Meta has struck a deal to pay out up to $18 billion and bolster child safety measures, but there's a catch. The states have agreed not to sue Meta under existing child safety laws over its retention and use of children’s data, specifically for training and testing its age-assurance model. This means Meta can continue to collect and use kids’ data without violating COPPA, the Children’s Online Privacy Protection Act.
The agreement requires Meta to develop and test a model within a year to detect users under 13. This model, while not explicitly AI-based, will be crucial in ensuring compliance with age-related restrictions. However, the legal pass granted could be difficult to enforce, as states have agreed not to bring any COPPA claims related to Meta’s use of children’s data in the future.
The carve-out could disincentivize future enforcement actions and complicate legal avenues for states if questions arise. This decision highlights a broader issue in the AI industry: the need for significant access to personal data to function effectively. While the agreement includes guardrails, the lack of clarity on data retention and usage could lead to potential misuse.
Philip N. Yannella, a privacy compliance expert, notes that such data minimization guardrails are typical. However, the involvement of an independent auditor will help monitor compliance, ensuring that Meta doesn’t use the data for ad targeting or algorithmic optimization. The settlement's terms also mean that if Meta uses the data outside the settlement’s terms, the release and covenant not to sue won't apply.







