SEPTEMBER 7 — Last month, Meta agreed to a settlement with 48 US states over claims that its social media platforms, Facebook and Instagram, violated federal child privacy laws and state consumer protection laws. Although it did not admit wrongdoing, Meta agreed to pay up to US$18 billion (RM72.9 billion) (the exact amount depends on certain conditions being met) to the states and also agreed to make changes to its platforms to improve youth online safety.

These changes include setting a default daily use limit of two hours for users under 18, restricting notifications during certain hours and hiding reactions (such as “likes”) for teenage users. These settings can be turned off by users but defaulting them to opt-out rather than opt-in is a step in the right direction to reduce engagement and improve online safety. These changes will be rolled out in the next six months, with improved age verification to follow in the next year for teenage users in the US.

Platform providers are unlikely to want to curtail these design features that maximise prolonged engagements and thus profits. — AFP pic
Platform providers are unlikely to want to curtail these design features that maximise prolonged engagements and thus profits. — AFP pic

What implications, if any, does this settlement have for users in Malaysia, where the under-16 social media ban came into effect 1 June 2026? Three months later, this ban seems to have little impact, as platforms have been given a grace period of six months to set up age verification protocols and remove accounts of users under 16.

It is expected that existing users thought to be under 16 and new registering users will have to scan government-issued identification to verify their age, similar to verification protocols used by financial institutions. Personal data privacy concerns have been countered by assurances that social media platforms will only verify age information and then delete the personal information. However, evidence from Australia suggests that teenagers are finding ways of getting around age restrictions. 

The debate around whether an age-based ban is implementable, enforceable or effective continues, but the Meta settlement reignites a broader online safety discussion. It shifts the regulatory focus from keeping users away from potential sources of harm and towards requiring platforms to implement safety by design, a principle already embedded in the Online Safety Act 2025.

The Meta settlement implies that a Big Tech company can be held liable for how their product design, such as infinite scrolling and social reward mechanisms, can endanger users. If one company can be held liable, so can others.

On one hand, the settlement allowed Meta to avoid an expensive trial with negative publicity, whatever the outcome. On the other hand, Meta acknowledged what technology policy experts have long been saying, that there are product design decisions and safeguards platform providers can make to improve online safety instead of simply denying responsibility for the content created and shared by individual users on their platforms.

The safety by design framework in the Child Protection Code of the Online Safety Act focuses on age-appropriate protections such as limiting exposure to harmful content and exploitative actions. Meanwhile the Risk Mitigation Code includes advertiser verification and labelling of manipulated and AI-generated content.

However, the changes Meta has agreed to implement in its settlement suggest that the platform itself can – and should be – regulated as a product. Regulating platforms requires policymakers to also expand their focus from content (what is on the platform) to code (how the platform is designed).

Two significant design features are notably absent from the safety measures Meta is planning to roll out in the US. The first is customised feeds and the second is infinite scroll.

Customised feeds use algorithmic recommendations to finetune content shown to users, intending to align content with user preferences. While these can introduce new content to users, over-customisation can lead to echo chambers reinforcing a particular worldview or state of mind, increasing confirmation bias and potentially reinforcing misinformation. Furthermore, customised feeds are designed to increase engagement, for example by showing shocking content that is more addictive. In extreme cases, this can lead to radicalisation.

Infinite scroll automatically loads the next few pieces of content when a user scrolls to the bottom of the page. This creates a continuous stream of content that encourages prolonged engagement by offering a constant supply of new information and dopamine hits. By removing stopping points, infinite scroll can encourage addictive behaviour, affecting mental health as well as reducing attention spans.

Both these features are relatively recent innovations of the attention economy. Earlier versions of social media feeds were user-curated, where content from creators and sources chosen by the user appeared chronologically with limited algorithmic recommendations. Feeds also had natural stopping points, determined by number of posts, followers or timespan. It is a simple technical matter to bring back these earlier designs, which would return some control to the user.

Platform providers are unlikely to want to curtail these design features that maximise prolonged engagements and thus profits. Nonetheless, the Meta settlement shows that collective action supported by evidence can apply enough pressure to yield results. Malaysia’s current online safety legislation permits regulators to demand more accountability from platforms. Policymakers looking to improve online safety should take note. 

*Rachel Gong is an Associate Director of Research at the Khazanah Research Institute. Her work focuses on digital policy, technology and society. The views expressed here are those of the author alone.

**This is the personal opinion of the writer or publication and does not necessarily represent the views of Malay Mail.