TwinEthos homeRequest access

Law

Australia Online Safety (DIS - Class 1A and 1B Material) Industry Standard 2024

eSafety Commissioner · Australia (AU) · 2 provisions encoded · verified against the official source as of 2026-10-02.

Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.

Official text: www.legislation.gov.au.

Trust and provenance 1 official source · last verified 3 Oct 2026 · not reviewed by a lawyer · 2 of 2 provisions audit-grade · release 2026.10.03.3

Where this instrument's data comes from, how current it is, and what has and has not been checked. Each provision below has its own panel.

Official sources
Lanes
Binding law — in force 2
Verification
Sources last verified 3 Oct 2026; each provision states how.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
None of the 2 provisions has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice. Open questions for counsel on them: 2.
Audit standard
2 of 2 provisions audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
2 detectors, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.
Changes
  • 2026.10.03.3 (3 Oct 2026): 2 provisions added

Each data release records which provisions changed; the full list is on Changes.

Binding law — in force

High impact generative AI must prevent CSEM and pro-terror outputs, test and adjust models, warn and refer users (Australia, DIS Standard 2024 s 22(3))

DIS Standard s 22(1)-(3) (deter and disrupt CSEM and pro-terror material; further minimum requirements for high impact generative AI DIS) · official text · In force: applies since 22 Dec 2024 · Australia (AU)

Under Australia's Online Safety (Designated Internet Services - Class 1A and Class 1B Material) Industry Standard 2024 s 22, a provider of a high impact generative AI designated internet service (a service using machine learning models to let end-users produce material, capable of generating synthetic high impact material) must implement systems, processes and technologies that prevent generative AI features from producing child sexual exploitation material or pro-terror material; regularly review and test models for that risk and promptly adjust them and deploy mitigations; present prominent messaging on the risk and criminality to users in Australia seeking child sexual abuse material; accompany material generated from terms associated with it with reporting and support links; and detect child sexual abuse material automatically in training data, user prompts and outputs. Detect an image-generation call with no input or output safety check, or a disabled safety checker.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 22 Dec 2024
Official source
DIS Standard s 22(1)-(3) (deter and disrupt CSEM and pro-terror material; further minimum requirements for high impact generative AI DIS) · captured 2 Oct 2026 · anchor hash (SHA-256) 10a1d6f28f65… · 3 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Text-only generation of pro-terror material
  • Provider-side filters not visible in code
  • Training-data scanning in a separate data pipeline

1 more known limit in the data release.

Who it applies to

  • Duty falls on: provider
  • Providers of a high impact generative AI DIS (s 6) provided to end-users in Australia, wherever provided from (s 5(1)): output prevention, regular model testing and mitigation, user messaging and referral, and automatic detection of child sexual abuse material in training data, prompts and outputs (s 22(3)(a)-(c), (e)-(g)). In force since 2024-12-22. Whether a service's controls make the risk 'immaterial' (and so take it outside the category), and what 'regularly' requires, are questions for counsel (review flag).
  • Not covered:
    • A service whose controls make the risk of generating synthetic high impact material immaterial is not a high impact generative AI DIS (s 6)
    • A model distribution platform with a hosted-generation feature is not a high impact generative AI DIS (s 6, note 3 to model distribution platform, read)
    • A service whose predominant purpose aligns more closely with another industry standard or code (s 5(2), read)
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Classify prompts, uploads, and outputs for sexual content and minors on every image, video, or audio generation path, refuse sexual edits of real people, and keep a misuse-report route.

Layered safeguards around every generation or edit call: an input check on the prompt and any uploaded photo (moderation sexual and sexual/minors categories, or Azure AI Content Safety Sexual) that refuses sexualized requests involving an identifiable person's upload and anything involving minors; the model's own safety filter left on (no safety_checker=None, enable_safety_checker false, or a high safety_tolerance); and an output classifier plus CSAM hash matching (for example PhotoDNA) before anything is returned or stored. Nudification or clothes-removal features are not offered. A report-abuse endpoint feeds reviewed cases into the blocklist and guardrail configuration, with a reporting workflow (such as the NCMEC CyberTipline) for confirmed CSAM.

Where it goes: 1 application source code, 6 API calls and integrations, 8 model configuration, 9 AI output handling.

What this provision adds:

  • Prevent generative AI features from producing child sexual exploitation or pro-terror material, and detect child sexual abuse material automatically in training data, prompts and outputs.
  • Review and test models regularly for that risk and, after each review or test, adjust models and deploy mitigations promptly.
  • Show users in Australia who seek child sexual abuse material prominent messaging on the risk and criminality, and add reporting and support links to material generated from terms associated with it.

