
Image: METAL
Summary
- OpenAI published the Australian Youth Safety Blueprint on 18 September 2026.
- It sets out six pillars: AI literacy, age assurance, under-18 safety policies, safeguards against manipulative outputs, crisis response, and parental controls.
- A demand that outside parties assess how companies actually implement these safeguards, and that summaries of those assessments be published, sits in the document's closing section.
OpenAI has published an Australian Youth Safety Blueprint. Released on 18 September 2026, the document sets out six pillars for policymakers to consider, and the original PDF, which METAL checked, runs to seven pages including the cover and the foreword. It arrived timed to a moment when the Australian government has the draft of its 2026 online safety amendment out for consultation.
The nature of the document is unlike an ordinary product announcement. It is a company that operates a conversational AI service, ChatGPT, writing down first what the rules for handling the teenagers among its users should look like. This is not promotional material showing off features; it is a proposal written to be read by legislators. The Blueprint states that "the responsibility should not fall primarily on young people or their families," and argues that companies must build age-appropriate safeguards into their products from the outset while giving parents usable tools and clear information. A line in the foreword notes that, unlike the arrival of social media, this time there is an opportunity to put protections in place at the start.
The first pillar asks policymakers to recognise what AI is good for before anything else. The document states that nearly nine in ten teens on ChatGPT use it within a single week for learning, finding information, building skills or productivity. The goal of policy, it says, should not be to keep young people away from AI but to teach them to use it safely and critically, and AI literacy should be treated as an opportunity and a safety strategy at once. A clause holds that school adoption should be teacher-led, and the document cites the Productivity Commission's recommendation of a national approach to educational technology and AI tools.
The second pillar is age assurance. It calls for privacy-protective, risk-based age estimation tools that distinguish under-18s from adults while minimising the collection of sensitive personal data, and it suggests relying where possible on the age information held by operating systems or app stores. OpenAI says it uses the same approach in Australia as it does globally, and that where confidence is insufficient ChatGPT defaults to a safer experience. Users wrongly placed in the under-18 experience can reverse it by submitting a selfie to Persona, a third-party identity verification service; OpenAI states that it does not see the selfie or any identification submitted, and that Persona deletes verification data within seven days. A sentence closing the section commits to continuing to minimise collection in line with the Privacy Act 1988.
The third pillar is under-18 safety policy. It calls for implementation to be evaluated through testing before deployment and monitoring and enforcement after it, and goes on to require protocols prepared in advance for serious situations including self-harm, exploitation, grooming and sexually exploitative material. In-service support, referrals to outside resources, and parental notification where appropriate are listed as components of those protocols. A further clause asks companies to publish their child safety policies so that families and users can see which safeguards and parental tools exist.
The fourth pillar is preventing manipulative or deceptive outputs. The document argues that regulation should target proven risks rather than prescribing one-size-fits-all defaults, and says systems should block outputs that encourage emotional overreliance, compulsive engagement, secrecy from parents or trusted adults, or confusion about whether the user is speaking with a machine or a human. A clause also tells systems not to initiate, reinforce or escalate anthropomorphic behaviour that makes them appear conscious, romantic or authoritative. Encouraging breaks during long sessions and signposting real support where distress is detected are bound into the same pillar.
The fifth pillar is a crisis response protocol. It provides that when a teen expresses suicidal intent, the parent whose account is linked should be notified by default, and that the user should be connected to real-world resources such as Triple Zero (000), Lifeline (13 11 14), Kids Helpline (1800 55 1800) or 13YARN. Alongside those sit items asking companies to support the organisations they refer users to, and to establish advisory councils of experts in mental health, wellbeing and child development. OpenAI cites its own Expert Council on Well-Being and AI as an example, and says it will share what it learns and support independent research.
The sixth pillar is parental controls. It includes linking a teen's account for those aged 13 and over through an email invitation, managing settings such as memory, chat history and location, and automatically receiving alerts when a teen's activity suggests an intent to self-harm. There is a clause on setting quiet hours and study hours to steer certain times of day toward educational use, and a final clause requiring timely notice to a parent when a child changes or disables a safety or privacy setting the parent had enabled.
The document also proposes the shape of the law that should sit on top of those six pillars. Rather than prescribing fixed technical measures, it asks for proportionate, outcomes-focused obligations and for companies to be required to identify, assess and mitigate risks of severe harm to teens. It judges that Australia already has a foundation, noting that eSafety's legally enforceable Codes and Standards address class 1 and class 2 material including certain AI-generated content, and that the National Classification Scheme operates alongside them. It also states that the Digital Duty of Care framework now under consultation would replace those Codes and Standards if enacted.
The most lawyerly demand comes at the end. It asks for outside assessment of how effectively companies have actually implemented teen safety safeguards, and for those assessments to rest on common standards so they can be compared across jurisdictions. Companies should publish a plain-language summary of the assessment on their websites while protecting information that could increase the risk of misuse or help circumvent safeguards. It is a design that moves the unit of obligation from feature specifications to verifiable outcomes, which is why the document reads closer to the grammar of a regulatory draft than to a product manual.
Product facts are attached to the same document. From August, OpenAI began rolling out ChatGPT for Teens as the default experience for users identified as aged 13 to 17 in Australia. According to reporting, Brent Thomas, Head of Policy for Australia and New Zealand at OpenAI, said, "We want teens to use AI responsibly to learn, create and explore." He added, "We've worked closely with experts to shape these features, guided by four commitments," naming them as putting teen safety first, encouraging real-world support, treating teens like teens, and being transparent about how the systems should behave.
This document is not the first of its kind. OpenAI released a global Teen Safety Blueprint on 6 November 2025, and this Blueprint places that framework onto one country's legislative timetable. METAL has reported that OpenAI is funding research on AI's impact on young people with five million dollars. METAL has also covered Anthropic suspending Claude accounts suspected of belonging to minors.
What the document is really contesting is where the burden of proof sits. It proposes moving from a stage where a company explains its own safeguards to one where outside parties assess the implementation and publish a summary of it. OpenAI writes in the same document that more than a billion people use the intelligence it has created, and at that scale the accuracy of age estimation and the threshold for parental notification could become values set by statute rather than choices made by a company. The document says consultation with the government is under way, and what remains to check next is which of the six pillars end up as obligations and which stay as recommendations.





Comments