The court never mentioned your adverts. It did not need to
A New Mexico judge ordered Meta to pay $567 million and to get better at guessing how old you are. He pointedly declined to touch advertising. The advertising consequences arrive regardless.
By Katie Delaney · 2026-08-07 · 13 min read
What the court ordered, and what it refused to#

A fox judges a fence by where it is weakest, not where it is tallest. The reporting on this ruling has concentrated on the number. The number is the least interesting part.
On 6 August 2026, Chief Judge Bryan Biedscheid of the First Judicial District Court in Santa Fe entered final judgment in State of New Mexico against Meta Platforms, ordering the company to pay and deposit a total of $567,000,000 into a fund. The 68-page judgment allocates it precisely: $420 million to treatment, $90 million to screening and assessment, $33 million to awareness and prevention, $15 million to referral and coordination, and $9 million to implementation and evaluation.
That follows a jury verdict in March 2026 which found 75,000 violations at the maximum $5,000 each, for a total of $375 million, bringing the combined figure to $942 million. Attorney General Raúl Torrez called it a landmark victory. Meta said it remains confident in its record of protecting teens online and will continue to defend itself against claims it says misrepresent the facts, per PBS News.
The part every marketing summary has got wrong#
Here is the correction worth making loudly, because a great deal of commentary this week has implied otherwise. The order contains no advertising remedy at all. The court expressly declined to order changes to algorithms, autoplay or infinite scroll, holding that those raise Section 230 and First Amendment implications, and reasoning that industry-wide feature regulation requires legislative or executive action, as Tech Policy Press sets out.
What the court did order sits under a heading called Age Assurance. Meta must continue improving its age assurance models and tools in New Mexico, using AI to enhance its heuristics with additional signals, and attempting to develop, within two years, a dedicated under-13 prediction model, using reasonable best efforts in light of COPPA limitations.
Read those qualifiers honestly. Attempting to develop. Reasonable best efforts. This is a softer obligation than the headlines suggest, and anyone telling you Meta has been ordered to build an under-13 detector is overstating it.
Why age assurance is a targeting setting in disguise#
Advertisers tend to file age assurance under trust and safety, somebody else's department, two floors down. That filing is the mistake, because classification is the gate through which every targeting option passes. The quarry has not moved; the fence around it has.
Once Meta treats a person as under 18, its own advertising rules for teen audiences strip most of the toolkit. This is where a widely repeated claim needs correcting: the surviving options are not age, gender and location. Gender is explicitly removed.
What actually remains is age and a location no smaller than a city. Removed worldwide are gender, postcodes and custom radius or pin-drop targeting, all detailed targeting covering interests, behaviours and demographics, language, every custom audience type including website, app, customer list, engagement and offline activity, and all lookalike audiences.
| Capability | Status for under-18 audiences | Practical effect |
|---|---|---|
| Age and city-level location | Available | Essentially all that is left of targeting |
| Gender | Removed | Contradicts the commonly repeated summary |
| Detailed targeting and interests | Removed | No behavioural or demographic layer |
| Custom audiences and lookalikes | Removed | First-party data stops working entirely |
| Most optimisation goals | Removed | No leads, value, landing page views or conversations |
| EU, EEA and Switzerland delivery | Not permitted at all | Ads cannot deliver to under-18s, since November 2023 |
Note the last row. In the EU, EEA and Switzerland, ads simply cannot deliver to audiences under 18. There is no reduced-targeting version. A misclassified user in Malta or Munich is not a harder person to reach, they are an unreachable one.
This is not a Meta idiosyncrasy either. Google's ad protections for children and teens disable ads personalisation and restrict sensitive categories for users under the digital age of consent, with further restrictions for under-18s above it. Two platforms, one direction of travel.
So the chain runs like this, and it never passes through a courtroom: age assurance decides classification, classification decides available targeting, available targeting decides reach and efficiency. The judgment strengthened the first link. The rest were already welded on.
The accuracy problem nobody prices into the plan#
If classification were perfect, this would be a story about teenagers. It is not perfect, and that is why it is a story about adults. This is the undergrowth the numbers hide in.
