RICO HOLT
How Australia Undid Itself  ·  Systems 16 Sep 2026

Still fixing the internet era

Almost a year after the under-16 social media ban, kids are still on TikTok on the train home. Canberra wants to govern AI while it is still fixing the internet era.

I'm sitting on a train from Parramatta to Central on Monday afternoon. I got on at about three o'clock, just as students were leaving school and filling the carriages. It was an all-stops service, so there were plenty of stops and a constant flow of school kids getting on and off.

At one point, I saw a lot of under-16-year-olds using social media. Many were watching TikTok, Instagram clips or other short-form videos on their phones.

It was almost a year after the government started bragging about its under-16 social media ban. This is what enforcement looked like in practice: under-16s openly using the platforms the government says it has restricted, while ministers receive praise around the world for supposedly leading the way.

Then, on Tuesday, I was watching Channel Ten's YouTube channel and saw Andrew Charlton talking about artificial intelligence. Charlton is, coincidentally, the federal member for Parramatta.

So, on Monday, I was on a train leaving Parramatta and watching under-16s use social media. On Tuesday, I was watching the member for Parramatta talk about how the government wants to approach AI. That coincidence is why I'm writing this piece.

That little train ride tells me something about how effective our governance is. The government has spent a fortune promoting this policy. So show us what it has actually achieved.

Explain how it works. Explain what it costs. Explain what Australians get out of it. That's a reasonable request when you're spending our money and asking for more authority over our lives.

I understand the concern. Social media can expose children to harmful content, manipulation, bullying, exploitation and addictive design. Parents deserve support, and children deserve protection.

But a law is not a success because it sounds tough or attracts international headlines. It is a success if it works.

And almost a year in, under-16s are still openly using social media on public transport. On that one train ride alone, I saw at least five separate incidents of kids using social media. There were probably more. That is not proof that the policy has achieved nothing, but it is a pretty strong reminder that the announcement and the reality are very different things.

Maybe there are workarounds. Maybe the platforms are not enforcing the rules properly. Maybe children are using accounts registered with different ages. Maybe they are using someone else's account, a different app or a technical method the government has not explained.

I don't know exactly how they are getting around it. That is the point.

Unlike China, Australia does not have a nationwide Great Firewall controlling every connection. And I don't think children here need to go to the extreme of buying a VPN to get around this ban. The workaround may be much simpler than that.

So where is the government's evidence?

How many children have actually been prevented from accessing the platforms? How many accounts have been blocked? How many children have simply moved to another service or used a workaround? How many adults have been caught in unnecessary age-verification checks? What personal information is being collected, and who is responsible if it is leaked or misused? What is the measured reduction in harm?

If the government says it is protecting children, show us the results. Don't just show us the legislation, the press release and the international praise. A government should not receive credit for announcing a restriction. It should be judged on whether the restriction works.

And this is where the broader problem becomes clear.

We have moved through three major technology eras in a very short time.

The internet era connected people to information, services and each other. It also created problems around privacy, cybersecurity, online fraud, digital identity, data ownership and the delivery of government services.

Then came the social media era. It made communication faster and more public, but it intensified problems involving misinformation, harassment, child safety, addictive design, online abuse and the power of large platforms.

Now we are entering the AI era. AI can generate content, automate decisions, imitate people, analyse enormous amounts of information and reshape entire industries.

But while the technology has moved forward, government is still trying to solve many of the problems created during the internet era. We are still dealing with basic digital systems that do not work properly, weak cybersecurity, poor data management, procurement failures and unclear responsibility when automated systems harm people.

At the same time, we are still trying to solve social media problems with blunt restrictions designed after the platforms have already changed.

Now Canberra wants to regulate AI, even though it has not demonstrated that it can reliably manage the technologies that came before it.

That does not mean the government should do nothing. It means the government should be honest about where it is starting from.

Before you tell everyone how you're going to govern one of the most complex technologies in the world, show us you can deliver the intervention you're proposing.

I know AI has risks. Fraud, impersonation, privacy, automated decisions that can seriously hurt people. There's good coming out of it as well. It can help people learn, build businesses, develop products and get work done.

So when Canberra says we need protection, I want to know exactly what protection they're selling us. How does this particular measure reduce this particular harm? What happens when someone works around it? What rights does it affect? Who checks whether it actually achieved anything?

You can't just keep pointing at the scary technology and expect that to answer every question about your policy.

Because the Australian government's track record with technology is not exactly reassuring.

Look at the Bureau of Meteorology. Their own explanation puts the website project at approximately $96.5 million, including $4.1 million for the front-end redesign. The rest, they say, went into rebuilding and testing the systems behind it, security, stability and bringing in weather data. Alright. That's a much bigger job than changing a few pages and plugging in an API. I accept that.

Now show us the breakdown. What got built? How much went into engineering? How much into management, consultancy, testing and migration? What improved? How was that improvement measured?

And yeah, Drupal surprised me. But the platform's name doesn't settle the argument. You could spend a fortune on the newest framework and still deliver rubbish. For that money, I expect the service to be fast, clear, accessible and dependable. People should be able to find the bloody radar without needing a tutorial.

