As we have noted previously, Australia has been at the forefront of experimenting with technology policies, ranging from social media bans for children to AI governance and regulation of deepfake pornography.
However, as the Australian Senate was debating legislation to strengthen the social media ban for children under 16, a surprise amendment was introduced. This amendment seeks to modify an unrelated competition law to mandate that devices and operating systems allow full access to third-party “digital safety services.” It is currently being rushed toward a vote within the next day or two.
We are deeply concerned about this amendment, not just the haste to pass it without thorough consideration and debate, but the adverse and predictable undermining of the security of every Australian. This represents an extreme model of mandated interoperability that introduces security vulnerability into every mobile device in Australia. We have previously cautioned against some forms of interoperability in the EU, but this Australian proposal is even more extreme and harmful.
When done correctly, interoperability in the digital space can yield significant benefits for consumers and businesses alike. For instance, the interoperability features built into modern smartphones enable millions of third-party applications to leverage on-board sensors, computing power, and connectivity services, fostering a thriving ecosystem of connected devices and applications. However, this ecosystem succeeds in large part because these tools incorporate built-in safeguards to protect user safety, security, and privacy.
Mandated interoperability becomes highly problematic when it undermines these essential safeguards, putting fundamental consumer privacy, safety, and security at risk.
As currently drafted, the amendment under debate in Canberra would require operating system providers to grant third-party services access to the operating system, sensitive system privileges, consumer device and app-usage data, content controls, and account-management functions—all without establishing clear need or criteria or safeguards governing which entities are qualified to receive such access.
This would compromise the security of mobile devices across Australia, expose them to potential exploitation by bad actors, and erode the defense-in-depth architecture that protects Australian users. The proposed level and depth of system access granted to third-party services is unprecedented, deeply insecure, and raises urgent and unresolvable legal and national security issues.
Compounding these substantive concerns, the amendment has not even been subjected to public consultation, technical, or national security scrutiny.
Parliament should reject this proposal and safeguard its digital security.