THE PERMISSIONED WEBPRIMARY PDF
An anonymous figure faces a vast illuminated identity checkpoint in a rain-dark network city.
CASEFILE 02626 AUG 202652 ATTORNEYS GENERALUP TO $18B

A CIVIL-LIBERTIES THREAT MODEL OF META'S TEEN-SAFETY SETTLEMENT

THE
PERMISSIONED
WEB

Children deserved a duty of care before Gen Z became the experiment. Adults and teenagers still deserve to speak, use pseudonyms, communicate privately, and enter the public internet without showing papers at the door.

READ THE AUDIT

Verdict: regulate the machine, not the identity of every person using it.

STATUS: SIGNED, SUBJECT TO COURT APPROVAL

00 / RAPID VERDICT

Encryption survives. The settlement mandates population-scale age classification.

The settlement leaves end-to-end encryption alone. WhatsApp and AI-first companions fall outside its product definition. Its civil-liberties danger lies elsewhere: every covered user enters an age-classification system, accounts can be linked, and parental dashboards can expose sensitive relationships.

Encryption

NOT ORDERED OPEN

No backdoor, client scanning, key escrow, or decryption mandate appears in the filed agreement.

WhatsApp

OUT OF SCOPE

WhatsApp is not named. Services whose primary function is direct messaging are excluded.

Meta AI

EXPLICITLY EXCLUDED

AI-first products and features are outside the definition. Mixed Instagram and AI surfaces remain unresolved.

Age assurance

POPULATION SCALE

Every covered account in a settling state enters an age-classification system, adults included.

Alternate accounts

LINKABLE

Device IDs, phone numbers, email addresses, and Meta matching technology may connect accounts.

READING PROTOCOL

Every finding carries one of three labels: confirmed requirement, analysis, or unresolved question. Citations point to the filed proposed consent judgment and the relevant technical or empirical sources.

01 / SCOPE BOUNDARY

Read the boundary before the panic.

The agreement covers Facebook, Instagram, and qualifying future social products. Direct messaging, WhatsApp, AI-first products or features, gaming, VR, and video editing are outside the defined product category.

Facebook + InstagramCoveredNamed Meta social-media platforms
Messenger + Instagram DirectProduct excludedParental tools can still expose messaging metadata
WhatsAppExcludedNot named; primary messaging services are outside scope
Meta AI + chatbotsExcludedExcluded when AI or chatbot use is the primary function
Gaming, VR, video editingExcludedExpress product-category carve-outs
Future Meta social productsConditionalCovered only if the settlement definition is met

Scope finding: The filed text leaves WhatsApp content and encryption outside scope. Facebook and Instagram messaging metadata can still reach parental tools. The harm is narrower, but real.

02 / THE CLASSIFICATION PERIMETER

Population-wide classification can become a KYC waterfall.

Every covered user enters the age-decision system, although ID verification is only one permitted method. Users who appear uncertain, suspicious, or incorrectly classified may face a demand for stronger proof.

01MANDATED

Put everyone in scope

Apply an age-assurance method to each covered Meta user in a settling state, adults included.

02PERMITTED

Collect or infer age signals

Possible inputs include ID checks, face estimates, Meta's own inference, commercial vendors, and Apple or Google age signals.

03MANDATED

Assign a legal-status bucket

Classify the account as teen or adult. The classification itself is durable even when raw proof is deleted.

04MANDATED

Resolve uncertainty downward

A flagged user may refuse another method; the account then receives teen restrictions. Refusing further proof produces the same treatment as a teen classification.

05MANDATED

Keep watching conduct

Posts, comments, actions, device links, and suspected circumvention can trigger reassessment or U13 review.

06MANDATED

Link the perimeter

Soft-matched accounts can share attempt limits and time limits. For supervised teens, a secondary profile can be disclosed to a parent.

A zero-knowledge proof can hide your birthday. It cannot make Meta forget which account asked, from which device and network, at what time, before which content load, after which appeal.

The Permissioned Web analysis

03 / PRIVACY CLAIMS UNDER LOAD

Test eight separate privacy properties.

A proof that reveals only “over 18” can still leave a linkable checkpoint record. The Office of the Privacy Commissioner of Canada says no age-assurance method is inherently privacy-preserving and warns against making age assurance the default condition for Internet access.

01

Data minimization

Does the system avoid collecting the ID, image, or exact birthday?

02

Confidentiality

Can outsiders or the service read what was collected?

03

Presentation unlinkability

Can two proof events be joined to the same person?

04

Issuer separation

Does the proof issuer learn which site or content was requested?

05

Service anonymity

Can the platform map the proof to an account, device, or legal identity?

06

Unobservability

Can anyone see that an age proof happened at all?

07

Purpose and retention

Can the signal be reused, logged, trained on, compelled, or kept?

08

Fairness and redress

Can ID-less, disabled, shared-device, or misclassified users get through and appeal?

OUR RULING

Cryptography narrows the disclosure. Meta still receives an eligibility event tied to an account, device, time, and network. Failed checks can trigger demands for stronger proof.

CANADA OPC

04 / FULL CROSS-EXAMINATION

Twenty questions the press release does not answer.

Open a file to see the governing text, our analysis, the remaining unknowns, and direct source links. “Critical” means a structural risk could have severe consequences; the actual outcome remains uncertain.

Lower direct riskSeriousCriticalEvidence gap
Q01Does the settlement reach WhatsApp, Meta AI, or end-to-end encryption?No direct encryption mandate. WhatsApp, direct-messaging features, and AI-first products are excluded; mixed Instagram and AI surfaces remain unresolved.lower
CONFIRMED

The covered Meta social-media platforms are Facebook and Instagram, plus qualifying future social products. Direct-message features such as Messenger and Instagram Direct are expressly excluded from that definition.

A service whose primary function is direct messaging is excluded, and WhatsApp is not named in the agreement. A future product or feature whose primary function is AI, chatbot use, or AI interaction is also excluded.

The agreement never orders a backdoor, key escrow, client-side scanning, or message-content decryption. Its express encryption rule protects age-assurance data in transit and at rest.

ANALYSIS

This is less intrusive than a scanning mandate. Meta can meet the messaging-related duties with account and interaction metadata; the agreement does not require access to message content.

For supervised teens, Meta must disclose messaging time, contact usernames, and usernames of reported accounts. It must also flag first contact with an adult and linked secondary accounts. Message content can remain encrypted while those relationships are exposed.

UNRESOLVED

The agreement does not explain hybrid surfaces, such as an AI companion embedded inside Instagram or a chatbot that directly shapes recommendations.

Q02Does this mean KYC for hundreds of millions of people?Every covered user must be age-classified. ID verification is one permitted method; a likely-circumvention finding triggers another method.critical
CONFIRMED

Within one year, Meta must apply an age-assurance method to every Meta social-media-platform user in a settling state, including adults.

Methods may be commercial or Meta-developed. The agreement specifically contemplates ID verification and facial age estimation and requires Meta to use reliable Apple or Google age signals.

When Meta thinks a previously adult-classified user circumvented the system, it must require another method. Refusal is allowed, but the user is then treated as a teen.

ANALYSIS

Traditional KYC verifies identity. Age assurance may instead estimate age or verify an age attribute, although an ID-based method can still reveal identity. The civil-liberties concern is that adult access depends on a machine-assigned status.

An adult flagged for likely circumvention may have to use another method, such as ID verification or a face-based check, to retain adult status.

UNRESOLVED

The fourteen-day rule for new, still-unassessed stated adults is internally confusing. The anti-circumvention refusal rule is clearer than the ordinary new-user rule.

Q03Will Meta deanonymize a teenager's alternate account to a parent?For supervised teens, the text creates a direct alternate-account outing channel.critical
CONFIRMED

Meta must improve soft matching with signals including device IDs, phone numbers, and email addresses. Age-assurance attempt limits and usage limits can be aggregated across matched accounts.

If a supervised teen creates or explicitly links a new secondary Meta account within Accounts Center, or Meta links the teen to a Soft-Matched Account, Meta must notify the supervising parent and provide a profile link.

There is no required teen veto, confidential-account exception, advance warning, or soft-match appeal before the disclosure.

ANALYSIS

For some LGBTQ+ youth, a second account controls who sees sensitive identity or support-seeking posts. The same risk may affect other users who compartmentalize sensitive speech, but the cited research here is specific to LGBTQ+ youth.

The review documents anonymity, restricted audiences, and multiple accounts as identity-management strategies for LGBTQ+ youth. It does not measure harm from this settlement's disclosure rule.

UNRESOLVED

Meta does not publish a settlement-specific accuracy threshold for soft matching or a remedy for an incorrect profile disclosure.

Q04Why may Meta retain children's data to train an age model?The settlement releases specified COPPA claims and permits retention of children's data for U13 detection and model development.serious
CONFIRMED

The settling attorneys general release certain COPPA-related claims tied to continued or future use of children's personal information solely to detect and remove under-13 users.

Meta may retain U13 data to develop, train, test, and measure its U13 model. That data cannot be used for advertising, marketing, or algorithmic optimization.

Age-assurance metadata may remain as long as needed to detect circumvention. The agreement's deletion terms do not cover a user's stated birth date, stated age, or teen/adult classification.

ANALYSIS

Deleting an age-assurance image does not erase the resulting age classification, which is outside the deletion terms. The agreement also permits U13 training data and circumvention metadata to be retained for specified purposes.

The purpose limits matter, but the public record does not show how Meta will enforce access controls or deletion across logs and backups.

UNRESOLVED

The agreement sets no fixed maximum for retaining U13 training data or circumvention metadata, and it specifies no model-unlearning process.

