Meta has agreed to a settlement worth up to $18 billion with attorneys general from 29 U.S. states that not only adds child‑safety measures but also bars the states from suing the company under existing child‑privacy statutes for its use of children’s data. The agreement, which focuses on compliance with the Children’s Online Privacy Protection Act (COPPA), grants Meta a permanent legal shield for data used to train and test an age‑assurance model.
Settlement terms and age‑assurance obligations
Under the deal, Meta must develop, train, and begin testing a system that can identify users younger than 13 on its platforms within one year of the settlement’s effective date. While the text does not require the model to be AI‑based, Meta’s current age‑detection tools rely on artificial‑intelligence technology, suggesting the new system will likely follow the same approach.
The agreement explicitly prohibits Meta from using data belonging to users under 13 for advertising, marketing, or any algorithmic optimization. Instead, the data may be used solely to detect and remove accounts belonging to minors. An independent auditor will monitor Meta’s compliance, providing an external check beyond the company’s own assurances.
Legal implications and expert commentary
State attorneys general have agreed “fully, finally, and forever” not to bring past, present, or future COPPA claims—or comparable state‑law claims—related to Meta’s use of children’s data for the age‑assurance model. Philip N. Yannella, a partner at Blank Rome, noted that such data‑minimization guardrails are common in privacy compliance, but cautioned that COPPA is a federal law enforced primarily by the FTC, which is not a party to the settlement.
Joshua Wurtzel of Schlam Stone & Dolan LLP warned that the immunity does not protect Meta if it uses the data outside the agreed parameters; any breach would nullify the covenant not to sue, though any ensuing dispute would still be legally complex. Peter Jackson, a Data & IP attorney at Greenberg Glusker LLP, said the carve‑out could “disincentivize future enforcement actions,” suggesting the settlement may limit states’ leverage in overseeing Meta’s data practices.
Enforcing the data‑isolation requirement presents practical challenges. Companies often find it difficult to keep data technically and organizationally separate from broader systems. The settlement requires Meta to isolate children’s behavioral signals solely for the purpose of age detection, yet the agreement does not detail what specific data will be retained, how much behavioral information will be included, or the duration of retention. The lack of clarity raises questions about whether insights derived from the data could inadvertently feed into other Meta products.
Broader industry context
The clause reflects a growing tension across the AI industry, where advanced agents increasingly need extensive personal data to function effectively. As AI tools become more integrated into consumer experiences, firms argue they require deep insight into user behavior—including that of children—to train reliable models. Meta’s settlement illustrates how regulators and companies are negotiating the balance between privacy protections and the data demands of emerging AI technologies.
While the settlement provides a clear financial commitment and a roadmap for age‑verification technology, its legal shield on children’s data use may set a precedent for future negotiations between tech firms and state regulators. The involvement of an independent auditor offers some oversight, but the ultimate effectiveness of the data‑use limitation will depend on Meta’s adherence to the strict boundaries outlined in the agreement and on any future actions by the FTC or other federal authorities.
Mitchell Landsberg is the senior reporter for News Raise and focuses on Technology. Mitchell regularly writes about social media platforms and how influencers, industry and general people use them to communicate and make money.




