Should design patterns make platforms liable for harmful content?
In August 2026, Meta agreed to pay roughly $17 to $18 billion to settle a lawsuit brought by a coalition of 51 attorneys general, alleging the company built features into Instagram and Facebook that drove compulsive use among children and teens. The settlement's actual remedies are telling: a default two-hour daily time limit for teens, a default nighttime usage block, stronger age verification, and an independent auditor with reporting rights directly to the states. Almost none of it is about content. All of it is about design.
That's not an accident, and it's not really about what the drafters of the lawsuit thought was most harmful. It's largely a function of a 1996 law that predates the entire industry being sued, and it's worth being precise about what that law does and doesn't explain, because the imprecision in how these cases get discussed publicly is itself doing damage.
Why lawsuits focus on features rather than content
Section 230 of the Communications Decency Act protects platforms from being treated as the publisher or speaker of content posted by someone else. For decades, that shield killed almost any lawsuit arguing a platform let harmful content stay up or algorithmically surfaced something dangerous. So plaintiffs' lawyers pivoted their theory. Instead of arguing that a platform published bad content, the more recent lawsuits argue that platforms are products, and that features like infinite scroll, autoplay, and the absence of default time limits are defects in that product, no different in principle from faulty brakes in a car. That reframing is a deliberate legal strategy for getting around a liability shield that otherwise blocks content-based claims entirely.
Courts haven't uniformly accepted that reframing. Take the same infinite scroll, autoplay, and notification system and pair them with a feed of nothing but recipe videos or nature documentaries, and there's no lawsuit, because nobody develops a compulsive relationship with a slideshow of casseroles. The mechanism only becomes a legal problem once specific content is running through it, which raises a real question about how cleanly "design" and "content" can be separated in practice. A federal appellate court reached a similar conclusion in Patterson v. Meta, a case brought after the Buffalo mass shooting, where the majority rejected the design-defect framing outright, noting that the plaintiffs could not plausibly claim the shooter would have acted the same way had he "become addicted to anodyne content, such as cooking tutorials or cat videos." The court read the claim as ultimately about content, not design, and Section 230 applied. Contrast that with Lemmon v. Snap, where a lawsuit over a speed filter that allegedly incentivized reckless driving succeeded, because the harm there genuinely didn't depend on what any user posted. The filter itself was the mechanism, independent of content.
That distinction explains why the Meta settlement's remedies look the way they do. Default time limits, nighttime blocks, and age verification target the category of harm that is most plausibly content-independent: features that would drive compulsive use even if the content itself were harmless. The harder legal territory, whether an algorithm that disproportionately surfaces self-harm or eating-disorder content to at-risk teens can be regulated without running into Section 230's protection for editorial and recommendation decisions, remains far less settled, and mostly wasn't what this particular settlement resolved.
The rule this strategy is quietly working around
It helps to know why Section 230 exists in the first place, because the design-versus-content workaround runs into the exact problem the law was built to prevent. Before 230, a mid-1990s case held that an online service which chose to moderate its message boards for content, in an effort to keep them family-friendly, had thereby taken on the legal exposure of a publisher, and could be sued for anything its moderators missed. The incentive that created was backwards: platforms that tried to clean things up ended up more exposed than platforms that didn't moderate at all. Section 230 fixed that by making clear that moderating content doesn't turn a platform into the publisher of everything it fails to catch.
There's a second, less visible piece of what 230 does: it lets platforms get meritless lawsuits dismissed early, before discovery and trial, which are where the real costs of litigation live. Winning a case after months of depositions and document production is still expensive even in victory. Getting a case thrown out before any of that starts is a different order of magnitude cheaper. A lawsuit framed around "product design" tends to survive that early dismissal stage far more often than one framed around third-party content, which means the design-versus-content workaround isn't just opening a new category of liability, it's also removing the off-ramp that used to end weak claims before they became expensive ones. It lets platforms focus on what actually matters: Safety.