Q05What is the error rate for adults wrongly classified as minors?The settlement sets no comparable hard cap for that direction of error.critical
CONFIRMED

The agreement defines the “U18 False Positive Rate” as the share of actual 13- to 17-year-olds classified as 18 or older. Commercial-method caps are 10 percent for ages 16 to 17 and 3 percent for ages 13 to 15. Meta-developed-method caps are 14 and 7 percent in year one, then 10 and 5 percent in year two.

No parallel numerical limit appears for adults classified as minors. Meta must offer a clear and conspicuous appeal, decide it timely, and give the user a basis; the agreement sets no deadline, independent review, or interim-access rule.

Testing must include performance across diverse demographic groups, including disability. The agreement sets no public subgroup threshold or publication requirement.

ANALYSIS

The incentives are asymmetric: the settlement caps aggregate rates for minors classified as adults, but not the reverse. That may encourage Meta to classify uncertain users as minors or demand another check.

NIST found that prototype facial age-estimation accuracy was strongly influenced by algorithm, age, sex, region of birth, image quality, and interactions among those factors. It did not evaluate Meta's deployed system. An aggregate error rate can hide which users bear the errors.

UNRESOLVED

The agreement requires no public reporting of adult challenge or appeal outcomes, restoration time, abstentions, or intersectional error rates.

Q06Can lawful expression become evidence that someone is lying about age?Yes. The agreement allows conduct and expression to feed age and circumvention judgments.critical
CONFIRMED

For U13 enforcement, Meta must assess posts, comments, and other actions that may provide age evidence. Meta must also require another age-assurance method when conduct supports a finding of likely circumvention.

ANALYSIS

Because the signal set is unpublished, an ordinary post such as a school reference or birthday message could influence an age decision. The agreement does not say which speech signals Meta will use.

The agreement requires proactive monitoring and allows conduct to support a likely-circumvention finding. A user's speech can therefore help trigger another age check.

UNRESOLVED

The agreement does not publish the signal inventory, model weights, or decision threshold. Appeals must state a basis, but the text does not require disclosure of the evidence category.

Q07Can account matching produce guilt by association?Yes. Group membership and relationships can become risk evidence without proving individual wrongdoing.serious
CONFIRMED

Meta may classify an adult account as Potentially Suspicious based on interactions with other accounts; searches for, likes, saves, or other engagement with violating content; or membership in a community Meta removed for policy violations.

Meta must maintain measures designed to limit discoverability and prevent interactions between teen users and Potentially Suspicious Accounts. If a message thread is established, Meta must warn the teen.

ANALYSIS

Membership in a removed group does not establish why someone joined it. A journalist or support worker may share that network with an offender.

A group link should not carry weight forever or override evidence of individual conduct. The agreement gives the affected adult no way to contest the label.

UNRESOLVED

The agreement does not reveal whether one group membership is enough, how stale links decay, or how an adult discovers and appeals the label.

Q08What protects a teenager whose parent or guardian is unsafe?The agreement does not contain a hostile-home exception.critical
CONFIRMED

For a supervised teen, Meta must provide the parent or guardian with time-use data; usernames of social connections, message contacts, and reported users; alerts for repeated searches about suicide, self-harm, or eating disorders; first-time direct contact with each adult; notices about specified suspicious accounts; and links to secondary accounts.

Meta must try to ensure that the supervisor is an adult parent or guardian and does not supervise too many accounts. The agreement does not address abuse, coercive control, foster care, emancipation, rejection, or a confidential-support channel.

ANALYSIS

Protections must account for an unsafe supervisor. The same disclosures that help a supportive parent can reveal a teen's sexuality or gender identity, religion, disability, health concerns, contacts, or help-seeking to a hostile one.

Confidentiality can itself protect adolescents. American Academy of Pediatrics guidance describes it as essential to high-quality adolescent care and to young people's health-care experiences and outcomes.

UNRESOLVED

There is no teen-controlled override, alternative trusted adult, independent ombudsperson, or minimum-necessary disclosure rule.

Q09What happens if an age-assurance vendor is breached?The settlement requires security controls but sets no breach-response or recovery rules of its own.critical
CONFIRMED

Age-assurance data must be held only long enough to determine age and then queued for deletion; specified U13 and anti-circumvention data may be retained at the coarsest viable granularity. Data collected or transmitted by Meta or a vendor must be encrypted in transit and at rest. Each method requires annual accredited third-party testing.

The settlement adds no breach-notification deadline, public vendor inventory, or settlement-specific recovery and compensation process.

ANALYSIS

If a vendor links proof material to network, device, or transaction metadata, one breach could expose both identity and where the proof was used, creating identity-theft and outing risks.

A system may minimize collection while remaining linkable, identifiable, unfair, or hard to challenge. Each privacy claim needs separate testing.

NIST treats a biometric characteristic as non-secret and bars it as a single-factor authenticator. Revoking a stored template does not change the underlying face.

UNRESOLVED

It remains unclear whether Meta will disclose the vendors and ancillary systems that handle age-assurance data beyond the agreement's minimum.

