Free guide: How to use AI in compliance
Back

Meta age assurance settlement: certified accuracy targets and a delete-by-default rule

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Published September 1, 2026Reviewed by Charlene Wang
Editorial illustration for the article "Meta age assurance settlement: certified accuracy targets and a delete-by-default rule".

Meta's age assurance settlement sets certified false positive caps, ISO 27566 testing and a delete-by-default data rule. What compliance teams should read now.

Table of contents

Meta agreed on 26 August 2026 to a proposed settlement with 51 attorneys general that pays states up to 17 billion dollars and imposes certified age assurance accuracy caps on Instagram and Facebook. The executed agreement also forces age data to be deleted once an age decision is made.

  • The deal was struck mid-trial in the U.S. District Court for the Northern District of California, case 4:23-cv-05448-YGR, and needs court approval through a consent judgment.
  • Third-party age assurance tools must hit a U18 false positive rate, excluding circumvention, at or below 10 percent for 16 and 17 year olds and 3 percent for 13 to 15 year olds within a year.
  • Meta's own models get a slower ramp: 14 percent for 16 and 17 year olds and 7 percent for 13 to 15 year olds in year one, then 10 and 5 by year two.
  • Age check evidence must be held only long enough to reach a decision, then queued for deletion, though the stated age and the verdict itself are exempt.
  • An independent auditor tests compliance across five reports, and any Final Report identifying a material gap forces a corrective action plan filed within 30 days and approved within 90.

What did Meta actually agree to?

Meta signed a consent judgment with 51 attorneys general, eight days into trial in the Northern District of California, resolving claims that Instagram and Facebook were designed to drive compulsive use by minors. The states sued under the Children's Online Privacy Protection Act and their own unfair and deceptive acts and practices statutes. The Meta age assurance settlement admits no liability, and reaches only users in the 51 settling jurisdictions.

California Attorney General Rob Bonta said the deal would "make social media less dangerous for our kids". Alongside the age rules, the agreement resets the product for under-18s: a default two-hour combined daily limit, a midnight to 6am access block, push notifications off from 10pm to 7am and during school hours, like counts hidden unless a supervising parent unlocks them, a block on cosmetic procedure filters, and an optional non-personalised feed. Everything below covers only the age assurance provisions, the part with implications outside social media.

The money runs in four streams. Exhibit B guarantees 11.7 billion dollars and caps the states at 16.7 billion; the cost fund and the Cambridge payment lift that to a 12.2 billion floor and the 17.2 billion headline.

TermValue
Cost fund payment75 million dollars, due within 30 days of the effective date
Guaranteed payments1,165,662,174.56 dollars per instalment, ten instalments, first within 30 days then each 15 January from 2027
Contingent payments502,402,600.77 dollars per instalment, ten instalments, permanently forfeited if rivals never match
Maximum state payment16,680,647,753.21 dollars across all instalments, before Cambridge and cost fund
Cambridge payment459,293,017.80 dollars settling the separate Cambridge Analytica claims
Largest allocationsCalifornia up to 2,197,944,372.61 dollars, New York up to 1,129,769,577.26 dollars
Agreement term10 years from the effective date, compliance date at six months

The effective date is the first business day after the court enters the consent judgment. As of 27 August 2026 no judgment has been entered, so none of the clocks have started.

How does the accuracy standard work?

The agreement does not ask Meta to guess ages well. It defines a metric, the U18 false positive rate, as the share of actual 13 to 17 year olds "incorrectly identified or predicted by Meta to be 18 years or older", then caps it and requires annual third-party testing. This is the part of the Meta age assurance settlement other platforms will be judged against.

Method type16 to 17 year olds13 to 15 year oldsDeadline
Commercially available tools10%3%One year from effective date
Meta proprietary models, year one14%7%One year from effective date
Meta proprietary models, year two10%5%Two years from effective date

All six thresholds are measured excluding method circumvention (Section II.A.6(a), at 23). The split matters twice over: commercial tools are certified by the third party, while Meta tests and certifies its own models, with the provider only vetting method and results. In exchange Meta forfeits the presumption of compliance for anything proprietary.

Maximum U18 false positive rates by age band: 3 and 10 percent for commercial tools, 7 and 14 percent for Meta models, easing to 5 and 10 by year two.
Analysis by Zyphe, from Section II.A.6(a) of the executed consent judgment.

Testing must reflect real world conditions: nothing tested on training or tuning data, performance measured across age, race, gender and disability status, and for face-based methods a spread of pose, lighting and facial archetypes (Section II.A.2, at 22). Certification must show the method reflects global best practices, or meets ISO 27566 or an equivalent internationally recognised standard. That is a disjunction, not a mandate, so ISO/IEC 27566-1:2025, the first international age assurance framework, functions as a safe harbour.

Two design choices deserve attention. Meta must ingest reliable age signals from Apple and Google operating systems and app stores, pushing the age question toward the device. And where a user chooses a check, attempts are capped at three per method in 24 hours, four in a month and six over two years, counted across linked accounts.

What does this mean for your KYC and AML obligations?

The Meta age assurance settlement binds two consumer platforms, not a bank or a crypto exchange. It still moves the baseline, because a court-enforced accuracy figure is the first hard number in a field run on vendor marketing claims. Four duties shift, each with an analogue in customer due diligence.

What does the presumption of compliance require?

Meta gets a presumption of compliance when it relies on a certified commercial tool, but only if all six of these hold.

Condition for the presumptionWhat it demands in practice
Operated to vendor specificationProduction matches the vendor's current technical specs and terms of use
Settings match testingEvery variable setting equals the one the tester used
No interferenceMeta did not encourage, facilitate or knowingly permit user circumvention
No wilful blindnessMeta did not ignore events that degraded the method's efficacy
Honest disclosureComplete and accurate information given to the testing provider
No other breachNo related violation of the agreement

Any team leaning on a third-party identity or age tool should hold the certificate, the tested configuration, and evidence that production matches it, the same evidencing discipline CIP record-keeping under 31 CFR 1020.220 already demands.

How long can age data be kept?

The clause reaches only data collected "for the sole purpose of conducting age assurance", which must be "held for the minimum period required to determine a user's age status", then deleted (Section II.A.8, at 28). Three carve-outs survive: under-13 data used to train the detection model, coarse metadata about the method used, deleted within 90 days once redundant, and, most consequentially, the user's stated date of birth, stated age and the age decision itself, which the clause expressly does not touch. Compare that with the five-year retention duty under UK MLR 2017 regulation 40 and the EU rules it mirrors, and the tension is plain. Because the clause bites only on sole-purpose age data, a document captured for both age and AML sits outside it, and that ambiguity is exactly what a supervisor will probe.

What appeal rights does it create?

Users misclassified as minors must get a clear route to appeal, with a timely decision and a stated basis (Section II.A.9, at 28). That is close to the reasoning duty GDPR Articles 22 and 15(1)(h) already impose when an automated decision restricts a person, and it is a control most onboarding stacks handle badly.

What did the states give up?

The states released COPPA claims, but only for retaining children's data to improve under-13 detection, and expressly not for advertising, marketing or algorithmic optimisation. Purpose limitation does the work. Enforcement is not theoretical: where a Final Report identifies a material gap, Meta must file a corrective action plan within 30 days, approved by the auditor within 90 unless the State Committee extends. Beyond that the remedy is judicial, because the terms sit in a consent judgment the states can ask the court to enforce.

What is still uncertain?

Five things could still blunt the Meta age assurance settlement. The caps ignore false negatives. Coverage stops at the settling states and excludes messaging surfaces such as Messenger and Instagram Direct. The presumption of compliance shifts risk onto vendors. The required accuracy may not exist yet. And the agreement disclaims its own precedential value, which limits how far the standard travels.

Take those in turn. No numeric ceiling is set on false negatives, and Section II.A.11 asks only for best efforts, so a system that shunts adults into teen accounts is legally compliant and merely annoying commercially.

The presumption moves risk down the chain. If a certified tool underperforms in production, Meta is presumptively covered while the vendor carries the hit. Expect certification to get expensive and tested configurations to narrow.

Accuracy at the required level may not exist yet. The parties wrote a fallback: if no commercial ID verification or facial age estimation method meets the threshold, the parties must meet and confer on alternatives. That is a negotiated admission that the technology may not clear its own bar.

Finally, Meta bought a disclaimer. The agreement says it does not establish a standard of care or serve as precedent in any non-participating state or foreign jurisdiction, and creates no private right of action. Nothing stops a supervisor asking why your error rate is worse than one a court just accepted, but nobody can sue on this document.

Nor is any of it binding until a judge signs, and the contingent money depends on Snap, TikTok and YouTube being bound to comparable terms. That trigger is a two-way ratchet: if they do, the states collect and Meta's own limits tighten, from a single two-hour allowance across both apps to 60 minutes on each inside the same 120-minute ceiling, and from a six-hour night block to nine. It is also the one mechanism that spreads the standard, because industry-wide adoption counts only if every rival is bound to age assurance no less restrictive than Meta's, audited independently for five years.

Why does the deletion clause matter more than the money?

The deletion clause matters more because the money is a one-off while the retention rule is a design constraint that outlasts it. Regulators have spent three years pushing age checks onto platforms while privacy authorities warned that mandatory checks create fresh pools of identity documents to steal. The Meta age assurance settlement is the first major instrument to answer that by contract.

The rule is narrow but useful: collect, decide, delete the evidence, keep the verdict. The identity industry reached the same conclusion from the breach side. Our age verification and digital identity guide argues the safest architecture is one where the checking party never holds the document, and the EU age verification trusted list takes a similar route through attestations. The state-law fights, including Texas app store age verification, argued about who must check, not what happens to the data afterwards. This agreement finally does.

How should compliance teams respond?

Treat the Meta age assurance settlement as a reference specification, not a legal standard, then work four steps. Inventory every age or identity check and name its vendor. Collect the current certificate and the exact configuration tested. Measure error rates by cohort, not in aggregate. Separate retention clocks so age evidence and AML records never share a store.

Then build the appeal path before you need it, with a stated basis for every adverse decision.

Zyphe was built for the architecture these terms reach for. Verification runs on an NFC chip read to ICAO 9303 and eIDAS standards, with two-step liveness and no image upload, so there is no document store to delete on a deadline or lose in a breach. Personal data is sharded across a decentralised network of more than 60,000 nodes under a 29-of-100 threshold scheme that never depends on one key holder, so AML records stay reconstructable on their own clock with no central honeypot. To see how that maps to your onboarding, book a demo or read how it works.

The bottom line

The headline of the Meta age assurance settlement is the payment, but the operative part is the engineering. For the first time an age check has a defined error metric, a certification route, an audit trail and a deletion deadline, enforceable by a court rather than promised in a trust centre. Teams running KYC and AML should read the injunctive terms as a preview of what supervisors will ask next: not whether you verify, but how accurate you are by cohort, who certified it, and how fast you delete what you no longer need.

Cited sources

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.

Frequently Asked Questions

No. It is a proposed settlement that takes effect only when the court enters a consent judgment in the MDL action. The effective date is the first business day after entry, and the six-month compliance date and one-year accuracy deadlines all run from there. As of 27 August 2026 no judgment had been entered, so none of the obligations were yet enforceable.

It is the percentage of real users aged 13 to 17 who are wrongly identified or predicted to be 18 or older, measured excluding circumvention. It is the single certified performance number, tested annually under real world conditions rather than on training or tuning data. Commercial tools are certified by an accredited third party; Meta self-certifies its own models.

No. The agreement is method-neutral. It names ID verification and facial age estimation as examples of methods a user may choose, and requires reliable age signals from Apple and Google platforms to be incorporated, but it sets an accuracy outcome rather than mandating any one technique.

Only as long as needed to reach the age decision, after which it must be queued for deletion. Three exceptions apply: under-13 data used to train and test the detection model, coarse metadata about the method used and deleted within 90 days once redundant, and the user's stated age and the resulting classification, which fall outside the clause entirely.

Not directly, and the agreement expressly disclaims any precedential effect outside the settling states. It still sets a reference point. A defined error metric, third-party certification and a delete-by-default rule are now the shape of a defensible age check anywhere, including gambling, alcohol delivery and adult content.

See privacy-first KYC in action

Verify identity without storing a single document. Reusable credentials, an exportable audit trail, and a 15-minute integration.

Book a demo