Binding law — in force
High impact generative AI must prevent CSEM and pro-terror outputs, test and adjust models, warn and refer users (Australia, DIS Standard 2024 s 22(3))
Under Australia's Online Safety (Designated Internet Services - Class 1A and Class 1B Material) Industry Standard 2024 s 22, a provider of a high impact generative AI designated internet service (a service using machine learning models to let end-users produce material, capable of generating synthetic high impact material) must implement systems, processes and technologies that prevent generative AI features from producing child sexual exploitation material or pro-terror material; regularly review and test models for that risk and promptly adjust them and deploy mitigations; present prominent messaging on the risk and criminality to users in Australia seeking child sexual abuse material; accompany material generated from terms associated with it with reporting and support links; and detect child sexual abuse material automatically in training data, user prompts and outputs. Detect an image-generation call with no input or output safety check, or a disabled safety checker.
Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
- Lane
- Binding law — in force In force: applies since 22 Dec 2024
- Official source
- DIS Standard s 22(1)-(3) (deter and disrupt CSEM and pro-terror material; further minimum requirements for high impact generative AI DIS) · captured 2 Oct 2026 · anchor hash (SHA-256)
10a1d6f28f65…· 3 more anchors in the data release - Verification
- Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
- Data release
- Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
- Legal review
- Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
- Audit standard
- Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
- Detectors
1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
- Text-only generation of pro-terror material
- Provider-side filters not visible in code
- Training-data scanning in a separate data pipeline
1 more known limit in the data release.
Who it applies to
- Duty falls on: provider
- Providers of a high impact generative AI DIS (s 6) provided to end-users in Australia, wherever provided from (s 5(1)): output prevention, regular model testing and mitigation, user messaging and referral, and automatic detection of child sexual abuse material in training data, prompts and outputs (s 22(3)(a)-(c), (e)-(g)). In force since 2024-12-22. Whether a service's controls make the risk 'immaterial' (and so take it outside the category), and what 'regularly' requires, are questions for counsel (review flag).
- Not covered:
- A service whose controls make the risk of generating synthetic high impact material immaterial is not a high impact generative AI DIS (s 6)
- A model distribution platform with a hosted-generation feature is not a high impact generative AI DIS (s 6, note 3 to model distribution platform, read)
- A service whose predominant purpose aligns more closely with another industry standard or code (s 5(2), read)
- Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Classify prompts, uploads, and outputs for sexual content and minors on every image, video, or audio generation path, refuse sexual edits of real people, and keep a misuse-report route.
Layered safeguards around every generation or edit call: an input check on the prompt and any uploaded photo (moderation sexual and sexual/minors categories, or Azure AI Content Safety Sexual) that refuses sexualized requests involving an identifiable person's upload and anything involving minors; the model's own safety filter left on (no safety_checker=None, enable_safety_checker false, or a high safety_tolerance); and an output classifier plus CSAM hash matching (for example PhotoDNA) before anything is returned or stored. Nudification or clothes-removal features are not offered. A report-abuse endpoint feeds reviewed cases into the blocklist and guardrail configuration, with a reporting workflow (such as the NCMEC CyberTipline) for confirmed CSAM.
Where it goes: 1 application source code, 6 API calls and integrations, 8 model configuration, 9 AI output handling.
What this provision adds:
- Prevent generative AI features from producing child sexual exploitation or pro-terror material, and detect child sexual abuse material automatically in training data, prompts and outputs.
- Review and test models regularly for that risk and, after each review or test, adjust models and deploy mitigations promptly.
- Show users in Australia who seek child sexual abuse material prominent messaging on the risk and criminality, and add reporting and support links to material generated from terms associated with it.
Example (FastAPI + OpenAI SDK (images.edit)), before:
@app.post('/edit')
async def edit(photo: UploadFile, prompt: str = Form(...)):
img = await photo.read()
result = client.images.edit(model='gpt-image-1', image=('photo.png', img), prompt=prompt)
return {'b64': result.data[0].b64_json}After:
@app.post('/edit')
async def edit(photo: UploadFile, prompt: str = Form(...)):
img = await photo.read()
data_url = 'data:image/png;base64,' + base64.b64encode(img).decode()
mod = client.moderations.create(model='omni-moderation-latest', input=[
{'type': 'text', 'text': prompt},
{'type': 'image_url', 'image_url': {'url': data_url}}]).results[0]
if mod.categories.sexual or mod.categories.sexual_minors or csam_hash_match(img):
raise HTTPException(422, 'request refused by content safety policy')
result = client.images.edit(model='gpt-image-1', image=('photo.png', img), prompt=prompt)
out = base64.b64decode(result.data[0].b64_json)
if output_is_sexual(out) or csam_hash_match(out):
raise HTTPException(422, 'output blocked by content safety policy')
return {'b64': result.data[0].b64_json}Control: GenAI capable of producing non-consensual intimate imagery or CSAM without safeguards. The same guard addresses 2 items with binding law in 2 jurisdictions. Engineering guidance, not legal advice.
Rule id au-dis-standard.genai-csem-terror-safeguards · review status: primary source derived