Editor’s Note: Meta announced a separate Texas accord Aug. 26, the day Judge Yvonne Gonzalez Rogers entered a consent judgment in the federal case in California. Thirty-three states brought it in 2023; 29 tried it. The judgment implements a broader agreement of 51 attorneys general; Meta’s roughly $18 billion umbrella spans 52, Texas included. It matters to companies which never signed it: the settling attorneys general released specified COPPA and analogous state-law claims over the data Meta needs to detect users under 13, and Meta’s commitment to build the model turns on that release.
For privacy and eDiscovery readers, the architecture is the story. Covered age-assurance data is held only long enough to determine age status, subject to permissions for specified U13 Data and Retainable Data. The rule does not reach a user’s stated date of birth, stated age or the outcome of the Age Assurance Method.
Watch two developments. Paxton’s TikTok trial arrives this fall, and roughly $5.3 billion remains contingent on Industry-Wide Adoption by Snap, TikTok, YouTube and qualifying new entrants, plus a separate monetary trigger for Core Industry Members with annual profits above $10 billion. That trigger may be satisfied through qualifying state-by-state obligations or a qualifying multistate settlement.
Content Assessment: The Meta settlement built an age-assurance architecture and gave Meta a release to go with it
Information - 93%
Insight - 92%
Relevance - 92%
Objectivity - 93%
Authority - 91%
92%
Excellent
A short percentage-based assessment of the qualitative benefit expressed as a percentage of positive reception of the recent article from ComplexDiscovery OÜ titled, "The Meta settlement built an age-assurance architecture and gave Meta a release to go with it."
News Analysis – Data Privacy and Protection Beat
The Meta settlement built an age-assurance architecture and gave Meta a release to go with it
ComplexDiscovery Staff
A federal judge entered a consent judgment Aug. 26 that writes age assurance into contract terms for Meta: numerical accuracy ceilings, a bounded deletion rule, an independent auditor, a decade of obligations. Meta agreed to all of it.
It also obtained something that does not come with the architecture. The settling attorneys general released their child-privacy claims over the data Meta’s under-13 model needs, and Meta’s one-year obligation to develop, train and initially test the prototype is conditioned on the release. The release is narrow and deliberate, and it reaches only the agreement’s defined Released Parties: Meta, plus the related entities and persons the agreement specifies with it. Anyone else building the same machinery builds it without that cover and cannot assume the covenant reaches them.
Texas Attorney General Ken Paxton announced Aug. 26 that Meta Platforms Inc. would pay the state more than $1 billion. The settlement also requires stricter age-assurance measures, a daily two-hour limit for teen users, notifications disabled by default during school hours, likes and reactions hidden by default, and a nighttime access mode. Texas Scorecard filled in what the announcement left out: a parent can lift the two-hour limit, the school-hours mute runs 8 a.m. to 3 p.m. and spares direct messages and security alerts, and the nighttime setting covers midnight to 6 a.m.
The same day, in a separate matter, Meta and a coalition of state attorneys general asked the U.S. District Court for the Northern District of California to enter a proposed consent judgment. Thirty-three states brought that federal case in 2023 and 29 took it to trial, which opened Aug. 18. Fifty-one attorneys general joined the settlement, and Texas is not among them.
Entry came fast. Docket entry 576 records the consent judgment by Judge Yvonne Gonzalez Rogers, granting the joint motion in both the member case and the multidistrict docket, with the settlement agreement attached. The case was terminated Aug. 26, the MDL member case closed the next day, and a clerk’s notice vacated the Sept. 8 exhibit-filing deadline. The speed is the notable part: the docket initially listed responses as due Sept. 9 and replies as due Sept. 16, but the court granted the joint motion on Aug. 26. Meta denies the allegations, and the judgment is not an admission of liability. What it is, read closely, is a trade.
What the settling attorneys general actually gave up
The states’ side of that trade sits in one provision. Under the agreement posted by the California attorney general’s office, each settling state’s attorney general released and covenanted not to sue over claims under the Children’s Online Privacy Protection Act, the COPPA Rule, or any analogous state law. Every element of that release does work. It runs to the fullest extent permitted by law, covers past, present and future claims, and reaches Meta’s continued or future maintenance or use of a child’s personal information. It is bounded just as carefully on the other side, applying to data kept for the sole purpose of improving Meta’s detection and removal of under-13 users and not reaching data used for ad targeting and delivery, marketing, or algorithmic optimization. TechCrunch, which reviewed the agreement, reported that it releases those claims “fully, finally, and forever.”
The structure runs in both directions. Meta’s commitment to develop, train and conduct initial testing of a prototype predicting which users are under 13, the U13 Age Model, within a year of the effective date is expressly contingent on that release and on the continued application of the Federal Trade Commission’s COPPA enforcement policy statement. Take away the release and the obligation goes with it.
The model program does not end with the one-year prototype. Section II.A.6.b.ii continues through year three. Meta must report prototype development and testing outcomes to the auditor, including performance against its pre-existing methods, and use best efforts to reach a false-positive rate no higher than the lowest achieved by a qualifying commercial method. At the end of year one, Meta sets a reasonably achievable enforcement target for year two and must use the model across all Meta SMP accounts to help meet it, explaining any shortfall to the auditor. The process repeats for year three. The obligation therefore extends beyond model development to setting, pursuing and reporting against enforcement targets.
Identifying children on a platform may require collecting or using children’s personal information, activity COPPA regulates. Meta addressed part of that state-enforcement risk by negotiating a limited release and covenant not to sue from the participating attorneys general, which is not a remedy any compliance department can obtain on its own.
The bound matters as much as the claim, and it runs in two directions. On the releasing side it reaches the 51 attorneys general who joined the settlement and no further; the Federal Trade Commission, the principal COPPA enforcer, is not among them. On the released side it is wider than Meta itself, extending to the company’s parents, subsidiaries, affiliates and divisions and to the officers, directors, employees, insurers, predecessors and successors of those entities. It stops at that corporate perimeter. The agreement provides that nothing in it applies to a non-participating state, and nothing in the record establishes that comparable terms would be available in another case.
Practitioners reading the agreement have landed in different places on whether that trade was sound. “These kinds of data minimization guardrails are pretty typical for privacy compliance: e.g., verifying compliance with deletion requests,” Philip N. Yannella, a partner at Blank Rome and co-chair of its privacy, security and data protection practice, told TechCrunch. The release also has edges. “If Meta uses the data outside those lines, the release and covenant not to sue don’t apply,” said Joshua Wurtzel, a partner at Schlam Stone & Dolan. Peter Jackson, a data and intellectual property attorney at Greenberg Glusker, was blunter about the drafting. “The Settlement Agreement’s age-assurance measures bear all the hallmarks of a heavy, and perhaps hasty, negotiation,” he said.
The bounded deletion rule underneath the mandate
The agreement does not ignore data minimization. It specifies it, and privacy and information-governance teams can work from the specification as a design benchmark. Three categories carry the same rule, subject to exceptions the section itself sets out: age-assurance data collected from users in settling states, data held on known under-13 users, and data a vendor collects for a commercially available method. Each must be held only for the minimum period needed to determine age status, then immediately queued for deletion and deleted in a reasonable period. The exceptions are the operative part. Meta may retain under-13 data to the extent required to develop, train, test and measure the U13 Age Model, and it may keep metadata about which method a user went through where system integrity and circumvention detection require it. Both categories must sit at the coarsest viable granularity and cannot be repurposed unless the law requires it, and the metadata carries a 90-day deletion deadline once its purpose ends.
Then comes a boundary that is less an exception than a limit on the rule’s reach. The section closes by providing that its terms do not pertain to the user’s stated date of birth or stated age, nor to the outcome of the Age Assurance Method, which the agreement illustrates with a teen or adult classification. Two of those are inputs a user supplies and one is the finding drawn from them, so the carve-out reaches both ends of the process. What the rule governs is the material gathered in between.