Q10Will Meta block VPNs, Tor, or WireGuard, or use deep packet inspection?The settlement requires none of these measures. Its implementation could still burden VPN or Tor users.serious
CONFIRMED

The agreement requires advanced anti-spoofing, resistance to bypass, account linking, proactive behavior monitoring, vendor coordination, and investigation of circumvention. It never mentions VPNs, Tor, WireGuard, ASN blocking, or DPI.

WireGuard encrypts encapsulated packets and sends its protocol packets over UDP. The protocol itself does not determine how a tunnel endpoint routes or translates the inner packet toward Meta.

MaxMind's GeoIP Anonymous IP database exposes flags for anonymous VPNs, hosting providers, public proxies, Tor exit nodes, and other anonymous networks.

In a UK study of 11- to 17-year-olds commissioned by DSIT, 22 percent of child VPN users cited access to age-restricted services. The study did not test this settlement or US behavior.

ANALYSIS

Using an exit IP to assign jurisdiction could misclassify travelers and VPN users. Reconciling it against device or account history would require more data, while blocking known exits or demanding stronger proof would burden privacy-tool users.

In a conventional consumer VPN configuration, Meta sees the public address used by the VPN egress. Separate app or device telemetry could reveal more.

Blocking or challenging an address based on those database flags uses IP reputation rather than packet inspection.

A network intermediary normally can inspect HTTPS only by terminating and re-establishing TLS, usually after a trusted root is installed on the device; the settlement does not require that. Meta, as the application endpoint, can still read requests sent to its own services.

Distinguishing circumvention from ordinary travel or privacy-tool use may require more location, device, and account-history data.

UNRESOLVED

The agreement does not specify how Meta assigns a user to a state or handles travel, relocation, VPNs, Tor, and carrier-grade NAT.

Q11Does this create an intranet or splinternet?The network layer remains intact. Platform access may still vary by jurisdiction and age classification.serious
CONFIRMED

The obligations are formally limited to settling jurisdictions and disclaim a standard of care or precedent elsewhere. Yet compliance requires Meta to decide who is in those jurisdictions.

Stronger product terms and additional state payments are triggered if Snap, TikTok, YouTube, and qualifying entrants adopt substantively equivalent obligations. Meta calls the agreement a new industry standard.

ANALYSIS

The network can remain globally reachable while platform features and access windows depend on jurisdiction, age classification, and accepted proof.

Meta may apply one national baseline or build state-specific versions. A national baseline would extend the rules beyond settling states; state-specific versions would require more location-based enforcement.

The underlying network can remain open even when platforms gate features and access windows by jurisdiction.

UNRESOLVED

The agreement does not specify whether Meta will geofence by state, apply a national policy, or withdraw features in some places.

Q12Will the independent audit tell the public anything useful?The auditor can inspect extensive nonpublic evidence. The public receives an executive summary after Meta and the state committee review and comment.serious
CONFIRMED

Meta and a state committee of up to six attorney-general offices mutually select the auditor, and Meta pays. The auditor is entitled to reasonably relevant and sufficient nonprivileged data, systems, records, personnel, and internal communications.

Drafts, final reports, and related audit materials are treated as confidential to the extent permitted by law. Public executive summaries exclude nonpublic, proprietary, and confidential information; Meta and the state committee may review and comment on a draft.

The auditor's mandate covers implementation of the agreement's injunctive provisions; it excludes historical conduct and matters outside those provisions.

ANALYSIS

Independent inspection adds scrutiny beyond Meta's own certification, but the public summary may omit enough evidence to prevent outside replication or challenge.

UNRESOLVED

The filed agreement provides no public dataset, protected researcher-access channel, or right to inspect an unredacted report.

Q13Where is “nothing about us without us”?The agreement references teen input but gives teens no decision-making role.gap
CONFIRMED

The agreement references teen, parent, and expert input, internal user research, and feedback. Decision, oversight, and enforcement roles are assigned to Meta, the state attorneys general, the courts, and the mutually chosen auditor; the agreement assigns no role to youth.

The agreement guarantees no youth seat or vote, no designated disability or LGBTQ+ representation, and no public account of how youth input affected decisions.

ANALYSIS

Meaningful participation needs space, voice, audience, and influence. A compensated youth council should have a defined role in audits and parental-disclosure rules, with power to publish dissent and request independent review.

Participation should allow pseudonyms, accessible formats, and separation from advertising or model-training data. Text-based and asynchronous options would reduce access barriers; youth in unsafe homes also need a way to participate without alerting a parent.

UNRESOLVED

Youth governance remains voluntary because the agreement imposes no such requirement.

Q14Why are AI companions excluded when their risks are relational?The settlement defines coverage by product category and provides no separate rules for companion-chatbot interactions.gap
CONFIRMED

The definition of a future covered platform excludes products, services, or features whose primary function is AI. The agreement does not separately regulate companion-chatbot interactions.

The FTC opened a Section 6(b) study seeking information about companion-chatbot safety testing, data handling, advertising, and effects on children and teens.

ANALYSIS

Companion chatbots can simulate interpersonal relationships and prompt users, especially minors, to trust them without using a conventional feed. A functional test would cover sustained, personalized relational interaction regardless of product label.

A functional regime could require clear AI disclosure, controls over stored sensitive information, separate consent for training, export and deletion, and independent safety testing.

UNRESOLVED

The agreement does not say how the AI exclusion applies to a companion feature embedded in Facebook or Instagram.

Q15Does the settlement entrench Big Tech?Directly it binds Meta. As a template, it can become a regulatory moat.serious
CONFIRMED

Compliance requires age inference for every covered user, cross-account matching, annual third-party testing, demographic performance checks, OS and app-store age signals, appeals, and a five-year audit.

The agreement names Snap, TikTok, and YouTube as Core Industry Members. It defines a New SMP Entrant as a product that, for four consecutive months, has at least five million monthly active US teens and at least 30 minutes of average daily teen use. Meta must notify the states before a third-party product can be treated as an entrant.

ANALYSIS

Fixed compliance costs favor incumbents that already possess identity infrastructure and cross-product graphs. That disadvantages a privacy-minimizing rival: collecting less identity and social-graph data makes Meta-style soft matching harder.

A federated ActivityPub network need not have a single operator, age classifier, supervising-parent graph, or global clock. Copying this model could force each small server to become an identity processor, create a central credential issuer, push legal status across the protocol, or move enforcement to Apple and Google.

UNRESOLVED

The settlement does not explain how a decentralized protocol, client, and thousands of independent communities would be counted as one product if its framework becomes general law.

Q16Who watches years six through ten?After report five, enforcement rests with courts and state attorneys general; the standing independent auditor is gone.serious
CONFIRMED

Most substantive obligations last ten years. The auditor's term ends 120 days after the fifth final report, with reports covering annual periods.

Courts retain jurisdiction and the settling attorneys general retain enforcement power. The decree separately requires annual third-party testing of every age-assurance method throughout the agreement term, so that testing outlasts the auditor.

ANALYSIS

After the fifth report, no independent body has a recurring duty to inspect the full system. Courts and attorneys general can still enforce the decree, but they receive no substitute annual audit covering model changes, vendors, appeals, and new uses of age data.

UNRESOLVED

No successor monitor, public-interest observer, researcher-access mandate, or automatic extension after serious findings is specified.

Q17Does the decree measure harm reduction or process compliance?The decree counts operational outputs and rarely measures whether users became safer.serious
CONFIRMED

The decree sets numeric targets for one direction of age-classification error and for U13 removals. In at least 90 percent of qualifying English- and Spanish-language Potentially Harmful Reported Content cases, Meta must respond within six hours with its decision. Meta must also give the auditor data on what users do after productive-pause notices.

Other provisions require only “best efforts,” “continuous improvement,” recurring evaluation, or a design intended to reduce harm. For productive pauses, Meta is presumptively compliant if it runs and documents the required assessment, even when it explains why no recommended change was made.

ANALYSIS

The audit can verify that a prompt appeared and a report entered a queue. That does not show fewer unwanted contacts, faster recovery from wrongful restrictions, or continued confidential access to support.

Public reporting should cover unwanted-contact prevalence and recurrence; report and appeal latency; both directions of age error by subgroup; parental disclosures; lawful-content overblocking; penalties for VPN or Tor use; breaches; and service withdrawal.

UNRESOLVED

There is no independent longitudinal well-being endpoint, autonomy measure, false-outing metric, or disproportionate-impact threshold.

Q18Can affected users challenge the architecture?Users cannot sue simply to enforce this decree. A separate challenge needs a concrete injury, a valid cause of action, and conduct attributable to the state.serious
CONFIRMED

The settlement creates no private right of action. Enforcement belongs to the government parties and courts. Independent private and class claims are preserved.

Meta and the settling states waive their own constitutional challenges. Users were not parties and did not waive theirs.

The cited cases protect specific interests: McIntyre protects anonymous political pamphleteering; NAACP protects membership privacy; Brown recognizes minors' First Amendment rights; and Packingham invalidated a broad state ban on social-media access. Paxton upheld age verification for sites dominated by material legally unavailable to minors; ordinary social media was outside that holding.

ANALYSIS

A user who can show an ID or face-scan demand, denial of protected speech, wrongful minor classification, or parental disclosure has a firmer standing argument than someone alleging only future risk.

Court-ordered conduct presents a better state-action theory than a product choice Meta made on its own, but attribution under Section 1983 remains fact-specific.

UNRESOLVED

Counsel would need to assess three postures: intervention while entry remains pending, prospective relief against an enforcing official, or an as-applied challenge after a user is harmed. None is guaranteed; standing, causation, state action, sovereign immunity, and remedy differ by route.

Q19Does the settlement change the surveillance-advertising business model?The settlement restricts some uses of retained age data and adds a feed option. It adds no general ban on profiling for recommendations or advertising.gap
CONFIRMED

U13 model-training data and certain retained age-assurance metadata cannot be used for ad targeting, marketing, or algorithmic optimization.

