
The Australian Government has released an exposure draft of the Online Safety Amendment (Digital Duty of Care) Bill 2026 (the Exposure Draft), which proposes to significantly overhaul the Australian Online Safety Act 2021 (Cth) (OSA). The Exposure Draft proposes to introduce an overarching digital duty of care (DDC), placing proactive obligations on online services to, so far as is reasonably practicable, maintain a safe online environment.
At a high level, the Exposure Draft sets out that a safe online environment is one in which:
- Australians are protected from seriously harmful material and conduct (which largely encompasses illegal content and activity, such as child exploitation material and terrorism-related content);
- children are protected from material that is harmful to children (such as pornography, material or conduct that encourages disordered eating and online bullying); and
- for social media services, design features with negative behavioural impacts (such as recommender features, logged-in features, endless-feed features, time-limited features and feedback features), do not operate for children under 16.
As part of complying with the DDC, persons responsible for online services would be required to: (i) manage such design features of the service appropriately (including by providing user empowerment tools as required); (ii) conduct risk assessments (in the case of providers of online services) to identify all reasonably foreseeable risks that could be posed by the service; and (iii) take effective measures as necessary to address those assessments.
Failure to comply with the DDC could attract civil penalties of up to A$109.2 million for corporations and the eSafety Commissioner would also have the power to issue formal warnings and remedial directions.
These proposed reforms would complement Australia’s Social Media Minimum Age (SMMA) regime and reform processes that are underway to modernise the National Classification Scheme.
Submissions can be made in relation to the Exposure Draft until 22 September 2026.
Who would be subject to the DDC?
The Exposure Draft provides that persons responsible for an online service will be subject to the DDC. A person responsible for an online service includes not only the provider of the service, but also any person in a position to exercise day-to-day control over it.
Online services are broadly defined in the Exposure Draft to capture various services throughout the online technology stack, including the following (as defined in the OSA):
- internet carriage services;
- social media services;
- relevant electronic services (which includes point to point communication services such as email, instant messaging, MSS, chat and multiplayer online games);
- designated internet services (which is very broad and includes websites, apps and other services that allow end users to access material online, subject to exceptions including for certain BVOD services);
- hosting services;
- internet search engine services;
- app distribution services;
- services that manufacture, supply, maintain or install equipment for use in Australia in connection with social media services, relevant electronic services, designated internet services and internet carriage services; and
- services that allow users to generate material by means of artificial intelligence and share that material by means of a service mentioned in (a) – (g) above.
The proposed “Digital Duty of Care”
The table below sets out at a glance the relevant provisions of the Exposure Draft which make up the proposed DDC:
| Provision of the Exposure Draft | Summary |
|---|---|
| Digital Duty of Care | |
New digital duty of care | A person responsible for an online service must ensure, so far as is reasonably practicable, a safe online environment. To comply with the duty, the person must also manage design features of the service (including by providing user empowerment tools as required), conduct risk assessments and take effective measures to address these assessments. The DDC will not require any action to be taken in relation to lawful communications occurring in private solely between consenting adults. Failure to comply will constitute a breach of the digital duty of care and attract penalties of 60,000 penalty units (A$21.84 million for individuals and A$109.2 million for corporations). |
New definition of a safe online environment | A ‘safe online environment’ is an online environment in which:
|
New definition for design features and further definitions for each feature | A ‘design feature’ of an online service includes:
The above design features are taken to have negative behavioural impacts for the purposes of the DDC. |
New definition for a user empowerment tool and requirements for risk assessments | A ‘user empowerment tool’ allows a user of an online service to manage the way design features operate for the user e.g. providing the user with control over the recommended content. The Minister may, by legislative instrument, require specified online services to provide specified user empowerment tools. To comply with the DDC, the person who provides an online service must conduct risk assessments in accordance with set criteria. This criterion includes assessing the likelihood and potential severity of those risks, documenting the measures that person has implemented to address those risks, extensive reporting requirements and other requirements. |
| New definition for seriously harmful material and conduct | ‘Seriously harmful material and conduct’ broadly encompasses illegal content and activity, including material or conduct relating to:
|
New definition for harmful to children | ‘Harmful to children’ is defined openly, encompassing material or conduct such as:
|
New definition for reasonably practicable | ‘Reasonably practicable’ in relation to a person's digital duty of care requires the consideration and weighing of all relevant matters, including:
|
Commissioner may issue formal warnings or remedial directions | If the person has failed or is failing to comply with the person’s digital duty of care or requirements for complaint and dispute processes for prescribed online services, the Commissioner may issue a formal warning or give the person a written remedial direction. |
| Supporting Provisions for the Digital Duty of Care | |
Digital Duty of Care Guidelines | The eSafety Commissioner may publish guidelines to assist persons responsible for online services to meet their digital duty of care. |
Prescribed online services are required to have compliant complaint and dispute processes | The Commissioner may determine classes of online services as prescribed online services and determine requirements for complaint and dispute processes. A person responsible for a prescribed online service must have complaint and dispute processes that are available equally to all Australians and comply with any requirements determined by the Commissioner. |
Overlap with the BOSE regime and industry codes and standards
As the DDC will incorporate and adapt existing elements of the OSA, the Exposure Draft attempts to address concerns from the online service industry regarding the potential for regulatory overlap within the OSA by proposing to repeal the basic online safety expectations (BOSE) regime contained in Part 4 of the OSA and the industry codes and standards developed under Division 7 of Part 9 of the OSA.