The most rigorous public evaluation is NIST's ongoing Face Analysis Technology Evaluation of age estimation, with results last updated on 29 July 2026. It reports accuracy as mean absolute error, and its own colour coding tells the story: green shading begins below two years of error, while yellow, pink and red mark errors above 3.5, 4.25 and 5 years.
The trend is genuinely positive. NIST's 2024 evaluation, covering about 11.5 million photographs across four government databases, found mean absolute error on the common visa dataset had fallen from 4.3 years in 2014 to 3.1 years in 2024. Five of six algorithms beat the best 2014 submission.
Three point one years. Now put that next to a boundary at eighteen and a rule that resolves uncertainty downward, and the consequence is arithmetic rather than opinion: a meaningful population of genuine adults in their late teens and early twenties will be classified as minors and stay there until they verify.
NIST adds a finding that should concern anyone with a female-skewed audience: error rates were almost always higher for female faces than for males. A classification system with uneven error does not shrink your audience evenly.
The other half of the accuracy problem runs the opposite way. Ofcom-commissioned research by Yonder Consulting, surveying 1,039 social media users aged 8 to 17 with fieldwork in July 2022, found that a third of children aged 8 to 17 with a social media profile hold an adult user age, having signed up with a false date of birth. Among 8 to 12 year olds, 23% had an 18-plus user age. That fieldwork is now four years old, so date it rather than presenting it as current, but the direction is unlikely to have reversed.
Read the two findings together and the picture is uncomfortable for a media plan, whichever way you follow the trail. Some of the adults you are buying are children who lied, and some of the children the system now blocks are adults it could not read.
The net is tightening from four directions#
One American judgment would not move a global media plan. What makes this worth your attention is that four regulators are prowling the same ground at once, and none of them needed the New Mexico case to start.
In the United Kingdom, Ofcom's guidance on highly effective age assurance defines the standard and names what fails it: self-declaration of age is not highly effective, and neither are payments that do not require the payer to be 18. Its Protection of Children Codes, in force from 25 July 2025, carry the line that matters most commercially: services with minimum age requirements that are not using strong age checks must assume younger children are present and provide an age-appropriate experience.
That is a default-to-caution rule applied to an entire service, not to an individual. It is how a platform ends up treating ambiguous users as young in bulk.
The Information Commissioner's Office has now put a price on getting it wrong, fining Reddit GBP 14.47 million on 24 February 2026 for failing to apply any robust age assurance mechanism, per the ICO. Commissioner John Edwards was direct: relying on users to declare their age themselves is not enough when children may be at risk, and the regulator is focusing on companies primarily using that method.
In Brussels, the European Commission adopted guidelines on the protection of minors under Article 28(1) of the Digital Services Act on 14 July 2025, recommending age verification for adult content and age estimation where risks are identified. Article 28(2) of the DSA carries the harder rule: platforms must not show advertising based on profiling where they know with reasonable certainty that the recipient is a minor. Enforcement is live, with preliminary findings issued to TikTok on 24 July 2026 that minors' accounts do not meet DSA safety standards.
In the United States, the amended COPPA Rule sets a compliance date that has already passed. The Federal Register text states that regulated entities had until 22 April 2026 to comply, with the FTC's rule amendments tightening how children's data may be monetised.
Five moves for a paid social strategy that holds#
The size of the prize is real, which is why this will keep tightening rather than settling. A peer-reviewed simulation study from the Harvard T.H. Chan School of Public Health, published in PLOS ONE, estimated nearly $11 billion in annual US advertising revenue from users aged 0 to 17 across six platforms, with Instagram at $4.8 billion, YouTube at $2.2 billion and TikTok at $2.0 billion. Its base year is 2022 and it is a model rather than measured spend, so treat it as an order of magnitude.
So, five moves. None require a legal opinion and all of them survive whichever way the appeal goes.
First, stop reading reach declines as creative fatigue by default. If a lookalike audience or a customer-list match rate has drifted downward without an obvious cause, classification is now a candidate explanation alongside the usual suspects. We covered the adjacent mechanism in your audience segments started quietly deleting themselves.
Second, separate youth marketing from youth-adjacent marketing#
Plenty of brands do not target under-18s and still get caught, because their audience skews young at the hedgerow edges. A university-town campaign, a gaming brand, a music festival: all of these sit close enough to the boundary that misclassification bites. Establish which campaigns are genuinely youth marketing and which merely border it, because the mitigations differ completely.