Teen users must be offered and reminded about a chronological nonpersonalized feed. The agreement does not make it the default.

The agreement adds no general data-minimization rule for Meta's existing teen profiles or its recommendation and advertising systems.

ANALYSIS

The agreement caps some use and prompts breaks, but it does not remove the engagement incentive or prohibit profiling for recommendations.

A privacy-focused duty of care would make nonprofiling feeds the default; bar the use of sexuality, religion, disability, health, crisis disclosures, and inferred vulnerability for recommendation or ad selection; and let users disable personalization and erase its profile.

UNRESOLVED

Implementation data will have to show an actual reduction in profile-data collection or use beyond the addition of timers to the same optimization systems.

Q20Where is the independent research foundation Meta announced?It appears in Meta's announcement, not in the filed operative agreement.gap
CONFIRMED

Meta says the agreement will establish an independent social-media research foundation and share consented user data to study teen well-being.

The filed agreement does not mention a research foundation and contains no term defining its governance, authority, or access to data.

ANALYSIS

A press release does not disclose who appoints the foundation's board, which data it receives, how consent can be withdrawn, whether researchers may publish adverse findings, or whether young people share governing power.

UNRESOLVED

Meta may be referring to a separate or not-yet-published instrument; the public record identified here does not show one. Until that document is public, readers cannot verify the foundation's independence or data rules.

06 / VPN, TOR, WIREGUARD, DPI

A VPN block usually starts with IP reputation. DPI is unnecessary.

Meta can flag a known exit IP without recognizing the WireGuard protocol. The unanswered question is how Meta will handle ambiguous location: tolerate it, demand stronger proof, or apply the strictest jurisdiction more broadly.

VANTAGE POINT

Internet provider

Usually sees the user IP, the VPN endpoint, timing, size, and an encrypted tunnel. It does not see the inner WireGuard packet.

VANTAGE POINT

VPN operator

Can see the subscriber or source IP and the egress side of connections. What it records depends on the protocol and the provider's architecture and logs.

VANTAGE POINT

Meta

Sees the VPN exit IP plus its own account, cookie, device, app, and behavioral telemetry. It usually does not see the original IP or WireGuard payload.

DPI IS A DIFFERENT ARCHITECTURE

Full HTTPS inspection normally requires an on-path system to terminate and recreate TLS, often using a trusted root certificate on a managed endpoint. The settlement orders no such system. Its anti-spoofing and bypass-resistance clauses leave Meta to choose the implementation.

FOUR IMPLEMENTATION PATHS THE TEXT LEAVES OPEN
01Honor the exit location

Simple, but makes jurisdiction easy to change

02Flag or block known exits

No DPI required; harms Tor, travelers, workplaces, schools, and shared VPN exits

03Reconcile more signals

Adds device, store region, account history, GPS, SIM, billing, and behavioral surveillance

04Apply the strictest rules broadly

Reduces geolocation disputes by exporting a permissioned baseline to everyone

Distinguishing a child evading a rule from an adult protecting anonymity means accepting some uncertainty or demanding more evidence from the user.

07 / CYBER THREAT REGISTER

The age gate is a distributed identity perimeter.

The table models plausible failures; it does not claim they have occurred. The attack surface runs from proof issuers and vendor code through Meta's classifiers and account graph, then into revocation and appeals.

ThreatAttack surfaceHuman impact
01Vendor breach

ID, selfie, liveness, scores, retries, IP, device, callback logs

Identity theft, outing, extortion, and exposure of face data that cannot be reissued like a password

02False flag to KYC

Model uncertainty, demographic error, camera quality, atypical behavior

Adult account restricted, ID or face scan demanded, and access errors concentrated in particular groups

03Static linkability

Credential ID, public key, signature, timing, rare issuer or format

Sites correlate the same holder even when the credential reveals only “over 18”

04Unsafe supervisor

Alternate-account link, crisis search, contact graph, report metadata

Outing, retaliation, chilled help-seeking, coercive control

05VPN reputation collision

Shared exit, Tor list, hosting ASN, traveler or corporate network

Privacy users treated as evaders, forced proof, service denial

06Function creep

Age status joined to content, device, location, and social graph

Possible reuse for advertising, policing, immigration screening, health profiling, or identity investigations

07Issuer outage or capture

Wallet failure, revocation outage, signing-key theft, policy pressure

Access denial at scale, forged age status, or one issuer able to revoke access for an entire population

08SDK supply chain

Third-party camera or document component inside the app

Raw camera or document data copied, verifier telemetry exposed to the host app, or a compromised SDK exfiltrating proofs

08 / SAFETY FOR WHOM?

The threat model must include the home.

A parental tool designed around the ideal caregiver can become an outing or coercive-control tool in the worst household. Safety systems cannot define every parent as safe and every pseudonym as deception.

