California’s AB 2273 — the Age-Appropriate Design Code Act — is one of the most sweeping children’s online privacy laws ever passed in the United States. Signed by Governor Gavin Newsom in September 2022, it doesn’t just update a checkbox in a terms-of-service agreement. It demands that technology companies redesign platforms from the ground up to protect anyone under 18.
That ambition triggered an immediate and fierce legal counterattack. As of March 2026, the U.S. Court of Appeals for the Ninth Circuit has blocked the majority of the law’s provisions following years of litigation. But the legal storm around AB 2273 doesn’t mean businesses can ignore it. Enforcement of surviving provisions remains possible, and similar laws are multiplying across the country.
This guide breaks down exactly what AB 2273 requires, who it covers, what the courts have decided, and what compliance looks like in practice.
What Is California AB 2273 — and Who Does It Cover?
California AB 2273 — also known as the California Age-Appropriate Design Code Act (CAADCA) — requires businesses that provide online services “likely to be accessed” by children under 18 to embed privacy and safety protections directly into product design. Signed into law on September 15, 2022, it was modeled closely on the United Kingdom’s Age-Appropriate Design Code and was unanimously passed by the California Legislature.
The critical phrase is “likely to be accessed.” Unlike the federal Children’s Online Privacy Protection Act (COPPA), which applies only to services directed at children under 13 or where operators have actual knowledge of child users, AB 2273 casts a much wider net. A business doesn’t need to know children are using its product — it just needs to be reasonably expected that they might.
Who Qualifies as a “Business” Under the Act?
AB 2273 applies to any entity that meets the definition of a “business” under the California Consumer Privacy Act (CCPA) — meaning it collects personal data, does business in California, and meets at least one of the CCPA’s thresholds (such as having annual gross revenues above $25 million, or buying or selling personal data of 100,000 or more consumers annually).
If that business provides an online service, product, or feature likely to be accessed by children, the Act applies.
What Types of Services Are Covered?
The law’s reach is intentionally broad. Based on the statutory language and legislative guidance, covered services include:
- Social media platforms and video-sharing apps
- Online video games and gaming platforms
- Music and video streaming services
- Connected devices — smartwatches, smart speakers, connected toys
- Virtual assistants
- Online education tools and ed-tech platforms
- Discussion forums and community platforms
- Blogs and general-audience websites routinely visited by a significant number of minors
A business is covered when competent and reliable evidence shows its service is routinely accessed by a significant number of children, when advertising is directed at children, or when the service is otherwise designed with child users in mind.
What the Law Defines as a “Child”
The Act defines a child as any consumer under 18 years of age — a significant departure from the federal COPPA standard of under 13. This extension to teenagers is one of the most consequential aspects of the law, as it sweeps in platforms that have historically argued that COPPA simply doesn’t apply to them.
What Does AB 2273 Actually Require Businesses to Do?
AB 2273 requires covered businesses to take six categories of action: conduct a Data Protection Impact Assessment, apply privacy protections by default, communicate in age-appropriate language, ban dark patterns, restrict profiling and geolocation of children, and estimate the age of users. Every obligation is structural — built into the design of a product, not just disclosed in a policy document.
Here is what each requirement means in practice.
1. Complete a Data Protection Impact Assessment (DPIA)
Before launching any new online service, product, or feature likely to be accessed by children, businesses must complete a systematic Data Protection Impact Assessment. For services already live before July 1, 2024, the DPIA deadline was that same date.
The DPIA must specifically identify:
- The purpose of the online service and how it uses children’s personal information
- The risks of material harm to children arising from data management practices
- Whether the design uses features intended to increase time on platform or compel sharing of personal data
- How and whether algorithmic systems or targeted advertising apply to children
- How the business collects or processes sensitive personal information
If any risks are identified, the business must create a documented, timed plan to mitigate or eliminate them before the service goes live to children. DPIAs must also be reviewed every two years. They remain confidential — protected from public disclosure regardless of the California Public Records Act — but the California Attorney General can request a specific DPIA in writing, and the business must produce it within five business days.
Privacy practitioners often recommend that DPIAs be conducted or reviewed by an independent third party. Because the DPIA identifies potential harms to children, it may contain sensitive business information; engaging outside counsel or a third-party assessor may allow the document to be shielded as privileged work product in litigation.
2. Configure All Default Privacy Settings to “High”
Every default privacy setting offered by a covered service must default to the highest level of protection available, unless the business can demonstrate a compelling reason that a different default setting is in the best interests of children. Commercial interest alone is not a compelling reason.
In practice, this means opt-in rather than opt-out for data sharing, location services disabled by default, and social features set to private. The UK’s experience under its analogous law offers a preview: TikTok disabled direct messages between children and adult accounts they don’t follow; the Google Play Store blocked under-18s from viewing adult-rated apps.
3. Use Age-Appropriate Language in Privacy Communications
All privacy notices, terms of service, policies, and community standards must be written concisely and prominently, in language suited to the developmental stage of the children likely to access the service. The Act breaks developmental stages into age groups:
- 0–5: Pre-literate and early literacy
- 6–9: Core primary school years
- 10–12: Pre-teen
- 13–15: Early teens
- 16–17: Approaching adulthood
A 13-year-old and a 35-year-old cannot reasonably be expected to parse the same legal boilerplate. The law demands that businesses acknowledge this reality in their product design.
