A view from DC: Getting to 'yes' on safe social media for teens

The historic multistate Meta settlement fast-tracks a teen-safety framework lawmakers long sought but could not require.

Contributors:
Cobun Zweifel-Keegan
CIPP/US, CIPM
Managing Director, Washington D.C.
IAPP
Editor's note
Meta's massive landmark settlement with almost every U.S. state attorney general last month will have ripple effects for digital responsibility professionals for years to come. Much has already been written about the innovative legal approach to social media addiction in the lawsuit, its unique provisions that push for other competitors' platforms to meet the same agreed standards and the record setting monetary settlement in the case.
But how innovative are its injunctive terms?
Though the package of operational requirements is expansive, prescriptive and remarkably granular, they also closely mirror the landscape of minor safety compliance obligations that would soon apply to social media and algorithmic feed companies. For some of these changes, prior or pending litigation would block, on free-speech grounds, regulatory mandates. But the voluntary nature of the legal settlement makes the same interventions allowable here.
We probably will not ever know for sure where the list of injunctive requirements came from, but it is interesting to note these parallels with existing or anticipated compliance obligations. Equally interesting are those areas where the new requirements diverge from existing proposals. Usually, the settlement is a little stronger than what we see in state laws, but there are a few examples where the opposite is true.
Age assurance accuracy
The settlement creates new age assurance frameworks, with multiple mechanisms for measuring ages under 18 and policing users under 13.
It also includes stringent benchmarks for the accuracy of these mechanisms. Meta's accuracy commitments generally follow the contours of more granular statutory requirements, while narrowly avoiding mapping onto them directly. This is a good example of the types of echoes of the national policy debate that can be heard throughout the settlement. Under the agreement, within the next year the rate of minor users who are incorrectly identified as over 18 must be under 10% for minors aged 16-17 and under 3% for minors aged 13-15. The thresholds are less stringent if Meta develops its own internal age assurance technologies, but only if they rely on different methods than commercially available technologies such as facial age estimation.
Meanwhile, New York's SAFE for Kids Act regulations impose a more granular set of accuracy requirements broken down into five age ranges, including 8% of 16-year-olds, 15% of 17-year-olds, 2% of minors ages 14 to 15, and 1% of minors ages 8 to13. The slight differences work in such a way that meeting all the targets simultaneously is possible, especially taking into account the other differences that make the math more complex. For example, the settlement excludes "method circumvention" from the false positive count, while New York's rules explicitly include "inconclusive age assurance outcomes" in the false positive counts. New York separately requires that platforms should be able to detect method circumvention with an accuracy rate of 98%.
Similarly, Utah's SB 194, though currently enjoined pending the resolution of NetChoice's legal challenge to the law, would require a more generous overall accuracy rating of 95%.
The settlement also mandates data minimization requirements limiting the usage of age assurance data, just like existing compliance rules.
Screen time limits
The agreement establishes a detailed structure for time management interventions, bifurcated into two phases, depending on how Meta’s competitors continue to behave. For simplicity, we can focus on the first, generally applicable, phase.
There are at least four time-based limits in the agreement:
- A default daily cumulative usage limit of two hours across all Meta platforms. This is a hard cap rather than just a passive warning, disabling all functionality except for direct messaging and access to settings, though it can be lifted with parental approval.
- A night access mode that locks teens out of the platform from midnight to 6 a.m. based on the device's local time zone and turns off push notifications for a slightly longer period, subject to parental changes.
- A school mode that disables push notifications during the standard school hours of 8 a.m. to 3 p.m.
- And the introduction of productive pauses, designed to "reduce or prevent excessive, mindless, or unintended teen usage." These are mandatory, escalating full-screen interruptions that trigger after 60 and 90 minutes of daily usage, alongside clear notices upon any 15-minute session of continuous, unbroken scrolling.
Overall, these new commitments create the most distinctive set of obligations seen in the settlement. Most existing state statutes, including the New York SAFE Act and various age-appropriate design codes, limit their own interventions to banning push notifications during overnight periods and requiring design features that would allow for voluntary time limits. Federal proposals, though not passed into law, have generally mapped into the same set of interventions.
Lawmakers have historically hesitated to mandate hard digital lockouts due to constitutional concerns regarding a minor's First Amendment right to receive information and the potential danger of restricting access to critical support networks during nighttime crises. A few states have pushed the boundary on this but have generally been blocked by courts. Virginia, for example, passed SB 854 last year, which would have created a one-hour daily limit on covered apps, but it was blocked by a court.
