Children and teenagers need better protection from social-media companies.

By  
Gigabit Systems
September 1, 2026
20 min read
Share this post

Protect Kids From Social Media. But Don’t Build a Surveillance System to Do It.

Protecting children shouldn’t require identifying everybody else.

Children and teenagers need better protection from social-media companies.

I don’t think that’s particularly controversial anymore.

The more difficult question is:

What are we willing to build in order to protect them?

Because buried inside Meta’s enormous child-safety settlement is something potentially much bigger than screen-time limits.

Age assurance.

Meta has agreed to implement stronger systems for determining whether Facebook and Instagram users are actually the ages they claim to be.

That sounds reasonable.

Until you think about the technical problem.

How does Instagram know you’re 16?

More importantly:

How does Instagram know you’re 46?

Meta Just Settled One of the Biggest Cases in Tech History

Meta agreed to pay states up to approximately $17.1 billion over ten years to resolve litigation accusing Facebook and Instagram of harming children through addictive product design and improperly collecting children’s information.

Meta denies wrongdoing.

The settlement includes significant changes for younger users.

Among them are a combined two-hour daily Facebook and Instagram limit, mandatory interruptions during extended usage, overnight restrictions, reduced school-hour notifications, stronger parental controls, age-appropriate content protections and new age-assurance measures.

Those are significant changes.

But there’s another part of this story receiving much less attention.

Meta Is Now Advertising for Its Competitors to Join It

Shortly after settling, Meta began publicly calling on TikTok and YouTube to adopt comparable protections.

Meta's public announcement⁠

Meta’s message is essentially:

We did it. Now you should too.

That sounds admirable.

Except Meta also has billions of dollars riding on whether its competitors agree.

Follow the $5.3 Billion

Meta’s settlement is structured unusually.

Approximately 70%—around $12.7 billion—is scheduled to be paid over the ten-year period.

The remaining approximately:

$5.3 billion

is conditional.

According to Meta itself, those funds are released only if TikTok and YouTube both implement specified protections—including age assurance, Night Mode and a one-hour daily limit—and make matching payments.

In other words:

Meta has a multibillion-dollar financial interest in its competitors adopting similar rules.

That doesn’t make those rules bad.

But it’s important context when Meta purchases advertisements encouraging the rest of the industry to “join us in supporting teens.”

This isn’t purely advocacy.

There is a very large financial incentive attached.

And Then There’s Age Assurance

This is the part cybersecurity and privacy professionals should be watching.

Social networks have historically had an obvious problem.

A website asks:

What is your birthday?

A 12-year-old enters:

I’m 18.

Problem solved.

Except nothing was solved.

So regulators increasingly want something stronger.

The Meta settlement calls for “robust age assurance.”

That means platforms need better ways to determine whether someone claiming to be an adult actually is one.

And that’s where child safety collides with privacy.

How Does the Internet Prove You’re an Adult?

There are several possibilities.

You could provide:

A government-issued ID.

A credit-card verification.

A facial image used for age estimation.

A third-party digital identity credential.

Or the platform could infer your likely age using information it already possesses.

Reuters reports that Meta historically has used clues including things like birthday-related information and school-related content, and the settlement requires stronger methods for identifying children.

Think about that second category.

You don’t explicitly prove your age.

The system determines it.

That’s a completely different privacy model.

Meta Already Has Age-Estimation Technology

This isn’t hypothetical technology.

Meta has previously used facial age-estimation technology from Yoti⁠ as one method for verifying ages in certain situations.

A person can submit a video selfie.

Technology analyzes facial characteristics.

The system estimates an age.

That may sound preferable to uploading a driver’s license.

And perhaps in some circumstances it is.

But biometrics create their own privacy questions.

Yoti Has Already Run Into a Regulator

Spain’s data-protection regulator sanctioned Yoti over its Digital ID application.

Yoti says the fine was €950,000 and that it is appealing the decision.

The controversy involved alleged GDPR violations concerning biometric processing, retention and consent associated with the Digital ID application.

Yoti strongly disputes the regulator’s conclusions and emphasizes that the decision did not involve a breach or compromise of users’ information.

That’s an important distinction.

But the case demonstrates the problem.

We want reliable age verification.

Reliable age verification requires information.

The more reliable we demand that determination become:

The more information the system may need.

The Privacy Paradox

Imagine an adult wants to use Instagram.

The platform needs to determine:

Adult or child?

How certain should it be?

60%?

80%?

95%?

99.9%?

Every additional nine creates pressure for additional evidence.

Maybe your birthday isn’t enough.

So analyze your face.

Maybe facial estimation isn’t certain enough.

Check your ID.

Maybe we don’t want IDs.

Analyze account history.

Your social graph.

Who you communicate with.

