Policy Research
Does Australia need a Digital Duty of Care?
By Emma Cooney, Zunairah Sinha, and Hamna Mohsin
·

THE PROPOSED DIGITAL DUTY OF CARE
The Australian Government has committed to introducing a Digital Duty of Care for providers of online services, amending the current Online Safety Act 2021. This will bring Australia into line with the UK Online Safety Act 2023 and the EU Digital Services Act.
This will directly shape the online experience of young Australians as the biggest users of social media, with 98% of young Australians aged 18-24 online.
Protocol welcomes the introduction of the Digital Duty of Care. This Policy Brief provides examples to illustrate the value this legislative change will bring to the online safety of young Australians.
THE RICKARD REPORT
This proposed duty of care follows the statutory review of the Online Safety Act 2021 which was announced in November 2023. The final report, led by Delia Rickard PSM, was published in October 2024.
The Rickard Report recommended the introduction of an overarching duty of care that encompasses due diligence, and is underpinned by safety by design principles, risk assessment, mitigation and measurement.
This would require all services to take reasonable steps to prevent foreseeable harms. It would also require online services to apply safety by design principles to the design of all new services and to any significant changes to existing ones.
Ultimately, it reflected the need for a shift to systematic based harm prevention away from the burden falling on the individual.
Core Enduring Categories of Harm
The Rickard Report recommended that the core enduring categories of harms to be covered by the legislation relate to:
1. Harms to young people (including child sexual exploitation and abuse (including grooming), bullying and problematic internet use);
2. Harms to people's mental and physical wellbeing (including threats to harm or kill, or attacks based on a person or group of people's protected characteristics, such as sex, gender, sexual orientation, race, ethnicity, disability, age or religion);
3. Instruction or promotion of harmful practices (such as self-harm/suicide, disordered eating and dares that could lead to grievous harm);
4. Threats to national security and social cohesion (such as through promotion of terrorism and abhorrent violent extremist content);
5. Other illegal content, conduct or activity.
INTERNATIONAL APPROACHES
European Union
The EU's Digital Duty of Care, enshrined in the Digital Services Act, applies to all service providers offering intermediary services to users. This includes online platforms (such as social media platforms) and online search engines. Additional obligations apply to 'very large online platforms' and 'very large online search engines'.
The concept of harm within the EU's duty of care is broader than the UK's Online Safety Act. It includes not only illegality but also 'unlawful or otherwise harmful information and activities' and 'illegal or otherwise harmful content and activities'. Additionally, it considers not only the harm to the individual but also 'societal and economic harm'.
Article 35 of the Digital Services Act provides that Providers of very large online platforms and of very large online search engines shall put in place reasonable, proportionate and effective mitigation measures, tailored to the specific systemic risks.
These risks include:
- the dissemination of illegal content through their services;
- any actual or foreseeable negative effects for the exercise of fundamental rights;
- any actual or foreseeable negative effects on civic discourse and electoral processes, and public security;
- any actual or foreseeable negative effects in relation to gender-based violence, the protection of public health and minors and serious negative consequences to the person's physical and mental well-being.
The United Kingdom
The UK adopts a risk-based supervisory model through the multiple, content-specific duties found in the Online Safety Act 2023.
These duties apply to service providers that allow users to share content online including social media platforms, and online search engines in relation to regulated 'user-to-user services' and 'search services'.
The Act establishes various duties of care in respect of services where risks of harm and illegality arise. Namely, it governs two categories of harm: 'illegal content and activity'; and 'content and activity that is harmful to children'.
Per section 234(2), harm is to be understood as 'physical or psychological harm'. This Act is concerned with harm encountered by individuals. It therefore contrasts the EU approach as it excludes broader societal or systemic harms from the scope of the legislation.
CASE STUDIES
Example 1: Warning! Addiction by Design
Social media platforms are built to keep us scrolling. Infinite scroll, autoplay, pull-to-refresh feeds, variable rewards, push notifications and highly personalised recommendation systems are designed to encourage excessive and compulsive use. In our attention economy, the amount of time we spend glued to our screens directly corresponds to the revenue the social media platforms bring in.
As young Australians, we have experienced first hand the design choices of these platforms vying for our attention. When one of us turned off push notifications from Snapchat and took a break from the platform for a number of days, the platform responded by emailing unsolicited invitations to return.
In 2026, social media companies are facing a reckoning over this addictive design. A Los Angeles jury found that Meta (owner of Instagram, Facebook and WhatsApp) and Google (owner of YouTube) intentionally built addictive social media platforms that harmed the 20-year-old plaintiff. Similarly, the European Commission has preliminarily found that TikTok, Instagram and Facebook failed to take measures to mitigate the risks of their own addictive design.
In light of this, the blame and burden should no longer be placed on the young people whose attention has become commodified. The question isn't how young people can be more disciplined, but why do we allow social media companies to design addiction machines in the first place?
Social media platforms now have an obligation to prevent Australians under the age of 16 from creating or keeping an account. However, this does not protect the 19 million Australians that are monthly users of Facebook, or the 70% of under-16s who have retained their accounts, from being subject to these addictive designs.
Australia's Digital Duty of Care would require platforms to proactively identify and mitigate the risks their design choices create. There are various concrete design changes that the social media platforms can, and should make, including disabling key addictive features including infinite scroll, requiring screen breaks and reducing the personalisation of recommender systems. Some are even calling for warning labels on social media platforms, similar to those on cigarette packaging and gambling platforms.
Example 2: Hate Speech: Now Trending
Elon Musk's first tweet after acquiring Twitter stated, "Free speech is the bedrock of a functioning society." But we ask: where is the line drawn between freedom of speech, and inciting violence or hatred?
Hate speech as a form of harm has increasingly been enabled on digital platforms through algorithms that thrive on the virality of inflammatory or controversial content, enabling the lines between hate speech and personal expression to be blurred. Many platforms, such as X, seek to prioritise the doctrine of freedom of speech, at the cost of harbouring violence, discrimination and other harms in the name of expressing opinions.
The United Nations defines hate speech as 'offensive discourse' which targets groups or individuals based on characteristics such as race, gender, or religion, which detrimentally impacts social peace and incites violence against others. The rise in social media use as a form of communication amongst young Australians has expanded the reach that hate speech has, through personalised algorithms that amplify problematic content, encouraging radicalisation and inciting violence.
The recent Royal Commission into Anti-Semitism has allowed experts to highlight the inflammatory nature of social media platforms, and how, for example, the rise in anti-semitic sentiments around Australia has been widely exacerbated by algorithmic targeting and the reinforcement of a pathway towards violence-inciting content. In the UK, the Commission for Countering Extremism has called on companies to ensure that there are built-in commitments to countering violent speech. The policy paper outlines how online platforms have become a 'conduit for polarisation and radicalisation' through recommender algorithms, and how companies profit from inflammatory content due to their 'viral' character.
Social media platforms have largely been granted broad powers of self-regulation, seen through community guidelines and moderation methods, allowing for the platforms themselves to determine what constitutes hateful or extremist content, and leading to inconsistent approaches. Whilst the desire to maintain freedom of speech and avoiding censorship is a pertinent issue, protecting communities through banning harmful content is paramount in assisting young Australians in their navigation of the internet, creating a complex balancing act for digital platform moderation.
A Digital Duty of Care would aid in mitigating the harmful effects of allowing hateful and violent speech to be platformed and amplified, protecting the safety of young Australians both affected by hate speech, and preventing individuals from spreading violent rhetoric online through a 'safety by design' approach. These protections are critical to ensuring that victims are not burdened with the task of reporting the harms done to them, and instead a proactive approach is taken in addressing the proliferation of hate speech and incitement of violence that is allowed, and profited from, on these platforms.
Example 3: Chatbots: Our New Worst Friends
A homework helper, personal assistant, and even a digital companion. The rise of chatbots is a worldwide phenomenon with recent reports indicating that young Australians are spending hours online daily, chatting with their newfound mates. But is this revolution really beneficial or just generating more profitable prototypes for big tech?
Experts have voiced concerns over AI chatbots' tendency towards sycophancy — using feedback loops of validation and praise to prolong user engagement — which in turn can create echo chambers that amplify harmful thoughts and behaviours.
These concerns have already played out in real-time with Adam Raine's family filing a lawsuit against OpenAI and CEO Sam Altman over GPT-4o in 2025. From Raine's conversations with ChatGPT, it was evident that the chatbot's role had gradually escalated from a homework helper to a suicide coach. Once the sixteen-year-old divulged mental health concerns, the chatbot responded by mentioning suicide six times more than him and actively discouraged him from seeking real-life support. It was argued that this case was the "predictable result of deliberate design choices."
And these harmful design choices aren't characteristic of ChatGPT alone. Character.AI — a chatbot with 20 million monthly users — was rated as safe for kids above 12. Yet, it was "programmed to engage in sexual roleplay, presented itself as a romantic partner, and even a psychotherapist falsely claiming to be licensed." In fact, one distraught parent who discovered sexually explicit conversations — typical of grooming — on their child's phone stated: "They told me the law has not caught up to this. They wanted to do something, but there's nothing they could do, because there's not a real person on the other end."
These cases highlight the harms that occur when "safety protocols are deprioritised in the AI development and deployment process" and emphasise that "AI products optimised to harvest user intimacy are exploitative and manipulative."
Although the aforementioned companies have updated their safety mechanisms to help mitigate future incidents, it is evident that several chatbots lack appropriate safety mechanisms such as enforcing proper age restrictions and offering support guidelines, ultimately exploiting user vulnerabilities for profit without allocating sufficient cost to guardrails.
Recently, Australia's eSafety Commissioner has registered new industry-drafted codes in a bid to require certain good-practice measures for mostly unregulated AI chatbots. Some are even pushing for AI chatbots to be included in Australia's under-16 social media ban.
Australia's digital duty of care would ensure that the onus to protect Australians, particularly vulnerable young users, would be on companies prioritising profit and innovation over user safety and wellbeing through mandating safety by design.
A full downloadable copy of this brief, "Protocol Digital Duty of Care Policy Brief" (1.36MB), is available on the Protocol Policy Lab website.

