On August 26, 2026, Meta agreed to pay up to $17.1 billion over ten years and overhaul how Instagram and Facebook operate for minors, settling a case brought by a bipartisan coalition of attorneys general from 51 states and territories just one week into trial before Judge Yvonne Gonzalez Rogers in the U.S. District Court for the Northern District of California (California DOJ; NY AG). The figure can rise toward $18 billion if TikTok and YouTube adopt comparable restrictions — a clause designed to spread the cost of teen-safety redesign across the industry rather than let competitors free-ride on Meta's compliance burden.
The case traces back to a 2023 multistate lawsuit — 33 attorneys general filed jointly in the Northern District, with several others suing separately — alleging Meta knew its algorithmic feeds, infinite scroll, and near-constant notifications were addictive to minors and misrepresented the risk to parents and regulators (NPR, 2023). Trial testimony from former Meta engineering director Arturo Béjar — who told the court the company was built to "keep people engaged even if it harmed their mental health" because disengaged users generate no revenue — reportedly accelerated settlement talks once the case reached open court in Oakland.
What Meta Actually Has to Build
The settlement is unusually specific for a legal document, functioning more like a product spec than a consent decree. Within months, Meta must ship: a default two-hour daily cap for under-18 users (removable only with parental sign-off); a midnight-to-6am access block; notification blackouts overnight and during school hours; age-assurance systems built to detect under-18 users and remove under-13 accounts; hidden like-and-reaction counts for minors; and a ban on cosmetic-surgery image filters. An independent auditor will monitor compliance, and the deal requires a response to flagged harmful content within six hours for 90% of reports.
This is the steelman case for the settlement, and it's a real one: self-regulation has had a decade to work and, by the plaintiff states' own trial record, didn't. Meta's existing teen protections — introduced piecemeal after the 2021 Facebook Papers — were mostly opt-in, and uptake among the users who needed them most was reportedly low. Making the defaults protective rather than permissive is a legitimate response to a documented behavioral-economics problem: few 15-year-olds will voluntarily toggle on a feature that reduces their own engagement. And structurally, one negotiated national settlement is a better outcome than the alternative Meta was actually facing — fifty separate state trials, verdicts, and injunctions, each potentially imposing conflicting design mandates. A federal circuit split over what a "safe" feed algorithm looks like would have been far more disruptive to how every platform operates than one uniform settlement.
Where the Deal Overreaches
But the settlement's critics — including some who support its aims — have identified real problems, and they're worth taking seriously rather than waving away as anti-regulatory reflex. Fairplay executive director Josh Golin objected that the deal leaves recommendation algorithms and chronological feeds opt-in rather than default, meaning the single most-studied driver of compulsive use is untouched by the mandatory provisions. Béjar himself, despite calling the settlement a "significant milestone," flagged that it lets Meta define what counts as "harm" for compliance purposes — a company grading its own homework is not a new problem in platform regulation, but it's a real one here given the auditor's scope depends on Meta's own harm taxonomy. Cybersafety Research Center director Yaël Eisenstat's caution that it's "premature" to know whether the changes will actually materialize as promised is the correct level of confidence twelve months out from a settlement whose enforcement mechanism is still an open question.
The deeper structural concern is one the trial-avoidance framing obscures: this is product regulation for the entire under-18 US internet population, negotiated behind closed doors between 51 state legal offices and one company's litigation team, with no legislative hearing, no public comment period, and no opportunity for competing platforms, child-development researchers, or free-expression advocates to weigh in on tradeoffs like whether a blanket two-hour cap is the right blunt instrument versus more targeted interventions. Congress has spent years failing to pass the Kids Online Safety Act precisely because lawmakers disagree on where the line between protection and censorship sits; a settlement lets 51 attorneys general answer that question by consent decree instead. That may be the pragmatic path given a gridlocked Congress, but it's worth naming as a bypass of the ordinary regulatory process, not a substitute for it.
The Real Test Is Enforcement, Not the Number
$17 billion sounds enormous until set against Meta's roughly $170 billion in 2025 revenue — a one-time, ten-year-amortized cost of doing business, not a number that changes incentives at the margin. The provisions that will actually matter are the ones with teeth: whether age assurance genuinely keeps under-13 users off the platform without becoming a privacy-invasive verification regime for everyone, and whether the independent auditor has real access rather than curated dashboards. Those questions won't be answered by the settlement text — they'll be answered by the first compliance report, whenever that lands.