Meta agreed to a massive $18 billion legal settlement containing an interesting safety provision signed by attorneys general from 29 states. State officials agreed not to sue Meta under existing child safety laws over how the company retains and uses children’s personal data.
This permission allows Meta to train and test age-assurance models without state lawsuits. Giving an online giant permission to collect and retain user records seems like a strange choice for a case centered entirely on child protection, making enforcement tricky down the road.
Settlement terms force Meta to build, train, and test software models designed to spot users under the age of 13 across its platforms. Meta must deploy this detection system within one year of the effective agreement date. While official text does not state that the system must run on smart code models, Meta currently uses automated tech to run age detection.
Federal standards under the Children’s Online Privacy Protection Act limit how websites gather and hold children’s personal data. The settlement paperwork states Meta does not need to violate federal rules to build its detection system. However, state attorneys general agreed to drop all past, present, and future claims regarding how Meta uses children’s data under state laws.
The agreement specifies that Meta cannot use data from children under 13 to serve targeted ads, execute marketing campaigns, or run algorithmic optimizations.
Legal expert Philip N. Yannella from law firm Blank Rome noted that asking for legal protections while testing safety features makes sense. He pointed out that privacy agreements usually include data minimization rules, like checking deletion requests. However, Yannella emphasized that federal regulators at the FTC hold primary power over federal children’s privacy rules, and the FTC is not a party to this specific state settlement.
Keeping children’s data separate from primary core algorithms creates huge technical hurdles. Meta must isolate behavioral signals, chat logs, and profile records from the rest of its massive data systems. An independent auditor will track Meta’s internal compliance so the public does not have to trust internal company reports alone.
Monitoring these data boundaries will prove difficult over time. Data gathered for age safety systems could accidentally leak into other internal tools. The settlement agreement leaves key questions open. It does not state how much raw data Meta can save, how long records remain on internal servers, or how model updates will change data retention practices over time.
While state attorneys general cannot sue over these specific data practices, private citizens still hold rights. Attorney Joshua Wurtzel noted that if Meta uses children’s data outside approved boundaries, individuals can file civil lawsuits, though proving those claims in court remains complicated.
Data attorney Peter Jackson warned that giving tech giants legal immunity creates bad incentives, potentially weakening future legal enforcement. The overall deal reflects fast, heavy negotiations between state officials and tech lawyers.
Building modern automated tools often requires massive training datasets. Developers build systems that analyze human behavior to spot young users online. However, collecting sensitive records to build safety features forces regulators to balance real child protection against user privacy.