Set the deletion terms against Texas Business and Commerce Code Section 541.101(a)(1), effective July 1, 2024. A controller must limit collection of personal data, the statute says, to what is “adequate, relevant, and reasonably necessary in relation to the purposes for which that personal data is processed, as disclosed to the consumer.”
The two work on different levers. The statute constrains collection, while the settlement adds a purpose limitation consistent with that principle and a deletion schedule the statute does not itself supply. Any organization standing up age assurance in Texas now has a worked example of both, negotiated by Meta and the participating attorneys general and entered as a federal judgment Aug. 26. What it is not is law in Texas. Texas did not join the coalition, the judgment does not bind it, and the example is a drafting model rather than a safe harbor.
The accuracy numbers travel with it, and the agreement defines what they measure: the U18 false positive rate is the share of actual users aged 13 through 17 whom Meta incorrectly identifies or predicts to be 18 or older, excluding method circumvention. Commercially available methods must meet ceilings of 3 percent for ages 13 to 15 and 10 percent for 16 and 17 within a year. Meta’s proprietary methods run a phased schedule instead, 7 percent and 14 percent respectively in year one, improving to 5 percent and 10 percent in year two. Read across the bands and the schedules converge only for 16- and 17-year-olds; for 13- to 15-year-olds Meta’s own models settle at 5 percent against the 3 percent a bought method must hit.
The looser numbers come with a different compliance posture, which is the part worth carrying into a build-or-buy conversation. For users on whom Meta uses and relies upon a Commercially Available Age Assurance Method, Meta receives a presumption of compliance with Section II.A.6 only when the latest third-party certification and the agreement’s specified operating conditions are satisfied. Those conditions include maintaining the vendor’s specifications, matching the tested settings, avoiding interference with the method, not willfully ignoring conditions that undermine its efficacy, providing complete and accurate information to testers, and complying with related agreement obligations. Proprietary Age Assurance Methods receive no such presumption and require continuous Meta oversight sufficient to ensure that they function as intended. Using a qualifying commercial method can therefore shift part of the evidentiary burden; using a proprietary method does not provide that presumption.
New York wrote its own numbers into 13 NYCRR Part 700 under the SAFE for Kids Act, on a finer grain: five age bands running from 0.1 percent for children 7 and under to 15 percent at 17, plus a 98 percent circumvention-detection floor. Biometric Update reported the rule takes effect Jan. 25, 2027.
Do not read the two schedules as a ranking, because they are not measuring the same thing. New York’s accuracy minimum excludes failures or refusals to provide requested data and inconclusive outcomes, then adds a second standard, the total accuracy minimum, that folds inconclusive outcomes back in at the same percentages. Meta’s ceilings exclude method circumvention. Each regime carves out a different category of hard case, and the carve-outs are where the comparison breaks.
Age assurance is becoming a specification with numbers in it, and vendor claims will start getting measured against them. Buyers evaluating providers this quarter should ask for false-positive rates broken out by age band rather than a single headline accuracy figure, ask what the fallback path collects when estimation fails, and ask where that fallback data sits and for how long. A vendor that answers the first question and dodges the other two has shown you where its risk lives.
Where estimation turns into identification
Here is what the deletion rule cannot fix. When estimation is inconclusive or disputed, the path forward may run through identification.
Aliya Bhatia, writing for the Center for Democracy and Technology in March 2025, laid out the mechanism. Estimation systems return ranges rather than ages, and a range of 15 to 19 is useless to a platform that has to know whether a user has reached 18. Some users may complete age estimation without providing an identity document; others may be directed to a government ID or another verification method when the estimate is inconclusive or disputed. Bhatia wrote that facial age-estimation systems are likelier to misclassify trans and nonbinary users, people of color, and people with disabilities affecting appearance, while users without suitable documentation face further obstacles at the verification step. Teenagers may not have a government ID readily available, and documents such as passports or birth certificates are often held by their parents. CDT advocates against broad age-verification mandates, which is worth knowing when reading its framing.
The vocabulary slips the same way, and it slipped in the coverage of this settlement on day one. Paxton’s office wrote that Meta would adopt stricter age-assurance measures, the Texas Tribune reported the same terms as stricter age verification, and the difference between an estimate and a document went missing somewhere between the two. For some users, the distance between them is a passport.
David Greene of the Electronic Frontier Foundation, a digital rights advocacy group, argued Aug. 26 that the settlement embeds age assurance into every product and requires collecting more personal information from users of all ages, raising exposure to breaches and to government data requests. The concern is not abstract. Discord said in October 2025 that among the accounts affected by a breach of a third-party vendor’s system, roughly 70,000 users may have had government-ID photos exposed, images the vendor used to review age-related appeals. That number counts the identity-document subset, not everyone whose data attackers reached.
The clock does not run on everything. The agreement permits Meta to retain under-13 data to the extent required to develop, train, test and measure the U13 Age Model. Some model data may therefore remain after other age-assurance data has been queued for deletion. Data on a clock is safer than data kept forever. It is not safe on the day it exists.
Recurring compliance evidence, and a decade of obligations
The compliance apparatus is where this stops being a privacy problem and becomes an information-governance one. An independent auditor sits over the injunctive terms, reporting findings to what the agreement calls the State Committee, a bipartisan group of six attorney general offices at most, appointed by the settling states. The auditor is entitled to the non-privileged information, personnel, systems and records reasonably relevant and sufficient to evaluate how Meta implements those terms, and the grant names raw data, aggregated data, internal documents and communications among them. The auditor’s engagement is bounded rather than open-ended. It begins two months after the effective date and runs until 120 days after the fifth final report.
The duties underneath it run yearly, and they do not stop at self-reporting. Meta must certify the number of enforced under-13 accounts for each platform annually. The auditor has to confirm that number by auditing the processes used to record the removals and the methodologies used to compute the totals, then report the figure and that year’s enforcement target to the settling states. Every Age Assurance Method adopted under the Age Assurance Framework must undergo annual testing by an accredited third party. Separately, Meta must provide the auditor annually with data on the design, testing and effectiveness of its soft-matching models, and document its reasoning when it declines to implement an industry development. Unless the agreement specifies otherwise, the obligations of the consent judgment expire 10 years from the effective date, and the court retains jurisdiction to enforce and modify it.
Read the retention terms and the audit terms together and the tension is plain. One set of provisions bounds how long data is kept. The other runs on recurring duties: annual testing by an accredited third party, annual certifications, annual submissions to the auditor, and access to relevant records on request. The agreement issues no blanket command that the resulting conformance evidence be retained. What it creates is a stream of that evidence, generated year after year, which an organization will want to be able to produce and which later proceedings may reach. Any organization copying this architecture needs a retention schedule that separates the operational data from the compliance record, because the first is a liability and the second is a defense.
The settlement also leaves a great deal unreleased. JURIST reported that it creates no private right of action and expressly does not establish a standard of care outside the participating jurisdictions, and it does not reach claims brought by individuals, schools, school districts or other government entities. Those cases are still moving. The conformance record Meta builds for the auditor, the annual certifications, the model testing data, the documented reasons for passing on an industry development, is therefore potentially discoverable by plaintiffs the settlement never covered, subject to relevance, privilege, confidentiality, proportionality and the other objections any such demand meets. Counsel advising a company that adopts this architecture should scope preservation to the compliance record itself and not only to the operational data underneath it, because that record could become an important discovery target.
Texas, and the money that is not yet owed
None of that architecture is visible in Texas. Paxton’s announcement describes age-assurance obligations and says nothing about how the resulting data must be handled. No Texas settlement text appears in the attorney general’s newsroom, in a site-scoped search of texasattorneygeneral.gov, or in the press-file directory that does host the 2024 order in the state’s facial-recognition case. Whether the Texas deal carries deletion terms, an auditor or any release is not established on the pages reviewed as of Aug. 29.
Its posture, by contrast, is now on the record. Bloomberg Law reported from an Aug. 25 email exchange between Paxton’s first assistant, Brent Webster, and Mahoney, obtained through a public-records request, that Texas passed on the multistate settlement, never joined the federal case, never appeared at the Oakland trial and never sued Meta on its own. The accord provides $1.05 billion and reaches $1.335 billion if YouTube and TikTok accept the same terms and safety changes. Paxton’s office announced only a payment above $1 billion, and Texas Scorecard described the deal as proposed. What is still unestablished is whether the Texas accord has been fully executed, and whether any filing is required to make it enforceable. Texas is meanwhile the jurisdiction with a minimization statute on the books and a trial against TikTok scheduled for the fall. Paxton’s office called this the third settlement worth over $1 billion it has secured from Big Tech companies, after $1.4 billion from Meta over facial recognition data and $1.375 billion from Google.
As of Aug. 29 the money arrives as three figures, each attached to a different scope. CNBC read the filing at $16.7 billion. Several attorneys general cited up to $17.1 billion, which adds $459,293,017.80 for Cambridge Analytica claims dating to 2018 and separate from the child-safety case. Meta described an umbrella of roughly $18 billion across agreements involving 52 attorneys general, Texas included, split into about $12.7 billion for participating jurisdictions and about $5.3 billion released only on conditions. Meta’s own announcement puts those conditions on YouTube and TikTok: adopting a one-hour daily limit, night mode and age assurance measures, and each paying an amount matching the contingent share. The published materials do not fully explain how those three descriptions line up, which is a gap in the disclosure rather than a contradiction among the figures, so any number repeated from here should carry its source and its scope.
The contingency is where the public shorthand and the agreement diverge, and the difference matters for anyone modeling what Meta’s competitors now face. The agreement defines Core Industry Members as Snap, TikTok and YouTube, for as long as their products remain available to U.S. teen users. Two conditions have to be satisfied, and neither is a single step.
First, Industry-Wide Adoption must occur for both contingent time-management obligations, the phase-two night access mode and the phase-two daily limit. Each Core Industry Member and any qualifying new entrant reaches that status through an enforceable commitment, an applicable law, or voluntary implementation verified by an independent auditor. The definition does not stop at the two product obligations. It also requires binding age-assurance obligations for users ages 13 through 17 no less restrictive than those in Section II.A, and an independent third-party audit running a minimum of five years. Coverage must not exclude any features or surfaces other than messaging or Longform Content, unless Meta waives that in writing.
Second, the monetary trigger applies only to Core Industry Members with annual profits above $10 billion. It can be met one state at a time, through obligations at least equal to that state’s aggregate contingency installments, or through a multistate settlement whose covered obligations at least equal the participating states’ aggregate installments.
Both public descriptions name two companies where the agreement names three. Meta’s announcement puts the money on YouTube and TikTok, and the Texas escalator runs on the same pair. Nothing in the record establishes a conflict, and the structure suggests why there need not be one: the adoption condition reaches every Core Industry Member, while the monetary condition reaches only those above the profit threshold. A company can be obliged to adopt without being in a position to pay the matching amount that releases the money.
Read together, the conditions describe a ratchet with a longer throw than the headline version suggests. Adoption has to be industry-wide, it reaches age assurance and audit terms as well as the two product obligations, and the matching-obligation condition applies only to Core Industry Members above the agreement’s $10 billion annual-profit threshold. The provisions defining these terms were obtained through a retrieval of the agreement rather than a raw reading of it, a limit worth carrying.
