On July 28, 2026, the New York Office of the Attorney General released final rules (the “Rules”) implementing the Stop Addictive Feeds Exploitation (SAFE) for Kids Act, which goes into effect on January 25, 2027.

The SAFE for Kids Act requires online “addictive social media platforms,” which are defined as websites, online services, and applications that offer an “addictive feed” as a significant portion of their services, to restrict providing an “addictive feed” and nighttime notifications for minor users unless they obtain verifiable parental consent.

The Rules establish detailed requirements, including age-assurance standards and parental-consent mechanisms. Some of the key provisions of the Rules are described below:

  • Scope and Applicability. The Rules interpret the “significant portion” standard of the statute’s “addictive social media platforms” definition to mean an online platform where 20% or more of time spent by monthly active users is spent on “addictive feeds” measured over any six-month period. An “addictive feed” is defined to mean an online platform, or portion thereof, in which multiple pieces of media are shared or generated by users, and concurrently or sequentially, recommended, selected, or prioritized for display to a user based on (1) information persistently associated with the user or the user’s device; or (2) the user’s previous interactions with user-generated content including the user’s interactions on different online platforms, media, or the pages, groups, or other user-generated media the user requests, subscribes to, or otherwise selects. Certain conduct is excluded from the definition of “addictive feed,” including recommendation in response to a search inquiry, recommendation in response to express and unambiguous requests for certain media, recommendation based on privacy and accessibility settings, and display of private communications.
  • Age Assurance Standards. At least one method for both age assurance and an appeal must not require a government-issued ID. However, each method must be certified annually to meet the accuracy standards set forth in the Rules, which set a high bar. The certification process involves testing of false positive rates; rate of inconclusive age assurance outcomes; false negative rates; detection of method circumvention; data collection, segregation, and deletion measures; data encryption and security measures; and, determination of whether it meets the accuracy minimum and total accuracy minimum.
  • Recordkeeping requirements.  The Rules also impose certain recordkeeping obligations on operators. As part of the certification process for age assurance methods, operators must maintain copies of all test results, reports, and certifications generated in compliance for no less than 10 years. Operators must also maintain records for no less than 5 years, where applicable: (1) the fact that an age assurance method was attempted on a user; (2) the age assurance method that successfully confirmed age status; (3) the date when the determination of age status was conducted; (4) the user’s age status; (5) information collected for compliance with these requirements; and, (6) data related to each age assurance method utilized on a month-by-month basis (e.g., total number of covered users: who attempted to confirm age status using that method; were successfully age-determined; were reclassified from adult to minor status; and, were denied adult status due to method circumvention).
Print:
Email this postTweet this postLike this postShare this post on LinkedIn
Photo of Lindsey Tonsager Lindsey Tonsager

Lindsey Tonsager is a recognized leader in representing companies before federal and state regulators, and is renowned for advising on minor protection, AI, and state comprehensive privacy laws.

Lindsey chairs the firm’s global Data Privacy and Cybersecurity practice. She advises clients in their…

Lindsey Tonsager is a recognized leader in representing companies before federal and state regulators, and is renowned for advising on minor protection, AI, and state comprehensive privacy laws.

Lindsey chairs the firm’s global Data Privacy and Cybersecurity practice. She advises clients in their strategic and proactive engagement with the Federal Trade Commission, the U.S. Congress, the California Privacy Protection Agency, and State Attorneys General on proposed changes to data protection laws, and regularly represents clients in responding to investigations and enforcement actions involving their privacy and information security practices.

Lindsey’s practice focuses on helping clients launch new products and services that implicate the laws governing the use of artificial intelligence; data processing for robotics, autonomous vehicles, and other connected devices; biometrics; online advertising; the collection of personal information from children, teens, and students online; e-mail marketing; disclosures of video viewing information; and new technologies.

Lindsey also assesses privacy and data security risks in complex corporate transactions where personal data is a critical asset or data processing risks are otherwise material. In light of a dynamic regulatory environment where new state, federal, and international data protection laws are always on the horizon and enforcement priorities are shifting, she focuses on designing risk-based global privacy programs for clients that can keep pace with evolving legal requirements and efficiently leverage the clients’ existing privacy policies and practices. She conducts data protection assessments to benchmark against legal requirements and industry trends and proposes practical risk mitigation measures.

Photo of Jenna Zhang Jenna Zhang

Jenna Zhang advises clients across industries on data privacy, cybersecurity, and emerging technologies. 

Jenna partners with clients to ensure their compliance with the rapidly evolving federal and state privacy and cybersecurity laws. She supports clients in designing new products and services, drafting privacy…

Jenna Zhang advises clients across industries on data privacy, cybersecurity, and emerging technologies. 

Jenna partners with clients to ensure their compliance with the rapidly evolving federal and state privacy and cybersecurity laws. She supports clients in designing new products and services, drafting privacy notices and terms of use, responding to cyber and data security incidents, and evaluating privacy and cybersecurity risks in corporate transactions. In particular, she advises clients on substantive requirements relating to children’s and student privacy, including COPPA, FERPA, age-appropriate design code laws, and social media laws.

As part of her practice, Jenna regularly represents clients in data privacy investigations and enforcement actions brought by the Federal Trade Commission and state attorneys general. She also supports clients in proactive engagement with regulators and policymakers to ensure their perspectives are heard.

Jenna also maintains an active pro bono practice with a focus on supporting families in adoptions, guardianships, and immigration matters.

Photo of Irene Kim Irene Kim

Irene Kim is an associate in the firm’s Washington, DC office, where she is a member of the Privacy and Cybersecurity and Advertising and Consumer Protection Investigations practice groups. She advises clients on a broad range of issues, including U.S. state and federal…

Irene Kim is an associate in the firm’s Washington, DC office, where she is a member of the Privacy and Cybersecurity and Advertising and Consumer Protection Investigations practice groups. She advises clients on a broad range of issues, including U.S. state and federal AI legislation, comprehensive state privacy laws, and regulatory compliance matters.