Get the latest insights, product updates, and news from Permission — shaping the future of user-owned data and AI innovation.
The floodgates are open.
Thousands of lawsuits are moving forward. States are writing new rules for kids online. And lawmakers are beginning to tell AI companies what they can and cannot do when children use their products.
And you don't have to look far to see it happening...
The courts: 3,000+ lawsuits get the green light
On August 10, the Ninth Circuit allowed more than 3,000 lawsuits against Meta, Google/YouTube, TikTok and Snap to move forward.
The cases allege that the companies deliberately designed features of their platforms to be addictive, particularly for young users.
The tech companies had argued that Section 230 of the Communications Decency Act protected them from the claims. The court rejected their attempt to use Section 230 to stop the litigation at this stage, finding that it provides a defense rather than immunity from being sued.
At their core, these cases are allegations about the platforms themselves: how they were designed, how they kept people engaged, and what responsibility the companies bear for the consequences.
The companies will still have the opportunity to defend themselves against those allegations.
But with more than 3,000 cases now getting the chance to be heard, this is getting harder to argue away.
New Jersey: families get a way to enforce the rules
One day later, New Jersey Governor Mikie Sherrill signed the New Jersey Kids Code Act into law.
The law establishes new design and privacy requirements for covered online services likely to be accessed by minors. Among other provisions, it requires high privacy settings by default, restricts certain push notifications, prohibits dark patterns for minors, limits how children's personal data can be used and retained, and places restrictions on targeted advertising.
But one provision in particular changes the accountability equation: a private right of action.
An individual under 18 who is injured by a violation can bring a claim under the law, with statutory damages of $5,000 per violation. Parents may also bring an action on a minor's behalf.
Which is legal language for something pretty simple: families don't have to wait around for a regulator to act. They can take companies to court themselves.
Colorado: AI safety starts becoming a legal requirement
Then there's Colorado.
Earlier this year, Governor Jared Polis signed Colorado HB 26-1263, establishing specific requirements for operators of conversational AI services.
And this one is worth paying attention to because the law doesn't simply tell AI companies to "keep kids safe." It starts defining what that actually means.
Operators must estimate users' ages. When dealing with minors, the law requires recurring disclosures that they are interacting with AI rather than a person and establishes protections around sexually explicit interactions.
It also addresses one of the most unsettling questions surrounding companion-style AI: emotional dependence.
The law requires safeguards designed to prevent conversational AI from producing statements that simulate emotional dependence. It also requires protocols for responding to suicidal ideation and self-harm, privacy and account-management tools for minors and parents or guardians, and reporting requirements intended to help regulators evaluate whether those safeguards are actually working.
The law takes effect January 1, 2027.
For companies building conversational AI, that's a meaningful shift. Child safety is moving beyond a set of voluntary guardrails companies write for themselves. In Colorado, some of those guardrails are becoming law.
It's no coincidence that this is all happening at once.
Big Tobacco didn't wake up one morning and discover the world had changed its mind. The reckoning came piece by piece, until lawsuits became regulation and an industry that had spent decades setting its own standards was finally forced to take responsibility for the harm its products caused.
We're watching that shift happen again.
For years, the responsibility for keeping kids safe online has fallen on parents.
Set the parental controls. Check the privacy settings. Watch the screen time. Know which apps they're using. Figure out who they're talking to. Keep up with every new platform, algorithm and now AI chatbot entering their lives.
All while the technology on the other side of the screen gets more sophisticated by the month.
Now courts and lawmakers are starting to ask the companies building that technology a much more uncomfortable question:
If children are using your products, what are you doing to keep them safe?
For families, that's the shift that matters most.
This isn't another round of false promises to "do better."
This is legislation. These are lawsuits. This is accountability beginning to have teeth.
Parents will always have the role of protecting their children online. We happen to believe they should have far more visibility and control over the technology entering their families' lives, not less.
But parents cannot be the entire safety system.
The law is making clear that the companies designing the products, writing the algorithms and building the AI our kids interact with have a responsibility, too.
And when they fail to meet it, they'll finally be held accountable.

.avif)