California moves child safety into the design of AI, social media and schools
California has enacted a broad package of laws addressing companion chatbots, addictive social-media features, age-verification signals, targeted advertising, children’s data, digital wellness and AI-generated child sexual exploitation material.
What it could improve
The package places duties at several points in the digital ecosystem. Companion-chatbot providers face crisis protocols, parental controls, independent child-safety audits and annual risk assessments. Social-media services face restrictions on autoplay and history-based algorithmic feeds for users under 16, while additional measures address targeted advertising, pupil data, school-issued technology and digital-wellness education.
What remains unresolved
A broad package can distribute responsibility more effectively, but implementation across separate laws, services and technical layers may still produce fragmented protection.
- Age-verification signals can reduce repeated discovery of a child’s age only if their technical and privacy standards are interoperable, secure and limited to necessary information.
- Independent audits need common outcome measures, meaningful transparency and safeguards against conflicts of interest.
- Protections attached to one application, account or school device may not continue when a child changes services, devices or connection environments.
- Parental controls can support families but should not transfer the primary burden of managing foreseeable service risks back to parents.
- Restrictions should distinguish developmental needs and evolving autonomy rather than treating every person under 18 as requiring identical controls.
- State-level rules can lead nationally, but children and services operate across borders; compatibility with wider US and international approaches will matter.
The Child-Friendly Internet perspective
California’s package is one of the clearest current examples of responsibility moving into product design, AI governance, education and data practice. Its age-signal provisions are especially relevant to a Child-Friendly Internet, provided they communicate child context without creating a reusable identity trail.
- Translate separate statutory duties into a coherent child-centred architecture spanning devices, networks, services and schools.
- Use privacy-preserving assurance that shares only the age or developmental information needed for a particular safeguard.
- Require age-appropriate defaults, wellbeing protections and independent evidence of effectiveness—not merely policy statements.
- Design safeguards to evolve with children’s capabilities and preserve beneficial access, participation and autonomy.
The central question
Can California’s separate safeguards operate as one coherent child-friendly environment without repeatedly identifying the child?
