What happened
Meta's child safety settlement with US state attorneys general, valued at 17.1 billion US dollars, has been described by the states as the largest US consumer protection resolution in the country's history.
The consent judgment was filed on 26 August 2026 in the Northern District of California, within a wider consolidating litigation. It requires structural and algorithmic changes to Facebook and Instagram affecting younger users, including enhanced age assurance, daily usage limits, overnight access restrictions, parental supervision tools and controls designed to shape engagement.
The settlement creates no new UK or EU obligations, but the issues it addresses are already live under GDPR, UK GDPR, the EU Digital Services Act, the UK Online Safety Act 2023 and the ICO's Children's Code. In the EU, the Commission issued preliminary findings against Meta on age assurance in April 2026, then in July 2026 questioned recommender systems, autoplay and infinite scroll, raising what it called addictive design. Those findings remain preliminary. DSA Article 28 requires proportionate measures for children, and Articles 34 and 35 require large platforms to mitigate systemic risks arising from design.
In the UK, the Online Safety Act requires a children's risk assessment that expressly considers how design and algorithms affect the risk of harm, followed by proportionate mitigation. Section 70 of the Children's Wellbeing and Schools Act 2026 inserted a new power broadening the Act from user-to-user services to internet services, allowing regulations that restrict access, time spent and times of day. Announced measures cover under-16s, autoplay and personalised feeds, but they are not yet active duties. The ICO fined Reddit 14.47 million pounds in February 2026 for UK GDPR failures including no robust age assurance and non-compliant impact assessments. In September 2026, Portuguese group D3 filed collective proceedings against four major platforms over engagement features.
Why this is a GRC story
Design is now the control. The distinction is between content compliance and design compliance. Moderating individual posts well does not answer whether recommender systems, autoplay and defaults create a separate risk. Product governance has to cover how a service is built, not only what appears on it.
The settlement is evidence, not law. It does not bind European regulators, but it shows that a given safeguard can be run at scale. That weakens the argument that a measure is technically impossible elsewhere and shifts the burden in proportionality arguments.
Two regulators, two regimes. One regulator covers harm from content and the other covers children's data. The same feature can trigger both, so the assessments cannot be run in isolation by teams that never compare notes.
Phased obligations must not be conflated. Existing duties, the new regulation-making power and announced future requirements are three distinct phases. Treating all three as already binding produces either wasted effort or false assurance.
What to watch
Watch whether the EU KIDS Act proposal converts the design debate into specific safety by design requirements. Watch whether the UK's first regulations land, with the government aiming to lay them by the end of 2026 and implement in spring 2027. And watch whether the ICO's approach extends beyond one platform, since it showed that a minimum age clause in terms is not enough when children can bypass the controls.
Attribution: Analysis based on JD Supra's publication of the Kennedys analysis and the underlying consent judgment and regulatory findings it cites. This article is original commentary, not a repost of the source material.
