I want to be careful about what kind of post this is, because it isn’t the same kind of post as “Another Day, Another Declaration.” That one was about a newsletter dressed up as a victory lap for evidence that didn’t support it. This one is different. This is the moment the actual strategy becomes visible — not another announcement to catalogue, but the point where you can finally see the shape of the thing the government has been building toward, and ask whether it hangs together.
It doesn’t, and I want to show my working on why.
What actually landed
On 8 September, Anthony Albanese and Anika Wells released draft legislation for a Digital Duty of Care, including an “Australian first” called My Feed, My Way. Social media platforms will have to notify users of a choice: opt in to an algorithmically curated feed, or opt out and see only the accounts they follow, in order. Under-18 protections extend into design features — addictive mechanics, self-esteem effects — and into content categories: eating disorder promotion, misogynistic material, pornography, crime glorification, content causing serious mental health distress. eSafety gets removal powers over nudify apps, a streamlined cyber-abuse scheme, and — this is the part with actual teeth — the power to use registered researchers and its own investigators to test, directly, what platforms are serving users, rather than relying on platforms to self-report. Penalties run to $109.2 million. Legislation is promised before year’s end.
Read on its own, it’s a reasonable, even overdue, piece of platform accountability. Read in sequence, it’s the fourth or fifth distinct policy instrument Australia has produced on this issue in under two years, and each one was built to solve the problem the previous one created or failed to solve. That’s the part worth sitting with.
I wanted to ask a few questions even at this point so I’ll drop then in here as a by way and then get back in track with the analysis via the theory of change discussion.
Who the “registered/approved researchers” actually are — as far as anyone can currently say:
The exposure draft’s own language is thin: “approved researchers, such as those from an Australian university” get two things — access to platform data for online-safety-related research, and the power to run sock-puppet testing. That’s it. No accreditation body, no criteria, no application process has been reported anywhere yet. This is functionally Australia’s version of the EU DSA’s Article 40 “vetted researcher” scheme, which is worth naming as a direct comparator, because that scheme’s actual track record is a caution, not a template to feel reassured by: EU vetted-researcher status is notoriously slow to grant, narrowly scoped, and has been criticised by researchers themselves for how little data platforms have actually had to hand over once approved. If Australia copies the label without copying — or improving on — the implementation detail, “approved researcher” risks becoming exactly the kind of unresolved gap Josh Taylor flagged with the opt-out mechanism itself: real on paper, undefined in practice, left for platforms and regulators to fight out later.
On the AIO —parallel timing
A Conversation piece published back in July — “Australia wants a ‘digital duty of care’. But how will we check what Big Tech is doing?” — presented the argument from Australian Digital Media researchers that the duty of care needs an “ecosystem of observability” combining three things: regulatory powers to compel platform data, independent research infrastructure (data donation, browser/mobile measurement, secure research environments), and stronger individual rights for Australians to access, download and donate their own platform data. They named the AIO directly as “one model for this infrastructure.” So this isn’t two separate efforts converging by coincidence — it’s the same research network pushing on two levers at once: build the bottom-up data-donation infrastructure regardless of what parliament does, and publicly campaign for the top-down regulatory access powers that just showed up in the exposure draft two months later.
During the same week’s coverage: Chanel Contos’s National Press Club appearance and the NSW Government’s urgent September 4 roundtable following the Sydney schoolboy assault allegations are being cited directly by other commentary as part of the pressure that shaped this exposure draft — her “23 minutes to misogynistic content” statistic is functioning as the kind of concrete evidence the researcher-access provisions are explicitly meant to make independently verifiable going forward, rather than something advocates have to keep re-measuring themselves via burner-phone experiments.
A theory of change that was available, and wasn’t used
Now, getting back to where we were in the chronological chain of events. Here’s the thing that gets lost every time this gets reported as a fresh initiative: the design-first version of this reform already existed, in 2024, before the account ban was legislated. Zoe Daniel’s private member’s bill on platform duty of care predates the Social Media Minimum Age Act. It was left to lapse. The government reached for the ban instead — drafted, introduced and passed in under two weeks, with a 24-hour public comment window, timed to a Mother’s Day announcement and a News Corp campaign, arriving in the last sitting week before an election.
I’ve written before about what that sequencing choice cost in evidentiary terms. What I want to name now is what it cost architecturally. Once the ban passed, an entire enforcement apparatus grew up around it: the Phase 2 industry codes, the age-assurance vendor contracts, the trusted-provider lists, eSafety’s document-demand powers reaching into third-party verification companies. That apparatus is not neutral scaffolding sitting empty, waiting for a better policy to move in. It has vendors with revenue tied to its continuation, a regulator whose newly expanded enforcement muscle (the Online Safety Amendment Bill, moving through parliament the same week) reaches further into that same verification paradigm, and a political constituency built around “world-first” account restriction as the signature achievement.
