Skip to content

Science2 publishers3 min readPublished

Australia's draft duty of care bill turns the recommendation algorithm into a user setting

Facebook, Instagram and TikTok would have to ask each Australian whether their default feed is algorithmic or friends-only. Approved researchers would get sanctioned fake accounts to test what the systems actually serve.

The Scientist · Science desk

Photograph accompanying Australia's draft duty of care bill turns the recommendation algorithm into a user setting
Photo: abc.net.au

What happened

  • The Australian government has introduced draft digital duty of care legislation, first planned and then shelved in 2024, which puts the onus on providers to build a safe online environment rather than react to individual posts.
  • Social media platforms including Facebook, Instagram and TikTok would have to offer users a popup choice between an algorithmically personalised default feed and one containing only content from friends and accounts they follow.
  • Providers would run regular risk assessments identifying all reasonably foreseeable risks and the content and design features behind them, handing them to the eSafety Commissioner within 30 days when asked.

Compiled by The ScientistSomething wrong?How this is made

Why it matters

  • decision Because the draft as reported leaves the popup's default state and wording unspecified, the platform's design team effectively decides how many Australians end up on the friends-only feed.
  • exposure A generative AI service, a messaging app or an online game inherits the same risk-assessment obligation as a ranked feed, which lands compliance engineering on teams that have never shipped a recommender.
  • precedent Two years of EU investigation into Meta's addictive design has produced a demand rather than a change, which sets the realistic Australian expectation in years rather than release cycles.

Building the feed option is a product task. A service that ships one ranked timeline would need a second retrieval path that draws only from accounts a user follows, a stored per-account preference that survives sessions and devices, and a prompt that fires at the right moment in the session. That is release work with a QA surface, not a policy document filed with a regulator.

What the draft requires, per The Conversation's account, is the choice itself: users get an option of whether their default feed includes algorithmically personalised content or only content from friends and people they follow, presented as a popup [5]. It does not, on that description, mandate that the friends-only mode be the pre-selected state, and neither publisher's text says who specifies the prompt's wording or which option sits under the cursor [2]. Communications Minister Anika Wells said many people may stick with the recommendation algorithm, and that the value is in giving people a choice: "It's empowering" [6]. She is probably right about the behaviour. Uptake in consent interfaces is largely a property of how the interface is built, which means the one number that would tell you whether this provision did anything is set by the party being regulated.

The clause I would watch is the researcher access. Approved researchers, such as those at an Australian university, would get access to provider data for online safety research, and could create false identities to test services [17]. That matters for a specific methodological reason: you cannot learn what a recommender serves a teenager who lingers on disordered-eating content by reading an aggregate transparency report [8]. You need accounts you control, behaving in ways you specify, and a record of what came back. Sanctioned sock puppets remove the terms-of-service obstacle to running that design. What the sources do not tell you is which data the access covers, or whether a platform that detects a research account may treat it differently [6], and detection would break the comparison the method depends on.

On enforcement, a breach carries fines of nearly A$110 million, with the eSafety Commissioner able to investigate compliance [16]. Neither text says whether that figure is per breach, per day, or per contravention [5], which is the difference between a deterrent and a rounding error for a company of Meta's size.

The comparable regime offers a timeline rather than an effect size. The EU's Digital Services Act has been used since 2024 to investigate potentially addictive features of Meta's platforms [11], and in the past week EU lawmakers demanded Meta be compelled to change that design in Europe [12]. Roughly two years of investigation, and the design change is still at the demand stage [4]. Both accounts here are the same article, published by The Conversation and syndicated by phys.org [1], so this is one report of a draft, not two.

Nothing in either text requires that risk assessments or feed-choice uptake be published [3]. Without those figures, the public record will show that Australians were offered a friends-only feed, and not what happened to the ones who took it.

What to watch

  • Whether the enacted text specifies the popup's pre-selected option and wording, or leaves both to the platform building it.
  • Whether the eSafety Commissioner publishes any part of the risk assessments it collects, or keeps them internal.
  • Whether the EU demand on Meta produces a shipped design change, which would be the first evidence a systems-based regime moves engineering rather than paperwork.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories