
Meta and YouTube found liable for addictive design. What it means for platforms.
On 26 March 2026, a Los Angeles jury found Meta and Google's YouTube liable for deliberately building addictive platforms that harmed the mental health of a young user, known as Kaley, who had used Instagram from age nine and YouTube from age six. The jury awarded $6 million in damages on the basis that the companies had acted with malice, oppression, or fraud. The verdict came one day after a New Mexico jury found Meta liable for failing to protect child users from predatory contact.
These are not isolated incidents. Thousands of similar cases are working their way through US courts, with a further set of federal cases scheduled for trial this summer. The legal theory that addictive product design constitutes personal injury, once untested, now has jury validation behind it.
What the verdict establishes
The argument in Kaley's case drew directly from the Big Tobacco playbook: that companies knowingly engineered products to be addictive, were aware of the harms, and prioritised growth over user safety. Internal documents and testimony showed both firms knew children were using their platforms and understood the risks posed by features including infinite scroll, algorithmic recommendations, and autoplay.
Critically, the case succeeded not on the basis of what users posted, which is largely protected under Section 230, but on the basis of product design. Platforms cannot rely on content liability shields to insulate themselves from claims about the systems and features they build.
The implication for platforms
Until now, the commercial case for proactive risk assessment and safety-by-design has rested on two pillars: avoiding regulatory fines and avoiding reputational damage. This verdict introduces a third, and arguably more immediate, exposure: civil liability at scale.
The question a court will ask is not only whether harm occurred, but whether the platform knew harm was possible and what it did about it.
This is not a US-specific concern. The UK Online Safety Act already requires services likely to be accessed by children to complete a Children's Risk Assessment. The regulatory logic and the litigation logic are converging on the same requirement: that platforms understand and document the risks their products create, and act on that understanding.
What platforms should be doing now
The immediate priority is to treat risk assessment as a substantive governance process, not a documentation exercise.
- Evaluate design features, not just content, for their potential to cause harm to child users.
- Maintain clear records of how risk conclusions were reached and what mitigations were put in place.
- Review assessments when the product changes, and keep pace with regulatory updates.
The verdict illustrates that documentation alone is not a defence. What the jury found wanting was not knowledge, but response. Platforms must be able to demonstrate that risk assessments are embedded in product decision-making: that identified risks are escalated, considered, and either mitigated or consciously accepted with a documented rationale.
Related Articles
Children's access to online services: a governance framework for compliance
"Likely to be accessed by children?" Children's access is shaping global online safety regulation. Here is how platforms can assess access in a defensible, regulator-ready way.
Online Safety Act compliance: a framework for better risk assessments
What we learned from reviewing Ofcom's response to platforms' first attempts at Online Safety Act risk assessments, distilled into eight steps that meet the regulator's expectations.
The Children's Risk Assessment deadline has arrived. What you need to know.
In-scope services must now demonstrate they have assessed the risks their platforms pose to children, and taken action to mitigate them. We break down what the Children's Risk Assessment involves and who it applies to.