Australia is changing how it regulates online safety.
The federal government’s draft digital duty of care legislation introduced earlier this month would require online services to identify and manage foreseeable risks.
These risks come not only from harmful content, but also from how services are designed and operated.
That includes features like recommender systems and endless feeds, which shape what users see and how far content spreads.
This is an important change. But a “duty of care” on paper does not automatically mean safer platforms.
Much will depend on whether the law stops companies from meeting their obligations with paperwork, user‑choice settings and internal assessments that outsiders cannot test.
Before the legislation is finalised, five areas need attention.
1. Risk assessments could become a box‑ticking exercise
The draft sets out a detailed risk‑assessment framework. Platforms would have to identify foreseeable risks, the content and design features that create those risks, and who might be affected. They would also need to assess likelihood and severity, document mitigation measures, and explain why they expect those measures to work. Assessments must be done at least yearly and kept for six years.
On paper, this is strong. But experience overseas shows that detailed rules do not guarantee meaningful assessments.
In the UK, the regulator Ofcom reviewed 104 risk assessments under its new online safety law. Many were formally compliant, but had serious weaknesses, including:
- “Low” or “negligible” risk ratings were often poorly explained and not backed by evidence.
- Some platforms treated a lack of evidence as proof that risk was low.
- Children’s risk assessments relied too much on self‑declared age.
- Platforms did not always consider how their large user base could multiply harm.
- Governance was weak: 69 of 104 assessments did not name the person responsible for online safety although guidance made clear that naming the person responsible for the risk assessment was necessary to fulfil the record-keeping duties under the Act.
The EU has seen similar problems. In early 2026, the European Commission found that TikTok had not properly assessed risks from addictive design features and that its safeguards appeared insufficient.
The lesson is clear: the issue is not whether platforms must produce risk assessments, but whether those assessments can stand up to rigorous interrogation.
Platforms should have to show what evidence supports their conclusions, how they measure whether safeguards work, and whether those measures actually reduce risk over time.
Otherwise, the digital duty of care could produce impressive compliance documents without necessarily producing safer services.
The eSafety Commissioner’s power to set standards, benchmarks and metrics for these assessments will be critical. Guidance should make clear that this power is meant to support evidence‑based assessments, not just formal paperwork.

2. “My Feed, My Way” must not shift responsibility back to users
The government’s “My Feed, My Way” proposal would require social media platforms to offer users over the age of 16 a choice: a personalised, algorithm‑driven feed, or a feed showing posts from people and creators they choose to follow.
More user control is welcome. Some platforms already offer a similar choice. X, for example, allows users to switch between its personalised “For You” feed and a chronological “Following” feed. A 2026 Nature study of X’s feed algorithm found that most participants were using the algorithmic feed before the experiment began, even though a chronological option existed. This does not prove that users prefer personalised feeds, but it shows that simply providing an alternative may not be enough: defaults and platform design strongly influence which option people actually use.
This raises a further key question:
If a user chooses the personalised feed and the recommender system then amplifies harmful material, could the platform argue it had already done enough by offering an alternative feed?
That should not be enough.
The EU provides a useful model. Its Digital Services Act (arts 38) requires very large platforms using recommender systems to offer an option not based on profiling. But that sits alongside separate duties to assess and mitigate systemic risks (arts 34 & 35).
In other words, giving users a choice does not replace the platform’s responsibility to manage risks created by its systems.
Australia should make clear that offering a non‑personalised feed does not, by itself, discharge a platform’s duty to address risks generated by its personalised system.
3. Platforms should not be allowed to mark their own homework
The framework raises a significant information asymmetry problem. Regulators and the public may struggle to determine whether a provider’s risk assessment is reliable. Platforms possess their algorithms, internal experiments, engagement data and safety metrics. Regulators, researchers and the public generally do not. If a major platform assesses its own recommender system and concludes the risk is “low”, how can anyone independently determine whether that conclusion is justified?
The EU’s Digital Services Act (arts 37) partly addresses this by requiring its largest platforms and search engines to undergo independent audits of key obligations. Auditors must keep information confidential where needed, but not in a way that undermines transparency or enforcement. In practice, this allows publication of redacted audit summaries that enable scrutiny without exposing trade secrets.
Australia should consider a proportionate independent‑assurance framework for major platforms. This should not impose costly audit obligations on every website or small business. Nor should private auditors replace the eSafety Commissioner. Instead, independent assurance should target services whose scale, reach, design or risk profile makes them capable of causing significant harm.
This would bring Australia closer to the EU model without copying it in full and would address both the information gap and legitimate confidentiality concerns.

4. The Bill protects privacy expressly, but not freedom of expression
This is one of the more significant gaps in the draft.
When deciding what safety measures are “reasonably practicable”, the core digital duty of care provisions expressly require platforms to consider the impact on the level of privacy an ordinary reasonable person would expect.
Freedom of expression is not given equivalent express recognition.
That matters especially when regulation moves beyond removing clearly harmful content and starts influencing recommendation, ranking and amplification systems.
Imagine a platform responds to an identified risk by automatically down‑ranking posts containing controversial words. It might reduce some abusive content, but it could also reduce the visibility of journalism, political criticism, academic discussion, satire or legitimate advocacy.
The UK’s Online Safety Act 2023 (s 22) requires providers to give particular regard to users’ legal rights to freedom of expression when deciding on and implementing safety measures. The EU’s Digital Services Act similarly requires systemic risk assessment and mitigation to account for freedom of expression and information (arts 34–35). Australia should consider a similar safeguard.
This would not prevent platforms from addressing harmful content. It would require them to consider whether a safety measure unnecessarily restricts lawful communication and whether a less restrictive alternative could achieve the same objective.
5. Researcher access looks promising, but may be too narrow
One of the most valuable parts of the draft is its proposed framework for researchers to access platform data. Approved researchers can help test how recommendation systems actually behave, who is exposed to particular material and whether safeguards are working.
But there is a question about who qualifies as an approved researcher. The draft currently limits approved researchers to people employed by Australian universities. That may be unnecessarily restrictive. Competent researchers may also work in independent research institutes, civil society organisations or other bodies with appropriate ethical and data‑security safeguards.
The EU’s Digital Services Act (art 40) already provides a model for “vetted researcher” access to data on systemic risks. Vetted researchers can come from a research organisation, not necessarily a university, as long as they can show independence from commercial interests, data‑security capacity and a commitment to publish results.
Australia should consider whether eligibility should be based more directly on research competence, independence, ethical oversight, data security and public‑interest purpose, potentially with a requirement that the lead applicant be Australian‑based to address jurisdictional and enforcement issues.
What needs to happen next
The proposed digital duty of care laws will achieve little if risk assessments become compliance paperwork, user choice shifts responsibility back to individuals, companies assess themselves without meaningful external scrutiny, or safety interventions unnecessarily restrict lawful expression.
The legislation also needs credible researcher access and enough transparency for outsiders to test what platforms say they are doing.
If these gaps are addressed, Australia’s digital duty of care could shift online safety regulation from reacting to harmful posts to governing the systems that create and amplify harm.
If they are not, the risk is a new regulatory architecture that looks much stronger on paper than it proves to be in practice.