Skip to content

Friday, August 28, 2026

Gigantum.net
Artificial intelligence

Buried in Meta’s $18B settlement is a legal pass on kids’ data

Meta’s settlement with 29 states allows it to retain certain data from children under 13 to train and test age-detection models, highlighting a privacy trade...

· 427 words

In addition to paying out up to $18 billion and adding child safety measures , Meta's settlement agreement with attorneys general from 29 states includes an interesting provision: The states have agreed not to sue Meta under existing child safety laws over its retention and use of children's data.

That permission is being granted for the limited purpose of training and testing Meta's age-assurance model and includes guardrails, but it's a curious policy decision to make in a case centered on child safety, and one that could be difficult to properly enforce.

As specified in the settlement agreement, Meta must develop, train, and begin testing a model designed to detect which users on Meta's platforms are under the age of 13. This must be done within a year of the document's effective date. (While the agreement doesn't specify that the model has to be AI-based, Meta's current age-detection tools are powered by AI technology.)

Under U.S. child safety law, COPPA (Children's Online Privacy Protection Act) typically requires that websites and apps limit the collection and retention of children's personal information. Meta's settlement agreement says that Meta shouldn't need to violate COPPA to train or implement its age-assurance models. However, the agreement also says that the state AGs have agreed "fully, finally, and forever" not to bring any past, present, or future COPPA claims — or claims under similar state laws — related to Meta's use of children's data.

The agreement makes clear that Meta can't use data from users under age 13 for ad targeting, marketing, or algorithmic optimization.

Meta's request for legal protection, and the state AGs' willingness to grant it, isn't unreasonable, says Philip N. Yannella, a partner at law firm Blank Rome and co-chair of its Privacy, Security & Data Protection practice. "These kinds of data minimization guardrails are pretty typical for privacy compliance: e.g., verifying compliance with deletion requests," he said, though he noted a caveat: COPPA is a federal law primarily enforced by the FTC, not the states, so it's unclear whether the FTC, which isn't a party to this settlement, has separately agreed to the same compromise.

It can be difficult for companies to keep data technically and organizationally isolated from the rest of their systems. Yet Meta is being asked to do just that — to isolate its understanding of children's behavior signals and other data and use it solely for detecting and removing under-13 users. Fortunately, an independent auditor will be involved in monitoring Meta's compliance with the settlement so we don't only have to rely on Meta's word.

Gathered from external sources. Rights to this text belong to whoever originally published it.