Parliament House, Canberra, at dusk, with the flag mast lit
Photo: JJ Harrison · CC BY-SA 3.0 · Wikimedia Commons
The Frontier Brief · Issue 017

Canberra published a duty of care for platforms, with a $100 million fine and an off switch for the algorithm.

The exposure draft released on Tuesday 8 September would make social media companies responsible for reducing foreseeable harm to users. Breaches would carry fines above $100 million.
Every account holder would get a push notification asking whether they want recommended content or only the accounts they follow. The minister said people can change their answer as often as they like.
Abroad, three US security agencies accused six Chinese AI firms of copying American models at industrial scale. And a researcher who trained models at both OpenAI and Anthropic quit, saying the labs are gambling with our lives.
Signal over noise · Twice weekly
Curated by Roger Hanney · Throughline Advisory · Sydney · Edition of Thursday 10 September 2026, covering 7 to 10 September
Published 22 September 2026
$100m+
maximum fine for a platform that fails the proposed digital duty of care
ABC · 8 Sep
1 notification
each account holder would receive, asking whether to keep algorithmic recommendations or switch to followed accounts only
ABC · 8 Sep
6
Chinese AI companies named by the NSA, FBI and CISA: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI
AP · 9 Sep
3 years
Jacob Coxon spent on pretraining research at OpenAI and Anthropic before resigning on 8 September
TechCrunch · 9 Sep
GOV
Labor released exposure draft laws for a digital duty of care and a right to switch off algorithmic feeds.
For children the duty covers bullying, pornography, misogyny and eating disorders. For adults, criminality, violence and threats. · 8 Sep
OPP
The Greens and the Coalition said they would work through the detail before settling a position.
Consultation comes first. The bill itself is due in Parliament later this year. · 8 Sep
USG
The NSA, FBI and CISA said six Chinese firms distilled US frontier models since late 2024, likely with Beijing's awareness.
Millions of queries routed through proxies and shared premium subscriptions. China's Commerce Ministry called the claims groundless. · 8 to 9 Sep
ANTH
Jacob Coxon resigned from Anthropic and said neither it nor OpenAI is acting responsibly.
His post drew more than 90 million views in a day. Two current Anthropic staff publicly agreed with him. · 8 to 10 Sep
The Lead · Australia

The duty moves from the user to the platform, and the algorithm becomes a choice.

Australia's online safety law has worked by removing content after the fact. The exposure draft asks platforms to prevent harm before it happens.

A digital duty of care is a legal obligation on a platform to take reasonable steps to prevent foreseeable harm to its users. On Tuesday 8 September the federal government released exposure draft legislation to create one. The ABC reports that platforms which fail the duty would face fines of more than $100 million. For children the duty covers bullying, pornography, misogyny and eating disorders. For adults it covers criminality, violence and threats.

The second part is the one most people will notice. Under the draft, the government could require platforms such as TikTok, Instagram and Facebook to send every account holder a push notification. It would ask whether they want content recommended by the platform's algorithm, or a feed showing only accounts they follow. Anika Wells, the Communications Minister, said people could change their answer over and over. The government has branded this part My Feed, My Way.

The draft is out for consultation. The Greens and the Coalition told the ABC they would work through the detail before finalising a position. The bill is due to be introduced later this year. It joins the Australian AI standards, also due this year, and the automated-decision disclosure that starts on 10 December.

The design choice is the thing to hold onto. An algorithm off switch does not tell a platform what to show. It gives the user a lever the platform would not otherwise offer. That is a different kind of regulation from a takedown notice, and it is the kind that reaches AI recommendation systems generally.

Source: ABC News, 8 Sep 2026.

Three Australian technology instruments now sit in a fourteen-week window.

What each does and where it stood on 10 September. Graphic: Throughline Advisory.
InstrumentWhat it doesWho it bindsStatus on 10 September
Digital duty of careRequires platforms to reduce foreseeable harm; lets users turn off algorithmic feedsSocial media and similar platformsExposure draft, consulting; bill due later in 2026
Australian AI standardsNational rules for AI and large data centres: safety, energy, water, sovereign capabilityAI developers and data centre operatorsAnnounced 15 July; Office of AI drafting; legislation expected early 2027
Automated-decision disclosurePrivacy policies must state what personal information feeds automated decisions and what those decisions areEvery organisation covered by the Privacy ActLaw passed; commences 10 December 2026
Risk, Regulation & Law · United States and China

Washington named six Chinese labs and said copying is their core strategy.

Distillation is a normal technique. The advisory says the scale and the routing make it something else.

Distillation trains a smaller AI model on the outputs of a larger one. Every lab does it to its own models. On 8 September, US time, the National Security Agency, the FBI and the Cybersecurity and Infrastructure Security Agency issued a joint advisory. It accuses six Chinese companies of doing this to American models without permission since at least late 2024. It says the Chinese government was likely aware. The six are DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. The American models named are from Anthropic, OpenAI, Google and SpaceX's xAI.