74%

of LGBTQ+ young people in a 2025 Trevor Project survey said they went online because connecting with others like them was difficult where they lived.

18,663 respondents recruited online. Descriptive association, not a causal or population estimate.
73%

said online spaces let them be completely themselves. A 26-study systematic review describes pseudonyms, audience controls, and multiple accounts as recurring identity-management tools.

Trevor Project survey plus Berger and colleagues' 2022 systematic review.

Neurodivergent access

A systematic review of autistic people's information and communication technology use found preliminary evidence that online communication can offer greater control and calm. Atypical communication should never count as automatic evidence of evasion.

OPEN SYSTEMATIC REVIEW
THE SETTLEMENT MAY DISCLOSE
  • Secondary-account profile links
  • People who message the teen
  • Social connections and reported users
  • Repeated self-harm or eating-disorder searches
  • First direct contact with each adult
A RIGHTS-PRESERVING SYSTEM NEEDS
  • Confidential health, identity, and crisis channels
  • A teen-controlled alternative trusted adult
  • Minimum-necessary and imminent-risk thresholds
  • Independent review before high-risk disclosure
  • Notice, veto, and appeal for account matching
For queer youth, the second account may be the first place they can tell the truth. In an unsafe home, confidentiality can be part of safeguarding.

10 / THE WATCHERS

Five years of independent audit inside a ten-year machine.

The auditor may inspect Meta's systems, data, documents, communications, and personnel. The public receives only an executive summary stripped of nonpublic, proprietary, and confidential material.

NOW

Proposed

Signed and filed, but subject to court approval. The obligations begin only after entry.

YEAR 1

Infrastructure

Population-wide age assurance, testing, classification, and initial product obligations phase in on their contractual clocks.

YEARS 1-5

Independent window

Meta and a committee of six attorneys general jointly choose the auditor, which Meta pays. The auditor submits confidential annual reports; the public receives filtered summaries.

YEARS 6-10

Oversight gap

Courts and attorneys general retain enforcement. Annual third-party testing of age methods continues after the independent auditor leaves.

END

No automatic public archive

Most duties expire after ten years, with no guaranteed public archive or continuing access for independent researchers.

Deep private visibility, shallow public reproducibility. Confidential reports can document defects that outsiders cannot verify from the public summaries. The summaries may omit subgroup data, and annual independent audits end after year five.

11 / THE REGULATORY MOAT

An incumbent's compliance stack can become everyone's admission price.

The settlement binds Meta alone. Its “industry-wide adoption” mechanism names major rivals and lets Meta notify attorneys general when a qualifying entrant crosses the agreement's thresholds. Compliance costs favor services with centralized identity graphs.

01

Fixed costs favor scale

A platform with billions of accounts can spread verification and compliance costs across far more users.

02

The incumbent flags entrants

Meta may notify the attorneys general when a product crosses the agreement's new-entrant thresholds. That gives Meta a formal role in the parity mechanism; enforcement remains with the states.

03

Apple and Google become chokepoints

Operating-system or app-store age signals may spare users repeated raw-ID checks, but they put eligibility in the hands of two mobile gatekeepers.

04

Federation fits badly

A decentralized service must either make each instance verify, trust a common issuer, carry age status across servers, push enforcement to clients, or geoblock. Every path changes the open protocol.

WHY “PERMISSIONED WEB” IS FAIR

Even without a legal-name check, the system must classify the account as teen or adult before unlocking the adult version of the service. The network remains connected, but access depends on a status credential.

12 / THE NON-DYSTOPIAN FORK

Duty of care without papers at the door.

Protect children by targeting dangerous features and the companies that operate them. Leave the identity of every person at the screen out of it.

01

Universal safety defaults

Default new accounts to a chronological, nonprofiling feed. Turn autoplay off and batch notifications. Stop infinite scroll after a finite set of posts and require a tap to continue. Route messages from unknown accounts to requests. Put privacy, mute, block, and report controls on the first settings screen. None of these defaults requires guessing a user's age.

02

Regulate the harmful feature

Target compulsive recommendation, mass contact, harassment, virality, dark patterns, grooming conduct, and sensitive-data targeting. Tie each duty to the feature or conduct that creates the risk, regardless of the user's inferred age.

03

Data minimization as safety

Collect less, retain it briefly, separate safety data from ads, prohibit cross-product reuse, preserve encryption, and publish a field-by-field inventory. Require a threat assessment comparing the safety system's identity and breach risks with the harm it addresses.

04

User-controlled feeds

Offer a persistent chronological feed, a nonprofiling feed, and feeds based only on topics the user selects. For each recommendation, show the signals that produced it and let the user disable them. Let users reset the profile and export preferences. Never personalize from crisis, religion, sexuality, disability, or health.

05

Ban manipulation directly

Prohibit asymmetric consent, repeated nagging, streak-loss pressure, guilt notifications, deceptive interfaces, and needless friction around deletion, privacy, and leaving. Write the duty around specific interface practices and test compliance against observed user behavior.

