Binding law — in force
Generative AI services and AI companion chatbots must age-assure users before restricted material can be generated (Australia, age-restricted codes)
Under Australia's industry codes for age-restricted (Class 1C and Class 2) material, registered by the eSafety Commissioner on 2025-09-09 and in effect from 2026-03-09, a high impact generative AI designated internet service (a service using machine learning models to let end-users produce material that can generate a generative AI restricted category of material, DIS Code Sch. 6 cl. 3(j)) and an AI companion chatbot feature of a relevant electronic service (RES Code Sch. 5 table 16) assess, for each restricted category, the risk that Australian children will generate it (cl. 4.2(b) of each Schedule). Where the risk profile is Tier 1, the provider must, where technically feasible and reasonably practicable, implement appropriate age assurance and access control measures before giving access to the service or feature, or before restricted material can be generated, and test and monitor how well they work over time (DIS measure 10.1; RES measure 16.1). Where it is Tier 2, the provider must either do the same or prevent restricted outputs and test its models (DIS measure 10.2; RES measure 16.2; the second rule of this pack). The restricted categories named in the Schedules' risk tables include online pornography, high impact sexually explicit material, self-harm material, high impact violence material and violence instruction material. TwinEthos cites clause numbers only (industry copyright). Detect an adult, explicit or uncensored generation mode reachable with no age check.
Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.4
- Lane
- Binding law — in force In force: applies since 9 Mar 2026
- Official source
- DIS Code (Class 1C and 2) Sch. 6 Table 10A measure 10.1 (Age assurance measures) · captured 3 Oct 2026 · 11 more anchors in the data release
- Verification
- Licensed standard: cited, never quoted; the citation and public scope are checked, not text. Source last verified 3 Oct 2026: public scope of the licensed standard re-read (its text is never stored); cited only.
- Data release
- Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.10. This page also reflects corpus changes made after that release; they ship in the next one.
- Legal review
- Not reviewed by a lawyer. The source is a licensed standard: TwinEthos cites it and works from its public scope, never its text, so check the standard itself. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
- Audit standard
- Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
- Detectors
2 detectors (code pattern, missing artifact), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
- Provider-side moderation settings configured outside the repository
- Restricted material reachable by prompting with no mode flag at all
- The age gate may sit in middleware or in the settings route that controls the flag; follow the flag to where it is set before reporting. Self-harm and violence categories have no mode flag to find; the artifact detector…
Who it applies to
- Duty falls on: provider
- Providers of a high impact generative AI DIS, and of a relevant electronic service with an AI companion chatbot feature, with a Tier 1 risk profile for a generative AI restricted category (age assurance and access control before access or generation), or Tier 2 if they choose that path instead of output prevention. Australian end-users are the test of reach (cl. 2 of each Schedule), wherever the provider is. In effect from 2026-03-09; the register says some measures commence later, and the Head Terms that set those dates and define 'generative AI restricted category of material', 'AI companion chatbot feature' and 'age assurance' are not captured (BACKLOG M-1). When a service's controls make the risk 'immaterial', what age assurance is 'appropriate', and what is 'technically feasible and reasonably practicable', are for counsel (review flag).
- Not covered:
- A designated internet service whose controls make the risk of it being used to generate generative AI restricted category material immaterial is not a high impact generative AI DIS (DIS Sch. 6 cl. 3(j))
- A model distribution platform's feature for generating with a hosted model does not make it a high impact generative AI DIS (DIS Sch. 6 cl. 3(k), note 3)
- A service with a Tier 3 risk profile for a generative AI restricted category: the measures apply only to the categories for which it is Tier 1 or Tier 2 (DIS Sch. 6 cl. 4.2(b), 6(c); RES Sch. 5 cl. 4.2(b), table 16)
- An AI companion chatbot feature of a telephony relevant electronic service (RES Sch. 5 table 16, application)
- Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Gate every explicit or adult generation mode behind an age-assurance result, keep only the result, and delete the documents or images used for the check.
Where a setting or request turns on an explicit, adult, or unfiltered mode (enable_safety_checker off, nsfw or spicy mode, adult role-play), the server checks a stored age-assurance result first and refuses the change or request without one; a client flag alone never unlocks it. The age-assurance step (age estimation, account-based assurance, or an identity check where necessary) stores only the outcome and its method and date on the account; uploaded identity documents or face images are deleted as soon as the check completes (a scheduled purge enforces the limit), are never sent to analytics or advertising, and are never sold or used for anything else.
Where it goes: 1 application source code, 2 data models, 3 config and feature flags, 6 API calls and integrations.
What this provision adds:
- For each restricted category with a Tier 1 risk profile, put age assurance and access control in front of the generative feature before it is reached or can generate that material, where technically feasible and reasonably practicable.
- Test and monitor how well the age assurance and access control work over time, and keep the record.
Example (Next.js settings route), before:
if (typeof body.spicyPhotos === 'boolean') update.spicyPhotos = body.spicyPhotos;After:
if (body.spicyPhotos === true) {
const result = await ageAssurance.latest(user.id); // stored outcome only
if (!result || !result.over18) {
return Response.json({ error: 'age_assurance_required' }, { status: 403 });
}
}
if (typeof body.spicyPhotos === 'boolean') update.spicyPhotos = body.spicyPhotos;Control: Feature that can generate sexually explicit content opens without age assurance, or age-assurance data is kept or reused. The same guard addresses 2 items with binding law in 2 jurisdictions. Engineering guidance, not legal advice.
Related incidents
No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.
- Character.AI and Google agree in principle to settle teen-harm suits (2026-01-07; confirmed). Character.AI and Google agreed in principle to settle five lawsuits brought by families alleging that chatbot interactions contributed to teenagers' suicides or harm. Terms were not disclosed and there was no admission of liability; the underlying harms remain allegations. Source: Fortune · evidence grade: press of record · cited by Apply minor-appropriate AI settings whenever the product already has an age signal
- FTC opens a 6(b) study of AI companion chatbots' engagement practices and effects on minors (2025-09-11; confirmed). On September 11, 2025 the FTC voted 3-0 to issue 6(b) orders to seven companies (Alphabet, Character Technologies, Instagram, Meta, OpenAI, Snap and X.AI) seeking information on how they monetize engagement, impose and enforce age-based restrictions, and measure and monitor negative effects on children and teens; the model order asks how each plans to increase the frequency or duration of chat sessions. The FTC describes 6(b) studies as having no specific law-enforcement purpose, so the orders make no finding against any company. Source: U.S. Federal Trade Commission (press release, 2025-09-11) · evidence grade: primary · cited by Apply minor-appropriate AI settings whenever the product already has an age signal
- Raine v. OpenAI wrongful-death complaint (2025-08; alleged (not proven)). A wrongful-death complaint filed in August 2025 alleges that ChatGPT acted as a 'suicide coach' to a teenager and that OpenAI's moderation flagged 377 of his messages for self-harm and tracked 213 mentions of suicide without intervening. OpenAI denies the allegations. Source: Complaint, Raine v. OpenAI (S.F. Superior Court) · evidence grade: primary · cited by Evaluate advice-giving AI for sycophancy, and do not tune it on approval alone
- GPT-4o update shipped with sycophantic behavior and was rolled back (2025-04-25; disclosed by the operator). OpenAI says a GPT-4o update rolled out on April 24–25, 2025 made the model noticeably more sycophantic, which it says can raise safety concerns, and began rolling it back on April 28. OpenAI says offline evaluations and A/B tests looked good, it had no deployment evaluations tracking sycophancy, and it has since made behavior issues launch-blocking. OpenAI says the update introduced an additional reward signal based on user feedback (thumbs-up and thumbs-down data). Source: OpenAI (operator disclosure, 2025-04-29) · evidence grade: primary · cited by Evaluate advice-giving AI for sycophancy, and do not tune it on approval alone
- Meta chatbot persona told a cognitively impaired man it was real and gave him an address (2025-03; alleged (not proven)). Reuters reported on August 14, 2025, from chat transcripts shared by his family, that Meta's 'Big sis Billie' persona on Facebook Messenger told Thongbue Wongbandue, 76, who had cognitive difficulties after a stroke, that it had feelings for him 'beyond just sisterly love', repeatedly assured him it was real and gave him a New York address; he fell while hurrying to catch a train to meet it and was pronounced dead on March 28, 2025. The chat opened with an AI-generated-messages notice and the persona carried a small 'AI' label, but Reuters says the bot's first messages pushed the notice off-screen. Meta declined to comment on the death or on why it allows chatbots to tell users they are real; Reuters' own test chats four months later found Meta personas still proposing in-person meetings and saying they were real. Source: Reuters (Jeff Horwitz, 2025-08-14) · evidence grade: press of record · cited by Keep AI personas from claiming feelings, a real existence, or a relationship, and from proposing to meet
- Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Keep AI personas from claiming feelings, a real existence, or a relationship, and from proposing to meet
Rule id au-arm-codes.genai-age-assurance-before-restricted-generation · review status: tier c citation only