California is trying to redesign childhood online
A new package of laws reaches beyond screen-time advice and into product design: addictive feeds for users under 16, liability when large platforms harm children, and stricter rules for AI companion chatbots. The next fight is over whether safety can be built in without turning age checks into a new privacy and speech problem.
For years, the American argument about kids and technology was pushed down to the household level: set a bedtime, take the phone away, check the apps, negotiate one more hour. California’s latest move changes the assignment. The state is telling some of the world’s biggest technology companies that the design of the product itself — the feed that never ends, the video that starts by itself, the chatbot that keeps a child talking — can become a legal safety issue.
Gov. Gavin Newsom signed the sweeping package on September 10 at a children’s museum near San Francisco. The Associated Press reported that the measures include restrictions on addictive social-media feeds for users under 16, stronger civil liability for large social-media companies when children are injured, risk assessments and safety controls for AI companion chatbots, and a new ability for families to decline school-issued laptops. The bills do not all do the same thing, and they do not all switch on at the same time. Read together, however, they amount to one of the clearest attempts by a U.S. state to move youth online safety from parental guidance into product engineering and legal accountability.
That distinction matters. The most consequential question is no longer simply whether a teenager is “on social media” or “using AI.” It is what version of the service the child receives, what the system knows about the child’s age, which engagement features are active, how a conversational system reacts when a child appears to be in danger, and who carries the financial risk when safeguards fail.
One package, three different levers
Design restrictions, chatbot safeguards and liability work on different parts of the same problem.
It is easy to compress the California package into a headline about a “social-media ban.” The final legislation is more specific. Assembly Bill 1709 targets what the law calls addictive features. The enrolled text says covered platforms may not provide those features to users under 16 and must take reasonable measures to keep them from doing so. The definition includes an addictive feed and autoplay, while leaving room for the attorney general to identify additional features through regulation.
Just as important, the latest text no longer means that every person under 16 must be erased from every covered social network. It expressly allows a younger user to keep or create an account if the platform does not provide the prohibited addictive features. That creates a policy model closer to a “youth mode” than a universal account ban: the same service could look materially different depending on the user’s age bracket.
Change the feed
Under-16 users cannot be served covered addictive features. Age assurance and enforcement rules become the hinge.
Change the chatbot
Companion-chatbot operators face child-safety assessments, default protections, crisis duties, data limits and audits.
Change the risk
Large social platforms can face statutory damages when a failure of ordinary care causes injury to a child.
Assembly Bill 2 works differently. Rather than prescribing a feed, it creates a damages framework tied to ordinary negligence law. For social-media platforms with more than $100 million in annual gross revenue, a child injured by a violation can seek statutory damages of $5,000 per violation, up to $1 million per child, or three times actual damages, whichever is larger. The provision is prospective, and the enacted text sunsets the special damages section in 2035. The practical significance is not that every bad online experience becomes a million-dollar case; plaintiffs would still have to establish the legal elements. The significance is that a company’s safety decisions now carry a more explicit litigation price.
The social-media rule is narrower — and more technical — than a ban
The final version puts pressure on product architecture rather than simply closing the door.
AB 1709’s most important policy choice is to separate access from engagement design. A child under 16 may still be able to have an account, but the covered platform has to withhold the features the statute classifies as addictive. That difference could reshape the experience in subtle ways. A chronological list of accounts a teenager deliberately follows may survive where a recommendation engine optimized to keep the teenager scrolling does not. A video selected by the user may play; the next one may not launch automatically. Notifications, recommendations and other attention-capturing tools could be treated differently as regulators define the boundary.
This also means the law will live or die on definitions. Platforms will argue over what counts as a recommendation, what is truly “addictive,” which services are covered and how aggressively the attorney general should expand the category. A static legal rule has to govern products that can change weekly. California’s answer is an e-Safety Advisory Commission and regulatory authority for the attorney general, giving the framework a way to evolve without waiting for a new statute every time a product team invents a new engagement mechanic.
Age assurance is the hinge — and the privacy risk
A rule for minors cannot work unless the service has a reliable way to know who is a minor.
California has been building an age-assurance system alongside its child-safety laws. The state’s Digital Age Assurance Act is scheduled to begin operating in 2027 and is designed around age brackets rather than a platform independently collecting a full identity document from every user. AB 1709 ties its compliance system to that framework. In theory, the service needs to know something like “under 16” or “adult,” not a person’s birthday, driver’s-license image and home address.
That sounds like a privacy improvement, but it does not make the argument disappear. Any system that gates lawful online activity by age has to create a signal somewhere, and critics worry that age checking can normalize more identification across the internet. Civil-liberties advocates have also argued that young people use online communities for education, political expression, health information and support that may not be available at home. The narrower final version of AB 1709 answers part of that criticism by allowing non-addictive accounts, but it does not eliminate the constitutional or privacy questions around deciding who gets which version of the internet.
The implementation challenge is therefore a three-part test: the age signal has to be accurate enough to stop obvious evasion, private enough not to become a new tracking system, and frictionless enough that adults are not pushed into excessive identity checks. A system that fails any one of those tests could undermine the public support that made the child-safety rules politically attractive in the first place.
Chatbots are being regulated as relationships, not just answer machines
SB 1119 focuses on the risks that emerge when a system keeps a child in a long, personalized conversation.
California already required companion chatbots to tell users that they are interacting with artificial intelligence and to maintain protocols around self-harm. SB 1119, known as Adam’s Law, goes further. The enrolled bill covers companion chatbots that sustain adaptive, human-like interactions over time, and it treats prolonged engagement with a child as a product-safety problem rather than merely a content-moderation problem.
The legislation requires age assurance and risk assessments before new or substantially modified companion chatbots are released. It calls for crisis-support procedures, including mental-health resource referrals and parental notice in defined high-risk circumstances. For child users, default settings are meant to limit notifications, usage time and persistent conversational memory unless a parent changes them. The bill also restricts behavioral advertising and the sale or unnecessary use of personal information gathered through a child’s chatbot conversations. Larger operators face independent child-safety audits, with high-level results disclosed and full reports available to the attorney general under specified conditions.
The law is named for Adam Raine, a California teenager who died by suicide in 2025. His parents have sued OpenAI, alleging that extended conversations with ChatGPT contributed to his death; the company has disputed legal responsibility in the litigation. California lawmakers cited the case while building the new safeguards. It is important to keep the distinction clear: a family’s allegations in a pending lawsuit are not the same thing as a court finding. The legislation is a policy response to the risk lawmakers believe the case exposed, not a verdict on the underlying lawsuit.
New or materially changed companion systems must be evaluated before they reach users.
Limits on notifications, session time and memory are designed to reduce dependence and overuse.
The law calls for support resources and defined parental-notice procedures in serious situations.
Independent reviews and reporting create evidence regulators can use rather than relying on promises.
Liability changes the conversation inside the company
AB 2 turns child-safety decisions into a question for lawyers, insurers, boards and product leaders — not only trust-and-safety teams.
Regulation can tell a company what it must build. Liability changes what happens when the company gets the trade-off wrong. AB 2 applies to large social-media platforms — those above the law’s $100 million annual gross-revenue threshold — and attaches statutory damages when a failure to exercise ordinary care causes injury to a child. The formula, up to $5,000 per violation and $1 million per child or three times actual damages, makes repeated failures potentially expensive without guaranteeing any particular award.
For families, the appeal is obvious: a safety promise without a remedy can feel voluntary. For platforms, the concern is equally obvious: a broad negligence theory can be difficult to price when harm may involve design choices, user-generated speech, family circumstances and a child’s own behavior. Courts will have to decide where ordinary care begins and ends. Federal protections for online intermediaries, First Amendment rules and causation standards will remain part of that litigation landscape.
But even before a case reaches a courtroom, liability can affect internal incentives. A recommendation experiment that once asked only whether engagement rose may now prompt a second set of questions: Was the change tested on minors? Did the company know about a safety risk? Were warnings ignored? Can engineers reconstruct what the product showed a child? Those are governance questions, and they encourage companies to preserve evidence, document safety decisions and involve senior leadership earlier.
