Kids and Teen Privacy: What Businesses Need to Know Right Now

Children's privacy has moved from a background compliance issue to one of the most actively enforced areas of U.S. data protection law. State attorneys general are investigating. Congress keeps trying, with limited success so far. Platforms are being sued. And for the first time, an AI company has taken a user to federal court over the use of its tools to generate child sexual abuse material. For any business whose products or services touch minors in any way, directly or incidentally, the risk landscape has changed materially in the last twelve months.
The Enforcement Focus
State attorneys general have made children's and teen privacy a priority enforcement area. Investigations have concentrated on a consistent set of failure points: inadequate parental notice and consent mechanisms, reliance on an “actual knowledge” standard that platforms use to avoid triggering obligations they would prefer not to meet, and data collection and sharing practices that continue even after a platform is on notice that it is serving minors.
The “actual knowledge” standard, which originates in the federal Children's Online Privacy Protection Act (COPPA), is particularly important to understand. Many platforms take the position that they are not required to implement children's privacy protections unless they affirmatively know they are collecting data from a minor. State AGs are increasingly scrutinizing whether that posture is defensible when the platform's design, user demographics, or marketing materials make it reasonably foreseeable that minors will be present, and some states are closing the gap directly: under the California Consumer Privacy Act (Cal. Civ. Code § 1798.120(c)), a business that willfully disregards a consumer's age is deemed to have actual knowledge of it. A platform that builds features attractive to teenagers, markets to young adults, and then asserts it had no actual knowledge of minor users is not in a strong legal position.
Age Assurance Is Becoming a Legal Requirement
Several states have enacted or proposed laws requiring platforms to implement age assurance mechanisms, technical controls designed to verify or estimate whether a user is a minor before exposing them to certain content or collecting their data. The Interactive Advertising Bureau recently proposed a framework for modernizing children's privacy law that would tie obligations to a company's actual knowledge of a user's age and calibrate protections to a minor's age and developmental capacity.
The direction of travel is clear. Businesses that currently rely on a terms-of-service checkbox stating that users must be 13 or older will find that approach increasingly difficult to defend as age assurance requirements become more specific and enforceable. Companies should be assessing now whether their current age verification practices are adequate and what changes may be required as new laws take effect.
AI and Minors, A New Liability Frontier
The intersection of AI and children's safety has produced a legal development worth watching closely. AI company xAI filed a federal lawsuit against a user who allegedly used the Grok image generation tool to produce deepfake images depicting child sexual abuse material. The case is one of the first instances of an AI provider seeking affirmative damages for illicit use of its tools, and it signals that AI developers are beginning to treat CSAM generation as a distinct legal and reputational risk, one that requires documented mitigation rather than reactive moderation.
xAI's legal filing specifically cited its mitigation protocols, including account suspensions, account terminations, and reporting to the National Center for Missing & Exploited Children, though plaintiffs in the related class action discussed below allege that reporting was inadequate, a dispute that remains unresolved. For businesses deploying AI tools capable of generating images or other media, the ability to demonstrate proactive mitigation will be relevant in any enforcement or litigation context. Whether or not AI providers face direct liability for user-generated content, the absence of documented safeguards is a vulnerability.
The Grok litigation is also no longer a single-company story. A related class action over AI-generated child sexual abuse material has since expanded to add another AI developer, Stability AI, as a defendant, a signal that this is an industry-wide exposure rather than an isolated dispute, and one that any business building or deploying generative AI tools should be tracking closely.
What Businesses Should Do Now
Companies that collect data from or about minors, or that operate platforms where minors are likely to be present, should conduct a systematic review of their current practices. That review should address whether parental consent mechanisms comply with applicable state laws, whether age assurance practices are defensible under current and anticipated standards, whether data minimization obligations for minors' data are being met, and whether the company has a documented protocol for handling illegal content generated through its platform.
The companies most exposed are not necessarily those actively targeting children. They are companies with general-audience products that have not seriously examined whether their practices adequately account for minor users. That gap, between “we don't market to kids” and “we have a compliant program for minors who use our service,” is exactly where enforcement is concentrated.
Rikka helps businesses assess compliance obligations for children's and teen privacy and build practical programs that address both current requirements and anticipated regulatory changes. Contact us at info@rikkagroup.com to discuss where your business stands.
Further Reading
Venable LLP, “States Shine Spotlight on Child and Teen Privacy Laws” (November 2025)
Loeb & Loeb LLP, “Children's Online Privacy in 2026: More State App Store, Design Code and Social Media Laws Enacted, Then Delayed” (June 2026)
The Guardian, “Musk's xAI Sues User Who Allegedly Used Grok to Create Child Sexual Abuse Material” (July 16, 2026)
U.S. Congress, “Kids Off Social Media Act of 2025,” S. 278, 119th Congress
NPR, “Class Action Suit Against AI Makers Over Deepfake Child Sexual Abuse Material Expands” (July 9, 2026)
This content is for informational purposes only and does not constitute legal advice.


