Third, build a verified-audience path for the people you actually want. Age verification converts an ambiguous user into a confirmed adult, which restores full targeting. That is a product and lifecycle job rather than a media-buying one, and it is the only durable answer to a default that resolves downward.
Fourth, treat the EU as a separate plan rather than a discount. In the EU, EEA and Switzerland the under-18 audience is not reduced, it is absent, so any pan-European buy needs its youth-adjacent budget modelled separately or it will simply underdeliver.
Customer list match rate
Track the trend, not the level. Sustained drift is the early signal.
18-24 reach index
The band where misclassification concentrates. Compare against 25-34.
Verified-adult share
If your product can verify age, this is the metric that restores targeting.
Fifth, get your own house in order before a regulator asks. Meta published its AI age assurance approach in May 2026, three months before the ruling, and followed it with a Teen Accounts update in June. The platforms are moving ahead of the courts, not behind them, and advertisers who wait for a rule to be handed down will be adapting a year late.
We disagree with the ruling and will appeal. We work hard to keep people safe on our platforms and have been transparent about the challenges of identifying and removing bad actors and harmful content.
For current behaviour rather than assumption, Pew Research Center's April 2026 survey of 1,458 US teens, fielded in autumn 2025, is the most recent methodology-stated source worth reading. It covers experiences among users rather than adoption rates, so do not lift reach percentages from it.
The fox does not test the ice by walking to the middle. Age assurance is the quiet mechanism that decides who your advertising is allowed to find, and it has been strengthened this month by a court that never mentioned advertising once.
If you want the paid social strategy rebuilt around what is actually addressable, that is what folkfox paid social does, alongside brand strategy and healthcare marketing, where age-gated audiences have been a constraint far longer than the rest of the market has noticed. The cost side is in Meta put its prices up 20 per cent, and the creative side in the platforms just made AI slop a distribution problem.
Frequently asked questions#
Did the New Mexico ruling change Meta's advertising rules?
No. The judgment ordered a $567 million fund and improvements to age assurance, but contains no advertising remedy. The court expressly declined to order changes to algorithms, autoplay or infinite scroll, citing Section 230 and First Amendment implications.
What targeting is available for under-18 audiences on Meta?
Age and a location no smaller than a city. Gender, detailed targeting, language, all custom audiences and lookalike audiences are removed, along with most optimisation goals. In the EU, EEA and Switzerland ads cannot deliver to under-18s at all.
How accurate is facial age estimation?
NIST measured mean absolute error falling from 4.3 years in 2014 to 3.1 years in 2024 on the same dataset. That is real progress, but an error of about three years across an eighteen-year boundary still misclassifies a meaningful number of young adults.
The NIST data on accuracy is fresh from 14 August, and the Challenge-T buffer policy adds nuance.
Why would age assurance shrink my adult audience?
Because uncertainty now resolves downward. Where a platform believes a user may be under 18 but cannot estimate precisely, it treats them as under 18 until they verify, so adults the model cannot read confidently lose full targeting eligibility.
Is self-declared age still acceptable to regulators?
No. Ofcom states self-declaration is not highly effective age assurance, and the ICO fined Reddit GBP 14.47 million in February 2026 for lacking a robust mechanism, with the Commissioner saying reliance on self-declaration is not enough.
What should advertisers actually do about this?
Track customer list match rates and 18-24 reach for drift, separate genuine youth marketing from youth-adjacent campaigns, plan the EU separately because under-18 delivery is prohibited there, and build a verified-adult path if your product allows one.
Read more on this topic#
On 1 August, your audience segments started quietly deleting themselves
The other mechanism quietly shrinking addressable audiences this quarter.
Read the pieceGoogle shipped an age signal your marketing team may not touch
The same classification logic arriving on the app store side.
Read the pieceMeta put its prices up 20 per cent in North America and nobody blinked
What rising costs do to a plan that is also losing targeting precision.
Read the pieceThe platforms just made AI slop a distribution problem
When creative has to do the qualifying, its quality stops being cosmetic.
Read the piece
Want to know how much of your audience is still addressable?
folkfox rebuilds paid social plans around what platforms will actually let you reach, with the classification risk measured rather than assumed, and the creative rewritten to do the qualifying.