There is something absurd about proposing a Digital Duty of Care to make the internet safer and then giving the internet-safety regulator statutory authority to operate sock-puppet accounts.
No, that is not satire.
The Albanese government's proposed changes to Australia's online-safety regime contemplate allowing the eSafety Commissioner to use what the government's own material calls "sock-puppet accounts." The government's May 2026 Digital Duty of Care response supported in principle giving the regulator greater flexibility in investigations, expressly including "the use of sock-puppet accounts."
The more recent exposure draft has attracted attention because it goes further in spelling out the machinery. As reported by The Noticer, the proposal contemplates false or fictitious identities being used in online-safety investigations and research, including generating material through online services and potentially using artificial intelligence.
Some of the commentary surrounding this has run ahead of the evidence. There is an important distinction between giving eSafety the ability to use covert identities for investigations and giving government officials authority to unleash armies of AI bots to manipulate Australian political opinion. The latter is a much larger allegation, and the material presently available does not establish that this is what the legislation is designed to do.
But that qualification does not make the proposal uninteresting. On the contrary, it exposes a remarkable contradiction at the heart of Australia's expanding online-safety bureaucracy.
Consider what eSafety itself says about fake accounts.
The regulator warns that anonymous and fake accounts can facilitate cyberbullying, adult cyber-abuse, scams, child exploitation and other harmful conduct. It says fake identities can make perpetrators difficult to identify and allow people whose accounts are blocked to reappear under new identities. It encourages platforms to identify and respond to fake, imposter and impersonator accounts.
Even more strikingly, eSafety's own 2026 regulatory guidance specifically discusses "sock puppeting" as a potential form of platform misuse. It describes fake accounts being used to manufacture apparent support for a viewpoint or participate in staged arguments that increase polarisation.
There is therefore a delicious circularity here. The online-safety regulator warns platforms about sock puppets while the government proposes giving the online-safety regulator explicit authority to operate sock puppets.
Of course, the obvious defence is that eSafety would be doing it for good purposes.
That argument deserves to be taken seriously. Police use undercover officers. Investigators sometimes conceal their identities. A regulator trying to discover how an algorithm treats vulnerable users may learn very little if it announces, "Good morning, this is the Australian Government conducting a regulatory inspection." Platforms could potentially recognise official testing accounts and give them an artificially sanitised experience.
There are consequently legitimate reasons for controlled undercover testing.
But precisely the same analogy demonstrates the problem. We do not normally say: police officers sometimes need to deceive suspects, therefore give them an undefined licence to deceive people whenever they consider it useful. Undercover policing raises questions about authorisation, proportionality, record keeping, entrapment, supervision and accountability.
The more intrusive the investigative technique, the stronger the safeguards should be. Sock puppets deserve the same treatment.
A regulator's fictitious account need not merely sit quietly in the corner observing what an algorithm serves it. Once the account can interact, post material and potentially generate material using AI, important boundaries appear.
Can the account argue with real Australians? Can it join political discussions? Can it "like" material and thereby affect an algorithm? Can several regulatory accounts interact with each other? Can they follow genuine users? Can they deliberately seek extremist material to determine what an algorithm recommends next? Can they generate provocative material to test moderation systems?
And what happens if ordinary Australians interact with these accounts without knowing that the person apparently arguing with them does not exist?
These are not arguments that such investigations must never occur. They are arguments for precisely the philosophy supposedly underpinning a Digital Duty of Care: identify foreseeable risks before they become harms.
The irony becomes sharper when one reads eSafety's own explanation of anonymous communication. The regulator warns that fake accounts can be used to manipulate public opinion and interfere in elections. It also says anonymity can make people feel less constrained by normal standards of behaviour and make accountability more difficult.
Very well. Apply that insight consistently. If fictitious identities can create risks when private citizens, trolls, scammers and foreign influence operations employ them, fictitious identities do not magically become incapable of creating risks because the person controlling the keyboard receives a government salary.
The comparison with undercover policing therefore cuts both ways. Society sometimes permits investigators to do things ordinary people cannot do because otherwise certain wrongdoing would be extremely difficult to investigate. But that exceptional authority is an argument for stronger controls, not weaker ones.
Imagine a police force announcing that crime is becoming so serious that officers need authority to assume false identities, infiltrate groups and interact covertly with citizens. The public response should not necessarily be "never." It should be: under what circumstances, authorised by whom, recorded where, subject to what limits, and reviewed by whom?
Exactly the same questions should be asked here. The issue is especially important because artificial intelligence changes the scale of what is possible. One human investigator maintaining one undercover account is one thing. Software capable of generating convincing material continuously is another. Once fictitious identities and automated content generation occupy the same statutory neighbourhood, Parliament should draw exceptionally bright lines around permissible conduct.
There should be no need to speculate about those lines. They should be written down. If sock puppets are solely investigative tools, say so. If they cannot be used to influence political discussion, say so. If they cannot artificially amplify or suppress viewpoints, say so. If human authorisation is required before an account interacts with a real person, specify it. If records must be retained so that an independent reviewer can reconstruct what happened, require that. If researchers receive the same privileges, establish who qualifies and who supervises them.
And if those safeguards already exist elsewhere, government should point Australians directly to them rather than asking the public to assume benign administration.
This is the central problem with regulatory exceptionalism. Every expansion of power comes wrapped in the immediate purpose for which its proponents say it is required. Yet legislation survives governments, commissioners and today's good intentions.
The question is therefore not whether the present eSafety Commissioner intends to conduct political influence operations. There is no evidence before us establishing that she does. The proper question is whether legislation creating covert digital identities contains sufficiently clear limits to prevent present or future officials from crossing the line between observing online behaviour and participating in it.
That is where the Digital Duty of Care should begin practising what it preaches. Canberra proposes to make digital platforms anticipate the harms their technologies can cause while simultaneously contemplating statutory authority for the online-safety regulator to enter those platforms behind fictitious identities.
Perhaps that power is sometimes necessary. But if everyone else is being told to anticipate foreseeable misuse, Parliament might begin by anticipating the foreseeable misuse of its own powers.
https://www.noticer.news/esafety-sock-puppet-account-digital-duty-care/