What the draft removes

The exposure draft of the Online Safety Amendment (Digital Duty of Care) Bill 2026 runs to 75 pages and three schedules. Schedule 1 is the part the release led on: notices requiring app stores and search engines to remove apps and websites designed for, or predominantly used for, generating fake nude material, and 24-hour deadlines in place of 48 for the cyber-bullying and cyber-abuse schemes. Schedules 2 and 3 are the structural change, and both commence on the day after the end of the 12 months beginning on Royal Assent.

Schedule 3 is titled Repeal of online content scheme industry codes and standards. Its item 5 reads, in full, Repeal the Division, and the Division is Division 7 of Part 9 of the Online Safety Act 2021, headed Industry codes and industry standards. That Division is sections 132 to 150: the power for industry to write codes, the Commissioner’s power in section 145 to determine a standard instead, and the duties in sections 143 and 146 to comply with them. Schedule 2, item 12, does the same to Part 4 of the Act, the basic online safety expectations, in three words: Repeal the Part.

Here is what sits on those two foundations today.

Instruments made under the provisions the draft repeals, and what they say about AI
InstrumentMade underWhat it says about generative AI
Designated Internet Services (Class 1A and 1B) Industry Standard 2024, in effect 22 December 2024s 145, Division 7 of Part 9Defines a high impact generative AI DIS. Section 22(3) requires its provider to regularly review and test models for misuse to generate child sexual exploitation or pro-terror material, adjust them after testing, and implement systems, processes and technologies that differentiate AI outputs generated by the model
Designated Internet Services Online Safety Code (Class 1C and Class 2), Schedule 6, effect beginning 9 March 2026Division 7 of Part 9Reuses the high impact generative AI DIS category for age-restricted material, with a note that it would include an AI companion chatbot meeting the definition
Basic Online Safety Expectations Determination 2022, compilation of 31 May 2024s 45, Part 4Section 8A: providers of services that use or enable generative AI will take reasonable steps to proactively minimise its use to produce unlawful or harmful material, with examples including keeping such material out of training material and detecting prompts that generate it

By the eSafety register’s own descriptions, the full set under Division 7 is six unlawful material codes, nine age-restricted material codes and two unlawful material standards. Division 7 is the provision every one of them is made under.

The draft’s transitional provisions are three items. They continue authorisations under section 163(2) and agreements, guidelines and statements under section 27, and switch off the new monitoring and enforcement statement for the financial year it starts in. None mentions a code, a standard or the expectations, and Schedule 3 has no transitional part at all. The phrase industry codes appears in the draft only in Schedule 3’s title and page headers.

What goes in their place

The replacement is section 26. A person responsible for an online service must ensure, so far as is reasonably practicable, a safe online environment. That means protecting people in Australia from a list of seriously harmful material and conduct; protecting children from material harmful to them and from harms associated with the operation of design features; and, for social media, keeping design features with negative behavioural impacts away from under-16s. To comply, the provider must manage design features, conduct a written risk assessment at least annually and before any change that could add risk, and take effective measures to address it. Breach carries 60,000 penalty units; the Prime Minister’s release says failure to comply could attract penalties of up to $109.2 million.

The duty is wider than the instruments it replaces. The DIS standard covers class 1A and 1B material, which is child sexual exploitation, pro-terror material and the like. The new duty adds, for children, disordered eating content, content promoting hostile attitudes towards women or gender equality, pornography, bullying and design features such as endless feeds. The release says digital services like online games, apps and AI chatbots will be required to protect under-18s from those harms and features.

It is also less specific. Nothing in section 26 or the risk assessment provision in section 26A tells a generative AI provider to test its model or mark its outputs. The detail is delegated: the Commissioner may determine additional requirements for risk assessments, including standards, benchmarks or other metrics, and may publish guidelines. Whether the model testing and output differentiation duties come back depends on what eSafety writes under those powers. The draft does not say.

Where the words “artificial intelligence” appear

The current compilation of the Online Safety Act, dated 12 September 2026, does not contain the words artificial intelligence, generative, chatbot or machine learning. We explained in August why it binds AI services anyway: a generative AI service is a designated internet service by default. The draft uses artificial intelligence twice, and chatbot and generative not at all.

The first is a new kind of online service, section 25A(1)(j): a service that allows users to generate material by means of artificial intelligence and share it by means of one of the listed services, such as social media or messaging. The test has two limbs, so on its words a tool that generates but does not let users share through one of those services is not caught by this paragraph. It would be caught, if at all, as a designated internet service, the same route as today. The second is in section 205K(2), which lets the Commissioner, using a sock puppet identity, generate material including by means of artificial intelligence to test a service, so long as producing it is not an offence.

Signs the draft is unfinished

It is an exposure draft and reads like one. Six of its seven simplified outlines say to be drafted. Schedule 2 raises the penalty for breaching a code direction under section 143(2) and a standard under section 146(1) to 60,000 penalty units, and Schedule 3 repeals both sections on the same commencement day. Section 25G lists a feedback feed feature where section 25F defines a feedback feature. None of that changes what the draft would do; it is a reason to read the introduced bill again rather than assume this text survives.

The department published the draft, in PDF and Word, on 8 September with feedback by email by noon on 22 September, no more than five pages, and says it will not publish individual comments, though a summary of all feedback received may be published. As at 6 October the publication page listed only the draft itself, with no explanatory material, and a ParlInfo title search for duty of care bills returned the 2024 private member’s bill and no 2026 government bill. The release says legislation is to be introduced to Parliament this year.

Our view

The trade is defensible, and it should be made openly. The DIS standard is narrow: it deals with the worst illegal material and nothing else, and a duty that also reaches design features and children’s exposure to harmful content covers far more of what people worry about with chatbots. But the standard is also the one place where Australian law tells an AI developer to do specific things to its model, and the draft repeals it without a sentence saying whether those things are meant to continue. A provider that meets the duty by running a sound risk assessment could stop marking its outputs, and nothing in the Act as drafted would require it to continue. If output differentiation and model testing are still government policy, the bill should say so, in the Act or in a transitional item, rather than leave it to instruments that do not exist yet. Readers who made submissions by 22 September may already have said this; under the department’s rules, we cannot read them.

Sources

  1. Exposure Draft, Online Safety Amendment (Digital Duty of Care) Bill 2026, Department of Infrastructure, Transport, Regional Development, Communications, Sport and the Arts, dated 08/09/2026, 75 pages (PDF downloaded and read in full 6 October 2026): the commencement table; Schedule 1 on fake nude material and 24-hour deadlines; Schedule 2 sections 25A to 25H, 26, 26A, 26B and 26E, item 12 repealing Part 4, items 28 and 29 on the s 143(2) and s 146(1) penalties, section 205K(2), and transitional items 64 to 66; Schedule 3 item 5 repealing Division 7 of Part 9.
  2. Exposure Draft, Online Safety Amendment (Digital Duty of Care) Bill 2026, publication page, infrastructure.gov.au (read 6 October 2026): published 8 September 2026; feedback by email closing 12pm 22 September, no longer than 5 pages; individual comments not published and a summary that may be; the draft in DOCX and PDF the only documents listed.
  3. Prime Minister of Australia, My Feed, My Way, media release, 8 September 2026 (read in full 6 October 2026): AI chatbots among services required to protect under-18s; penalties of up to $109.2 million; legislation to be introduced to Parliament this year.
  4. Online Safety Act 2021, Federal Register of Legislation, compilation C2026C00396, compilation date 12 September 2026 (read 6 October 2026): Part 4 headed Basic online safety expectations; Division 7 of Part 9 headed Industry codes and industry standards, sections 132 to 150 including 143, 145 and 146; and a full-text search returning no occurrence of artificial intelligence, generative, chatbot or machine learning.
  5. Online Safety (Basic Online Safety Expectations) Determination 2022, Federal Register of Legislation, compilation dated 31 May 2024 (read 6 October 2026): section 8A on generative artificial intelligence capabilities.
  6. Register of online industry codes and standards, eSafety Commissioner, last updated 17 June 2026 (read 6 October 2026): unlawful material codes for five industry sections plus an additional search engine code; age-restricted material codes for three and then six industry sections; the two unlawful material standards in effect 22 December 2024.
  7. Online Safety (Designated Internet Services, Class 1A and Class 1B Material) Industry Standard 2024, eSafety Commissioner (PDF, read in full 4 August 2026, section 22(3) re-read 6 October 2026): the definition of a high impact generative AI DIS and the minimum requirements in section 22(3).
  8. Schedule 6, Designated Internet Services Online Safety Code (Class 1C and Class 2 Material), eSafety register (PDF, read in full 4 August 2026, definitions re-read 6 October 2026): the high impact generative AI DIS definition and the AI companion chatbot note.
  9. ParlInfo bills search, title “duty of care”, Parliament of Australia (run 6 October 2026): three results, the Online Safety Amendment (Digital Duty of Care) Bill 2024 and two climate change bills, none a 2026 government bill.

How we checked this. The exposure draft was downloaded from the department’s publication page and read in full; every quotation from it is verbatim. The Act’s Part and Division headings, and the absence of the AI terms, come from the full text of the current compilation as rendered by the Federal Register. We have not formed or stated a view on whether instruments made under a repealed provision lapse as a matter of law; the claim is that the draft repeals the provisions and contains no item continuing the instruments. The ParlInfo absence is about that search on 6 October; a bill introduced since may not yet be indexed. We have not asked the department or eSafety whether the generative AI duties are intended to continue. The “our view” section is opinion based on the documents cited.

Made a submission on the draft, or read Schedule 3 differently? Tell us and we will check it against the document and log the outcome here.