A period of 12 months is proposed between Royal Assent and the commencement of the DDC to enable sufficient time for guidance to be developed and to ensure the online services industry is prepared for this transition.
Other reforms proposed by the Exposure Draft
The Exposure Draft also proposes to make a number of further amendments to the OSA, including:
Increased penalties – Substantially increased penalties for certain SMMA obligation breaches (under sections 63D, 63DA(1) and 63DB(1) of the OSA) and for non-compliance with the industry codes and standards under sections 143(2) and 146(1) the OSA from 30,000 penalty units to 60,000 penalty units (up to A$109.2 million for corporations). It also proposes to increase a number of other penalties throughout the OSA, particularly for infringement notices and non-compliance with removal notices.
Transparency obligations – Formal powers for the eSafety Commissioner to require providers of online services to prepare and give the Commissioner transparency reports detailing matters including the extent to which the provider is complying with the OSA, the effectiveness of measures taken to comply, the nature and extent of harms associated with the provider's service, and the provider's performance against certain benchmarks. The Commissioner would also be able to publish those reports (or summaries of them) on the Commissioner's website. Additionally, the eSafety Commissioner could require providers of online services to publish specified information about their operations and activities relating to the online safety of their Australian users on the provider's website.
Expansion of eSafety Commissioner’s enforcement powers and functions – The Exposure Draft proposes that the eSafety Commissioner would have its powers expanded to issue warnings, require remedial action, compel the production of information, require attendance for examination and pursue civil penalty proceedings.
Fake nude material removal powers – New powers for the eSafety Commissioner to issue removal notices requiring app distribution services and internet search engine services to remove apps or websites that are designed for, or predominantly used to generate, fake nude material, with compliance required within 24 hours.
Updated link deletion notice powers – Expanded link deletion notice powers would also allow the Commissioner to require internet search engine providers to cease providing links to cyber-bullying material targeted at Australian children, intimate images, and cyber-abuse material targeted at Australian adults, with compliance required within 24 hours.
Removal notice compliance changes – The compliance timeframe for existing removal notices (covering cyber-bullying material, intimate images, and cyber-abuse material) would be reduced from 48 hours to 24 hours. The Commissioner would also be able to waive the requirement that a complaint first be made to the service provider where the service lacks a functional or accessible complaints mechanism or where making the complaint would create a reasonably foreseeable risk of further harm. Additionally, the Commissioner could issue a removal notice without a prior complaint where the same material has been reposted within six months of an earlier notice.
Research data access scheme – A new data access sharing scheme for providers of online services to give approved researchers (being persons employed by an Australian university who meet prescribed criteria) access to certain data in certain circumstances for the purposes of online safety related research.
Authorising the use of ‘sock puppet’ identities – Authorisation and a wide immunity for approved researchers and the eSafety Commissioner to use "sock puppet identities" (i.e. fake online accounts) to carry out online safety research and enforcement activities.
Australian points of contact – The Commissioner would also be empowered to require providers of online services to nominate a person ordinarily resident in Australia as a point of contact, with a civil penalty of 1,000 penalty units (or, for corporations, A$1.82 million) for non-compliance.