The instrument is the Online Safety (Designated Internet Services - Class 1A and Class 1B Material) Industry Standard 2024. The eSafety Commissioner, Julie Inman Grant, determined it on 19 June 2024 under section 145 of the Online Safety Act 2021. It was registered on 21 June 2024 as F2024L00710, and it commences six months after registration, which put it in force on 22 December 2024. It runs to 46 pages and the word “generative” appears in it 51 times.

None of that is new. What seems to be missing from the public conversation is what the thing actually says, so we read it.

What makes a service a high impact generative AI DIS

The definition has two limbs. A high impact generative AI DIS is a designated internet service that uses machine learning models to enable an end-user to produce material and is capable of being used to generate synthetic high impact material. For a service in this category, high impact material means material that has been or would likely be classified X18+ Restricted or RC as a film or computer game, or Category 2 Restricted or RC as a publication.

Then comes the sentence that carries the entire regulatory design. A service is not a high impact generative AI DIS if it incorporates controls such that the risk of the service being used to generate synthetic high impact material is immaterial.

That is not a licence, a register, or a pre-approval. It is a category you fall into by capability and climb out of by control. Build effective safeguards and the obligations below do not attach to you at all. Ship something that can be driven to produce the worst categories of material and they do.

What it obliges a provider to do

The standard is structured as compliance measures, each naming the service types it binds. A high impact generative AI DIS is named in most of them, including terms of use, systems for responding to prohibited material, resourcing trust and safety functions, detecting and removing known child sexual abuse material and known pro-terror material, complaint tools, and referring unresolved complaints to the Commissioner.

The measure written specifically for generative AI is the sharpest. Its provider must, at a minimum:

  • implement systems, processes and technologies that prevent generative AI features from being used to generate outputs that contain child sexual exploitation material or pro-terror material;
  • regularly review and test models on the potential risk that a model is used to generate that material;
  • promptly after that testing, adjust models and deploy mitigations aimed at reducing both misuse and unintentional use;
  • implement systems, processes and technologies that differentiate AI outputs generated by the model; and
  • present prominent messaging to end-users in Australia who specifically seek images of child sexual abuse material.

The fourth of those is worth stopping on. A duty to differentiate AI outputs is a provenance obligation, of the kind usually discussed in Australia as a future policy question. It has been in force for more than eighteen months.

The clause that reaches the prompt

Detection duties normally attach to what a service publishes. Because a generative service produces material rather than hosting it, the standard follows the problem upstream. On the obligation to detect and remove known child sexual abuse material, it notes that may require the provider to assess whether inputs into the service contain child sexual abuse material.

That is a note rather than an operative clause, and notes explain rather than impose. But it tells you how the Commissioner reads the duty: for a generative service, meeting it can mean examining what users type in, not only what the model gives back. The standard also carries a technical-feasibility limb, so a provider is not required to use a system where it is not technically feasible or reasonably practicable.

Our view

Two things follow, and they pull in opposite directions.

The first is that the common claim that Australia has no binding rules for generative AI is wrong, and has been wrong since December 2024. Anyone operating a generative service reachable from Australia should know whether they are inside this category, because the obligations are specific enough to audit against and the Commissioner has enforcement powers under the Act.

The second is that this is a narrow instrument doing a specific job. It is aimed at the worst categories of illegal material, class 1A and 1B, not at bias, accuracy, automated decisions, employment effects or any of the things the guardrails debate is actually about. Reading it as a general AI law would be as wrong as saying nothing exists. It regulates one harm well and is silent on the rest by design.

What it does show is that the machinery to bind AI providers already exists and is being used, through online safety law rather than AI law. That is a fact worth having in the argument about what to do next.

How we sourced this

Everything above comes from the text of the Online Safety (Designated Internet Services - Class 1A and Class 1B Material) Industry Standard 2024, which we downloaded as a PDF and read in full rather than working from any summary or explanatory statement. Quoted phrases are the instrument’s own words. The registration identifier, the determining officer, the authority and the commencement formula are all on its face. The count of 51 uses of “generative” is our own from the extracted text.

What we have not done. This is a description of an instrument, not legal advice, and whether any particular service falls inside the category is a question about that service’s capabilities and controls that we have not assessed for anyone. We have not read the explanatory statement or the supplementary explanatory statements, which may qualify how the Commissioner intends provisions to operate. We have not examined the parallel Relevant Electronic Services standard, or the separate Age-Restricted Material codes registered in 2025, beyond noting they exist. We have not sought comment from eSafety or from any provider, and we make no claim that any named company is or is not complying. Where we describe a note rather than an operative subsection, we say so.

Sources

  1. eSafety Commissioner, Online Safety (Designated Internet Services - Class 1A and Class 1B Material) Industry Standard 2024 (PDF, 46 pages, F2024L00710, registered 21 June 2024, downloaded and read 4 August 2026): the definition of a high impact generative AI DIS and its immaterial-risk exclusion, the meaning of high impact material for that category, the compliance measures that name it, the minimum requirements written for generative AI including the duty to differentiate AI outputs, the note on assessing inputs, the technical-feasibility limb, the determining officer and date, the authority under section 145 of the Online Safety Act 2021, and the six-month commencement formula.
  2. eSafety Commissioner, Register of Online Safety Codes and Standards (read 4 August 2026): that the Unlawful Material Standards for relevant electronic services and designated internet services were registered on 21 June 2024 and came into effect on 22 December 2024, and the existence and dates of the separate Age-Restricted Material codes.
  3. AI Geek, what the National AI Plan actually says: that the mandatory guardrails framing does not appear in it.

Work on a generative service reachable from Australia, or read this instrument differently? Tell us and we will check it against the standard and log the outcome here.