Digital Duty of Care Model for Online Safety

Announcement date
8 September 2026

Link to announcement 
https://minister.infrastructure.gov.au/wells/media-release/my-feed-my-way

Problem being addressed
The Report of the Statutory Review of the Online Safety Act 2021 (the Review) found that Australians continue to face significant and emerging harms in their interactions with the online environment, alongside strong community expectations that government take action to keep people safe online.

While Australia’s online safety framework was world‑leading when first introduced in 2015 and strengthened through the Online Safety Act 2021 (the Act), the Review concluded that it has not kept pace with rapid changes in the online ecosystem. In particular, the Review found that the current regulatory approach — focused on the removal of harmful material and setting expectations through unenforceable Basic Online Safety Expectations and enforceable industry codes and standards — has delivered important protections but is no longer sufficient to address the scale and complexity of online harms.

The Review noted that comparable jurisdictions, including the United Kingdom and the European Union, have moved to a systems‑based regulatory model that places responsibility on online services to proactively manage risks to user safety. The Review concluded that this approach is the only way to achieve meaningful and sustained improvements in online safety, and recommended Australia adopt an overarching duty of care, supported by due diligence obligations, requiring services to prevent foreseeable harms arising from their products and services.

The Review further found that a duty of care would provide a more effective mechanism to address a growing range of harms not explicitly captured under the Act. This includes address risks associated with service design features such as algorithms and recommender systems that can amplify harmful content, as well as AI‑enabled technologies, including those used to create deepfakes.

The Review concluded that a duty‑based, technologically neutral framework would better future‑proof the Act against rapid technological change, which is likely to continue to outpace ad hoc legislative reform. The Review also noted that a systems‑based duty of care would help counteract the commercial incentives of online services to maximise user engagement and monetisation — such as through addictive design features, harmful algorithms and the promotion of extreme content — by creating a regulatory incentive to prioritise user safety where market forces alone do not.

Proposal 
The Impact Analysis Equivalent considers the implementation of a number of recommendations from the review of the Act, including:

  • adopting a singular and overarching duty of care that encompasses due diligence, and is underpinned by safety-by-design principles, risk assessment, risk mitigation and measurement
  • reporting and transparency obligations for high-risk services
  • code making powers to support compliance with a duty of care
  • ad-hoc audit requirements on certain services regarding their compliance with a duty of care
  • requiring services to have an internal dispute resolution process
  • new removal notice powers for eSafety to require online services to remove specific ‘nudification’ apps and websites 
  • enhancing the operation of existing complaints and content removal schemes to ensure there is an effective safety net when people do experience online harms 
  • stronger monitoring, investigation and evidence gathering powers for the regulator.

The Review identified several benefits to these recommended reforms:

  • shifting the focus of the Act from reacting to harms to preventing them, and from removing pieces of online content to requiring service providers to incorporate risk management into the design and operation of services, to create a substantial uplift in online safety for Australians
  • shifting the burden of online safety from individual users to service providers, and making providers more responsive to those who have experienced harms online
  • improving eSafety’s ability to help people who have experienced harms online and capacity to monitor, investigate and enforce compliance
  • moving beyond a burdensome and complicated co-regulatory code-making framework without creating safe harbours for platforms 
  • combatting the widespread availability of online services facilitating exploitation and abuse, such as location tracking technology and AI tools capable of producing  deepfake intimate images and child sexual abuse material. 

Potential costs of these reforms to Australian businesses are captured in the regulatory burden estimate below. The costs include: labour and legal costs involved in studying the new legislation and determining compliance steps; developing internal systems and processes for compliance; and responding to transparency reporting notices as required. 

The Review suggested for compliance requirements on online services to be proportionate, being calibrated to both their reach (user numbers) and risk (based on factors including functions or features, likelihood of access by children, and ability to enable illegal or harmful content and activity). The Review noted that introducing a duty of care would create greater alignment with major overseas online safety regimes, simplifying compliance, reducing costs and regulatory burden for online services operating internationally. 

The Department of Infrastructure, Transport, Regional Development, Communications, Sport and the Arts (DITRDCSA) noted that the potential unintended consequences that could arise from the application of a digital duty of care, not specifically identified in the Review report, may include:

  • Small or low risk online services may feel that they must comply with a duty of care when they consider they are not currently regulated by existing provisions of the Online Safety Act. This risk will be mitigated through careful industry engagement by the regulator in advance of the duty of care being implemented, calibrating obligations and compliance planning based on risk of harm to Australian users and producing clear regulatory guidance. In the longer term, concessions or exemptions may also be considered for very low risk services where there is specific evidence that such concessions are warranted. 
  • Online services, including those that would be considered low risk, may take a more risk-averse approach to harm prevention than intended, for example by employing more stringent content moderation. This risk will be mitigated by providing appropriate guidance to services to ensure their risk assessment obligations align with community expectations.
  • Online services may be concerned about duplication of compliance actions under industry codes and standards with those under the duty of care. It is intended that the duty eventually replace existing codes and standards after a period of transition designed to minimise, as far as practical, unnecessary industry compliance burdens. The transition to a duty of care will include ample notice and clear signposting of the timing for each stage. 

DITRDCSA also noted that unintended consequences from the other proposed reforms outlined above may include:

  • Changes to wait times for actioning complaints under the Act’s complaints schemes may initially intensify eSafety’s workload, however it is anticipated this will be countered by the requirement for services to establish or improve their internal complaints handling mechanisms, and by harm prevention obligations under a duty of care.

Assessed Impact Analysis outcome
Impact Analysis Equivalent

Assessment comments
The Office of Impact Analysis (OIA) does not assess the quality of reviews and documents used in lieu of an Impact Analysis (IA). Impact Analysis Equivalents (IAE) are assessed by OIA for relevance to the recommended options and for the coverage of the seven Impact Analysis questions. 

This IAE was prepared under the former Australian Government Impact Analysis Framework that was in effect up until 30 June 2026. For this IAE, the OIA assessed that the options analysed in the Review to be sufficiently relevant to the proposal.

Regulatory burden
The DITRDCSA estimates the changes will increase average regulatory costs for Australian businesses by $1.408 million per year, over ten years.