A duty of care is a legal obligation to take reasonable steps to prevent foreseeable harm. In online safety contexts, it requires platforms to assess risks, apply controls, keep records, and show that safety measures are proportionate to the service and the users affected.
Expanded Definition
Duty of care is a legal and governance concept, but in cybersecurity and online safety it functions as an operational expectation: an organisation must identify foreseeable harm, assess how likely it is, and take reasonable steps to reduce that risk. It is broader than a single technical control and narrower than a general ethical principle, because it is judged against the service, the users, and the context in which the harm could occur.
In practice, duty of care often overlaps with risk management, incident readiness, documentation, and control selection. The strongest implementations show a clear line from identified hazard to mitigation, monitoring, and review. That is why frameworks such as the NIST Cybersecurity Framework 2.0 are useful: they help teams translate a general obligation into governance, protection, detection, response, and recovery activities.
Definitions vary across jurisdictions and sectors, and no single standard governs this term yet. The most common misapplication is treating duty of care as a one-time legal checkbox, which occurs when teams document a policy but do not test whether controls are proportionate to the actual harm profile.
Examples and Use Cases
Implementing duty of care rigorously often introduces extra review, documentation, and escalation overhead, requiring organisations to weigh speed of release against defensible safety decisions.
- A social platform maps harmful content scenarios, then records why its moderation thresholds and escalation paths are proportionate to user risk.
- A SaaS provider assesses account takeover, data exposure, and abuse paths, then aligns monitoring and response playbooks to the most foreseeable harms.
- A marketplace keeps audit records showing how identity checks, fraud controls, and dispute handling were selected to reduce predictable customer harm.
- An AI service operator documents known failure modes, human oversight points, and escalation criteria to show reasonable steps were taken before deployment.
- A cloud security team links a control set to business impact analysis and incident evidence, often using the NIST Cybersecurity Framework 2.0 as the structure for that mapping.
These examples show that duty of care is not just about having controls, but about being able to explain why those controls were chosen, how they were validated, and what risk they were intended to reduce.
Why It Matters for Security Teams
For security teams, duty of care matters because it shapes how risk decisions are defended after an incident, complaint, or regulatory review. If the organisation cannot show that it considered foreseeable harm, selected proportionate safeguards, and maintained evidence, even strong technical measures may look arbitrary or incomplete.
This concept is especially important where identity, access, and agentic AI intersect. Poor authentication design, weak privileged access controls, or uncontrolled AI agents can all create foreseeable harm, and duty of care forces teams to treat those exposures as governance issues, not just technical defects. When the service handles personal data or trust-sensitive workflows, the expectations around documentation and proportionality become even more visible.
Security leaders typically encounter the practical weight of duty of care only after a breach, abuse event, or harm claim, at which point evidence of reasonable prevention and response becomes operationally unavoidable to produce.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST AI RMF and NIST SP 800-63 set the technical controls, while EU AI Act and NIS2 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OC-01 | Outlines organisational context and risk priorities relevant to duty of care. |
| NIST AI RMF | GOVERN | Governance functions support accountability, documentation, and risk ownership for AI-related duty of care. |
| NIST SP 800-63 | IAL2 | Identity assurance levels help define reasonable steps when identity proofing is part of harm prevention. |
| EU AI Act | Requires risk management and technical documentation for certain AI uses tied to foreseeable harm. | |
| NIS2 | Expects appropriate and proportionate cybersecurity risk-management measures for covered entities. |
Maintain risk files and technical records showing controls are proportionate and continuously reviewed.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 20, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org