On September 10, California prohibited social media companies from serving autoplay, infinite scroll, and history-ranked feeds to users under sixteen. The same package requires companion chatbots to disclose they are machines, alert parents when a child signals self-harm, and run a crisis protocol on suicide queries. The regulation attaches civil penalties to injuries caused by the platform.1 These provisions regulate how the product will be built. Earlier child-safety statutes regulated what children could see, and courts struck most of them down as restrictions on speech. California is betting that regulating product design rather than permissible speech offers a more durable constitutional path. Other states are likely to test the same theory.
The evidence on social media and adolescent mental health is still contested in 2026. It remains suggestive in aggregate, and stronger for a vulnerable minority than for the median user. What changed was the cost of inaction for the platforms. In August, Meta agreed to pay up to $17.1 billion to 47 states to settle claims that it engineered its products to addict minors, with part of the settlement contingent on Snap, TikTok, and YouTube reaching similar terms.2 Design-code bills had died in committee for a decade under sustained lobbying, but once a platform's exposure had been priced in a courtroom, a statute restricting autoplay for minors became an obvious next step. The settlement, more than any new study, explains the timing.
From Canberra to California
California is the sixth jurisdiction to adopt a minimum age. Australia's Social Media Minimum Age law took effect on December 10, 2025, making platforms liable for fines of up to $49.5 million if they fail to take reasonable steps to keep under-16s off their services.3 Newsom cited it in his State of the State address in January when asking whether California was doing enough.4
The regulations differ in critical ways. Australia, Indonesia, and California place the obligation on the platform, leaving the technology company to solve age verification. Indonesia's PP Tunas, signed in March 2025 and given implementing rules in March 2026, applies an under-16 threshold in a country where the state faces few constitutional limits on what it can order a platform to do.5 Britain regulates process: the Online Safety Act imposes duties of care and child-safety codes, treats age assurance as one tool among several, and lets Ofcom fine up to 10 percent of global revenue.6 France and Greece set the bar at age fifteen. France's ban passed both chambers on July 21, blocks new accounts from September 1, and reaches existing accounts in January. It carries no penalties for children or parents and awaits Constitutional Council review.7 Greece has scheduled its own ban for January 2027, and is lobbying Brussels for a Union-wide floor to eliminate risk of circumvention.8
Age verification remains unresolved. Australia's first month produced 4.7 million deactivated accounts. In its March compliance review, regulators documented children re-registering and revising their self-declared age through low-confidence facial estimation.9 Britain's adult-content checks in July 2025 sent VPN apps to the top of the App Store within a day.10 A rule that binds the compliant and exempts the motivated shifts where harm emerges without necessarily reducing it. Verification is the gap the platforms will litigate in California, and the outcome there will decide whether California's approach survives a Ninth Circuit review.
What the evidence shows
The strong claim, associated with Jonathan Haidt, is that smartphones and social media caused the post-2012 rise in adolescent anxiety, depression, and self-harm, particularly among girls.11 The record is consistent with this claim. Major depressive episodes among American teenagers roughly doubled between 2011 and 2021, and the Surgeon General's 2023 advisory reported that adolescents spending more than three hours a day on social media faced roughly double the risk of depressive symptoms.12 The skeptical position is that effect sizes in the large panel studies are small, that causation plausibly runs in both directions, and that screen time explains less variance in wellbeing than sleep or exercise.13 Both sides read the same data, but disagree about whether a small average effect conceals a large one in a vulnerable subgroup.
Two findings are firm enough to shape policy. Harm is concentrated among two subgroups: heavy users and children who were already struggling. The features California names are designed to sustain use past the point a user might otherwise stop, when the capacity for self-regulation is still developing. A rule aimed at those features does not require the aggregate causal claim to be true. The Electronic Frontier Foundation's objection, that California defines addictive features broadly enough that restrictions could reach ordinary functions rather than a narrow set of manipulative designs, is the most serious counterargument on record.1 This matters because a design rule becomes harder to distinguish from a speech restriction as the category expands. The state's case is strongest where it can tie a specific feature, such as autoplay or infinite scroll, to prolonged use rather than to the content being delivered.
The chatbot provisions rest on less evidence. The Adam Raine case, in which a teenager discussed suicidal ideation with ChatGPT before his death, is a single documented case.14 It did expose a gap: a product that sustains emotionally intimate conversation with a minor at scale, with no disclosure that it is a machine and no crisis protocol, is hard to imagine in most other consumer categories. California has regulated using that logic before a base rate exists. Whether the precaution is proportionate will depend on incident data that does not yet exist.
What decides whether the gate holds
The constitutional question comes first. NetChoice has already enjoined design-code laws in California, Ohio, and Arkansas, and the Ninth Circuit's Bonta ruling preserved the distinction California now relies on, treating features as conduct and content as speech. If a court reads autoplay as expressive, the approach likely fails in California and Britain's process model becomes the more durable alternative.
The verification question follows. Platforms will either converge on a common age signal, most plausibly the device-level credential California's AB 1856 now requires operating systems to expose and the European Commission's verification app is built to supply, or they will fragment by jurisdiction. Fragmentation creates a compliance cost that falls hardest on smaller platforms, an outcome the largest incumbents have little reason to resist.
The financial question is narrower. Meta's payout is partly conditional on its rivals settling. If Snap, TikTok, and YouTube hold out, the states' leverage weakens, and the liability pressure that moved legislatures this year eases with it.
The base case is that the regulation holds in a narrower form than signed. In this case, expect similar regulations to spread. France's ban is in force this month. Greece follows in fifteen months. A European floor is plausible within two years, driven by Paris and Athens, and American states will keep passing versions until Congress ratifies them or moves on its own. For platforms, the practical decision is whether to build one verification standard now or defend a patchwork later. Litigation has raised the cost of leaving child-safety risks unmanaged just as regulatory diffusion is raising the cost of solving them jurisdiction by jurisdiction. Together, those pressures make a common standard increasingly attractive.