The Australian Labor party has introduced an exposure draft of the Online Safety Amendment (Digital Duty of Care) Bill 2026 (Digital Duty of Care Bill/Draft Bill) for “consultation”. The Digital Duty of Care Bill proposes to make a number of minor (and major) amendments to the Online Safety Act 2021(Cth) (Online Safety Act) and adds an entire Schedule 2 relating to the “digital duty of care”. As the Digital Duty of Care Bill remains an exposure draft, its final form may change following consultation, and no explanatory memorandum or other guidance is available regarding how its will apply in practice. View the exposure draft and consultation details here for updates.
Overview of the Digital Duty of Care Bill
The proposed Digital Duty of Care Bill would place greater responsibility on online service providers to identify and address risks arising from the design and operation of their services. For directors and business owners, the reforms raise questions about compliance, governance and responsibility for services delivered through external providers.
What are the major parts that will be repealed or replaced?
| Provision of the Draft Bill | Proposed change |
| Schedule 2, item 7 | Replace Part 2 of the Online Safety Act with a new Part 2 containing the digital duty of care, definitions, risk assessment requirements and supporting provisions. |
| Schedule 2, items 5 and 12 | Repeal the definition of “basic online safety expectations” and Part 4, which establishes the Basic Online Safety Expectations framework. |
| Schedule 3, item 5 | Repeal Division 7 of Part 9, which establishes the online content scheme’s industry codes and standards framework. Other Schedule 3 items remove related provisions and references. |
Once enacted online businesses will need to “assess compliance against the new statutory duty” instead of relying on compliance with existing standards and codes. Existing compliance processes will likely remain useful but will need to be checked against the new requirements.
Who does the new Digital Duty of Care apply to?
Proposed section 25A covers internet carriage, social media, electronic communications, designated internet services, hosting, search engines, app distribution and specified equipment-related services. It also expressly includes services allowing users to generate material using AI and share it through specified online services.
Websites, apps and online games can fall within these categories. Coverage depends on the statutory definitions and the service’s functions and its ‘predominant purpose’.
The Digital Duty of Care applies to providers and anyone in a position to exercise day-to-day control of a service.
The Draft Bill does not contain a general exemption based on small-business status or turnover. Proposed section 25A(3) permits ministerial exemptions for services posing little risk or used minimally in Australia. An exemption would require an instrument. it is not automatic.
What will the digital duty of care require?
Proposed section 26 states:
“(1) A person responsible for an online service must ensure, so far as is reasonably practicable, a safe online environment.
(2) This requirement is the person’s digital duty of care.”
[Bold is our emphasis].
Section 26(3) also requires appropriate management of design features, requires user-empowerment tools, risk assessments and effective measures to address “identified risks”.
Under section 25H, practicability depends on the likelihood and severity of harm, knowledge of the risks, available controls, costs and privacy impacts. Section 26(7) excludes action concerning lawful communications occurring privately and solely between consenting adults.
Proposed section 25B – A safe online environment
Item 7 of Schedule 2 proposes to insert section 25B into the Online Safety Ac which defines “safe online environment” as:
“(1) A safe online environment is an online environment in which:
(a) persons in Australia are protected from seriously harmful material and conduct; and
(b) children in Australia are protected from:
(i) material and conduct that is harmful to children; and
(ii) harms associated with the operation of design features of online services; and
(c) if the service concerned is a social media service—design features of the service that have negative behavioural impacts do not operate for children in Australia who have not reached 16 years of age.”
[Bold is our emphasis].
Sections 25C–25G define the relevant harms and features. The design provisions cover matters including personalised recommendations, endless feeds and engagement feedback. For social media services, section 25B(1)(c) specifically addresses the operation of certain features for children under sixteen (16), with proposed section 25G identifying the features taken to have negative behavioural impacts. Businesses would need to assess whether their features fall within those statutory definitions and what changes are required to meet the duty.
Proposed sections 25B(2)–(3) would also allow the Minister to determine, by legislative instrument, whether an online service is a social media service for the purposes of section 25B. That determination would not otherwise change the Online Safety Act’s definition of a social media service.
Proposed section 25C – Seriously harmful material and conduct
Proposed section 25C defines the terms material and conduct under section 25B(1)(a).
The definition includes child sexual exploitation and abuse material; grooming; material encouraging sexual violence, extreme violence or cruelty; explicit threats of physical violence; serious harassment; material encouraging suicide or self-harm; specified terrorism-related material; and material encouraging criminal offences or illicit drug use.
The list could be expanded under proposed section 25C(2), which provides:
“(2) For the purposes of paragraph (1)(m), the Minister may, by legislative instrument, determine material or conduct, or a combination of material and conduct, that the Minister is satisfied may cause serious harm.”
For businesses, this would require an assessment of how their service could expose people to the material listed in section 25B(1)(a) or facilitate the listed conduct. Depending on the service, that assessment could cover uploaded content, public comments, messaging and recommendations. The relevant protections would apply to adults as well as children.
