The Australian Government recently released the exposure draft of the Online Safety Amendment (Digital Duty of Care) Bill 2026 (the Draft Bill), which would amend the Online Safety Act 2021 (Cth) (Online Safety Act) by introducing a new ‘digital duty of care’.

The Draft Bill proposes the most significant overhaul of Australia’s online safety framework since the Online Safety Act commenced in January 2022, moving from reactive content removal to proactive, systems-based regulation across almost every website and app. The Draft Bill has been described by the Australian Government as requiring providers to “step up and do more to keep Australians safe from harm on their platforms”. The policy rationale is set out in the Australian Government’s impact analysis of the Digital Duty of Care Model for Online Safety, which frames the reform as “shifting the focus of the Act from reacting to harms to preventing them”.

While the policy objective has attracted support from a range of stakeholders, the Draft Bill substantially departs from the Issues Paper on a Digital Duty of Care, on which industry and the community were consulted (Issues Paper) and the 2024 Report of the Statutory Review of the Online Safety Act (the Rickard Review). It is likely that several parts of the Draft Bill will undergo further change.

Eight key takeaways

The Draft Bill is technically dense, but its practical implications can be distilled into eight key takeaways:

  1. The Draft Bill imposes a single ‘digital duty of care’ on the person responsible for an ‘online service’ - proposing to replace the service-specific (and often confusing) treatment of different kinds of providers under the existing regime of the Online Safety Act. The regime has always had an expansive scope, reaching beyond social media, but it now expressly extends to generative AI services and applies uniformly to a broad range of online providers.
  2. A covered service must conduct annual written risk assessments, retain them for six years, and produce them to the eSafety Commissioner on request. Maximum penalties of $109.2 million apply.
  3. The Draft Bill repeals the existing provisions in relation to the Online Safety Codes and Standards (Codes and Standards) and Basic Online Safety Expectations (BOSE), replacing a detailed, service-specific regime with the principles-based digital duty of care. Compliance guidance is proposed to be provided by the eSafety Commissioner’s guidelines.
  4. The Draft Bill proposes an opt-out model for algorithms, rather than one which is opt in, despite some stakeholder expectations for default safety settings. This is to be achieved through ‘user empowerment tools’ specified by the Minister, which have not yet been published.
  5. The ‘user empowerment tool’ concept is far broader than algorithms and allows the Minister to require any covered service to give its users control over design features specified by the Minister.
  6. The Draft Bill’s key definitions contain apparent inconsistencies that require further clarification. For example, ‘harm’ is defined by reference to material or conduct only, yet the duty itself appears also to address harms arising from design features.
  7. The Draft Bill grants very broad delegated powers to the Minister to expand the scope of harms and services covered by the Online Safety Act.
  8. There are no express protections for legitimate forms of communication, such as journalism, political communications, court reporting, health information and educational content, which would all be subject to the Draft Bill.

The duty of care applies broadly

The digital duty of care sits at the centre of the Draft Bill. Section 26(1) provides that a person responsible for an online service “must ensure, so far as is reasonably practicable, a safe online environment”.

Section 25A defines ‘online services’ broadly to include social media, search engines, app distribution services, hosting services, equipment-related services and services that allow users to generate and share material by means of artificial intelligence (in this article, covered services). The Online Safety Act has never been limited to social media platforms, and most covered services already fell within its remit, with the express inclusion of AI services being the genuinely new category. What has changed is the framing: instead of regulating each kind of provider through separate, service-specific provisions or instruments, such as through differentiated Codes and Standards, the Draft Bill imposes one duty on the ‘person responsible’ for a covered service. The practical effect is that a single, uniform obligation would attach to a broad range of operators of websites and apps accessible in Australia.

The earlier Issues Paper proposed that the digital duty of care would require service providers to maintain “effective systems and processes” that:

  • so far as is reasonably practicable, provide a safe online environment for all Australians;
  • prevent, monitor and appropriately address content and activity that is illegal or harmful to young people; and
  • ensure the safety of service features, including AI and algorithmic content recommendation or generation systems and bot accounts.

Under the Issues Paper framework, failure of a service provider to take reasonable steps to maintain effective systems and processes would constitute a breach. The Issues Paper was also explicit that “services will not be liable for individual instances of harmful content or activity”. The Rickard Review recommended a risk-tiering approach, rather than a blanket obligation applying across all online services.

The Draft Bill departs substantially from both these frameworks.

Under the Issues Paper, providers would be liable for failing to maintain adequate systems and processes - that is, a process-driven obligation that makes them answerable for the quality of their efforts. By contrast, the Draft Bill imposes an obligation to ‘ensure’ a safe online environment in which every person in Australia is protected from certain harms. That is an outcomes-focused obligation: if a person suffers relevant harm, there will be a presumption that the environment was unsafe. While the ‘reasonably practicable’ test in section 25H softens this, as currently drafted it leaves those responsible for covered services facing uncertain regulatory risk, particularly as the matters that section 25H requires to be taken into account do not mirror the scope of the digital duty of care.

