On 10 September 2026, Texas District Judge Cory Liu granted summary judgment against TikTok under the Texas Deceptive Trade Practices Act. Texas Attorney General Ken Paxton had filed the case in January 2025. The court resolved liability before trial, leaving only penalties and operational remedies for the next phase, which is listed for October (TechRepublic, ruling PDF).
Read the two findings carefully, because neither one is about failing to protect children.
The first is about content removal. TikTok said publicly that material breaking its Community Guidelines would be taken down. Internal moderation instructions told reviewers to sort some of that material as “hard to find” instead of “do not allow”. The court found that this internal sorting let rule-breaking material stay on the network while the public statement said it would not.
The second is about Restricted Mode, the parental control TikTok puts at the front of its safety messaging. The court found it did not work the way it was promoted. Internal discussions quoted in the filings have staff saying the tool “exposed users to a high amount of content that should have been filtered out”.
The violation in both cases is the distance between what the company said the control did and what the control did. Not the absence of a control. The gap.
If you run an age gate, you have written that same kind of sentence somewhere. Probably several times, on pages owned by several teams, none of whom read your false negative rate.
Why this is a different kind of exposure
Most of what we write about here is regulatory. Ofcom’s codes, the DSA, COPPA, the state age-verification statutes. Those share a shape: a regulator defines a standard, you build to the standard, the regulator checks.
Consumer protection law works differently, and in three ways that matter.
It does not need a sector rule. The Texas DTPA is a general statute about deceiving consumers. It applies whether or not any age-verification law covers you. A platform in a US state with no age-assurance statute at all can still be liable for describing an age control that does not behave as described.
The standard comes from your own words. Under a regulation, the bar is set by the regulator and is the same for everyone. Under consumer protection law, you set your own bar when you publish the claim, and you’re measured against it. A modest, accurate claim is safe. An impressive, loose one is a liability you wrote yourself.
Internal documents are the evidence. Both Texas findings rest on internal material: moderation instructions and staff discussions. Your Slack thread about the false negative rate, your post-incident review, your product ticket saying estimation is passing 16 year olds at the 18 line, all of that is discoverable and all of it dates from before the marketing page was written.
The FTC has the same tool federally in Section 5 of the FTC Act, which covers deceptive acts and practices. It’s already being pointed at this area: the Digital Childhood Institute’s 2026 complaint to the FTC about Apple’s parental controls pleads Section 5 deception alongside COPPA (Tech Policy Press). Whether that complaint goes anywhere is a separate question. The theory is the point.
Outside the US the equivalents already exist and are being used. In the EU, the Unfair Commercial Practices Directive treats a misleading claim about the main characteristics of a service as a misleading action. In the UK, the Digital Markets, Competition and Consumers Act gave the Competition and Markets Authority direct enforcement powers over consumer protection breaches, so a misleading safety claim no longer has to go through a court first. In Australia, section 18 of the Australian Consumer Law covers misleading or deceptive conduct in trade, and the Australian Competition and Consumer Commission has spent years applying it to digital products.
So this is not one Texas judge. It’s a route to liability that exists in every market you sell in, and it does not care whether an age-assurance regulator has reached you yet.
Then Meta put an auditor on it
Two weeks before the TikTok ruling, on 26 August 2026, Meta settled with 52 attorneys general for $18 billion. Just over $17 billion covers the suit brought by 29 states in 2023 (CNN, TechCrunch).
The money is paid over ten years, which softens it considerably against Meta’s revenue. The interesting part is the obligations.
Meta must run a default two hour daily screen time limit, with prompts every 15 minutes. Accounts it identifies as minors are blocked from the apps between midnight and 6am and have notifications muted between 8am and 3pm. Teens don’t see like counts by default. Meta must develop, train and begin testing a model to detect users under 13. The commitments run for ten years. An independent auditor checks compliance. And roughly 30% of the payment depends on whether TikTok and YouTube adopt the same guidelines.
Every one of those measures depends on knowing which accounts belong to minors. That’s the observation TechCrunch led with, and Dr Alexis Ingber put it plainly in that piece: the design changes look good on paper and all of them rest on age verification that does not currently work well enough to carry them.
For everyone who isn’t Meta, the useful detail is the auditor. A settlement of this kind does something a regulation does not. It appoints someone whose job is to open the system and check whether the stated measure is running, on a schedule, for ten years. That’s a much harder test than an annual compliance statement. It is, roughly, the Texas question asked continuously instead of once in litigation.
Both events point the same way. The claim and the behaviour are being compared by people with subpoena power.
Where your age-assurance claims actually live
Teams tend to think of this as a marketing problem and check the marketing page. The claims are spread much wider than that, and most of them were written by someone who has never seen the numbers.
The product marketing page. “Verified adults only.” “We verify every user’s age.” Written by marketing, signed off by nobody technical.
The help centre. Often the worst offender, because support writes plainly and support writes absolutes. “Users under 18 cannot access this content.”
Terms of service and community guidelines. “We do not permit users under 13.” A prohibition is safe. “We prevent users under 13” is a claim about a mechanism.
The parental controls screen. This is exactly what caught TikTok. The copy next to a toggle is a promise about what the toggle does. “Blocks mature content” is a much stronger statement than “Filters most mature content”, and the difference is measurable in your own logs.
App store listings and age ratings questionnaires. Written once, at launch, by whoever shipped it. Never revisited when the model changed.
Sales collateral, security questionnaires and RFP answers. A written answer to an enterprise buyer is a representation. If your answer to “do you verify age” is “yes, all users are age verified” and the truth is “we run estimation with a document fallback and a 3% manual override rate”, you’ve made a claim to a counterparty with a contract.
Your trust centre or transparency report. Any published number becomes a claim you are asserting is true on the date you published it. That’s good, if the number is real and dated. It’s the worst kind of exposure if it was accurate in March and nobody updated it.
Press statements after an incident. Said under pressure, by someone senior, without checking. These end up quoted back.
Go and read all eight. Most teams find at least one sentence they cannot defend with data.
The unsafe claim patterns
Four shapes cause almost all of the trouble.
Absolutes. Prevents, blocks, ensures, guarantees, all, every, no. An age check is a statistical control with a false negative rate above zero. Every absolute is a statement your own metrics contradict.
Outcome claims instead of measure claims. “No minors on the platform” is a claim about the world. “We run highly effective age assurance on every signup” is a claim about what you do. You control the second one. You do not control the first.
Claims about a control you do not measure. If nobody can produce the pass rate of your parental control filter, you can’t describe how well it works, and you shouldn’t. This is the Restricted Mode problem exactly. TikTok described a filter that its own staff could see was leaking.
Stale claims. The claim was true against the model you ran in January. You retrained in June and the threshold moved. Nobody owns the sentence on the marketing page, so it still says January.
There’s a fifth that’s specific to this space and worth naming. Borrowing a store’s claim as your own. If your only age signal is an app store age bracket from Apple or Google, you can say you consume that signal. You cannot say you verify your users’ ages, because you don’t, and the store’s terms will tell you the signal is declared rather than verified. We wrote about that distinction in why a store signal isn’t an age check.
What a defensible claim looks like
The fix is not to stop saying anything. Silence is bad for conversion and it’s bad for regulators too, since several codes expect you to tell users what you do. The fix is to describe the measure, name the method, and put a date on any number.
Here’s the rewrite pattern.
| Unsafe | Defensible |
|---|---|
| Verified adults only | Every account completes an age check before accessing this area |
| We prevent under-13s from signing up | We run age assurance at signup and remove accounts we identify as under 13 |
| Blocks mature content | Filters content classified as mature. No filter catches everything, so you can also report anything we missed |
| Our age check is 99% accurate | Our facial age estimation had a mean absolute error of X years on the Y test set, measured Z |
| Fully compliant with the Online Safety Act | We use [named method] as our highly effective age assurance measure under Ofcom’s guidance |
| All users are age verified (in an RFP answer) | 94% of users pass browser-based estimation. The remaining 6% complete document verification or are refused. 0.4% are resolved by manual review |
The figures in the last row are made up to show the shape of a good answer. Use your own.
The right column is longer. It’s also the column you can still stand behind after someone reads your logs, and the enterprise buyer reading the RFP will trust it more, because a specific number with a method attached is how a real measurement looks.
One rule covers most of it: if the sentence would need a caveat to be true, put the caveat in the sentence. A footnote in a help centre article is not a caveat if the headline claim appears on the pricing page.
Making the claim defensible is an evidence job
A claim is safe when you can produce the measurement behind it on the day you’re asked. That means the numbers have to exist before anyone asks, and they have to be tied to a version of the system.
Four things do most of the work.
A decision record for every age decision. Outcome, method, threshold, confidence, policy version, timestamp. Not the document image. Without the policy version you cannot say which claim period a decision belongs to, which means you cannot show that a claim was true when you made it.
A claims register. A list of every published sentence about age or safety, where it lives, which metric supports it, who owns it, and when it was last checked against that metric. This is dull and nobody wants to own it. It is also the single artefact that would have made the Restricted Mode problem visible internally, because writing down “which number supports this?” next to a claim is how you discover there isn’t one.
A measured effectiveness number, refreshed. Pass rate, false negative rate at your challenge age, step-up rate, appeal upheld rate. We’ve set out how to compute these in measuring age assurance effectiveness, and the appeal upheld rate in particular is the one field measurement of your gate you’ll ever get (the appeal path nobody measures).
A review trigger on model change. When the model, the threshold or the vendor changes, the claims register gets read. This is the control that stops stale claims, and it’s a one line addition to a release checklist.
There’s an uncomfortable corollary. Once you measure, you know. A team that knows its false negative rate and publishes an absolute has moved from careless to something a court will describe less kindly. That’s not an argument against measuring. Texas shows what happens when the internal documents say one thing and the public page says another, and the internal documents existed either way. Measuring at least gives you the chance to fix the sentence.
The related trap runs the other way. An age gate is not a liability shield, and saying you have one does not transfer the risk, which we covered in the Roblox lawsuits.
How Xident is built for this
Three parts of our design exist because of this problem.
Decision records, not retained documents. Every decision returns outcome, method, threshold, confidence, policy version and timestamp, and that’s what we store. It means you can answer “what measure was in force on 3 March, and what did it do” without holding anyone’s passport image. That record is the evidence under any claim you publish.
Published numbers with the method attached. We publish a 0.03% false positive rate against Germany’s KJM 1% threshold and our results against the Australian age assurance trial benchmarks, with the test conditions named. We do it that way because a number without a method is not a measurement, and we’d rather you quote something you can defend than something that sounds better.
A cheap Check and a separate document Verification. On Growth those are €0.02 and €0.20. The gap is what makes it affordable to run a step-up instead of writing an absolute you can’t support. You can honestly say “every user completes an age check, and anyone the check can’t resolve completes document verification” when the second path costs ten times the first rather than a hundred.
The free sandbox grants 1,000 Checks and 100 document Verifications as one-time allowances, not a monthly quota. The Verifications are there so you can run the document path end to end, including the branch where the first method says no, before you write a word of marketing copy about it.
The short version
Texas did not find that TikTok failed to protect children. It found that TikTok described protections that behaved differently from the description, and that this is a deceptive trade practice. Meta’s settlement then put an independent auditor in place for ten years to check whether stated measures actually run.
Your age gate has a false negative rate. Everyone’s does. That is not the risk. The risk is the sentence on your parental controls screen written by someone who has never seen that number.
Go and read every place your product claims something about age. Ask which measurement supports each sentence. Where there isn’t one, either build the measurement or change the sentence. Changing the sentence is cheaper and takes an afternoon.
Xident provides age verification and age estimation infrastructure built on decision records rather than retained documents, so the claims you publish have measurements underneath them. The free sandbox includes a one-time allowance of 1,000 Checks and 100 document Verifications. Talk to us about the claims your programme cannot currently evidence.