Kids and Teen Privacy: What Businesses Need to Know Right Now

Children's privacy has moved from a background compliance issue to one of the most actively enforced areas of U.S. data protection law. State attorneys general are investigating. Congress keeps trying, with limited success so far. Platforms are being sued. And for the first time, an AI company has taken a user to federal court over using its tools to generate child sexual abuse material.
If your product or service touches minors in any way, directly or indirectly, the risk has changed a lot in the last year.
Why Regulators Are Focused Here Right Now
State attorneys general have made children's and teen privacy a top enforcement priority. Their investigations keep circling the same three failure points:
- Weak or missing parental notice and consent
- Platforms leaning on an "actual knowledge" standard to avoid obligations they'd rather not meet
- Collecting and sharing data even after learning minors are on the platform
The "Actual Knowledge" Loophole Is Closing
The "actual knowledge" standard comes from the federal Children's Online Privacy Protection Act (COPPA), and it's worth understanding well. Many platforms argue they don't need children's privacy protections unless they affirmatively know a user is a minor.
State AGs are pushing back. If your platform's design, user base, or marketing make it reasonably foreseeable that minors are present, "we didn't know" gets harder to defend. Some states have already closed the gap directly: under the California Consumer Privacy Act (Cal. Civ. Code § 1798.120(c)), a business that willfully disregards a consumer's age is treated as if it knew that age.
In plain terms: if you build features that appeal to teenagers, market to young adults, and then claim you had no idea minors were using your product, that's not a strong legal position.
Age Assurance Is Becoming a Legal Requirement
Several states have already passed, or proposed, laws requiring "age assurance": technical controls that verify or estimate whether a user is a minor before showing them certain content or collecting their data. The Interactive Advertising Bureau has proposed a framework that would tie a company's obligations to what it actually knows about a user's age, and scale protections to that age.
The direction is clear: a terms-of-service checkbox asking users to confirm they're over 13 won't hold up much longer. As age assurance laws get more specific and easier to enforce, that approach gets harder to defend. Companies should check now whether their age verification is strong enough, and what will need to change as new laws take effect.
AI and Minors: A New Liability Frontier
The xAI Lawsuit
AI company xAI filed a federal lawsuit against a user who allegedly used its Grok image tool to generate child sexual abuse material (CSAM). It's one of the first cases where an AI provider has sought damages over illegal use of its own tool.
The signal matters more than the lawsuit itself: AI developers are starting to treat CSAM generation as its own legal and reputational risk, one that needs documented mitigation, not just after-the-fact moderation.
xAI's filing pointed to its mitigation steps: suspending and terminating accounts, and reporting to the National Center for Missing & Exploited Children. Plaintiffs in a related class action (see Further Reading, below) say that reporting fell short. That dispute isn't resolved yet.
The lesson for any business deploying AI image or media tools: being able to show real, documented mitigation will matter if you ever face enforcement or litigation. Whether or not AI providers end up liable for what users generate, not having documented safeguards is itself a vulnerability.
Why This Is an Industry Problem, Not One Company's
The Grok case isn't a single-company story anymore. A related class action over AI-generated CSAM has expanded to add Stability AI as a defendant. That's a signal this is an industry-wide exposure, not one company's problem, and it's worth tracking if you build or deploy generative AI tools.
What Businesses Should Do Now
If you collect data from or about minors, or run a platform where minors are likely present, it's time for a systematic review. That review should check:
- Do your parental consent mechanisms comply with the state laws that apply to you?
- Would your age assurance practices hold up under current and coming standards?
- Are you meeting data minimization requirements for minors' data?
- Do you have a documented protocol for handling illegal content generated on your platform?
Where the Real Risk Sits
The companies most exposed aren't necessarily the ones targeting kids on purpose. They're general-audience products that have never seriously checked whether their practices account for minor users at all. That gap, between "we don't market to kids" and "we have a compliant program for the minors already using our product," is exactly where enforcement is concentrated.
Rikka helps growing tech companies pressure-test exactly this: whether your parental consent, age assurance, and content-moderation practices would hold up under an AG investigation, not just a terms-of-service checkbox. [See our Privacy & Cybersecurity work] or email us at info@rikkagroup.com to talk through where your business stands.
Further Reading
- Venable LLP, "States Shine Spotlight on Child and Teen Privacy Laws" (November 2025)
- Loeb & Loeb LLP, "Children's Online Privacy in 2026: More State App Store, Design Code and Social Media Laws Enacted, Then Delayed" (June 2026)
- The Guardian, "Musk's xAI Sues User Who Allegedly Used Grok to Create Child Sexual Abuse Material" (July 16, 2026)
- U.S. Congress, "Kids Off Social Media Act of 2025," S. 278, 119th Congress
- NPR, "Class Action Suit Against AI Makers Over Deepfake Child Sexual Abuse Material Expands" (July 9, 2026)
This content is for informational purposes only and does not constitute legal advice.


















