Safe by design: unpacking Australia’s proposed digital duty of care for online services

Cameron Gascoyne, Greg Williams, Alex Horder, Alex Fiddis
21 Sep 2026
9 minutes

On 8 September 2026, the Australian Government released an exposure draft of the Online Safety Amendment (Digital Duty of Care) Bill 2026 (Exposure Draft Bill) following the Government's response to its 2024 review of the Online Safety Act 2021 (Cth) (Online Safety Act). The Exposure Draft Bill would fundamentally reshape the regulatory landscape for online service providers in Australia, replacing the current co-regulatory framework with a prescriptive, regulator-enforced model. Public consultation closes at 12:00 pm on 22 September 2026.

At its centre is a new statutory "digital duty of care", which would impose a proactive obligation on a broad range of online service providers to protect users from online harms. Beyond this headline measure, the Exposure Draft Bill would repeal the online content scheme industry codes and standards and significantly expand the eSafety Commissioner’s enforcement powers, with substantially increased penalties for non-compliance; the Exposure Draft does not expressly repeal the existing Basic Online Safety Expectations determination, and any change to BOSE would need to be confirmed in the final legislation or accompanying instruments.

The proposed reforms should be considered alongside the Government's parallel initiatives on mandatory Australian Standards for AI and the next wave of privacy law reform. Together, they reflect an accelerating shift towards a comprehensive, regulator-led digital governance framework in Australia.

The digital duty of care: what does a "safe online environment" look like?

The centrepiece of the Exposure Draft Bill is a new statutory digital duty of care, which would require any person responsible for an online service to "ensure, so far as is reasonably practicable, a safe online environment".

The duty will apply not only to online service providers but also to anyone who can "exercise day-to-day control" over an online service. The definition of "online service" is broad, covering the usual suspects currently regulated by the relevant codes and standards (subject to some adjustments to the existing equipment provider category) but also extending to services that let users generate AI content and share it through another online service. In practice, this means AI developers, content tools and technology businesses that are not currently regulated under the Online Safety Act may be caught.

A "safe online environment" is one in which:

  • all persons are protected from "seriously harmful material and conduct" – an exhaustive but Ministerially extendable category covering material relating to child sexual exploitation and abuse, grooming, sexual violence, extreme violence, harassment and self-harm; and

  • children attract a broader, additional layer of protection from:

    o material and conduct "harmful to children" – a wider but less exhaustively defined category, including pornography, eating disorder content, misogynistic material, abuse, harassment or bullying, and any other material or conduct capable of inflicting serious harm on a child; and

    o "harms" arising from platform design features – which can flow from material or conduct whether or not directly engaged with or experienced by a user.

For social media services, certain design features are taken to have "negative behavioural impacts" for users under 16, with restrictions and default settings to be specified by rules or determinations. These include recommender, logged-in, endless-feed, feedback and time-limited features, plus any other feature the Minister determines. This would complement the Government’s broader suite of child safety measures we previously examined.

The duty is not absolute; the "reasonably practicable" qualifier, which largely reflects principles from workplace safety legislation (see below), requires weighing up all relevant matters, including:

  • the likelihood and degree of harm;

  • what is known or ought reasonably to be known about the risk;

  • the availability of mitigation measures; and

  • the cost of those measures, or the impact on user privacy, including whether that cost or impact would be "grossly disproportionate" to the risk.

What will the digital duty of care require?

The digital duty of care carries with it three mandatory pillars:

  1. Managing design features, including providing any required user empowerment tools

  • The Minister would have the power to require specified online services to provide "user empowerment tools" – features that give users greater control over how a service operates, such as shaping what content is recommended to them.

  • A critical part of this pillar is the Australian Government's My Feed, My Way initiative, which would require social media platforms to let users choose between a personalised algorithmic feed and a feed showing only content from accounts they follow. This algorithm opt-out is expected to be among the first tools prescribed by the Minister.

  1. Conducting risk assessments

  • Providers would be required to prepare written risk assessments addressing the harm posed by their service. Each assessment would need to identify all reasonably foreseeable risks, evaluate their likelihood and severity, document mitigation measures and their expected effectiveness, and provide for regular review, along with any additional requirements determined by the eSafety Commissioner.

  • Assessments would need to be reviewed at least annually and before making any changes to a service that could introduce new or additional risks, retained for six years and furnished to the eSafety Commissioner within 30 days on request.

  • These obligations go well beyond the existing Codes and Standards, bringing Australia closer to the broad risk-assessment regimes under the EU's Digital Services Act and the UK's Online Safety Act 2023.

  1. Taking effective measures to address those assessments

Cross-party momentum behind a prescriptive regulatory model has been building for some time, signalling to industry that compliance obligations in this space are a question of "when", not "if". The proposed obligations closely mirror the Australian Greens' Online Safety Amendment (Fix Our Feeds) Bill 2026, introduced into the Senate in April, a proposal now effectively subsumed within the Australian Government's considerably broader Exposure Draft Bill.

Beyond the digital duty of care

The Exposure Draft Bill introduces several additional obligations designed to support the digital duty of care, most of which would only take effect once the eSafety Commissioner makes a determination or issues a written notice:

  • Complaint and dispute processes. Persons responsible for prescribed online services would be required to maintain complaint and dispute processes meeting requirements set by the eSafety Commissioner.

  • Transparency reports. The eSafety Commissioner could require providers, by written notice, to prepare transparency reports on service safety, such as compliance with the Online Safety Act and performance against specified standards or benchmarks. The eSafety Commissioner would have the power to publish these reports on its website.

  • Publication of safety information. The eSafety Commissioner would be empowered, by legislative instrument, to determine that providers in a specific class must publish information about their operations or activities relating to online safety (such as content moderation decisions or complaints received) on their website.

  • Information for online safety-related research. A new statutory framework would enable data access schemes requiring providers to give approved researchers access to data for online safety research.

  • Nominated point of contact: The eSafety Commissioner could require providers to nominate an Australian-resident individual as a point of contact.

The Exposure Draft Bill would repeal the online content scheme industry codes and standards, which would cease to have effect from the commencement of the digital duty of care (12 months after Royal Assent). The status of the existing Basic Online Safety Expectations determination is not expressly altered in the Exposure Draft text; any future replacement or repeal would occur via legislative instrument or subsequent amendment.

Other changes to the Online Safety Act are also proposed, including:

  • "Sock puppet identities". The eSafety Commissioner and approved researchers would be permitted to assume false identities when carrying out activities in relation to online services.

  • New removal notice powers for "fake nude material". This framework would prohibit certain apps and websites designed for, or predominantly used to generate, sexually explicit deepfake images; providers of app distribution and internet search engine services would be required to comply with removal notices within 24 hours, and decisions to give such notices would be subject to review by the Administrative Review Tribunal.

  • Expanded link deletion powers. The eSafety Commissioner would gain new powers to require internet search engine services to remove links to cyberbullying material targeting children, cyber-abuse material targeting adults, and intimate image abuse material.

  • Accelerated content removal timeframes. Compliance periods for several existing takedown and removal notice regimes would be reduced from 48 hours to 24 hours.

Expanded enforcement powers and consequences for non-compliance

The eSafety Commissioner would gain substantially broader powers, including to issue formal warnings and remedial directions and to publish those warnings publicly, adding a reputational dimension to regulatory action. Notably, a remedial direction could be issued where the eSafety Commissioner reasonably believes a contravention has occurred or is likely to occur – a deliberately low threshold that businesses should treat as a practical trigger for intervention.

The eSafety Commissioner's compliance and investigative powers would also be expanded, including the power to require persons to give information or evidence, and produce documents – a tool that underscores the regulator's intent to pursue enforcement proactively.

The potential financial exposure for non-compliance is significant. Bodies corporate that breach the digital duty of care, or fail to comply with a remedial direction, could attract a civil penalty of up to approximately $109 million (based on the current value of penalty units under Australian law), and for infringement notices, penalties could be issued of up to approximately $218,000. The Government has also signalled substantial maximum penalties for systemic breaches.

Familiar frameworks, unfamiliar territory: product liability and workplace safety parallels

The Exposure Draft Bill's duty of care draws deliberately from product liability and workplace safety law. As the Minister for Communications has noted: "Just as we have basic safety standards for cars, toys or food, the duty of care applies basic standards for the online products we use every day."

  • Product liability. The Exposure Draft Bill creates a statutory duty, akin to the law of negligence but comprising specific obligations to ensure that a "safe online environment". This is a new concept and its precise content will no doubt be developed through case law. However, the Exposure Draft Bill does not create an express private right of action permitting an individual to sue for damages. Rather, the risk for online service providers is regulatory action (including fines) by the eSafety Commissioner. If the Exposure Draft Bill becomes law it seems inevitable that individuals will argue that the statutory duty should inform the content of an online service provider's duty of care in negligence and therefore provide a basis to sue for damages. However, there is no such express right in the legislation and whether such arguments would succeed remains to be seen.

  • Workplace safety. The "reasonably practicable" standard closely tracks the duty framework under the Work Health and Safety Act 2011 (Cth). The requirement for documented annual risk assessments identifying risks, affected persons, and mitigation measures is directly analogous to obligations on persons conducting a business or undertaking under workplace safety legislation.

Key takeaways

The Exposure Draft Bill signals a fundamental regulatory shift – from industry-led codes to a prescriptive, regulator-enforced duty model. However, significant uncertainties remain. No explanatory statement has been released and many obligations will depend on Ministerial rules, legislative instruments or eSafety Commissioner guidance yet to be developed.

Most key changes would commence 12 months after Royal Assent, though expanded removal and link deletion notice powers would take effect immediately. Given the breadth of the reforms and the substantial penalties for non-compliance, organisations operating across the online services ecosystem may wish to consider engaging with the consultation process (noting public consultation closes at 12:00 pm on 22 September 2026) and should begin preparing for a significantly more prescriptive regulatory environment. Five areas warrant early attention:

  • Map your exposure. The definition of "online service" is broad, capturing social media, search engines, hosting, app distribution and AI-generated content services. Organisations should assess whether their operations fall within scope, including services that may not traditionally be considered "online platforms".

  • Prepare for mandatory risk assessments. Annual written risk assessments that identify foreseeable risks will be a cornerstone of compliance. Organisations should begin building internal processes and governance structures to support this obligation now.

  • Review existing compliance. Providers that have invested in meeting the BOSE framework and Codes and Standards should audit that work to determine what can be leveraged as a foundation for the new regime and to identify where gaps remain.

  • Build algorithmic feed compliance into product roadmaps. The My Feed, My Way initiative will require platforms to offer users genuine choice over algorithmic personalisation. Product and engineering teams should start scoping the technical and design changes required.

  • Monitor subordinate legislation and eSafety Commissioner guidance. Much of the operational detail – including the prescribed user empowerment tools, risk assessment requirements, and complaint process standards – will be set by Ministerial rules and eSafety Commissioner determinations. This is a space to watch closely as the regime takes shape.

Be the first to know

Legal updates and articles on the topics that matter to you, sent as they happen.

Subscribe
Disclaimer
Clayton Utz communications are intended to provide commentary and general information. They should not be relied upon as legal advice. Formal legal advice should be sought in particular transactions or on matters of interest arising from this communication. Persons listed may not be admitted in all States and Territories.