Meta’s chief legal officer, C.J. Mahoney, framed the design in those terms, saying the approach “will only work if all our peers join us. Because teens move fluidly across dozens of apps, we need an industry-wide solution.” Bonta called the settlement “a floor conceptually, not a ceiling.” Florida Attorney General James Uthmeier, whose state stayed out along with New Mexico, called it a win for Meta. All three can be right.
What would your organization actually delete, and what could it prove it deleted, if an auditor with access to your systems asked next quarter?

News sources
- Meta and State Attorneys General [Proposed] Consent Judgment and Settlement Agreement, Dkt. 572-1 (California Attorney General)
- People of the State of California v. Meta Platforms, Inc. (4:23-cv-05448), docket entry 576 (CourtListener)
- Attorney General Ken Paxton Secures Over $1 Billion from Meta in Historic Settlement that Protects Texas Kids Online (Texas Attorney General)
- Attorney General Bonta Secures Transformative $17 Billion Settlement with Meta, Proposed Settlement Includes Fundamental Changes to Instagram and Facebook (California Attorney General)
- Meta agrees to court-enforced limits on teen social media use in $18B settlements (JURIST)
- Buried in Meta’s $18B settlement is a legal pass on kids’ data (TechCrunch)
- Meta settles social media addiction case with California, other states for $16.7 billion (CNBC)
- After Meta’s landmark settlement with state AGs, legal headaches remain (CNBC)
- Meta to pay Texas $1 billion in child safety case (The Texas Tribune)
- Texas’ Billion-Dollar Side Deal Ranks High in Meta Settlement (Bloomberg Law)
- Texas Business and Commerce Code Section 541.101 – Controller Duties; Transparency (Texas Public Law)
- Age Estimation Requires Verification for Many Users (Center for Democracy and Technology)
- EFF Statement on Meta Settlement (Electronic Frontier Foundation)
- Meta, US attorneys general reach multibillion dollar settlement to end social media addiction trial (IAPP)
- Meta’s accuracy minimums confirm that yes, some third-party age checks do work (Biometric Update)
- Discord Voluntarily Pushes Mandatory Age Verification Despite Recent Data Breach (Electronic Frontier Foundation)
- Paxton Announces $1 Billion Settlement With Meta Over Child Safety (Texas Scorecard)
- SAFE for Kids Act Implementing Rules, Part 700 of Title 13 of the NYCRR (New York Attorney General)
- New York puts accuracy minimums for age assurance into effect with SAFE for Kids Act (Biometric Update)
- Our Agreement With US State Attorneys General (Meta)
- Meta, 29 States Head to Court in Biggest Test Yet of Youth Social Media Litigation (Claims Journal)
- Discord reveals more on data breach – says 70,000 government ID photos may have been leaked (TechRadar Pro)
Assisted by GAI and LLM technologies
Additional reading
- DOJ ties a quarter of TikTok’s $400 million COPPA settlement to vacating a 2019 decree
- Four days offline, and a threshold already under review
- A program not yet publicly operational, and an untested Computer Fraud and Abuse Act defense
- Recent AI evaluation incidents expose gaps in containment, configuration and evidence
- When hacktivists join the fight: A closer read of Cyber Law Toolkit scenario 36
- Beijing contests House Salt Typhoon report as Congress weighs a wider cleanup
- Restore the controller, risk losing evidence: federal water guidance leaves the sequence open
- Policy without control: the AI governance gap in IBM’s 2026 Cost of a Data Breach Report
- ShinyHunters’ July 31 deadline for EY arrives after third-party tax-data breach
- The new negligence baseline: how voluntary CI Fortify guidance becomes Exhibit A in post-breach litigation
Source: ComplexDiscovery OÜ

ComplexDiscovery’s mission is to enable clarity for complex decisions by providing independent, data‑driven reporting, research, and commentary that make digital risk, legal technology, and regulatory change more legible for practitioners, policymakers, and business leaders.


