As a voluntary agreement, the Meta settlement is not subject to the same First Amendment objections. And it avoids safety concerns by exempting direct messaging from both the daily screentime limits and nighttime lockouts, ensuring teens are not isolated from peer support or emergency communications.
Ugly filters only
Another First Amendment dodge shows up in Meta's agreement not to display like counts on teen users' content. Though long contemplated as an intervention that could improve mental health among young users, this is another example of a rule that would be unconstitutional if mandated by a legislature. In fact, the U.S. Court of Appeals for the Ninth Circuit invalidated just such a rule from the California Age-Appropriate Design Code.
Meta has also agreed to disable the ability of teen users to apply cosmetic procedure filters to their content. These are augmented reality effects that distort, sculpt, redefine, or idealize a user's facial structure in ways that mimic cosmetic surgery, such as lip fillers, jawline enhancements, cheekbone alterations. Harmless AR effects like cartoon overlays or basic color smoothing are allowed. This level of prescription over content would almost certainly never be attempted through a legislative intervention, but Meta's concessions in this case make it reality.
The boring feed option
The settlement requires Meta to provide teen users — and their supervising parents — with an option to set their default feed to a nonpersonalized feed, populated by accounts the user follows or is connected with, displayed in reverse chronological order without algorithmic optimization for engagement. The platforms must also actively prompt teen users within 10 days of account creation, and every 90 days thereafter, offering the option to switch to the chronological feed.
This, too, mirrors the ideas that have shown up in recent legislative activity. However, the New York SAFE for Kids Act goes one step farther, making the nonpersonalized feed the default setting, absent parental consent.
Parents permanently over shoulder
Setting aside New York's unique law, the parental oversight requirements throughout the Meta settlement provide for far more parental control than most legislatures have contemplated. In fact, this may be the most aggressively pro-parent set of requirements seen outside of the U.S. House, where Republican lawmakers have been particularly enamored of parental rights in their recent proposals. Additionally, parental intervention is perhaps the area where Meta's existing rollout of teen safety features will need to be most markedly changed in the coming months.
The protective default settings for teens in the settlement can usually only be changed if teens link their account with a supervising parent. EFF decried this "parental supervision tradeoff," concluding that the enhanced parental controls "may be ultimately workable for young people with healthy and safe relationships with their parent or guardian. But obviously it is not good at all for a Teen User lacking such a safe relationship."
Under the settlement, supervising parents are granted visibility into adolescents' platform usage, including discrete metrics for total time spent, messaging time, viewing of longform content, lists of social connections, and alerts regarding new account creations. It includes interesting requirements about hunting out alt accounts using "single user multiple account" systems, requiring Meta to apply the same time limits when it identifies a teen users' Finsta, as the kids call it.
Remarkably, the structure in the settlement even limits parental choices to override teen time limits, requiring exemptions provided by parents to be themselves time limited. That is, if a parent allows for additional time on a platform, they will be required to select an amount of time for which the exemption is valid, such as one day or one week, and cannot be given an option to permanently expand the time limit.
A holistic approach to content
In setting limits on age-inappropriate content such as material related to self-harm, eating disorders, sexually explicit language, and viral challenges, the settlement introduces some innovative ideas.
For one, it defines a concept of "sensitive aggregate content." This includes topics that may be benign in isolation, such as discussions of fitness routines or diet, but can become psychologically toxic to adolescents when an algorithm serves them in relentless quantities. Meta agrees to deploy product interventions that would interrupt repeated exposure to content in these categories.
This likely approaches the type of intervention envisioned by a "duty of care" under legislation like the Kids Online Safety Act, which would require platforms to mitigate specific harms to minors, without prescribing how it is done. It is a more holistic approach than some other legislative interventions, like the U.K.'s Online Safety Act, which is more focused on strict limits for only the "primary priority content” like self-harm and eating disorders.
What's next for global platforms?
Though this outcome fast-tracks the deployment of many safety mechanism that had only been dreamed of until now, there are many open questions. Will these mandates become industry standard among Meta’s competitors, as the settlement seems to envision? Will they spread to other countries, or will strict bans, like Australia’s approach, win the day? And Meta's courtroom saga is probably still unfinished. Notably, Florida's attorney general rejected the multistate settlement, tweeting that "The payouts are peanuts compared to the profound harms Meta's profit-driven addictive features inflicted on kids, and a slap on the wrist for a trillion-dollar corp.
Please send feedback, updates and chronological content to cobun@iapp.org.

This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.
Submit for CPEsContributors:
Cobun Zweifel-Keegan
CIPP/US, CIPM
Managing Director, Washington D.C.
IAPP
Tags:



