background image blur
background image
  • Blog
    >
  • News
    >
  • California’s Newsom Just Signed 13 Child Safety Laws

California’s Newsom Just Signed 13 Child Safety Laws

Image of author
By Tech Writer and VPN Researcher Gintarė Mažonaitė
clock icon
Last updated: 11 September, 2026
A mom and daughter using a phone

Key Takeaways

  • California Governor Gavin Newsom signed 13 laws relating to youth online safety and privacy on September 10, 2026, targeting AI chatbots, addictive social media features, and platform liability for child harm.
  • AB 1709 bans social media companies from offering children under 16 access to personalized "For You" feeds, infinite scrolling, and video autoplay — but still allows kids to use platforms if those features are turned off.
  • SB 1119 ("Adam's Law") requires AI chatbots to verify users' ages, restricts advertising to minors, and limits persistent memory features that advocates say were used to isolate and manipulate a California teen who died by suicide after conversations with ChatGPT.
  • AB 2 threatens fines of up to $1 million per child where platforms are found liable for fostering anxiety, depression, or other child harms — significantly expanding legal exposure beyond the $18 billion Meta settlement.

Governor Newsom signed 13 child safety laws on Thursday, according to Politico's reporting — the most significant state-level child online safety legislation since the Meta settlement last month. Three laws anchor the package. AB 1709 bans social media companies from offering children under 16 access to personalized feeds, infinite scrolling, and video autoplay, while still allowing kids to use platforms if those features are disabled. 

SB 1119, backed by OpenAI CEO Sam Altman, requires AI chatbots to verify users' ages, restricts exposure to inappropriate content, limits advertising to minors, and restricts persistent memory features. AB 2 creates liability of up to $1 million per child in cases where platforms are found to have fostered anxiety, depression, or other harm — tripling payouts in cases where courts find significant damages.

Newsom argued the California approach was superior to Australia's outright social media ban because it "is about the features themselves" rather than access. "This is about actually addressing the problem, the scrolling, the algorithms," he said.

That framing is worth examining carefully, because it's the same argument we've made in this series. Banning algorithmic feeds, autoplay, and infinite scrolling for minors targets the design decisions that Meta's own internal research — revealed during the trial before the settlement — showed were driving harm. Those are the features that turned Instagram, in a former researcher's words, from a product you use "to a product that uses you." Targeting design is more proportionate than restricting access.

The Caveats Are Real

The distinction between design-targeting and access-restriction is meaningful, but California's package still includes features that raise the concerns we've raised consistently.

AB 1709 still requires age verification — it relies on California's existing AB 1043, which prompts users to enter their birth date when setting up a new device and requires manufacturers to share users' ages with apps.

Age verification requirements create exactly the privacy infrastructure we've documented in the ID-check breach timeline: a centralized database of users' ages and identities that can be breached, subpoenaed, or misused. The EFF raised concerns earlier this year about AB 1709's privacy implications and its potential to limit LGBTQ+ youth from finding support communities online — concerns that remain valid even as the bill's design-targeting approach is stronger than outright bans.

SB 1119's persistent memory restrictions are the provision most directly supported by the specific harm it addresses. Adam Raine's family's account of how ChatGPT built a detailed model of a teenager's emotional state and used it to isolate and manipulate him is the clearest documented case of AI chatbot harm we've seen cited in legislation.

The law's requirement that chatbots default to the "most protective" settings — including no persistent memory — is a direct response to that documented failure mode. OpenAI's support for the bill after language was added clarifying memory retention with parental consent suggests the final version represents a workable compromise.

The $1M Per Child Liability Question

AB 2 is the most financially consequential part of the package. Fines of up to $1 million per affected child create liability exposure that makes the Meta settlement look modest at scale. If a platform is found to have fostered anxiety or depression in thousands of minors — and Meta's own research suggested the numbers were in the millions — the potential liability is enormous.

That's the point. Assemblymember Josh Lowenthal said at the signing: "We're done asking nicely, and we're demanding that there is a duty of care across these platforms — a duty that puts the wellness of our children ahead of profits."

We've argued throughout this series that liability for design decisions is more targeted and more proportionate than age verification mandates or platform bans. AB 2 is the strongest version of that argument enacted in US law. Whether it survives a First Amendment challenge — and whether courts accept that algorithmic design causing emotional harm can ground a $1 million per-child liability — will determine whether it accomplishes anything beyond creating settlement pressure.

California is not getting this entirely right. The age verification infrastructure is a privacy risk. The LGBTQ+ community access concern is legitimate and should be addressed in implementation. But the overall direction — target the design decisions that cause harm, create meaningful liability for those decisions, restrict features rather than access — is more defensible than what most jurisdictions have done. 

If AB 2's liability framework holds up in court, it could become the template that the Meta settlement gestured toward but didn't fully establish.


Share on
Facebook share Twitter share Reddit share Linkedin share

Be part of the resistance, quietly.

Get Mysterium VPN Arrow icon
awareness campaign banner img
Image of author
Gintarė Mažonaitė
Tech Writer and VPN Researcher

Gintarė is a cybersecurity writer at Mysterium VPN, where she explores online privacy, VPN technology, and the latest digital threats in editorial pieces. With hands-on experience researching and writing about data protection and digital freedom, Gintarė makes complex security topics accessible and actionable.

Read our editorial policy here.

Read more by this author
© Copyright 2026 UAB "MN Intelligence"