The document is Schedule 6 of the Consolidated Industry Codes of Practice for the Online Industry, covering class 1C and class 2 material, which is the age-restricted tier rather than the illegal one. It runs to 36 pages. eSafety's own register records that the schedules covering designated internet services, relevant electronic services, social media messaging features and equipment providers were added to the register on 9 September 2025, and will came into effect beginning on 9 March 2026, the grammatical slip being the register's, not ours. An earlier wave covering internet carriage, hosting and search engines took effect on 27 December 2025.

So this has been law for nearly five months, and it is more directly about generative AI than either instrument that has been getting the attention.

The same category, borrowed for a different tier

It reuses the term from the 2024 standard. A high impact generative AI DIS is a designated internet service that uses machine learning models to enable an end-user to produce material and is capable of being used to generate a generative AI restricted category material, with the same escape hatch: it is not one if it incorporates controls such that the risk of the service being used to generate a generative AI restricted category material is immaterial.

The structure is identical to the 2024 standard. Only the material class changes, from the illegal categories to the age-restricted ones. Build effective controls and you are outside it; ship something that can be driven to produce the restricted categories and you are inside.

It names AI companion chatbots

Attached to that definition is a note that does something Australian instruments rarely do, which is name the application out loud:

A high impact generative AI DIS would include an AI companion chatbot that meets the definition of high impact generative AI DIS.

That is a note rather than an operative clause, and notes explain rather than impose. But it tells you what the drafters had in front of them. Companion chatbots have been the subject of a great deal of Australian commentary about whether anything covers them. This says they are covered, and has said so since March.

Some generative services skip the risk assessment and go straight to the top tier

The code works on risk tiers, and providers normally assess their own. Clause 4.4(b) removes that step for one group. A high impact generative AI DIS that has the sole or predominant purpose of generating material in respect of any of the generative AI restricted categories is not required to undertake a risk assessment in respect of that category of material and will automatically have a Tier 1 risk profile for that material, and must comply with the Tier 1 measures.

Tier 1 is the heaviest set. A service built to generate that material does not get to argue about its risk rating; the instrument assigns it.

What Tier 1 actually requires: age assurance, tested

The measure at the centre of this code is not a content filter. It is a gate. A provider must, where technically feasible and reasonably practicable, implement appropriate age assurance measures and access control measures before providing access to the designated internet service or the relevant high-risk materials. And it does not stop at implementation: the provider must also take appropriate steps to test and monitor the effectiveness of its age assurance and access control measures over time.

Worth noting what the code does not say. The words “age estimation” and “age verification” do not appear in it at all. It says “age assurance” twelve times and leaves the method to the provider, subject to being appropriate, feasible and demonstrably effective. That is a design choice, and a defensible one given how fast the technology is moving, but it means the hard question of what counts as appropriate is answered outside the instrument.

A regulated category for platforms that host uploaded models

The definition we did not expect to find is this one. A model distribution platform is a designated internet service which has a purpose which includes making available machine learning models and allows end-users to upload machine learning models to the service.

That is a description of a model hub, and it comes with its own measures table rather than being folded into the generative category. The code is also explicit that the models are part of the service: a note records that models made available on the service, including those uploaded to it, are components of the service, while material generated using those models but not stored on or accessible through the service is not.

So Australian online safety law already contains a category for the platform layer of the open-model ecosystem, drawing the line at what the platform hosts rather than at what people do with what they download.

It answers the question our last piece had to leave open

An hour ago we wrote that neither 2024 standard mentions the other's service class, so nothing in either instrument says what happens when a service is more than one thing. This code does say. Where a service meets more than one definition, for instance a high impact class 2 DIS that is also a high impact generative AI DIS, the service is taken to be a service of each of those kinds.

Both sets of obligations attach. That is the answer for the codes; it is not necessarily the answer for the 2024 standards, which are separate instruments and still silent.

Our view, labelled as such

The public argument about regulating AI in Australia is still largely about a proposal. Meanwhile there are now three instruments in force that regulate generative systems directly, and the newest and most specific of them is the one nobody cites. It names companion chatbots, it regulates model hosting, and it puts an age gate in front of services whose purpose is generating restricted material.

Our reservation is the same one we would apply to any of this. “Where technically feasible and reasonably practicable” is doing a great deal of load-bearing work in a measure whose whole force depends on it, and the code sets no floor for what an appropriate age assurance measure is. The duty to test and monitor effectiveness is the part with teeth, because it converts a one-off implementation into something a regulator can ask for evidence of. Whether it is being asked for is a separate question, and one we can only answer by looking at enforcement, which we have not done here.

How we sourced this

Schedule 6 was downloaded as a PDF from the eSafety Commissioner and read as extracted text rather than through any summary. Quoted phrases are the code's own words. The word counts are our own from that extracted text and are counts of the literal word. The registration and commencement dates are quoted from eSafety's register of online industry codes and standards, including its grammatical slip, which we have not silently corrected. The code's official title uses an en-dash; we render it as a hyphen for house style, without altering the words.

What we have not done. This is a description of one schedule, not legal advice, and we have assessed no service against it. We read Schedule 6 (designated internet services) in full and have NOT read the other schedules in this code set: hosting, internet carriage, search engines, social media core and messaging features, relevant electronic services, app distribution or equipment. Where we describe the measures tables we do so from the operative clauses that point to them; a summary table near the front of the document extracts with its columns interleaved, so we have not quoted from it. We have not read the head terms, the explanatory materials, or the two directions to comply that eSafety has published with the provider name withheld. We have not sought comment from eSafety or from any provider, and we name no company.

Sources

  1. eSafety Commissioner, Schedule 6 - Designated Internet Services Online Safety Code (Class 1C and Class 2 Material) (PDF, 36 pages, downloaded and read 4 August 2026): the definition of a high impact generative AI DIS and its immateriality carve-out, the note naming AI companion chatbots, the definition of a model distribution platform and the notes on what counts as a component of the service, clause 4.4(b) on automatic Tier 1 for sole-or-predominant-purpose services, the age assurance and access control measures and the duty to test and monitor their effectiveness, and the rule that a service meeting more than one definition is taken to be each kind. Also the absence of the terms “age estimation” and “age verification”.
  2. eSafety Commissioner, Register of Online Industry Codes and Standards (read 4 August 2026): that the designated internet services, relevant electronic services, social media messaging features and equipment schedules were added on 9 September 2025 and take effect from 9 March 2026, and that the earlier wave covering internet carriage, hosting and search engines took effect from 27 December 2025.
  3. AI Geek, Australia already regulates generative AI and the sibling standard that never says it: our readings of the two 2024 class 1A and 1B standards.

Work on a service that could fall inside any of these definitions, or read the code differently? Tell us and we will check it against the text and log the outcome here.