Algorithm opt-out laws sound good until you ask who determines what’s in and what’s out

Australia wants to let you opt out of social media algorithms — but the real question is who gets to decide what a safe feed looks like.

Regulator with oversized magnifying glass examining complex machine representing algorithmic systems
Regulator with oversized magnifying glass examining complex machine representing algorithmic systems

The government's proposed digital duty of care legislation promises Australians something that sounds genuinely appealing: the right to escape the algorithmic feed, to opt out of the machine that decides what you see and when you see it. It is a reasonable instinct. Recommender algorithms are powerful, often opaque, and there is real evidence they can amplify harmful content. The problem is not the instinct. The problem is what happens when you translate that instinct into law — because somebody has to draw the line between "harmful" and "allowed," and the legislation does not make clear that somebody is you.

Bottom LineAustralia's proposed digital duty of care laws would give users the option to opt out of social media recommendation algorithms, but the real power in the framework sits not with users but with regulators and politicians who will decide what counts as harmful, what platforms must suppress, and what a "safe" feed looks like — and those decisions will be made largely out of public view, enforced against systems nobody in government can actually inspect.

The opt-out is a category error dressed as a privacy setting

Start with the opt-out mechanism itself. On the surface it looks like an expansion of user choice. In practice, as Curtin University internet studies professor Tama Leaver points out, it raises an immediate and unanswered question: which algorithm, exactly? Instagram alone runs at least three distinct recommender systems — the main feed, stories, and reels — each doing a different job. Opting out of "the algorithm" on a platform like that is not a coherent action. It is a category error dressed up as a privacy setting. The legislation may well produce a pop-up message that gives users the feeling of control while delivering very little of the substance.

That observation connects to a broader structural problem with opt-out models. As The Bearing has covered in detail, the real leverage in algorithmic reform sits with defaults, not with opt-outs. If you want to change what most users experience, you change what they get before they touch a single setting. Leaver himself notes that a chronological feed by default — requiring users to actively opt in to algorithmic curation — would be a far more powerful intervention. The government did not choose that. The option it chose preserves the algorithm as the default and adds a rarely-used escape hatch. Platforms will be relieved.

"Psycho-social harm" is a phrase wide enough to drive a truck through

Now to the part that matters more. Alongside the opt-out provision, the legislation places a duty on platforms to "identify and manage risks" around content — including content the law will designate as causing "psycho-social harm" in categories covering body image, bullying, and a handful of others. For under-18s, the list extends further. Breaches carry fines of more than $100 million.

The most important question is: Who decides what goes on that list? Not users. Not courts, initially. A regulator, operating under ministerial direction, working from categories that will be defined in delegated legislation rather than the primary bill. "Psycho-social harm" is a phrase wide enough to drive a truck through. Content about disordered eating is one thing. But the same definitional machinery that catches that content can catch information about diet, about gender, about political candidates, about protest. The word "harmful" has never in the history of content regulation stayed neatly inside the boundaries its authors originally drew.

The word "harmful" has never in the history of content regulation stayed neatly inside the boundaries its authors originally drew.

Regulators cannot meaningfully inspect the systems they are being asked to police

The enforcement problem makes this worse, not better. Algorithms are not transparent systems. They are the product of billions of micro-decisions made by models trained on data that no outside party has seen, producing outputs that even the platforms' own engineers cannot fully predict or explain. The eSafety Commissioner, under these laws, would be tasked with verifying compliance with rules about what those algorithms amplify. The image of a regulator with a magnifying glass pressed against an opaque wall is not too far off the mark. Leaver acknowledges the social media ban already ran into exactly this problem: companies were asked to comply but not required to explain how. The new laws gesture at researcher and eSafety access to compliance information, but the detail is not yet public and the track record is not encouraging.

The case for some form of duty of care on digital platforms is legitimate. Platforms have real power over information environments and have, in documented cases, amplified content they knew was harmful because engagement was profitable. That is a genuine problem worth addressing.

But a law that hands definitional power over "harm" to regulators, applies it to systems those regulators cannot meaningfully inspect, and wraps it all in the language of user choice without delivering much of the substance is not a careful solution to that problem. It is the architecture of overreach wearing the branding of safety. The opt-out is for you. The decisions about what you can see are for someone else.


Sources

The Conversation — Proposed laws would let you opt out of social media algorithms. An expert explains

The Bearing — Algorithm opt-in is really a platform opt-out

Frequently Asked Questions

What does Australia's digital duty of care legislation actually do?
The proposed laws require social media platforms to give users the option to opt out of recommendation algorithms, and place a duty on platforms to identify and manage risks around content designated as causing 'psycho-social harm.' Breaches carry fines of more than $100 million. The categories of harmful content will be defined not in the primary legislation but in delegated instruments, meaning regulators and ministers will have significant latitude to expand them over time.

Why is opting out of a social media algorithm more complicated than it sounds?
Platforms like Instagram run multiple distinct recommender systems simultaneously — separate algorithms govern the main feed, stories, and reels. Opting out of 'the algorithm' is not a coherent action on systems structured this way. The legislation is likely to produce a settings toggle that gives users a sense of control without meaningfully changing what most of them see.

Why is an opt-out system weaker than an opt-in system?
Because most users never change default settings. If the algorithm is the default, the overwhelming majority of users will remain inside it regardless of whether an opt-out exists. Changing the default to a chronological feed — and requiring users to actively opt in to algorithmic curation — would affect nearly every user on the platform, not just the small fraction who adjust settings.

Who decides what counts as harmful content under the new laws?
Not courts, and not users. The harm categories will be set by a regulator operating under ministerial direction, using definitions established in delegated legislation rather than the primary bill. This means the scope of what platforms must suppress can be expanded with minimal parliamentary oversight.

Can the eSafety Commissioner actually enforce rules about what algorithms amplify?
This is the core enforcement problem the legislation does not resolve. Recommendation algorithms produce outputs that even their own engineers cannot fully predict or explain, and no outside regulator has access to the training data or model architecture that drives them. The laws gesture at researcher and regulator access to compliance information, but the detail has not been made public.