
"Australia's encryption wars in 2026: TOLA survives, E2EE holds"
Australia's encryption wars in 2026: TOLA survives, E2EE holds
Australia's TOLA Act was one of the first laws anywhere to give agencies formal powers to compel technical assistance from encrypted-service providers. Eight years on, the powers are still there, the reviews have come and gone, and end-to-end encryption (E2EE) in mainstream apps is still standing. Here's the state of play as of October 2026.
What the TOLA Act actually does
The Telecommunications and Other Legislation Amendment (Assistance and Access) Act 2018 created a three-tier framework:
- Technical Assistance Requests (TARs) — voluntary requests to providers for help.
- Technical Assistance Notices (TANs) — compulsory notices requiring providers to give agencies assistance they are already capable of providing.
- Technical Capability Notices (TCNs) — compulsory notices requiring providers to build a capability, with a statutory prohibition on requiring a "systemic weakness" or "systemic vulnerability" to be introduced.
The Independent National Security Legislation Monitor (INSLM) reviewed the Act and concluded the powers were, with two exceptions, necessary — but compliant with human rights "if, but only if" the review's central safeguards were implemented, most importantly moving the issuing of TANs and approval of TCNs to judicial oversight and creating an Investigatory Powers Commission. (INSLM 9th report)
The reviews: recommendations landed, structure didn't change
The Parliamentary Joint Committee on Intelligence and Security (PJCIS) completed its own review of the TOLA regime in December 2021. It made 29 recommendations, the headline one being that the powers be retained with additional safeguards and oversight — while acknowledging that some of the industry fears voiced at passage "have not been realised." The committee also noted that some of the most contentious powers had never been used. (PJCIS media release, 22 December 2021)
The legislative response so far has been incremental. The Telecommunications and Other Legislation Amendment Bill 2025, introduced on 27 August 2025, is a housekeeping package — evidence rules for network activity warrants, moving the Communications Access Coordinator to Home Affairs, limited stored-communications access for testing, and fixes to international production orders. The PJCIS tabled its report on 7 October 2025 recommending the Bill pass unamended — with no restructuring of the TOLA assistance powers in sight. (Parliamentary Library bill digest, PJCIS media release, 7 October 2025)
So the honest 2026 status is: the core powers remain as legislated in 2018, the INSLM's structural reforms (judicial issuance of TANs/TCNs, an Investigatory Powers Commission) have not been enacted, and governments of both stripes have kept the framework intact. Label the INSLM recommendations what they are — recommended, not law.
The E2EE debate: pressure without a ban
Three pressure points have run in parallel over 2026:
- Online Safety Act standards. eSafety's industry standards for detecting child sexual abuse material, first proposed in 2023, contemplate scanning obligations for messaging and file-storage services — "including for E2EE services if feasible." Providers such as Fastmail publicly argued the proposed scans were "not technically good" solutions, and the standards' feasibility carve-out for E2EE remains the fault line. (iTnews, 21 November 2023)
- The under-16 social media minimum age. Age-restricted platform rules have applied since 10 December 2025, with eSafety's compliance updates through 2026 showing platforms working through age assurance. Messaging services remain a separate question from social media, and no law currently requires breaking E2EE to verify age.
- A mild regulatory turn. eSafety's transparency-notice approach — naming what platforms can do about abuse, including device-based detection on encrypted services — has favoured client-side, opt-in safety tooling over mandated scanning of encrypted content. There is no Australian ban on E2EE, and none proposed in any bill before Parliament as of October 2026.
What this means for you
- E2EE in Signal, iMessage and WhatsApp remains lawful and unbroken in Australia. Use it; the threat to it is regulatory pressure, not a technical defeat.
- The real TOLA risk sits with providers, not users. A TAN or TCN obliges a company to assist agencies within statutory limits. Choosing providers that implement true E2EE with no plaintext access (Signal's design, for example) keeps them unable to hand over what they never had.
- Client-side scanning is the watch-item. If any future mandate lands, it will arrive dressed as child-safety compliance, and it will scan on your device before encryption. A hardened phone OS you control, like GrapheneOS, gives you visibility over what your device runs — see our firmware verification guide.
- Check the notices. When a claim about a TCN or TAN circulates, go to the INSLM and PJCIS publications rather than social-media summaries.
The Australian position in 2026 is stable in the way that matters to users: the compulsory-assistance architecture is unchanged, the reviews ask for oversight rather than repeal, and encrypted messaging keeps working. Vigilance is still warranted — the next enforcement round of the Online Safety Act standards is where this fight resumes.
This post is general information, not legal advice.