The dollar figures understate the actual cost
It's worth being honest about why the public reaction to Meta's legal troubles has been mostly celebratory: Meta is an easy company to root against, and a defendant nobody likes is exactly the condition under which courts and juries are most willing to accept an expansive new theory of liability, one that then doesn't stay confined to the company it was built for.
Look at what the underlying jury verdicts actually paid out, separate from the AG settlement. A California jury in March 2026 found Meta and YouTube liable for designing addictive products and awarded a combined $6 million, about $4.2 million from Meta and $1.8 million from YouTube. Around the same time, a New Mexico jury ordered Meta to pay $375 million over allegations it enabled child exploitation on its platforms. Against tens of billions of dollars in quarterly revenue, those numbers are close to noise. But the trials that produced them ran six and seven weeks, with extensive discovery, depositions of senior executives, and enormous volumes of internal documents entered into evidence. Meta and Google can fund that kind of defense without much strain. Most companies can't, which means the actual deterrent effect of these cases isn't really the verdict amount, it's the process required to reach one, win or lose.
That's also why this legal theory won't stay limited to the handful of giants people are currently frustrated with. A recommendation algorithm, a notification system, a comment section sorted newest-first, a chat app's read receipts: under the same reasoning being applied to Meta, all of these qualify as "design choices" that could theoretically support a similar claim. A small forum or a mid-size app facing the same discovery timeline and deposition schedule as Meta doesn't have Meta's resources to absorb it, regardless of how the case would ultimately be decided on the merits.
That's not a reason to discount the harms other users experienced. It is a reason to be skeptical of the assumption that "the company will adjust its product to reduce liability" is a cost-free outcome. When a platform responds to legal exposure by dialing back recommendation systems or discovery features across the board, every user feels that change, not just the ones whose case drove it, and the users who relied on exactly those features for something good rarely make it into the story explaining why the product changed.
Being a parent doesn't make someone a policy expert
One habit worth naming directly, because it shows up constantly in coverage of these cases: a parent whose child was harmed is treated, in interviews and in courtroom testimony alike, as though their personal experience also qualifies them to prescribe how content moderation or recommendation algorithms should be regulated industry-wide.
Those two things are not the same, and the difference matters. A parent has every right to sue over a specific, concrete harm done to their own child, and their account of what happened is real evidence about that case. But standing to bring a claim about a personal injury is different from expertise in engineering, adolescent psychology, or internet law, and a platform-wide regulatory prescription built primarily from one family's story, however tragic, is a different kind of claim than "here is what happened to my daughter." Treating "I am a parent" as sufficient credentialing to weigh in on how an algorithm should be designed is a bit like treating "I am a cancer patient" as sufficient credentialing to redesign FDA drug-approval methodology. The lived experience is real and worth taking seriously as testimony about harm. It isn't a substitute for the separate, harder question of what a workable regulation or ranking-system design should actually look like at the scale of a platform used by billions of people with wildly different needs.
This matters for how these cases get decided, too, not just how they get discussed. Juries and the public respond to a sympathetic, specific story more readily than to an abstract argument about system design, which is part of why individual testimony ends up doing outsized legal work relative to how much it can actually establish about a platform-wide defect.
The cigarette comparison doesn't hold up
A comparison shows up constantly in coverage of these lawsuits: social media is "the new cigarettes," and platforms are said to be doing to teenagers today what tobacco companies did decades ago. It's a rhetorically powerful comparison. It's also a poor empirical fit, and the numbers say why.
A landmark comparative study on dependence found that around 32 percent of people who try nicotine even once go on to become long-term, habitual users. For alcohol, marijuana, and cocaine, that rate is roughly 15 percent. For heroin, it's around 23 percent. Cigarettes cause cancer and other serious harm in the large majority of people who smoke regularly, largely regardless of what else is happening in that person's life. That's what makes nicotine dependence a pharmacological property of the substance: it acts on the brain's reward system in a way that doesn't much care about the user's prior mental health, home environment, or trauma history.
Compare that to social media. The World Health Organization's most recent international survey, covering roughly 280,000 adolescents across 44 countries, found that about 1 in 10 qualify as "problematic" social media users under a nine-symptom disorder scale, with real regional variation and a strong concentration among adolescents already dealing with low parental monitoring, existing mental health struggles, or poor school performance. In other words: the overwhelming majority of people who use social media do not develop anything resembling an addiction to it, and the minority who do skew heavily toward people who were already vulnerable before they opened the app. That's a structurally different harm profile than nicotine, where the substance itself is the active ingredient in the harm regardless of the user's starting point. Calling both "addiction" collapses two very different mechanisms into one word, and one of them is a comparison plaintiffs' lawyers and advocates reach for because it's viscerally effective, not because the underlying epidemiology matches.
The causation problem this creates showed up directly in the first bellwether social media trial to reach a jury verdict, involving a plaintiff, identified as KGM, who began using YouTube at age 6 and Instagram at age 9 and testified that her social media use contributed to depression, self-harm, and body dysmorphic disorder. Her suffering was real. It's also true, as legal scholar Eric Goldman noted in his analysis of the verdict, that her life included other documented sources of trauma, and there was some evidence social media had also helped her cope with it. The jury wasn't asked whether social media was the cause of her harm, only whether it was "a substantial factor," a standard loose enough that it's genuinely difficult to know what the verdict is actually saying about the product, versus about a sympathetic plaintiff with a complicated life.
Caution here doesn't require opposing accountability
None of this is an argument against Section 230, or a case that platforms shouldn't answer for genuine deception or genuine statutory violations, which is what the Meta settlement's underlying allegations actually claim. It's an observation that the specific legal theory being used to route around 230 carries costs worth naming, even for someone who wants real accountability to happen.
Some of that cost is already visible in how the current cases have played out. Internal company emails in which employees raised safety concerns and debated tradeoffs were presented in court as evidence the companies knew about a risk and proceeded anyway. That's a reasonable inference in some circumstances, but as a standing incentive, it teaches every company watching that the safest move is to stop having those conversations in writing, which produces less internal scrutiny of safety risks, not more. In a related New Mexico case, prosecutors pointed to Meta's 2023 decision to add end-to-end encryption to Messenger as evidence the company had made it harder to detect predators, since encrypted messages are harder for law enforcement to access. Applied broadly, that reasoning treats a privacy and security upgrade, one that protects billions of people from stalkers, data breaches, and surveillance, as evidence of negligence. That's a bad incentive if the actual goal is safer products going forward, not just accountability for the past.
Call each harm by its name
None of this requires taking a side on whether Meta deserved to lose, or whether its product decisions were reckless. It's a case for describing what's actually going on with more precision than the current discourse tends to allow, on three specific fronts.
First, design harms and content harms are not one issue, even when a press release or a news segment presents them that way. A feature that makes a product habit-forming regardless of what's on it is a different claim, with different evidence, than an algorithm surfacing dangerous content to a vulnerable person, or a platform failing to prevent child exploitation.
Second, a parent's account of what happened to their own child is real and worth taking seriously as testimony, but it isn't the same thing as expertise in how a regulation or a ranking algorithm should be built, and treating the two as interchangeable lets emotionally powerful individual stories stand in for the harder, more technical argument that platform-wide policy actually requires.
Third, the comparison to cigarettes imports a model of harm, chemical, near-universal, largely independent of the user's circumstances, that doesn't match what the actual prevalence numbers show about social media, where the negative outcomes concentrate heavily among people who were already vulnerable rather than occurring at anything like the rate nicotine produces dependence in first-time users.
None of that means nothing is wrong, or that nobody was harmed, or that companies shouldn't answer for genuine deception or genuine statutory violations. It means the strongest, most defensible claims, the ones about verifiable deception, verifiable statutory violations, and content-independent design choices, are better served by being described precisely than by being folded into a single undifferentiated narrative of harm. Sloppy language doesn't just risk being unfair to a defendant. It produces legal theories broad and vague enough to eventually catch small platforms, beneficial privacy features, and ordinary editorial choices in the same net meant for the specific, provable problems, which is a bad outcome regardless of how someone feels about Meta.