirmation that “a simple bank debit card won’t work” turned a technical detail into the story’s most-repeated line. No named statement from Ofcom or Australia’s eSafety Commissioner specifically endorses or criticizes Valve’s particular implementation, so any claim of regulatory approval or disapproval of Steam’s specific method should be treated as unconfirmed.

Five Predictions for Where This Goes Next

  1. Xbox and PlayStation will publish their own Australian compliance pages within weeks. Both companies are named in the same app-distribution code Valve is complying with, and regulatory pressure to show a working system will only build now that Steam has gone first.
  2. Debit-card or ID-document alternatives arrive within Valve’s system inside a few months. The public backlash over excluded adults creates real pressure, and eSafety’s own guidance against overly broad verification gives Valve regulatory cover to widen accepted methods.
  3. Smaller PC storefronts will face a harder compliance choice. Building or licensing an equivalent system is expensive, and some smaller platforms may simply geoblock R18+ listings from Australian accounts rather than build a card-check pipeline of their own.
  4. Data-retention questions will force a follow-up disclosure. Journalists and privacy researchers are already asking how long card data tied to age checks is stored, and that gap in Valve’s public documentation is the most likely next flashpoint.
  5. More countries will adopt Australia’s app-distribution model rather than the UK’s broader Online Safety Act framework. A narrower rule aimed specifically at R18+ content is easier for regulators to pass and for platforms to scope, making it a more exportable template than the UK’s wider legislation.

Timeline: How We Got Here

DateEvent
November 2024Australia passes the Online Safety Amendment (Social Media Minimum Age) Act
December 10, 2025Australia’s social-media minimum-age framework takes effect for covered platforms (not Steam)
July 15, 2026Ofcom publishes its UK age-assurance report, naming credit-card checks a recognized method
September 9, 2026Australia’s app-distribution age-assurance deadline for R18+ content takes effect
September 23-24, 2026Australian media reports Steam’s credit-card-only requirement is live
September 24, 2026Steam Support’s UK age-assurance documentation confirmed active
September 27, 2026No confirmed Valve press statement or usage data published beyond support documentation

What This Means If You’re an Australian Steam User

If you’re trying to buy or view an R18+ title on Steam in Australia right now, the fastest path is adding a valid credit card, not a debit card, to your account under Account Details, then opting into Mature Content Preferences once the authorization clears. If you don’t have a credit card, there’s currently no published alternative path from Valve, which is precisely the gap driving most of the criticism above. Keep an eye on Steam’s own support documentation, since that’s the only channel Valve has used to communicate changes so far, and it’s the page most likely to be updated if a broader set of verification options ships.

Players who’ve dealt with other Steam service issues recently, whether that’s checking whether a Steam outage is behind a login failure or tracking Valve’s next hardware moves after the Steam Deck 2 announcement, should expect Valve’s compliance posture to keep evolving as more regulators weigh in. Valve has also had to address user trust on the data-security side before, following the CEVA Logistics breach that touched Steam’s supply chain, so how the company handles retention of newly collected age-check payment data will get scrutiny from the same audience.

The Bigger Regulatory Picture

Steam’s Australian rollout doesn’t exist in isolation. Governments worldwide are converging on the idea that platforms, not parents or self-reported checkboxes, bear responsibility for keeping minors away from age-gated content and accounts. Epic Games founder Tim Sweeney has already pushed back publicly on a related but distinct EU proposal, arguing against a blanket under-13 social media restriction in comments covered in Shattered’s report on the EU’s Kids Act debate. The common thread across the UK, Australia, and the EU’s various proposals is that regulators are done treating age gates as optional UX, and companies that build the cheapest compliant option first, as Valve just did, are setting norms the rest of the industry will either follow or actively push back against.

For readers who care about keeping payment and identity data out of systems they don’t need to touch, the broader privacy toolkit, from private search engines that don’t log your queries to minimizing what identity data any single platform holds, matters more with every new age-check rollout, not less.

Frequently Asked Questions

Does Steam require ID to buy games in Australia?

No. Steam’s Australian age check runs entirely on a stored, authorized credit card. No driver’s licence, passport, or other photo ID is accepted as an alternative under the current system.

Will a debit card work for Steam’s Australian age verification?

No. Reporting from PC Gamer confirms Steam’s system requires a credit card specifically, and a standard bank debit card does not satisfy the check.

What law forced Steam to add this age check in Australia?

Australia’s Age-Restricted Material Codes for app distribution services, which carried a compliance deadline of September 9, 2026 and covers Microsoft, Sony, and Valve. It’s a separate rule from Australia’s social-media minimum-age law, which doesn’t classify Steam as a covered social platform.

Is this the same system Steam uses in the UK?

It’s built on the same credit-card architecture. Steam’s UK age-assurance system, confirmed live by September 24, 2026 under the Online Safety Act, uses an identical stored-card authorization flow, though the two systems answer to different regulators and different laws.

What content gets blocked without a verified account?

R18+-classified games and their associated Steam community hubs are gated behind the check. Unrated and lower-rated content is unaffected.

Are Xbox and PlayStation adding the same kind of age check in Australia?

Both companies are named alongside Valve in Australia’s app-distribution age-assurance rule, but neither Microsoft nor Sony has published a Steam-equivalent support page describing its specific method as of this writing. Treat any claim about their exact system as unconfirmed until they publish one.

Does using a VPN bypass Steam’s age check?

There’s no verified data showing this works reliably, and no confirmed spike in VPN usage tied to the rollout. A VPN changes apparent location but doesn’t necessarily clear an account-level card check tied to a stored billing address.

How long does Steam keep the credit card data used for age checks?

Valve hasn’t published a retention policy specific to age-check card data. That gap is currently one of the most-cited unanswered questions from privacy-focused coverage of the rollout.