Australia Releases Draft Digital Duty of Care
On September 8, 2026, the Australian Government released an exposure draft of the Online Safety Amendment (Digital Duty of Care) Bill 2026 (the “draft”). It proposes requiring online services to identify and reduce risks of harm to Australian users proactively. The Government also announced “My Feed, My Way,” an initiative allowing social media users to choose whether their default feeds include personalised recommendations.
The draft would require service providers to manage product design features, conduct written risk assessments and take effective measures to address identified risks. How products recommend content, which features they make available to children, and whether safeguards remain effective would all become matters for assessing compliance. Applying the penalty unit value in force when the draft was released and the fivefold corporate maximum, a body corporate’s failure to comply with the duty could attract penalties of up to A$109.2 million (approximately RMB531 million), consistent with the Government’s announcement. The draft is under consultation, and the Government plans to introduce legislation into Parliament in 2026. This analysis addresses the text released on September 8.
1. Scope and standard of the digital duty of care
The draft would introduce a Digital Duty of Care into the Online Safety Act 2021. Proposed section 26 would require persons responsible for online services to ensure a safe online environment, so far as is reasonably practicable.
The scope covers multiple parts of the online services ecosystem. Proposed section 25A lists social media services, relevant electronic services, designated internet services, hosting services, search engines, app distribution services and internet carriage services. Certain equipment-related services, and services allowing users to generate material using AI and share it through listed services, would also be covered. Responsibility extends both to service providers and to persons in a position to exercise day-to-day control of a service.
Gaming platforms, AI chat products, app stores and related technology providers therefore need to assess which categories their functions place them in. The draft does not restrict the general duty to large social media platforms or automatically exempt services with few users. The Minister could, by legislative instrument, exempt services posing little risk to Australian users or used minimally in Australia from some or all of the relevant provisions. Specific exemptions and conditions remain to be determined.
The “reasonably practicable” standard determines the extent of the duty. Proposed section 25H requires consideration of the likelihood and severity of harm, risks that the responsible person knows or ought reasonably to know about, and available and suitable methods of eliminating or minimising those risks. After assessing the risks and available measures, the person must also weigh costs and the impact on the level of privacy an ordinary reasonable person would expect, including whether those costs or impacts are grossly disproportionate to the risk.
This standard requires businesses to explain the basis for their choice of safeguards. For example, if identifying underage users requires collecting more personal information, a business would need to assess both the protective effect and the privacy impact; invoking safety alone would not replace that assessment. The draft also expressly states that the digital duty of care does not require action in relation to lawful communications occurring privately solely between consenting adults.
2. Child protection and product design requirements
The draft establishes different layers of protection within a safe online environment. Services would need to protect all persons in Australia from seriously harmful material and conduct, including child sexual exploitation, encouragement of self-harm or suicide, serious threats of violence and terrorism-related material. For children under 18, additional protection would cover material and conduct harmful to children, as well as harms associated with the operation of online service design features.
Proposed section 25D includes pornography; material or conduct encouraging, promoting or instructing disordered eating; material or conduct encouraging or promoting hostility towards women or gender equality; material or conduct glorifying crime or encouraging dangerous stunts or harmful practices; and abuse, harassment and bullying. These categories extend child protection scrutiny to the behavioural and psychological effects of content.
For social media, the draft additionally requires design features with negative behavioural impacts not to operate for children in Australia under 16. This forms part of the safe online environment standard within the digital duty of care and must be distinguished from the general protections for children under 18. Compliance would still be assessed in conjunction with the “reasonably practicable” standard described above.
Proposed sections 25F and 25G define the relevant features in some detail:
- Recommender features: selecting and displaying material based on information associated with a user’s account.
- Endless-feed features: feeds without an endpoint, or feeds that add content at the endpoint, at intervals or in response to user input.
- Feedback features: showing users information about others’ viewing, engagement or subscriptions relating to their accounts or content.
- Time-limited features: making content viewable only for a limited period after publication.
- Related logged-in features: requiring an account to access at least one of the endless-feed, feedback or time-limited features described above.
The draft directly treats these listed features as having negative behavioural impacts. Requirements to manage them would not depend on proof of an individual instance of harm. Product reviews would therefore need to examine specific recommendation interfaces, engagement feedback and content presentation. For services other than social media, these features could still be relevant to child-harm risk assessments, but the full set of social media requirements for under-16 users should not automatically be applied to them.
3. Choice over social media recommendations
Under the Government’s “My Feed, My Way” initiative, social media services would notify new and existing users, letting them choose whether their default feeds include personalised recommendations. Users could keep algorithmic recommendations or opt out and view posts from the friends and creators they choose to follow.
The proposal would be implemented through the draft’s power to require user empowerment tools. Proposed section 26 requires appropriate management of design features and authorises the Minister to specify, by legislative instrument, which online services must provide which user empowerment tools. The draft gives control over the kind of content recommended to users as an example, but the section does not fully prescribe notification frequency, interface design or default options.
Subsequent instruments would determine how platforms present, retain and implement users’ choices. The Government is currently proposing a choice mechanism; this does not establish that algorithmic recommendations must be switched off by default for every user.
4. Written risk assessments and product changes
Proposed section 26A would require providers to identify all reasonably foreseeable risks, the content, design features, other systems or processes giving rise to those risks, and people who may be affected. Providers would assess likelihood and potential severity, document measures already implemented or proposed, record their expected effectiveness, the basis for that assessment and relevant periods of effectiveness, and arrange regular reviews.
The draft also specifies timing and record requirements:
- Conduct assessments at least annually, with the eSafety Commissioner able to prescribe shorter intervals.
- Assess service changes that could introduce new or additional risks before making those changes.
- Retain assessments for at least six years and provide them within 30 days of a request from the eSafety Commissioner.
The Commissioner could also prescribe assessment format, detail and metrics.
These requirements directly connect risk assessment to product release processes. For example, before introducing a new recommendation mechanism, a platform would need to determine whether it introduces additional risks, analyse its effects on different user groups and retain the basis for its assessment of safeguards’ expected effectiveness. Assessment records need to explain why safeguards are expected to work and provide for continuing review. Simply recording that a reporting function has been introduced would not address those requirements.
5. Enforcement and the legislative timetable
Proposed section 26B specifies a civil penalty maximum of 60,000 penalty units for failure to comply with the digital duty of care. Section 162(1) of the Online Safety Act 2021 applies Part 4 of the Regulatory Powers (Standard Provisions) Act 2014. Under section 82(5)(a) of that Act, the maximum for a body corporate is five times the amount specified in the provision. The Commonwealth penalty unit increased from A$330 to A$364 on July 1, 2026. At the unit value in force when the draft was released, the maximum for a person other than a body corporate would therefore be A$21.84 million; the corporate maximum would be 60,000 × A$364 × 5 = A$109.2 million, consistent with the Government’s announcement. At the September 9, 2026 RMB central parity rate of RMB4.8610 per Australian dollar, this is approximately RMB531 million. The RMB equivalent is provided only to illustrate the scale of the penalty. This is the proposed maximum converted at the current unit value. The applicable monetary amount would depend on the penalty unit value when the contravention occurs, and the court would determine the actual penalty under the law.
The eSafety Commissioner could also issue formal warnings and remedial directions requiring specified action to prevent future non-compliance. The maximum is not a penalty automatically triggered whenever an item of harmful content appears.
The draft also proposes a removal mechanism for “nudify” apps and websites. Under proposed sections 86B and 86C, where an app or website is designed predominantly to generate fake nude material, or is predominantly used for that purpose, the eSafety Commissioner could issue notices to app distribution services or search engines requiring removal of the app, related links, or advertising, information or access relating to it. Recipients would need to comply to the extent they are capable of doing so within 24 hours, unless the Commissioner allows a longer period.
The draft distinguishes two commencement arrangements. Schedule 1, including the removal provisions described above, would commence the day after Royal Assent. Schedules 2 and 3, including the digital duty of care, would commence the day after the end of the 12-month period beginning on Royal Assent. These remain relative dates in a draft; no fixed compliance date for the digital duty of care has yet been established.
The Department has set a feedback deadline of noon on September 22, 2026. Businesses providing services in Australia can begin by mapping product functions to the draft’s categories, identifying content and design features children may encounter, and checking whether risk assessment can be integrated into product change processes. Specific exemptions, user empowerment tool requirements and assessment details will need to be tracked as the final legislation and supporting instruments develop.
References
Australian Government joint announcement, “My Feed, My Way”: https://minister.infrastructure.gov.au/wells/media-release/my-feed-my-way; exposure draft and consultation arrangements: https://www.infrastructure.gov.au/department/media/publications/exposure-draft-online-safety-amendment-digital-duty-care-bill-2026; full exposure draft dated September 8, 2026: https://www.infrastructure.gov.au/sites/default/files/documents/exposure-draft-online-safety-amendment-digital-duty-of-care-bill-2026-september2026.pdf; Online Safety Act 2021, section 162: https://www.legislation.gov.au/C2021A00076/latest; Regulatory Powers (Standard Provisions) Act 2014, section 82(5): https://www.legislation.gov.au/C2014A00093/latest; Crimes (Amount of a Penalty Unit) Instrument 2026: https://www.legislation.gov.au/F2026N00424/asmade; RMB central parity rates published by the State Administration of Foreign Exchange: https://www.safe.gov.cn/AppStructured/hlw/RMBQuery.do.