Proposed section 25D – Harmful to children
Proposed section 25D provides, in full:
“(1) The following material and conduct is harmful to children:
(a) pornography;
(b) material or conduct that encourages, promotes or provides instruction for disordered eating;
(c) material or conduct that encourages or promotes hostile attitudes towards women or gender equality;
(d) material or conduct that glorifies crime or encourages dangerous stunts or harmful practices;
(e) abuse, harassment or bullying;
(f) any other material or conduct, or combination of material and conduct:
(i) that could inflict serious harm to a child; or
(ii) that is determined under subsection (2).
(2) For the purposes of subparagraph (1)(f)(ii), the Minister may, by legislative instrument, determine material or conduct, or a combination of material and conduct, that the Minister is satisfied may cause harm to children.”
This provision would extend the child-protection component of the duty beyond material that is unlawful. Pornography, for example, is expressly included even where the particular material may lawfully be accessed by adults.
A covered adult-content platform would therefore need to assess whether children could access pornography through its website, previews, recommendations or other features, and implement reasonably practicable protections. The provision does not itself prescribe a particular age-verification technology.
The definition also extends beyond sexual content. Platforms carrying user posts, videos or comments would need to assess exposure to the other listed categories, including bullying and content encouraging dangerous stunts.
Section 25D(1)(f)(i) is a catch-all provision: material or conduct could fall within the definition because it could inflict serious harm on a child, without first being separately prescribed by the Minister.
Subsection 25D(2) would additionally allow the Minister to specify further material or conduct by legislative instrument. Businesses would therefore need to review both the statutory categories and any subsequent instruments when assessing their obligations.
What records would providers need to keep to ensure compliance?
Proposed section 26A requires a written risk assessment identifying reasonably foreseeable risks, affected people and the content, design features and systems creating those risks. It must record the measures implemented or proposed, their expected effectiveness and arrangements for review.
Assessments must be:
- conducted at least annually, or more frequently if prescribed;
- conducted before service changes that could introduce new or additional risks;
- retained for at least six (6) years; and
- provided to the Commissioner within thirty (30) days of a request.
Practically, providers would need to add risk assessment to product-change approvals and maintain accessible compliance records. Contracts with developers and other suppliers may also provide the information necessary to complete those tasks.
Which requirements would depend on later decisions?
The Draft Bill authorises the Minister to make delegated legislation including in relation to:
- User controls: section 26(4) permits the Minister to prescribe tools for specified services. The detailed feed-choice requirements associated with “My Feed, My Way” are not set out in the draft itself.
- Complaints: section 26F allows the eSafety Commissioner to prescribe service classes and complaint-process requirements.
- Reporting: proposed Part 13 permits transparency-report notices and requirements to publish specified safety information.
- Research data: proposed Part 14 allows rules requiring access to data for approved research.
- Australian contact: section 229A permits notices or determinations requiring a locally resident contact.
Businesses would need to monitor applicable instruments and notices. These provisions do not mean every business must immediately provide every form of report, tool or data access.
Other changes to removal notices
Schedule 1 would reduce certain existing removal-notice compliance periods from forty-eight (48) to twenty-four (24) hours and expand search-link deletion powers. It also inserts Part 6A, allowing notices to app distributors and search engines concerning apps or websites predominantly designed or used to generate fake-nude or deep-faked material.
Affected businesses would need processes for promptly identifying, escalating and implementing notices, including outside ordinary office hours where necessary.
Penalties and commencement
Proposed sections 26B and 26D specify 60,000 penalty units for breach of the duty or a remedial direction. At $364 per unit, this is $21.84 million for an individual and, applying the corporate multiplier, $109.2 million for a corporation. These are maximum civil penalties.
The Draft Bill provides for Schedule 1 to commence the day after Royal Assent. Schedules 2 and 3 would commence after a twelve (12) month period following Royal Assent. The proposed repeal does not excuse current non-compliance.
For directors, the immediate tasks are identifying covered services, allocating compliance responsibility and checking that the business can assess risks, obtain supplier information and respond to regulatory notices.
How Dundas Lawyers can help your business prepare
Directors and business owners should consider reviewing their online services, internal responsibilities, safety procedures and supplier contracts before the proposed regime commences.
We can assist with:
- assessing whether your business and its services may be covered;
- advising on directors’ responsibilities and governance arrangements;
- reviewing risk assessment processes, terms of use and complaints procedures;
- drafting or reviewing agreements with developers, hosts and other providers; and
- responding to online safety complaints and regulatory correspondence.
Links and further references
Legislation
Online Safety Act 2021 (Cth)
Online Safety Amendment (Digital Duty of Care) Bill 2026 (Cth) — exposure draft
Further information
If you need advice about your business’s online safety obligations, contact us for a confidential and obligation‑free discussion.

