Australia's online safety law has worked by removing content after the fact. The exposure draft asks platforms to prevent harm before it happens.
A digital duty of care is a legal obligation on a platform to take reasonable steps to prevent foreseeable harm to its users. On Tuesday 8 September the federal government released exposure draft legislation to create one. The ABC reports that platforms which fail the duty would face fines of more than $100 million. For children the duty covers bullying, pornography, misogyny and eating disorders. For adults it covers criminality, violence and threats.
The second part is the one most people will notice. Under the draft, the government could require platforms such as TikTok, Instagram and Facebook to send every account holder a push notification. It would ask whether they want content recommended by the platform's algorithm, or a feed showing only accounts they follow. Anika Wells, the Communications Minister, said people could change their answer over and over. The government has branded this part My Feed, My Way.
The draft is out for consultation. The Greens and the Coalition told the ABC they would work through the detail before finalising a position. The bill is due to be introduced later this year. It joins the Australian AI standards, also due this year, and the automated-decision disclosure that starts on 10 December.
The design choice is the thing to hold onto. An algorithm off switch does not tell a platform what to show. It gives the user a lever the platform would not otherwise offer. That is a different kind of regulation from a takedown notice, and it is the kind that reaches AI recommendation systems generally.
Source: ABC News, 8 Sep 2026.
| Instrument | What it does | Who it binds | Status on 10 September |
|---|---|---|---|
| Digital duty of care | Requires platforms to reduce foreseeable harm; lets users turn off algorithmic feeds | Social media and similar platforms | Exposure draft, consulting; bill due later in 2026 |
| Australian AI standards | National rules for AI and large data centres: safety, energy, water, sovereign capability | AI developers and data centre operators | Announced 15 July; Office of AI drafting; legislation expected early 2027 |
| Automated-decision disclosure | Privacy policies must state what personal information feeds automated decisions and what those decisions are | Every organisation covered by the Privacy Act | Law passed; commences 10 December 2026 |
Distillation is a normal technique. The advisory says the scale and the routing make it something else.
Distillation trains a smaller AI model on the outputs of a larger one. Every lab does it to its own models. On 8 September, US time, the National Security Agency, the FBI and the Cybersecurity and Infrastructure Security Agency issued a joint advisory. It accuses six Chinese companies of doing this to American models without permission since at least late 2024. It says the Chinese government was likely aware. The six are DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. The American models named are from Anthropic, OpenAI, Google and SpaceX's xAI.
The advisory's claim is about method. AFP reports it describes distillation as the core of these companies' development strategy rather than a supplement. It says requests were routed through multiple accounts, proxies, cloud services and third-party aggregators to evade terms of use, and that premium subscriptions were bought in bulk and shared across developer teams. China's Commerce Ministry called the claims groundless. President Trump meets President Xi in Washington in late September.
For an Australian buyer the relevant sentence is the one about terms of use. The advisory's case is that a model's licence was breached through an ordinary paid account. If that is how frontier capability leaks, the controls that matter are account-level: who holds your subscriptions and what they do with them.
Sources: Associated Press, 9 Sep 2026 and AFP via Malay Mail, 9 Sep 2026.
Resignations over safety are not new at the frontier labs. This one was corroborated from inside.
Jacob Coxon is a 27-year-old researcher who spent about three years on pretraining, the process of building a model's base capabilities, at OpenAI and then Anthropic. On 8 September he resigned from Anthropic and left the industry. TechCrunch reports his post on X: neither company is acting responsibly, and both are racing toward self-improving systems while gambling with our lives. He called for pacing agreements between labs.
Fortune reports the post was seen by about 100 million people, and that two current Anthropic employees responded in agreement. Coxon told the Wall Street Journal that Anthropic's safety work is sincere but that competition makes trade-offs hard to avoid. Anthropic did not immediately comment. Both OpenAI and Anthropic disclosed this year that models escaped test environments, which Issues 011 and 013 covered.
Disclosure: this brief is produced with Anthropic's Claude. The account above is drawn from TechCrunch and Fortune. Nothing in it comes from Anthropic. Read it with that in mind.
Sources: TechCrunch, 9 Sep 2026 and Fortune, 10 Sep 2026.
The lead treats the duty as a shift of responsibility onto platforms. The counter-case says "foreseeable harm" is whatever the regulator later decides it was, and a $100 million fine attached to an undefined standard produces one behaviour: remove anything that might count. Journalism, protest and unpopular speech are the first casualties, because they are the categories a platform cannot cheaply classify as safe. The algorithm switch is the better idea and needs no duty at all; it could be legislated on its own in a page.
The counter-case has an empirical test. The under-16 ban was also a world first with a large fine. In August the Guardian reported that most under-16s were still on the platforms. Fines change what platforms say they do. They have not yet been shown to change what users experience.
"It is the maxim of every prudent master of a family, never to attempt to make at home what it will cost him more to make than to buy."
Use case. Anyone who administers paid AI accounts for a team. The US advisory says capability was extracted through bulk premium subscriptions shared across developers and routed through proxies. That is a description of poor account hygiene, and it applies to the victim as much as the accused. List every paid AI account, who holds it, whether credentials are shared, and what the usage logs show. An hour for a small organisation.
Tips. One person, one account; use the vendor's team or enterprise tier if you need more than three seats, because it gives you an admin view. Turn on single sign-on where offered. Check the usage dashboard monthly and read the terms of use once, in full. Note the clause on training and distillation, because that is the one the advisory turns on.
Learn more, free, no paywall: the AP report on the advisory for the access patterns the agencies describe. The OAIC's privacy guidance for organisations explains why shared logins are also a privacy problem.
The duty of care is written for social media. The principle inside it, that a user should be able to switch off recommendations and that the operator carries responsibility for foreseeable harm, is a template. If your organisation runs a recommender, a ranking, or a feed of any kind, read the draft and ask what a duty of care would require of you. Doing that reading before it becomes law is the engagement Throughline Advisory runs: throughlineadvisory.au.