So when the duty of care — the reform actually aimed at design, not access — finally arrives, it doesn’t land in an empty room where design-first thinking can shape the whole architecture from scratch. It lands in a room where surveillance-and-verification is already the operational default, and has to be built to coexist with it rather than replace it. This isn’t a coherent strategy unfolding in the right order. It’s a good instrument arriving after a worse one has already poured the foundation, and having to accommodate the foundation rather than correct it.
The mechanism undercuts its own justification
There’s a second problem, sitting inside the bill itself rather than in its timing. The government’s language around My Feed, My Way is explicitly universalist — Wells frames it as “basic standards for the online products we use every day,” alongside cars, toys, food. That’s inclusive-design logic: build the protection into the system for everyone, rather than trying to identify and specially protect a vulnerable subset. It’s good theory. Universal design works because the protected state is the automatic one — nobody has to find it, understand it, or activate it. Curb cuts don’t require a wheelchair user to request one.
But My Feed, My Way is an opt-out, not an opt-in. The algorithmically optimised, high-engagement default stays exactly where it is; the protective state is the thing a user has to notice, understand, and deliberately choose. We already know what that produces, because we’ve watched the experiment run. Meta’s own court testimony in the US put uptake of its “Take a Break” feature — designed to interrupt exactly the kind of compulsive scrolling this bill is meant to address — at 1.8%. The EU has offered an algorithm opt-out since 2023, and a Dutch court had to order Meta to stop silently reverting users back to the algorithmic feed on every relaunch, years after nominal compliance. If the justification for going broad rather than narrow is genuinely inclusive-design thinking, the logically consistent implementation is an opt-in default, which is what the Greens and Chanel Contos have been arguing for. The government chose the version that photographs the same way in a press release but almost certainly won’t behave the same way in practice.
Who this doesn’t reach, and who’s left holding it
And then there’s the population question, which is the one that should worry anyone thinking about this as a child-safety measure rather than a general consumer-choice one. The opt-out applies to users over 16. The government’s own account ban was supposed to mean under-16s aren’t the audience for this at all — they’re not meant to be logged in, so the question of their feed algorithm shouldn’t arise.
Except eSafety’s own evaluation data says otherwise. Three months in, account ownership among under-16s had fallen from 52.4% to 42.1% — real, but partial — and of the children who kept accounts, half said the platform simply never asked them to verify their age. Not evasion. No prompt at all. Independently, the University of Newcastle’s BMJ study found more than 85% of under-16s still using restricted platforms at the same three-month mark. So the population this bill’s under-18 content protections are meant to reach isn’t a hypothetical edge case sitting outside the ban’s success. It’s the substantial majority the ban didn’t actually remove — now relying on content-level protections that exist, but on an opt-out mechanism that structurally doesn’t extend to them, because they’re either logged out (where Wu’s Nature Human Behaviour piece already flagged the recommendation system may be less safe, not more, absent any restricted mode) or logged in on an account the platform never checked.
Meanwhile the adults meant to be managing all of this — parents and teachers — have less visibility than they had before, not more. eSafety’s own evaluation found parental awareness of children’s social media use actually declined after the ban took effect, concentrated among parents of girls and 10–12 year olds. Teachers, who inherit whatever happened in a student’s feed the moment it walks into a classroom the next morning, get no new tools at all in this bill — the digital literacy and relational-education infrastructure that would let schools and families actually build capability, rather than just manage fallout, isn’t part of the package. It’s the same gap Lisa Given flagged about the earlier duty of care consultation: real teeth on paper, aimed at platforms, with nothing resourced for the people standing between the platform and the child.
The generational bet nobody has actually defended
There’s a longer-run theory of change sitting underneath all of this that almost never gets said out loud, and I think it deserves to be dragged into the open, because I’m not convinced it survives contact with the evidence we already have.
The theory goes something like this: the ban won’t look like it’s working on the generation that’s already on these platforms, because they were socialised into algorithmic social media before the restriction existed, and restriction always looks like resistance in its first cohort. But the next generation — Gen Alpha, kids who are eight, nine, ten right now — will turn 16 having never legally held an account. For them, the age gate won’t be an imposition on an established habit. It’ll just be an unremarkable fact of childhood, the way not being allowed to drive at twelve is. Robinson, La Sala and Harrison named this directly in their 2025 title: is this a “seatbelt moment” — a restriction that looks costly and contested at first and becomes invisible, uncontested background norm within a generation — or a missed opportunity dressed up as one?
It’s a coherent theory. Seatbelts really did work that way: resistance was highest among drivers who’d learned to drive without them, and uptake became close to automatic once a full generation had never known driving any other way. If social media restriction follows the same curve, today’s dismal compliance numbers — 85%+ of under-16s still using restricted platforms, half of retained accounts never even prompted for age checks — aren’t a verdict on the policy. They’re what a first cohort always looks like, and the real test is what a fully Gen Alpha 15-year-old’s relationship to these platforms looks like in 2032.
But I want to push on two things before I let that theory do any work, because right now it’s operating as an unexamined assumption rather than something anyone has actually argued for or is measuring.
The first is empirical, and it’s sitting in plain sight in the argument over whether “brainrot” belongs to Gen Z or Gen Alpha. The honest answer is both, and how it belongs to both is the point: Gen Z, with full algorithmic platform access, generated and refined this content natively — the irony, the absurdist compression, the in-group signalling. Gen Alpha, meanwhile, absorbed an enormous amount of it into daily vocabulary and offline culture without needing platform accounts of their own to do it. Skibidi Toilet, sigma, rizz — this is a nine-year-old’s vocabulary now, transmitted through older siblings, playground repetition, YouTube (which sits partly outside the restriction architecture), and family devices, not through a personal, algorithmically curated feed. That’s a direct empirical challenge to the seatbelt theory’s core mechanism. Seatbelt norms shifted because the behaviour itself — driving unbelted — has no meaningful peer-transmission pathway once you’re not behind a wheel. Platform culture has an enormous one. Excluding a nine-year-old from an Instagram account doesn’t wall them off from the platform’s cultural output; it just changes the delivery mechanism from direct and individually curated to lateral and peer-mediated. If the goal was a generation genuinely insulated from what these platforms produce, the account ban may be solving the wrong layer of the problem entirely — the content diffuses regardless of who’s logged in.
The second problem is normative, and it’s the sharper one: even if the seatbelt theory worked exactly as advertised, is a childhood spent in what we might call a stigmatised relationship to social media — access as illicit, policed, something you get around rather than something you’re taught to navigate — actually the outcome we want? We have a template for what stigma-based restriction does to adolescent behaviour, from decades of underage drinking and smoking policy, and it isn’t uncomplicated normalisation. It’s secrecy from the adults meant to be guiding you — which is precisely what eSafety’s own data already shows happening, with parental awareness of children’s social media use declining, not rising, since the ban took effect. It’s status economies built around successful circumvention rather than around competent use — TikTok how-to guides on evading TikTok’s own age gate, published on the platform being regulated, are not a normalisation success story, they’re the underground-economy version of the same dynamic. And it forecloses exactly the capability-building the digital literacy argument I made above is trying to protect. A generation that grows up treating platform access as contraband to be smuggled rather than a tool to be taught isn’t obviously better prepared for the platforms they’ll use as adults — a cliff-edge from total exclusion to unrestricted access at 16, with no graduated exposure and no explicit skill-building in between, is a pedagogy problem dressed up as a public health win.
And here’s what makes this a genuine theory-of-change problem rather than just a debate to have later: nobody is actually measuring which of these dynamics is occurring. eSafety’s longitudinal evaluation tracks account status, usage duration, and self-reported wellbeing. It isn’t set up to track cultural diffusion, peer-transmission of platform content among excluded users, or whether the relationship young people have to these platforms is becoming one of literacy or one of stigma. We’re running a generational bet — quietly assuming the seatbelt curve will apply, structuring policy timelines around a 2027–2028 review window that presumes it — without building the instruments that would tell us, a decade from now, whether we bet on the right mechanism at all.
A brief detour through brain rot, because it’s not really a detour
I want to pause on something that looks like a side issue and isn’t, because it’s sitting in the same water as everything above it, and because I keep watching it get used as if it settles an argument it can’t actually settle.
“Brain rot” was Oxford’s word of the year for 2024, and since then it’s been doing an enormous amount of unexamined work in exactly this debate. The trouble is that nobody using the term is using it to mean the same thing. Pull apart the ways it’s actually deployed and you get at least four distinct referents wearing one label: a content genre (the singing toilets, the AI-slop, the absurdist short-form video); a slang register that circulates alongside that genre and, tellingly, migrates into offline speech among children who’ve never held a personal account — which is itself a data point against the idea that account restriction meaningfully insulates a generation from platform culture, since the vocabulary clearly doesn’t need an account to travel; a subjective experiential state, the “fogged-out, low-selectivity” feeling Maxi Heitmayer’s Gen Z interview subjects describe, in which the content is a response to an already-depleted state rather than its cause; and, most recently, a proposed clinical construct — a psychometric “Brain Rot Scale,” explicitly modelled on substance-addiction neurobiology, complete with subscales for Attention Dysregulation, Digital Compulsivity and Cognitive Dependency, tested on an Egyptian convenience sample and explaining a modest 35% of variance, with the authors themselves conceding it hasn’t been validated against any existing measure of problematic internet use. Thoreau, who coined the term in 1854, meant something different again: not an individual affliction at all, but a society choosing simple ideas over complex ones.