Then we looked at the procurement audit. Nine Digital Transformation Agency procurements. A combined reported value of $54.5 million. The Auditor-General's 2022 findings described ineffective procurement, weak oversight and ineffective contract management across the cases examined. That's an independent audit identifying failures in the machinery that buys and manages technology for us.

And this isn't just about one website or one department. It's a pattern Australians have seen before: ambitious digital announcements, large contracts, complicated delivery arrangements and not enough clear accountability when the result falls short.

The robodebt scandal showed what happens when government treats an automated system as an administrative shortcut instead of a decision that can seriously affect people's lives. The system unlawfully raised debts against vulnerable Australians, and the Royal Commission found serious failures in design, legality, oversight and responsibility.

That should permanently change the standard for government technology. If an automated system can take money from people, deny them a service, make a decision about their rights or expose them to enforcement, "the computer said so" is not an acceptable explanation. Someone must understand the system, test it properly, monitor it and answer for its consequences.

The COVIDSafe app is another reminder that public trust is not created by a press conference. The government spent millions developing and promoting an app that was supposed to help contact tracing, but its practical usefulness was limited and adoption was never what the public was promised. The Auditor-General found that the app's effectiveness could not be demonstrated in the way Australians had been led to expect.

Again, the lesson is not that every government technology project must be perfect. The lesson is that officials need to define success before they spend the money, measure it honestly afterwards and admit when the promised benefit did not materialise.

The under-16 social media ban deserves the same scrutiny. If the government says it is protecting children, show us how many children have actually been prevented from accessing the platforms. Show us how age verification works, what data it collects, how that data is protected and how many children have simply moved to another service or used a workaround.

My train ride suggested that the gap between the announcement and reality is already enormous. Seeing a lot of under-16-year-olds using TikTok and Instagram clips is not a scientific evaluation, but it is a useful reminder that a law can exist on paper while ordinary people continue doing exactly what it was supposed to stop.

So where is the evidence? What is the measured reduction in harm? How many false positives are there? How many adults are being subjected to unnecessary identity checks? What happens to children who are pushed into less visible or less safe online spaces? And how much did the government spend creating a system that children can apparently ignore during the trip home from school?

Then there's the procurement machinery itself. The Digital Transformation Agency was created to improve how government buys and delivers technology. Yet the audit found ineffective procurement, weak oversight and ineffective contract management across the cases examined. So if you want Australians to trust the next programme, show us what changed. Show us how you're preventing the same problems. Don't expect a fresh announcement to erase the old record.

The Wakeley video dispute raises another question: do you understand the limits of what you're trying to enforce? The eSafety disclosure records a $623,971.70 adverse costs order. Its case table and footnote point to the discontinued Federal Court proceeding against X. That isn't the complete cost of the case, because eSafety's own legal expenditure for it wasn't separately itemised there. Over six hundred grand in an adverse costs order, before we can even identify the whole bill.

I expect the regulator to understand its powers, its jurisdiction and the practical limits of its approach before committing taxpayers to the fight. That matters even more when the government is proposing new rules for AI. A regulator that cannot clearly explain the legal basis, technical operation, cost and likely effect of an intervention should not be demanding broader powers to impose it.

And then there's the spotlight. Why does the government always have to be the face of Australian technology? Where are the Australians actually working in these fields: the engineers, researchers, founders, security specialists and people running the systems? Why can't we put them in front of an international audience alongside the minister?

I'm not saying Andrew Charlton is tech-illiterate. He did build a platform, and that platform was sold while he was involved with it. That is a legitimate achievement. But demanding governance on a global stage is a different thing from having built one successful platform. Charlton has an economics and policy background, corporate experience and a consultancy business behind him. Those credentials have relevance. They don't establish that he can independently judge every technical prescription being put forward on infrastructure, skills, model development, security and safety. A minister can represent government policy. Australians building the technology should have a visible role in representing Australian capability.

The danger is that we keep repeating the same cycle. A new technology arrives. Government reacts after the fact. A major problem becomes politically embarrassing. Ministers announce a sweeping solution. Money is spent. New powers are created. The technology changes again. Then the public is left dealing with the original problem, plus the unintended consequences of the intervention.

That is how we end up in the AI era still trying to repair failures from the internet era and still trying to contain problems from the social media era.

Good intentions don't pay the bill. We do.

So before expanding your authority over social media, AI or any other technology, demonstrate that the particular intervention is technically workable, proportionate, accountable and beneficial to Australians.

Show us the evidence. Bring the technical people into the room. Publish the costs. Set a date to review the result, and tell us who answers if it fails.

You're asking Australians for money, power and trust. Show us what you can deliver with them.

Rico Holt  ·  ricoholt.com

If this one landed

Free full read. Stay on the list and get the next one first.

Join the List

How Australia Undid Itself  ·  Systems

Back to Writing

Get the Next One Early

New pieces drop most weeks. Systems, sport, the permission machines nobody names. Straight to your inbox.