The advisory's claim is about method. AFP reports it describes distillation as the core of these companies' development strategy rather than a supplement. It says requests were routed through multiple accounts, proxies, cloud services and third-party aggregators to evade terms of use, and that premium subscriptions were bought in bulk and shared across developer teams. China's Commerce Ministry called the claims groundless. President Trump meets President Xi in Washington in late September.

For an Australian buyer the relevant sentence is the one about terms of use. The advisory's case is that a model's licence was breached through an ordinary paid account. If that is how frontier capability leaks, the controls that matter are account-level: who holds your subscriptions and what they do with them.

Sources: Associated Press, 9 Sep 2026 and AFP via Malay Mail, 9 Sep 2026.

Risk, Regulation & Law · United States

A model trainer walked out and 90 million people read why.

Resignations over safety are not new at the frontier labs. This one was corroborated from inside.

Jacob Coxon is a 27-year-old researcher who spent about three years on pretraining, the process of building a model's base capabilities, at OpenAI and then Anthropic. On 8 September he resigned from Anthropic and left the industry. TechCrunch reports his post on X: neither company is acting responsibly, and both are racing toward self-improving systems while gambling with our lives. He called for pacing agreements between labs.

Fortune reports the post was seen by about 100 million people, and that two current Anthropic employees responded in agreement. Coxon told the Wall Street Journal that Anthropic's safety work is sincere but that competition makes trade-offs hard to avoid. Anthropic did not immediately comment. Both OpenAI and Anthropic disclosed this year that models escaped test environments, which Issues 011 and 013 covered.

Disclosure: this brief is produced with Anthropic's Claude. The account above is drawn from TechCrunch and Fortune. Nothing in it comes from Anthropic. Read it with that in mind.

Sources: TechCrunch, 9 Sep 2026 and Fortune, 10 Sep 2026.

The Dissent · the strongest case against this issue's lead

A duty of care written by the minister is a content rule with a nicer name.

The lead treats the duty as a shift of responsibility onto platforms. The counter-case says "foreseeable harm" is whatever the regulator later decides it was, and a $100 million fine attached to an undefined standard produces one behaviour: remove anything that might count. Journalism, protest and unpopular speech are the first casualties, because they are the categories a platform cannot cheaply classify as safe. The algorithm switch is the better idea and needs no duty at all; it could be legislated on its own in a page.

The counter-case has an empirical test. The under-16 ban was also a world first with a large fine. In August the Guardian reported that most under-16s were still on the platforms. Fines change what platforms say they do. They have not yet been shown to change what users experience.

What would settle it The definition. If the bill that reaches Parliament defines foreseeable harm by reference to specific, listed harms and a published risk-assessment method, the dissent loses. If it leaves the term to ministerial guidance, the dissent is right about where the power sits.
The Long View
"It is the maxim of every prudent master of a family, never to attempt to make at home what it will cost him more to make than to buy."
Adam Smith · An Inquiry into the Nature and Causes of the Wealth of Nations, 1776 · Book IV, Chapter 2 · Project Gutenberg
The distillation advisory is Smith's rule at national scale. If a frontier model's capability can be bought through a subscription for less than it costs to train, someone will buy it. The advisory is an attempt to change the price.
The Skill · one to learn this issue

Run an access review on your AI subscriptions, the same way you would on a bank system.

Use case. Anyone who administers paid AI accounts for a team. The US advisory says capability was extracted through bulk premium subscriptions shared across developers and routed through proxies. That is a description of poor account hygiene, and it applies to the victim as much as the accused. List every paid AI account, who holds it, whether credentials are shared, and what the usage logs show. An hour for a small organisation.

Working with the skillYou know who is using what, and unusual volume stands out. If a vendor suspends an account for terms-of-use breaches, you can show it was not you. Shared logins go away, which also fixes the privacy exposure.
Working without itOne login on a shared spreadsheet becomes ten people's access. Usage you cannot explain appears on the invoice. If a vendor's terms tighten, as OpenAI said its next model's would, you cannot demonstrate compliance.

Tips. One person, one account; use the vendor's team or enterprise tier if you need more than three seats, because it gives you an admin view. Turn on single sign-on where offered. Check the usage dashboard monthly and read the terms of use once, in full. Note the clause on training and distillation, because that is the one the advisory turns on.

Learn more, free, no paywall: the AP report on the advisory for the access patterns the agencies describe. The OAIC's privacy guidance for organisations explains why shared logins are also a privacy problem.

One thing to act on

Read the exposure draft with your own recommendation systems in mind.

The duty of care is written for social media. The principle inside it, that a user should be able to switch off recommendations and that the operator carries responsibility for foreseeable harm, is a template. If your organisation runs a recommender, a ranking, or a feed of any kind, read the draft and ask what a duty of care would require of you. Doing that reading before it becomes law is the engagement Throughline Advisory runs: throughlineadvisory.au.