The Promise of the Online Safety Act
In 2021, Australia passed the Online Safety Act, a sweeping piece of legislation that gave the eSafety Commissioner unprecedented powers to order the removal of harmful online content. The Act was hailed as a global benchmark, with the government claiming it would make Australia the safest place in the world to be online. The law created a two-tier system: a basic online safety expectation (BOSE) for all providers, and specific industry codes that major platforms must follow.
The Act's flagship power was the ability to issue a 'removal notice' for 'class 1' material—content depicting abhorrent violent conduct, such as terrorist attacks. Under Section 108, the Commissioner could direct a platform to take down such material within 24 hours, with penalties up to $555,000 for non-compliance. It seemed like a decisive tool for an era of live-streamed massacres, from Christchurch to Buffalo.
The First Test: The Christchurch Video Resurfaces
On March 15, 2019, a terrorist live-streamed his attack on two mosques in Christchurch, New Zealand, killing 51 people. The video spread across Facebook, YouTube, and X (then Twitter) within minutes. Australia's Online Safety Act was designed precisely for this scenario. The first major test came in 2023, when the video resurfaced on Telegram and other platforms. The eSafety Commissioner issued removal notices to several companies, including Telegram, which refused to comply.
Telegram's refusal exposed a gap: the Act only applies to providers with a 'relevant connection' to Australia. Telegram, a Dubai-based company, argued it had no physical presence or servers in Australia, and thus no obligation. The Commissioner took no enforcement action, citing the difficulty of extraterritorial enforcement. This was not an isolated incident; a 2022 review by the Australian Institute of Criminology found that extremist content removal requests were only 45% effective within the first 24 hours.
Scope Creep and Definitional Blur
The Act's definition of 'class 1 material' is narrow, but its 'class 2' categories are broad, covering cyber-bullying, non-consensual intimate images, and 'seriously harmful' content. This breadth has led to criticism that the Act gives the Commissioner quasi-judicial power to make subjective judgments. For example, in 2022, the Commissioner ordered a Twitter post to be removed that criticized a public figure, citing 'serious harm' to the individual's reputation. The post was later reinstated after public outcry, but the chill on free speech was evident.
This is not just a theoretical concern. The Act empowers the Commissioner to force platforms to take down content that is 'likely to cause serious harm' to an Australian. The term 'serious harm' is not defined in the legislation, leaving it open to interpretation. In a 2023 Senate inquiry, the Australian Human Rights Commission warned that the Act could be used to suppress legitimate political dissent, especially in the context of climate change protests or criticism of government policy.
Enforcement: A Paper Tiger?
The Act's penalties for non-compliance are significant, but the enforcement record is weak. As of 2024, the eSafety Commissioner had issued 47 removal notices, but only 12 resulted in fines. The largest fine was $1.5 million against X for failing to answer questions about its handling of child sexual abuse material—not for actual non-removal of content. This suggests the Commissioner is more willing to punish procedural failures than substantive ones.
Furthermore, the Act relies on 'industry codes' that platforms themselves draft. These codes are meant to be enforceable, but they are often vague. For example, the 'disinformation code' agreed to by major platforms in 2023 includes provisions for 'labeling' state-affiliated media, but no clear metric for success. The Australian Communications and Media Authority (ACMA) has admitted it has no way to verify compliance with these codes.
Transparency and Accountability Gaps
The Act requires the Commissioner to publish an annual report on its activities, but the report is notably thin on specifics. For instance, the 2023 annual report lists the number of removal notices issued, but does not disclose which platforms were targeted or how many were successful. This lack of transparency undermines public trust. A 2024 study by the Australian National University found that 68% of Australians were unaware of the Act's existence, and 74% said they had no confidence in the government's ability to regulate online content.
There is also no independent appeals process for content creators. If a user's content is removed under a removal notice, they have no right to challenge the decision directly. The only recourse is a judicial review, which is expensive and time-consuming. This creates a system where the Commissioner acts as both prosecutor and judge, with little oversight.
Comparative Perspective: The UK and EU Approach
To understand what Australia might have done better, we can look to the United Kingdom's Online Safety Act (2023) and the European Union's Digital Services Act (DSA, 2022). The UK Act, while also controversial, includes a 'safe harbor' for platforms that comply with a 'duty of care' framework. The DSA requires platforms to provide clear reasons for content removals and allows users to appeal to an out-of-court dispute settlement body. Australia's Act has no equivalent provision, leaving users without a clear path to challenge takedowns.
| Feature | Australia (OSA) | UK (OSA) | EU (DSA) |
|---|---|---|---|
| Appeals process for users | No | Yes, via Ofcom | Yes, via certified bodies |
| Extraterritorial enforcement | Weak | Stronger (targets any platform serving UK users) | Strong (global platforms must comply) |
| Definition of harmful content | Broad, subjective | Specific categories | Specific categories |
| Transparency reporting | Minimal | Detailed | Extensive |
These comparisons show that Australia's Act is not merely 'new and untested'—it is structurally weaker in key areas. The DSA, for instance, requires platforms to publish detailed reports on content moderation, including the number of takedowns by category. Australia's Act has no such requirement, making it difficult for researchers and the public to assess its impact.
Recommendations for Reform
Given these flaws, what should Australia do? First, it should amend the Act to include an independent appeals mechanism for content removals. This would protect free speech and ensure that the Commissioner's decisions are reviewed by a neutral body. Second, it should strengthen extraterritorial provisions by explicitly stating that any platform that has 'a substantial number of Australian users' is subject to the Act, regardless of physical presence.
Third, it should create a transparent enforcement database, listing all removal notices and their outcomes, similar to the EU's transparency database. Fourth, it should set clear, objective definitions for 'serious harm' and 'class 1 material' to reduce the risk of arbitrary enforcement. Finally, it should invest in a proactive monitoring system that uses existing technologies to detect extremist content before it goes viral, rather than relying on reactive notices.
Conclusion: A Law That Needs a Second Draft
The Online Safety Act was a bold attempt to regulate online harm, but its first test revealed critical failures. The Act's vague definitions, weak enforcement, and lack of accountability make it ineffective against determined platforms like Telegram and dangerous to free speech. The Australian government has promised a review of the Act in 2025. That review must be willing to make substantial changes, not just tweaks around the edges. Otherwise, Australia will continue to fall short of its goal to be the safest place to be online—while also becoming a cautionary tale for other nations drafting similar laws.
We need a law that protects citizens without sacrificing democratic principles. That means clear rules, fair processes, and real accountability. The current Act fails on all three counts. It's time for a second draft.
Comments (0)
Please sign in to post a comment.
Don't have an account? Create one
No comments yet. Be the first to comment!