The Brake Integrity Standard
One-paragraph version. Social-media litigation and regulation increasingly target the product features associated with compulsive use, but there is still no coherent standard for the plainest question a user can ask: when I tell the feed to stop or change, does my choice actually take effect, and does it stay? This paper names that missing standard brake integrity. When a platform offers a control to stop, limit, reset, or redirect a recommendation or engagement function, activating it must produce a prompt, understandable, material, and persistent change consistent with what the platform promised. Every account should have that. Child and teen accounts should additionally get safer defaults (a non-profiled or following-only feed, autoplay off, overnight-notification limits, no re-engagement pressure), with the level of parental involvement varying by age band and with the direct control belonging to the young person as they approach adulthood. The intervention aims first at the platform's own controls and delivery mechanics, not at classifying or removing lawful speech, because that is the surface most defensible under current First Amendment and Section 230 precedent. A separate, experimental appendix explores labeling the recommendation mechanism ("you are seeing this because…"); any system that labels the meaning of individual posts needs substantially more evidence and governance before it belongs in policy.
0. What this is, and what it is not
This is a framing-and-standard paper. It argues where to intervene, why that surface is the most defensible one available, and what a minimum standard would have to specify. It is not a statute, a technical specification, a legal opinion, or a claim that any platform would voluntarily adopt it. The author is not a lawyer; every constitutional and statutory statement below is directional and should be checked by counsel against the primary sources cited. The paper is AI-assisted; the reasoning is the author's, the drafting collaborative, and the honest-limits section (§7) is where it earns trust.
A note on scope discipline learned from earlier drafts of this project: for a design standard, the definition is the policy. "De-amplify engagement" and "controls that work" are not yet standards until they say which signals, how fast, how long, and across which surfaces. This paper tries to state the observable core precisely and to be honest that the operational thresholds are the real work, not a footnote to be finished later (see §5, and the AADC vagueness holding in §4).
1. The landscape, as of August 2026
Four separate legal tracks are often blurred together. Keeping them apart is the first correction, because they involve different courts, theories, and subjects. Each track below carries its own date. Tracks 1, 2 and 4 are current to mid-July 2026; track 3 was rewritten on August 13, 2026, after New Mexico entered final judgment.
Track 1: the federal addiction MDL. Meta (Facebook/Instagram), Google/Alphabet (YouTube), ByteDance (TikTok), and Snap (Snapchat) are the named defendants in MDL 3047, consolidated in the Northern District of California before U.S. District Judge Yvonne Gonzalez Rogers. The MDL held 3,137 pending actions as of the August 3, 2026 JPML report (up 244 in the month since July 1). The theory is product design: plaintiffs allege the companies intentionally built features to keep young users returning. In an order filed June 29, 2026 (announced June 30), the court denied Meta's motion for summary judgment on the state attorneys general's deception, unfair-practices, and COPPA claims (finding material factual disputes over whether the platforms are addictive and whether Meta misrepresented that), and gave the states a narrower partial summary judgment on COPPA: Meta's notice and parental-consent procedures did not comply with the statute. That is a compliance finding, not yet liability; whether COPPA applied to the services at issue (child-directed status, knowledge of under-13 users) remains for trial. In the same order, the court found Meta's own documents could support the theory that its time-restriction tools were a "public relations stunt", deployed while the company knew more time on the platform was linked to worse outcomes for teens; that is cited evidence, still disputed, and it puts the functionality of the offered brakes directly inside the case. The August trial in Oakland, against Meta alone (the other MDL defendants face separate personal-injury and school-district tracks), combines the 29 participating states' consolidated COPPA claims with consumer-protection claims from four of those states (California, Colorado, Kentucky, New Jersey): jury selection began August 12, 2026, opening statements were delivered August 18, and evidence was heard on four days before an advisory jury (Meta moved to withdraw its jury demand, Dkt 2807; the judge decided to empanel an advisory jury and retained the ultimate findings). It never reached a verdict. On August 26, 2026, four days into evidence, the court entered a consent judgment resolving the claims of 51 states, commonwealths and territories, and with them fifteen parallel state-court AG cases the agreement lists by name, including Tennessee's Nashville trial, then in its fifth week of evidence: a maximum of $16,680,647,753.21 over ten annual installments, of which about 30 percent is contingent on Snap, TikTok and YouTube accepting equivalent teen time-management obligations and otherwise reverts to Meta, plus a $75 million cost fund and a $459,293,017.80 Cambridge Analytica-era release component paid to 48 of the settling states. Meta's own filing had characterized the four states' penalty exposure as up to about $1.4 trillion (violation counts times per-violation statutory maximums), calling the demanded remedies "entirely unmoored" from the claimed practices, a sanction with "no analog in the history of consumer protection enforcement"; the states never presented a request, and no court ruled on any number.
That consent judgment is the most important single document for this proposal, and it cuts both ways. It is the first enforceable American order to write a feed brake with the properties section 3 asks for: a default two-hour daily limit across Instagram and Facebook (the agreement's covered platforms, with messaging expressly excluded) and a default overnight block, neither of which a teen can loosen without a parent; an express duty that teens not be able to use adjacent surfaces to "effectively circumvent" the limit; a ban on the app suggesting "that the Teen User utilize a different Meta SMP or engage in messaging" when the brake engages; like counts off by default; and a non-personalized feed that must be offered without either answer preselected. It demonstrates that every objection about technical feasibility was an objection about willingness. And it is not a standard. Its stronger settings apply only on "Industry-Wide Adoption" by the other three companies, roughly $5 billion of its money is forfeit to Meta if that never happens, its independent auditor covers the first five years of a ten-year term, and the judgment states that nothing in it may "establish a standard of care for, or serve as precedent in any non-participating U.S. state or any international jurisdiction whatsoever." One company, ten years, by agreement, disclaiming generality. That is the gap this proposal exists to close.