The constitutional fight is already waiting
California has learned that writing an online-safety law is easier than keeping every provision alive in federal court.
The new package arrives with legal history attached. In March, the U.S. Court of Appeals for the Ninth Circuit kept most challenged provisions of California’s earlier Age-Appropriate Design Code blocked while litigation continues. That case is not a ruling on AB 1709, AB 2 or SB 1119. It does, however, show why the new laws were drafted with close attention to speech, age estimation and product design.
Opponents are already framing the dispute in constitutional and privacy terms. The Electronic Frontier Foundation opposed AB 1709 during the legislative process, warning that broad age restrictions can silence young people and force more users into age checks. NetChoice, an industry group that has repeatedly challenged state technology laws, urged Newsom to veto AB 2 and argued that large damages tied to hosted speech could pressure platforms to remove lawful expression. Those groups have won important injunctions against earlier California rules, so their objections cannot be dismissed as theoretical.
Supporters answer that the new framework is aimed at conduct and design: autoplay, addictive recommendation loops, unsafe chatbot behavior, inadequate crisis handling and failures of reasonable care. That is the legal line California will try to defend. The closer a rule looks like a neutral safety standard for a product feature, the stronger the state’s position may be; the closer enforcement looks like government pressure over what lawful material a young person may see, the harder the First Amendment questions become.
What changes for a family — and what does not
The laws do not flip a statewide switch today, and they do not replace parental judgment.
Parents should not expect every teenager’s phone to look different this morning. The statutes have implementation dates, regulatory work and technical dependencies. SB 1119 makes key provisions operative in July 2027. The age-assurance system on which AB 1709 relies is tied to California’s broader 2027 age-bracket framework. Laws can also be delayed or narrowed by litigation. For families, the immediate change is therefore less visible than the long-term direction.
If the laws take effect as designed, under-16 users could receive a stripped-down social-media experience that removes designated engagement features while preserving basic communication and deliberate browsing. Parents of children using companion chatbots should eventually see stronger default protections, clearer controls and more defined crisis procedures. Families in public schools will also have a new option, reported by the AP, to decline school-issued laptops under one of the signed measures — a reminder that the package extends beyond social platforms and into the broader question of how much technology children are expected to use.
California’s real influence may be the product spec
A state law can reach beyond state lines when companies decide it is easier to build one safer product than fifty different versions.
California is the country’s most populous state and one of the centers of the technology industry. That combination gives its consumer rules unusual leverage. A platform can build a California-only compliance system, but engineering, legal review and customer support become more complicated as more states adopt different age thresholds and definitions. Companies sometimes respond by using the strictest workable standard more broadly. If that happens here, a rule written in Sacramento could influence what a teenager sees in Ohio or Florida even without a federal law.
There is already movement elsewhere. New York has adopted restrictions that let parents block algorithmically suggested social-media feeds for children, with implementation expected in 2027. Other states have pursued age checks, parental consent and design mandates. At the same time, the federal government has struggled for years to agree on a comprehensive child online-safety framework. That vacuum makes state experiments more important — and makes the risk of a fragmented national rulebook more acute.
The biggest companies may be able to absorb that complexity. Smaller services may not. Although some California duties apply only above revenue thresholds or provide different audit requirements for smaller operators, the overall compliance trend favors firms with lawyers, trust-and-safety teams, policy engineers and age-assurance infrastructure. One unintended consequence could be that regulation raises the cost of entering a market dominated by large incumbents. Policymakers will have to weigh that competition effect against the argument that products used by children should not get a safety exemption simply because a developer is small.
The hard part is turning legal language into reliable software
The bills create obligations; engineers still have to make them work millions of times a day.
A feed restriction sounds simple until a platform has to distinguish a user-chosen sequence from a behavioral recommendation, handle a shared family device, detect a child who lies about age, and preserve privacy while doing all of it. A chatbot crisis protocol sounds simple until the system must separate an actual imminent threat from dark humor, fiction, a homework question or a quotation — and decide when to involve a parent without causing a different kind of harm. Independent audits help, but auditors also need access to evidence that is meaningful, reproducible and privacy-protective.
That is why the most consequential implementation details may never make a headline. Companies will need versioned safety tests, logs showing which controls were active for a child user, procedures for model updates, audit trails for parental changes, and careful limits on how age data flows between operating systems, app stores and individual services. Regulators will need technical expertise to tell the difference between a real safeguard and a compliance screen that exists mainly on paper.
The California package is therefore an experiment in whether consumer technology can be regulated more like other products that families assume have been tested before reaching children. The analogy is imperfect — software changes constantly and speech is involved — but the political premise is clear. Lawmakers no longer accept “parents should supervise better” as the only answer when the platform itself is optimized to hold attention or maintain an emotional interaction.
The national question hiding inside a California law
Who should carry the burden when a product is powerful enough to shape a child’s attention, relationships and choices?
For a decade, responsibility was distributed in a way that favored the platform. Parents were told to monitor. Schools were told to teach digital citizenship. Teenagers were told to log off. Companies added dashboards, reminders and parental controls, but the core engagement machine largely remained intact. California’s new approach reverses that presumption for certain features: if the company designed the mechanism, the company may have to prove that the mechanism is appropriate for a child.
That does not guarantee the laws will work. A teenager can migrate to a less regulated service. Age assurance can fail. A stripped-down feed can still contain cruelty or misinformation. A chatbot with better crisis detection can still make mistakes. Parents can be absent, overburdened or themselves unsafe. And courts may find that some statutory language reaches too far into protected expression. The laws cannot solve childhood, mental health or family life by regulation.
But they can alter the default. That is the significance of this week’s package. The debate is moving from “Should children use technology?” to “What obligations attach when a company deliberately builds technology for repeated use by children?” That is a more concrete question, and it can be tested: what data is collected, what features are disabled, what happens in a crisis, what the audit found, and what remedy exists when a duty is breached.
The most durable version of child online safety will probably not come from one dramatic prohibition. It will come from hundreds of small product decisions that make the safer path the ordinary path: a feed that ends, a notification that waits, a chatbot that knows when to stop, an age signal that reveals no more than necessary, and an audit that can tell regulators whether any of those promises are real.
California has now written that philosophy into law. The next year will show whether platforms can translate it into products, whether regulators can enforce it without building a surveillance system, and whether courts accept the distinction between regulating dangerous design and regulating protected speech. For parents elsewhere in America, that makes the state more than a local laboratory. It is an early look at the rules that could define what “age-appropriate by design” means across the country.
Quick answers
Does California now ban social media for everyone under 16?
No. The final AB 1709 text bars covered platforms from providing specified addictive features to users under 16. It allows younger users to keep or create accounts if those prohibited features are not provided.
Does the $1 million figure mean every harmed child receives $1 million?
No. AB 2 establishes a statutory-damages formula for qualifying large platforms: $5,000 per violation up to a $1 million per-child cap, or three times actual damages, whichever is larger. Liability still depends on proving the required legal elements.
When do the chatbot rules start?
SB 1119 sets July 1, 2027 as the operative date for major child-chatbot provisions. Some audit mechanics depend on related legislation and operator size.
Why is age verification controversial if the goal is child safety?
Because a service must distinguish children from adults before it can apply age-specific rules. Advocates want privacy-preserving age brackets; critics worry that age gates can still expand identity checks, data collection and restrictions on lawful speech.
Sources and document trail
- Associated Press, Sept. 10, 2026 — signing-day overview, platform response and school-device opt-out.
- California AB 1709, enrolled text — under-16 addictive-feature restrictions, age assurance, enforcement and e-Safety commission.
- California SB 1119, enrolled text — companion-chatbot child-safety, advertising, privacy and audit requirements.
- California AB 2, enrolled text — civil liability and statutory-damages framework for large social-media platforms.
- Office of California Sen. Steve Padilla, Aug. 31, 2026 — legislative summary of Adam’s Law and its child-safety controls.
- U.S. Court of Appeals for the Ninth Circuit, NetChoice v. Bonta, March 12, 2026 — legal background on California’s earlier Age-Appropriate Design Code.
Comments
Post a Comment