New York SAFE for Kids Act Age Verification Rules: What Platforms Must Do

Techwalla may earn compensation through affiliate links in this story. Learn more about our affiliate and product review process here.

New York SAFE for Kids Act Age Verification Rules: What Platforms Must Do

New York has finalized implementation rules for a child-safety law that may, in practice, require social media platforms to assess the age of every user in the state. The confirmed obligation is narrow but consequential: platforms must establish that a user is an adult before serving an algorithmic feed or a nighttime notification. Any user whose adult status hasn't been confirmed falls into scope by default.

Governor Kathy Hochul and Attorney General Letitia James announced the final rules yesterday. Published in the State Register today, they take effect 180 days later, on January 25, 2027, according to the Governor's office. Violations carry civil penalties of up to $5,000 per infraction, with the AG's office authorized to seek injunctions against noncompliant platforms.

Hochul signed the Stop Addictive Feeds Exploitation (SAFE) for Kids Act in June 2024. The law doesn't restrict content access; it targets the delivery mechanism. Algorithmic recommendation feeds and late-night push notifications are what state officials link to depression, anxiety, and sleep disorders in children and teenagers, per the Governor's office. Restricting those features for minors requires platforms to make a determination about every user they can't already confirm is an adult and that's where the scope of this rule expands well beyond its stated target.


Advertisement

Who the rules cover

Video of the Day

The law applies to what the rules term "Addictive Online Platforms": services that display user-generated content and on which users spend at least 20 percent of their time engaged with algorithmically curated feeds, measured over a rolling six-month period, per the Governor's office. The final rules establish criteria to clarify which platforms clear that threshold, though those specific criteria aren't detailed in the public announcements.

The scope question matters most for smaller and emerging services. The Computer & Communications Industry Association warned during the comment period that imprecise definitions could push companies to simply ban minors rather than build a compliant age-assurance system and absorb potential liability, according to the CCIA's comment letter. A rule that sweeps in dozens of niche platforms carries meaningfully different compliance burdens than one that lands only on the largest players.


Video of the Day

What platforms must do under New York's social media age-verification rules

Flowchart explaining New York SAFE for Kids Act age verification: platforms verify adult status before enabling algorithmic feeds or midnight-to-6 a.m. notifications, with unconfirmed users defaulting to non-algorithmic options or parental-consent paths

The confirmed requirement: platforms must determine that a user is an adult before providing algorithmic feeds or nighttime notifications, according to the New York AG's office. That obligation isn't limited to accounts that already appear to belong to teenagers. It attaches to any user whose adult status hasn't been established.

Platforms may use any age-assurance method that meets accuracy benchmarks and protects user data, per the Governor's office. During the proposed-rules phase last fall, the AG's office cited examples: requesting an uploaded image, or cross-referencing a verified phone number or email address against available data, as First Amendment Watch reported. Whatever method a platform selects must be tested annually, with results retained for at least five years both confirmed in this week's announcements, per the Governor's office.

Two provisions from the September 2025 proposed rule text are consistent with the confirmed framework but have not been explicitly verified in yesterday's announcements. The proposed rules required platforms to reclassify any account they gain actual knowledge belongs to a minor within 10 business days, per the proposed rule text. They also required platforms to review and update their parental consent methods at least annually, per the proposed rule text. Both appear likely to survive into the final text, but neither should be treated as settled until the full rules are reviewed.

The choice platforms must make. Nothing in the announced rules explicitly requires platforms to verify every account. But the structure is constraining. A platform that hasn't confirmed a user's adult status cannot legally serve that user an algorithmic feed. Three paths exist: verify the full user base; default all unverified accounts to non-algorithmic feeds and accept the product limitation; or do what critics warned and simply prohibit minors from the service rather than absorb compliance costs. Platforms have not indicated which approach they'll take, and the choice will shape how disruptive these rules prove in practice.

For confirmed minors who want algorithmic feeds or nighttime notifications, there's a parental-consent route. A minor can authorize the platform to contact a parent, at which point the platform must obtain verifiable consent, per the proposed rule text. The final rules confirm that minor users must also have a clear option to update their age status when they turn 18, per the Governor's office.


Advertisement

Advertisement

What users will see starting January 25, 2027

Side-by-side mock screens showing what users see after January 25, 2027: adults getting algorithmic feeds, unverified users prompted or restricted, minors without parental consent seeing chronological feeds and a midnight-to-6 a.m. notification blackout

Minors keep access to the platforms themselves. That's explicit in the final rules. What changes is how content gets surfaced to them and for adults, what platforms ask before serving a feed at all.