This is Ferguson’s construct balkanization problem, which I cited earlier in relation to Rausch and Haidt, showing up again in a completely different corner of the same debate: a folk category getting formalised into something that reads as diagnostic before anyone has established it’s distinct from constructs we already have names for. A scale with excellent internal reliability tells you the instrument is internally consistent. It doesn’t tell you “brain rot” is a real, discrete thing rather than a relabelling of attention difficulties, compulsive checking and existing problematic-use patterns that already have measures.
And it matters which definition is doing the work, because they don’t point toward the same account of what’s happening, let alone the same fix. Compare three recent, more careful pieces of evidence side by side. The passive-sensing study on adolescent phone use I wrote about last week found that low mood predicts more scrolling the next day — a general, content-agnostic disengagement response, consistent with mood management theory: feeling bad, reach for something that costs nothing. Doomscrolling, the pandemic-era construct, is narrower and arguably runs on a different engine entirely — purposeful seeking of threat-relevant, distressing content, closer to anxious vigilance than numbing, a coping strategy that backfires by compounding the very anxiety it’s trying to manage. And Heitmayer’s brain rot, on his own account, sits closer to the first mechanism than the second: his participants describe seeking out content that makes no demand and carries no threat, the near-opposite of doomscrolling’s compulsive checking of bad news. Three different psychological stories, three different underlying mechanisms, one increasingly interchangeable vocabulary — and each new content cycle seems to arrive with a fresh label rather than a resolved question about whether the last one was even right.
Here’s the useful, if slightly deflating, thing this detour actually tells us. Ask what any of this changes about the case for something like My Feed, My Way, and the honest answer is: less than the discourse implies. The strongest evidence for regulating engagement-optimised feeds doesn’t need brain rot, in any of its four senses, to be real. It’s sitting in Meta’s own 2020 internal research: when the company ran chronological feeds experimentally, users got bored faster and left for competitors, which is about as clean a demonstration as exists that the algorithmic ranking isn’t neutral scaffolding, it’s the thing actively manufacturing the engagement everyone is worried about. That evidence stands regardless of whether “brain rot” turns out to be attention dysregulation, mood-driven disengagement, cultural slang, or nothing distinct at all. Which means that when brain rot gets invoked as the reason we need to act — rather than the algorithmic economics standing on their own — it isn’t adding evidentiary weight, it’s borrowing urgency from a construct nobody has actually pinned down. That’s precisely the move I flagged at the top of this post: evidence handled like a fridge magnet, taken out of the room it lives in and put somewhere it can do a different job. The tobacco analogy one of Heitmayer’s own interview subjects reached for — regulate the industry, don’t just tell the individual to smoke less — doesn’t require anyone to have first proven brain rot is a diagnosable condition. It only requires the engagement economics to be what they demonstrably already are.
All over the shop, precisely
So: is this a coherent theory of change finally showing its hand? I don’t think that’s quite right either, and I want to be precise about the claim I’m making, because “incoherent” undersells it. There have been several theories of change here, each internally sensible on its own terms, arriving in the wrong order and now stacked on top of each other rather than replacing one another. The ban’s theory: exclude the population, protect by absence. The industry codes’ theory: verify identity, gate by age. The duty of care’s theory: fix the system, protect by design, regardless of who’s in it. And running underneath all three, unstated and untested: the seatbelt theory, betting that generational turnover will eventually make the first three retroactively look right, on a timeline nobody has committed to actually measuring. Each of these is individually defensible. None of them were built with the others in mind, because none of them were legislated — or even articulated — in the order a single coherent strategy would have chosen. Design-first was available, and shelved, in 2024.
What we’re watching now isn’t a strategy unfolding. It’s a government retrofitting the reform it should have started with onto infrastructure built by the reform it reached for instead, while badging the least structurally demanding piece of the retrofit — a toggle most users won’t find and Meta’s own numbers suggest they wouldn’t use if they did — as the headline. The eSafety document-demand powers, the researcher testing authority, the requirement that platforms document and maintain their harm-mitigation measures: that’s the part of this bill actually shaped by lessons learned, including from the EU’s own enforcement failures. It’s riding into parliament on the opt-out’s press cycle because it isn’t sellable on its own.
I said in July that it was too early to call the ban a failure, and that cuts both ways — too early to call it a success, too. I’ll say something similar here: it’s too early to know whether the duty of care’s substantive parts survive Senate negotiation intact, or get diluted the way the penalty language already seems to have moved between May’s turnover-linked formula and September’s flat cap. But it isn’t too early to say the sequencing was a choice, not an accident, and that the bill in front of parliament right now is being asked to do the work of correcting an architecture it had no hand in designing.