August 27, 2026

Child safety design is now a director liability question in New Zealand

A close-up shot of smartphone displaying social media apps icons on screen.

A settlement that reprices platform risk

On 26 August 2026, Meta agreed to pay up to US$18 billion, around NZ$30 billion, to settle child safety claims brought by 48 US states, Washington DC and several territories. The deal ended a federal trial in Oakland that had opened only the previous week, with Mark Zuckerberg among the witnesses expected to testify.

For scale, that is roughly 9% of Meta’s 2025 revenue of US$201 billion. Investors treated it as a bargain: Meta shares rose about 1.5% on the news. Against the US$1.4 trillion the four trial states alone had sought, a discounted certainty beat an open-ended trial.

The money is not the story for New Zealand businesses. What Meta agreed to do is.

Design features are now legal obligations

The settlement forces Meta to build in default two-hour daily time limits for teens, remove push notifications during school hours, run a night mode blocking alerts between midnight and 6am, deploy “robust” age-assurance, strip social comparison features such as like counts, disable cosmetic surgery filters and submit to an independent auditor. California attorney general Rob Bonta called it “real change, real transparency, real protections for children and teens across the country.”

Meta framed it as leadership, saying it had “partnered with state attorneys general to set a new industry standard”. Tellingly, 30% of the payout, about US$5.3 billion, only releases if YouTube and TikTok adopt similar features and pay in. Meta has effectively weaponised a settlement to drag competitors into the same compliance net.

Not everyone bought it. Florida’s attorney general refused to join, arguing the “payouts are peanuts compared to the profound harms”. New Mexico was excluded because it already won: a jury found Meta liable, and a judge later ordered US$567 million into a child mental health fund on top of US$375 million in penalties.

New Zealand moved the same week

The timing is remarkable. One day before the settlement, on 25 August 2026, the government introduced the Online Safety (Minimum Age and Child Safety Risk Assessment) Bill, banning social media for under-16s and requiring high-risk platforms to take reasonable steps to verify age, run regular child safety risk assessments, and answer to a new independent regulator.

The enforcement mechanism is the number that should focus boardrooms: penalties of up to 10% of global annual revenue. Applied to Meta’s 2025 figures, that is roughly US$20 billion, more than the entire US settlement. A March 2026 select committee inquiry found there were no legal requirements for platforms to proactively implement safety measures. The bill ends that.

These platforms are not fringe. 58% of New Zealanders use Facebook daily and 47% use Messenger daily, per InternetNZ’s December 2025 survey of 1,003 people. This is core business infrastructure, not a teen novelty.

The liability gap most coverage misses

Here is where it gets uncomfortable for directors. A single failure in an age-assurance system triggers three legal exposures at once: regulatory action under the new bill, privacy claims under the Privacy Act 2020, and director liability over what the board approved. Those land across three different insurance lines, management liability, cyber, and technology errors and omissions, each with its own exclusions and limits.

The distinction is not academic. A system that was adequate at launch but failed in operation is a technology E&O question. A system that was never adequate is a directors and officers question about what the board signed off. A system that was breached is a cyber question. One regulatory finding can touch all three, and the insurance market has not settled how to price it.

TUANZ chief executive Craig Young argued for a “Security by Design philosophy where trust is earned because safety is an inherent, built-in feature of digital services, not an optional extra”. That is now a compliance instruction, not a slogan.

Whether the ban works is almost beside the point

Researchers are candid that a ban will leak. Dr Cassandra Mudgway of the University of Canterbury cited Australian data showing over 80% of 10 to 15-year-olds still used social media three months after its ban. Dr Rachel Tan of the University of Waikato called it “an important first step” that “adds friction” and shifts norms even if it is not fully effective.

The political appetite has hardened. Dr Samantha Marsh of the University of Auckland said in August 2026 that “our kids are precious and their brains are precious and currently these products have not been shown to be safe for them”, noting around 90% of young New Zealanders use social media and 22% meet criteria for problematic use.

For advertisers, agencies, app developers and any SaaS firm whose product could reach a minor, the message from Oakland and Wellington is the same in the same week. Child safety design is no longer reputational goodwill. It is a compliance obligation with a 10% penalty attached and a director’s personal exposure sitting behind it. The businesses that treat the risk assessment as a standing discipline rather than a one-off form will be the ones whose insurers still take their calls.

Sources

Community

Join the discussion

Add useful context, ask a good question, or challenge an idea — keep it specific and respectful.

Create a commenter account

Enter the name you want shown publicly and your email. We will email you a password-set link; you cannot comment until you use it.

Your email is used for sign-in and account security. It is not published with comments.

Subscribe for weekly news

Subscribe For Weekly News

* indicates required