Analysis
Meta's $18 billion settlement with 29 state attorneys general over youth safety contains a provision almost nobody covered on announcement day: the states agreed not to sue Meta under existing child-safety statutes for retaining and using children's personal data, TechCrunch reported. The permission is scoped -- it covers training and testing Meta's age-assurance model, and comes with guardrails -- but it is still a data-use immunity granted inside a case whose entire premise was that Meta mishandled children's data.
The logic is circular in a way that is worth stating plainly. The states want Meta to reliably know which users are minors so the behavioral remedies bite. Reliably knowing that requires an age-estimation model. Training an age-estimation model requires children's data. So the settlement that punishes Meta for collecting children's data also licenses it to keep collecting children's data, for one purpose.
The behavioral remedies
The rest of the deal is more conventional. Under-18 accounts default to a two-hour daily time limit, adjustable only by a parent. The apps are blocked by default between midnight and 6am, again parent-adjustable. The money -- up to $18 billion -- is distributed to states over ten years, and about 30% of it, roughly $5.3 billion, only gets paid if YouTube and TikTok implement their own one-hour daily limits, Night Mode and age-assurance measures. That structure effectively turns Meta's settlement into a lobbying instrument aimed at its two largest attention competitors.
How we got here
The multistate action grew out of the 2021 Frances Haugen disclosures and the wave of state suits filed in October 2023 alleging Meta designed Facebook and Instagram to be addictive to minors and collected under-13 data in violation of COPPA. Meta settled rather than take the case to a jury. For scale: the FTC's 2019 privacy fine against Facebook was $5 billion, and Google's 2019 COPPA settlement over YouTube was $170 million. Eighteen billion, even spread over a decade and partly contingent, is an order-of-magnitude reset in what platform child-safety exposure costs.
What it means for everyone else
Any consumer app with teen users should read the remedy list as a preview of the compliance floor: default time caps, overnight blocking, parental override, and a defensible age-assurance stack. Roblox, Snap, Discord and TikTok are the obvious next targets, and the contingent $5.3 billion gives Meta a direct financial incentive to see that happen. Age-verification vendors -- Yoti, Incode, Persona, k-ID -- just had their addressable market redefined by a settlement agreement rather than a statute.
The counterweight
The remedies rest on technology that TechCrunch reported does not work well. Age estimation from behavior and imagery has meaningful error rates, skews by skin tone and by age band, and fails hardest at exactly the 13-to-17 boundary that matters. A two-hour limit enforced against a model that misclassifies a meaningful share of teens as adults is a headline, not a control. And $18 billion over ten years, partly contingent, discounts to a manageable annual number against Meta's revenue -- this is expensive, not existential.
The clause to watch is the carve-out's expiry. A data-use immunity granted for model training tends to become permanent infrastructure unless someone wrote an end date into it.