致:开发面向或可能触及未成年人的App、游戏、社交及AI陪伴/聊天机器人产品的企业(美国 / 中国 / 全球)律师提醒与合规建议 | 2026年8月 | 仅供参考,不构成针对具体事务的法律意见
如果贵司的产品面向未成年人,或虽未刻意面向、但实际上有大量未成年人在使用,则下面这起案子值得相关企业认真研读。2026年8月26日,社交平台巨头 Meta(Facebook 与 Instagram 的母公司)同意在十年内支付最高约170亿美元,以了结美国数十个州(2023年起共42位总检察长提起、其中33州联邦联合诉讼)对其“把产品设计成让孩子上瘾”的指控——这是美国科技行业史上最大的单案和解。本案发生在美国、适用美国法律,但它对全球同类产品企业都有直接的借鉴意义。本文向企业解释:案子为什么发生、法律追的是什么、这条红线是否全球一致,并分别为美国企业、中国企业与其他全球企业给出合规建议。
关于“儿童安全和解案”的定性说明
本案在美国通称为“儿童安全和解案(child-safety settlement)”。此处的“儿童安全”有其特定含义,需特别说明:
•
它并非指人身安全事故,也不同于儿童性剥削内容(CSAM)类案件;
•
它特指——未成年人因社交/数字产品的“成瘾性设计”与薄弱的年龄门槛,所遭受的身心健康损害(如成瘾、睡眠剥夺、焦虑抑郁、身体形象问题),以及在未取得家长同意情况下的儿童个人信息被收集(涉 COPPA);
•
因此,本案的“安全”落点在“产品设计对未成年人心理健康、使用行为与个人数据的保护”,监管审查的对象是产品的设计与默认设置,而非平台上的具体内容。
一、Meta儿童安全案件的核心: 告的不是“内容”,而是平台的“设计”
各州起诉 Meta,靠的不是“平台上有坏内容”,而是“平台被刻意设计成让未成年人上瘾”。这是本案与以往平台责任案最根本的区别。2023年,共有42位州与特区总检察长对 Meta 提起诉讼——其中33个州于当年10月在加州北区联邦法院提起联合(合并)诉讼,哥伦比亚特区及其余数州则在各自法院另行起诉——共同主张 Meta 明知其设计会损害青少年身心健康却仍为之,并向公众隐瞒(庭审阶段约有29个州参与)。相关联邦案件在加州北区联邦法院合并审理, 2026年8月18日开庭,一周后即达成拟议和解。
本案件的意义在于:平台企业过去习惯依赖的“内容并非本司发布、平台免责”的这类抗辩, 在其平台“设计缺陷”这一路径下, 基本无从援用。
二、为什么“产品设计”本身会使企业被追责?
监管者的逻辑是:若企业的产品以一整套机制,系统性地利用未成年人尚不成熟的自控能力延长其停留时间,则由此造成的伤害,企业须承担责任。被反复点名的“成瘾性设计”包括:
•
无限下滑——取消自然的停止点;
•
不确定节奏的推送通知——像间歇性奖励一样反复“召回”用户;
•
以“黏性/参与度”为唯一优化目标的推荐算法——优先推送最能延长停留、而非对用户最有益的内容;
•
点赞、已读、连续打卡等社交激励——放大青少年对同伴认可的敏感与焦虑。
这些机制被指造成:未成年人强迫性使用、睡眠剥夺、注意力与情绪问题、身体形象焦虑,乃至与抑郁、焦虑相关的心理损害。与此同时,在明知有大量不满13岁儿童使用的情况下,未取得家长同意即收集其个人信息,已被指违反美国《儿童在线隐私保护法》(COPPA)。请注意:这里的每一项“设计”,很多产品都有——这正是本案示范意义的来源。
三、Meta 被要求做的整改,即企业未来可能被要求做的
这次和解最值得企业警惕之处,是它把一系列产品改造变成了“可强制执行的义务”。以下清单,可直接读作监管者眼中的“合规基线”:
和解要求 Meta 落实的整改(面向未成年人):
•
- 默认设置每日使用时长上限(是默认,不是可选功能);
•
- 夜间默认锁定使用,且仅家长可解除;
•
- 提供更强的家长监督与控制工具;
•
- 采用稳健的年龄核验,识别18岁以下及13岁以下用户;
•
- 禁止就自身安全功能作虚假或误导性宣传;
•
- 接受独立第三方审计员的合规监督。
关于生效:该和解目前仍为“拟议”,须经审理法官 Yvonne Gonzalez Rogers 最终批准方为终局;据报道法官已表示倾向批准,但截至本文尚未正式核准。Meta 已表示将在“数月内”着手落实。对企业而言,不必等它终局——上面这份清单,现在就应视为参照标准。
四、法律逻辑:监管者用的是“老法律”, 门槛并不高
很多企业误以为“没有专门的算法/AI 法,就没人管得了我”。本案恰恰相反:各州没有依赖任何新立法,而是用三部现成的法律打出组合拳——(1)州消费者保护法,针对就产品安全性作出的虚假或误导陈述与隐瞒;(2)公共妨害,针对对公众(尤其青少年)健康造成的持续性危害;(3)联邦 COPPA,针对未经家长同意收集儿童数据。这意味着:即便在没有专门立法的领域,监管者依然可以运用传统法律,直接审查企业的产品设计与默认设置。“无专门法即无风险”是危险的错觉。
五、律师合规建议:风险正在向哪些企业蔓延
⚠ 合规建议:符合以下任一情形,企业即已处于风险区
•
产品含有留住用户、拉长使用时长的机制(无限下滑、推送、参与度算法等);
•
用户中存在未成年人——无论企业是否“面向”未成年人,只要事实上存在,即可能被追责;
•
年龄门槛形同虚设(仅由用户自行勾选年龄);
•
曾对外宣传“安全”“适合青少年”等承诺,却与实际功能不符;
•
产品属于 AI 陪伴、虚拟伴侣或聊天机器人——因情感黏性更强,极可能成为下一个“设计救济”式追责目标。
六、这起案子只管美国吗?——红线是否全球一致
这是企业最关心的问题。答案分两层:
第一层(法律适用):本案适用美国法律,但决定企业是否“被管”的,不是公司国籍,而是其所服务的市场。 只要企业向美国用户(尤其是相关州的未成年人)提供产品,或事实上收集了美国儿童的数据,即可能落入美国州消费者保护法与联邦 COPPA 的管辖——即便其总部位于中国、欧洲或其他任何地方。反之,若企业完全不进入美国市场,则本案的美国法律责任原则上不直接适用。换言之:进入美国市场=直接受约束;不进入=不受该美国法律直接约束。
第二层(监管趋势):但“不进入美国就高枕无忧”是错的。 “成瘾性设计 + 薄弱年龄门槛 + 未成年人数据”这条红线,正在全球范围内趋同立法——各主要法域都在朝同一方向收紧。因此,即使不在美国市场,全球企业也应把本案当作“领先指标”来借鉴,而非隔岸观火。
同一条红线,正在各地成为法律
•
美国:州消费者保护法、公共妨害、COPPA;加州 SB 243(陪伴型聊天机器人)、纽约 RAISE 法案等州级新规。
•
中国:《未成年人网络保护条例》《未成年人保护法》网络保护专章、防沉迷与“未成年人模式”、《算法推荐管理规定》(不得诱导未成年人沉迷)、《人工智能拟人化交互服务管理暂行办法》。
•
欧盟:《数字服务法》(DSA)未成年人保护义务、禁止向儿童定向投放广告、针对无限滚动/自动播放/个性化推荐等“成瘾性设计”的执法,及委员会未成年人保护指南;年龄核验是2026年执法重点。
•
英国:《在线安全法》(Online Safety Act)与《适龄设计准则》(Children's Code)。
结论:进入美国市场的企业,必须直接对标本案的合规基线;不进入美国市场的企业,虽不受美国法律直接约束,但由于本国/本地区正在立同样的规矩,同样需要认真借鉴。对“出海”企业而言,更是要同时满足目标市场与母国的双重要求。
七、分类合规建议
以下按企业类型给出可操作的重点(交叉适用时,以更严格者为准):
(A)美国企业 / 已进入美国市场的企业
•
① 直接对标和解基线:面向未成年人的时长上限、夜间限制、家长控制默认开启;
•
② 部署稳健年龄核验,识别18岁以下与13岁以下用户并分级保护;
•
③ 严格遵守 COPPA:对13岁以下用户取得家长可核实的同意、数据最小化;
•
④ 对标州级新规:加州 SB 243、纽约 RAISE 法案等,按最严州要求统一执行;
•
⑤ 确保所有对外“安全”宣传真实可验证,避免构成 FTC/州法下的欺骗性陈述;
•
⑥ 妥善管理内部研究,发现风险及时处置——假定内部文件将来可能被强制披露。
(B)中国企业(含出海企业)
•
① 国内合规先做到位:落实《未成年人网络保护条例》——未成年人模式/专区、防沉迷、影响评估、算法不得诱导沉迷、AI 拟人化服务对儿童屏蔽“虚拟伴侣”并取得家长同意;
•
② 若产品触及美国用户(含应用商店可下载、面向美国投放),即受美国 COPPA 与州法约束——需另建一套美国向合规(年龄核验、家长同意、安全默认);
•
③ 出海=双重合规:目标市场(美/欧/英等)与中国规则并行,以更严者为基线;切勿以“国内已合规”默认满足海外要求;
•
④ 谨慎处理数据跨境与儿童数据,兼顾中国数据出境规则与目标市场儿童隐私法;
•
⑤ 对外宣传口径统一、真实,避免在任一市场构成虚假宣传;
•
⑥ 面向未成年人的 AI 陪伴/聊天机器人尤须提前内建安全默认与危机干预机制。
(C)其他全球企业
•
① 先判断是否进入美国市场:若是,按上文(A)对标美国合规基线;
•
