Australia’s Digital Duty of Care: A step towards an Internet designed to protect children
Australia has released an exposure draft of the Online Safety Amendment (Digital Duty of Care) Bill 2026. It would require providers of online services to ensure, so far as reasonably practicable, a safe online environment—and move responsibility towards the organisations that design and operate digital services.
What it could improve
The draft represents an important shift from responding to individual incidents towards preventing foreseeable harm through service design. Providers would be expected to assess foreseeable risks, implement effective measures, keep safeguards effective as services evolve, manage potentially harmful design features, support user control over recommended content, maintain risk-assessment records and respond to regulatory oversight.
What remains unresolved
The proposed duty creates a potentially strong legal foundation, but legislation alone does not establish a consistent Child-Friendly Internet ecosystem.
- How will services recognise children reliably and proportionately when children may declare an inaccurate age, use another person’s account, retain an existing account or access a service while signed out?
- Without an interoperable assurance mechanism, will every service conduct its own age check—creating repeated verification, inconsistent decisions and unnecessary collection of identity documents, facial estimates or behavioural information?
- Each provider would implement the duty within its own environment. Safeguards applied by one service would not automatically continue when the child moves to another application, game, website, AI service or account.
- The ‘reasonably practicable’ standard allows proportionate implementation, but services could interpret risks and appropriate safeguards differently. Regulatory guidance and enforcement will therefore be critical.
- Recommendation controls can empower users, but younger children should not be expected to understand and configure complex safety or wellbeing settings. Age-appropriate defaults remain essential.
- A single under-18 category may not always distinguish appropriately between the needs, capabilities and growing autonomy of younger children and older teenagers.
- Compliance reports should be supported by evidence of children’s actual experiences, including whether harm moves to less-regulated services or safeguards unintentionally restrict beneficial access and participation.
The Child-Friendly Internet perspective
Australia’s proposal closely aligns with Safe by Design, Age-Appropriate by Design and Digital Wellbeing by Design. However, a provider-by-provider duty does not itself create the technical foundation needed for consistent, privacy-preserving protection across the wider Internet.
- A Child-Friendly Internet ecosystem could complement the legislation with a trusted assurance signal that communicates only the necessary age or developmental category—not the child’s identity.
- Participating networks and digital services could recognise that signal and activate their own appropriate protections without repeatedly identifying the child.
- This shared foundation would not replace regulation, platform moderation, family support, education, child-protection services or law enforcement. It would help those responsibilities operate more consistently.
The central question
How can Australia’s proposed duty of care become consistent, age-appropriate protection wherever a child goes online—without requiring every service to identify the child again?
