What happens when the law meets the digital giants? I discussed this on “Un Giorno Speciale” on Radio Radio, as a guest of Alessio De Paolis. The starting point was the settlement with which Meta closed, in the United States, the lawsuit brought by twenty-nine States over the impact of social media on minors. From there, three knots worth untangling in order: why an agreement of this kind is not a conviction, why the United States and Europe follow opposite paths in protecting the young, and what changes with the arrival of artificial intelligence agents.
The settlement
At the end of August 2026, before the federal court in Oakland, Meta agreed to pay around 16.7 billion dollars (up to almost 18 billion should other platforms, such as TikTok and YouTube, also settle their cases) to close the litigation brought by twenty-nine state attorneys general. The allegations were three: having designed Facebook and Instagram so as to induce addiction in minors; having provided the public with misleading information about the safety of the platforms; and having collected minors’ personal data without parental consent, in breach of the federal law on children’s online privacy, the Children’s Online Privacy Protection Act. The agreement, reported among others by CNBC and NPR, provides for concrete measures to protect adolescents (daily usage caps, night-time blocks, parental controls and age-verification systems designed to exclude the under-13s) to be implemented over a decade.
One technical point should be fixed at the outset, because the word “ruling” is circulating improperly. This is an agreement of a transactional nature, reached while the trial was under way: it contains no admission of guilt and, indeed, Meta denies the allegations. The settlement closes the dispute; it does not establish liability. In terms familiar to an Italian lawyer, it is a negotiated resolution, not a conviction. The market’s reaction, with the share price up more than four per cent immediately after the announcement, helps to read the affair for what it is on the business level.
Not recidivism: a flaw upstream
The story fits a script we have seen before. Back in 2021 the data protection authority of the Republic of San Marino fined the companies of the Facebook group a total of five million euro, with decisions concerning the security measures against data exfiltration through scraping and the obligation to verify, for children under sixteen, that consent had been given by their parents.
A pattern that repeats itself invites an uncomfortable suspicion: that organisations of this size may factor the loss of certain disputes into their cost-benefit assessments. This is a matter of business risk in general: however aligned an organisation may be with regulatory compliance, business needs and objectives drive choices of this kind, and not only among the web giants. In our view, however, the point is not recidivism: it is, rather, a flaw upstream in the United States framework, which intervenes after the event has occurred. In Europe, and in Italy, with the AI Act, the Digital Omnibus and Law No 132 of 23 September 2025, the approach pursued is instead a preventive one. If history has repeated itself so far, a framework of this kind aims to ensure that, in theory, it should not repeat itself again.
Two models: the United States and Europe
These organisations work with data, and must come to terms with disciplines that differ profoundly across the world. The United States contests above all the issue of manipulation, increasingly felt at global level; on the legislative side the framework is still under construction, between the long-standing COPPA rules for the under-13s and the broader Kids Online Safety Act, passed by the House of Representatives on 29 June 2026 and now before the Senate, which would introduce a duty of care owed by platforms to minors and limits on the features that encourage compulsive use.
Europe moves from a preventive approach. Article 5 of the AI Act lists among the prohibited practices the use of artificial intelligence systems, or of tools incorporating their components, aimed at manipulating people’s free will and at exploiting the vulnerabilities of vulnerable groups, such as minors and the elderly; systems that interact with people or generate content are further subject to specific transparency obligations. On the platform side, the Digital Services Act and the European Commission’s guidelines on the protection of minors of 14 July 2025, together with the age-verification blueprint now in its pilot phase, shift the centre of gravity towards prevention. The underlying knot is the forcing: taking advantage of the unrestrained use, by vulnerable subjects, of a tool that should have purely recreational and connective purposes, which is the nature of the social network.
One limit remains, and it is technical before it is legal: years on, placing effective safeguards at the point where identity and age are verified remains a near-impossible operation. We wanted a free web and open platforms: this is the other side of the coin.
The frontier of artificial intelligence agents
The third knot looks ahead. Attention has moved from chatbots to agentic artificial intelligence, systems capable of carrying out tasks autonomously. The underlying question changes too: when the actor is a system operating on its own, who answers for the consequences.
In Europe the current answer runs through liability for defective products, now redesigned by Directive (EU) 2024/2853, which extends the rules to software and artificial intelligence systems: the manufacturer answers, even when it has no legal seat in Europe. One point, however, is settled as a matter of law: liability cannot be attributed to something that has no consciousness. Even the most autonomous agent remains a tool, an evolved calculator with no awareness of itself, supporting us in our daily activities. Liability, today, is therefore shared between whoever produced the artificial intelligence system and whoever uses it. This is the ground I had the opportunity to address, on the governance side, contributing to the volume “Agentic AI” edited by Nicola Fabiano, who in 2021, as president of the San Marino authority, signed the very decisions recalled above.
The precedent
One last aspect deserves attention. The United States operates in a common law context, in which judicial precedents guide subsequent decisions with a force comparable, simplifying to the extreme, to that of our codes. An agreement of this size therefore creates a precedent destined to carry weight: it is reasonable to expect the other digital platforms, from Google to TikTok to Snapchat, to align with this approach. TikTok, for that matter, has already been the subject of several inquiries by European supervisory authorities, together with the products of the Meta group. In Europe, alongside the AI Act, the field is covered by the Digital Services Act and by the rules on online markets and platforms.
Critical profiles
The affair condenses several tensions worth keeping distinct. The first concerns the effectiveness of protection: a financial agreement, however large, that establishes no liability risks turning into a predictable, and therefore plannable, cost rather than a deterrent; one should expect the conduct of organisations, when it comes to sanctions, to tend increasingly towards settlement rather than admission of guilt. The second concerns method: ex post intervention, typical of the United States model, arrives when the harm has already occurred, while the European framework bets on prevention, with the burden of proving that it holds in practice. The third is technical: without reliable age-verification systems, much of the protection remains stated rather than effective. The fourth is at the frontier: the growing autonomy of artificial intelligence agents pushes the problem of attribution forward, within a framework that today resolves it by sharing liability between producer and user.
Conclusions
The Meta settlement does not close a story; it photographs a phase. It delivers concrete measures to protect adolescents, a precedent that in the common law system is destined to guide analogous cases against the other platforms and, at the same time, confirmation that the United States model acts mainly downstream, once the event has already occurred. Europe has chosen the opposite path, that of the preventive rule, and over the coming years we will measure its capacity to hold up in practice, including with respect to the frontier of artificial intelligence agents, where the attribution of consequences still rests on the division between those who produce and those who use.
🎧 Listen to the full interview, in Italian, from 2:26:00: lnkd.in/e_jBKX4x
▶️ Watch the video of the segment (in Italian): youtube.com/watch?v=6ZHKb2PezrY
📰 Read the Radio Radio article (in Italian): Meta nei guai per la dipendenza dei minori
Cover image: Radio Radio
Author: Valentina Grazia Sapuppo




