top of page

$375 Million. One verdict. Are years of reckoning, finally arriving?

Updated: Apr 7

From New Mexico to Global Regulation: Shifting Expectations of Platform Responsibility


By Anna Hayes & Kirra Pendergast


A Turning Point in Online Safety


Seven and a half hours. That’s all it took for twelve ordinary people to unveil what decades of legal abstraction, lobbying, and child online safety spin had worked hard to keep hidden. Even more alarming is that this fog was not just maintained by platforms and policymakers. It was supported by a wider culture of reassurance. This culture often translates a structural crisis into the comforting language of parental controls and digital resilience. Too often, what is marketed as education is merely industry-friendly sedation for adults while children bear the risk.


Image

There’s a strange atmosphere in a courtroom when a jury returns after a short deliberation. In this case, seven and a half hours is brief enough to evoke confusion and anxiety. It signals the closing of a door on something that can no longer be argued away.


New Mexico just closed that door on Meta.


The jury found the company liable for misleading users about the safety of its platforms and for endangering children. They imposed the maximum penalty available: US$5,000 per violation, totalling US$375 million. After this verdict, the jurors returned to their families, having done in seven and a half hours what regulators, legislators, and advocates had struggled to achieve for nearly two decades. Twelve ordinary people examined the evidence and reached a conclusion that the most powerful technology company in the world had spent years insisting was impossible.


They knew. The machine knew. And knowing, it chose to do nothing.


More Than Just a Verdict


This story isn’t just about one overdue verdict. It would be convenient for Meta and the industry to frame this as an isolated incident—one ambitious state attorney general, one rogue jury, one newsworthy moment. But that framing is misleading.


This verdict comes amid a Los Angeles trial where Meta and YouTube are accused of intentionally designing addictive features that harmed a young woman's mental health. This case is one of three bellwether trials selected because their outcomes will shape the trajectory of thousands of lawsuits still winding through the American legal system. Thousands. Not dozens. Thousands of families. Thousands of children. Thousands of documented harms.


The New Mexico case was built on a foundation that the tech industry has spent decades trying to obscure: the damage done to children online is not accidental. It is, in critical and documented ways, a foreseeable outcome of deliberate design.


The state's attorneys put the product itself on trial. Features like infinite scroll, autoplay video, and encrypted messaging were presented to the public as innovations—user empowerment, connection, joy, love, and the inevitable march of progress. Yet, in a court of law, they were challenged as instruments of harm, built into platforms that executives knew were being used to exploit children at scale. Meanwhile, the man behind every crack in US law sails the globe on a yacht the size of a small island, all while internal documents shown to the jury estimated that at least 100,000 children receive sexually abusive content from adults on Facebook and Instagram every single day.


Not every month. Every day. A number so vast and specific that it collapses the word "accidental" entirely. You cannot stumble into harm that you have quantified.


Meta's own head of content policy, Monika Bickert, warned in writing, "We are about to do a bad thing as a company. This is so irresponsible." She cautioned that encryption would blind the platform to child exploitation, to terrorist planning, and to the very categories of harm that the company was publicly promising to combat.


Meta proceeded anyway.


This isn’t negligence in the ordinary sense. It’s a decision, made with knowledge and documented evidence, to accept foreseeable harm in pursuit of a strategic objective.


The Global Shift in Regulation


The EU's Digital Services Act clearly states that platforms must consider how design choices, including algorithmic systems and interface structures, can exploit minors' vulnerabilities. The UK's Age Appropriate Design Code echoes this sentiment. Australia’s Online Safety Act places this obligation squarely on the service provider—not the user, not the child, not the parent reaching for their phone at midnight, wondering where their teenager has gone.


The regulatory architecture of the developed world is moving steadily toward one conclusion: if you build a system, you are responsible for what that system does. Not what you intended. Not what you advertised. What it does.


New Mexico's jury just wrote that conclusion into a US$375 million cheque. Not nearly enough, but it’s a start.


Does this mean the Section 230 shield is finally cracking? We live in hope!


For twenty-nine years, Section 230 of the Communications Decency Act has been the invisible wall behind which American tech companies have sheltered. Designed in a time when the internet was young and the stakes were relatively modest, this law states that platforms are not publishers and cannot be held liable for what their users post.


In its time, this was a reasonable idea to protect a fledgling spoke in the US economic wheel. Now, it’s something else entirely.


The New Mexico judge rejected Meta's Section 230 defence—not on the question of content, but on the question of conduct. The state was not suing Meta for what users posted. It was suing for what Meta built, what Meta chose, what Meta knew, and what Meta continued to deploy after that knowledge was documented and ignored. This means the legal question is no longer whether a platform hosts harmful content. It’s whether the platform's systems—its algorithms, its design, its defaults, its business model—created conditions where harm was not just possible but predictable.


This is precisely the analytical framework that regulators worldwide have been building toward. The DSA's systemic risk assessment obligations, the UK Online Safety Act's duty of care, and Australia's Safety by Design principles all ask the same foundational question that the New Mexico jury asked in seven and a half hours: Did you know? Did you design it anyway? Did you profit while it happened?


