New York’s finalized rules for the SAFE for Kids Act are now on the books, but as social media companies prepare for compliance, researchers and child advocacy groups say the real test is still ahead and some say the law’s language leaves room for confusion.
The Stop Addictive Feeds Exploitation for Kids Act, signed nearly two years ago, will require platforms to shut off algorithm-driven feeds for users under 18 unless a parent consents. The law takes effect in January 2027, giving companies a runway to build out age-verification systems, a process experts say is more complicated than it sounds.
“The law basically requires that addictive social media platforms don’t show addictive targeted algorithmic feeds to minor users unless they get parental consent,” said Ariel Fox Johnson of Common Sense Media, one of the groups that pushed for the law.
The intent, Johnson said, is to interrupt the kind of algorithmic drift that can pull young users into harmful content loops.
“Sometimes, teens might be looking up information about exercise, and they get taken down rabbit holes to more about weight and body image and go into negative spaces,” she said.
But translating that intent into enforceable rules is where some experts see trouble.
Corinne Jones, an assistant professor at Rensselaer Polytechnic Institute, said age verification is likely to be an uphill battle from the start.
“I think it’s going to be difficult to verify people’s ages. People get around age verification all the time,” Jones said.
She also pushed back on the law’s core terminology.
“I am unclear about what they mean by addictive feeds. That’s a vague term to me. There are a lot of ways you can define addiction,” Jones said.
New York’s regulations were written with privacy safeguards attached to the verification process, according to Johnson, who said the rules avoid a hard requirement for government identification.
“Companies can’t require, for purposes of this law, a government ID. They can do things like biometric age estimation through video or photos, or cross-checks against an email or phone numbers,” Johnson said.
Jones said that flexibility doesn’t eliminate the risk.
“ID verification comes with a lot of risks, especially around privacy, and it comes with more risk for some people, especially those who already feel targeted,” she said. “Instead of doing all this age verification and potentially risking people’s privacy, social media companies could redesign their platforms in ways that are designed around people’s safety.”
Not every group backing the law’s goals is on board with its approach. The New York Civil Liberties Union has opposed the measure, saying in a statement: “We all share the goal of protecting young people online, but the SAFE for Kids Act poses unacceptable privacy risks to adults and youth alike and limits free speech. Notwithstanding the AG’s careful rulemaking, the law requires tech companies to collect and process sensitive and revealing information, like location information, about young people. It requires parents and guardians to reveal their ages and identities, effectively eliminating anonymous speech on covered platforms, chilling controversial speech, and encroaching on New Yorkers’ First Amendment and privacy rights. For these reasons, courts across the country have struck down age assurance laws almost everywhere they’ve been enacted.”
One lingering question is how enforcement will actually play out. While the law is understood to apply to major platforms, its text does not name specific companies, referring only to “social media companies” broadly.
Spectrum News 1 reached out to several major platforms for comment on the finalized rules and did not immediately hear back.
Companies now have 180 days to stand up an age-verification system before the law takes full effect. Those that don’t comply face fines of $5,000 per violation.