Late one Thursday this week, a judge in New Mexico did something courts almost never do: he wrote a rulebook for Instagram. No overnight notifications for teenagers. Time limits for under-eighteens. Privacy on by default. And prove your age. The bill for Meta: nine hundred and forty-two million dollars.
But every rule is aimed at children specifically — and a platform can't see who is a child. So the moment you decide to treat kids differently, you have to inspect everyone, just to tell them apart. And a privacy law from 1998, written to protect children, makes inspecting the youngest ones illegal.
In March, a New Mexico jury found that Meta had knowingly built products that harmed children's mental health, and had hidden what it knew about the sexual exploitation of children on its platforms — "unconscionable" practices under the state's consumer-protection law. This week the price landed: nine hundred and forty-two million dollars, much of it to treat the young people already harmed.
Then the judge ordered Meta to redesign the app. But this is one ruling, in one state — and forty states are suing over the same harm, each in its own courtroom, with no national law to follow. So judges write the design one state at a time. And every one of them hits the same wall.
The argument everyone is having — should platforms verify your age, yes or no — is the wrong argument. It quietly assumes there is only one way to protect a child: first, figure out which users are children.
And that single assumption is where it goes sideways. To find the children in a crowd, you have to check the ID of everyone in the crowd. So the real question isn't whether to check harder — it's whether protecting kids has to mean a cage around all of us.
Think about what "verify your age" requires. A site can't see how old you are; to know you're not twelve, it must ask you to prove it — an ID, a face scan, a card. And it can't check only the children, because to single them out it would first have to know who the children are — the very thing it doesn't know. So it checks everyone.
That is the cage: an identity checkpoint on the front door of the internet. Anonymity ends, and every platform becomes a vault of IDs waiting to be breached. And here's the part that should give everyone pause — it doesn't even work. Australia banned under-sixteens from social media; three months in, more than eighty-five percent were still online. The government's answer was to double the fines. When a lock doesn't hold, the instinct is always a bigger lock.
Back to the judge, and the wall he hit. He could not order the check that matters most — is this user under thirteen? Because to check a child's age you first have to collect a child's data. And collecting a child's data is the exact thing a 1998 law forbids: COPPA, written to keep kids' information out of corporate hands.
Sit with that. A privacy law, written to protect children, now blocks the tool meant to protect them. And every one of those forty courtrooms hits the same wall — the slowest, most piecemeal way imaginable to regulate a product used by a hundred million people. Meanwhile the two designs that might actually escape the cage never get built, because nobody with the power to write them is writing them.
So what would escaping the cage look like? Two designs already exist. The first: stop asking how old people are, and make the product safe for everyone — no endless scroll, no autoplay, no 2 a.m. notifications, for anyone. If it's safe by default, you never need to know who's a child. The price: it treats every adult like a child too. California tried to write it in law; the parts that dictated design in detail were struck down as compelled speech — but the part that lets a platform skip age checks and just give everyone the safe settings survived. The one path that needs no cage is the one the Constitution allows.
The second escape: prove your age without revealing who you are. A zero-knowledge proof lets a trusted source vouch that you're over eighteen and hand the site one bit — yes or no. No name, no birthday, no document. Europe is piloting it; Google open-sourced the tools. It's the cage without the bars. But the price is real too: the EU app was hacked in April, the source that vouches for you can become a log of everywhere you go, and if you have no bank and no ID, no one can vouch for you at all.
It's easy to read a nine-hundred-and-forty-two-million-dollar ruling as one company finally getting caught. The harder, more useful story sits underneath: a society decided to protect children online and discovered it had never chosen how — so the job fell to juries and judges, improvising in the dark, blocked by a privacy law older than these platforms, reaching by default for the one tool everyone already argues about.
There may be good reasons to build that checkpoint. But it is a choice, and its price is everyone's anonymity — and it is not the only design on the table. So next time someone says the answer is simply to verify age, the useful question isn't yes or no. It's: whose design is this, who wrote it — and does keeping one child safe really require caging the rest of us?
Not who's to blame — how it's built. The full interactive blueprint, with the parts that didn't fit the video, lives on this page. По-русски →
Watch on YouTube Subscribe