Policypublished

Meta’s Up-to-$18 Billion Deal Carves Out Under-13 Data for Age-Assurance Testing

The agreement bars advertising and optimization uses of the data, but gives Meta protection from specified state claims as it builds a system to identify under-13 users. The FTC’s position remains unresolved.

By 4 min read
Meta’s Up-to-$18 Billion Deal Carves Out Under-13 Data for Age-Assurance Testing

Listen to this story

The audio brief

About 1:24
0:001:24
Read transcript
Meta can use a limited slice of data from users under thirteen to build and test an age-assurance system—but the same settlement bars the company from using that data for advertising, marketing, or algorithmic optimization. The agreement with attorneys general from twenty-nine states requires Meta to develop the detector and begin testing it within one year of the deal taking effect. In return, Meta gets protection from specified past, present, and future state claims—including claims under COPPA, the federal children’s privacy law—when they concern this narrowly defined use of children’s data. That creates a legal carve-out for building a system intended to identify under-thirteen accounts, not a general license to reuse kids’ information. The scale of the settlement is reported differently: TechCrunch puts it at up to eighteen billion dollars, while The Washington Post reports up to seventeen-point-one billion. More consequential than the difference may be what the agreement leaves open. It does not define which data Meta can retain, how much behavioral information training can include, or how long that material can be kept as the model evolves. An independent auditor will monitor compliance, but the Federal Trade Commission was not a party. So the key unresolved question is whether federal enforcement will accept the same compromise—and how tightly Meta’s permitted training data can be separated from the rest of its systems.

Story brief

3 key points

Meta’s settlement with attorneys general from 29 states creates a narrowly defined exception for using under-13 users’ data to train and test an age-assurance model, which must be operationalized within one year of the agreement taking effect. The data cannot support advertising, marketing, or algorithmic optimization, but the deal shields covered age-assurance use from specified state and COPPA-related claims. The...

  1. 01

    The settlement requires Meta to develop, train, and begin testing the detector within one year of its effective date.

  2. 02

    Coverage differs by account: TechCrunch reports up to $18 billion; The Washington Post reports up to $17.1 billion.

  3. 03

    An independent auditor will monitor compliance, but the FTC’s position on the federal compromise remains unclear.

Meta’s child-safety settlement gives the company a limited route to use data from users under 13 to train and test an age-assurance model, while barring use of that data for ads, marketing, or algorithmic optimization. The deal also protects Meta from specified past, present, and future state claims tied to that use, creating a consequential legal boundary around a system meant to identify young accounts.

A required detector, built with restricted data

The settlement requires Meta to develop, train, and begin testing a model designed to identify users younger than 13 within one year of its effective date. It allows the relevant children’s data only for training and testing that age-assurance model, with data-use guardrails. In this case, age assurance means building a system intended to determine which accounts belong to children under 13.

The permitted use sits beside explicit prohibitions: Meta cannot use data from under-13 users for ad targeting, marketing, or algorithmic optimization. The structure is therefore not a general authorization to reuse children’s information. It is a restricted training-and-testing exception tied to a specific detection task, alongside an obligation to add child-safety measures.

The carve-out extends to future state claims

The settlement agreement with attorneys general from 29 states includes protection from past, present, and future claims under COPPA, the federal children’s privacy law, or similar state laws when those claims concern Meta’s use of children’s data for age assurance. That protection is broader than a resolution of earlier conduct: it also defines the legal room available for the future data use covered by the agreement.

Its reach is not complete. The FTC primarily enforces COPPA and was not a party to the settlement, so it is unclear whether the agency has accepted the same compromise. An independent auditor is expected to monitor Meta’s compliance, adding oversight but not resolving the federal enforcement question.

The operational boundary is still undefined

The agreement’s restrictions are clear about several prohibited uses, but important implementation details remain open. It does not specify what data Meta will retain for training, how much behavioral information it may include, or how long that information will be kept. Those choices will shape how readily the permitted training data can be kept separate from other company systems.

Three boundaries the agreement leaves unspecified

  • The categories of children’s data Meta will retain for model training.
  • The amount of behavioral information that training may involve.
  • How long Meta will retain that data as the model changes.

A separate Senate fight over verification

The settlement lands as child-safety advocates raise concerns about a new Senate bill. The American Principles Project and other advocates say the bill would relax age-verification requirements and create an advertising carveout for Google. Those are the advocates’ characterizations of the proposed legislation, not terms established by the settlement.

The settlement’s top-line payment is also described differently in the two accounts. TechCrunch describes an agreement worth up to $18 billion, while The Washington Post says Meta agreed to pay states and territories up to $17.1 billion to resolve allegations about the platform’s effects on children’s mental health. The agreement’s data provisions make the practical stakes clearer than that difference alone: enforcing age limits may require access to the very information child-privacy rules aim to constrain.

Editorial analysis

Our Read

The agreement turns age assurance into both a compliance obligation and a data-governance test. Its most consequential feature is not simply the requirement that Meta identify under-13 users, but the attempt to ring-fence the data needed to train that system while limiting certain state claims. The next concrete signal is whether the FTC takes a position on the compromise, and whether settlement disclosures specify the data, retention period, and behavioral signals used in training. Those details will determine how narrow the exception is in operation.

Citation desk / original work

Cite this

Permanent attributionView citation
Finding 01

The agreement turns age assurance into both a compliance obligation and a data-governance test.

/posts/meta-s-up-to-18-billion-deal-carves-out-under-13-data-for-age-assurance-testing#finding-1

Sources

  1. techcrunch.comBuried in Meta's $18B settlement is a legal pass on kids' data | TechCrunch
  2. washingtonpost.comAI & Tech Brief: Exclusive | Child safety advocates raise alarm on Senate bill