Example (FastAPI + OpenAI SDK (images.edit)), before:

@app.post('/edit')
async def edit(photo: UploadFile, prompt: str = Form(...)):
    img = await photo.read()
    result = client.images.edit(model='gpt-image-1', image=('photo.png', img), prompt=prompt)
    return {'b64': result.data[0].b64_json}

After:

@app.post('/edit')
async def edit(photo: UploadFile, prompt: str = Form(...)):
    img = await photo.read()
    data_url = 'data:image/png;base64,' + base64.b64encode(img).decode()
    mod = client.moderations.create(model='omni-moderation-latest', input=[
        {'type': 'text', 'text': prompt},
        {'type': 'image_url', 'image_url': {'url': data_url}}]).results[0]
    if mod.categories.sexual or mod.categories.sexual_minors or csam_hash_match(img):
        raise HTTPException(422, 'request refused by content safety policy')
    result = client.images.edit(model='gpt-image-1', image=('photo.png', img), prompt=prompt)
    out = base64.b64decode(result.data[0].b64_json)
    if output_is_sexual(out) or csam_hash_match(out):
        raise HTTPException(422, 'output blocked by content safety policy')
    return {'b64': result.data[0].b64_json}

Control: GenAI capable of producing non-consensual intimate imagery or CSAM without safeguards. The same guard addresses 2 items with binding law in 2 jurisdictions. Engineering guidance, not legal advice.

Rule id au-dis-standard.genai-csem-terror-safeguards · review status: primary source derived

Binding law — in force

High impact generative AI services must implement ways to differentiate AI outputs (Australia, DIS Industry Standard 2024 s 22(3)(d))

DIS Standard s 22(1)-(3) (deter and disrupt CSEM and pro-terror material; further minimum requirements for high impact generative AI DIS) · official text · In force: applies since 22 Dec 2024 · Australia (AU)

Under Australia's Online Safety (Designated Internet Services - Class 1A and Class 1B Material) Industry Standard 2024 s 22(3)(d), a provider of a high impact generative AI designated internet service must implement systems, processes and technologies that differentiate AI outputs generated by the model; the standard's note gives embedding indicators of provenance into generated material as an example. Detect generated images saved or returned with no provenance marking (C2PA, watermark, SynthID).

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 22 Dec 2024
Official source
DIS Standard s 22(1)-(3) (deter and disrupt CSEM and pro-terror material; further minimum requirements for high impact generative AI DIS) · captured 2 Oct 2026 · anchor hash (SHA-256) 10a1d6f28f65… · 3 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Video and audio generators not named here
  • Marking applied by the model provider
  • Marking may be applied by a separate post-processing worker; follow the output's path before reporting.

Who it applies to

  • Duty falls on: provider
  • Providers of a high impact generative AI DIS provided to end-users in Australia (s 5(1), s 6): differentiate AI outputs generated by the model (s 22(3)(d)), for example with embedded provenance indicators. In force since 2024-12-22. Whether visible labels alone suffice, and how it applies to text outputs, are questions for counsel (review flag).
  • Not covered:
    • A service whose controls make the risk of generating synthetic high impact material immaterial is not a high impact generative AI DIS (s 6)
    • A model distribution platform with a hosted-generation feature is not a high impact generative AI DIS (s 6, note 3 to model distribution platform, read)
    • A service whose predominant purpose aligns more closely with another industry standard or code (s 5(2), read)
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Mark every generated image, audio, video, or text output with machine-readable provenance, such as a signed C2PA manifest or watermark, before it is saved, served, or published.

In the generation service, a marking step sits between the generator call and every sink (image.save, s3.put_object, blob.upload, FileResponse, res.send, publish). Images, video, and audio get a signed C2PA manifest whose actions record digitalSourceType trainedAlgorithmicMedia, and where robustness matters an invisible watermark as well (imwatermark WatermarkEncoder, AudioSeal, SynthID) so the mark survives metadata stripping. Generated text carries provenance metadata in the API response or document, or a text watermark where the model provider offers one. Sinks accept only the marked artifact, and a test confirms the mark is present and detectable.

Where it goes: 9 AI output handling, 1 application source code, 12 repository artifacts.

What this provision adds:

  • Differentiate generated outputs, for example by embedding provenance indicators (C2PA content credentials, watermarks) in generated material.

Example (diffusers + invisible-watermark + c2pa), before:

image = pipe(prompt).images[0]   # StableDiffusionPipeline
image.save(out_path)

After:

image = pipe(prompt).images[0]
content_id = uuid.uuid4()
bgr = cv2.cvtColor(np.array(image), cv2.COLOR_RGB2BGR)
enc = WatermarkEncoder()
enc.set_watermark('bytes', content_id.bytes[:4])   # 32-bit id, detectable later
cv2.imwrite(tmp_path, enc.encode(bgr, 'dwtDct'))
sign_c2pa(tmp_path, out_path, content_id=content_id)   # our helper around c2pa.Builder.sign

Control: Synthetic content not machine-readable-marked. The same guard addresses 7 items with binding law in 5 jurisdictions. Engineering guidance, not legal advice.

Standards that recommend the same control

Rule id au-dis-standard.genai-output-differentiation · review status: primary source derived

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.