News

Australia's Algorithm Opt-Out: What the Draft Law Really Promises

Australia's draft My Feed, My Way scheme would let over-16s escape the recommendation algorithm, backed by penalties up to A$109.2 million. But the draft never promises a chronological feed — and after Meta's $18 billion and TikTok's $400 million settlements, AI assistants are already repeating the same expand-first sequence.

· Sep 17, 2026
Australia's Algorithm Opt-Out: What the Draft Law Really Promises
Illustration generated by AI
Table of contents
  1. What the draft actually says
  2. The chronological feed nobody actually promised
  3. The pattern: two very large numbers in one American summer
  4. AI is running the same sequence, faster
  5. What actually reduces profiling — and what doesn't
  6. FAQ
  7. Bottom line
  8. Sources and further reading

Australia published draft legislation on September 8 that would force social media platforms to offer every user over 16 a way out of the recommendation algorithm. The scheme is called My Feed, My Way, non-compliance carries penalties up to A$109.2 million (about US$79 million), and it arrives after a US summer in which Meta agreed to pay up to $18 billion and TikTok $400 million over how their products treat minors. One detail is being widely misreported, though — including by companies with a stake in the outcome.

What the draft actually says

The measure sits inside Australia's draft Digital Duty of Care legislation, released for targeted consultation and intended to reach the Parliament of Australia this year. Platforms would have to let users aged over 16 choose between an algorithmically recommended feed and one built only from accounts they deliberately follow, and to notify both new and existing users so they can pick their default. Enforcement sits with the eSafety Commissioner. Prime Minister Anthony Albanese framed it as "not about giving government control, it is about giving people control."

Australia already has form here: its world-first under-16 social media ban took effect in December 2025, and France, the UK and New Zealand have pursued comparable measures.

What the under-16 debate means for VPN users

The chronological feed nobody actually promised

Here is the correction. Coverage of this draft — including Proton's own write-up, and affiliate briefings built on it — describes the alternative as a chronological feed. The draft does not say that.

What it specifies is a feed sourced from accounts you follow. It does not specify how those posts are ordered. Those are two different controls, and only the second one is the thing people actually object to.

The distinction matters because engagement optimization does not live in the follow graph — it lives in the ranking function. A platform can comply with a "only accounts you follow" rule and still sort those posts by predicted engagement, still inject the most provocative reply first, still hold back a post to serve it when you are most likely to react. You would lose the recommended strangers and keep the slot machine. A genuinely chronological feed — reverse-ordered by publish time, no model in the loop — is a far stronger constraint, and one outside experts and advocates are asking for rather than one the draft guarantees.

If you read one thing into the final bill when it lands, read whether the word "chronological" made it in, and whether the non-algorithmic feed is the default or something users must go and switch on. Defaults decide adoption; an opt-out buried three menus deep changes nothing.

The pattern: two very large numbers in one American summer

Action Amount Who Date
Meta settlement over teen addiction claims Up to $18 billion 48 states, DC and territories Announced late August 2026
TikTok COPPA settlement $400 million US DOJ with the FTC August 21, 2026

The Meta settlement ended a trial brought by state attorneys general alleging Facebook and Instagram were engineered to hook young people. New Mexico and Florida stayed out — New Mexico had already won its own case, Florida's attorney general judged the terms too soft. Alongside the money, Meta agreed to two-hour daily time limits that only a parent can lift, to stop showing like counts to young users, and — note this — to offer young users an optional non-personalized feed.

TikTok's $400 million resolves a case filed in August 2024 over children under 13 and its Kids Mode: $300 million payable immediately, $100 million conditional on vacating an earlier consent decree against its predecessor Musical.ly. The DOJ complaint alleged the company knowingly let under-13s create accounts and failed to honor parents' deletion requests.

Notice that Meta's court-ordered remedy and Australia's proposed law are the same shape: an optional non-algorithmic feed, offered to users, on a platform whose revenue still depends on the algorithmic one. Regulators have converged on the same instrument. None of it changes what the business is — attention sold to advertisers, priced by how well the system predicts you. A fine is a cost of goods. The incentive underneath is untouched.

AI is running the same sequence, faster

The social media reckoning took roughly a decade: expand, dominate, then answer for it. AI assistants are compressing that timeline, and two releases from this August show how.

ChatGPT for Teens began rolling out globally on August 18 for users aged 13 to 17, across free and paid plans, bundling parental controls, a study mode, quiet hours and wider alerting to parents on high-risk conversations. The safeguards themselves are reasonable. The mechanism underneath deserves more attention than it got: the mode applies to users who state they are 13–17 or whom the system estimates to be — age inference, which by definition means profiling behavioral signals to guess something you did not disclose. That is the same class of inference the algorithm debate is about, deployed for a protective purpose.

