Australia’s Digital Duty of Care: what regulating algorithms could mean for businesses
Australia’s proposed Digital Duty of Care could change the way online safety is regulated. Instead of focusing only on harmful content after it appears, the draft legislation would require digital services to address the systems, design choices and algorithms that can create or amplify harm.
Speaking at a recent Spencer West event in London, Andrew Ailwood, Managing and Founding Partner of Spencer West Australia, explored the proposals and their implications for technology businesses, regulators and policymakers in Australia, the UK and beyond.
What is Australia proposing?
Australia has repeatedly taken an early position on online safety. Its restrictions on social media access for under-16s, alongside mounting concern about the effects of digital services on mental health and social norms, have added momentum to calls for further intervention.
The draft duty would cover a wide range of services, including social media, search engines, generative AI tools, messaging services, websites and hosting providers. In practical terms, providers may be expected to:
- identify reasonably foreseeable online harms;
- carry out regular risk assessments;
- manage potentially harmful design features;
- give users greater control over how algorithms curate content; and
- take reasonable and effective steps to make services safer.
Why are algorithms and product design in scope?
The proposals look beyond the removal of individual posts or merely regulating content itself. They focus on features that shape behaviour: recommendation systems, endless feeds, engagement metrics and disappearing content. These mechanisms can encourage repeated use, amplify particular material and make it harder for users to disengage.
This is an important evolution in regulation. Earlier internet laws often treated service providers as “mere conduits” for material they did not create, offering “safe harbour” protection. Major digital services now do much more than carry content: their algorithms select, rank and promote it. Their design features encourage regular and extended use and reward posting. Australia’s proposed framework recognises that active role and would place greater responsibility – and potentially greater development and moderation costs – on providers.
How would the duty protect children and give users more control?
Children are a central concern. Services may need to address serious harmful material, age-inappropriate content and design features capable of producing negative behavioural effects. The draft also points towards greater user choice over algorithmically curated experiences, with some features potentially unavailable to children by default. That ambition raises difficult questions about age assurance, privacy and proportionality.
Who would enforce the Digital Duty of Care and what does it mean for online businesses?
Oversight would sit with Australia’s eSafety Commissioner. The Commissioner could issue guidance, require transparency reports and publish information about compliance, including moderation decisions, complaints and account suspensions. Providers would not simply have to meet a standard; they would need to show how they were meeting it.
The proposals contemplate significant consequences for non-compliance, including penalties of up to A$100 million. Unlike some European models, a fine may not be tied to the provider’s turnover. Unlike the existing under-16s social media ban, a broad range of online services, big and small, are potentially caught by the duty. The Commissioner could also direct remedial action to prevent further breaches.
This could mean a significant regulatory burden for all sorts of online businesses – not just large social media and AI companies. All sorts of online business that host user generated content, provide interactivity and create online communities could be caught – whether or not they have an active presence in Australia.
What questions remain unresolved?
Much remains broadly defined and may need to be expanded on through the legislative process, policy guidance or judicial interpretation. “Reasonably foreseeable harm” will need careful interpretation. Relevant factors may include the likelihood and severity of harm, what a provider knew, whether it could reduce the risk, the cost of doing so and the privacy implications of closer monitoring. Further clarity on how online service providers can take “reasonably practicable” steps to prevent harm may also be needed. The legislative debate is also likely to explore protections for political and journalistic expression as the potential impact on political communication attracts scrutiny.
What could other countries learn from Australia?
The debate has global implications. Concerns raised by the current US administration include freedom of expression, the burden on technology companies and the practical challenge of adjusting algorithms in one market without affecting users elsewhere. Australia has nevertheless shown that it is prepared to challenge major digital businesses where domestic public interests are at stake.
For other countries such as the UK and European jurisdictions, the central lesson is that the next phase of online safety regulation may focus as much on product architecture as on content. Businesses should therefore consider not only what appears on a service, but how recommender systems, generative AI and engagement-led features influence what users encounter and how they behave.
The issue is unlikely to remain confined to Australia. If the legislation progresses through consultation and parliamentary scrutiny, regulators in the UK, Europe and other jurisdictions will watch closely. The defining question is no longer simply what content a digital service hosts, but how its systems shape behaviour, and where responsibility for the consequences should sit.