Meta's $16.68 billion child safety settlement is a D&O and tech benchmark

29 states, a $1.4 trillion exposure ceiling, and a settlement reached mid-trial. The number boards of any company with children's data obligations should be comparing their policy limits against

Meta's $16.68 billion child safety settlement is a D&O and tech  benchmark

Professional Risks

By

Meta has agreed to pay up to $16.68 billion (all figures in US dollars) to settle a lawsuit brought by a coalition of 29 state attorneys general alleging the company engineered Facebook and Instagram to be addictive to children, misrepresented the platforms' mental health harms, and unlawfully collected personal data from minors without parental consent.

The settlement, filed in court Wednesday, calls for Meta to pay approximately 7% upfront with the remainder structured over time. As part of a proposed consent judgment, Meta must introduce daily usage limits and nighttime blocks for teenage users, stronger age-verification measures to keep children off its platforms, and expanded parental control tools. Meta denied any wrongdoing.

The case was heard before US District Judge Yvonne Gonzalez Rogers in Oakland and co-led by California Attorney General Rob Bonta alongside attorneys general from Colorado, New Jersey and Kentucky, representing all 29 states. The four lead states pursued additional consumer protection claims under their own state laws, while all 29 states brought federal claims alleging violations of the Children's Online Privacy Protection Act, which prohibits platforms from collecting data on minors without parental consent.

Mark Rowland, chief executive at the UK's Mental Health Foundation, welcomed the changes but said they shouldn't stop at American users.

"We are pleased to see Meta making these changes in America, and now they must be implemented worldwide," Rowland said. "There is a significant and growing body of evidence showing how social media can harm people's mental health."

Rowland said the settlement's daily usage limits reflect the kind of change needed across the industry more broadly, not just at Meta.

"Changes like introducing daily usage limits are the exact sort of improvements social media platforms need to introduce to reduce the risk of addictive behaviours developing among users," Rowland said. "Other social media platforms that target young people, such as TikTok and X, should also introduce these measures to protect users' mental health."

The settlement came during the trial's second week, following testimony from Instagram head Adam Mosseri. Meta founder and CEO Mark Zuckerberg had been expected to testify before the case settled. Meta shares rose approximately 5% in premarket trading on the news - a market response that underscores how investors viewed a negotiated settlement as materially preferable to an open-ended jury verdict.

The exposure that was on the table

The gap between what Meta agreed to pay and what it could have faced is the number that matters most for risk managers and boards reading this settlement. Ahead of trial, Meta's own court filings put the ceiling on possible penalties at roughly $1.4 trillion. The states argued a more realistic figure was closer to $200 billion. The $16.68 billion settlement represents approximately 1.2% of the states' own estimate of exposure and less than a rounding error of Meta's theoretical maximum liability.

That arithmetic is not unique to Meta. In New Mexico, a separate state-level action produced a jury verdict of $375 million against Meta in March 2026, followed by an August court order directing Meta to pay an additional $567 million into an abatement fund for treatment and prevention programs - a combined New Mexico liability of approximately $942 million that arrived before the federal settlement.

The case is one of more than 3,000 lawsuits against Meta and other social media companies consolidated before Judge Gonzalez Rogers. Meta, Snap, YouTube parent Alphabet, and TikTok parent ByteDance continue to face thousands of pending cases. A separate case against Meta in Nashville has been at trial since July.

What this settlement establishes for D&O programs

For insurance brokers and risk managers, the settlement establishes a concrete liability benchmark where previously only theoretical exposure existed.

The legal theory underlying the case - that company leadership knew the platforms caused harm to children, designed engagement features with that knowledge, and misrepresented the extent of those harms to regulators and the public - is a D&O liability framework, not just a consumer protection one. It goes to whether boards adequately governed the company's product design decisions, whether material information about those products was accurately disclosed, and whether the governance structures in place were adequate given what leadership knew. That is the same analytical framework D&O underwriters apply when assessing the adequacy of limits for technology and platform companies with significant user populations.

For any company that processes data from children or teenagers - not just social media platforms - the $16.68 billion settlement resets the reference point for what a regulatory enforcement action at scale looks like. COPPA applies to websites and online services directed at children under 13, but state consumer protection laws that formed part of this action extend to practices affecting older teenagers, and the age-verification obligations in the consent judgment extend to users across Meta's platforms more broadly. Any company whose digital product reaches minors and whose board has not specifically reviewed its COPPA compliance, its data governance practices for younger users, and whether its D&O limits reflect this category of exposure has an open question that this settlement makes harder to defer.

The cyber and technology E&O dimension

The case was explicitly argued on grounds that Meta engineered specific product features - algorithmic recommendations, infinite scroll, notification systems, social comparison mechanics - to maximise engagement at the expense of user welfare. That framing maps directly onto the technology errors and omissions question of whether a product was designed with adequate care for its reasonably foreseeable users.

For brokers placing cyber and technology E&O programs for companies with user-facing digital products, the settlement is a concrete argument for reviewing whether current policy language addresses product design liability - the liability that arises not from a data breach or a system failure, but from a product working exactly as designed in ways that cause harm to users. The distinction between cyber coverage (which typically responds to security failures and data breaches) and technology E&O (which addresses the design and performance of technology products) is the specific wording question this case puts in focus. A company whose technology E&O policy was written narrowly around system failure and whose cyber policy was written around data security events may find a product design liability claim sits between the two.

The advice obligation that follows

The $16.68 billion settlement does not require any broker to take immediate action on an existing program. What it does is provide the most concrete available evidence of what the liability scale looks like when a major technology company's product governance and children's data practices are litigated to a settlement in federal court. For brokers whose clients include technology companies, digital platforms, media companies, or any business with significant data obligations toward minor users, that evidence is the basis for a renewal conversation about whether current D&O, cyber and technology E&O programs reflect the documented and now-quantified exposure this category of risk can produce.

Keep up with the latest news and events

Join our mailing list, it’s free!