Users confirmed as adults remain eligible for algorithmic feeds and nighttime notifications as before, assuming the platform is otherwise compliant.

Users whose age hasn't been confirmed face a choice that depends on what the platform decides to build. On a platform that pursues full user-base verification, they may be prompted to confirm their age before regaining access to algorithmic feeds. On a platform that defaults unverified accounts to non-algorithmic feeds instead, they could find themselves on a chronological or follow-only view without being asked for any verification at all. Both outcomes are plausible under the rules; neither is mandated.

Minors without parental consent can still use the platform and see content from accounts they already follow, served in a fixed sequence such as chronological order. The algorithmic feed is off, as are notifications between midnight and 6 a.m. Platforms cannot cut them off entirely, per the Governor's office.

Minors whose parents have consented get access to algorithmic feeds and nighttime notifications. How smoothly that consent process works will depend on how each platform implements it.

New York's position is that content access stays intact for everyone; what changes is the recommendation layer. The CCIA, in its comments on the proposed rules, argued that broad age-assurance requirements will add friction for all users regardless of age, according to the CCIA. That argument applies most directly to the unverified-adult problem the large share of adult users who've never been asked for age confirmation and may now face a prompt to provide one.


Advertisement

Advertisement

Where the law gets messy

Privacy cuts both ways. New York says platforms can verify age using methods that keep user data protected. The CCIA's comment letter cited research finding that highly accurate age-assurance tools may require collecting new categories of sensitive personal information specifically facial imagery or government-issued identification creating their own privacy exposure, according to the CCIA. The final rules, as announced, don't appear to resolve that tension.

Nighttime notifications and location tracking. Enforcing a midnight-to-6 a.m. blackout requires knowing where a user's device is located. The September 2025 proposed rules required operators to draw on all reliable location-related information and take reasonable steps to detect users trying to conceal their location, per the proposed rule text. The CCIA argued that requirement effectively mandates location tracking of the very population the law is designed to protect, per the CCIA. Whether the final rules modified that language remains unclear from yesterday's announcements.

Accuracy and demographic fairness. Age-estimation tools don't fail evenly. Research cited in the CCIA's comment letter found that facial estimation tools misclassify users in both directions, with false positive rates generally higher for women than men and varying further across demographic groups, according to the CCIA. That's an industry-sourced concern, not an independently adjudicated finding, but it points to real implementation questions the annual accuracy-testing requirement will need to confront.

Legal headwinds. More than 20 states have passed age-verification laws, and many face active court challenges, First Amendment Watch reported last fall. An Arkansas court ruling, cited in the CCIA's comment letter, characterized parental-consent frameworks as imposing government authority over minors' speech rather than reinforcing parental rights a framing that could inform how New York's rules fare if challenged, per the CCIA. No litigation against the final rules has been announced, but the broader legal environment for this class of law remains contested.


Advertisement

Advertisement

What's confirmed and what isn't

The requirements confirmed in this week's announcements: covered platforms must establish adult status before serving algorithmic feeds or nighttime notifications; they must select age-assurance methods meeting accuracy and privacy standards; they must test those methods annually and retain results for five years; minors cannot receive algorithmic feeds without parental consent; and minor users must have a clear option to update their age status when they turn 18. Violations carry civil penalties of up to $5,000 per infraction, per the Governor's office.

The proposed-rule details that appear consistent with the final framework but still need verification against the full text: the 10-business-day window for reclassifying accounts after a platform gains knowledge a user is a minor, the annual review requirement for parental consent methods, and the location-based enforcement language for nighttime notifications. Treat all three as likely, not settled.

Beyond the text, the bigger open questions are practical. Will platforms verify all users, or restructure default feeds to avoid building out verification infrastructure? Will parental consent flows be straightforward enough that families actually use them, or friction-heavy enough to function as a de facto barrier? And will any legal challenges reach the courts before the January 25 deadline?

New York's approach is more targeted than most state-level frameworks, regulating algorithmic delivery specifically rather than platform access as a whole. More than 20 states are moving on similar legislation, according to First Amendment Watch. Whether New York's ruleset becomes the template others adopt, or the cautionary example they revise around, will depend on what the platforms actually build in the next six months.

Advertisement

Advertisement