The Australian Government has released an exposure draft of the Online Safety Amendment (Digital Duty of Care) Bill 2026 detailing proposed changes to the Online Safety Act 2021 (Cth) (the "OSA"). This follows the Government's response to the Statutory Review of the OSA in 2024 which was released earlier this year. Refer to our update and further background on the changes here: Review of the Online Safety Act - Australia.
The key proposed change is the introduction of a "digital duty of care" that requires a broad range of online service providers to take steps to protect users and provide a safe environment online. The exposure draft also proposes repealing the Basic Online Safety Expectations and industry codes/standards that currently exist, moving the OSA regime away from co-regulatory to a direct model with the eSafety Commissioner empowered with additional enforcement powers. Feedback on the exposure draft legislation is open until 22 September 2026.
The digital duty of care
The proposed digital duty of care would introduce a new obligation on persons responsible for online services to ensure, so far as is reasonably practicable, a safe online environment.
Who does it apply to?
The application of the proposed digital duty of care is broad as it would apply to a person responsible for an online service who provides the service or is in a position to exercise day-to-day control of the service. "Online services" captures internet carriage services, social media, relevant electronic services, designated internet services, hosting services, internet search engines, app distributors, device manufacturers and AI providers.
What is a safe online environment?
To ensure a "safe online environment," service providers must provide an online environment in which:
- persons in Australia are protected from seriously harmful material and conduct, which includes a wide range of materials, such as material and conduct relating to:
- child sexual exploitation or abuse;
- sexual violence;
- extreme violence or cruelty including threats of rape or death;
- menacing or harassing an individual;
- self-harm, suicide, cruelty against animals or sadistic online exploitation;
- terrorism;
- criminal offences and drug use; or
- abhorrent violent conduct; and
- children in Australia are protected from:
- material and conduct that is harmful to children, including material or conduct that relates to:
- pornography;
- disordered eating;
- hostile attitudes toward women or gender equality;
- glorification of crime or dangerous stunts or harmful practices; or
- abuse, harassment or bullying;
- harms associated with the operation of design features of online services; and
- (in the case of social media services), design features of the service that have negative behavioural impacts must not operate for children under 16 years of age, with those design features being:
- recommender features;
- a logged-in feature;
- an endless feed;
- a feedback feed feature; or
- a time limited feature.
- material and conduct that is harmful to children, including material or conduct that relates to:
What is reasonably practicable?
The digital duty of care would require providers to do things that are reasonably able to be done, taking into account and weighing up all relevant matters. The matters that are contemplated in the exposure draft include:
- the likelihood of harm occurring;
- the degree of the harm that might result;
- what the person knows (or reasonably ought to know) about the harm or risk of harm and the ways to mitigate or eliminate the harm; and
- the availability of ways to eliminate or mitigate the risk of harm, and the costs associated with doing so and the impact on the level of privacy that an ordinary person would expect to be afforded.
Mandatory requirements
In addition to ensuring a safe online environment, service providers would be required to:
- manage design features (i.e. recommender features, logged-in features, endless-feeds, feedback features and time-limited features) of the service appropriately including by providing user empowerment tools (which permit users of online services to manage the way features of the service operate for the user including by providing control over the kind of content that is recommended for the user);
- conduct risk assessments as required under the OSA; and
- take effective measures as necessary to address those assessments.
What are the risk assessment requirements?
Risk assessments must be undertaken annually (unless a shorter interval is determined by the eSafety Commissioner) and before any changes are made to an online service that could introduce new or additional risks. Risk assessments must:
- identify all reasonably foreseeable risks including the content, design features and other systems/processes that give rise to those risks and the people who may be affected by the risks;
- assess the likelihood and severity of the risks;
- document the measures implemented to address the risks and record an assessment of the expected effectiveness of the measures, the basis for the assessment and the time period in which the measures will be effective and in place for; and
- provide for regular review and reassessment of risk mitigation measures.
The digital duty of care is supported by new powers for the eSafety Commissioner to issue formal warnings for non-compliance and give written directions requiring specified actions be taken. Additionally, service providers must have in place complaint and dispute processes. Failure to comply with the digital duty of care will attract high penalties of up to approximately AUD 109 million.
What are the other proposed changes?
The exposure draft legislation contains several other key changes to the OSA, including:
- Repealing the basic online safety expectations and the online content scheme industry codes and standards – it is proposed that these are replaced with the digital duty of care regime and stronger enforcement powers for the eSafety Commissioner, noting the Government had proposed that this would occur after a period of transition designed to minimise unnecessary industry compliance burdens;
- Australian point of contact – empowering eSafety to require online service providers to appoint a point of contact that resides in Australia and to provide the details of the contact to the eSafety Commissioner;
- Introducing complaints and disputes processes – prescribed online services would be required to have a complaint and dispute process that is available equally to all Australians and complies with any requirements determined by eSafety.
- Transparency reports – eSafety would be able to require online service providers to prepare transparency reports about the safety of an online service, including compliance with the OSA and associated compliance measures, the kinds of harms related to the service, safety or risk features and performance reports and have the power to publish the full report or a summary on the eSafety website;
- Publication requirements – eSafety would be able to require certain online service providers publish specified information on their website about their operations and activities relating to the online safety of Australian users, including risk assessments and mitigation measures and information about user complaints;
- Data access scheme for researchers – approved researchers would be able to access data for online safety-related research under a separate set of rules;
- A number of new penalties and removal notice powers – many of the proposed powers for eSafety are accompanied by large penalties and fines and the ability for eSafety to issue formal warnings and infringement notices. Additionally, eSafety would have additional powers to issue removal notices including in relation to fake nude materials and links to cyberbullying material targeting children and a reduction in the compliance period; and
- Sock puppet identities – eSafety and approved researchers would be able to assume false identities when exercising regulatory functions providing them with immunity from any service provider's terms of use in order to carry out investigations.
Next steps
As with the recent proposed amendments to the Privacy Act 1988 (Cth) (refer to our update here: Australia Privacy Update – Proposed privacy law reform), the consultation period is very short which suggests that the Government is seeking to put legislation before the Parliament in the near future.
Feedback on the exposure draft legislation is open until 22 September 2026. Please contact a member of our team if you would like to discuss the impact of the proposed reforms.
White & Case means the international legal practice comprising White & Case LLP, a New York State registered limited liability partnership, White & Case LLP, a limited liability partnership incorporated under English law and all other affiliated partnerships, companies and entities.
This article is prepared for the general information of interested persons. It is not, and does not attempt to be, comprehensive in nature. Due to the general nature of its content, it should not be regarded as legal advice.
© 2026 White & Case LLP