② 无论是否进入美国,均应对标本地规则:欧盟 DSA(未成年人保护、禁止向儿童定向广告、成瘾性设计与年龄核验)、英国《在线安全法》与《适龄设计准则》等;
•
③ 以“最严法域”为统一设计标准,避免为不同市场维护多套彼此冲突的默认设置;
•
④ 把年龄核验作为2026年的合规重点(多地执法均聚焦于此);
•
⑤ 安全宣传须真实;内部风险研究须留档并及时应对;
•
⑥ AI 陪伴/聊天机器人等高黏性产品,提前建立面向未成年人的安全默认设置。
结语
这起案子给全行业的信号非常直接:让未成年人上瘾的“设计”本身,正在成为被诉的理由,而且这条红线在美国、中国、欧盟、英国等地正同步收紧。无论企业身处哪个市场,与其等待法院或监管者下令后再花巨资被动整改,不如在产品设计之初就把未成年人保护“内建”进架构,并保留每一项合规决策的书面记录。“先上线、以后再补合规”,如今是代价最高的一条路。如需就贵司具体产品与目标市场开展合规评估,请与我们的律师联系。
免责声明:本文基于截至2026年8月的公开报道整理,旨在向相关产品企业作一般性解释与风险提醒,不构成针对具体事务的法律意见。各法域规则复杂且不断更新,部分事实(如和解是否已获法院终局批准、参与州的确切数目)各来源略有出入;和解在获法院正式批准前仍属拟议。采取行动前请就具体情形咨询我所AI相关执业律师。
CHINESE / ENGLISH
English Version
Reading the Product-Compliance Red Line from Meta's US$17 Billion Child-Safety Settlement
To: Companies developing Apps, games, social platforms, and AI companion / chatbot products that are aimed at — or likely to reach — minors (United States / China / Global)
Counsel's Alert & Compliance Guidance | August 2026 | For general information only; not legal advice on any specific matter
If your company's product is aimed at minors — or, though not intentionally aimed at them, is in fact used by large numbers of minors — the following case warrants close study. On August 26, 2026, social-media giant Meta (the parent of Facebook and Instagram) agreed to pay up to approximately US$17 billion over ten years to resolve claims by dozens of U.S. states (brought since 2023 by a total of 42 attorneys general, 33 of them in a consolidated federal action) that it had “designed its products to addict children” — the largest single-case settlement in the history of the U.S. technology industry. The case arose in the United States and is governed by U.S. law, yet it carries direct lessons for comparable product companies worldwide. This memorandum explains why the case arose, what the law is targeting, whether this red line is consistent across jurisdictions, and offers compliance recommendations separately for U.S., Chinese, and other global companies.
A note on the term “child-safety settlement”
This case is commonly referred to in the United States as a “child-safety settlement.” The phrase “child safety” here has a specific meaning that merits clarification:
•
It does not refer to a physical-safety incident, nor is it a case about child sexual abuse material (CSAM);
•
It refers specifically to the physical and psychological harm to minors (such as addiction, sleep deprivation, anxiety and depression, and body-image problems) caused by the “addictive design” and weak age gates of social / digital products, together with the collection of children's personal information without parental consent (implicating COPPA);
•
Accordingly, “safety” in this case turns on protecting minors' mental health, usage behavior, and personal data through product design — the object of regulatory scrutiny is the product's design and default settings, not the specific content carried on the platform.
I. The heart of the Meta child-safety case: the claim targets the platform's “design,” not its “content”
The states sued Meta not on the theory that “there is bad content on the platform,” but that “the platform was deliberately designed to addict minors.” That is the fundamental distinction between this case and earlier platform-liability cases. In 2023, a total of 42 state and territorial attorneys general sued Meta — 33 states brought a consolidated (joint) action in the U.S. District Court for the Northern District of California that October, while the District of Columbia and several other states filed separately in their own courts — jointly alleging that Meta knew its design would harm the physical and mental health of adolescents yet proceeded anyway, and concealed this from the public (roughly 29 states participated at the trial stage). The related federal actions were consolidated before the Northern District of California; trial opened on August 18, 2026, and a proposed settlement was reached about a week later.
The significance of the case is this: the defenses that platform companies have traditionally relied on — “the content was not published by us; the platform is not liable” — are essentially unavailable under this “design-defect” theory.
II. Why can “product design” itself expose a company to liability?
The regulators' logic runs as follows: if a company's product uses an integrated set of mechanisms to systematically exploit minors' still-immature self-control in order to prolong their time on the platform, the company must answer for the resulting harm. The “addictive design” features repeatedly singled out include:
•
Infinite scroll — removing the natural stopping point;
•
Push notifications with unpredictable timing — repeatedly “recalling” the user, much like an intermittent reward;
•
Recommendation algorithms optimized solely for “stickiness / engagement” — prioritizing content that maximizes time-on-app rather than content that best serves the user;
•
Social-validation mechanics such as likes, read receipts, and streaks — amplifying adolescents' sensitivity to peer approval and their anxiety.
These mechanisms are alleged to cause compulsive use, sleep deprivation, attention and mood problems, body-image anxiety, and even depression- and anxiety-related psychological harm among minors. At the same time, knowingly collecting the personal information of large numbers of children under 13 without parental consent has been alleged to violate the U.S. Children's Online Privacy Protection Act (COPPA). Note that many products incorporate every one of these “design” features — which is precisely what gives this case its precedential force.
III. What Meta was required to change is what companies may be required to do next
The most cautionary feature of this settlement is that it converts a series of product changes into “enforceable obligations.” The following list can be read directly as the “compliance baseline” in the eyes of regulators:
Remedial measures the settlement requires Meta to implement (for minors):
•
- Default daily time limits (a default, not an optional feature);
•
- Overnight use locked by default, removable only by a parent;
•
- Stronger parental supervision and control tools;
•
- Robust age assurance to identify users under 18 and under 13;
•
- A prohibition on false or misleading statements about its own safety features;
•
- Compliance oversight by an independent third-party auditor.
On the effective date: the settlement remains “proposed” and will not become final until approved by the presiding judge, Yvonne Gonzalez Rogers; she is reported to have indicated that she is inclined to approve it, though she had not formally done so as of this writing. Meta has said it will begin implementation “within months.” For companies, there is no need to wait for finality — the list above should already be treated as a reference standard.
IV. The legal mechanics: regulators are using “old laws,” and the threshold is not high
Many companies mistakenly assume that “with no dedicated algorithm / AI statute, no one can regulate me.” This case shows the opposite. The states relied on no new legislation; instead, they combined three existing bodies of law — (1) state consumer-protection statutes, aimed at false or misleading statements and concealment regarding product safety; (2) public nuisance, aimed at ongoing harm to public (and particularly adolescent) health; and (3) the federal COPPA, aimed at the collection of children's data without parental consent. The lesson is that, even in areas without dedicated legislation, regulators can still use traditional law to scrutinize a company's product design and default settings directly. “No dedicated statute means no risk” is a dangerous misconception.
V. Compliance guidance: which companies the risk is spreading to
⚠ Compliance alert: if any of the following applies, the company is already in the risk zone
•
The product contains mechanisms to retain users and prolong time-on-app (infinite scroll, push notifications, engagement-driven algorithms, and the like);
•
Minors are among the users — whether or not the company “targets” minors, their factual presence alone may give rise to liability;
•
Age gating is nominal only (relying solely on users self-declaring their age);
•
The company has publicly promoted “safety” or “suitable for teens” claims that do not match the product's actual features;
•
The product is an AI companion, virtual partner, or chatbot — with stronger emotional stickiness, it is a likely next target for “design-remedy” enforcement.
VI. Does this case concern only the United States? — Is the red line globally consistent?
This is the question companies care about most. The answer has two layers.
Layer one (application of law): the case is governed by U.S. law, but what determines whether a company is “regulated” is not its nationality but the market it serves. So long as a company offers products to U.S. users (particularly minors in the relevant states), or in fact collects U.S. children's data, it may fall within the reach of U.S. state consumer-protection laws and the federal COPPA — even if it is headquartered in China, Europe, or anywhere else. Conversely, if a company does not enter the U.S. market at all, the U.S. liability at issue here does not, in principle, apply directly. In short: entering the U.S. market = directly bound; staying out = not directly bound by this U.S. law.
Layer two (regulatory trend): but “no U.S. presence means nothing to worry about” is mistaken. The red line of “addictive design + weak age gates + minors' data” is converging in legislation worldwide, with the major jurisdictions all tightening in the same direction. Accordingly, even without a U.S.-market presence, global companies should treat this case as a leading indicator to learn from, rather than a distant spectacle.
The same red line is becoming law across jurisdictions
•
United States: state consumer-protection statutes, public nuisance, and COPPA; state-level measures such as California SB 243 (companion chatbots) and New York's RAISE Act.
•
China: the Regulations on the Protection of Minors in Cyberspace; the online-protection chapter of the Law on the Protection of Minors; anti-addiction rules and “minor mode”; the Provisions on the Administration of Algorithmic Recommendations (which forbid inducing minors into addiction); and the Interim Measures for the Administration of AI Anthropomorphic Interactive Services.
•
European Union: minor-protection obligations under the Digital Services Act (DSA); a ban on targeted advertising to children; enforcement against “addictive design” such as infinite scroll, autoplay, and personalized recommendations; and the Commission's guidelines on the protection of minors — with age assurance a 2026 enforcement priority.
•
United Kingdom: the Online Safety Act and the Age Appropriate Design Code (Children's Code).
Bottom line: companies entering the U.S. market must benchmark directly against this case's compliance baseline; companies that stay out of the U.S. market, though not directly bound by U.S. law, must still take it seriously, because their home country or region is enacting the very same rules. For companies expanding abroad, the imperative is to satisfy the dual requirements of both the target market and the home jurisdiction.