Track 2: the California state-court bellwethers. A separate coordinated proceeding (JCCP 5255, roughly 1,600 cases) is running in California state court, not the MDL. Its first bellwether, K.G.M. v. Meta and Google (Los Angeles Superior Court), produced a $6 million verdict on March 25, 2026 ($3M compensatory, $3M punitive, allocated 70/30: Meta $4.2M, Google $1.8M, which is why some outlets report only Meta's share). In early June 2026 (the ruling was announced June 10) the trial court denied the defendants' new-trial and judgment-notwithstanding-the-verdict motions; both defendants have now filed notices of appeal (Meta in early July, YouTube on July 13, 2026). The verdict has not been reviewed, let alone affirmed, by an appellate court. The second bellwether never reached a jury: YouTube (June 23), TikTok (June 30) and Snap (tentative settlement announced July 20) all settled out confidentially, and on July 22, 2026 the plaintiff voluntarily dismissed his remaining claims against Meta, which on the available reporting paid nothing. That is a withdrawal, not a settlement with Meta and not a defence verdict, and whether it was with prejudice is not established. Note the pattern for the argument in section 1: of the two California test cases resolved so far, one produced a verdict and the other ended with the defendants leaving one at a time, which is the paying-and-continuing equilibrium this paper describes rather than an exception to it. (The Los Angeles Superior Court docket is not publicly retrievable online, so the July 20 and July 22 events rest on news coverage, not a filing.)
Track 3: New Mexico's standalone action. State of New Mexico v. Meta, tried in Santa Fe under the New Mexico Unfair Practices Act, produced a $375 million civil-penalty verdict on March 24, 2026 (the statutory maximum of $5,000 for each of 75,000 violations) for misrepresentations about platform safety and failures to protect children from exploitation. This is a consumer-protection / child-safety case, not an addiction case, and not part of the MDL. It is now decided, and it is the most important thing in this landscape for the argument that follows. On August 6, 2026 the court entered final judgment: Meta's platforms are a public nuisance in New Mexico, Section 230 does not shield it from that claim, and it must pay $567 million into an abatement fund on top of the verdict, $942 million in all. The State had asked for about $953 million and did not get that number. The judgment orders five years of supervised changes to under-18 accounts: no push notifications from 10:00 PM to 7:00 AM or during school hours, like counts hidden by default, and a 90-hour monthly cap across Facebook and Instagram. And it refused every request aimed at the feed, granting "no abatement relief relative to the design and implementation of Meta's algorithms." That is the first design remedy actually entered against a major platform in the United States, and the shape of what it granted against what it refused runs straight through §4 and §7 of this paper. Meta has said it will appeal.
Track 4: Tennessee's consumer-protection trial. State of Tennessee ex rel. Skrmetti v. Meta Platforms and Instagram, No. 23-1364-IV in Davidson County Chancery Court, went to a jury on July 24, 2026, with opening statements delivered July 27 and the court's calendar running to September 3. It matters to this paper more than its size suggests, because the State pleaded the broken-control theory as its own count rather than as evidence for a wider one. The allegation is that Meta promoted "Time Spent" tools from 2018, learned by March 2020 that they reported materially wrong numbers ("That representation was false. By March 2020, Meta employees recognized that the Time Spent tool presented materially flawed information to consumers"), had its own decommissioning team recommend removal by mid-2020, and kept the tool anyway, on the reasoning that "The regulatory and brand risk from removing our only addiction-related features outweighs" the benefit of accurate data. That is a control retained as signage after the company had established it was not connected to anything, which is the sharpest available statement of what this paper means by a brake that is not a brake. Posture discipline: these are allegations in a complaint, not findings; the operative amended complaint is under seal so the quotations come from the superseded 2023 version; Meta's motion to dismiss was denied at the pleading stage in March 2024 (not a merits holding on Section 230); and Tennessee's appellate courts declined five times to hear Meta's interim appeals, which is a refusal to take the question up, not an affirmance. The State also seeks a permanent injunction "prohibiting Defendants from using platform features that cause compulsive use among Young Users", a design remedy the Chancellor rather than the jury would decide.
The tell across all four: the deception and consent claims travel; the bare "is it addictive" claim is where the case gets stuck. That is the terrain this paper builds on.
The settlements matter too. Snap and TikTok settled the first California bellwether around the turn of 2026; all four defendants settled the first federal bellwether, a Kentucky school district's case (near $27 million combined, per the settlement agreements later obtained through a public-records request); YouTube and TikTok then settled the second California bellwether confidentially in late June. Money is moving, no liability is admitted, and no disclosed, enforceable, sector-wide design standard has resulted. Paying and continuing is, so far, the equilibrium.
And crucially: the design surface is no longer unregulated. An earlier version of this project claimed no one had named a design target. That is not accurate, and the accurate version is stronger:
- California SB 976 (Protecting Our Kids from Social Media Addiction Act, 2024) restricts "addictive"/personalized feeds for known minors behind a verifiable-parental-consent gate, imposes overnight and school-hours notification blackouts, and defaults minor accounts to private mode. The Ninth Circuit (NetChoice v. Bonta, No. 25-146, September 9, 2025) declined to enjoin the addictive-feed provision and let the default-private-mode setting stand, while enjoining the like-count restriction. (The precise reasoning is load-bearing and is discussed in §4.)
- New York's SAFE for Kids Act enacts the same core idea; it is not yet in effect (awaiting Attorney General rulemaking) and has not been litigated.
