The instrument is the Online Safety (Relevant Electronic Services - Class 1A and Class 1B Material) Industry Standard 2024. Like its sibling it was determined by Commissioner Julie Inman Grant under section 145 of the Online Safety Act 2021, and it commences 6 months after registration, which put it in force on the same date. It was registered as F2024L00711 on 21 June 2024; the designated internet services standard we read earlier on 4 August is F2024L00710, registered the same day.

They are a matched pair, made together, and they diverge on the subject this masthead exists to cover.

The count, and it is not close

Word counts taken from the extracted text of each instrument
 Designated internet services (F2024L00710)Relevant electronic services (F2024L00711)
Pages4640
“generative”510
“synthetic”present, in the category definition0
“machine learning”51
A generative AI categoryyes, defined and boundno

The designated internet services standard defines a high impact generative AI DIS and attaches specific minimum duties to it: prevent the generation of certain material, test models for that risk, adjust and deploy mitigations after testing, and implement systems, processes and technologies that differentiate AI outputs generated by the model. That last one is a provenance obligation, and it is the reason the earlier story mattered.

None of that appears in the relevant electronic services standard.

What a relevant electronic service is

The standard defines a communication relevant electronic service as one the predominant purpose of which is to enable an end-user to communicate with another end-user, or to find and be recommended other end-users for that purpose. In plain terms: messaging, email, chat and the services built around them, as against the designated internet services category that captures websites and apps that make material available.

That is the category where AI assistants have been arriving fastest.

Where AI does appear, honestly characterised

It would be wrong to say the instrument is silent on AI. It mentions it three times, and none of the three creates a duty aimed at generative systems.

  • In the list of matters a provider must consider when assessing risk, one factor is the risk to the online safety of end-users in Australia in relation to material generated by artificial intelligence. AI-generated material is a risk to be assessed, not a category to be regulated.
  • In a note giving examples of detection technology, it lists machine learning and artificial intelligence systems that scan for known child sexual abuse material. Here AI is the compliance tool, not the regulated thing.
  • In the development programs section, a program may include arrangements to reduce the risk to the online safety of end-users in Australia in relation to class 1A material or class 1B material generated by artificial intelligence.

So the drafters had AI-generated material clearly in view while writing this instrument. They wrote it in as a risk to manage and as a tool to manage it with. They did not write in a category, a definition, or a single one of the model-level duties that the sibling standard imposes.

The qualification that matters, and we are not skipping it

The obvious inference is that a messaging service with an AI assistant escapes the provenance duty. We are not making that claim, for a reason we can show.

Neither standard mentions the other's service class. We searched both: the relevant electronic services standard never refers to a designated internet service, and the designated internet services standard never refers to a relevant electronic service. Nothing in either instrument allocates a service to one or the other. That allocation is done by the service-type definitions in the Online Safety Act, and a single product can be more than one thing under that Act, with different components falling into different classes.

So whether a particular messaging app with a generative feature is caught by the designated internet services standard for that feature is a question about that product's architecture. We have not assessed any product, and this piece names none.

Our view, labelled as such

The interesting thing is not that one instrument is weaker. It is that the pair was made together, by one office, on one day, under one section, and only one of them treats generative AI as a thing requiring its own rules. Read together they say something specific about how Australian online safety law arrived at AI: it did so through the category of service that publishes material, not the category that carries messages between people.

That was a defensible place to start in mid-2024. Whether it is still the right shape in 2026, when assistants are embedded in the messaging surfaces themselves, is a real question, and it is one the mandatory guardrails debate does not touch either, because that debate is about a proposal and this is about instruments already in force.

We are not calling this a loophole. A gap between two instruments is only a loophole if something falls through it, and establishing that would require looking at specific services against the Act's definitions, which is exactly the work we have not done here.

How we sourced this

Both instruments were downloaded as PDFs from the eSafety Commissioner and read as extracted text, not through any summary. The word counts above are our own, taken from that extracted text, and are reported as counts of the literal word rather than of concepts. Quoted phrases are the instruments' own words. The registration identifiers, the determining officer, the authority and the commencement formula are on the face of each instrument. The official title of the standard uses an em-dash between “Services” and “Class 1A”; we render it as a hyphen for house style, without altering the words.

What we have not done. This is a description of two instruments, not legal advice. We have not assessed any particular service against either standard, and we name no company. We have not read the explanatory statements for either instrument, which may qualify how the Commissioner intends provisions to operate. We have not examined the separate Age-Restricted Material codes, which are a different instrument set with their own commencement. We have not sought comment from eSafety. Where a provision is a note rather than an operative subsection, we say so.

Sources

  1. eSafety Commissioner, Online Safety (Relevant Electronic Services - Class 1A and Class 1B Material) Industry Standard 2024 (PDF, 40 pages, F2024L00711, registered 21 June 2024, downloaded and read 4 August 2026): the commencement formula and authority under section 145, the definition of a communication relevant electronic service, the risk-assessment factor covering material generated by artificial intelligence, the note listing machine learning and artificial intelligence systems as examples of detection technology, and the development programs provision. Also the absence of the word “generative” anywhere in the text.
  2. eSafety Commissioner, Online Safety (Designated Internet Services - Class 1A and Class 1B Material) Industry Standard 2024 (PDF, 46 pages, F2024L00710, registered 21 June 2024, read 4 August 2026): the high impact generative AI DIS category and the minimum requirements attaching to it, including the duty to differentiate AI outputs.
  3. AI Geek, Australia already regulates generative AI: our reading of the designated internet services standard, published 4 August 2026.

Work on a service that could fall under either standard, or read these instruments differently? Tell us and we will check it against the text and log the outcome here.