California has moved to restrict some of the most habit-forming features used by social-media platforms, with Governor Gavin Newsom signing new laws designed to reduce online risks for children.
The legislation prohibits platforms from offering users under 16 certain addictive features, including autoplay and personalised algorithmic feeds built around a user’s history and profile. It forms part of a wider package covering AI chatbots, children’s privacy and online exploitation.
The state says the measures are intended to shift responsibility away from parents having to police every app and towards technology companies designing safer products from the beginning.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
Autoplay and personalised feeds come under scrutiny
The most direct social-media measure is Assembly Bill 1709.
California already had restrictions on providing addictive feeds to minors without parental consent. The new law goes further by targeting features that can keep younger users continuously engaged with a platform.
Autoplay is one example.
Instead of requiring a child to actively choose another video, the platform automatically begins playing the next piece of content.
Algorithmic feeds work differently.
They analyse what a person watches, clicks, likes or spends time viewing and then continuously select new posts designed to match those interests.
For adults, these features can make an app more convenient. For children, regulators increasingly argue that the same systems can encourage excessive use by creating an effectively endless stream of personalised content.
California’s new legislation specifically prohibits covered social-media platforms from providing users under 16 with addictive features such as autoplay and feeds based on their profile or previous behaviour.
This is part of a much broader child-safety package
The social-media restrictions were signed alongside a series of laws dealing with artificial intelligence and children’s data.
One of the most significant is Senate Bill 1119, known as Adam’s Law, which creates a more detailed regulatory framework for AI companion chatbots used by children.
Companion chatbots are AI systems designed to simulate ongoing personal relationships rather than simply answer isolated questions.
Under the new framework, operators must introduce child-safety controls, crisis-response procedures for suicidal or self-harm-related conversations and parental safeguards. The law also restricts targeted advertising and the sale or unnecessary use of children’s personal information gathered through chatbot conversations.
Independent safety audits are another major requirement.
The law requires operators to assess whether their systems create foreseeable risks to children and, over time, undergo independent reviews of their safeguards. Key provisions begin becoming operative from July 1, 2027.
Why regulators are targeting product design instead of only harmful posts
For years, debates around child safety online focused mainly on dangerous content.
The newer approach looks at the architecture of the platform itself.
The argument is that even harmless videos or posts can become problematic when software is deliberately designed to maximise the amount of time a child spends scrolling.
California began moving in this direction in 2024 when Newsom signed SB 976, which restricted addictive feeds for minors without parental consent and limited notifications during school hours and late at night.
The latest legislation pushes that model further.
Rather than asking only whether a piece of content is harmful, regulators are asking whether features such as endless feeds, autoplay and personalised recommendations create unhealthy patterns of use.
That distinction could have wider implications for companies such as Meta, TikTok, YouTube and other platforms if similar rules spread beyond California.
California is also tightening AI and privacy protections
Newsom’s package covers considerably more than social media.
California says the legislation strengthens privacy protections against targeted advertising to children, regulates the use of K-12 pupil information in AI systems and expands child sexual exploitation laws to cover digitally altered and AI-generated material involving minors.
The state had already passed another package in 2025 requiring social-media warning labels, new age-verification measures and stronger safeguards around AI chatbot interactions with minors.
The result is an increasingly layered regulatory approach.
Companies may have to determine a user’s age, alter how recommendations work for children, restrict certain advertising, provide parental controls and subject some AI products to formal safety assessments.
Newsom has described this as a question of responsibility rather than opposition to technology.
For technology companies, however, the practical challenge will be implementing child-specific restrictions without collecting excessive personal information simply to determine whether a user is a minor.
That tension between privacy and age assurance is likely to remain one of the central questions as more governments attempt to regulate children’s online experiences.
What this means for you: For parents, the law could eventually mean fewer automatic feeds and stronger controls when children use social-media or AI companion services in California. It also shows the direction regulation is moving globally: platforms are increasingly being expected to make child safety part of their product design rather than leaving the entire burden on families.
The420 Insight: California is moving the debate from “what harmful content should be removed?” to “which product features should children never receive in the first place?” If that approach spreads, autoplay, endless recommendation feeds and highly personalised engagement systems could become the next major battleground in social-media regulation.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics