Author: Nita Farahany Source: https://nitafarahany.substack.com/p/what-the-law-is-trying-to-do-about Published: March 22, 2026
This essay is the eighth class of the third week's third segment (Class 8.3 of roughly 30) in Nita Farahany's Advanced Topics in AI Law and Policy course, published March 22, 2026. It closes Week 8 by mapping three contemporary laws to three competing theories of the consent problem and the remedy each theory implies, and previews the Ninth Circuit's NetChoice II ruling of March 12, 2026, which Farahany frames as determining which of the approaches survives First Amendment review.
Three theories of the consent problem
Farahany organizes the class around three diagnoses of why consent fails and the remedy each diagnosis implies. The information-failure account treats the problem as inadequate disclosure and prescribes better disclosure, the approach Farahany associates with GDPR and CCPA. The capacity-failure account treats some users as unable to give legally meaningful consent and prescribes categorical protection of those vulnerable users, the approach she associates with COPPA. The design-failure account treats the surrounding environment as the problem and prescribes regulating that environment itself, the approach she associates with CAADCA. Each of the three laws examined in the class is presented as an instance of one of these theories.
California DELETE Act (information theory)
The first law, the California DELETE Act, was signed in 2023 with enforcement beginning in 2026. It establishes a universal opt-out under which a single request to the California Privacy Protection Agency propagates to every registered data broker, roughly 500 in California, and brokers must comply within 45 days. Farahany characterizes the law as solving the exercise-of-existing-rights problem rather than the consent-at-collection problem. From the design-theory standpoint developed later in the class, she frames the critique as making exit cheaper without making entry meaningful.
COPPA and FTC age-verification policy (capacity theory)
The second law is COPPA together with the FTC's age-verification policy, comprising the January 2025 final rule and a February 2026 policy statement. The capacity premise is that children under 13 cannot give legally meaningful consent and that parents must consent on their behalf. Farahany notes that COPPA's "actual knowledge" standard creates an incentive to know less, and that FTC v. Epic ($275M, 2022) reached a "should have known" result through Section 5 of the FTC Act.
The class describes an age-verification trap: state laws require age verification, verification requires collecting data from children, and COPPA prohibits collecting data from children without parental consent. The February 2026 FTC policy statement responds with prosecutorial-discretion non-enforcement of COPPA against age-verification systems that delete data promptly, which Farahany characterizes as a pragmatic patch on a structural conflict rather than a fix.
California Age-Appropriate Design Code Act (design theory)
The third law is the California Age-Appropriate Design Code Act (CAADCA, 2022), which Farahany presents as a design-theory law that tells platforms what to build rather than what to say. Its provisions include a data protection impact assessment (DPIA) requirement, age estimation, default high-privacy settings, "best interests" content judgments, and penalties of $7,500 per intentional violation per child. NetChoice's First Amendment challenge argues that the law compels platforms to exercise content judgment and therefore compels editorial speech.
In the Ninth Circuit's NetChoice II ruling of March 12, 2026, the court blocked the DPIA, data-use, and dark-patterns provisions on vagueness grounds while allowing the coverage definition and the age-estimation requirement (with opt-out) to proceed. Farahany describes the mixed result as setting a template for future child-safety drafting.
The constitutional through-line
Farahany draws a constitutional pattern across the three laws: those that regulate settings, defaults, and enumerated data practices tend to survive, while those that delegate content judgment to platforms under vague standards and severe penalties tend to fail. She concludes that the design-theory approach is constitutionally permissible, but only when drafted with a specificity that the original CAADCA did not provide.
Relationships
- part-of: Nita Farahany Advanced Topics course (Class 8.3 of ~30)
- related: Coppa (planned), California Delete Act (planned)
- previous: Inside My Advanced Topics Class 8.2: The Environment Is the Argument (Farahany, March 2026) next: Inside My Advanced Topics Class 9.1: The Senate Just Agreed On Something (Farahany, March 2026)