VII. Compliance recommendations by company type
The following sets out actionable priorities by company type (where more than one applies, the stricter standard governs):
(A) U.S. companies / companies already in the U.S. market
•
① Benchmark directly against the settlement baseline: time limits, overnight restrictions, and parental controls for minors, on by default;
•
② Deploy robust age assurance to identify users under 18 and under 13, with tiered protections;
•
③ Comply strictly with COPPA: obtain verifiable parental consent for users under 13 and practice data minimization;
•
④ Track state-level measures such as California SB 243 and New York's RAISE Act, applying the strictest state standard uniformly;
•
⑤ Ensure that every outward “safety” claim is truthful and verifiable, so as to avoid deceptive statements under FTC / state law;
•
⑥ Manage internal research prudently and address risks promptly — assume internal documents may later be compelled to disclosure.
(B) Chinese companies (including those expanding overseas)
•
① Get domestic compliance right first: implement the Regulations on the Protection of Minors in Cyberspace — minor mode / zones, anti-addiction measures, impact assessments, algorithms that do not induce addiction, and, for AI anthropomorphic services, blocking “virtual partner” features for children and obtaining parental consent;
•
② If the product reaches U.S. users (including being downloadable from app stores or marketed to the U.S.), it is subject to U.S. COPPA and state law — a separate U.S.-facing compliance layer (age assurance, parental consent, safe defaults) is required;
•
③ Going global = dual compliance: run the target-market rules (U.S. / EU / UK, etc.) in parallel with the Chinese rules, taking the stricter as the baseline; never assume that “already compliant at home” satisfies overseas requirements;
•
④ Handle cross-border transfers and children's data with care, reconciling China's data-export rules with the target market's children's-privacy laws;
•
⑤ Keep external messaging consistent and truthful to avoid false advertising in any market;
•
⑥ For AI companion / chatbot products aimed at minors in particular, build in safe defaults and crisis-intervention mechanisms in advance.
(C) Other global companies
•
① First determine whether you are entering the U.S. market: if so, benchmark against the U.S. baseline in (A) above;
•
② Whether or not you enter the U.S., benchmark against local rules: the EU DSA (protection of minors, ban on targeted advertising to children, addictive design, and age assurance), the UK Online Safety Act and Children's Code, and the like;
•
③ Use the “strictest jurisdiction” as a single design standard, avoiding the maintenance of multiple, conflicting sets of defaults across markets;
•
④ Make age assurance a 2026 compliance priority (enforcement across jurisdictions is focused on it);
•
⑤ Keep safety claims truthful; document internal risk research and address it promptly;
•
⑥ For high-stickiness products such as AI companions / chatbots, build in safe defaults for minors in advance.
Closing
The signal this case sends to the entire industry is unmistakable: “design” that addicts minors is itself becoming a ground for suit, and this red line is tightening in parallel across the United States, China, the EU, and the UK. Whatever market a company operates in, rather than remediating reactively — and at great expense — only after a court or regulator so orders, the wiser course is to build minor protection into the product architecture from the outset and to keep a written record of every compliance decision. “Launch first, fix compliance later” is now the most expensive path of all. For a compliance assessment tailored to your specific product and target markets, please contact our attorneys.
Disclaimer: This memorandum is compiled from public reporting available as of August 2026 and is intended to provide general explanation and risk alerts to relevant product companies; it does not constitute legal advice on any specific matter. The rules across jurisdictions are complex and continually evolving, and certain facts (such as whether the settlement has received final court approval and the exact number of participating states) vary among sources; the settlement remains proposed until formally approved by the court. Before taking action on any specific matter, please consult our firm's AI-practice attorneys.
/ END.
*本文为上海曼昆律师事务所的原创文章,仅代表本文作者个人观点,不构成对特定事项的法律咨询和法律意见。如需转载及法律咨询,请添加客服:mankunlawyer / MankunLawFirm(WhatsApp)


