Meta Platforms Inc. has agreed to a landmark settlement with nearly every U.S. state that aims to impose curfews and time limits on teenage users of Instagram and Facebook. The agreement, reached after a federal trial in Oakland, California, requires Meta to identify which of its users are aged 13 to 17 within one year. Once identified, those accounts will have restrictions automatically enabled, with only parents permitted to modify or remove the limitations.
Despite the settlement’s ambitions, significant challenges remain regarding how Meta will verify users’ ages and parental identities. The company must determine the age of every user in the participating states and territories, including adults, to enforce these measures. Proposed verification methods include government-issued identification, mandatory selfies, and behavioral analysis of user activity. Accounts that fail to confirm age within 14 days will be subject to the same restrictions placed on teenagers.
However, the effectiveness of such approaches is uncertain. Critics point to similar regulations abroad, such as in Australia where the ban on social media use by children under 16 has been largely circumvented through virtual private networks (VPNs) that disguise users’ true identities and locations. The challenge extends to parental verification as well. The settlement offers no mechanisms to conclusively prove that an adult acting as a guardian is legitimate, raising concerns over potential misrepresentation. During the trial, Judge Yvonne Gonzalez Rogers questioned how Meta would prevent older siblings or other individuals from impersonating parents. A California prosecutor involved in the case acknowledged the issue, noting that there is currently no requirement for parental identification such as birth certificates.
Experts highlight that without reliable verification, curfews and time limits may remain largely theoretical. Jasmine Enberg, a social media analyst, remarked that teenagers are adept at circumventing such controls and that the onus may shift onto parents to enforce the rules, possibly insulating Meta from future legal challenges. In France, where a ban on users under 15 was struck down recently, regulators found that children often bypass restrictions with parental assistance.
To estimate users’ ages when explicit identification is unavailable, Meta plans to analyze behavioral data, a practice that raises privacy concerns. The digital rights advocacy group Electronic Frontier Foundation warned this approach institutionalizes invasive surveillance and risks exposing users to data breaches and government inquiries. The proposed safeguards limit data collection to what is necessary for age estimation and provide an appeal process for adults misclassified as minors. Iain Corby, head of the Age Verification Providers Association, called the settlement “the most significant intervention in children’s online safety” to date.
Nevertheless, age verification methods carry inherent risks. A breach at a third-party age-verification vendor in October compromised government IDs of 70,000 Discord users, underscoring potential vulnerabilities. Other technology companies, such as OpenAI, have experimented with approximating users’ ages based on interaction patterns, a practice Meta’s settlement permits.
Internationally, regulatory frameworks vary. The European Union has delayed similar measures due to strict rules on tracking minors, while France employs a “double-blind system” where a trusted third party verifies age without revealing user identities to websites. This type of system does not exist in the United States, where Meta will conduct all age verification internally and retain the collected data.
As Meta moves forward with implementing these unprecedented restrictions, questions remain about their practical enforcement and impact on user privacy.
