Meta has reached a roughly $18 billion settlement with 52 US state, territorial and District of Columbia attorneys general. It has been called both a step toward platform accountability and too little, too late. MediaNama put both readings to lawyers, child-rights researchers, product designers and youth-policy groups. The settlement delivers real money and real restrictions, but several warned it still leans on old tools. Parental consent, age verification and fixed time limits have not reliably worked before.
That matters beyond the US. As MediaNama has reported, roughly $5.3 billion of Meta’s payment is conditional on YouTube and TikTok adopting similar safeguards. It could set an industry template before any government writes a comparable rule. India is one of the places watching that template take shape. None of the three platforms face an equivalent binding obligation there today.
The terms, briefly
The settlement remains subject to judicial approval. Under its terms, Meta pays $12.7 billion regardless of what happens next. Up to $5.3 billion more becomes payable if YouTube and TikTok adopt matching measures. Those include a one-hour daily limit, night mode and age assurance, plus comparable payments of their own. Meta’s own obligations start with a two-hour daily limit across Facebook and Instagram. Midnight-to-6 am access restriction and muted school-hour notifications follow. Independent audits will check compliance for five years. Neither YouTube nor TikTok has said it will participate.
A settlement acting like regulation
Apar Gupta is an advocate and founder-director of the Internet Freedom Foundation (IFF). He said the unusual part isn’t the fine. It’s what the fine is designed to do to Meta’s competitors.
“What makes this settlement unusual is that part of Meta’s financial liability depends on what companies that are not parties to the case choose to do,” Gupta said.
He compared it to the 1998 tobacco Master Settlement Agreement — one of the few precedents for a settlement reshaping an entire industry’s practices.
The original case had a clear legal basis, Gupta said. An October 24, 2023 complaint relied on state consumer protection laws and the Children’s Online Privacy Protection Act (COPPA). That law lets state attorneys general enforce it directly. The complaint alleged that Meta collected data from under-13 users without parental consent. But YouTube and TikTok are not bound by a judgment against Meta.
“Rules governing how millions of children use online platforms should ordinarily be made through legislation or transparent regulation, with evidence, consultation and public scrutiny,” Gupta said.
If Meta’s terms become the industry default, he added, the audit results behind them should be public too. Children, in his view, should have a voice in that process.
The age-assurance problem, from three angles
Age assurance was the one place nearly every respondent raised a flag, for different reasons. Gupta said the method matters as much as the goal. Some systems require users to hand over more personal information, or submit to identity or biometric checks. India previews how complicated this gets. Section 9 of the Digital Personal Data Protection (DPDP) Act, 2023 requires verifiable parental consent. It bars tracking, behavioural monitoring and targeted advertising aimed at children. Rule 10 of the DPDP Rules separately lists ways to confirm the consenting adult’s identity, including a virtual token. Both provisions take effect May 13, 2027.
Gupta warned that an ill-designed authentication flow “can potentially lead to age gating which results in mass surveillance.”
Avaantika Chawla is assistant professor at Jindal Global Law School and assistant director of its Child Rights Clinic. She pointed to India’s existing consent requirement as a partial answer to whether an industry-wide standard creates new data-protection risk.
Angelina Dash is project manager at the Centre for Communication Governance (CCG), National Law University Delhi. She flagged the implementation gap instead. Meta has signalled support for age checks at the app-store level, shifting the task to Apple and Google.
That model is complicated in India, Dash said, by “widespread usage of shared digital devices.” CyberPeace, in a written response, summed up the trade-off. Age assurance must be “privacy-preserving, proportionate and based on data minimisation,” the organisation said. Protecting children “by creating another system that unnecessarily exposes everyone’s identity,” it added, defeats its own purpose.
Time limits are not the same as safer design
Niyam Bhushan, founder at DesignRev, responded to MediaNama’s questions on the settlement from a product and design perspective. He was the most skeptical of the fixes as written.
“Design is shaped by intent more than interaction,” he said. Time limits, Night Mode and reduced engagement cues add only “mild to moderate friction.”
Motivated users route around that friction with ignore-and-extend taps. If the restriction is a hard stop, they may turn to VPNs instead.
His proposed fix leans on enforcement, not defaults:
- An app-level stop at night, not just an account-level one — so it also works on a shared parent’s device.
