Meta's $18B Deal Exposed: Why It Can Keep Children's Data to Train AI Age Verification

TL;DR
- Meta has agreed to an $18 billion settlement with 29 states to resolve lawsuits alleging it violated children's privacy and safety laws, but a key clause allows it to retain data from users under 13 instead of deleting it.
- That retained data will be used to train and test new AI-powered age-verification and age-estimation models, which Meta says are necessary to better detect and remove underage users from Instagram and Facebook.
- Privacy advocates and lawmakers are split on the deal, calling it a fundamental trade-off between improving child safety tools and creating a massive, sensitive dataset of children's faces, voices, and behavior.
The Settlement That Stunned Silicon Valley
Meta has reached a landmark $18 billion agreement with a coalition of 29 states to settle allegations that it knowingly failed to protect children on its platforms. Announced this week, the deal is one of the largest consumer protection settlements in tech history and aims to resolve claims that Instagram and Facebook violated the Children's Online Privacy Protection Act (COPPA) and state consumer protection laws by allowing children under 13 to create accounts and harvesting their data without verifiable parental consent.
The coalition, led by attorneys general from California, New York, Illinois, and Tennessee, had accused Meta of deploying addictive design features while lacking effective age-gating. Beyond the financial penalty, which will be paid out over several years, Meta has agreed to a sweeping set of product reforms, including stricter default privacy settings for teens, limits on algorithmic recommendations for minors, and independent audits of its child safety systems for the next five years.
But one provision buried in the settlement has drawn intense scrutiny from privacy experts and is now threatening to overshadow the entire agreement.
The Clause That Lets Meta Keep Children's Data
At the heart of the controversy is a carve-out that explicitly permits Meta to retain data it has already collected from accounts identified as belonging to children under 13.
Under normal COPPA enforcement, a company found to have illegally collected data from children would be required to delete it. This settlement does the opposite. Instead of purging the data, Meta is allowed to keep it in a siloed, internal system under the condition that it is used solely for developing and improving age-assurance technologies.
According to the settlement terms, this includes photos, videos, self-reported birthdates, behavioral signals, and account activity that can be used to train machine learning models to estimate a user's age. The data cannot be used for advertising, ad targeting, or for training general-purpose generative AI models, and Meta is barred from selling it or sharing it with third parties. The company must also de-identify the data where technically feasible and submit to annual third-party audits to verify compliance.
State negotiators who supported the clause argue it was a pragmatic necessity. Deleting the data, they contend, would destroy the very information needed to build better safeguards.
Why Meta Says It Needs The Data to Build Better Age Checks
Meta's core argument is that its current age-verification systems don't work well enough, and it needs real-world data from actual underage users to fix them.
For years, the company has relied on self-declared birthdays, a system easily bypassed by children entering a false date of birth. Its newer efforts have included AI tools that analyze signals like profile information, social connections, and even facial age-estimation technology that scans a selfie video to predict a user's age. However, those AI models have struggled with accuracy and accusations of bias, often misclassifying younger teens as adults and vice versa.
To train a more accurate model, you need a large, labeled dataset of confirmed children. Meta says the retained data provides exactly that — a ground-truth set of accounts already verified as belonging to under-13 users through internal investigations, parent reports, and moderator reviews. By feeding this data into its age-detection AI, the company claims it can teach the system to recognize subtle patterns in language, behavior, and appearance that distinguish a 12-year-old from a 16-year-old or an adult.
In a statement, Meta said the approach will allow it to "more quickly and accurately identify and remove underage accounts before they can be exposed to inappropriate content or contacts," calling it a critical investment in proactive child safety.
The Privacy Paradox: Safety vs. Surveillance
Critics say the solution creates a cure that is worse than the disease.
Child privacy advocates, including groups like Fairplay and the Electronic Frontier Foundation, have condemned the provision as a dangerous precedent. They argue the settlement effectively rewards Meta for its past violations by letting it convert illegally collected children's data into a valuable AI training asset. Creating a permanent repository of children's biometric and behavioral data, they warn, creates a high-value target for hackers and normalizes the idea that children's privacy can be traded for product development.
There are also concerns about function creep. While the settlement restricts how the data can be used today, advocates question what prevents Meta from lobbying to expand those uses in the future once the models are built. Others have raised questions about consent, noting that parents of the affected children were never asked if they wanted their child's data retained for AI training, even for safety purposes.
Legal experts are divided. Some see it as a necessary and forward-looking compromise that acknowledges deletion alone doesn't make kids safer online. Others argue it undermines the core principle of COPPA — that data from children under 13 should not be collected in the first place without explicit parental permission, and if it is, it must be destroyed.
What's Next for Meta and For Regulation
The settlement still requires final approval from a state court, and several details remain to be finalized, including the exact technical standards for de-identification and the scope of the independent audits.
If approved, Meta's new AI age-verification system is expected to roll out widely across Instagram, Facebook, and potentially WhatsApp within the next 12 to 18 months. The outcome will be closely watched in Washington, where Congress is debating the Kids Online Safety Act (KOSA) and updates to COPPA that would mandate stronger age-assurance for all major platforms.
For now, the $18 billion deal leaves the tech industry with a difficult and unresolved question: Is the best way to protect children's privacy in the future to hold onto the data that violated it in the past?
Get All The Latest Updates Delivered Straight To Your Inbox For Free!