An Australian law that just became enforceable today is the real story behind Steam's new age gate, not a Valve policy whim. Since September 9, 2026, every app distribution service operating in Australia has been legally required to verify a user is 18 or older before letting them download R18+ software, and Steam's version of that check accepts exactly one form of proof: a linked Australian credit card. No debit card, no PayPal, no ID upload, no account-age fallback. Remove the card and the account reverts to a restricted, under-18 state, even mid-catalog.

  • Australia's Age-Restricted Material App Distribution Services Code became enforceable on September 9, 2026, six months after it took effect, and applies to every app store operating in the country, not just Steam.
  • Valve's implementation accepts only a linked Australian credit card as proof of age; debit cards and PayPal are not officially supported, though some users report inconsistent debit approvals from Australia's big four banks.
  • Apple, Microsoft and Google all hit the same deadline with methods that don't require a credit card: Apple confirms age automatically, Microsoft leans on third-party checks from Yoti and VerifyMy, and Google exposes a developer-facing Age Signals API.
  • Valve already ran this exact credit-card-only model in the UK starting August 2025, so Australia is the second market getting the identical fix rather than a new experiment.
Steam's single-path age check for Australian accountsDiagram showing an Australian Steam account requesting R18+ content, branching to two outcomes: a linked Australian credit card unlocks the catalog in orange, while no credit card, including debit cards and PayPal, leaves the account locked in grey.STEAM AU / AGE GATEAU STEAM ACCOUNTrequests R18+ titleAU CREDIT CARDlinked to account?NO / DEBIT / PAYPALaccount stays locked,treated as under 18CARD ON FILER18+ catalog unlocks,card must stay linkedgenztech.blog
Fig 1 Steam's Australian age gate has exactly one accepted path: a linked credit card. Everything else, including debit cards and PayPal, leaves the account locked out of R18+ titles.

What is the law actually requiring here?

Australia's eSafety Commissioner registered six online safety industry codes on September 9, 2025, covering social media, equipment providers, and app distribution services among others. The App Distribution Services Code took effect on March 9, 2026, and gave platforms a six-month transition window. That window closed on September 9, 2026: from that date, every app distribution service operating in Australia must have "appropriate age assurance" in place before letting a user download or purchase an app rated R18+. The code is written as technology-neutral, meaning it doesn't mandate a specific method, only that one exists and actually works. Breaching a compliance direction from eSafety can carry civil penalties up to A$49.5 million, which is why the deadline landed hard across the industry this week rather than trickling in quietly.

RelatedXbox Outage Blocks Disc Games, Not Just Digital Ones

That framing matters: most coverage this week treated this as a Steam story first. It's really a compliance-deadline story, and Steam just happens to be the platform that picked the strictest way to clear the same bar every other major storefront cleared this week.

Why did Valve pick a credit card specifically?

Valve's in-client message to affected users states plainly: "Valve is required by the Age-Restricted Material App Distribution Services Code to verify that you are 18 or older before accessing mature content." A credit card works as a proxy because Australian banks generally require an applicant to already be an adult, so holding one is treated as sufficient evidence. Valve used this exact justification when it rolled the same system out for UK Steam accounts in August 2025, framing it as more private than uploading a government ID or submitting to a facial scan, since Valve never has to see or store any biometric or identity document. On privacy grounds alone, that's a defensible design choice.

The problem is what it assumes about who owns a credit card. Credit is a lending product gated by income and credit history, not simply age, and Reserve Bank figures cited by outlets covering the rollout put roughly 14.7 million credit cards on issue against Australia's approximately 22 million adults. Multiple outlets framed that gap as excluding something close to half of Australian consumers, and while that's a rough estimate rather than an exact headcount, since one person can hold more than one card, it lines up with the community reports piling up this week from adults who simply don't have one.

How does this compare to what other storefronts did for the same deadline?

PlatformMethod used for the Sep 9, 2026 deadlineCredit card required?
Steam (Valve)Linked Australian credit card, no alternative offeredYes, the only accepted method
Apple App StoreAutomatic account-level age confirmation, method undisclosedNo
Microsoft Store / XboxThird-party age assurance via Yoti and VerifyMyNo
Google PlayPlay Age Signals API, a developer-facing signal rather than a storefront gateNo

None of the other three named their exact verification mechanism in full, which is itself a sign the code's technology-neutral wording invites a range of solutions. But all three built something that doesn't require a specific banking product. Valve is the outlier, and it's an outlier by choice: it already had a working, tested credit-card gate from the UK rollout thirteen months earlier and simply pointed the same system at Australian accounts rather than building a second method.

RelatedSteam Hit a Record $11.1B in the First Half of 2026

How did we get here, and when did this actually start?

  1. Mar 2025Codes drafted Industry associations submit the App Distribution Services Code and five others to Australia's eSafety Commissioner.
  2. Aug 2025Valve tests the model in the UK Steam rolls out the identical credit-card-only check for UK accounts under the UK's Online Safety Act.
  3. Sep 9, 2025Codes registered eSafety formally registers all six online safety industry codes, starting a compliance clock.
  4. Mar 9, 2026Codes take effect A six-month transition window opens for app distribution services to build and ship age assurance.
  5. Sep 9, 2026Deadline hits Every Australian app store must have age assurance live; Steam's version accepts only a linked credit card.

Who is actually affected by this?

Australian Steam users trying to buy or launch R18+ titles, Cyberpunk 2077 among them, are the ones hitting the wall directly. Younger adults just past 18, along with anyone who prefers debit cards or simply hasn't needed credit, are disproportionately the ones without a card to link. That's a specific, foreseeable gap: the people this law is supposed to let through, verified adults, are exactly the group most likely to lack the one instrument Valve accepts. It's worth being precise about scope too. This doesn't touch Steam's non-mature catalog, and it doesn't affect console storefronts running their own separate age-assurance systems under the same code.

What to watch
  • Whether Valve adds a second method. Apple, Microsoft and Google all shipped alternatives to a hard card gate for the same deadline; sustained backlash is the kind of pressure that pushed similar changes elsewhere.
  • eSafety enforcement. A compliance direction breach carries penalties up to A$49.5 million; the regulator's read on whether a credit-card-only gate counts as "appropriate" age assurance is the number worth watching.
  • Whether this becomes Valve's standing global default. The UK got it first in August 2025 and Australia is the second; a growing list of countries writing similar laws, including the EU's hardware-bound attestation work, means more markets could get the same treatment next.
  • Debit-card workarounds. Community reports of some big-four-bank debit cards passing despite the official credit-only rule suggest the check isn't as airtight as Valve's messaging implies.

Our take

Valve's privacy argument for a credit card over an ID upload is genuinely sound: it never has to touch a birth certificate, a passport scan, or a face. But a credit card was never actually a test of age. It's a test of creditworthiness that happens to correlate with adulthood, and correlation isn't the same as coverage. Apple, Microsoft and Google all found ways to clear an identical legal bar without turning a bank product into an identity check, which is the strongest evidence that Valve's choice here is about convenience, reusing infrastructure it already built for the UK, rather than necessity. The next reasonable move isn't rolling this back to no verification at all; it's adding a second path, the way its rivals already did, so meeting the law doesn't quietly double as a wealth test.

Primary sources

Original analysis by GenZTech Team, based on eSafety Commissioner code documentation and independent reporting linked above.