Section 230 was never designed to answer those questions in the platform's favour. It was created for a different internet, with different stakes, and different children. Children who, in 1996, were not spending six, eight, or ten hours a day inside algorithmically optimised systems built to capture their attention at any developmental cost.


The Corporate Crisis Communication Gap


A phrase that recurs in corporate crisis communications is, "We take the safety of our users, especially young people, very seriously." This positions the company as a force for good, responding to challenges it did not anticipate and does not welcome. They frame harm as something that arrives from outside—from bad actors, from an unruly internet, from the inherent complexity of scale.


Meta's spokesperson, when the New Mexico lawsuit was first filed in 2023, claimed the company used "sophisticated technology," hired "child safety experts," and worked with law enforcement "to help root out predators." That statement now sits in the trial record alongside the internal estimate of 100,000 children harmed daily, the content policy chief's warning that the company was "about to do a bad thing," and evidence from the attorney general's undercover investigation. This investigation revealed that accounts posing as children under 14 were quickly sent sexually explicit material and contacted by adults seeking more. The gap between public statements and private knowledge is not a gap; it’s a canyon. The New Mexico verdict has illuminated every inch of it.


This matters beyond Meta. It matters for every platform currently reviewing its legal exposure, calibrating its public language, and deciding whether to invest meaningfully in child safety or continue investing in the appearance of child safety while managing litigation risk on the other side of the spreadsheet. The cost of that calculation has just changed dramatically.


The Global Landscape of Child Online Safety


New Mexico did not happen in isolation. It occurred at a time when the international regulatory architecture for child online safety has reached a critical mass.


Australia has passed a Social Media Age Delay law, making it one of the strictest in the world regarding restricting platform access for children under 16. The EU's Digital Services Act now requires very large online platforms to conduct systemic risk assessments that explicitly cover risks to children—including addictive design, algorithmic harm, and the exploitation of minors' inexperience. The UK's Online Safety Act imposes a duty of care that is enforceable, auditable, and backed by the power to fine companies up to 10% of their global annual turnover. Ofcom is not waiting.


Across the Middle East, South Asia, and Latin America, child-focused digital regulation is accelerating. The UAE is developing a child-centred model that distributes responsibility across platforms, service providers, and caregivers. Brazil's LGPD contains specific child protections, while South Africa's POPIA treats children as a special category deserving heightened safeguards.


The direction of travel is unmistakable. The speed is accelerating.


Big Tech has operated for thirty years under a different standard than every other product on earth. Not because the harm was smaller, but because it was, in many cases, vastly larger and more pervasive. However, because the harm was mediated by screens and networks, because Section 230 provided legal cover, and because the platforms were culturally new, the law moved slowly. The children most affected were, in the language of engagement metrics, also the users most valuable to retain.


That era is ending. The New Mexico verdict is one marker of its end. The European enforcement actions are another. The Australian legislation is yet another. The thousands of lawsuits in American courts are another. The senators who have testified about algorithms connecting children with predators are another.


The Meta machine knew. For years, in documented memos, risk assessments, and internal research reports, the machine knew. The question that every regulator, lawyer, board member, and trust and safety professional must now answer is not whether platforms caused harm to children.


The Path Forward: Three Obligations


The path from here—for platforms, regulators, compliance professionals, and trust and safety teams—runs directly through three obligations that are no longer optional.


1. Safety by Design Must Be Structural, Not Cosmetic.


The era of safety teams as reputational insurance is over. Safety must be embedded in product architecture, in the design review process, in pre-launch risk assessments, and in the default settings that every child encounters before they ever choose anything themselves. The UK Age Appropriate Design Code made this a legal standard. The DSA made systemic risk assessment a legal requirement. And the New Mexico jury just made the consequences of cosmetic safety a US$375 million lesson.


2. Governance Must Be Honest About What It Knows.


The most damning aspect of the New Mexico trial was not what the company did. It was what it knew. Internal documentation of harm, warnings from senior employees, and estimates of scale all existed alongside public statements that said the opposite. That gap is a governance failure of the most fundamental kind. Boards must demand honest risk reporting. Executives must insist on honest product safety assessments. The systems that allow internal knowledge to be quarantined from public accountability must be treated, from this day forward, as the legal liability they have always been.


3. Children Must Be Treated as Rights Holders, Not Engagement Metrics.


Every major international framework—from the UN Convention on the Rights of the Child to the EU Charter of Fundamental Rights—recognises children as rights holders with specific and elevated protections. Design choices that treat children's developmental vulnerabilities as features to be exploited rather than risks to be mitigated are not just ethically wrong. They are, as the New Mexico jury confirmed, legally actionable.


The New Mexico verdict is a turning point in the global accountability arc for platform harm to children. For platforms, regulators, investors, and compliance and trust & safety professionals building the systems of the next decade... the moment to act was years ago. The second-best moment is now.

 
 
 

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page