Current Region:
Global

New Mexico Court Judgement: Positive or negative for Age Assurance?

August 7, 2026

On 6 August 2026, Judge Biedscheid of the First Judicial District Court in Santa Fe issued his findings of fact, conclusions of law and judgement in State of New Mexico v Meta Platforms, Inc. The case had been brought by New Mexico Attorney General Raúl Torrez, alleging that Meta’s platforms constituted a public nuisance by causing widespread harm to the mental health and safety of children and teenagers in New Mexico.

The verdict is historic. After a two-phase trial running from February to May 2026, the court found Meta liable, ordered it to pay $375 million in civil penalties for 75,000 violations of New Mexico’s Unfair Practices Act and required it to contribute a further $567 million into an abatement fund to address the youth mental health crisis its platforms have contributed to creating. Total financial exposure: $942 million for conduct in a single US state.

For those of us working in age assurance, the judgement is a complex document. It contains some genuinely important advances, some significant missed opportunities and at least one structural flaw that Meta could exploit to minimise the practical effect of the age assurance measures it does order.

The positive findings for age assurance

The court’s factual findings are remarkable in their breadth and detail. The judgement establishes, after a full adversarial trial, that Meta knowingly designed engagement-optimising features that are harmful to teenagers, that those features caused a measurable public health crisis in New Mexico, and that Meta’s existing measures to protect children were inadequate. These are now findings of a court of law, not allegations. That matters enormously for the broader age assurance landscape.

The judgement also confirms that Section 230 of the Communications Decency Act does not shield platforms from liability based on their design choices, following an emerging line of appellate authority from Nevada, the Ninth Circuit and the Third Circuit. This is significant because Section 230 has long been deployed as a near-universal defence against platform liability claims. Its erosion in the design context opens the door to individual plaintiff litigation on the same theories that underpinned this case.

The court explicitly acknowledged that age verification is “the key to making Meta’s platforms safe for adolescents” at both the under-13 and under-18 boundaries. That is a judicial endorsement of the principle that age assurance is not an optional extra but a structural necessity for safe platform operation. We will be citing that finding for years.
The court also ordered Meta to proactively request proof of age from accounts its systems predict to be under 13, and to delete accounts that do not verify within 30 days. This is the first time a US court has ordered a major social media platform to conduct active age verification rather than simply relying on self-declaration. It is a modest but real step.

The less positive findings for age assurance

The age assurance remedy as ordered has serious limitations, and we think it is important to be candid about them.
The verification obligation only bites where Meta’s own heuristic systems flag an account as potentially under 13. Meta controls the threshold at which that flag is triggered. A threshold calibrated to minimise false positives, which is the commercially rational choice, will systematically miss a large proportion of genuine under-13 users. The court set no accuracy standard, required no independent audit and mandated no minimum detection rate. The remedy is therefore as strong or as weak as Meta chooses to make it.
The under-13 classifier Meta is required to develop within two years must meet only a “reasonable best efforts” standard. That is an almost unenforceable obligation in the absence of a defined performance benchmark. A model that performs marginally better than Meta’s existing heuristics would satisfy the letter of the order.
Most significantly, there is no age assurance requirement at the under-18 boundary at all. The court found that grooming, sextortion and CSAM facilitated by adult-to-minor connections on Meta’s platforms were among the most serious harms before it. Yet any adult can register on Instagram today with a self-declared age of 22 and receive full adult permissions with no verification of any kind. The Teen Account protections that are designed to prevent adult-to-minor contact operate entirely on the basis of declared or estimated age, and a determined bad actor can circumvent them at the point of registration.
There is a further vulnerability the judgement does not address. An adult seeking to access the teen ecosystem does not need to declare an adult age at all. By registering with a self-declared age of 14, a bad actor gains access to the teen account network, where the protections designed to prevent adult-to-minor contact do not apply because the platform believes all parties to be peers. The entire architecture of the Teen Account safety system assumes the threat comes from outside the minor population. It has no mechanism for identifying adults who have falsely declared minority to gain entry.
The court’s reasoning on the under-18 gap relies heavily on COPPA as a legal barrier to age verification tools. We think that reasoning is legally insufficient. COPPA’s operative constraint is on collecting personal information from children under 13 without parental consent. It does not in terms apply to verification of users asserting they are teenagers in the 13-17 range, and the court made no finding that it does. Privacy-preserving verification methods, including zero-knowledge proof architectures and on-device approaches, may not constitute collection of personal information under COPPA at all. The court did not engage with this.

The Paxton question

The most significant legal gap in the judgement is its failure to engage with Free Speech Coalition v Paxton, the Supreme Court’s July 2025 decision upholding Texas’s age verification law for online pornography. Paxton establishes that the state’s interest in protecting minors from harmful content justifies platform-level age verification requirements even where they impose friction on users. Its harmful-to-minors framing is broader than pornography and is directly applicable to the harms this court found Meta’s platforms to have caused.
Paxton was settled law before Phase 2 of the trial even opened. A New Mexico state court is bound by US Supreme Court authority on federal constitutional questions. The court’s constitutional caution about ordering age verification had no adequate legal basis once Paxton was decided, and the failure to engage with it is a significant flaw in the age assurance sections of the judgement.

The increased private litigation risk for all platforms

The New Mexico judgement has implications that extend well beyond Meta and well beyond New Mexico. Every social media platform that allows minors to access its services without robust age assurance should take note.
The judgement constitutes formal, judicially established notice that engagement-optimising platform features cause measurable harm to children, that self-declaration of age is an inadequate safeguard, and that existing heuristic-based approaches to age detection fall short of what is needed. Any platform that continues to rely solely on those approaches after this judgement cannot credibly claim ignorance of the risk.
Individual plaintiffs in future litigation across the United States will be able to point to these findings. The public nuisance framework used in New Mexico limits recovery to abatement rather than individual compensation, but it does not prevent individual negligence or products liability claims based on the same underlying facts. The Section 230 design-liability line the court drew, following Nevada, Ninth Circuit and Third Circuit authority, makes those claims considerably more viable than they were before this judgement.
A platform that knowingly chose minimum compliance over available certified age assurance alternatives, after a court found its existing measures insufficient, will face serious difficulty defending a future individual plaintiff claim on that basis. The commercial incentive to go further than courts require may therefore be stronger than any individual judgement suggests. Proactive deployment of robust, certified age assurance is not just the right thing to do for child safety. After this judgement, it is also the more defensible commercial and legal posture for any platform operating in the United States.

What happens next

Meta has announced it will appeal. The liability finding is well supported by the evidence and the Section 230 analysis follows defensible authority, but a significant appellate battle lies ahead.
Whatever the appellate outcome, this judgement will be studied carefully by attorneys general and legislators across the United States and beyond. Its factual findings on platform harm will be quoted as an authority in other cases.   But the British, Australian and European approaches of setting statutory age assurance standards across the board remain the model that the US would need to follow if its lawmakers decide they wish to require effective age assurance in this sector.
The court itself said as much. In paragraph 138, after explaining why it could not order more robust age assurance, it noted that “the regulatory solutions to these problems lie in the executive and legislative branches and not with this Court.”
The AVPA remains committed to providing technical expertise to legislators and regulators, and if they determine that age assurance is required for any sector, we consistently argue for the adoption of international standards to deliver proportionate, privacy-preserving and genuinely effective implementation of age restrictions.