What the draft removes
The exposure draft of the Online Safety Amendment (Digital Duty of Care) Bill 2026 runs to 75 pages and three schedules. Schedule 1 is the part the release led on: notices requiring app stores and search engines to remove apps and websites designed for, or predominantly used for, generating fake nude material, and 24-hour deadlines in place of 48 for the cyber-bullying and cyber-abuse schemes. Schedules 2 and 3 are the structural change, and both commence on the day after the end of the 12 months beginning on Royal Assent.
Schedule 3 is titled Repeal of online content scheme industry codes and
standards
. Its item 5 reads, in full, Repeal the Division
, and the Division is
Division 7 of Part 9 of the Online Safety Act 2021, headed Industry codes and industry
standards
. That Division is sections 132 to 150: the power for industry to write codes,
the Commissioner’s power in section 145 to determine a standard instead, and the
duties in sections 143 and 146 to comply with them. Schedule 2, item 12, does the same to
Part 4 of the Act, the basic online safety expectations, in three words: Repeal the
Part
.
Here is what sits on those two foundations today.
| Instrument | Made under | What it says about generative AI |
|---|---|---|
| Designated Internet Services (Class 1A and 1B) Industry Standard 2024, in effect 22 December 2024 | s 145, Division 7 of Part 9 | Defines a high impact generative AI DIS. Section 22(3) requires its provider to regularly review and test modelsfor misuse to generate child sexual exploitation or pro-terror material, adjust them after testing, and implement systems, processes and technologies that differentiate AI outputs generated by the model |
| Designated Internet Services Online Safety Code (Class 1C and Class 2), Schedule 6, effect beginning 9 March 2026 | Division 7 of Part 9 | Reuses the high impact generative AI DIS category for age-restricted material, with a note that it would include an AI companion chatbotmeeting the definition |
| Basic Online Safety Expectations Determination 2022, compilation of 31 May 2024 | s 45, Part 4 | Section 8A: providers of services that use or enable generative AI will take reasonable steps to proactively minimiseits use to produce unlawful or harmful material, with examples including keeping such material out of training material and detecting prompts that generate it |
By the eSafety register’s own descriptions, the full set under Division 7 is six unlawful material codes, nine age-restricted material codes and two unlawful material standards. Division 7 is the provision every one of them is made under.
The draft’s transitional provisions are three items. They continue
authorisations under section 163(2) and agreements, guidelines and statements under
section 27, and switch off the new monitoring and enforcement statement for the financial
year it starts in. None mentions a code, a standard or the expectations, and Schedule 3
has no transitional part at all. The phrase industry codes
appears in the draft only
in Schedule 3’s title and page headers.
What goes in their place
The replacement is section 26. A person responsible for an online service must
ensure, so far as is reasonably practicable, a safe online environment
. That means
protecting people in Australia from a list of seriously harmful material and conduct;
protecting children from material harmful to them and from harms associated with the
operation of design features
; and, for social media, keeping design features with
negative behavioural impacts away from under-16s. To comply, the provider must manage
design features, conduct a written risk assessment at least annually and before any change
that could add risk, and take effective measures to address it. Breach carries 60,000
penalty units; the Prime Minister’s release says failure to comply could attract
penalties of up to $109.2 million
.
The duty is wider than the instruments it replaces. The DIS standard covers class 1A and
1B material, which is child sexual exploitation, pro-terror material and the like. The new
duty adds, for children, disordered eating content, content promoting hostile attitudes
towards women or gender equality
, pornography, bullying and design features such as
endless feeds. The release says digital services like online games, apps and AI
chatbots
will be required to protect under-18s from those harms and features.
It is also less specific. Nothing in section 26 or the risk assessment provision in
section 26A tells a generative AI provider to test its model or mark its outputs. The
detail is delegated: the Commissioner may determine additional requirements for risk
assessments, including standards, benchmarks or other metrics
, and may publish
guidelines. Whether the model testing and output differentiation duties come back depends
on what eSafety writes under those powers. The draft does not say.
Where the words “artificial intelligence” appear
The current compilation of the Online Safety Act, dated 12 September 2026, does not
contain the words artificial intelligence, generative, chatbot or machine learning. We
explained in August why it binds AI services
anyway: a generative AI service is a designated internet service by default. The draft
uses artificial intelligence
twice, and chatbot
and generative
not at
all.
The first is a new kind of online service, section 25A(1)(j): a service that allows
users to
generate material by means of artificial intelligence and share it by means
of one of the listed services, such as social media or messaging. The test has two limbs,
so on its words a tool that generates but does not let users share through one of those
services is not caught by this paragraph. It would be caught, if at all, as a designated internet service,
the same route as today. The second is in section 205K(2), which lets the Commissioner,
using a sock puppet identity
, generate material including by means of artificial
intelligence
to test a service, so long as producing it is not an offence.
Signs the draft is unfinished
It is an exposure draft and reads like one. Six of its seven simplified outlines say to be drafted
. Schedule 2 raises the penalty for breaching a code direction under section
143(2) and a standard under section 146(1) to 60,000 penalty units, and Schedule 3 repeals
both sections on the same commencement day. Section 25G lists a feedback feed
feature
where section 25F defines a feedback feature. None of that changes what the
draft would do; it is a reason to read the introduced bill again rather than assume this
text survives.
The department published the draft, in PDF and Word, on 8 September with feedback by
email by noon on 22 September, no more than five pages, and says it will not publish
individual comments, though a summary of all feedback received may be published
.
As at 6 October the publication page listed only the draft itself, with no explanatory
material, and a ParlInfo title search for duty of care bills returned the 2024 private
member’s bill and no 2026 government bill. The release says legislation is to be
introduced to Parliament this year
.
Our view
The trade is defensible, and it should be made openly. The DIS standard is narrow: it deals with the worst illegal material and nothing else, and a duty that also reaches design features and children’s exposure to harmful content covers far more of what people worry about with chatbots. But the standard is also the one place where Australian law tells an AI developer to do specific things to its model, and the draft repeals it without a sentence saying whether those things are meant to continue. A provider that meets the duty by running a sound risk assessment could stop marking its outputs, and nothing in the Act as drafted would require it to continue. If output differentiation and model testing are still government policy, the bill should say so, in the Act or in a transitional item, rather than leave it to instruments that do not exist yet. Readers who made submissions by 22 September may already have said this; under the department’s rules, we cannot read them.
Sources
- Exposure Draft, Online Safety Amendment (Digital Duty of Care) Bill 2026, Department of Infrastructure, Transport, Regional Development, Communications, Sport and the Arts, dated 08/09/2026, 75 pages (PDF downloaded and read in full 6 October 2026): the commencement table; Schedule 1 on fake nude material and 24-hour deadlines; Schedule 2 sections 25A to 25H, 26, 26A, 26B and 26E, item 12 repealing Part 4, items 28 and 29 on the s 143(2) and s 146(1) penalties, section 205K(2), and transitional items 64 to 66; Schedule 3 item 5 repealing Division 7 of Part 9.
- Exposure Draft, Online Safety Amendment (Digital Duty of Care) Bill 2026, publication page, infrastructure.gov.au (read 6 October 2026): published 8 September 2026; feedback by email closing 12pm 22 September, no longer than 5 pages; individual comments not published and a summary that may be; the draft in DOCX and PDF the only documents listed.
- Prime Minister of Australia, My Feed, My Way, media release, 8 September 2026 (read in full 6 October 2026): AI chatbots among services required to protect under-18s; penalties of up to $109.2 million; legislation to be introduced to Parliament this year.
- Online Safety Act 2021, Federal Register of Legislation, compilation C2026C00396, compilation date 12 September 2026 (read 6 October 2026): Part 4 headed Basic online safety expectations; Division 7 of Part 9 headed Industry codes and industry standards, sections 132 to 150 including 143, 145 and 146; and a full-text search returning no occurrence of artificial intelligence, generative, chatbot or machine learning.
- Online Safety (Basic Online Safety Expectations) Determination 2022, Federal Register of Legislation, compilation dated 31 May 2024 (read 6 October 2026): section 8A on generative artificial intelligence capabilities.
- Register of online industry codes and standards, eSafety Commissioner, last updated 17 June 2026 (read 6 October 2026): unlawful material codes for five industry sections plus an additional search engine code; age-restricted material codes for three and then six industry sections; the two unlawful material standards in effect 22 December 2024.
- Online Safety (Designated Internet Services, Class 1A and Class 1B Material) Industry Standard 2024, eSafety Commissioner (PDF, read in full 4 August 2026, section 22(3) re-read 6 October 2026): the definition of a high impact generative AI DIS and the minimum requirements in section 22(3).
- Schedule 6, Designated Internet Services Online Safety Code (Class 1C and Class 2 Material), eSafety register (PDF, read in full 4 August 2026, definitions re-read 6 October 2026): the high impact generative AI DIS definition and the AI companion chatbot note.
- ParlInfo bills search, title “duty of care”, Parliament of Australia (run 6 October 2026): three results, the Online Safety Amendment (Digital Duty of Care) Bill 2024 and two climate change bills, none a 2026 government bill.
How we checked this. The exposure draft was downloaded from the department’s publication page and read in full; every quotation from it is verbatim. The Act’s Part and Division headings, and the absence of the AI terms, come from the full text of the current compilation as rendered by the Federal Register. We have not formed or stated a view on whether instruments made under a repealed provision lapse as a matter of law; the claim is that the draft repeals the provisions and contains no item continuing the instruments. The ParlInfo absence is about that search on 6 October; a bill introduced since may not yet be indexed. We have not asked the department or eSafety whether the generative AI duties are intended to continue. The “our view” section is opinion based on the documents cited.
Made a submission on the draft, or read Schedule 3 differently? Tell us and we will check it against the document and log the outcome here.