The instruments are short. Each is a notice under subsection 143(1) of the Online Safety Act 2021, signed by the eSafety Commissioner, Julie Inman Grant, directing a provider to comply with the Designated Internet Services Online Safety Code covering class 1C and class 2 material. The provider is withheld in both. Everything else is on the page.

The same category, twice

Each notice states that the provider is a high impact generative AI DIS with a tier 1 risk profile as defined in clauses 3 and 4.4(b) of the DIS Code. That is not incidental wording. It is the category we described a day ago as the code's most AI-specific invention, and the code defines it precisely: a service that uses machine learning models to enable an end-user to produce material and is capable of being used to generate a generative AI restricted category material, with a carve-out for a service that incorporates controls such that the risk of the service being used to generate a generative AI restricted category material is immaterial.

Read that carve-out next to the enforcement and the shape of the thing appears. The category is defined by the absence of adequate controls, and the contravention alleged is the absence of adequate controls. A service that had them would not be in the category to begin with.

The two measures, and why the first one is the interesting one

Both notices cite the identical pair.

The compliance measures cited in both Directions to Comply
MeasureThe contravention, in the notice's words
CM 10.1 Failing to implement appropriate age assurance and access control measures before providing access to the service or allowing end-users to generate a generative AI restricted category of material, being online pornography.
CM 10.19 Failing to implement appropriate age assurance and access control measures before allowing end-users to access online pornography.

CM 10.19 is the obligation you would expect of any service that shows pornography: check age before access. CM 10.1 is the one that only exists because the service is generative. It reaches the moment before the material exists, when a user asks the model to make it. Australia is not only regulating what an AI service shows a minor; it is regulating what it will let a minor ask it to produce.

What differs between the two, stated without a theory

The May notice does not set a date. It directs the provider to comply with the code, and then sets out reconsideration rights: an internal review by eSafety under section 220A of the Act within 30 days, and review by the Administrative Review Tribunal within 28 days. The June notice directs compliance by 16 July 2026 and contains no reconsideration or review section at all.

We do not know why they differ, and the documents do not say. A template change, a difference in what each provider was told separately, or something about the two matters would all explain it. We note the difference because it is on the face of two documents a month apart, and we leave it there.

Both carry the same consequence for ignoring the direction. Under subsection 143(2) the provider must comply, and if it does not, eSafety may apply to the Federal Court for an order that the provider pay the Commonwealth a pecuniary penalty in respect of its contravention of a civil penalty provision.

Our view, labelled as such

Two notices is not a crackdown, and anyone reading a wave of enforcement into this is reading more than is there. What is worth noticing is the aim. When Australia's age-restricted code was finally used, both times, it was used on the generative side of the online industry rather than on search, social media or hosting, and against the exact tier the code invented for services that let a user make the material rather than find it. A regulator's first two shots tell you what it thinks the live problem is.

It also closes a loop we left open. Reading the three instruments together, we found that AI-specific obligations land on the designated internet services side and never on the messaging side, twice, independently. The enforcement has now landed in the same place. That is a consistent regulatory posture rather than a drafting accident, which is a more useful thing for a provider to know than the count of notices.

How we sourced this

Both notices were downloaded as PDFs from eSafety's register of online industry codes and standards and read in full as extracted text, not through any summary. Every quoted phrase is the notice's own words, or the code's own words where the definition of a term is quoted. The provider names, contact details and in the June notice several surrounding phrases are redacted by eSafety, not by us; we quote only around the redactions and never across one.

What we do not know, and it is a fair amount. We do not know who either provider is, because eSafety withholds it. We do not know what happened after the 16 July 2026 deadline in the June notice, whether either provider complied, sought reconsideration, went to the Administrative Review Tribunal, or whether any Federal Court proceeding has followed, and we could find no public record either way. We have not sought comment from eSafety. We checked the register on 5 August 2026 and these were the only two Directions to Comply on it, but a notice issued and not yet published would not be visible to us. We make no claim about any identifiable company, and none is named in either document.

Sources

  1. eSafety Commissioner, Direction to comply: provider name withheld (PDF, notice under s143(1) of the Online Safety Act 2021, signed 19 May 2026, read 5 August 2026): the tier 1 high impact generative AI DIS characterisation, the CM 10.1 and CM 10.19 contraventions, the pecuniary penalty consequence under s143(2), and the s220A and Administrative Review Tribunal reconsideration rights.
  2. eSafety Commissioner, Direction to comply: provider name withheld (PDF, notice under s143(1), signed 16 June 2026, read 5 August 2026): the same characterisation and the same two compliance measures, the direction to comply by 16 July 2026, and the absence of any reconsideration section.
  3. eSafety Commissioner, Register of Online Safety Codes and Standards (read 5 August 2026): that these two notices are the only Directions to Comply published, listed under the Age-Restricted Material Codes.
  4. Consolidated Industry Codes of Practice for the Online Industry, Schedule 6, Designated Internet Services (Class 1C and Class 2 Material) (PDF, read 4 and 5 August 2026): the definition of a high impact generative AI DIS and the note bringing AI companion chatbots within it.

Know something about either matter, or read these notices differently? Tell us and we will check it against the documents and log the outcome here.