Hook
Australia’s eSafety Commissioner just filed a $38 million civil penalty suit against Telegram for failing to detect abhorrent violent material tied to the Christchurch and Buffalo shootings. This is not a criminal referral. It’s a civil penalty proceeding under the Online Safety Act 2021. That distinction matters more than the headline. Speed is the currency, but accuracy is the vault. The real signal here has less to do with video takedowns and more to do with how the regulator weaponizes “reasonable steps.” If you’re reading this as another privacy vs. safety debate, you’re already behind.
I’ve spent years auditing protocol-layer risk. The first thing to understand is that eSafety is not claiming Telegram ignored takedown notices. The claim is failure to detect. In legal terms, that means the regulator is attacking the detection layer, not the response layer. That’s a structural challenge to Telegram’s entire product architecture.
Context
After the March 2019 Christchurch attack, Australia rushed amendments into the Criminal Code Act 1995, specifically section 474, creating “abhorrent violent material” (AVM) obligations. The 2021 Online Safety Act then handed the eSafety Commissioner regulatory teeth. The law’s language says platforms must remove AVM “as soon as practicable” after becoming aware. The safe-harbor mental model was reactive: report, discover, remove. But Australia’s enforcement history, especially eSafety’s 2024 suit against X Corp, shows the regulator shifting from notice-and-takedown toward proactive detection obligations.

Telegram is a relevant electronic service under the law. Its servers are distributed; its headquarters are in Dubai; but it services Australian users, so jurisdiction is straightforward. The more important fact: Telegram’s public channel architecture is not end-to-end encrypted. Public channels and large public groups are fully visible to Telegram’s infrastructure. That removes the obvious technical defense. If content is visible to the server, it’s detectable by the operator. eSafety knows this. That’s why they filed.
Core
Here is the part the media narrative misses. The civil penalty route lets eSafety bypass criminal procedural protections. Criminal charges require proof beyond reasonable doubt. Civil penalties only need to satisfy the balance of probabilities. So why $38 million? The number is an anchor. The statute allows daily penalties and multiples per violation. In a civil penalty proceeding, aggravating factors like prior non-compliance can inflate the final figure. Telegram already has a regulatory rap sheet: Germany fined it over hate speech; Brazil temporarily banned it; the EU designated it a Very Large Online Platform under the DSA. All of that is now admissible ammunition.
The technical core is “reasonable steps.” What does a platform with a billion users need to do? The two-tier structure matters. For public channels, hash-based content fingerprinting is possible. PhotoDNA, perceptual hashing, and metadata-driven classifier pipelines are standard industry tools. Meta’s moderation stack does this at scale. Telegram, to its credit, has token forces: community reports, some AI classification for CSAM, and a takedown process for verified channels. But the scale gap is enormous. Based on my own audits of similar systems, detecting viral AVM in a channel with 100,000 members requires not just classification but real-time propagation tracking. That means measuring re-shares, URL previews, and bot forwards across the channel graph. Telegram’s public API actually exposes enough metadata to build this, but Telegram itself hasn’t built it.
Here’s the causal chain eSafety will present. AVM spreads through Telegram’s public channel graph. The graph is accessible to the platform. The platform has a search and recommendation system. That system can surface content. Therefore, Telegram has the technical ability to detect viral AVM. The only missing ingredient is intent. The court is being asked to infer intent from the absence of scalable detection systems. This is not a technological argument. It’s an argument about resource allocation.
The “large group” blind spot is equally important. Public channels are searchable, indexed, and easy to scan. But the most damaging AVM spreads through massive semi-private public groups. These groups sit between public and private. They require an invite or link, but they scale to hundreds of thousands. They can be configured to hide from search. This intermediate zone is Telegram’s regulatory soft belly—large enough to spread toxic content, segmented enough to avoid automatic crawling. A civil court may define “service” to include these groups. If that happens, the compliance surface expands dramatically.
There is also the international-law tension. Telegram is registered in the British Virgin Islands, headquartered in Dubai, with infrastructure across multiple jurisdictions. It can attempt a “conflicting compliance obligations” defense, arguing that forced detection violates privacy laws elsewhere. That argument usually fails when a service proactively targets Australian users. The court likely won’t buy it.
The final point: This isn’t a one-off. The Christchurch Call initiative, launched by nations after the 2019 shooting, has remained a soft-power pledge. This lawsuit is the judicial arm of that initiative. By suing Telegram in an Australian domestic court, eSafety converts a diplomatic commitment into enforceable civil liability. Other Five Eyes regulators are watching. The UK’s Ofcom has already opened a parallel track. If this succeeds, expect copycat litigation. Speed is the currency, but accuracy is the vault.

Contrarian
Now the contrarian view. The mainstream take is “privacy vs. safety.” That frame is lazy. Telegram could satisfy a reasonable-steps obligation without decrypting anything. Public channels and large public groups are not end-to-end encrypted. Telegram’s servers can see every message in those spaces. The real issue is that Telegram’s business model treats all user content as uniformly private, even when it is not. That creates a perverse incentive: the platform cannot create a moderation tier for public spaces without admitting that some content is less private than users assume. The lawsuit is forcing Telegram to draw a technical line it has spent years avoiding.
Seen this way, the true risk is not the $38 million. It’s the possibility that the court orders ongoing monitoring obligations. Compliance costs could outrun the penalty by a factor of five or ten. The judgment becomes a “hidden tax” on the current architecture. That is how regulatory risk compounds: one favorable court order becomes an annual compliance line item. In trading terms, this is a short-volatility position that gets squeezed as the hazard becomes priced.
And don’t count out a settlement. Telegram could propose a pilot with eSafety around metadata-level reporting, not content decryption. That would be a face-saving compromise. But the regulator has strategic momentum. It chose Telegram specifically, not Signal or WhatsApp, because Telegram has the longest track record of resistance. This is a message to every encrypted platform: build in verifiable moderation from the start, or face litigation.

Takeaway
Next watch: interim injunctions and any orders to produce metadata. If eSafety asks for broad metadata disclosure, the case becomes a template for law enforcement access. If Telegram settles, it sets an even stronger precedent: regulators can force privacy-first products into moderation pipelines just by threatening to make their operations public. The price of opacity just went up. Speed is the currency, but accuracy is the vault. I’ll be monitoring the court docket the way I monitor ETF flows: early execution, not reaction.