An Australian law that just became enforceable today is the real story behind Steam's new age gate, not a Valve policy whim. Since September 9, 2026, every app distribution service operating in Australia has been legally required to verify a user is 18 or older before letting them download R18+ software, and Steam's version of that check accepts exactly one form of proof: a linked Australian credit card. No debit card, no PayPal, no ID upload, no account-age fallback. Remove the card and the account reverts to a restricted, under-18 state, even mid-catalog.
- Australia's Age-Restricted Material App Distribution Services Code became enforceable on September 9, 2026, six months after it took effect, and applies to every app store operating in the country, not just Steam.
- Valve's implementation accepts only a linked Australian credit card as proof of age; debit cards and PayPal are not officially supported, though some users report inconsistent debit approvals from Australia's big four banks.
- Apple, Microsoft and Google all hit the same deadline with methods that don't require a credit card: Apple confirms age automatically, Microsoft leans on third-party checks from Yoti and VerifyMy, and Google exposes a developer-facing Age Signals API.
- Valve already ran this exact credit-card-only model in the UK starting August 2025, so Australia is the second market getting the identical fix rather than a new experiment.
What is the law actually requiring here?
Australia's eSafety Commissioner registered six online safety industry codes on September 9, 2025, covering social media, equipment providers, and app distribution services among others. The App Distribution Services Code took effect on March 9, 2026, and gave platforms a six-month transition window. That window closed on September 9, 2026: from that date, every app distribution service operating in Australia must have "appropriate age assurance" in place before letting a user download or purchase an app rated R18+. The code is written as technology-neutral, meaning it doesn't mandate a specific method, only that one exists and actually works. Breaching a compliance direction from eSafety can carry civil penalties up to A$49.5 million, which is why the deadline landed hard across the industry this week rather than trickling in quietly.
RelatedXbox Outage Blocks Disc Games, Not Just Digital Ones
That framing matters: most coverage this week treated this as a Steam story first. It's really a compliance-deadline story, and Steam just happens to be the platform that picked the strictest way to clear the same bar every other major storefront cleared this week.
Why did Valve pick a credit card specifically?
Valve's in-client message to affected users states plainly: "Valve is required by the Age-Restricted Material App Distribution Services Code to verify that you are 18 or older before accessing mature content." A credit card works as a proxy because Australian banks generally require an applicant to already be an adult, so holding one is treated as sufficient evidence. Valve used this exact justification when it rolled the same system out for UK Steam accounts in August 2025, framing it as more private than uploading a government ID or submitting to a facial scan, since Valve never has to see or store any biometric or identity document. On privacy grounds alone, that's a defensible design choice.
The problem is what it assumes about who owns a credit card. Credit is a lending product gated by income and credit history, not simply age, and Reserve Bank figures cited by outlets covering the rollout put roughly 14.7 million credit cards on issue against Australia's approximately 22 million adults. Multiple outlets framed that gap as excluding something close to half of Australian consumers, and while that's a rough estimate rather than an exact headcount, since one person can hold more than one card, it lines up with the community reports piling up this week from adults who simply don't have one.
How does this compare to what other storefronts did for the same deadline?
| Platform | Method used for the Sep 9, 2026 deadline | Credit card required? |
|---|---|---|
| Steam (Valve) | Linked Australian credit card, no alternative offered | Yes, the only accepted method |
| Apple App Store | Automatic account-level age confirmation, method undisclosed | No |
| Microsoft Store / Xbox | Third-party age assurance via Yoti and VerifyMy | No |
| Google Play | Play Age Signals API, a developer-facing signal rather than a storefront gate | No |
None of the other three named their exact verification mechanism in full, which is itself a sign the code's technology-neutral wording invites a range of solutions. But all three built something that doesn't require a specific banking product. Valve is the outlier, and it's an outlier by choice: it already had a working, tested credit-card gate from the UK rollout thirteen months earlier and simply pointed the same system at Australian accounts rather than building a second method.
RelatedSteam Hit a Record $11.1B in the First Half of 2026
How did we get here, and when did this actually start?
- Mar 2025Codes drafted Industry associations submit the App Distribution Services Code and five others to Australia's eSafety Commissioner.
- Aug 2025Valve tests the model in the UK Steam rolls out the identical credit-card-only check for UK accounts under the UK's Online Safety Act.
- Sep 9, 2025Codes registered eSafety formally registers all six online safety industry codes, starting a compliance clock.
- Mar 9, 2026Codes take effect A six-month transition window opens for app distribution services to build and ship age assurance.
- Sep 9, 2026Deadline hits Every Australian app store must have age assurance live; Steam's version accepts only a linked credit card.
Who is actually affected by this?
Australian Steam users trying to buy or launch R18+ titles, Cyberpunk 2077 among them, are the ones hitting the wall directly. Younger adults just past 18, along with anyone who prefers debit cards or simply hasn't needed credit, are disproportionately the ones without a card to link. That's a specific, foreseeable gap: the people this law is supposed to let through, verified adults, are exactly the group most likely to lack the one instrument Valve accepts. It's worth being precise about scope too. This doesn't touch Steam's non-mature catalog, and it doesn't affect console storefronts running their own separate age-assurance systems under the same code.
- Whether Valve adds a second method. Apple, Microsoft and Google all shipped alternatives to a hard card gate for the same deadline; sustained backlash is the kind of pressure that pushed similar changes elsewhere.
- eSafety enforcement. A compliance direction breach carries penalties up to A$49.5 million; the regulator's read on whether a credit-card-only gate counts as "appropriate" age assurance is the number worth watching.
- Whether this becomes Valve's standing global default. The UK got it first in August 2025 and Australia is the second; a growing list of countries writing similar laws, including the EU's hardware-bound attestation work, means more markets could get the same treatment next.
- Debit-card workarounds. Community reports of some big-four-bank debit cards passing despite the official credit-only rule suggest the check isn't as airtight as Valve's messaging implies.
Our take
Valve's privacy argument for a credit card over an ID upload is genuinely sound: it never has to touch a birth certificate, a passport scan, or a face. But a credit card was never actually a test of age. It's a test of creditworthiness that happens to correlate with adulthood, and correlation isn't the same as coverage. Apple, Microsoft and Google all found ways to clear an identical legal bar without turning a bank product into an identity check, which is the strongest evidence that Valve's choice here is about convenience, reusing infrastructure it already built for the UK, rather than necessity. The next reasonable move isn't rolling this back to no verification at all; it's adding a second path, the way its rivals already did, so meeting the law doesn't quietly double as a wealth test.
- GovernanceeSafety Commissioner: Background to the Age-Restricted Codes registration and effective dates for the App Distribution Services Code
- ReportingGamingOnLinux: Age Verification for Steam rolls out in Australia requiring a Credit Card confirms Steam's in-client requirement and accepted method
- ReportinggHacks: Steam's Age Verification in Australia Only Accepts Credit Cards, Excluding Half of Consumers credit card ownership figures cited for Australia
- ReportingTech Business News: App Store Age Checks Become Law In Australia From September 9 penalty figures and the industry-wide compliance deadline
- ReportingShareRing: App Store Age Checks Land in Australia Today comparison of Apple, Microsoft and Google's separate approaches
Original analysis by GenZTech Team, based on eSafety Commissioner code documentation and independent reporting linked above.
