For several years, Meta has faced a massive multidistrict litigation (MDL) combining thousands of lawsuits in nearly every U.S. state and territory, alleging that the social media company designed its platforms to be addictive and harmful to minor users. State attorneys general in the MDL reached a nearly $17 billion settlement on August 26, 2026 – a far cry from the $200 billion the attorneys general were asking for. As part of the settlement, Meta agreed to implement age assurance, hard caps on teen screen time, and a slate of protective design defaults. In the coming months, teen users will see their scrolling experience change, with more options on feeds, fewer notifications, and possibly the need to prove their age or ask parents’ permission to change settings.
This is not the end of Meta and other social media companies’ deluge of product liability lawsuits, but the MDL was the heftiest and, to date, the most consequential. While this case helped advance the idea that platforms can be responsible for their product design regardless of the content hosted on the platform, the settlement goes both too far and not far enough in mandating certain safe-by-design requirements. Specifically, the agreement normalizes age assurance as the price of using a large social media platform, leaves the most protective settings to parents who have to go find them first, hands those same parents surveillance capabilities that will not be safe in every household, and gives Meta unprecedented influence over setting the terms of kids’ online safety across the industry.
The Age Assurance Cat Is Out of the Bag
For years, lawmakers, age-verification proponents, and digital rights advocates have butted heads over whether the privacy and speech-blocking threats of age verification are a worthy trade-off for knowing for certain whether a user is a minor to minimize harm. Most platforms simply require a self-attestation of one’s age – a low barrier easily surmounted by fudging the birth year. The MDL settlement made it clear that age assurance is no longer up for debate; Meta must know a user’s age with reasonable certainty to provide age-appropriate experiences and sufficiently mitigate apparent risks.
Age assurance is a thorny topic for good reason, mostly because of the privacy risk, but also because mistaking an adult user for a minor can impede that adult’s access to speech, as well as their ability to speak. Depending on the requirements, age-verification mandates could also mean the end of online anonymity – a crucial distinction for investigative journalists, those seeking support in abusive situations, those representing vulnerable identities that could be punished by everyone from despotic governments to unsupportive households, and many others.
At this point, nothing can be said for sure regarding how serious the age-assurance mandate really is. The settlement is technology-neutral in how Meta affirms users’ ages and frames Meta’s age-assurance implementation as a sort of experiment. It requires a certain accuracy threshold and mandates annual third-party audits of commercially available methods that Meta chooses to implement. A separate independent auditor, selected by a bipartisan group of up to six attorneys general offices alongside Meta, also evaluates age-assurance metrics and reports on them. Meanwhile, Meta continues to push for app-store-level age verification – an approach codified in Texas’ App Store Accountability Act, which the Supreme Court has allowed to be enforced while lower courts decide whether the law should be struck down on First Amendment grounds.
This Meta settlement effectively circumvents First Amendment questions about platform-level age verification by adopting voluntary age-assurance requirements. But the voluntary commitment does not erase concerns about limiting speech and access to others’ speech. We at Public Knowledge know interest in age-verification requirements is popular among kids safety advocates, but we believe the level of assurance should be tiered to the risk of the specific feature rather than applied uniformly to an entire platform or website.
The Problem with Mixing Safe Design with Parental Consent
The settlement requires Meta to implement a strict two-hour usage limit across Instagram and Facebook for teen users, and to turn off notifications during the hours teens are in school or should be asleep. Beyond usage limits, Meta has also agreed to provide teen users with a non-algorithmic feed option and the ability to turn off autoplay, as well as to implement productive pauses and notifications to reduce mindless platform usage. Parents can adjust settings on their teen’s behalf. While we’d prefer to turn off such engagement-maximizing features by default, with a preference for an opt-in scheme, users having more agency over how a feed is presented to them is a positive change. Default protections include hidden likes, blocking certain filters, and maintaining existing content standards that Meta has based on movie ratings criteria and parent feedback. Meta has also promised to strengthen protections against unwanted contact from strangers and make it harder for suspicious adults to find teens.
Unfortunately, some voluntary design changes in this settlement give us digital rights advocates heartburn. When it comes to connections to potentially harmful people, Meta has agreed to limit discoverability between teen users and suspicious accounts, and make teen accounts private by default – all good ideas. Where it gets concerning is Meta agreeing to provide parents with information on their teen’s messaging contacts – a level of surveillance that could facilitate other sorts of real-life harm. Consider, for example, a teen seeking to contact an adult to help remove themselves from an abusive household – and that abusive parent discovering such contact and punishing the teen for it. Meta has also agreed to notify parents if their teen user is searching terms related to suicide, self-harm, or eating disorders – which, for the right parent, could be an opening to provide needed support, but for the abusive parent, could cut off teens from the supportive online communities they may be seeking by searching such terms.
Misery Loves Company
Notably, this settlement’s requirements apply only to Meta, not to other platforms often accused of harming minor users. Hence why Meta called on YouTube and TikTok – the two social media platforms teens use as much as, if not more than, Meta’s Instagram and Facebook – to implement many of these feature changes. With teens spending an average of nearly five hours a day on social media, it’s not hard to see how a teen user scrolling through Instagram Reels hits the 2-hour ceiling and immediately switches to watching TikTok videos – after all, the continuous-scroll short-form video products are largely substitutes. Excessive social media use isn’t resolved, as teen users may choose to spend more time on other platforms (and maybe explore lesser-known platforms with fewer protections).
While Meta’s effort to get its competitors on board with these platform changes may be to help ensure teen users are better protected throughout the social media ecosystem, Meta’s plea to YouTube and TikTok also reads as: “If we’re losing out on ad dollars to avoid being punished for encouraging excessive use, our biggest competitors should also suffer a loss in ad dollars.” In any case, if TikTok and YouTube want to avoid coughing up billions to settle social media addiction cases, they, too, will concede. In fact, Meta is positioning the settlement as the de facto industry standard for teen online safety in the absence of regulation.
It is not ridiculous to speculate that Meta is using this settlement to dictate what kids’ online safety standards look like for everyone else. The $17 billion over 10 years is the price it is willing to pay to set the rules of the road, and those rules could realistically confine new social media market entrants, limiting their ability to capitalize on the huge boon of ad-based business models driven by engagement-maximizing design features or from not having to deal with burdensome age-assurance architecture. Despite the market competition concerns, adhering to these standards may simply be the price to pay for deploying the engagement-maximizing design central to so many claims of harm. This makes the variety of procompetition, anti-monopoly policy proposals being considered by Congress all that much more important.
The settlement includes consequential provisions around “industry-wide adoption.” Meta has agreed to limit a teen user’s engagement to just one hour and release 30% of each state’s payment if Snap, TikTok and YouTube become subject to equivalent usage limit obligations, whether through their own settlements with that state, through legislation, or through voluntary compliance certified by an independent auditor. They must also be subject to age-assurance requirements “no less restrictive” than the ones Meta wrote for itself, plus a minimum of five years of third-party audits. States are therefore incentivized to lobby Meta’s competitors to jump on board in order to get the full promised payment, but only on terms Meta negotiated.
These industry requirements also pertain to any new social media company (but not chatbots or video games) that enters the market and is built primarily for teens to create and share user-generated video, competes for the same teen attention as Instagram and Facebook, and reaches 5 million U.S. monthly teen users averaging 30 minutes a day. Once a newcomer crosses those thresholds, states have five months to bring it under equivalent terms, or industry-wide adoption lapses. Meta’s obligations then revert to the weaker tier of protections. The practical result is that every state with money on the line has an incentive to chase down not just Snap, TikTok and YouTube, but every future platform that gets popular enough to threaten Meta’s market dominance. A company approaching five million teen users now faces a predictable regulatory event that flows not from any statute passed by anyone accountable to voters, but from the terms of a private settlement it had no part in negotiating, with compliance costs Meta can absorb far more comfortably than a newer market entrant can.
Effectively, this Meta settlement substitutes for regulation. A bill imposing the same obligations would have come with hearings, a public record, and the ability of a future legislature to amend or repeal it. Many of those obligations have drawn First Amendment challenges when proposed as legislation, yet a settlement leaves the users actually affected with no clear way to contest terms Meta accepted on the industry’s behalf. And while the settlement does not bind Meta’s competitors, it gives states billions of dollars in incentive to press those companies toward similar commitments. The concern therefore extends past Meta’s own rights. Users themselves are the ones who will see their reach limited or their access to lawful speech reduced.
Section 230 Is Not the Problem
For a while, plaintiffs hoping to hold social media platforms accountable for harm failed because of Section 230, because those cases often relied on exposure to user-generated content as the cause of harm. Courts allowed the MDL to proceed because the AGs pleaded around Section 230 by locating the harm not in what users saw but in how the platforms were built. But after hundreds of cases, judges are still landing in different places on which features qualify – autoplay, infinite scroll and variable reward schedules have been treated as content-agnostic design by some courts and as inseparable from curation by others.
In this settlement, Meta admitted no liability. No doctrine was settled here. Fortunately, we have proposed clarifying in statute that Section 230’s liability shield does not cover product design features that are neither third-party content nor the platform’s own expressive speech. In theory, conduct beyond hosting and moderating content is already outside Section 230’s scope. A targeted clarification would not impose liability on any design feature. It would simply let the argument be made in court on the merits, on content-neutral grounds that can survive First Amendment scrutiny, unlike the Section 230 sunset bills and content-based carve-outs that keep resurfacing in Congress.
The Work is Far From Over
The settlement runs 10 years, binds one company, and applies only in the states that signed it (all but New Mexico, Florida and Texas, which reached a different settlement). It admits no liability and expressly disclaims establishing a standard of care. Enforcement rests entirely with the attorneys general, whose largest remaining financial stake in the agreement depends less on how faithfully Meta complies than on whether Meta’s competitors can be brought to heel.
Meanwhile, lawmakers remain keen to pass legislation to regulate the broader social media industry. After all, the settlement’s requirements are only valid for 10 years. The Kids Online Safety Act (KOSA), which passed in a package of safe-by-design kids’ online safety bills in the House this year, contains many of the settlement’s feature-based requirements. But the Senate has a different version of KOSA, and the House and Senate are unlikely to reconcile the versions before the 119th Congress wraps up in January. While Congress works through its gridlock, states will continue to fill the void and push for safe-by-design and age-verification laws – like Age-Appropriate Design Codes adopted by a handful of states already, and Texas’ App Store Accountability Act – and many of these bills will continue to be challenged on First Amendment grounds.
Absent congressional or state action, every one of these obligations in the Meta settlement simply expires. What we need in the meantime is durable policy that balances public interest values and is made by people accountable to the public, not to a settlement’s payment schedule. That means comprehensive privacy legislation to limit the data collection driving these design choices in the first place, a targeted clarification that Section 230 does not shield product design, and kids’ safety laws that set protective defaults instead of shifting the work onto parents.
