
California has a habit of treating its laws like national policy, and what Governor Gavin Newsom just signed will likely ripple far beyond state lines. As reported by Engadget, Newsom has signed a package of laws targeting how minors interact with social media platforms and AI chatbots. The stated goal is child safety. But buried in the fine print is a problem that should make every privacy-conscious adult pay attention, not just parents.
The new rules hit AI chatbot companies first. Platforms must now enforce time limits on teen users, display mental health resources, activate safety protocols when self-harm comes up in conversation, and notify parents if a child disables safety settings. California will also require independent child safety audits and annual risk assessments from AI companies. Fail to comply, and they face legal liability. This follows a separate round of AI compliance measures Newsom signed just a day earlier, building out a broader audit framework for the industry.
The social media restrictions are where things get genuinely contentious. California now bans platforms from letting users under 16 access what the law defines as “addictive features.” That definition is broad enough to include autoplay video, push notifications, and algorithm-driven content feeds. Basically the core mechanics of how every major social platform works today.
The Electronic Frontier Foundation was blunt in its criticism. “Denying minors access to digital forums, or stripping out basic tools needed to navigate them, is not going to help make young people safer or healthier,” said EFF Associate Director of State Affairs Rindala Alajaji. The EFF’s position is that this is a functional ban on social media for teenagers, dressed up as protection.
But here’s the part that affects everyone. To enforce age restrictions at this scale, platforms will need to verify user ages. And that means collecting more personal data from all users, including adults, not just kids. The EFF flagged this directly, pointing out that age verification requirements consistently create new privacy risks by forcing people to hand over identifying information to the very companies already under scrutiny for mishandling data. It’s a pattern that has played out repeatedly in age verification debates across the US and UK.
The package also includes expanded laws on child sexual exploitation to cover AI-generated and digitally altered images, new restrictions on targeted advertising aimed at minors, and tighter controls on how AI systems use data from K-12 students. Those measures have faced far less pushback.
The tension here is real. Protecting children online is a legitimate and urgent problem. But laws that require mass age verification hand platforms exactly the kind of data they should have less of, not more. California may have meant well. The consequences could cut both ways.