The Apple Messages plugin is the sharper example. OpenAI shipped a plugin that lets ChatGPT search iMessage, SMS and RCS conversations, draft replies and send them. It is narrower than headlines suggested — Mac only, and limited to ChatGPT Work and Codex users — and it is opt-in. But setup requires approving AppleScript, Accessibility and Full Disk Access, and that last one is not scoped to Messages. Full Disk Access is a system-wide macOS permission that also covers Mail, Safari history and local backups. OpenAI says the plugin runs locally, reads messages only in response to a request, builds no complete index and stores content locally by default. Those are policy commitments, not technical limits: nothing in macOS constrains a process with Full Disk Access to the files it promised to touch.

This is where end-to-end encryption gets misunderstood. E2EE protects a message in transit between devices. It does nothing about what happens on the endpoint after decryption, and every messaging app must decrypt to display. Any local process with sufficient permission reads the plaintext — the encryption was never breached, it was simply irrelevant at that point in the chain. That is worth internalizing before granting any AI tool disk-level access to a machine that holds your conversations.

Should you use a VPN with ChatGPT and other AI apps?

What actually reduces profiling — and what doesn't

Be precise about which tool solves which problem, because the marketing routinely blurs it.

A VPN does not help with algorithmic profiling. It hides your IP address and encrypts traffic from your network and ISP. It does nothing once you have logged into an account: the platform identifies you by your session, not your IP, and every like, dwell time and scroll still feeds the model. Anyone selling a VPN as an answer to the feed problem is selling you the wrong tool.

What does change the incentive is how the product is paid for. A service funded by subscription has no advertiser to optimize engagement for. Proton's AI assistant Lumo is the clearest current example on the privacy side: Proton states that conversations are stored with zero-access encryption so that not even Proton can read them, that it does not log chats, that it never uses customer data to train models, and that the client code is open source and verifiable. Proton is a Swiss company, Lumo is built and hosted in Europe, and the service is presented as GDPR-compliant. There is a free tier with capped messages and image generation, and a paid Lumo AI Plus tier that lifts those limits.

One honest caveat that the marketing does not spell out: zero-access encryption protects conversations at rest. Your prompt still has to be processed in readable form for a model to answer it. That is a real and meaningful difference from a provider that retains and trains on your history — but it is not the same as the message never being legible anywhere, and you should not treat it as such.

The practical stack, in order of actual impact on profiling: use the non-algorithmic feed where one exists and set it as your default; keep a separate account or browser profile for anything you do not want correlated; pay for tools whose revenue does not depend on your attention; and use a VPN for the specific job it does — network-level privacy from your ISP and on untrusted Wi-Fi.

FAQ

Does Australia's law give me a chronological feed?

The draft guarantees a feed limited to accounts you follow. It does not specify that those posts must be ordered by time, so a platform could still rank them by predicted engagement. Watch the final bill for that wording.

Who does the opt-out apply to?

Users over 16. Australia's separate under-16 social media ban, in force since December 2025, already keeps younger users off the platforms entirely.

What happens if platforms ignore it?

Penalties of up to A$109.2 million — roughly US$79 million — enforced by the eSafety Commissioner. The bill still has to pass parliament.

Can a VPN stop an algorithm profiling me?

No. A VPN hides your IP and encrypts traffic in transit. Once you sign in, the platform identifies you by account and keeps profiling your behavior regardless of where the traffic appears to come from.

Is my iMessage history safe from AI tools?

End-to-end encryption protects messages in transit, not on your device after decryption. A Mac app granted Full Disk Access can read message databases, Mail and Safari history. Grant that permission deliberately, and only to software you would trust with all three.

Bottom line

Australia's proposal is the most interesting regulatory instrument yet, because it targets the mechanism rather than the age of the user — but it is a draft, and the version that matters is the one that specifies ordering and defaults. Meta's $18 billion and TikTok's $400 million show that regulators can now impose real costs; they have not shown that costs change design, because the remedy on offer is an optional feed on a platform that still monetizes the other one.

The AI half of the story is the part to watch, because the sequence is running again on a shorter clock. Expansion into trusted surfaces — a teen product, a plugin inside the messaging app — is arriving ahead of the settled norms about what those tools may collect. The leverage consumers actually hold is the same as it has always been: choose products whose revenue model does not require the profiling, and read the permission dialog before you tap allow.

Sources and further reading

Sources

  • Australia to let social media users opt out of algorithm-based feeds (September 8, 2026) cnbc.com
  • Proton: Australians could soon turn off social media algorithms proton.me
  • Meta to pay up to $18 billion in settlement with states over social-media addiction claims variety.com
  • TikTok reaches $400M settlement over children's privacy lawsuit techcrunch.com
  • OpenAI launches a safer ChatGPT for teens techcrunch.com
  • ChatGPT can now search Apple Messages, raising privacy concerns fortune.com
  • Proton Lumo — privacy and encryption claims proton.me

Try Lumo