- The EU Digital Services Act, Article 38, binds very large platforms to offer at least one recommender option not based on profiling. The Commission's July 2025 guidelines on protecting minors recommend non-profiled defaults, permanent feed resets, lasting effect for "not interested" feedback, autoplay off by default, notification protections, and "why you are seeing this" explanations. The Commission issued preliminary findings that TikTok's addictive design (February 6, 2026) and Meta's Instagram and Facebook (July 10, 2026) breach the DSA, focused on infinite scroll, autoplay, notifications, and recommender systems. It separately issued a preliminary finding (April 29, 2026, IP/26/920) that Meta had failed to keep under-13s off Instagram and Facebook, a distinct age-assurance breach.
So the honest framing is not "here is a target no one has named." It is: the target is named; what is still missing, especially in the United States, is a coherent, user-centered standard for whether a person's decision to stop or redirect the system actually takes effect and persists. That standard is what this paper proposes, and §9 states what it adds to SB 976, the DSA, and the age-restriction bills.
2. The reframe: from "is addiction real" to "does the user's control work"
The instinct to litigate "is social-media addiction a real clinical condition" leads into a swamp of expert-witness battles over a contested diagnostic category. The reframe here moves the question to something measurable and already inside consumer-protection and product-liability law: when a platform tells a user a control does something, does the control do it, and does it last?
Additive, not adversarial. This reframe does not need to prove that addiction is unreal, or to displace the plaintiffs, clinicians, and youth-safety advocates litigating it. Its advantage is that it works independently: whether or not anyone proves a clinical diagnosis, a platform should still have to make its represented controls actually work. The brake and the addiction claim are allies at two depths, not competitors.
Consent, severed from the act (the moral frame). A dead man's switch is supposed to stop a machine when the human's hand comes off. Engagement platforms often behave like the inverse: the machine keeps running, or quietly restarts, after the hand comes off. You choose "following only," close the app, reopen it, and you are back in the algorithmic feed. Your stated will was present in form (there was a setting) and absent in effect (it did not persist). That is the felt experience the movement calls severed consent, and it is a good public diagnosis. It is not, by itself, a precise legal standard, because "controls that work" and "severed consent" are broad until they distinguish the kinds of control a user exercises. The precise, defined term this paper uses for the regulable object is control integrity (§3).
The delivery loop, not the content. What makes a feed compulsive is not any individual post; it is the loop mechanics: infinite scroll, autoplay, variable-ratio reward, push notifications, and ranking that optimizes for time-on-site. A brilliant post and a banal one ride the same loop. This matters because the regulable, more speech-defensible surface is the architecture of delivery and the controls over it, not the expression delivered. (The word "more" is doing real work; §4 is honest that "architecture" is not a magic phrase that removes the First Amendment.)
Amplified or extracted (a diagnostic lens, not an absolute). One way to ask what a feed is doing: does the system, when your stated will and its objective disagree, amplify the person (serve the will you actually expressed) or extract the person (farm your attention as raw material)? A real feed can do both at once, on different axes, and a user's own intent is often mixed. So this is a lens for the conflict case, not an ontological claim that a system is wholly one or the other. Stated that way, it clarifies the design question: does the user keep a clear, durable ability to redirect or stop the system? A working brake is the minimum evidence that the platform remains answerable to the person using it. (The lens has scholarly neighbors regulators already know: Zuboff on behavioral-surplus extraction, Wu on the attention economy.)
Why now. The loop is not static. As personalization models improve, they get better at predicting the exact next item that will hold attention, so the gap between what a user would choose and what the system serves tends to widen, not shrink. That is why the remedy has to be structural, a control the user actually holds, rather than a plea for restraint that the incentives will keep eroding.
3. The standard: brake integrity, plus youth defaults
The proposal has two layers. Making the base layer universal is deliberate: it avoids resting the existence of a working control on age assurance (a hard, privacy-fraught problem, §7), and it is harder for a platform to rebut, because it does not claim adults forfeit control at eighteen.
Layer I. Brake Integrity (universal)
When a service presents a control to stop, limit, reset, or redirect a personalization or engagement function, the control must be:
- discoverable (findable without external instructions);
- clear (it states what will change; "show me less" is not the same promise as "turn off personalized recommendations");
- promptly effective (the behavior changes soon after activation);
- materially effective (it changes the feed in a way the user can perceive, not cosmetically);
- persistent (the choice survives closing and reopening the app, another device, an app update, and time, until the user deliberately changes it);
- scoped (it covers the related surfaces, not one screen: Shorts/Reels, Explore, notifications, suggested accounts);
- non-circumventing (the platform does not repeatedly nag, silently reset, or route the user back into the same mode).
Every account, regardless of age, should have controls that meet these tests for at least: turning personalized recommendations off / selecting a following-only or non-profiled feed; pausing recommendation signals; turning autoplay off; and suppressing engagement-driven notifications.
Layer II. Youth Defaults (age-differentiated)
For child and teen accounts, the safer settings should be on by default (not merely available): a non-profiled or following-only feed, autoplay off, overnight notifications off, no streaks or repeated re-engagement prompts, finite stopping points, and stronger limits on behavioral profiling. This is where age assurance becomes relevant: to the additional protections, not to the existence of a working brake.
Two disciplines the youth layer must carry (developed in §7): age bands (a seventeen-year-old is not a seven-year-old; direct control should belong to the older teen, not depend solely on a guardian), and privacy-preserving parental support (a guardian can enable autoplay-off or overnight limits as settings without receiving a surveillance feed of what the teen watched or searched).
Why this is stated in observable terms
Modern ranking is multi-objective. A platform can truthfully say it "reduced the watch-time weight and added a well-being term" while the user's experience is unchanged. So the compliance test is written first in terms of what the product does that a user or an outside tester can observe, and only second in terms of the internal objective. (The honest limit on auditing the objective itself is §5.)
4. The legal architecture: two different machines, one defensible core
The single most important legal correction to earlier drafts: do not treat "regulating the algorithm" as categorically outside the First Amendment or Section 230. Two distinct doctrines are in play, and they are often conflated.
Section 230 governs retrospective liability for harm from third-party content. It immunizes "publishing," and the Ninth Circuit currently treats algorithmic recommendation as publishing. In Doe 1 v. Meta Platforms (9th Cir., No. 24-1672, April 28, 2026), the court held that "matching users with content is publishing conduct, even when the user has not requested the content," and that engagement-driven recommendation of third-party posts is therefore barred by Section 230. That holding is the current law of the circuit and the circuit is actively trying to undo it. Judge Berzon, joined by Judge W. Fletcher, urged the court to reconsider en banc "our precedent extending section 230 immunity to recommendation of content and connections to users," and Judge R. Nelson, who wrote the opinion, added that "it will fall to the en banc court" to settle it. The plaintiffs petitioned on May 12, 2026; the panel ordered Meta to respond the same day, which is not what a court does with a petition it means to deny. That petition was denied on August 17, 2026, the day before the state attorneys general's trial opened, and the order repays reading because the vote is not what the denial suggests. Judge R. Nelson voted to deny; Judges W. Fletcher and Berzon recommended granting rehearing en banc. The order then records that "[t]he full court has been advised of the petition and no judge has requested a vote on whether to rehear this matter en banc", so the petition failed for want of a call for a vote rather than on a contested one. Two of the three judges who heard the case wanted it reheard and the wider court did not take it up.
The practical effect is that Doe 1 is now final at the circuit level, absent certiorari, and this paper should treat recommendation-as-publishing as the settled law of the Ninth Circuit rather than as a holding under active reconsideration. The practical effect is not that the question is closed: a denial of rehearing is not an endorsement of the panel's reasoning, and the split on the recommendation is a matter of record for any later challenge. Build on it as the law of this circuit, and note that it is circuit law rather than national law. The narrow escape hatch is Lemmon v. Snap (9th Cir., 2021): a product-design duty survives Section 230 when it operates independently of third-party content (Snap's Speed Filter, where the danger was the speeding, not any message). Section 230 is a liability shield the platform holds, not a source of legislative power; a prospective statute is not "cleared" by Section 230, and a recommendation-objective mandate cannot assume it escapes publishing doctrine.
That characterization now has direct appellate support, from the same circuit and on the same day. In People of the State of California v. Meta Platforms, Inc. (9th Cir., No. 24-7032, filed August 10, 2026, published), the court dismissed Meta's appeal from the MDL 3047 rulings for lack of jurisdiction, holding that Section 230 provides "a defense to liability, not immunity from suit", so an order refusing it is reviewable after final judgment rather than immediately. Three things in that are useful here and none of them is the outcome. It is published, so the reading binds the circuit. It confirms that Section 230 operates as a defense a defendant raises, which is the distinction this paragraph draws between a shield and a grant of power. And the opinion records that "Meta does not identify any constitutional interests at stake" in that appeal, which is worth holding beside the confident claim, common in commentary, that feed design is straightforwardly protected expression: the largest platform in the litigation, appealing on exactly this question, did not assert it. Read with Doe 1, the circuit currently says that algorithmic recommendation is publishing conduct for Section 230 purposes and that Section 230 is a defense rather than an immunity from suit, which together mean a platform must generally try the case before it can appeal the point.
The First Amendment governs prospective statutes regulating platform conduct. In Moody v. NetChoice (SCOTUS, 2024), the Court explained that a platform's selection, ordering, and curation of third-party posts into a feed can be protected editorial expression. That discussion was guidance, not a merits holding (the Court vacated and remanded on facial-challenge grounds and did not decide either statute's constitutionality), and it expressly reserved other functions. Justice Barrett's concurrence flags the lane most relevant here: an algorithm that "just present[s] automatically to each user whatever the algorithm thinks the user will like," with no human editorial judgment, "might raise different constitutional questions." That lane is open and fact-intensive, not established in this proposal's favor, which is exactly why categorical confidence is a mistake.
Put together, these cases yield a tiered ranking of legal exposure, from most defensible to least:
- Control integrity (this paper's core). Requiring that a control the platform offers actually works and persists regulates the platform's own interaction with its user, operating independently of any particular third-party content. This is the Lemmon lane, the strongest available ground.
- Default and interface rules (autoplay off by default, notification limits, following-only availability, finite stopping points). More contestable, but conduct-focused; SB 976's default-private-mode survived intermediate scrutiny as content-neutral.
- Ranking-objective mandates (government specifies the objective by which lawful third-party speech must be ordered). This meets Moody head-on and is materially more exposed.
- Content-characterizing labels (a government-mandated label declaring a post "a wedge" or "divisive"). The most exposed of all: SB 976's like-count/feedback restriction was found content-based, drew strict scrutiny, and the Ninth Circuit ordered it blocked (a preliminary ruling, on likelihood of success); a label characterizing lawful speech likely draws a compelled-editorial-speech challenge under Moody. This is why the wedge-label is confined to the experimental appendix, not this standard.
These tiers rank statutes. A court's remedy is a different machine, and on August 6, 2026 the difference became impossible to ignore.
Two courts took the same measure, hiding like counts on minors' accounts unless a parent consents, and reached opposite constitutional results eleven months apart. In NetChoice v. Bonta (9th Cir., No. 25-146, September 9, 2025) the court found California's version content-based, applied strict scrutiny, and held that "the like-count default setting is not the least restrictive way to advance California's interest in protecting minors' mental health"; it reversed the district court's refusal to block the provision and remanded "with instructions to enter an order enjoining its enforcement." The New Mexico court ordered its version, reasoning that a like count is "merely a feature created and offered by Meta to principally track and motivate user feedback, all without altering the underlying published content."
