← Red Threads

Australia Digital Duty of Care: operative authority and adult choice

Instrument reviewed: Online Safety Amendment (Digital Duty of Care) Bill 2026, exposure draft dated 8 September 2026. Research date: 9 September 2026. This is proposed legislation, not an enacted duty. The preceding whole-case assessment in forest-reviews.md was read before this lane. All draft powers below are conditional on enactment and, where specified, later instruments.

Primary sources: [D — exposure draft, 75 PDF pages/71 numbered pages](http[local research file] [A — Online Safety Act 2021, official compilation C2024C00852, 11 December 2024](http[local research file] The Register’s [latest-version landing page](http[local research file] identifies that compilation as current. Page locators below are PDF page / printed page, not zero-based reader indices.

Principal finding

The draft would create an enforceable, continuing obligation on service providers and persons exercising day-to-day control to manage online risks. It is not confined to removing already unlawful posts. Parliament would specify initial categories, the minister could expand specified categories and require user controls through legislative instruments, and eSafety could specify assessment requirements and direct remedial action after reasonably believing the duty had been breached. This is a concrete delegation over service design, with legal limits and review routes. It is not evidence that those powers have already been exercised.

The adult-choice boundary is narrower than a general right to assume risk. Under proposed s26(7), the digital duty does not require action concerning lawful communications occurring privately solely between consenting adults. It does not expressly exempt all willing adult consumption of public material or an adult’s private interaction with an AI system. Whether particular AI chats meet the exception remains unresolved; an AI is not expressly treated as a consenting adult. Conversely, pornography is listed in the child-specific category, not automatically in the adult/general list. [D, ss25B–25D, PDF30–33/printed26–29; s26(7), PDF36/printed32.]

Who can require what?

Decision owner Proposed requirement or power Clause, trigger and limit
Parliament, through the enacted text A safe environment so far as reasonably practicable; appropriate design-feature management, written risk assessment and effective measures addressing assessments. D ss25H, 26–26A, PDF35–38/printed31–34. Reasonable practicability weighs likelihood, severity, knowledge, available measures, cost and privacy impact. This is a risk-management duty, not an absolute guarantee that no harm occurs.
Minister Exempt a service/class from one or more duty provisions, possibly conditionally, where risk is small or Australian use minimal. D s25A(3)–(5), PDF30/printed26. Must seek and consider eSafety advice under s27B. This supplies a potential small/low-risk-service route, not an automatic small-business exemption.
Minister Add serious-harm categories; add child-harm categories; deem further design features to have negative behavioural impacts. D ss25C(2), 25D(2), 25G(2), PDF32–34/printed28–30. Legislative instruments; s27B requires eSafety advice. Adult/general additions require ministerial satisfaction that material/conduct may cause serious harm.
Minister Treat a service as social media, or not, for the safe-environment provision; require specified services to provide specified user-empowerment tools. D ss25B(2)–(3), 26(4)–(6), PDF31/printed27 and PDF36/printed32. The special s27B advice list does not include these two powers. Tools may control recommendation/design operation; actual tools and services await instruments.
eSafety Commissioner Set additional assessment detail, methods, standards/metrics and intervals shorter than annual. D s26A(2)(f), (3)–(4), PDF37–38/printed33–34. Legislative instrument. Assess before changes introducing new/additional risk; keep assessments six years and produce within 30 days of request.
eSafety Commissioner Give a written direction specifying action to prevent future duty failures. D s26D, PDF38–39/printed34–35. Requires reasonable belief of present/past noncompliance; not a legislative instrument. Failure to comply carries a separate civil penalty. ART review is added by Schedule 2 item 58.
eSafety Commissioner Select service classes requiring complaint/dispute processes and specify process requirements; direct remediation of noncompliance. D ss26F–26G, PDF39–40/printed35–36. Processes must be equally available to Australians. Detailed entitlements depend on a later instrument; this is not an express universal right to have removed content restored.
eSafety Commissioner Require transparency reports; require classes of providers to publish operational safety information. D ss192C–192N, PDF53–58/printed49–54. Reporting notice must satisfy statutory purposes and consider burden; it must state reasons and review rights. Publication requirements may cover moderation, account removal, complaints and risk assessment.
eSafety Commissioner Compel information/documents, relevant answers and attendance for examination concerning listed investigations or compliance/possible contraventions. D ss198–205, PDF59–63/printed55–59. Reason to believe the person can provide relevant material; the new general compliance limb excludes Part 4A social-media minimum-age provisions. Existing investigation powers are expanded/recast, not created from nothing.
Minister through legislative rules; prospective eSafety approval decisions if the rules so provide Establish researcher-approval and data-access schemes, including data classes, requests, fees, conditions and revocations. D ss205B–205F, PDF63–66/printed59–62; A s240 identifies the minister as legislative-rule maker. Compelled access would depend on those rules. University employment, approval under legislative rules, ethics approval and a prescribed public-interest research kind constrain eligibility.
Approved researchers and eSafety Use fictitious accounts for authorized research/regulatory purposes despite contrary laws or contractual terms. D ss205G–205L, PDF66–68/printed62–64. Listed uses include observing, recording and testing. Engaging other users is limited to what is necessary to prevent account closure. The Commissioner’s additional material-generation power expressly excludes criminal production/dissemination/possession. Good-faith civil immunity is provided.
eSafety Commissioner; courts and tribunal in their distinct roles Issue warnings/infringement notices; seek statutory enforcement; make specified decisions reviewable. D ss26B–26D, 163A, 220 amendments, PDF38–39/printed34–35, PDF45–46/printed41–42, PDF68/printed64; A ss162–165. Do not present the court-level maximum as an amount the Commissioner can conclusively impose without court process.

Coverage and harm thresholds

Proposed s25A covers internet carriage, social media, relevant electronic services, designated internet services, hosting, search, app distribution, specified equipment-related services, and services permitting AI generation and sharing through the listed service types (PDF29–30/printed25–26). Existing A s13A expressly includes email, instant messaging, SMS/MMS, chat and multiplayer online games. A s14 supplies a broad internet-content-service category subject to exclusions. Accordingly, messaging and games are within the proposed duty through existing definitions; the private-adult exception affects action required, rather than excluding all messaging services. The AI limb is functionally described, not a blanket designation of every offline model or every AI developer. Other categories might independently cover an online AI product.

The general protection in s25B(1)(a) uses s25C’s list: child sexual exploitation/abuse and grooming; encouragement/instruction of sexual or extreme violence; explicit violent threats; intentional serious-harm harassment; encouragement of suicide, self-harm, sadistic exploitation or animal cruelty; specified terrorism support; encouragement/instruction of crime and illicit drug use; abhorrent violent conduct; and ministerially added categories. There is no single overarching requirement that every item must first be independently criminal. Nor is the entire list subject to the existing adult-targeted cyber-abuse test in A s7. These are distinct schemes. [D PDF31–32/printed27–28; A ss5, 7.]

The retained A s5 definition makes serious harm physical or mental-health harm of sufficient seriousness, including serious psychological harm/distress, and excludes mere ordinary emotional responses. This matters to the minister’s expansion threshold and references to serious harm. It does not require re-proving each expressly listed s25C category under A s7’s separate targeted-abuse test.

Child-specific s25D additionally names pornography, disordered-eating promotion/instruction, promotion of hostility toward women or gender equality, crime glorification/dangerous stunts/harmful practices, and abuse/harassment/bullying. It includes a residual category capable of seriously harming a child and ministerially determined additions, the latter using a child-harm satisfaction threshold. The minister’s power is not the sole source of that residual coverage. [D PDF32–33/printed28–29.]

For social media, s25B(1)(c) additionally requires the specified negative-impact features not to operate for children under 16. Sections 25F–25G define and deem recommendation, login-dependent, endless-feed, feedback and time-limited features to have those impacts. This is stronger than an optional parental toggle. It is subject to the overarching reasonably-practicable duty and ministerial service determinations. The draft does not itself prescribe a particular adult algorithm opt-in/opt-out interface: later user-tool instruments would supply that detail. [D PDF31–36/printed27–32.]

Privacy, identity, expression and researcher boundaries

Privacy appears expressly in s25H’s proportionality assessment. Section 26(7)’s private-consenting-adult exception is an additional substantive boundary. Neither supplies an explicit general encryption exemption or a technical rule forbidding every possible demand affecting encryption. The inspected operative draft does not prescribe universal government-ID collection, a named age-verification vendor or a general obligation to identify all users. Distinguish absence of such a clause from proof that future implementation has no identity or encryption implications.

Existing A ss194–195 already permit notices for held end-user identity/contact information on reasonable grounds of relevance to the Act, with compliance limited by capability. They are not newly invented by this draft, and are not a universal account-ID collection requirement. Their reference to the Act’s operation would sit alongside an expanded Act if enacted. Schedule 2 item 63 also adds eSafety to the Privacy Act definition of enforcement body; the detailed interaction with Australian Privacy Principles was not audited here.

Existing A s233 preserves the constitutional implied freedom of political communication. This is not a general statutory right to access all lawful adult material. The draft supplies no comparable comprehensive adult-consent override. Privacy is a weighed factor; a preference to accept risk does not, by itself, switch off the service’s whole duty. That leaves a substantive adult-autonomy question without justifying the claim that every lawful adult choice is prohibited.

For transparency reports published by eSafety, s192G expressly excludes protected confidential and personal information (PDF55/printed51). For provider publication, s192M(6) instead points to kinds of information specified in the determination for exclusion (PDF58/printed54). Do not treat the two protections as identical.

Research access has real institutional selection. Section 205B requires employment by an Australian university, approval under legislative rules, ethics approval through the university and a prescribed public-interest kind of research. It does not grant automatic access to every NGO, advocate or company. Section 205C permits later rules about conflicts, privacy/security/confidentiality, commercial use restrictions, cost-limited provider fees, and review/reconsideration of decisions to grant access requests. Those subjects are delegated; the complete safeguards and review entitlements are not already written into this draft. No named organization is appointed or given a present data-access entitlement. [D PDF64–65/printed60–61.]

Cross-lane comparison: Reset.Tech Australia's 2024 submission 70 requested vetted researcher access including third-sector organizations (printed p26/PDF28). The draft instead expressly requires employment by an Australian university, plus the prospective approval and research conditions above. That is a narrower independent eligibility route than the advocate requested; it does not award Reset a data right. It does not rule out university collaboration or indirect institutional benefit. This proposal-side passage was inspected by the parent researcher and reconciled in the independent review, rather than independently reacquired in this lane. Sources: [Reset submission 70](http[local research file] [policy-lineage.md]([local research file] draft s205B, PDF64/printed60.

Supervision, remedies and changes from existing law

The draft adds ART review for duty, complaint-process and data-access remedial directions through s220(12), and for transparency notices through new s220(23). Existing A s220A requires an internal-review scheme for decisions of the kinds in s220. The draft does not spell out a new automatic stay or a general merits appeal against all rulemaking, warnings or researcher approvals. Do not infer no judicial remedy; the detailed judicial-review/stay framework and future research-review rules were not examined. [D PDF68/printed64; A ss220–220A.]

Ministerial appointment and conflict/termination rules remain in A ss167–176. A s188 permits binding ministerial directions of a general nature only; its note expressly identifies disallowance and sunsetting exemptions. That is different from a ministerial power to reverse a particular notice. The draft’s new duty instruments are legislative instruments, while individual remedial directions and the annual enforcement-priority statement are expressly non-legislative. No new exemption from parliamentary disallowance is written alongside the duty instruments read here; an instrument-specific application of the general Legislation Act exemptions was not completed. Do not claim every instrument is immune from scrutiny, or that every one receives an affirmative parliamentary vote.

Under new s166C, eSafety must publish annual monitoring/enforcement priorities, but the statement expressly does not restrict its functions or powers. Existing annual reporting continues; the draft adds counts of new directions. Existing good-faith protection from damages in A s222 is distinct from access to review. The draft also resets the s239A independent-review timing by reference to duty commencement; the surviving provision requires a written report tabled in Parliament. [D PDF49–51/printed45–47 and PDF70/printed66; A ss183, 222, 239A.]

A consequential change is information compulsion. Existing A ss198–205 tie powers to specified investigations and allow a reasonable excuse and refusal on self-incrimination grounds. The replacement expands scope to compliance/possible contravention, removes that general reasonable-excuse wording, and compels self-incriminating material while providing individual use and derivative-use protection, subject to stated exceptions. It preserves a journalist-source exception. A private examination, adviser and record remain, although the draft makes obtaining the record request-based and timing subject to the Commissioner/delegate’s view. The existing 12-month criminal maximum for noncompliance is retained/recast; the civil penalty stated becomes 1,000 units. [D PDF59–63/printed55–59; A ss198–205.]

The draft states 60,000 penalty units for duty breach and disobeying duty-remediation directions; 6,000 for complaint-process, transparency and data-access failures; and 1,000 for failing a required Australian contact nomination. New s163A specifies 12 units for an individual or 600 for a corporation per alleged contravention in the listed infringement-notice scheme. These are distinct mechanisms; corporate multipliers, continuing contraventions and dollar conversion were not calculated here. Existing A s162 makes eSafety an applicant and names the Federal Court and Federal Circuit and Family Court (Division 2) as relevant civil-penalty courts.

Not every clause is a new power. Proposed s177A substantially relocates existing A s28’s general necessary/convenient power. Grant and educational/research functions substantially continue existing A s27, with transitional continuity in Schedule 2 item 65. By contrast, the general duty, expanded compliance-information limb and research-access scheme are material new instruments. Schedule 2 repeals the Basic Online Safety Expectations Part 4; Schedule 3 repeals the online-content industry-code/standard division. This is a replacement architecture, not simply an additional overlay while all earlier instruments necessarily persist. [D PDF41/printed37, PDF50/printed46, PDF72–74/printed68–70; A ss27–28.]

Separate immediate notice changes

Schedule 1 would commence the day after assent; the duty and industry-code repeal schedules would commence after 12 months (D PDF6/printed2). Proposed s86B permits eSafety, on reasonable grounds of predominant design or use for fake-nude generation, to order app-store/search removal of an app, links, advertising, information or access. Section 86C gives 24 hours unless extended, capability-limited compliance and 6,000 units; s220(10B) adds ART review. This is a specific proposed distribution gate, separate from the general duty. The definition scope of fake nude material was not resolved in this lane: no definition appeared in the inserted lists read, but existing and incorporated definitions were not comprehensively traced. This is not an explicitly marked missing definition or evidence of redaction; the definition question remains unresolved in this scoped reading. [D PDF7–9/printed3–5.]

Other Schedule 1 amendments reduce the initial platform-complaint waiting period from 48 to 24 hours, permit waivers for inaccessible complaints systems or foreseeable further harm, and address reposts after a prior removal notice. They do not erase the distinct substantive targeted-adult-abuse test. New search-link deletion notices generally require a prior removal notice, an appropriateness judgment and revocation when no longer required or outstanding removals are complied with. These are extensions of existing removal machinery, not a newly invented power to remove any disliked speech. [D PDF9–22/printed5–18; A ss7, 88–90.]

Evidence scope and stopping point

The shared web-reader rendition of the original publisher’s PDF was used. Read: front matter/commencement; Schedule 2 operative definitions, duty, enforcement, transparency, information, research, review and transition provisions; Schedule 3 repeal provisions; targeted Schedule 1 fake-nude, adult-removal, link-deletion, review and disclosure amendments. Detailed adjacent Schedule 1 paragraphs were not all separately examined. For the existing Act, read the cited definitions, powers, enforcement, ministerial oversight, information, review, expression and rulemaking provisions, not the entire Act.

No original PDF bytes were retained by this lane. Initial direct URL web-open returned a non-retryable safe-open error; one ordinary PDF GET timed out after 30 seconds with no body. Reusing the access agent’s already working source reference supplied the necessary text. These were transport errors, not an automatic sandbox-approval rejection; no blocked browser route was retried. Parliament explanatory-page opens and one current Legislation Act route also failed, so this packet limits its disallowance claim as stated above. Neither this lane nor the access lane acquired original draft bytes or a file hash. The access lane retains scoped public-reader evidence and a stated visual gap; this file is not a preserved original.

The instrument breakpoint is reached. The strongest defensible interpretation is expanded preventative service-design regulation with ministerial category-setting, eSafety implementation/enforcement and selected review mechanisms. A rival interpretation focused on ordinary prevention of serious harms remains compatible with the text; motive is not resolved. The decisive autonomy gap is how the minister/regulator would distinguish protected adult choice from preventable harm in concrete instruments and decisions, especially AI interactions. The private-adult exception belongs to the digital duty; it does not purport to disable every separate notice or information power in the Act. Missing discriminating records are settled definitions, actual user-tool/risk-assessment/data-access rules, safeguards and review procedures, and later decisions applying them. No new branch is opened here; return to the whole-case assessment.