Three experts on tech challenges & realities Meta faces in restricting kids’ platform access

As widely reported, here for example, Meta has agreed to pay $18 billion and sharply limit underage platform access to settle US lawsuits over children’s social media addiction to its platform. Three cybersecurity experts weigh in on some of the cybersecurity steps, missteps and implications involved in the governance that Meta is required to invoke, and that other social platforms may also be faced with.

Michael Bell, CEO and Founder, Suzu Labs:

“The settlement requires Meta to certify an age assurance AI within one year and have it tested annually. That is the right requirement. The problem is in how those systems get built. When you benchmark your safety AI against a competitor’s model by feeding it adversarial prompts through fake accounts, you are not learning how that model protects children. You are learning how it responds when it is being attacked. Those are different things. Research published in Nature shows that training on outputs from another model causes the student model to lose the rare-case knowledge, the edge-case judgment, that makes a safety system actually function. Child safety is almost entirely an edge-case problem. The auditor will be certifying a system that may have been developed by inheriting the blind spots of the models it was tested against, not by building independent safeguards. That is what the court needs to understand before it accepts Meta’s compliance reporting at face value.”

Yasir Zahid, Cybersecurity Leader, Founding Member, Secure.com 

The headline here is 18 billion dollars, but the real lesson for security leaders is about data governance. Regulators went after how children under 13 had their data collected and used, and how product design shaped that. That is a governance problem, not just a legal one. 

If your platform touches minors, you now have to prove age assurance works, prove default settings are safe, and prove what data you hold and why. An independent auditor will check Meta for ten years, so evidence has to be continuous, not a once a year snapshot. 

My advice is simple: Map where minor data lives, tighten consent controls to match COPPA and state privacy laws, and treat safety defaults as security controls you can test and demonstrate. If you cannot show your work, you carry the risk.

Ted Miracco, CEO, Approov on attestation issues of time limits for mobile app users:

“The mechanics of getting the time-limit guardrails right for teens on mobile platforms needs some planning and for most organizations, a clearer understanding of what’s involved, what’s needed and what’s challenging.

“Remember that in April 2026, the European Commission launched a white-label age verification app, built under a contract reported at roughly €2 million. It was billed as privacy-preserving: prove you’re over eighteen without handing a website your passport. Within days, researcher Paul Moore bypassed it. In July, after hardening and a re-release as version 2026.07-1, he bypassed it again — using Chrome extensions he says he built in minutes with an AI assistant.

“The second technique matters most. His extension detects the age verification QR code on a website and relays it to a remote, automated phone running the genuine app with a genuine credential. A real signature returns in seconds. Nothing is forged. He called it unfixable.

“I’d put it differently. This underscores that the security industry is largely built on the assumption that the user and the app owner are on the same side and the attacker is a third party. Age verification inverts that, as the user becomes the adversary. Almost none of our collective defensive playbook was designed for a world where the person you’re protecting is the person trying to get around you. Pretending otherwise is how you end up calling a relay attack unfixable instead of just predictable.

“When a privacy-preserving system fails publicly on a quarterly cadence, regulators won’t conclude that the goal was wrong. They’ll conclude the checks weren’t strict enough. Every bypass becomes an argument for something more invasive. Prove your age becomes prove your identity, and the privacy-first framing that justified the program may become the casualty of its own ineffectiveness.

“For anyone building or procuring these systems for mobile users such as teens: get the trust boundary right before buying any hardening. If security depends on the client behaving honestly, obfuscation buys time, not much of it, and not safety. Mobile app publishers need to fund attestation before cosmetics. And be honest about the remainder — attestation is necessary and insufficient, and anyone claiming it tells you who is holding the phone is selling the same client-side trust that just failed twice in four months.

I am calling it now. This will not deter Meta. Stricter enforcement is needed. Ideally by third parties. And more lawsuits are needed as Meta has proven that it will not change its behaviour on its own.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading