Australia’s proposed Digital Duty of Care represents an important new stage in the long struggle to make digital platforms accept responsibility for the environments they create.
The exposure draft of the Online Safety Amendment (Digital Duty of Care) Bill 2026 would require online services to take reasonable steps to provide Australians with a safe online environment. Providers would have to identify foreseeable risks, examine how their content and design features contribute to those risks, and introduce measures to prevent or reduce serious harm.
This is a fundamental change of approach. Rather than relying primarily on users to report harmful material after it appears, responsibility begins to move upstream—to the companies designing the platforms and the algorithms that determine how people experience them.
Manufacturers of cars, medicines, food and children’s toys are expected to consider safety before their products reach the public. Digital services, despite influencing behaviour, relationships, mental health and access to information, have largely escaped comparable obligations.
That distinction has become increasingly difficult to justify.
From permission-based marketing to algorithmic control
The principle of giving users control over their digital environment is not new to me. I advocated a version of it during the early development of broadband more than 25 years ago.
In 2001, I made a formal submission to the Productivity Commission as part of its inquiry into telecommunications competition. In the accompanying market analysis, I argued that emerging broadband services needed new business models based on permission-based marketing.
The concept was simple: users should remain in control of their personal information and decide whether, and under what conditions, it could be used by businesses. Advertising should be based on informed participation and an agreed exchange of value rather than the invisible extraction of data.
I also linked permission-based marketing to open networks and customer choice. Businesses could establish one-to-one relationships with customers, but they should not gain automatic control over people’s data or their digital experience.
The 2001 Productivity Commission submission records that I had already been promoting this approach for some time. I continued developing it in subsequent BuddeComm reports covering broadband, mobile services, digital media, privacy and the emerging digital economy.
By 2008, our research included headings such as “Users need to be in charge” and “Industry control needs to be changed into trust”. A later report placed permission-based marketing within a wider discussion of privacy and trust, alongside warnings that consumer trust was eroding and government intervention would eventually become unavoidable.
Unfortunately, permission-based systems never became the foundation of the digital economy. The advertising model was too profitable. Personal information became an enormously valuable commercial asset, while the platforms accumulated ever-greater power over users’ data, attention and participation.
What began as online advertising developed into a system of behavioural profiling and algorithmic influence.
The harm is built into the system
The major platforms do not simply display material selected by users. Their recommender systems determine what receives attention, what disappears from view and what is placed before us repeatedly.
These systems are designed primarily to maximise engagement because attention generates advertising revenue and valuable personal data. Material provoking fear, anger, anxiety or outrage can therefore be commercially successful regardless of its effects on individuals or society.
Children and vulnerable people are particularly exposed. Someone interested in dieting may be drawn towards increasingly extreme eating-disorder material. A person experiencing emotional distress can be repeatedly shown content dealing with suicide or self-harm. Misogyny, dangerous behaviour and extremist ideas can be amplified because provocative content keeps people watching.
The platforms have known about these risks for years. They can no longer plausibly be dismissed as unexpected side effects.
As I argued in Meta’s US$18 billion settlement treats the damage, not the cause, parents and young people cannot carry this responsibility alone. Lasting protection requires safer design to be built into the platforms themselves.
A Digital Duty of Care addresses that central problem. It asks not only whether an individual post should be removed, but whether the platform’s algorithms, commercial incentives and product design are creating or amplifying foreseeable harm.
Building on Australia’s under-16 initiative
The proposal should be viewed as the next step after Australia’s prohibition on children under 16 holding accounts on major social-media platforms.
Australia was the first country to introduce such a nationwide restriction. The early results have been mixed. Platforms removed or restricted millions of accounts, but many teenagers continued using social media or found ways around the controls.
This does not necessarily mean the initiative failed. As I argued in Australia’s social media ban offers lessons for the Netherlands, the policy’s significance cannot be measured only by immediate compliance figures.
It changed social expectations, gave parents and schools greater support in setting boundaries and challenged the assumption that unrestricted social-media access was inevitable. It also forced governments elsewhere to confront the issue.
France, Britain, Denmark, New Zealand and other countries are now developing or considering their own approaches. They are not simply copying Australia. Each is refining the concept according to its legal system, culture and experience.
This is how sound digital policy should develop. Countries introduce measures, examine the results and learn from one another. Australia’s imperfections can help other countries design better policies, just as their experience can help us improve our own.
The Digital Duty of Care could have a similar international influence.
My feed, whose choice?
The government’s proposed “My Feed, My Way” initiative would give Australians over 16 a choice between algorithmically recommended material and content from people and organisations they have chosen to follow.
This is, in effect, a modern expression of the permission-based principle. Users should have meaningful control over the systems influencing their attention instead of being subjected automatically to whatever produces the greatest engagement for the platform.
However, having examined the exposure draft, I believe the final legislation needs to be clearer. The bill does not yet establish an explicit right to a chronological or follower-only feed. Instead, it allows the minister to prescribe future “user empowerment tools”.
The right to opt out of algorithmic recommendations should be clearly included in the legislation. It should also be easy to exercise and not undermined by confusing settings, repeated prompts or other design techniques intended to steer users back towards the platform’s preferred option.
Protecting democracy as well as individuals
The bill is strongest in addressing recognisable harms such as sexual exploitation, grooming, bullying, pornography, eating-disorder material, self-harm and content promoting hostility towards women.
These protections are essential, but the problem extends beyond individual safety.
In Democratic promise to algorithmic power: How social media reshaped truth, I examined how social media’s original democratic promise has been undermined by systems that reward emotional reaction, polarisation and constant engagement.
Democracy does not require agreement, but it depends on sufficient common ground for disagreement to remain meaningful. Algorithmic feedback loops increasingly divide societies into separate information environments, each reinforcing its own version of reality.
Governments must not be allowed to determine which political opinions citizens may express. But freedom of expression does not give corporations an unrestricted right to manipulate attention, amplify division and monetise human vulnerability.
The focus should therefore be on the machinery of amplification rather than on suppressing legitimate political debate.
Middle powers must work together
Australia cannot transform the global digital economy alone. The dominant platforms are mostly American companies operating across hundreds of markets and possessing extraordinary financial, technological and political power.
Progress will require cooperation among middle powers and regional blocs. Australia, Canada, New Zealand, Britain, the European Union and like-minded Asian democracies should compare evidence, coordinate regulatory principles and develop compatible expectations for safety by design.
They do not need identical laws. The international response to Australia’s under-16 initiative already demonstrates how countries can pursue different approaches while learning from one another.
Individually, these countries can be pressured or ignored. Together, they represent markets that even the largest technology companies cannot easily dismiss. If their requirements become broadly compatible, platforms may find it more practical to improve their global systems than maintain weaker products in unregulated markets.
There will be considerable resistance. The platforms will oppose measures that reduce engagement, restrict behavioural profiling or weaken their control over what users see because these measures strike directly at their business models.
Political pressure will also come from Washington. The Trump Administration has already warned against foreign regulations and penalties it regards as targeting American technology companies.
It is therefore encouraging that Prime Minister Anthony Albanese has said Australia will determine its online-safety policies according to the national interest.
This is not anti-Americanism. Australia expects foreign companies in every other industry to comply with its safety, competition and consumer-protection laws. Digital corporations should be no exception.
Returning technology to its proper purpose
The Digital Duty of Care remains an exposure draft and requires further work. Its success will depend on effective enforcement, regulatory independence, access to platform data and the ability to determine whether safety measures actually reduce harm.
The danger is that it could generate risk assessments, transparency reports and corporate policies without fundamentally changing the platforms themselves.
Nevertheless, its underlying principle deserves support. Digital platforms have become part of the social infrastructure through which people communicate, build relationships, receive information and participate in democracy.
The companies controlling that infrastructure cannot continue maximising engagement and profits while transferring the resulting psychological and social costs to children, families, schools, health services and the wider community.
My argument in 2001 was that people should control how their information and participation were used. A quarter of a century later, that remains the central issue.
Australia’s under-16 initiative helped change the international conversation. The Digital Duty of Care can take the next step by establishing that those who design our digital environment must accept responsibility for its foreseeable consequences.
Paul Budde