Mind the postures, because they are not symmetrical and the asymmetry cuts against the tidy version of this story. California's is a preliminary ruling on likelihood of success, entered before any trial. New Mexico's is a final judgment after a two-phase trial, and it is on appeal. Neither is settled law. What they establish jointly is not that one court is right, but that the same feature can be characterized either way depending on which question is being asked.
Both are defensible, because they are answering different questions. A legislature regulating an industry faces the First Amendment directly. A court sitting in equity over a defendant it has already found liable for a public nuisance is choosing a remedy, and its limits are the scope of the wrong proved and the reach of its own jurisdiction. So the same design change can sit in tier 4 as a statute and be ordered as a remedy, which means this ranking answers "what may be legislated," not "what may ever be imposed."
The corollary is less comfortable and belongs here too. Remedial latitude is bounded by the case: the New Mexico court refused the industry-wide measures precisely because it had "jurisdiction over just one social media company," worried that friction on Meta alone would "merely shift users to other, non-party platforms," and said flatly that "the regulatory solutions to these problems lie in the executive and legislative branches and not with this Court." A remedy can reach further than a statute against one company, and nowhere near as far across a market. The two routes are not substitutes.
What that court did with this paper's actual proposal is the load-bearing result. It ordered the tier 1 and tier 2 measures, notification blackouts and a usage cap and the like-count default, on the ground that they are "least connected with platform content." It refused tier 3 outright, granting "no abatement relief relative to the design and implementation of Meta's algorithms" because that relief "would directly alter and limit the manner in which platform content is displayed" and so "would likely violate the First Amendment and Section 230." The line it drew is the line drawn above, and it drew it in the same place. That is a real test of this ranking and the ranking survived it, in one state trial court, now on appeal.
Precision is part of the legal architecture, not the finish work. In NetChoice v. Bonta (the Age-Appropriate Design Code appeal, 9th Cir., No. 25-2366, March 12, 2026), the court un-enjoined the age-estimation requirement but kept the injunction on the data-use and dark-pattern provisions on First Amendment vagueness grounds, because terms like "materially detrimental" and "well-being" did not give adequate notice of prohibited conduct. For a design standard, undefined criteria are not a detail to settle later; they can be the difference between an enforceable rule and an enjoined one. The observable-test framing in §3 and §5 is an attempt to write to that constraint.
The live corroboration. SB 976's addictive-feed restriction and default-private-mode are live, un-enjoined law after the Ninth Circuit's September 2025 decision. Two honest caveats: (a) the court declined to enjoin on standing and facial-challenge-burden grounds and expressly left open whether a personalized feed is the platform's protected speech, so this is durability under preliminary challenge, not a merits blessing; and (b) the one feed-adjacent mandate the court ordered blocked (hiding like counts) is the instructive warning that regulating which content or metrics are shown is far more dangerous than regulating whether the feed is algorithmically personalized by default. Control integrity sits on the safe side of that line.
A second legal system reached the same shape of answer from the opposite direction, and it is the best comparative evidence this paper has. On August 14, 2026 the French Conseil constitutionnel, reviewing a bill before promulgation on a referral by 120 deputies, struck article 1 of the law intended to protect minors from the risks of social media, which would have barred under-15s outright. The ground was freedom of expression and communication under article 11 of the 1789 Declaration. The reasoning is the part that matters here, at paragraph 17: the legislature could not institute a prohibition of general scope, imposed without regard to the individual minor's situation or to the risks specific to each service, without disregarding that freedom. The defect the court identified was bluntness, not the attempt.
Set that beside New Mexico. A court declined the feed-design remedies because a court is the wrong instrument and because ordering one firm while its competitors are absent is unfair, and said in terms that regulation of industry-wide features requires legislative or executive action. A constitutional court then struck a legislature's answer because it was undifferentiated. Read together they do not say that regulating design is unavailable. They say the workable instrument is calibrated, service-specific and market-wide, which is a description of a standard and a description of neither a lawsuit nor a ban. That is the strongest external corroboration in this paper for why the proposal is shaped the way it is, and it arrives from a jurisdiction with no Section 230 and no First Amendment.
And there is already a working example of the shape both decisions point at. Australia's minimum-age obligation took effect on 10 December 2025 under Part 4A of its Online Safety Act. Read carefully, it is not the ban it is usually called: it prohibits no minor from anything. It places a duty on age-restricted social media platforms to take reasonable steps to prevent Australians under 16 from holding accounts, backed by a civil penalty, and it carves out messaging, voice and video calling, online gaming, and services whose primary purpose is education, health support or professional development.
That is a duty with a standard of care and a defined scope, imposed on the operator rather than on the child, which is the same grammar this paper's proposal uses. Whether it works is a separate and still-open question, and the early evidence includes meaningful circumvention alongside large numbers of removed accounts. But it demonstrates that the calibrated, service-specific, operator-facing form is drafts-able and enactable, which is the objection most often made to it.
The French reform was not abandoned: the government was tasked with preparing a legally robust replacement, targeted at spring 2027. What survives the second attempt will be worth reading, because it is the first serious test of whether a calibrated version clears the bar the blunt one failed.
5. Auditability and anti-circumvention
Earlier drafts claimed a changed ranking objective is "auditable from outside." That is not generally true: an outside observer cannot inspect objective functions, weights, training data, or internal experiments without mandated access. What can be tested from outside is what the product does. So the compliance model is layered:
Observable tests (outside the platform): a non-profiled/following-only mode exists, is easy to activate, has a visible active state, takes effect promptly, persists across sessions and devices, keeps autoplay off, suppresses engagement notifications, does not auto-revert, keeps search and explicitly-requested content available, and is not compensated for by ramping up another surface.
Mandated internal evidence (with legal access): a public control specification, version histories, controlled-account testing, documentation of ranking signals and prohibited substitutions, machine-readable records of when a preference was activated and honored, outcome testing across age groups and languages, anti-circumvention testing, and a complaint-and-remediation process.
Anti-circumvention is non-optional. A platform can reduce engagement pressure in the main feed while increasing notifications, suggested accounts, streaks, and direct-message prompts. Compliance has to cover the whole relevant product experience, or it simply moves the loop.
Who enforces. The standard does not by itself pick an enforcer, and the choice matters for feasibility. Control integrity is a deception claim at heart, so it fits the FTC's unfair-and-deceptive-practices authority; the state attorneys general already litigating the MDL are a natural second venue; and a dedicated digital regulator on the EU's DSA model is a third. The observable tests are written to be usable by any of them, or by an independent auditor operating under mandated access.
The honest formulation is therefore: control performance can be tested from outside; full verification of ranking compliance requires legally mandated documentation, data access, and independent audit.
6. Why not just have the platforms detect and down-rank the harmful stuff?
Because the party best positioned to build that detector is the party you would least want running it silently.
These platforms are the entities on earth best placed to classify content at scale: the most compute, the most reach, and the deepest behavioral profile of every user, the same modeling that makes a feed compulsive in the first place. Detection is not the hard part. The danger is who would hold a silent, platform-owned classifier of what counts as harmful or "divisive" for every child, and why they would run it honestly. The firm you would ask earns its money on engagement, and the most engaging content is often the most inflammatory. The biggest of these firms booked on the order of $26.8 billion in net income in a single quarter (as of Q1 2026; figures like this date quickly and carry an as-of date here for that reason). It has a built-in reason to under-enforce on the outrage that drives its revenue, or over-enforce on speech it dislikes, and a silent classifier cannot be checked from outside.
The conclusion is not "detection is impossible." It is: a detector this cheap to build and this profitable to bias must never be the silent, centralized mechanism. That is why the standard here regulates the objective and the controls rather than mandating a classifier, why any labeling that does happen must be a contestable, user-facing thing rather than a silent filter, and why the wedge-label specifically is confined to the experimental appendix. Change what the feed optimizes for, and there is no classifier to trust; "did the offered control work and persist?" is something an outsider can actually test.
7. The honest limits (load-bearing; do not skip)
-
This is a frame plus a standard sketch, not a finished rule. Measurable thresholds ("how fast must a control take effect; how long must it persist; how much friction before an override is manipulative"), a testing and audit methodology, enforcement, and surviving legal challenge are the bulk of the work and are not fully here.
-
Age verification is still the showstopper, and the thing blocking it is not the First Amendment. On August 6, 2026 a judge who had just found Meta's platforms a public nuisance, and who called age verification "the key to making Meta's platforms safe for adolescents," held that he could not order it. COPPA defines collection broadly enough to reach "passive tracking of a child online," so the statute written to protect children forbids gathering the data needed to find them. The same statute shuts the workaround: the court found Meta's own age classifier "is hindered by COPPA and its prohibition on the use of data that is needed to train a classifier to be more accurate in its age predictions." He was careful to add that he was "not criticizing the policies behind COPPA." The FTC's 2026 enforcement-discretion policy does not undo it, and the court refused to rely on that policy because it "does not create any substantive rights or entitlements." That is one trial court and it is on appeal, but the statute it read is the same one everybody else has to read.
Meanwhile American courts keep finding reasons not to decide the question at all: unripe in the SB 976 appeal, because the requirement does not begin until 2027; undecided in the Age-Appropriate Design Code appeal, for want of a developed record; statutorily barred in New Mexico. "The courts have not resolved this" is a very different claim from "the courts have rejected this," and only the first is true. Congress tied this knot and only Congress can untie it, which is worth saying plainly to the people who keep asking courts to.
The mitigation this paper leans on is structural and is unchanged by any of it: because Layer I (the working brake) is universal, the existence of control does not depend on age assurance at all. Age assurance is needed only for the default protections, which narrows the problem without eliminating it. And the solution must still not build a surveillance infrastructure worse than the harm it addresses, which is the one reason to prefer this deadlock to a bad fix.
-
Youth autonomy, not only parental control. "Let the guardian decide" is too simple for an under-18 population. Some guardians are controlling, abusive, or hostile to a child's identity; a parental tool that surfaces a teen's interests, health questions, sexuality, or relationships can itself cause harm. Older teens should hold the direct brake themselves; parental support should be about settings (autoplay off, overnight limits) rather than content surveillance.
-
De-amplification affects speech distribution, and this stopped being a prediction on August 6, 2026. Any change to ranking affects which speech reaches which audience, so even "content-neutral" is a strong defense, not an absolute one, and the Moody "purely reactive algorithm" question is unresolved (§4). A court has now refused ranking relief on exactly that ground, holding that the requested algorithm changes "would directly alter and limit the manner in which platform content is displayed" and "would likely violate the First Amendment and Section 230." This paper put ranking mandates in tier 3 for this reason and was right to. Note also why the state lost: the court called its algorithm requests "vague and aspirational, rather than objective and measurable." That is the strongest external argument this paper has for writing the standard in observable terms (§3, §5), and it is an argument made by a judge who wanted to grant something and could not find a specification to grant. Following-only or chronological defaults also carry distributional effects (they can disadvantage new creators and people who rely on discovery); that does not defeat the standard, but it should be measured.
-
Platforms will pre-empt and will litigate. The likeliest response to a public campaign is a cosmetic brake plus a press release (Instagram Teen Accounts is arguably this move already), which deflates a movement without touching the loop. The persistence and anti-circumvention tests exist precisely so a cosmetic brake fails them. Platforms may also argue a mandated objective is a regulatory taking or compelled speech; counsel required.
-
The evidence is not all one way, and the standard must not overclaim. Three empirical claims must be kept separate: that a design increases compulsive use, that a proposed control changes behavior, and that the behavioral change improves welfare. The closest existing experiment (Guess et al., Science, 2023) found that switching users to a reverse-chronological feed reduced time on platform but did not measurably improve polarization, knowledge, or well-being over a three-month adult window. That is real counter-evidence to a naive "chronological fixes everything" claim. The fair response is that a three-month adult study is not a developmental-exposure study of minors and that reduced compulsive use is a legitimate end in itself, not only a proxy for mental health, but the paper should make that argument openly rather than list falsifiers it has not checked against the literature (see §8).
-
The wedge classifier is the dangerous part, and it is not in this standard. The question of whether a post is tribal sorting versus legitimate advocacy, satire, or reporting is normative and contested, and even perfect behavioral prediction does not resolve it. A parental toggle changes who activates a label, not who defines the category, trains the model, or benefits from its operation. "Visible" does not equal "contestable" without a specified appeal process, and a mandated label on lawful speech invites the strongest constitutional challenge (§4, tier 4). Labeling research also shows an implied-truth effect: warning some items makes the unlabeled ones read as vetted. For all these reasons the wedge-label is a research hypothesis in the experimental appendix, not a policy recommendation. The appendix also develops the stronger, brake-aligned alternative: labeling the recommendation mechanism ("you are seeing this because you engaged with similar posts," with a control to stop using that signal) rather than the meaning of the speech, which supports recommendation literacy without characterizing anyone's lawful expression. (Inoculation research, van der Linden and colleagues, supports the "name the manipulative move" mechanism, which is why the idea is worth studying rather than discarding.)
-
Displacement, which a court has now used as a reason to deny relief. De-amplify the big platforms' feeds for minors and attention can migrate to group chats, Discord, gaming platforms, or smaller apps outside any single statute's reach. The standard regulates the venue; it should not assume the harm stays put. In New Mexico this was not a hypothetical objection but a holding: significant sign-up friction on one company would be "inequitable and unduly injurious to Meta" and would "merely shift users to other, non-party platforms." Displacement is the argument a single-defendant proceeding cannot answer, which is a further reason the durable version of this standard is legislative rather than litigated.
-
The banishment risk. De-amplifying minors' feeds lowers the ad value of that cohort, so one rational platform response is to stop serving under-18s at all rather than build and maintain a parallel low-engagement product, which would trade this proposal's problem for the blunt age-ban and age-verification fight it is trying to avoid. The universal base layer (§3, Layer I) is a partial hedge, since a working brake is required for every account regardless of age and banishing minors does not escape it, but the youth-defaults layer still creates the incentive, and the proposal should say so plainly. Courts feel this too: the New Mexico court declined design relief partly because restrictions on one company "could harm the viability of Meta and its platforms" given "the absence of Meta's competitors in this litigation." An obligation that lands on one firm is a competitive penalty; the same obligation across a market is a standard. That asymmetry is an argument for legislating this, not for softening it.
-
The counter-narratives, and the honest answer to each. A proposal is stronger for naming its opponents' best lines. "We already offer parental controls" is often true and often inadequate; the persistence and scope tests (§3) are exactly what a cosmetic control fails. "This breaks discovery for small creators" is partly true, a real distributional cost to measure (§7.4), not a reason the brake should not work. "Chronological feeds help disinformation" is arguable, and is part of why the standard regulates control integrity and defaults rather than mandating one feed order. "This is a backdoor to government control of speech" is the strongest bad-faith line, and the reason the core is the platform's own control and the wedge-label is confined to research (§4). "Parents, not platforms, should manage screen time" ignores that the loop is engineered against the parent too; the youth defaults are a floor, not a substitute for parenting.
-
Meta-honesty flag. This document reasons about media effects and its own relevance to policy, a surface where fluent, self-flattering narrative is the failure mode. The reasoned parts (the tractability of control integrity, the legal tiering) are hypotheses to be tested against the primary sources, not findings. An earlier version of this project also carried factual errors about the litigation that were caught only on external review; the sources here have been re-checked against primary dispositions for that reason, and are dated.
8. Falsifiability: what would show this is wrong
- Persistent controls do not reduce compulsive use. If durable, working brakes for minors do not measurably reduce compulsive-use metrics and high-arousal exposure, the "controls that work" premise is weakened. (Held honestly against Guess et al., §7.6: reduced time-on-platform is established for chronological feeds; the attitudinal/welfare link is not, and this standard's claim is about restoring control, with reduced compulsion as the near-term measurable, not a mental-health guarantee.)
- Control integrity cannot be specified enforceably. If "prompt, material, persistent, non-circumventing" cannot be turned into thresholds that survive the AADC vagueness bar (§4), the standard reduces to the aspiration it criticizes.
- The objective substitutes invisibly. If platforms can satisfy every observable test while re-introducing engagement pressure through renamed signals or other surfaces that outside audit cannot catch, the anti-circumvention model has failed.
- The Lemmon lane closes. If courts treat requiring an offered control to work as itself compelling or restricting the platform's protected editorial speech, the paper's central legal bet (control integrity is the Lemmon lane, not the Moody lane) is wrong.
9. What this adds to the existing record
Because §1 establishes that the design surface is already regulated, this paper must justify itself against what exists:
- Versus SB 976 / NY SAFE: those gate personalized feeds for minors behind parental consent. Brake integrity is universal at the base layer (a working, persistent control for everyone), makes durable user choice the object rather than a broad personalization restriction, avoids making parental consent the sole escape valve, and adds the persistence and anti-circumvention tests that turn "a setting exists" into "the setting works and stays." It also stays on the safer side of the SB 976 like-count strike-down by never regulating which content or metrics are shown.
- Versus the DSA / EU minors guidelines: the DSA already mandates a non-profiled option and the guidelines already describe resets and lasting feedback. This paper's contribution is a testable integrity standard (observable pass/partial/fail criteria and an audit model) rather than a list of desired features, and the explicit §230-vs-First-Amendment tiering for the US context.
- Versus age-restriction bills (UK under-16 ban, etc.): those restrict access. This restricts the loop and the controls over it, which does not require deciding that minors may not use these services at all, and which extends a base-layer benefit to adults.
The one-line version of the contribution: existing law increasingly names design as the target; what is missing is a user-centered standard for whether the person's decision to stop or redirect the system actually takes effect and persists. That standard is brake integrity.
Provenance and methodology
The conceptual tools here were carried in from a creative and analytical practice and applied to a policy problem: the dead-man's-switch image, "consent severed from the act," and the "amplify or extract" lens began outside policy and are restated in full above, so nothing load-bearing lives elsewhere. This paper is AI-assisted: the seed insights and judgment are the author's; drafting was collaborative; the legal and empirical claims were verified against primary sources (see below), and the honest-limits section is the check on fluent overreach. This paper deliberately does not name a human legal, technical, or youth-safety reviewer, because it has not been through one; that review is part of the 95% still to be done.
Sources (reviewed July 2026; dispositions dated)
Litigation and regulation in this area move weekly; each item carries an as-of date and should be re-checked against the primary source before circulation.
- MDL 3047 (four defendants; 3,137 pending per the August 3, 2026 JPML report; June 29 2026 summary-judgment order, announced June 30, incl. the narrowed COPPA compliance finding and the "public relations stunt" language at p. 23; Aug 12/18 2026 trial against Meta alone, 29-state COPPA claims plus four states' consumer claims; Feb 2027 follow-on for 14 states; ~$1.4T Meta-characterized exposure, "entirely unmoored" / "no analog" per Meta's filing): JPML report; the summary-judgment order, Dkt 3214, via CourtListener/RECAP (primary, verified 2026-07-16); Meta's penalty filing, Dkt 455 (primary); California AG release; Top Class Actions on the COPPA scope; Law.com/The Recorder; JURIST; Engadget on the trial structure.
- K.G.M. v. Meta and Google ($6M, LA Superior Court, Mar 25 2026, split 70/30 Meta/Google; new-trial/JNOV denied early Jun 2026, announced Jun 10; Meta appeal filed early July, YouTube Jul 13 2026; second bellwether: Meta and Snap to trial Jul 27 2026 after YouTube (Jun 23) and TikTok (Jun 30) settled): CNBC; AP via US News; Law.com; NBC News.
- State of New Mexico v. Meta ($375M jury verdict Mar 24 2026 under the NM Unfair Practices Act, child-safety; final judgment Aug 6 2026 adding a $567M abatement fund for $942M total, plus a five-year injunction on under-18 accounts and NO relief against the algorithm; Meta says it will appeal): NM DOJ; Santa Fe New Mexican; Source NM.
- California SB 976 and NetChoice v. Bonta, No. 25-146 (9th Cir. Sep 9 2025) (addictive-feed provision and default-private-mode un-enjoined; like-count enjoined; feed-expressiveness left open): SB 976 text; 9th Cir. opinion.
- NY SAFE for Kids Act (enacted 2024; pre-effective, awaiting AG rulemaking): NY AG proposed rules.
- Moody v. NetChoice (SCOTUS 2024, curated feeds as editorial expression, guidance not merits; Barrett concurrence on reactive algorithms): opinion.
- Doe 1 v. Meta Platforms (9th Cir. Apr 28 2026, recommendation is publishing under §230; distinguishes Lemmon): opinion. Rehearing en banc denied Aug 17 2026 (No. 24-1672, DktEntry 55), with Judges W. Fletcher and Berzon recommending it be granted and no judge of the full court requesting a vote: order via CourtListener/RECAP.
- People of the State of California v. Meta Platforms (9th Cir. Aug 10 2026, published; §230 is a defense to liability, not immunity from suit, so appeals from orders denying it were dismissed for lack of jurisdiction; Meta identified no constitutional interests in that appeal): opinion via CourtListener/RECAP.
- Lemmon v. Snap (9th Cir. 2021, product-design duty independent of content survives §230): analysis.
- NetChoice v. Bonta (AADC) (9th Cir. Mar 12 2026, age-estimation un-enjoined; data-use/dark-pattern provisions enjoined on vagueness): opinion.
- EU DSA Art. 38 (non-profiling recommender option) and Commission minors guidelines (Jul 2025); preliminary findings: TikTok addictive design Feb 6 2026, Meta under-13 age assurance Apr 29 2026, Meta addictive design Jul 10 2026: Commission minors guidelines; Meta addictive-design finding; Meta under-13 finding, IP/26/920.
- Guess et al., Science (2023) (chronological feed reduced time, not attitudes): study.
- UK (under-16 ban announced Jun 15 2026; 16-17 curfews/addictive-feature defaults Jul 15 2026; both targeted spring 2027): GOV.UK.
- Meta Q1 2026 net income (~$26.8B, incl. one-time tax benefit) (as-of Q1 2026, dates quickly): Meta IR.
Financial and case figures are as reported and not independently audited here; legal characterizations are directional and for counsel to confirm.