Malcolm Burrows B.Bus.,MBA.,LL.B.,LL.M.,MQLS.
Legal Practice Director
T: +61 7 3221 0013 (preferred)
M: +61 419 726 535
E: mburrows@dundaslawyers.com.au

Related insights
-

Digital Duty of Care Bill 2026
The Australian Labor party has introduced an exposure draft of the Online Safety Amendment (Digital Duty of Care) Bill 2026 (Digital Duty of Care Bill/Draft Bill) for “consultation”. The Digital Duty of Care Bill proposes to make a number of minor (and major) amendments to the Online Safety Act 2021(Cth) (Online Safety Act) and adds…
-

AI compliance programs: one size does not fit all
Australia does not have any standalone legislation addressing how businesses can safely implement Artificial Intelligence (AI). Use of AI by Australian businesses is, however, regulated, not by a patchwork combination of Federal and State legislation, industry-specific legislation and standards, professional body rules and guidance issued by government departments and other regulators. This article discusses the…
-

AI evidence misleading Court: Ba v Sterling Parts Australia
On 17 June 2026, Symons J delivered judgment in the case of Ba v Sterling Parts Australia Pty Ltd [2026] FedCFamC2G 1245 (Ba v Sterling Parts). Ba v Sterling Parts was a proceeding brought by Weiman Ba (Applicant) in the second division of the Federal Circuit and Family Court of Australia (Court). Symons J dismissed…
-

Office of AI announced by Federal Government
On 15 July 2026, Prime Minister Anthony Albanese (Prime Minister) announced by media release an expansion of the Federal Government’s (Government) existing artificial intelligence (AI) governance framework, including the establishment of a new Office of AI as well as plans to legislate national standards governing large-scale data centres, AI training and the use of Australian…
-

AI businesses should have duty of care
In a recent interview with InnovationAus.com, Victorian Senator Michelle Ananda-Rajah (Senator) emphasised the need to adopt digital duty of care laws for artificial intelligence (AI) companies.[1] As a representative of the ALP and former AI start-up founder, the Senator calls for the proposed digital duty of care to apply to AI companies. If implemented, the…
-

Federal Court orders winding up of crypto mining investment scheme
The Federal Court of Australia delivered judgment in Australian Securities and Investments Commission v NGS Crypto Pty Ltd (No 5) [2025] FCA 1611, on 18 December 2025 ordering the winding up of two (2) cryptocurrency related entities after finding that they operated an unlicensed financial services business and an unregistered managed investment scheme in contravention…
-

Online Safety – is your online business a DIS or a RES?
Whether your online business has to comply with the obligations contained in the Online Safety Act 2021 (Cth) (OSA), and related standards and industry codes will largely depend on how your business is classified because of the functionality it provides to end users in Australia.
-

Bill to allow victims of AI deepfakes to sue for emotional damages
On 24 November 2025, Senator David Pocock introduced a private Senator’s bill, the Online Safety and Other Legislation Amendment (My Face, My Rights) Bill 2025 (Cth) (Bill) to amend the Online Safety Act 2021 (Cth) (Online Safety Act) and the Privacy Act 1988 (Cth) (Privacy Act).
-

Malcolm Burrows on ABC’s “Legal Eagles” segment – Deepfakes
On 3 December 2025, Malcolm Burrows appeared live on Katherine Feeney’s ABC Radio program, “Legal Eagles” as the Technology and Intellectual Property Lawyer to discuss the proposed amendments to the Online Safety Act 2021 (Cth) through the introduction of the Online Safety and other legislation Amendment (My Face Rights) Bill (Cth) 2025 (My Face Rights…
Recent cases Digital Duty of Care Bill 2026
-
Australian Securities and Investments Commission v FIIG Securities Limited [2026] FCA 92
CORPORATIONS – Financial services licence – ASIC sought declaration under s 1317E(1) of the Corporations Act 2001 (Cth) (Corporations Act) in respect of admitted contraventions of s 912A of the Corporations Act – ASIC sought orders imposing a pecuniary penalty in an agreed sum – where defendant was subject to a cyber attack as a…
-
Universal City Studios LLC v Telstra Limited (No 2) [2025] FCA 1485
COPYRIGHT – application for orders disabling access to new means of access to certain target online locations (Additional Urgent Access Means) – where site blocking and ancillary orders previously made with respect to target online locations under s 115A of the Copyright Act 1968 (Cth) – where target online locations subsequently made available through different…
-
Anthony v Apple Inc [2025] FCA 902
COMPETITION LAW — representative proceeding against Apple by developers and users — representative proceeding against Google by developers and users — group members’ claims for overcharge — digital technology — Apple mobile devices — Android mobile devices — operating system software — smart phones — tablets — personal computers — native apps — web apps…