How long your account has existed.

What content you interact with.

What school references appear.

Other signals.

Individually, some of these approaches may preserve considerably more privacy than uploading identification.

But collectively they raise another question:

How much should a social network analyze about you simply to decide how old you are?

We’re Solving Two Different Problems

This distinction is getting lost.

Problem one:

Children need better protection online.

Problem two:

Platforms need a mechanism for identifying who is a child.

Those are related.

They are not identical.

And the second problem creates infrastructure that has capabilities extending beyond the first.

Once a platform can reliably distinguish:

  1. 12.

  2. 13.

  3. 14.

  4. 15.

  5. 16.

It has created an age-based identity layer.

That capability doesn’t disappear when the original child-safety debate ends.

Your Phone Can Already Limit Your Child’s Instagram

Here’s another uncomfortable part of the discussion.

Both Apple and Google already provide extensive parental controls at the operating-system level.

Parents can restrict:

App usage.

Screen time.

Nighttime access.

Downloads.

Purchases.

Websites.

Content.

Communications.

Notifications.

Entire applications.

A parent can effectively say:

Instagram gets one hour.

Or:

Instagram doesn’t work after 9 PM.

Or:

My child cannot use Instagram at all.

And the operating system can enforce that without requiring every adult Instagram user to establish their age with Instagram.

That doesn’t mean platform-level controls are unnecessary.

Far from it.

Because operating-system parental controls cannot fix:

Recommendation algorithms.

Dangerous content.

Predatory interactions.

Platform design.

Harmful engagement mechanisms.

Inadequate moderation.

Those are the platform’s responsibility.

But it does mean we should distinguish between:

Controlling children’s devices

and

identifying everyone using a service.

Meta Still Controls the Algorithm

This is where the debate should stay focused.

Suppose Instagram perfectly identifies every 14-year-old tomorrow.

Great.

Now what?

Age verification doesn’t automatically make the recommendation engine healthy.

It doesn’t automatically remove harmful material.

It doesn’t eliminate predatory accounts.

It doesn’t necessarily solve compulsive product design.

It doesn’t create independent oversight.

It simply gives Meta better information about:

Who is a child.

That’s useful.

But identifying the user and protecting the user are two different technical problems.

The Settlement Does Address Product Design

To be fair, this settlement doesn’t stop at age assurance.

It imposes substantial product restrictions.

Among them:

Two-hour combined daily limits.

Mandatory pauses.

Midnight-to-6 a.m. restrictions.

School-hour notification restrictions.

Stronger parental controls.

Options involving algorithmic feeds.

Restrictions involving likes and appearance-related features.

Additional protections around harmful content.

Those provisions deserve attention.

And some may genuinely improve children’s experiences online.

The mistake would be treating every technology introduced under the banner of child safety as automatically privacy-preserving because the objective is admirable.

Good intentions don’t eliminate cybersecurity architecture.

Australia Is Wrestling With the Same Problem

This isn’t uniquely American.

Governments around the world are trying to answer the same question:

How do you keep children out of inappropriate digital environments without constructing an unnecessarily invasive identity system for everybody else?

That’s an extraordinarily difficult engineering problem.

Age assurance exists on a spectrum.

At one end:

“Tell us your birthday.”

Almost no privacy intrusion.

Almost no assurance.

At the other:

“Prove exactly who you are.”

Much stronger assurance.

Much greater privacy consequences.

The goal should be finding the least intrusive mechanism capable of accomplishing the legitimate safety objective.

Not simply maximizing certainty.

Cybersecurity People Should Recognize This Problem Immediately

We deal with this tradeoff constantly.

Security wants more information.

More logs.

More telemetry.

More identity.

More monitoring.

More authentication.

And sometimes that’s absolutely necessary.

But every additional piece of information collected creates something else:

Data that now needs protecting.

If millions of people submit identity documents to prove their ages:

Those documents become valuable.

If millions provide facial information:

That information becomes sensitive.

If behavioral signals determine age:

Those behavioral profiles become consequential.

If third-party identity providers participate:

We’ve introduced additional companies into the trust chain.

Security doesn’t eliminate risk.

It moves risk around.

Biometrics Deserve Special Treatment

You can reset a password.

You can cancel a credit card.

You can change an email address.

Your face is considerably harder to replace.

That doesn’t mean facial age estimation is inherently unsafe.

Some systems are specifically engineered to minimize retention and avoid identifying the individual.

But when biometric information enters any system, businesses and regulators should ask difficult questions.

What exactly is collected?

Is an image stored?

Is a biometric template created?

How long does anything persist?

Can it be reused?

Who processes it?

Can it be linked to another account?

Can governments request it?

What happens after verification?

Can the information be deleted?

What happens if the provider is breached?

Those aren’t anti-technology questions.

They’re cybersecurity questions.

Now Imagine Age Verification Becomes Normal

This is where the settlement becomes bigger than Instagram.

Suppose every major platform adopts robust age assurance.

TikTok.

YouTube.

Instagram.

Facebook.

Snapchat.

Reddit.

Gaming platforms.

Messaging platforms.

AI platforms.

Adult-content websites.

Online marketplaces.

Suddenly proving—or having systems infer—your age becomes a routine part of internet access.

Maybe that’s where society ultimately decides to go.

But we should understand what we’re building before we get there.

Because infrastructure created for one legitimate purpose has a habit of finding additional purposes.

Identity Systems Create Enormous Power

Identity is valuable.

Knowing:

Who someone is.

Approximately how old they are.

Which accounts belong to them.

Which devices belong to them.

Where they authenticate.

Which services they use.

Which restrictions apply to them.

creates tremendous capability.

Sometimes we want that capability.

Banks need identity verification.

Governments need identity systems.

Healthcare organizations need to know which patient they’re treating.

Companies need to authenticate employees.

But anonymous and pseudonymous participation has also been part of the internet since its beginning.

Moving toward universal age assurance changes that balance.

Perhaps gradually.

Perhaps dramatically.

But it changes it.

Child Safety Shouldn’t End the Privacy Debate

This is where I think both sides get something wrong.

One side says:

Think of the children. Build whatever verification is necessary.

The other says:

Privacy. Therefore don’t regulate anything.

Neither is sufficient.

We should be capable of holding two thoughts simultaneously:

Social-media companies should be required to protect children.

And:

The systems used to accomplish that protection should collect the minimum information necessary.

Those positions aren’t contradictory.

That’s what responsible cybersecurity looks like.

Require Privacy by Design

If governments mandate stronger age assurance, then governments should simultaneously require strong privacy protections around it.

The objective should be:

Verify the attribute without unnecessarily identifying the person.

For example:

“This user is over 18.”

may be all Instagram needs.

Instagram doesn’t necessarily need:

“This is John Smith, born March 4, 1987, living at 123 Main Street, driver’s license number XXXXXXXX.”

That’s an important architectural distinction.

Modern cryptography and digital-identity systems increasingly make attribute verification possible without transmitting an entire identity.

That’s where regulators should push the industry.

Prove what needs proving.

Reveal nothing else.

Businesses Should Learn From This Too

The principle applies far beyond social media.

Organizations constantly collect more information than they actually need.

A form asks for ten fields when four would accomplish the task.

A database keeps records indefinitely.

An application stores identity documents after verification is finished.

An employee exports customer information “just in case.”

A vendor wants an entire dataset when it only needs one attribute.

Then everybody acts surprised when a breach becomes catastrophic.

There’s a simple data-protection principle every SMB should understand:

You cannot lose data you never collected.

And you cannot expose data you already deleted.

Data minimization is cybersecurity.

Meta’s Settlement Could Become an Industry Standard

This is why the $5.3 billion structure deserves attention.

Meta isn’t merely implementing these controls itself.

It has a substantial financial incentive for TikTok and YouTube to adopt comparable restrictions.

Meta openly says it wants an industry-wide framework.

If competitors agree, today’s settlement terms could become tomorrow’s industry baseline.

Then regulators look at everyone else and ask:

Why aren’t you doing it too?

That’s how standards spread.

Which means decisions being made today about age assurance architecture could eventually affect enormous portions of the internet.

Protect the Kids. Protect Everyone Else Too.

I strongly support giving parents more control over what children encounter online.

I support preventing adults from contacting children inappropriately.

I support restricting dangerous content.

I support making recommendation systems safer.

I support interrupting endless scrolling.

I support forcing technology companies to consider children’s welfare alongside engagement metrics.

And I think platforms should be held accountable when their product decisions create foreseeable harm.

But none of those beliefs require giving technology companies unlimited permission to build identity infrastructure.

We can demand both:

Safer technology for children.

And:

Privacy-preserving technology for everyone.

The best age-assurance system isn’t necessarily the one that knows exactly who you are.

It’s the one that can establish what it needs to know—and then knows as little else about you as possible.

Because there’s a dangerous habit developing in technology policy:

Identify a genuine problem.

Build an enormous data-collection system to solve it.

Then promise everyone the data will be protected.

Cybersecurity professionals know how that story sometimes ends.

Children deserve protection from technology companies.

Adults deserve protection too.

70% of all cyber attacks target small businesses, I can help protect yours.

#Cybersecurity #DataPrivacy #OnlineSafety #DataProtection #TechPolicy


Protect kids from social media. Absolutely. But should every adult have to prove they’re an adult to use it?

Share this post
See some more of our most recent posts...