9 September 2026. Bounded official-source legal-clock pass, now closed. This note does not determine this operator's compliance or identify an eSafety assurance.
The closest documented match is the Online Safety (Designated Internet Services—Class 1A and Class 1B Material) Industry Standard 2024, which commenced 22 December 2024, rather than January 2025. Its contemporary announcement expressly discusses some generative-AI and nudification services. That makes it a strong candidate for the instrument being loosely described in the email; it does not establish that this was the operator's intended reference. The separate RES standard has the same clock. The other concrete AI-related changes checked here commenced in May and September 2024.
The source assertion is the respondent's 25 December 2024 email, section 6, retained Tilak declaration Exhibit 6 PDF21: it says eSafety communicated specific requirements, the service complied, and was confirmed aligned with upcoming AI legislation effective January 2025. It is an interested participant's account, with no instrument name or enclosed Australian assurance on that page. Local source: ../sf-compliance-wave-2026-09-09/tilak-declaration-june13-2025.pdf; this pass read the existing PDF21 text extract, not the rest of the declaration afresh.
| Instrument | Making / registration | Commencement | Relevance and boundary |
|---|---|---|---|
| DIS Class1A/1B Standard2024, F2024L00710 | Made19June2024 by Julie Inman Grant; Federal Register registration21June2024 | 22December2024 | Closest substantive match: includes high-impact generative-AI services and model distribution platforms, with duties directed to specified seriously harmful classes. |
| RES Class1A/1B Standard2024, F2024L00711 | Made19June2024 by Julie Inman Grant; Federal Register registration21June2024 | 22December2024 | Companion instrument for relevant electronic services. Its date is a cross-check, not a service-classification finding. |
| BOSE Amendment Determination2024, F2024L00590 | Minister Michelle Rowland; registered30May2024 | 31May2024 | Adds express generative-AI expectations. This is a different legal mechanism from the mandatory standard, and an earlier clock. |
| Criminal Code Amendment (Deepfake Sexual Material) Act2024, C2024A00078 | Assent and registration2September2024 | 3September2024 | Criminal transmission offences covering altered/created sexual depictions; not a January service-approval regime. |
Both standards' section2 says commencement is six months after the later of the day after registration under the Online Safety Act and the day after registration under the Legislation Act. Original covers/footers establish Federal Register registration; eSafety's published guidance expressly confirms the resulting22December date. The contemporary21June announcement says both were registered that day and would come into force six months after registration, following the disallowance period. The22December date therefore comes from the regulator's explicit account as well as the statutory formula, not an assumption that all registration events must be identical.
Sources: [DIS original](http[local research file] [RES original](http[local research file] covers and PDF5/printed1, sections1–5; [eSafety21June2024 announcement](http[local research file] article body, reader lines212–237; [eSafety regulatory-guidance index](http[local research file] Online Safety Codes and Standards and Basic Online Safety Expectations sections (current page, last-updated26May2026).
Section3 identifies section145 of the Online Safety Act2021 as authority. Section5 applies wherever a designated service is supplied from, only insofar as it serves end-users in Australia, and provides a predominant-purpose exception where another applicable code or standard better aligns with the service. The high-impact generative-AI definition in section6 turns on machine-learning generation capacity and synthetic high-impact material; it excludes a service with controls rendering that risk immaterial. For that category, high-impact material uses X18+/RC film or game and Category2-restricted/RC publication classifications. This is a category trigger, not a finding that every generated adult image breaches the standard. Section4's protective object and the actual duties concern Class1A/1B material. Those classes include child sexual exploitation/pro-terror/extreme crime-and-violence material and specified other crime/violence/drug material. (Original PDF5–7 and12/printed1–3,8.)
The June announcement specifically says the standards may cover apps generating pornography or nudifying images without effective controls preventing their application to children. That sentence supplies the concrete service-type connection to the operator's description. It still does not classify or clear any named service.
For a covered high-impact generative-AI DIS, section22(3) requires preventive systems for child-sexual-exploitation/pro-terror outputs; regular model testing/review and prompt mitigation adjustments; differentiation of AI outputs; warnings for Australian users specifically seeking child-abuse images; report/support information for relevant generation terms; and automated detection/action on child-abuse material in training data, prompts and outputs. The notes acknowledge limited model visibility/control and require reliance on available alternatives in those circumstances. PDF33–34/printed29–30, visually checked.
The instrument also requires contractual provisions governing Class1A/1B use and giving suspension, restriction, termination or material-removal rights for child-exploitation/pro-terror misuse, plus appropriate enforcement in the circumstances specified by section13. Section19 requires management, supervision, internal reporting and sufficient skilled personnel. Section20 requires appropriate known-CSAM detection/removal, with express technical/practicability and encryption/systemic-weakness exceptions and alternative-action duties; it does not displace section22. These are scoped readings of sections13(2),13(5),19 and20, not a claim to have audited every applicable clause. Locators: PDF24–25/printed20–21; PDF30–31/printed26–27.
Two timing qualifications matter. Section7's ordinary first risk-assessment deadline can be six months after commencement, but section7(6)(f) expressly exempts high-impact generative-AI DIS from subsections(1) and(4), with a material-change qualification in the following page's note. Do not mechanically assign that initial assessment deadline to every AI service. Section36(3) prevents a compliance-report request under that particular section before the first anniversary of commencement, and permits no more than one in12months; subsection(5) gives two months to respond. Those limits do not mean the standard's substantive duties wait a year or that all other reporting powers are unavailable. Section38 requires compliance-action records to be kept for at least two years after the relevant calendar year's end. PDF17–18,44–46/printed13–14,40–42.
None of these readings establishes a general eSafety certification of an operator's entire business, immunity under other laws, or satisfaction of the duties in practice.
The [BOSE amendment](http[local research file] section2 commenced the day after30May registration, hence31May2024. Schedule1 item7 inserts section8A: reasonable steps for end-user safety in design, implementation and maintenance of generative-AI capabilities, and proactively minimising their use for unlawful/harmful material or activity. Examples concern lifecycle risk assessment, training data and harmful prompts. Original PDF3,5–6/printed1,3–4. The expectation is broader in subject matter than the DIS harmful-material classes, but its enforcement form must be distinguished: Online Safety Act section45(4) says a determination under that section does not itself impose a duty enforceable by court proceedings. Part4 separately supplies reporting mechanisms. [Act compilation in force11December2024](http[local research file] sections44–45, scoped reader only.
The current eSafety guidance index dates the BOSE guidance's January2025 revision to the replacement of AAT by ART. A guidance revision date must not be relabelled legislative commencement. The available record does not establish that the respondent meant this update, or knew of it before the email.
The [Deepfake Sexual Material Act](http[local research file] is another genuine2024 AI-adjacent change, but its section2 is explicit:3September2024. New Criminal Code section474.17A concerns using a carriage service to transmit specified sexual material of a person who is or appears18+, with knowledge of lack of consent or recklessness about consent. Altered or wholly technologically created depictions count; transmit includes making available, publication, distribution, advertising and promotion. There are specified exceptions. The creation/alteration aggravated offence under474.17AA(5) also requires the underlying transmission offence. This is not a blanket criminalisation of every act of making an image, and not a prospective eSafety approval system. Schedule1 item7 applies the amendments to material transmitted after commencement irrespective of when created/altered. PDF5–10,13/printed1–6,9.
Four official original PDFs were obtained by ordinary public GET and preserved, with acquisition timestamps, finalURLs, bytes and SHA256 in legal-captures.json. Complete text extracts were generated for retrieval, but generation is not full-document reading. DIS read scope: original title, sections1–5, selected section6 definitions, section7, selected section8/9 material, sections10–12 table/overlap rules, selected13/14 clauses,19–20,22–23 thresholds,36–38; substantive pages were inspected through retained extraction and the public reader. Visual checks were PDF1,5,33,34. RES scope: cover and sections1–5 only; visualPDF5. BOSE: all8pages extracted text read; visualPDF3. Deepfake Act: PDF5–10,13 text; visualPDF6. Other rendered pages are not claimed as visual reads.
DIS SHA256 afe30304b7094509de84a1845534b346a48c4fc2f2f07e163fd47fd040ce487d; RES75d2ce8834e804815dad8b72102bd61d4a2ec757b3edd336be541bfee0f3b8b9; BOSE39171722f9c258fa07d9e69324f781c0de000b358defc159fb492b2dfe5eae3a; Deepfake Act1ab54fc6a743c991d2db80aee8897206b10000933649364b77d53d6a40a60e1d.
The June eSafety announcement and current guidance-index ordinary GETs timed out. Their public web-reader/indexed-primary passages were available and read; no original-HTML hash is asserted, and no transport retry was pursued. Act45 was a scoped public-reader read, not a retained original. This lane made no service-specific query or target-service visit. No January2025 commencement matching the asserted AI regime was located in this bounded pass; this is not an exhaustive negative over all Australian instruments.
Carver's separate service-specific lane has identified official ClothOff correspondence in FOILog141/request25202 that expressly invokes the22December2024 DIS commencement. That is a useful separately sourced counterpart for the clock; this lane has not independently reread that bundle and does not join ClothOff to Drawnudes or promote a request for further information into compliance confirmation.
The next discriminator is the actual eSafety-to-respondent correspondence: dated requirement list, named legal basis/service classification, evidence supplied in reply, and exact wording/scope of any acknowledgement or assessment. Likely custodians are eSafety's relevant industry-standards/compliance team and the operator; there is no outreach in this run. The forest implication is a credible sector-wide compliance mechanism with an unresolved operator-specific assertion, rather than proof of a January AI licensing regime or regulator-to-regulator coordination. Acquisition stops here for root's combined review.