In addition to paying out up to $18 billion and adding child safety measures , Meta’s settlement agreement with attorneys general from 29 states includes an interesting provision: the states have agreed not to sue Meta under existing child safety laws over its retention and use of children’s data.

That permission is being granted for the limited purpose of training and testing Meta’s age-assurance model and includes guardrails, but it’s a curious policy decision to make in a case centered on child safety, and one that could be difficult to properly enforce.

As specified in the settlement agreement, Meta must develop, train, and begin testing a model designed to detect which users on Meta’s platforms are under the age of 13. This must be done within a year of the document’s effective date. (While the agreement doesn’t specify that the model has to be AI-based, Meta’s current age-detection tools are powered by AI technology.)

Under U.S. child safety law, COPPA (the Children’s Online Privacy Protection Act), typically requires that websites and apps limit the collection and retention of children’s personal information. Meta’s settlement agreement says that Meta shouldn’t need to violate COPPA to train or implement its age-assurance models. However, the agreement also says that the state AGs have agreed “fully, finally, and forever” not to bring any past, present or future COPPA claims — or claims under similar state laws — related to Meta’s use of children’s data.

The agreement makes clear that Meta can’t use data from users under age 13 for ad targeting, marketing, or algorithmic optimization.

Meta’s request for legal protection, and the state AGs’ willingness to grant it, isn’t unreasonable, says Philip N. Yannella, a partner at law firm Blank Rome and co-chair of its Privacy, Security & Data Protection practice. “These kinds of data minimization guardrails are pretty typical for privacy compliance: e.g., verifying compliance with deletion requests,” he said, though he noted a caveat: COPPA is a federal law primarily enforced by the FTC, not the states, so it’s unclear whether the FTC, which isn’t a party to this settlement, has separately agreed to the same compromise.

It can be difficult for companies to keep data technically and organizationally isolated from the rest of their systems. Yet Meta is being asked to do just that — to isolate its understanding of children’s behavior signals and other data and use it solely for detecting and removing under-13 users. Fortunately, an independent auditor will be involved in monitoring Meta’s compliance with the settlement so we don’t only have to rely on Meta’s word.

Policing this limitation could be complicated. The data could hypothetically feed into other Meta systems over time, or could raise questions over whether the data, signals, or insights derived from it are being used elsewhere within the company. What’s not clear from the agreement is what data Meta will retain for training the model, how much behavioral information that may include, or how long it will retain the data. We also don’t know how these models will change in the future as Meta meets the settlement’s terms.

Barring state AGs from raising COPPA or similar state-law claims over this use of children’s data in the future could complicate the legal avenues states can pursue if questions arise around how Meta is using the data.

That doesn’t prevent them from pursuing legal claims, notes Joshua Wurtzel , a partner at Schlam Stone & Dolan LLP. “If Meta uses the data outside those lines, the release and covenant not to sue don’t apply,” he said. But those legal disputes could still be complicated, since they’d hinge on whether Meta’s use of the data fell within the settlement’s terms.

Peter Jackson, a Data & IP attorney at Greenberg Glusker LLP, agrees, saying the carve-out here could “disincentivize future enforcement actions.”

“The Settlement Agreement’s age-assurance measures bear all the hallmarks of a heavy, and perhaps hasty, negotiation,” he says.

The decision also touches on a broader question that’s been coming up across the AI industry lately, especially as more AI agents are being developed to help consumers with various tasks. The systems often require significant access to users’ personal data to work well. Similarly, Meta may need deep insight into children’s use of social media use in order to identify which accounts belong to young people.