AI Policy Wiki
Dashboard

Inside My Advanced Topics Class 9.2: The Law That Kept Getting Blocked (Farahany, March 2026)

medium confidence · updated 2026-06-06

The middle class of Week 9 deep-dives the design code (UK Children's Code, CAADCA) and data minimization (COPPA 2.0) strategies, then takes seriously the case AGAINST new mandates: fraud theory, product-liability theory, transparency-plus-private-ordering. Anchored on the New Mexico v. Meta verdict (March 2026) and the LA bellwether KGM trial verdict — both delivered the same week as this class.

Author: Nita Farahany Source: https://nitafarahany.substack.com/p/the-law-that-kept-getting-blocked Published: March 24, 2026

This source is a write-up of the middle class of Week 9 in Nita Farahany's Advanced Topics in AI Law and Policy course (Class 9.2 of roughly 30). It examines two regulatory strategies for child online safety — design codes and data minimization — and then sets out the case that existing legal mechanisms, properly enforced, may accomplish much of what new statutes attempt. The class is framed around two jury verdicts delivered the same week: the New Mexico v. Meta verdict and the Los Angeles bellwether KGM trial verdict, both in March 2026.

Design-code and data-minimization strategies

The class deep-dives two approaches to regulating children's online experiences.

The design-code approach is examined through the UK Information Commissioner's Office Children's Code, in effect since September 2021, and the California Age-Appropriate Design Code Act (CAADCA). The UK code sets out 15 design standards, including a high-privacy default, no nudge techniques, no behavioral profiling without demonstrable need, geolocation off by default, and mandatory data minimization. It does not require age verification. Farahany describes its enforcement record as mixed: substantial paperwork compliance, but contested on whether product design has materially changed.

Farahany identifies CAADCA's mitigation requirement as the constitutional flashpoint distinguishing the two codes. The UK code mandates settings. CAADCA mandated settings plus a content judgment — a requirement to mitigate "potentially harmful content." The content-judgment requirement is what triggered strict-scrutiny First Amendment analysis. The lesson she draws is that settings-mandates are constitutionally easier to defend, while content-mitigation mandates are constitutionally hard.

The data-minimization approach is examined through COPPA 2.0, which Farahany restates as the theory that "if you can't ban dark patterns, ban the data collection that makes dark patterns effective." COPPA 2.0 would ban targeted ads to under-17s and replace the "actual knowledge" standard with "knowledge fairly implied." Critics including the Information Technology and Innovation Foundation (ITIF) argue the approach attacks the wrong layer and leaves engagement architecture untouched.

The case against new mandates

The class takes seriously the position that existing law, properly enforced, may be sufficient, and organizes it into three arguments.

The fraud theory holds that when platforms make misleading representations about safety while internal research documents harm, that conduct is a deceptive trade practice under FTC §5, requiring no new statute. Farahany anchors this on the New Mexico v. Meta verdict (March 2026), in which a jury found Meta violated the state Unfair Practices Act on two counts: concealment of child sexual exploitation and concealment of child mental-health harms. The jury also returned an "unconscionable trade practices" finding for unfairly exploiting children's vulnerabilities.

The product-liability theory holds that design choices such as infinite scroll, autoplay, and notification engineering are product decisions that may foreseeably harm users, and that some such claims survive Section 230 after Lemmon v. Snap. Farahany anchors this on the Los Angeles bellwether KGM/Meta verdict (March 2026), in which a jury found YouTube and Meta negligent in product design and found that negligence was a substantial factor in causing harm. She draws a tobacco-litigation analogy, noting that such litigation suggests timelines measured in decades.

The transparency-plus-private-ordering theory would mandate algorithmic-system disclosures and rely on parents, app stores, third-party tools, and researchers to act on them — described as the algorithmic equivalent of nutrition labeling. Farahany characterizes it as constitutionally favorable but dependent on motivated, informed actors.

Farahany's summary is that each approach has costs and benefits and none individually solves the problem. She argues the next generation of child-safety law will likely combine elements of multiple strategies, and that it will be drafted in the shadow of NetChoice II, the subject of Class 9.3.

Provenance

The source is a Substack essay by Nita Farahany published March 24, 2026, documenting one session of her Advanced Topics in AI Law and Policy course.

Relationships