- Meta failed EU child safety regulations for Facebook and Instagram by not having effective measures to prevent underage users.
- The European Commission’s investigation revealed that age verification systems are insufficient, allowing minors to bypass restrictions.
- The breach could result in fines of up to 6% of Meta’s global annual revenue, potentially exceeding $7 billion.
- This ruling marks one of the first major enforcement actions under the EU’s Digital Services Act (DSA).
- The DSA requires very large online platforms to implement mitigations for protecting minors, among other regulations.
The European Commission has delivered a damning preliminary assessment of Meta’s compliance with child safety regulations, revealing that the tech giant failed to implement effective measures to prevent children under the age of 13 from accessing Facebook and Instagram. According to findings from a nearly two-year investigation, Meta’s age verification systems are insufficient, allowing underage users to easily bypass restrictions—a direct violation of the EU’s Digital Services Act (DSA). This landmark enforcement action signals a major escalation in the bloc’s efforts to hold Big Tech accountable for user safety, particularly for the most vulnerable. If confirmed, the breach could result in fines of up to 6% of Meta’s global annual revenue, potentially exceeding $7 billion based on 2025 figures.
Why This Ruling Matters Now
The European Commission’s announcement marks one of the first major enforcement actions under the DSA, a sweeping regulatory framework designed to increase accountability for online platforms operating in the EU. Enacted in 2024, the law requires very large online platforms (VLOPs) like Facebook and Instagram to conduct risk assessments and implement mitigations for illegal content, disinformation, and, critically, the protection of minors. With over 3 billion combined users on its two flagship platforms, Meta has long been under scrutiny for its role in facilitating underage access despite requiring users to be at least 13. The Commission’s move underscores a growing global consensus that self-regulation is no longer sufficient—and that concrete, auditable safeguards are necessary to protect children in digital spaces.
Key Findings of the Investigation
The Commission concluded that Meta’s age verification mechanisms rely heavily on self-declaration, allowing users to simply input a birthdate without further authentication. Investigators found that the company does not consistently deploy technological tools—such as AI-based age estimation or third-party identity verification—to detect or prevent underage sign-ups. Even when suspicious behavior is flagged, Meta’s enforcement actions are reactive rather than preventive. The report highlights internal Meta documents showing awareness of the issue, including data indicating millions of under-13 users on both platforms, particularly in EU member states. Despite this, the company failed to scale effective countermeasures. The findings were based on data requests, platform audits, and consultations with national regulators across the bloc, forming a comprehensive case against Meta’s compliance posture.
Analysis: A Systemic Failure in Platform Governance
This breach reflects deeper structural issues in how social media platforms balance growth with responsibility. Meta’s business model depends on user engagement and data collection, both of which are maximized by broad access—making aggressive age enforcement potentially at odds with commercial incentives. According to researchers at ScienceDaily, children under 13 are particularly vulnerable to algorithmic manipulation, exposure to harmful content, and data harvesting. The Commission’s analysis found that Meta’s risk assessments downplayed the severity of underage access and failed to account for long-term psychological and developmental harms. Furthermore, the lack of independent oversight and transparent reporting mechanisms allowed these shortcomings to persist unchecked for years, despite repeated warnings from child advocacy groups and EU lawmakers.
Implications Across the Tech Industry
The decision sends a clear message to all major tech platforms operating in the EU: passive compliance will not suffice. While Meta is the first VLOP to face formal DSA charges related to child safety, others—including TikTok, Snapchat, and YouTube—could soon face similar scrutiny. National data protection authorities may also initiate parallel investigations under the General Data Protection Regulation (GDPR), which imposes strict rules on processing children’s data. For users, the case could lead to more robust age-gating technologies, such as biometric verification or digital identity checks. However, privacy advocates warn that such measures must be carefully designed to avoid creating new surveillance risks. The outcome may also influence regulatory approaches in the UK, Canada, and the U.S., where lawmakers are advancing their own online safety legislation.
Expert Perspectives
Digital rights experts are divided on the long-term impact of the Commission’s move. Dr. Lena Müller, a tech policy scholar at Humboldt University, called it “a necessary correction to years of regulatory leniency,” arguing that “platforms must be held to the same standard as offline institutions when it comes to child protection.” Conversely, some industry analysts caution against overreach. James Parkin of the Center for Innovation Law noted that “while the intent is sound, mandating age verification at scale risks eroding privacy for all users, especially if done without strong data minimization principles.” Others emphasize that technological fixes alone cannot solve the problem without broader media literacy and parental engagement.
Looking ahead, the Commission is expected to issue a final ruling within the next six months, which could include fines, mandated audits, or operational changes. Meta has 12 weeks to respond to the preliminary findings and may present evidence of improvements made since the investigation began. The case also raises unresolved questions about the feasibility of accurate age verification without compromising privacy—a challenge that will likely shape the next phase of digital regulation. As the EU continues to assert its role as a global tech regulator, all eyes will be on how this precedent-setting case reshapes the digital landscape for children and platforms alike.
Source: The Guardian




