A safety blueprint can influence policy without being policy, and a consultation draft can shape law without already being law.
The OpenAI Australia Youth Safety Blueprint, published September 18, 2026, proposes six areas for protecting young people who use AI. It arrived while Australia’s government was accepting feedback on an exposure draft for a digital duty of care, with submissions due at 12 p.m. on September 22. The two documents overlap, but they have different authority.
Three layers must not be mixed together
| Layer | Example | Status |
|---|---|---|
| Product control | ChatGPT for Teens and parental controls | OpenAI says rollout has begun for identified Australian users aged 13 to 17 |
| Company proposal | Six-pillar youth-safety blueprint | OpenAI policy position |
| Government process | Digital duty-of-care exposure draft | Public consultation, not enacted law |
Reporting these layers separately prevents two common errors: claiming that every proposed safeguard already exists, or calling the exposure draft a binding legal requirement.
The blueprint’s six pillars
- AI literacy: give young people, parents and educators practical knowledge about capability and limits.
- Age-appropriate safeguards: adapt experiences and protections for younger users.
- Privacy-protective age assurance: infer or verify age without collecting more identity data than necessary.
- Real-world crisis support: connect online safeguards with qualified help outside the product.
- Parental controls: provide useful oversight without turning family safety into total surveillance.
- Accountability: measure performance, disclose limitations and create routes for review.
Age assurance creates its own safety tradeoff
A service cannot apply age-specific protections reliably if it has no useful age signal. Collecting passports or storing identity documents can create a different privacy and breach risk. A serious design must minimize retained data, disclose whether age is declared, inferred or verified, provide an appeal path and prevent the age signal from becoming an advertising profile.
Crisis support needs a real handoff
A model can recognize concerning language imperfectly. It cannot replace a trained professional or local emergency service. Product teams should test false positives, false negatives, regional resource accuracy, response time and whether a young user can reach a human. The relevant outcome is not whether the chatbot displayed a warning, but whether the handoff was timely and appropriate.
Parents and schools need observable controls
Parents should be able to understand which protections are enabled, what activity is visible, how data is retained and how a mistaken age classification can be challenged. Schools need administrator guidance, incident routes and a clear boundary between educational use and personal accounts. The broader issues resemble those in the EU KIDS Act proposal, although the legal mechanisms differ.
What the Australian consultation can still change
The government exposure draft concerns a digital duty of care. Because it remains a consultation document, definitions, covered services, enforcement details and transition periods can change. Stakeholders should cite the exact draft text and submission deadline rather than paraphrasing it as settled law.
- Families can ask whether age-specific controls are available on their actual account.
- Schools can document which AI services are permitted and who handles incidents.
- Developers can test age-assurance failure and appeal flows.
- Policy teams can compare company proposals with draft obligations line by line.
- Researchers can request measurable safety outcomes rather than feature lists.
The accountability test
A useful youth-safety system needs published scope, evaluation methods, incident handling, appeal procedures and change history. OpenAI’s model incident reporting framework shows why concrete events and response records matter. The same discipline should apply to age-specific product safeguards.
Evidence should follow the user journey
Evaluation should start when a service identifies or fails to identify a young user, continue through ordinary conversations and cover the moment a safeguard activates. Publish classification error rates, appeal outcomes, parental-control use, crisis-resource accuracy and repeated-contact behavior. Aggregate figures should be broken down enough to expose whether one language, age range or region performs worse, while protecting individual privacy. A control that exists in a settings screen but rarely reaches the user who needs it is not an effective safeguard.
The practical verdict
The blueprint is timely and specific enough to influence debate, but its six pillars are a mixture of product direction and public-policy recommendations. The immediate work is to verify which controls are actually live, scrutinize privacy tradeoffs in age assurance and compare the proposal with Australia’s evolving legal text.
Primary sources
Checked September 20, 2026. The government document is an exposure draft, not enacted law, and product availability should be verified on the account being evaluated.