Australia has moved faster than almost any other country on children's online safety in the past twelve months. The under-16 social media minimum age has been in force since 10 December 2025. A second wave of industry codes now reaches generative AI and companion chatbots. The Government has committed to a statutory digital duty of care. And the Children's Online Privacy Code must be registered by 10 December 2026. For organisations that work with children, this is no longer a platform problem. It is an operating environment.
What do Australia's new children's online safety rules require of organisations?
Organisations that provide, fund or procure digital services used by children in Australia must now show that they have assessed and reduced foreseeable harms, that they handle children's data under a children's privacy code, and that they can evidence "reasonable steps" on age assurance. The obligations sit with platforms first, but schools, charities, health providers, sports bodies and government agencies inherit them through the services they choose and the children they serve.
The instruments, in order of urgency
1. The Children's Online Privacy Code, registered by 10 December 2026. The Office of the Australian Information Commissioner (OAIC) consulted on a draft code until 5 June 2026 and is required to register the final code by 10 December 2026. It will set binding standards for how online services likely to be accessed by children collect, use and disclose personal information, in the spirit of the UK's Age Appropriate Design Code. Commencement and transition arrangements are still being settled, but the direction is clear: default-high privacy for children, data minimisation, and an end to design that nudges children into sharing more than they need to.
2. The social media minimum age, in force since 10 December 2025. Age-restricted social media platforms must take reasonable steps to prevent Australians under 16 from holding accounts. The eSafety Commissioner issued principles-based regulatory guidance on 16 September 2025, and non-compliance carries penalties of up to A$49.5 million. This is the rule most families and schools know about. It is also the one most likely to displace children onto services that are not covered.
3. Phase 2 industry codes, including AI. eSafety's second phase of codes came into effect in stages: search, hosting and carriage services from 27 December 2025, and the remaining sectors from 9 March 2026, explicitly including generative AI and AI companion services and app distribution. Age assurance requirements under the app-store code applied from 9 September 2026. For the first time, an online-safety regulator has put chatbots and AI companions inside a binding code framework.
4. A statutory digital duty of care. On 14 April 2026 the Government published its response to the independent statutory review of the Online Safety Act, accepting or agreeing to consider 64 of the review's 67 recommendations. The centrepiece is a risk-based digital duty of care, which shifts the model from reacting to individual pieces of content towards requiring services to identify and mitigate foreseeable harms systemically. Drafting and consultation are the next stage.
5. AI governance for government. Australia stepped back from mandatory high-risk AI guardrails for the private sector in its December 2025 National AI Plan, favouring voluntary guidance. Commonwealth agencies are different: mandatory requirements applied from 15 June 2026 with full compliance expected by 10 December 2026. Any public body deploying AI in services that touch children now needs an impact assessment that includes children's rights.
Why a compliance checklist is not enough
Each of these instruments was written for platforms. Organisations that work with children face a different question: how do we keep children safe across the services we use, commission and recommend, when those services are changing their behaviour under regulatory pressure?
A child-rights approach answers that question better than a checklist. The UN Convention on the Rights of the Child, and General Comment 25 on children's rights in the digital environment, ask three things of any organisation: that it understands the risks children actually face, that it weighs protection against children's rights to participation, information and privacy, and that it can show its working. Those are also the three things a duty-of-care regime will ask.
In practice that means:
- Map your digital footprint through a child's eyes. Which services do the children you serve use because of you? A learning platform, a wellbeing app, a messaging tool for a youth programme, a chatbot on your website. Each is now inside Australia's regulatory perimeter.
- Ask providers for evidence, not assurances. Under the codes and the coming duty of care, providers must document risk assessments and mitigations. Ask to see them. A provider that cannot produce one is a risk to you.
- Treat age assurance as a safeguarding question. Minimum-age rules push younger children towards services designed for adults, or towards lying about their age. Your safeguarding policy should say what you do when that happens.
- Bring your own data practices up to the Children's Online Privacy Code. If you collect information about children online, the code will set the benchmark whether or not you are formally covered by it. Funders, parents and regulators will judge you against it.
- Assess any AI you deploy for children before you deploy it. A Children's Rights Impact Assessment, adapted for AI systems, is the most defensible way to do that.
What this means for INGOs and organisations operating across regions
Australia is not alone. Singapore's app-store age assurance became mandatory on 1 April 2026 and its Online Safety Commission opened on 29 June 2026. Malaysia's Online Safety Act took effect on 1 January 2026, with a Child Protection Code from 1 June 2026. Indonesia's PP Tunas regulation applied from 28 March 2026. The UK Online Safety Act and the EU Digital Services Act set the template that all of these borrow from.
An organisation with children in more than one of these jurisdictions cannot run five compliance programmes. It needs one child-safety standard, grounded in children's rights, that maps onto each regime. That is where a cross-jurisdiction readiness review pays for itself.
Frequently asked questions
Does the Children's Online Privacy Code apply to charities and schools? The code will apply to organisations covered by the Privacy Act that provide online services likely to be accessed by children. Coverage of small organisations and specific sectors is part of what the final code will settle. Even organisations outside its formal scope will be measured against it by funders, parents and partners.
What is a "reasonable step" on age assurance? eSafety's guidance is principles-based. It expects platforms to use methods proportionate to risk, to avoid relying on self-declaration alone, and to protect the privacy of the data used for age checks. It does not mandate a single technology.
Are AI chatbots covered by Australian online safety law? Yes. Phase 2 industry codes explicitly bring generative AI and AI companion services into scope from 9 March 2026, and the coming digital duty of care will apply to them as to any other online service.
What is a Children's Rights Impact Assessment? A structured assessment of how a product, policy or system affects children's rights, using the UN Convention on the Rights of the Child as the framework. It looks beyond harm to participation, privacy, development and non-discrimination, and it produces a documented rationale for design and policy decisions.
What should an organisation do before 10 December 2026? Inventory the digital services children use because of you. Ask each provider for its risk assessment. Review your own collection of children's data against the draft Children's Online Privacy Code. Assess any AI you run for children. Write down what you found and what you changed.
Regulatory details cited here are accurate as of September 2026 and should be checked against the eSafety Commissioner and OAIC websites before being relied on in a compliance decision.