Several other elements from the Issues Paper are missing from the Draft Bill.

  • First, the concept of ‘effective systems and processes’ does not appear anywhere in the Draft Bill, despite being the centrepiece of the Issues Paper’s framework. That concept would have given providers a clear compliance target against which to build adequate systems and to discharge their digital duty of care.
  • Second, there is no obligation directed specifically at AI, algorithmic systems or bot accounts, despite the Issues Paper explicitly contemplating these as key sources of emerging harm requiring dedicated attention.
  • Third, the concept of ‘reasonable foreseeability’, which the Issues Paper positioned as central to the duty, is not carried through consistently in the Draft Bill. The ‘reasonably practicable’ test and the risk assessment provisions (section 26A) address questions of likelihood and foreseeability inconsistently.
  • Finally, the Issues Paper’s language that services should “prevent, monitor and appropriately address” reasonably foreseeable harms has been replaced with a near-absolute obligation to “ensure” safety (albeit caveated by practicability).

Compliance burden is significant

The Draft Bill requires each provider to conduct a written risk assessment under section 26A.

The assessment must:

  • meet the minimum requirements of section 26A (including by identifying all reasonably foreseeable risks – not just those relevant to the digital duty of care);
  • be updated annually at a minimum;
  • be retained for at least six years; and
  • be provided to the eSafety Commissioner within 30 days of a request.

The maximum penalty for failing to meet this obligation is $109.2 million.

This is a material compliance burden that applies to each covered service, regardless of scale. In its current form, even a simple informational website with no user-generated content and no connection to the harms of concern would be required to conduct annual risk assessments, retain records for six years and produce them to the eSafety Commissioner on request. That approach differs from equivalent European legislation (and as recommended in the Rickard Review), which provides threshold tests based on revenue, size or reach. That breadth is difficult to reconcile with the Australian Government’s impact analysis, which estimates that the whole package of reforms will increase regulatory costs for Australian businesses by $1.408 million per year over ten years, on the basis that compliance requirements would be “proportionate, being calibrated to both their reach (user numbers) and risk” - calibration that the Draft Bill does not appear to presently deliver.

The only potential relief available is a discretionary ministerial exemption for an online service or class of services posing ‘little risk’ or used ‘minimally’ in Australia. However, the Minister is not obliged to exempt any particular services.

Codes and Standards would be repealed

The Draft Bill repeals the existing provisions that establish the Codes and Standards and the BOSE, replacing this complex matrix of regulations and industry codes with the digital duty of care and guidelines to be published by the eSafety Commissioner. The Australian Government’s impact analysis indicates that the duty is intended to “eventually replace existing codes and standards after a period of transition” designed to minimise “unnecessary industry compliance burdens”, with “ample notice and clear signposting of the timing for each stage”.

The repeal may reflect the view that the current regime has become too detailed and too administratively demanding for the eSafety Commissioner to administer. The enforcement process concerning X Corp is illustrative: enforcing a single BOSE transparency notice took more than three years and involved a first-instance judicial review proceeding, an appeal to the Full Court and civil penalty proceedings, culminating in orders made by consent in eSafety Commissioner v X Corp (Civil Penalty) [2026] FCA 629 that imposed a civil penalty of $650,000.

In place of registered codes developed with industry, providers are left with an outcomes-focused duty to “ensure” a safe online environment, no threshold relief, and only non-binding guidelines from the eSafety Commissioner against which to measure compliance. That combination shifts the burden of assessing what the duty requires onto every provider.

Three categories of online harm

The Draft Bill targets online harms through three specific categories: content, conduct and design features.

Content

The content limb regulates the material provided on a service. Providers must ensure their services do not host seriously harmful material (as defined in section 25C) or material harmful to children (as defined in section 25D).

When it comes to children, additional content restrictions apply. This is where the drafting of the Draft Bill is more open to subjective interpretation. To take one example, the ban on material that provides instructions for disordered eating would certainly cover material that encourages anorexia. But does it also include online content that promotes the latest diet fad where medical authorities have issued warnings? What about where no warnings have been issued?

Conduct

The conduct limb regulates whether a service facilitates harmful behaviour. This concerns whether a covered service enables users to engage in harmful conduct, for example, by allowing users to bully or harass one another. Since sections 25C and 25D regulate both material and conduct, online services cannot remain content neutral. While many major platforms already monitor user conduct (for example, by scanning comments for objectionable words and phrases), this new obligation would apply to every covered service, regardless of scale.

Design features

The design features category regulates how a service operates. It is the broadest and least specific of the three categories.

Section 25F lists categories of design features, including recommender features, logged-in features, endless-feed features, feedback features and time-limited features. The definitions extend beyond social media; a ‘recommender feature’, for example, potentially captures e-commerce product recommendations and what an online streaming service recommends as the next movie to watch based on a user’s viewing history or preferences.

Section 25G then treats all listed features as having ‘negative behavioural impacts’ without requiring evidence of actual harm in any particular case (whether this deeming of negative behavioural impacts is limited to social media services under section 25B(1)(c) is not clear).

Adding to the complexity, the definition of ‘safe online environment’ under section 25B is itself split into three distinct categories:

  • protection of adults from seriously harmful material and conduct;
  • protection of children from material and conduct harmful to children; and
  • for social media services, protection of children under 16 from design feature harms. The third category appears directed at addressing gaps left by the social media minimum age restrictions (SMMA) – it applies only to design features that have negative behavioural impacts for children under 16. However, if under the SMMA users under 16 cannot have accounts, it is unclear how this limb is intended to operate, particularly as many of the design features listed in section 25F depend on the user accessing the service with an account.

Lastly, section 25E defines ‘harm’ by reference to material or conduct only, omitting design features entirely. Under this definition, it is unclear what kinds of ‘harms’ an online service is required to address in its annual risk assessment, or otherwise seek to avoid as part of ensuring a safe online environment.

The Minister has broad delegated powers

The Draft Bill grants very broad delegated powers to the Minister. The Minister can add categories of harm and design features by legislative instrument, determine whether a service is a social media service for the purposes of the children’s design feature limb, and expand the scope of services caught by the regime. While it is not unusual for legislation to grant powers to the Minister or a regulator, the breadth of the proposed laws as they currently stand, together with the listing of certain kinds of harm that are at risk of being read in a subjective manner, means that there may be few legislative limits on how the Minister may act under these powers.

No express protection for legitimate material

There are currently no explicit exceptions for material published for legitimate purposes, even where the intent is to inform rather than harm. The digital duty of care contains only one express carve-out: section 26(7), which concerns lawful private communications between consenting adults.

The breadth of the drafting may create significant unintended consequences. Legitimate material, such as news, political communications, court reporting, health information and educational content, is caught by default. The key risk is that the proposed legislation does not just prohibit material that any reasonable mind would consider to be objectionable, but instead (1) affects material that reasonable minds may differ on; and (2) does not appear to place any importance on the context in which that material is communicated.

Algorithms are not directly regulated

Media attention concerning the Draft Bill has centred on control over algorithms.

However, the Draft Bill does not directly regulate algorithms. Instead, it requires providers to manage design features appropriately, including by providing ‘user empowerment tools’ as required by the Minister. The concept of ‘user empowerment tools’ is, however, far broader than an algorithmic opt out and could extend to controls over any design feature. This gives the Minister significant discretion to determine which design features are subject to those controls.

That said, the diverse range of online services and the services they offer means that it may be practically difficult for the Minister to specify ‘user empowerment tools’ in a way that is clearly understood and actionable by online services. As this new framework moves away from the granular approach adopted under the Online Safety Codes and Standards, it may make it more difficult for the Minister to tailor the exercise of their rule-making power to specific circumstances.

Critically, the model appears to be opt out rather than opt in, meaning that users must actively locate and engage a control in account preferences to access safety settings, rather than having those settings apply by default.

Other significant amendments

The Draft Bill also makes several other significant amendments to the Online Safety Act, including:

  • Nudify apps: App stores and search engines may be directed to remove ‘nudify’ apps or links to fake-nude generators, generally within 24 hours.
  • Faster removal: Removal timeframes shorten from 48 to 24 hours, and the eSafety Commissioner may waive the requirement to complain to the platform first, and no fresh complaint is needed where material is reposted within six months.
  • Link deletion: The eSafety Commissioner may direct search engines to remove links to cyberbullying, intimate image and cyber abuse material, generally within 24 hours.
  • Sock puppet identities: Researchers and the eSafety Commissioner may assume false identities on platforms to observe and test services, overriding terms of service, with civil immunity for the good faith exercise of those powers.
  • Transparency: The eSafety Commissioner may require transparency reports, and providers may need to nominate an Australian-resident point of contact.

What this means

The purpose of these online safety reforms is to ensure that users can engage in positive online experiences and use platforms safely. The proposed digital duty of care, in its current form, applies uniformly to every covered service without a statutory threshold, departs materially from the framework that was consulted on in the Issues Paper, and leaves key gaps including unclear definitions, missing exemptions and broad delegated powers. Unless these matters are addressed, many providers will face uncertainty about the practical scope and risks of their digital duty of care obligations.

The Australian Government has indicated that it intends to introduce the Draft Bill to Parliament this year. Consultation closes at midday on 22 September 2026.