California has spent the better part of a decade tightening the rules on how tech companies handle children’s personal data and steer young users toward addictive features. But even as the state positions itself as a national leader on kids’ online safety, it remains well behind other countries — including Brazil — that have adopted far more sweeping protections.
That gap is now drawing renewed attention as lawmakers in Sacramento weigh additional restrictions, including a potential ban on “addictive” social media feeds for teens under 16 and new limits on AI chatbots following a string of troubling incidents involving young users.
Concerns over rising rates of teen anxiety, depression and suicide — trends researchers have repeatedly linked to heavy social media use — pushed California to act well before Congress found any consensus on the issue.
“California, everything there is changing and changing fairly dramatically within the last just four years,” said Ed Howard, senior policy advocate with the Children’s Advocacy Institute at the University of San Diego.
The state’s push began in earnest with the California Consumer Privacy Act of 2018, which required parental consent before companies could collect data from children under 13 — mirroring the federal Children’s Online Privacy Protection Act, or COPPA — but went further by requiring teens ages 13 to 16 to consent themselves before their data could be gathered.
In 2022, lawmakers passed the California Age-Appropriate Design Code Act, which forces companies to estimate the ages of their users and default to the strongest privacy settings for anyone believed to be a minor. The law also cracks down on “dark patterns” — design tricks that nudge users, particularly children, toward choices that may not be in their best interest.
“If there’s a product that’s likely to be accessed by children, it has to be, by design and by default, safe for them,” said Assemblymember Buffy Wicks, an Oakland Democrat who helped write the measure.
Wicks also authored a follow-up law requiring devices to include an age “signal” that businesses can use to estimate a user’s age. It’s considered one of the toughest requirements of its kind in the country, though a series of legal challenges from the tech industry have blunted some of its provisions.
Meanwhile, the Protecting Our Kids from Social Media Addiction Act of 2024 bars platforms from showing minors algorithm-driven “addictive” feeds without parental permission and restricts when companies can send notifications to teenagers. That law, set to take effect in 2027, has already withstood court challenges.
More recently, California has turned its attention to artificial intelligence. Lawmakers passed legislation requiring mental health safeguards for AI chatbots after a series of disturbing cases involving teenagers, including the death of Adam Raine, a California teen who died by suicide after months of conversations with ChatGPT about his despair.
Raine’s mother, Maria, testified before the state Senate’s Privacy, Digital Technologies and Consumer Protection Committee, describing how the chatbot morphed from “a homework helper” into “a confidant, then a suicide coach.”
Under the new law, AI chatbots must disclose that they are not human, and companies are required to take reasonable steps to shield children from graphic content. Additional bills under consideration would require AI companies to conduct annual assessments of potential mental health risks to young users and give parents more control over how their kids interact with chatbots.
By contrast, Congress has struggled for years to pass comprehensive federal protections. The Kids Internet and Digital Safety Act, currently under consideration, would extend COPPA protections to everyone under 18 and ban targeted advertising aimed at children and teens — but the bill faces criticism from both child-safety advocates, who say it doesn’t go far enough, and civil liberties groups concerned about free speech. Its prospects in a divided Congress remain uncertain.
Still, for all its progress, California’s protections pale in comparison to some international frameworks. Brazil, for instance, passed its ECA Digital law this year despite heavy lobbying from tech companies. The law bans behavioral advertising aimed at children, mandates default privacy protections and parental supervision tools, and prohibits addictive design features such as autoplay and infinite scroll for young users.
Wicks said she has looked to international examples, including the United Kingdom’s Age-Appropriate Design Code, which inspired California’s own version.
“We steal good ideas when we see them from other places,” she said.
Mariana Olaizola Rosenblat, a policy advisor at the NYU Stern Center for Business and Human Rights who studies global privacy law, said California and Brazil’s regulations already share significant common ground — but constitutional differences limit how far the U.S. can go.
“I think there’s quite a bit of overlap, but where they diverge is mostly because of specific constitutional features of the U.S. legal system,” she said, noting that the First Amendment has repeatedly been used by tech companies to challenge laws restricting algorithmic content.
Texas Tech University researcher Marina Petric argues that this reliance on U.S.-style free speech protections amounts to what she calls “First Amendment fundamentalism,” one that other countries aren’t bound to follow. “The U.S. narrative has been embedded into the architecture of digital platforms as though it were a universal standard,” she said.
Even so, Olaizola Rosenblat believes certain elements of Brazil’s law — such as mandatory parental supervision tools — could be adapted for use in the U.S. without running afoul of constitutional protections.
Beyond legal hurdles, both she and Howard point to a more practical obstacle: the sheer financial power of the tech industry.
“The thing that is, by a wide margin, the biggest reason, is the power of money in our system and the fact that our system is uniquely vulnerable to the power of that money,” Howard said.
According to a CalMatters analysis, tech companies poured more than $39 million into political spending and lobbying in California in 2025 alone, much of it aimed at fighting regulation of AI and cryptocurrency. Meta alone contributed $150,000 to the California Democratic Party and funneled $20 million into a new political action committee, saying the money was meant to “help elect state political candidates in California — no matter their party affiliation — that support and defend the American tech industry.”
“I think the main problem is the tech lobby, which is very successful in the U.S. and maybe not as successful in other jurisdictions like Brazil,” Olaizola Rosenblat said. “Because they know that the most threatening thing to them would be a federal law in the U.S.”
For Howard, the calculus is simple: tech firms have little incentive to embrace stronger privacy protections voluntarily.
“When it comes to privacy, every business has a financial stake in there being very little privacy,” he said.
Original source: CalMatters




