top of page

The Defective Draft of the Digital Duty of Care Bill: Australia Can Do Better

contemporarywomeno
2 days ago
6 min read

By Noelle Martin - Lawyer, PhD Candidate at UWA Law School


Last week, the Australian Government released an exposure draft of its Digital Duty of Care Bill (‘the Bill’) which, if passed, would impose a new enforceable duty on digital services to ensure a ‘safe online environment’ for Australians. The Bill also contains a suite of other online safety measures, including new takedown powers to tackle so-called ‘nudify’ apps.


However, only a fraction of these sweeping online safety reforms has dominated news headlines: specifically, the Bill’s new measures to ‘fix our feeds’ and give social media users more choice over the content they see, after recent campaign efforts by not-for-profit organisation Teach Us Consent. While these particular measures are — in principle — desperately needed, there is a whole lot more to the Bill that public discourse has overlooked. This article sets out three defects in the Bill that require urgent policy reconsideration.


The Proposed Digital Duty of Care:


Under the Bill, digital services are duty-bound to ensure a ‘safe online environment’ for Australian children and adults. The duty requires that digital services protect Australian children from harmful material and conduct, including pornography, material that promotes hostile attitudes to women, and conduct that promotes disordered eating, among other things. The duty also requires that children are protected from harms associated with design features of digital services, such as recommender and endless-feed features. For children under 16, digital services cannot operate design features that have negative behavioural impacts.


For adults (as well as children), the duty requires that digital services protect ‘persons in Australia’ from ‘seriously harmful material and conduct’. Under the Bill, there is a prescribed, exhaustive list of 13 categories of ‘seriously harmful material and conduct’, including material that promotes self-harm, and explicit threats of rape and death.

A failure of digital services to comply with the digital duty may result in civil penalties of $109.2 million.


While these measures are long-overdue, but welcome changes, there are fundamental defects of the Bill that require urgent policy reconsideration. Three of these defects are discussed below.


1) Narrow Scope of the Digital Duty of Care


The first defect: under the Bill, digital services must ensure Australians are safe from ‘seriously harmful material and conduct’ and there is a predetermined list of categories of material or conduct that meets this definition. This exhaustive list (and therefore, the application of the duty) is narrow in scope, and far narrower than the United Kingdom’s online safety duties.


Under the UK’s online safety laws, service providers are duty-bound to protect UK users from illegal content, among other things. The UK’s online safety regulatory regime captures 17 types of priority illegal content and over 130 priority offences — that fall within its scope. Some of these include:

‘[T]errorism; child sexual exploitation and abuse; hate; harassment, stalking, threats and abuse; controlling or coercive behaviour; intimate image abuse; extreme pornography; sexual exploitation of adults; human trafficking; unlawful immigration; fraud and financial offences; proceeds of crime; drugs and psychoactive substances; firearms, knives and other weapons; encouraging or assisting suicide; foreign interference; animal cruelty.’

The UK’s online safety duties are significantly broader in scope than Australia’s proposed digital duty. For example, unlike in the UK, Australia’s digital duty, as currently drafted, does not expressly impose a duty on digital services to protect Australians from image-based sexual abuse (notwithstanding other Australian laws that seek to tackle image-based sexual abuse outside of the proposed duty).


Without urgent reconsideration of what falls within scope of the digital duty, Australians could be less protected by law than our neighbours in the UK; and — for those who care about political point-scoring over meaningful, sustainable, and long-term change — Australia would be at risk of progressively losing its title as a world-leader in online safety regulation — a feature that has given consecutive Australian governments of late considerable bragging rights on the world stage.


2) No Private Right of Action to Sue for Breach of the Duty


The second defect: unlike the European Union’s online safety laws, Australia’s exposure draft contains no statutory private right of action for individuals to bring claims against digital services for breaches of the duty. In the EU, article 54 of the Digital Services Act expressly provides EU citizens with the right to seek compensation ‘in respect of any damage or loss suffered’ due to infringements of any obligations under those laws.


This gap for Australia is significant because it means that Australians must rely on Australia’s national online safety regulator, the Office of the eSafety Commissioner, to enforce the proposed duty. Research published in a prominent law journal on Australia’s online safety regulator reveals an alarmingly poor track-record of enforcement — with there being only 2 civil penalties (eSafety v X Corp and eSafety v Rotondo) that the regulator has successfully secured in the history of its lifespan.