- Capped sessions with forced re-login between them.
- An in-app cybercrime-reporting option no more than two taps away, with a public record of outcomes.
CyberPeace made a related point about what time limits can’t do. “A teenager may spend two hours online without encountering anything harmful, while a single interaction lasting a few minutes could have profound consequences,” the organisation said. Its argument: shift the focus from regulating duration to regulating “the conditions of engagement.”
That means age-appropriate defaults, safer direct messaging, responsible recommender systems and independent scrutiny of platform risk.
Aparajita Bharti, co-founder of Young Leaders for Active Citizenship (YLAC), framed it as a design-versus-outcome problem. Regulation, she said, should prescribe what platforms must achieve, not the exact feature that gets them there. Specific mandates, in her view, can misfire. As an example, she pointed to India’s own panic-button requirement on mobile phones. It has strained emergency services, she said, through accidental presses. As a cautionary precedent for blanket restrictions, she cited South Korea’s “Cinderella law.” The gaming curfew for minors was eventually repealed after being widely bypassed.
Parental controls can cut both ways
Dash’s sharpest point was about who ends up doing the work. Many of the settlement’s safety features still route through parents, she said. They include:
- Relaxed screentime defaults.
- Alerts when a child contacts an adult.
- Notifications about searches involving self-harm or eating disorders.
That, Dash said, is “necessitating larger conversations around the pitfalls of parental consent as a panacea for children’s online safety.”
In much of the Global South, she added, that assumes a digitally literate parent. In practice, it isn’t always the parent who introduced their child to the platform in the first place.
Dash also raised a gendered risk specific to notification-based controls. Alerts naming a teenager’s social connections, she said, could become “contentious” in households with stricter expectations around a daughter’s friendships. Messaging-duration alerts, similarly, could carry “comparatively adverse implications for girls” using the same features.
Chawla’s response argued for the same caution, from a different direction. A teenager’s right to participation is protected under Article 12 of the UN Convention on the Rights of the Child (UNCRC). That right, Chawla said, should scale with age and maturity.
“Parental control must decrease and a child’s agency and autonomy increase in line with their age and maturity,” Professor Chawla said. “We must be wary of being overly protective.”
What India still has to work out
Astha Kapoor, co-founder of the Aapti Institute, called the settlement “too little, too late.”
It comes, she said, after years of Meta denying the harms it now effectively accepts responsibility for. She said Indian policymakers are likely watching closely. One reason: India hasn’t tried a fine-based intervention that puts responsibility on platforms rather than parents or children.
Her biggest open question is Meta’s own vague use of the word “teens.” She set that against early Indian experiments such as Andhra Pradesh’s proposed age tokens. There, it remains unclear how a guardian’s consent would even be captured or verified. Kapoor said the underlying problem is structural, not just regulatory.
It will need platform accountability alongside social awareness of overuse — “not unlike the efforts towards making smoking unacceptable,” Kapoor said.
MediaNama sent detailed questions to Meta and YouTube ahead of publication. Meta responded, but only by pointing to material it had already made public. Meta said it was not in a position to provide further details and did not directly answer the specific questions in this piece. YouTube did not respond by the time of publication.
MediaNama sent the following questions to Meta:
- Why did the settlement terms make the release of approximately $5.3 billion of Meta’s payment conditional on YouTube and TikTok adopting the specified safeguards and making matching payments?
- Have YouTube or TikTok indicated to Meta whether they intend to participate in the framework? If so, could you clarify their position?
- If either YouTube or TikTok does not adopt the specified measures, or does not make the corresponding payment, what happens to the conditional portion of Meta’s settlement payment?
MediaNama sent the following questions to YouTube:
- Has YouTube been approached by Meta regarding the proposed framework, and does YouTube intend to participate?
- Does YouTube support the specific measures Meta has proposed, including a one-hour daily limit, Night Mode and age assurance for users under 18?
- If YouTube were to adopt any of these measures, would they apply globally or only in the US jurisdictions covered by the settlement?
- Does YouTube believe fixed screen-time limits are an effective child-safety measure, or should platforms instead focus on safety-by-design and reducing potentially harmful engagement?
The story will be updated if MediaNama receives any further responses from the parties.
Also read:

