By John Wayne on Tuesday, 15 September 2026
Category: Race, Culture, Nation

Digital Duty of Care: When Online “Safety” Becomes Online Social Control

 The phrase "Digital Duty of Care" sounds almost impossible to oppose. Who could object to forcing enormous technology companies to make their products safer? Social-media platforms have deliberately engineered systems to maximise engagement, children have plainly suffered from some of those systems, and governments have every reason to ask whether companies such as Meta, Google and ByteDance should bear greater responsibility for what their platforms do. The problem begins when that principle is converted into law.

Australia is moving towards a regulatory model under which online services may increasingly be expected not merely to remove clearly unlawful material after it appears, but to identify risks in advance, redesign systems to mitigate those risks and demonstrate to regulators that reasonable precautions have been taken. The Albanese Government has pursued a Digital Duty of Care approach, while a separate private senator's bill introduced by Greens Senator Sarah Hanson-Young, the Online Safety Amendment (Fix Our Feeds) Bill 2026, illustrates the same broader regulatory movement. That bill would require social-media services to allow users to opt out of algorithmically recommended content while also imposing reporting, risk-assessment and mitigation obligations.

This approach has an obvious attraction. Instead of asking why a platform failed to remove the thousandth harmful post, regulators can ask why the platform was designed so that harmful material could be amplified to millions of people in the first place. Yet precisely because this model regulates systems rather than merely particular illegal acts, it potentially creates enormous discretionary power, and the first problem is the concept upon which much of that discretion depends: "harm."

The criminal law normally operates by identifying prohibited conduct with considerable precision. Assault, fraud, threats and child exploitation are offences because legislation establishes legal boundaries around particular conduct. A regulatory duty of care operates differently. A platform may be required to identify foreseeable risks and adopt proportionate measures to mitigate them. Those concepts make intuitive sense in occupational health and safety, where a factory owner can inspect a machine, identify whether a guard is missing and estimate the likelihood that somebody will lose a hand. Speech is considerably more difficult.

What constitutes harmful political discussion? What constitutes harmful discussion of religion? At what point does criticism become hostility? When does controversial medical debate become misinformation? How much exposure to disturbing material constitutes unacceptable psychological harm? There is no engineering instrument capable of producing objective answers to such questions, yet somebody eventually has to answer them if "harm" becomes the organising principle of regulation, which is proposed.

Britain's Online Safety Act demonstrates how extensive such a system can become. The British regime requires covered services to assess risks arising from illegal content, while services likely to be accessed by children have additional obligations to assess children's exposure to harmful material and implement appropriate protections. Ofcom has developed detailed risk-assessment guidance, codes and enforcement mechanisms. The British authorities also emphasise that freedom of expression remains protected and that the regime is principally directed towards systems and processes rather than regulators ordering the deletion of individual posts. That qualification matters, but it does not eliminate the underlying problem.

Regulatory uncertainty can encourage censorship even where a government never explicitly orders censorship. Imagine that a platform faces enormous financial penalties if a regulator later decides that it failed adequately to manage harmful material, while suffering little comparable legal risk from unnecessarily restricting lawful material. The commercial incentives are obvious. When uncertain, suppress the risky material. When an automated system cannot confidently distinguish political criticism from prohibited hostility, reduce the distribution of both. When lawyers cannot confidently determine whether controversial medical discussion might later attract regulatory attention, the commercially safer decision may be to restrict it.

No government censor therefore needs to telephone a social-media company and demand that a particular dissident be silenced. The state can establish the liability structure while corporations make millions of individual moderation decisions within it. Regulation consequently migrates from Parliament into statutory principles, regulatory standards, codes, risk assessments, corporate compliance departments and ultimately automated moderation systems. The citizen whose post disappears may never know which link in that chain was responsible.

This is no longer merely theoretical in Britain. Ofcom is actively enforcing the Online Safety Act's risk-assessment requirements and has demanded extensive information from regulated providers. The potential penalties for serious breaches can reach £18 million or 10 per cent of qualifying worldwide revenue, whichever is greater. Those figures matter because they demonstrate why corporations will inevitably treat regulatory uncertainty seriously. A rational company facing enormous potential penalties will construct its systems around avoiding regulatory risk.

The third difficulty concerns executive and administrative power. Modern regulatory statutes increasingly establish broad principles in primary legislation while allowing regulators and ministers to supply substantial operational detail later through codes, standards, guidance and subordinate instruments. There are practical reasons for doing this because technology develops far faster than Parliament legislates, but democratic accountability changes with it. If Parliament prohibits a precisely defined category of speech, senators and members must publicly vote upon the prohibition. If Parliament instead establishes a broad statutory obligation to prevent harm and delegates much of the practical definition of compliance, politically important decisions can migrate away from the parliamentary chamber.

The question then ceases to be simply, "Should Australians be forbidden from saying this?" It becomes, "Has the platform adequately mitigated the systemic risk associated with users encountering material of this kind?" The second formulation sounds technical and administrative, yet under sufficiently expansive definitions of harm it can sometimes produce a remarkably similar practical result.

Another problem is that the regulatory burden will not fall equally. Meta can employ armies of engineers, lawyers, policy specialists and compliance officers. Google can construct elaborate auditing systems, while ByteDance can maintain teams devoted exclusively to satisfying regulators. A small Australian discussion forum, independent publishing platform, specialised community website or start-up attempting to challenge the technological giants cannot operate on the same scale.

A complicated regulatory system can therefore produce the opposite of its advertised objective. Legislation presented as an assault upon Big Tech may become a competitive moat protecting Big Tech. Every mandatory risk assessment, transparency report, algorithmic audit, child-safety architecture, age-assurance system and regulatory submission imposes a fixed cost. For a corporation earning tens of billions of dollars that cost is irritating. For a company employing six people it may determine whether the business exists at all. Regulation intended to restrain technological incumbents can therefore strengthen them against potential competitors.

There is also a technical problem with the fashionable attack upon algorithms. Senator Sarah Hanson-Young's Fix Our Feeds Bill would require social-media services to provide users with an option to opt out of recommended content. As a matter of consumer choice, that has considerable merit. A person should reasonably be able to tell a platform to stop deciding what he ought to see and instead show him material from people he has deliberately chosen to follow. But algorithms themselves are not inherently sinister.

Every large information system requires some method of sorting information. Search engines use algorithms, spam filters use algorithms, online shops use algorithms and music services use algorithms. Even a supposedly neutral chronological feed is the product of rules governing what appears on a screen. Pure chronology can create its own problems because high-volume posters can dominate the feed, spam can overwhelm useful information and material genuinely relevant to a person's interests can disappear beneath enormous quantities of noise.

The real issue is therefore not "algorithms versus no algorithms" but who controls the algorithm and what objective it is designed to optimise. A recommendation system optimised overwhelmingly for engagement may encourage outrage, compulsive scrolling and emotional manipulation because those responses keep people staring at screens. An algorithm configured around choices genuinely made by the user might instead be extremely useful. Legislation that treats recommendation technology itself as the villain risks confusing the tool with the commercial incentives governing its operation.

Then comes the privacy paradox. To demonstrate that users are being protected from harm, platforms may need to know considerably more about them. A service attempting to determine whether a child is being exposed to unsuitable material must first have some way of determining whether the user is a child. That creates pressure for age assurance, and Australia is already confronting the resulting privacy questions. The Office of the Australian Information Commissioner has issued specific guidance concerning the collection, use and disclosure of personal information through age-assurance technologies.

The paradox is difficult to escape. A service required to determine whether recommendation systems disproportionately expose vulnerable people to harmful material may need behavioural information about those people. A service required to prove that its safety interventions work may require telemetry showing what users see, how long they look at it, what they click and how they respond. Legislation introduced partly to protect citizens from intrusive technology can consequently create incentives for additional observation and data processing.

The problem becomes particularly acute with children. Governments understandably want strong protections for minors, but reliably separating children from adults online requires some mechanism for distinguishing one from the other. Britain demonstrates the logic clearly: Ofcom's implementation of the Online Safety Act gives highly effective age assurance an important role in determining whether children can access certain services. Once such infrastructure becomes commonplace, legitimate questions arise about privacy, data security and whether systems introduced for a narrow protective purpose will remain confined to that purpose.

Another weakness concerns verification. Governments can command platforms to assess risks, mitigate them and report their results, but regulators still face the problem of determining whether those assessments accurately describe enormously complicated proprietary systems. Platforms possess quantities of internal information unavailable to ordinary researchers, journalists and the public. A corporation might report that harmful exposure declined substantially following an intervention, but without access to definitions, methodologies and underlying datasets outsiders may have difficulty determining exactly what the reported improvement means.

Regulation can therefore deteriorate into an elaborate exchange of corporate reports and regulatory paperwork. The platform measures itself and reports its measurements; the regulator examines the report and demands further documentation; the corporation responds with another compliance document, while the recommendation machinery that actually determines what hundreds of millions of people see remains largely invisible to the public.

Behind these practical questions lies a philosophical problem that receives much less attention. Duty-of-care legislation subtly changes the assumed relationship between citizens and information. Traditional liberalism begins with an adult citizen presumed capable of encountering arguments, lies, propaganda, stupidity, offence and unpleasant opinions. Government may intervene where expression crosses defined legal boundaries such as threats, fraud, defamation or incitement, but the adult citizen does not ordinarily require the state to curate his intellectual environment.

The emerging digital-safety model begins from a different premise. Information itself increasingly becomes a field of risk requiring systematic management. Once that principle is established, the relevant question is no longer simply whether material is lawful but whether exposure to it creates a sufficient risk of harm that somebody ought to have prevented the exposure. That represents an enormous conceptual change in the relationship between government, corporations, citizens and speech.

The strongest case for a Digital Duty of Care concerns children, deliberately addictive design and genuine criminality. Platforms should not knowingly engineer children into compulsive behaviour and then pretend that parental responsibility ends the argument. Nor should companies be indifferent when their systems facilitate child exploitation, fraud, threats or other criminal conduct. But those hard cases should not obscure the danger of constructing a general administrative architecture capable of managing lawful human communication.

Britain provides an important warning precisely because its Online Safety Act began from propositions almost everyone could support: protecting children and combating illegal material online. It has nevertheless developed into one of the democratic world's most extensive systems of internet regulation, involving risk assessments, codes of practice, age-assurance requirements, record keeping and continuing regulatory supervision. The lesson is not that Britain's system is literally a Ministry of Truth. It is that regulatory systems established for compelling cases can gradually acquire a reach considerably greater than the examples originally used to justify them.

Australia should therefore ask a simple question before travelling too far down the same road: what precisely are technology companies being required to prevent? If the answer concerns child sexual exploitation, fraud, terrorism, credible threats or other clearly unlawful conduct, the legal system has comparatively identifiable boundaries around which platform obligations can be constructed. If the answer expands into misinformation, unhealthy attitudes, offensive ideas, psychological risk, harmful political material or loosely defined social harms, the regulatory project enters radically different territory.

At that point platforms cease merely to be private businesses required to obey the law. They risk becoming delegated governors of speech. Modern censorship does not require Canberra to establish an Orwellian Ministry of Truth tomorrow morning. A far more plausible mechanism is gradual and administrative: Parliament establishes a broad duty, regulators develop standards and guidance, corporate lawyers interpret those requirements cautiously, automated systems suppress material that appears risky, and citizens discover that lawful arguments receive fewer views, disappear from searches or become difficult to post. Everyone involved can plausibly insist that nobody ordered the censorship of a particular opinion.

There is a legitimate case for making enormous technology corporations responsible for dangerous systems that they deliberately design. There is an equally legitimate reason to distrust a regulatory framework that allows an elastic concept of "harm" to become the gateway to permanent supervision of digital communication. The challenge is therefore not simply to make the internet safer. It is to ensure that "safety" does not become the administrative vocabulary through which freedom quietly disappears. That is where the present Digital Duty of Care Bill fails.

https://www.theaustralian.com.au/nation/governments-duty-of-care-laws-granted-pathway-after-greens-offer-support/news-story/898846f8cb3f645023b5cc9c198e30d6

https://www.weeklytimesnow.com.au/news/national/liberals-will-absolutely-oppose-labors-digital-duty-of-care-bill-in-current-form/video/7f2f6f496f6d986bebfb141bd1e235d2