California bans social media's endless feed for under-16s

11.09.2026 8 min 27

On 10 September California's governor signed thirteen bills on children and technology at once. One of them, AB 1709, does something no US state has done before: it forbids social platforms from giving anyone under 16 an algorithmic feed or autoplay at all, with no parental consent option to switch it back on. The awkward question the law does not answer is how a platform is supposed to know who is 15.

In short

  • AB 1709 bans "addictive features" for under-16s outright. Enforcement is by the Attorney General or a local prosecutor, with civil penalties.
  • A second law, named after a teenager who died, sets rules for companion chatbots: crisis protocols, parental controls, and independent child safety audits.
  • California is building the age signal into the operating system and app store layer, not into every website, through a separate law that starts in January 2027.
  • The EFF asked for a veto, arguing the bill bans ordinary features and pushes platforms towards ID checks and biometric age estimation for everyone.

What an addictive feature is, legally

The bill's own findings say platforms are engineered around algorithmic recommendation, infinite scroll, autoplay and notifications, and it treats those as the target. In practice AB 1709 prohibits a covered platform from providing an addictive feature to a user under 16, and requires the platform to take reasonable measures to ensure under-16s are not offered one.

California already had a narrower rule. The Protecting Our Kids from Social Media Addiction Act bars an addictive feed to a known minor unless the operator has verifiable parental consent. AB 1709 removes that escape hatch for the under-16 bracket: consent no longer unlocks it.

  1. AB 1709 (Lowenthal): the under-16 ban on addictive features, plus an e-Safety Advisory Commission inside the Department of Justice.
  2. SB 1119 (Padilla, Wicks, Bauer-Kahan): companion chatbots for children. Crisis protocols where a child expresses suicidal ideation, parental controls, notification if a child turns safety settings off, and the first US requirement for independent child safety audits and annual risk assessments.
  3. AB 2 (Lowenthal): makes a social media platform liable in damages where a failure of ordinary care injures a child. It sunsets on 1 January 2035.
  4. AB 2246 (Wicks): repeals California's Age-Appropriate Design Code and replaces it with a rewritten version, after the original was tied up in court.
  5. AB 1856 (Wicks): age verification signals in software applications, the plumbing for everything above.
Worth correcting a common summary: AB 2 is not a ban on advertising to children. It is a liability rule: it lets damages be claimed when a platform's want of ordinary care injures a child. The advertising and pupil-data protections in the package sit in other bills.

The part that decides whether any of this works

A rule that applies to people under 16 needs a way to tell who they are, and that is where California has chosen a different route from most age-check laws. Rather than making every website interrogate its visitors, a separate statute already on the books, the Digital Age Assurance Act, requires from 1 January 2027 that an application ask the operating system or app store for an age bracket when it is downloaded and launched.

If that works as intended, the phone tells the app roughly how old its owner is, and no individual service has to collect documents. It is the same architectural move Britain is making with device-level checks, and we wrote about that when the UK announced it would legislate the nudity filter into the handset itself. Two governments, two subjects, one shared conclusion: the enforcement point is moving down the stack, out of the website and into the device you already own.

13bills signed on 10 September in one package
16age below which addictive features are prohibited
1 Jan 2027when the device-level age signal requirement starts
2035year the platform liability law expires unless renewed

The objection

The Electronic Frontier Foundation asked the governor to veto AB 1709 and did not soften its language. Its argument is not that engagement design is harmless. It is that the bill's definition sweeps in the ordinary machinery of a social network, including feeds built from who you follow and what you liked, so that the practical result for a 15-year-old is exclusion rather than a safer experience.

Age-gating requirements will force everyone to give big tech companies even more personal information.

Electronic Frontier Foundation, in its letter urging a veto

The second half of the objection is the one that matters for readers who are not teenagers. To keep under-16s out, platforms must establish who is over 16, and the tools for that are government ID or biometric age estimation. Either creates a store of sensitive data that did not previously exist, and biometric estimation has documented error rates that differ by race and gender. The group also warns of legal confusion, since AB 1709 overlaps with two laws California already passed.

There is a real disagreement underneath this, and it is worth stating plainly rather than picking a side. The state's case is that a design engineered for compulsive use is not speech and can be regulated like any other product feature. The critics' case is that a feed is how speech gets found, and removing it from a minor is removing the library, not the cigarette.

What happens next

  1. California bars addictive feeds to known minors without verifiable parental consent.
  2. Thirteen bills signed, including the flat under-16 ban and the chatbot law.
  3. The device-level age signal requirement takes effect, giving the ban a mechanism.
  4. Litigation. California's previous design-code law was blocked in court, which is why one of these bills rewrites it from scratch.

The court risk is not hypothetical. The original Age-Appropriate Design Code was challenged and enjoined, and AB 2246 exists precisely to replace it with something that might survive review. Expect the same argument to be made against AB 1709.

Where this fits

California is not acting alone, and the direction of travel across countries is by now clear enough to keep a list of. We maintain one: which countries restrict social media for minors, and at what age. What changes with this package is not the idea of an age limit, which is now common, but the decision to ban the feed itself rather than the account, and to put the age signal in the operating system.

A VPN is the reflex answer whenever a jurisdiction fences something off, and it is worth being precise about why it is a weak one here. Changing your apparent country does nothing about an age bracket your phone reports from the app store account it is signed into. This is not a geographic block, and it is not enforced at the network layer.

Does this mean under-16s cannot use social media in California?
Not exactly. They cannot be offered algorithmic feeds, autoplay and similar features. Critics argue that with those removed from every major service the practical effect is close to exclusion; the state argues the account remains, just without the engagement machinery.
Will I have to prove my age to use social media?
The design intent is that your device or app store supplies an age bracket rather than each service demanding documents, under a separate law starting in January 2027. Whether platforms rely on that alone or add their own checks is the open question, and it is the heart of the EFF's objection.
Who enforces the ban?
The Attorney General or a local public prosecutor, through a civil action, with civil penalties for a non-compliant platform. The law does not create a private right of action for individuals under this provision.
What is the chatbot law about?
It sets safety requirements for companion chatbots used by children, including protocols when a child expresses suicidal ideation, parental controls, notifying parents if safety settings are switched off, and independent child safety audits with annual risk assessments.
Could a VPN get around it?
No. The mechanism is an age signal tied to the device and the app store account, not to the country your traffic appears to come from.

californiausaage verificationsocial medialegislationprivacydigital rightseffaichatbots

Read also