06

Outcome-based public audit

Publish both directions of age error, subgroup results, appeals, unwanted-contact prevalence, lawful-content suppression, disclosures to parents, breaches, and remediation. Oversight must last as long as the obligations.

07

Due process with deadlines

Give immediate notice and identify the evidence category. Require human review by a fixed deadline and allow an external appeal. Restore access after reversal, delete erroneous labels, and preserve export rights while the appeal is pending. The word “timely” sets no deadline.

08

Youth governing power

Create a compensated youth council with votes on audit questions, disclosure rules, major product changes, and research priorities. Include LGBTQ+, autistic, disabled, foster, homeless, rural, and religious-minority youth.

09

A hostile-home threat model

Never disclose alternate accounts, searches, group membership, health, religion, or identity by default. Let a teen choose a confidential-support mode or designate another trusted adult. Permit disclosure without consent only under a defined imminent-risk test, disclose the minimum facts needed, and provide an independent ombudsperson.

10

Protect federation and exit

Tier duties by systemic risk and resources. Provide open compliance tools. Ban most-favored-treatment clauses that make small rivals copy incumbent systems. Do not make age status portable across services, block VPNs, censor domains, or exclude noncompliant clients from app stores. Preserve pseudonyms, multiple accounts, interoperability, and local moderation.

11

Regulate AI companions by function

Require companions to disclose that they are artificial and prohibit dependency manipulation. Give users an ephemeral mode, controls over sensitive memory, separate consent for training, and export and deletion. Bar ads based on intimate disclosures and require independent crisis testing. Preserve access to companions that support communication or routine without using manipulative design.

TESTABLE RED LINES

Make “privacy-preserving” falsifiable.

  1. No gate for harmless content. Deploy safer defaults for everyone first.
  2. No ID or selfie as the sole route or sole appeal.
  3. No VPN, Tor, or proxy use as evidence of age or wrongdoing.
  4. No persistent age identifier shared across services.
  5. Delete raw and intermediate data, including logs, backups, and crash reports.
  6. Publish errors in both directions, subgroup results, abstentions, and appeal times.
  7. Provide independent human appeal with a fixed deadline and no loss while pending.
  8. Audit protocols, SDKs, vendors, verifier behavior, retention, and deletion.
  9. Build for unsafe homes, ID-less users, shared devices, disability, and pseudonyms.
  10. Give affected young people voting power over the system's design, including audit questions and disclosure rules.
A split cyberpunk city contrasts identity turnstiles with an open, interoperable digital commons.
THE CHOICE IS ARCHITECTURAL

Regulate the machine.
Minimize the data.
Preserve the pseudonym.
Audit the outcome.
Let users leave.

Never make safety synonymous with identification.

13 / SEND THE DEMAND

Nothing about us without us. No papers at the door.

Find your representative with a ZIP code, copy the letter, and deliver it through the member's official channel. This site has no submission database and receives none of the information entered here or on the House website.

PRIVATE HANDOFF

Find the House office that represents your ZIP.

The House publishes no central list of member email addresses; its locator links to each member's contact page. This form submits directly to that official locator. This site receives no ZIP, name, email address, street address, or message. A ZIP that crosses district lines may require more information on house.gov.

Opens house.gov in a new tab. The letter stays on your device.
OPEN THE HOUSE LOCATOR WITHOUT ENTERING A ZIP
CONSTITUENT LETTER / EDIT FREELY

Demand a Digital First Amendment.

Congressional offices often ask for a name and address to verify constituency. If you use an office contact form, those details go to that office under its own privacy policy. They never pass through The Permissioned Web.

14 / NAME THE SIGNAL

A cheap domain that can carry the project.

permissionedweb.org matches the project title and had a low registration price when checked. No domain has been purchased. Availability and retail pricing can change before checkout.

No registration record was found through authoritative RDAP at 22:32 UTC on 26 August 2026. Prices shown were Porkbun retail prices at research time and may exclude taxes or premium changes. Porkbun lists WHOIS privacy and DNSSEC support. This report recommends the .org; the .fyi had the lowest listed renewal price.

15 / SOURCE LEDGER

Primary text first. Inference labeled.

This same-day public-interest analysis maps possible harms without predicting that all will occur. It labels claims as settlement terms, Meta choices, technical possibilities, legal arguments, or empirical findings.

Primary record

Security and identity

Messaging and metadata

Youth rights and evidence

Law and constitutional rights

Alternative architecture

Civic action

Evidence standard

“Confirmed” means the filed text or an authoritative technical source says it. “Analysis” draws an inference from cited facts. “Unresolved” identifies a missing instrument, metric, method, or implementation choice.

Metadata discipline

The report distinguishes encrypted content from metadata and documented collection from possible inference. It does not allege that Meta has profiled any specific community described here.

Legal discipline

The report grades constitutional arguments by their support and unresolved questions. Whether a nonparty can sue depends on standing, state action, procedure, and the requested remedy.