Put simply, Australians cannot rely on their online safety regulator to enforce this duty effectively. But even if Australians could rely on the regulator, monies from any court-ordered pecuniary civil penalties for non-compliance of the digital duty is a debt payable to the Commonwealth of Australia, and would not flow directly into the hands of the individuals impacted (unless otherwise provided).


The Australian Government should urgently reconsider its Digital Duty of Care reforms to provide individuals with an express, statutory right of action for breaches of the duty to bring the country in-line with the EU, and to account for the enforcement shortcomings of Australia’s online safety regulatory agency.


3) Gaps in Proposals to Tackle So-Called Nudify Apps


The third defect: under the exposure draft, the eSafety Commissioner is given new takedown powers to remove so-called ‘nudify’ apps and websites, but these particular proposals are riddled with ambiguities and gaps.


First, these proposals allow for the removal of apps or websites that are predominantly designed (or used) to generate ‘fake nude material’. But the Bill does not define ‘fake nude material’. This is a serious omission given the kinds of deepfake apps or websites that exist, and the various forms of deepfake abuse that exist.


Deepfake abuse is not limited to apps or websites that can generate fake ‘nude’ material, there are all sorts of deepfake abuse apps or websites: from so-called ‘kissing apps’, bots that allow men to generate videos of them ejaculating on women’s faces, tools that are used to remove images of women from their hijabs or saris, ‘personalised deepfake abuse generators’, ‘undressing apps’, ‘strip bots’, and ‘cloth-off apps’. Generative artificial intelligence technologies can also be trained on unsuspecting social media users’ images, videos, or audio, which training data can subsequently be used to generate fake intimate imagery of real or fake people.


A failure to define ‘fake nude material’ could mean that certain apps or websites that may not generate fake ‘nude’ material, but may generate fake private, intimate, sexual, graphic, explicit, or otherwise exploitative material, may fall outside the scope of these laws. This ambiguity must be addressed for more clarity, and to ensure the proposed laws are fit-for-purpose to respond to the practical reality of deepfake abuse.


Second, these proposed takedown powers are limited to apps or websites that are designed or used for the ‘predominant purpose’ of generating fake nude material. But the generation of ‘fake nude material’ can be facilitated by multi-purpose, generalised apps or websites, such as Elon Musk’s artificial intelligence assistant, Grok. A failure to explicitly address how these kinds of multi-purpose technologies would be treated under these proposals — even if they are responded to in a different way than apps or websites ‘predominantly’ designed or used to generate ‘fake nude material’ — limits the effectiveness of these proposed laws to respond to the rising threat of deepfake abuse.


Finally, these proposed takedown powers are limited to the removal of apps or websites that ‘generate’ fake nude material. ‘Generate’ is not defined in the Bill or elsewhere in Australia’s Online Safety Act 2021 (Cth), but it is the only term used in these so-called ‘nudify’ proposals — not ‘create’, ‘edit’, ‘produce’ and/or ‘alter’ fake nude material, which are terms used elsewhere in Australia’s image-based sexual abuse laws, at the Commonwealth- and state-level. This raises questions about whether these proposals apply only to material generated through generative artificial intelligence technologies as opposed to cruder or other forms of image-manipulation tools. This definitional inconsistency and ambiguity ought to be remedied to avoid any potential confusion as to the scope, application, and interpretation of these proposed laws.


Taken together, these defects — alongside others not listed here — amount to fundamental flaws in Australia’s Digital Duty of Care exposure draft. In principle, these new online safety measures are desperately needed, but the Bill, as drafted, requires urgent policy reconsideration — while there’s still time.


To cite this article:


Suggested Citation: Noelle Martin, ‘The Defective Draft of the Digital Duty of Care Bill: Australia Can Do Better’ (2026), Medium.

 
 
 

Recent Posts

See All
NO MORE VIOLENCE RALLY SPEECH

Noelle Martin's What Were You Wearing Speech - Referenced (19 April 2026) Citation: Noelle Martin, Speech at No More Rally organised by WWYW, 19 April 2026.

 
 
 

Comments


©2023 Noelle Martin

bottom of page