The Meta Settlement Fixes One Privacy Problem by Creating Another

Meta agreed this week to pay up to $17 billion and rebuild core parts of Facebook and Instagram to resolve claims from a coalition of state attorneys-general that it designed its platforms to addict children and misled the public about the risks. It is the largest privacy and consumer protection settlement in US history outside the tobacco cases of the 1990s. At the time of writing, it is still awaiting approval from Judge Yvonne Gonzalez Rogers in the Northern District of California, so the final terms could still move.

Buried inside the relief is a detail that matters more to founders and platforms than the headline number. Meta has committed to "strengthen its age-assurance technology." The settlement asks Meta to get better at knowing exactly who its users are and how old they are.

That is a reasonable ask on its face. It is also a company that has spent three years being sued for collecting too much data about children now being told, as the remedy, to collect more precise data about everyone.

What the settlement actually requires

The terms include default time limits and overnight access blocks for users under 18, muted notifications during school hours, hidden like counts and reaction totals for teen accounts, and restrictions on beauty filters tied to cosmetic surgery. Teen accounts will default to private, with messaging restricted from adults the teen has not affirmatively connected to.

The age-assurance piece sits underneath all of it. Every one of those protections depends on Meta correctly identifying who is a teenager and who is not. A time limit that only applies to minors requires knowing who the minors are. A settlement built on "we didn't verify age carefully enough" resolves itself, structurally, by asking for more verification.

Where COPPA actually fits

A meaningful piece of the states' leverage came from the Children's Online Privacy Protection Act (COPPA), which is worth being precise about because it gets invoked loosely. COPPA dates to 1998. It applies only to operators who have "actual knowledge" they are collecting personal information from a child under 13, and it requires verifiable parental consent before that collection happens. It says nothing about 13 to 17 year olds, which is the entire population most of this settlement is actually designed to protect.

The states' theory leaned on that actual knowledge standard. Meta's own policy has always barred users under 13. The claim was that Meta knew, at scale, that large numbers of under-13 users were on the platform anyway, because kids routinely register with false birth dates and Meta's own systems could see the signal, and that Meta used that data, including to train machine learning and generative AI models, without the consent COPPA requires.

That is a narrow statute doing a lot of work here because there is nothing broader to reach for. Congress has never passed a comprehensive federal children's privacy law that covers teenagers, or a federal age-verification standard of any kind. COPPA's 13-year cutoff, written for the pre-smartphone internet, is functionally the only federal tool available, and it explains why so much of the actual protective architecture in this settlement, the parts covering 13 to 17 year olds, had to be negotiated as settlement terms rather than derived from statute.

Kids don't have the ID this problem wants them to have

There is a practical wrinkle in "stronger age verification" that rarely gets said out loud: the population you are trying to verify mostly does not hold the credential the strongest verification methods rely on. A 14 year old does not have a driver's license. Many do not have a passport. ID-based age verification, the method regulators often point to as the gold standard, is built around a document most of the target population cannot produce. ‍

That pushes platforms toward the two alternatives: biometric age estimation from a face scan, or behavioral inference built from tracking what an account actually does over time. Both require Meta to hold more (and more sensitive) data than a birthdate field ever did. Neither is what most people picture when they hear "we're getting better at checking ages."

Australia already ran this experiment

Australia's under-16 social media ban took effect in December 2025, the first law of its kind anywhere. The government reported 4.7 million account removals in the first month, a figure that has since climbed past 5 million. It looked, briefly, like decisive enforcement.

Then eSafety, Australia's internet regulator, published its own study in July. More than four out of five Australian teens under 16 were still using social media three months after the ban took effect. Most were using their own accounts. About two-thirds had hit an age check at some point, and it was almost always a self-declaration or a selfie-based estimate, the same soft verification methods critics say Meta already had. Daily use among teens had barely moved. ‍

Australia's response was not to abandon the framework. It was to escalate. In late June, the government proposed raising maximum penalties for non-compliance to nearly A$99 million and giving the regulator sharper enforcement powers. Reddit is separately challenging the law's constitutionality in Australia's High Court. Australia's Information Commissioner has its own, parallel role enforcing the privacy provisions embedded in the same statute, separate from the safety regulator, which is a useful signal on its own. Even Australia treats age verification as a data protection question, not only a child-safety one.

The lesson for any platform watching from the US is not that age verification fails outright. It is that soft verification fails, and the escalation path runs directly toward the ID-based and biometric methods that carry the most privacy exposure. Australia went first. Its trajectory is a preview of where settlement terms and state laws here are likely headed if self-declaration keeps proving porous.

This is public pressure and private litigation doing the work, not new legislation

It is worth naming what mechanism actually produced these changes. Congress has not passed a federal law governing how platforms verify age or handle minors' data. The design changes came out of a courtroom, driven by state attorneys general acting under public and political pressure, not a statute Congress wrote for this problem.

And the state settlement does not close the exposure. Thousands of individual plaintiffs and more than a thousand school districts still have active claims pending in the federal multi-district litigation before the same judge, plus a parallel coordinated proceeding of roughly 2,500 personal injury cases in California state court. Those plaintiffs' lawyers have said plainly they intend to keep going against Meta, Snap, TikTok, and YouTube regardless of the state settlement. A Los Angeles jury already returned a $6 million verdict against Meta and YouTube in one bellwether case this year, and Snap and TikTok both settled parallel claims rather than face trial.

None of that is legislation. It is public opinion translated into litigation pressure, case by case, settlement by settlement, and it is currently doing more to shape how platforms treat minors than anything out of Washington.

An industry standard by other means ‍

Meta is leaning into that dynamic rather than fighting it. In its public statement on the settlement, Meta's Chief Legal Officer called on TikTok and YouTube to adopt the same Time Limit Commitments and Night Mode features, framing them as "the right path forward for our whole industry." Snap is notably in the same position without being name-checked in that statement, having already settled its own piece of the youth addiction litigation and facing the same category of pressure to match whatever standard emerges.

At the same time, Meta has been lobbying regulators in Europe to shift age verification up the stack entirely, to app stores rather than individual platforms, which would let Meta offload both the compliance burden and the liability for getting it wrong. Watch both moves together. A company that just paid up to $17 billion for a privacy and safety failure is simultaneously trying to set the industry standard on its own terms and trying to hand the hardest part of that standard to someone else.

What this means if you are building right now

If your platform has any meaningful minor user base (actual or foreseeable) three things are worth doing now rather than after your own plaintiff's letter or state AG inquiry arrives.

Document your age-assurance method and why you chose it. Self-declaration alone is increasingly hard to defend as reasonable, but jumping to biometric or ID-based verification creates its own data minimization and security exposure, made harder by the fact that most minors do not hold the ID those systems assume they have.

Treat this as a data protection design decision, not just a trust and safety feature. Australia's Information Commissioner having its own enforcement lane, separate from the safety regulator, is the template. Whatever verification method you pick is itself subject to privacy law, apart from whatever child-safety standard is telling you to verify age in the first place.

Expect the standard to keep moving through courts and state legislatures, not Congress. Between the still-pending claims, active state-court litigation, and whatever terms filter down once the Meta settlement is approved, a compliance posture that is current today will not stay current for long.

The Meta settlement will get covered as a story about money and about kids' safety, and it is both of those things. It is also a live case study in the hardest problem in privacy law: proving you know less about someone often requires knowing more about them first.

Next
Next

The Confidentiality Leaks Hiding in Your AI Tools