4. Ban Dark Patterns
The Act prohibits interface designs that lead or encourage children to take actions that are “materially detrimental” to their physical health, mental health, or wellbeing. Dark patterns in this context include:
- Confusing or misleading privacy settings designed to push users toward lower-privacy choices
- Pre-checked consent boxes for data sharing
- Deceptive framing that makes opting out of tracking harder than opting in
- UI flows that pressure children into accepting notifications, sharing locations, or creating public profiles
This is where the law directly targets platform design practices that have drawn sustained criticism from child development experts and digital rights advocates.
5. Restrict Profiling and Geolocation of Children
The Act prohibits profiling children — using browsing history, behavioral data, or inferred similarities to other users to present content or advertising — unless there is a compelling reason that such use is in the best interests of children, or the child is actively and knowingly engaged with the relevant feature.
Precise geolocation data cannot be collected from a child without a compelling reason. Whenever a child’s location is being tracked, the service must display a prominent signal indicating that the tracking is active.
The prohibition extends to the sale of children’s personal information and its use for purposes beyond what is necessary for the service the child is actively using.
6. Estimate the Age of Users
Covered businesses must estimate the age of their users with “a reasonable level of certainty appropriate to the risks” posed by their data management practices. Alternatively, a business may apply all the Act’s child protections universally to every user — regardless of age.
This age-estimation requirement is one of the Act’s most technically contested provisions. Privacy advocates worry that robust age verification requires businesses to collect more sensitive data from users, not less — potentially increasing the risk it is supposed to mitigate. This tension remains unresolved in both the law and the ongoing litigation.
How Steep Are the Penalties Under AB 2273?
The California Attorney General enforces AB 2273. Penalties reach $2,500 per affected child for each negligent violation and $7,500 per affected child for each intentional violation. On a platform used by millions of children, intentional non-compliance could translate into billions of dollars in potential exposure — making these among the most consequential per-capita penalties in U.S. privacy law.
There is no private right of action — individual users cannot sue companies under this law. Only the Attorney General can bring civil actions on behalf of the people of California. All recovered penalties are deposited into the Consumer Privacy Fund.
One important safeguard for businesses: before pursuing penalties, the Attorney General must offer a 90-day cure period to businesses that are already in “substantial compliance” with specified provisions of the Act. This window is not guaranteed for all violations and does not apply to clearly intentional conduct.
The law also authorizes the Attorney General to seek injunctive relief — a court order requiring a company to change its practices — regardless of whether monetary penalties are pursued.
The Legal Battle: What the Courts Have Decided
NetChoice v. Bonta is one of the most consequential tech law cases in the United States. As of March 2026, the Ninth Circuit has agreed that a majority of AB 2273’s challenged provisions are likely unconstitutional, with five of six substantive provisions remaining under a preliminary injunction — meaning enforcement remains blocked while the case proceeds.
Understanding the litigation timeline is essential to understanding what the law actually does today.
A Timeline of NetChoice v. Bonta
September 15, 2022: Governor Newsom signs AB 2273. The law is set to take effect July 1, 2024.
December 2022: NetChoice — a tech trade association representing Google, Meta, Amazon, and TikTok — files suit in the U.S. District Court for the Northern District of California, arguing the law violates the First and Fourth Amendments, the Commerce Clause, and is preempted by COPPA and Section 230 of the Communications Decency Act.
September 18, 2023: District Court Judge Beth Labson Freeman grants a full preliminary injunction, finding the Act likely violates the First Amendment. The entire law is blocked.
August 16, 2024: The Ninth Circuit partially upholds the injunction on the DPIA requirement — finding it likely violates the First Amendment by compelling businesses to assess and potentially restrict content — but vacates the broader injunction and remands the remaining provisions to the district court for further analysis.
March 2025: The district court, on remand, again grants a second preliminary injunction blocking the entire statute.
March 12, 2026: The Ninth Circuit issues its most recent ruling. Of the six substantive provisions challenged by NetChoice, five remain enjoined. The court agrees that a majority of the law is unconstitutional under the First Amendment framework.
What Is the Core Legal Argument?
NetChoice argues that the DPIA requirement effectively conscripts private companies to act as government-directed censors — assessing what content children might see and modifying their services accordingly. The court found this type of compelled editorial assessment likely fails strict First Amendment scrutiny.
Supporters of the law counter that the DPIA requirement is a standard business regulation — comparable to environmental impact assessments or financial risk disclosures — not a restriction on speech. The Electronic Privacy Information Center (EPIC) argued in an amicus brief that the law “does not require companies to remove or even demote any specific content.”
The constitutional question — when does platform design regulation become compelled speech? — remains unsettled and is likely to eventually reach the U.S. Supreme Court.
What Provisions Are Currently Enforceable?
While most challenged provisions remain enjoined, several provisions were not challenged by NetChoice and were never blocked. These include:
- The requirement to provide an obvious signal when children are being tracked
- The requirement to provide prominent tools so children can exercise their privacy rights
- Rules limiting the processing of precise geolocation information
- The prohibition on using age-estimation data for any other purpose
Businesses should treat these provisions as currently enforceable, regardless of the broader injunction.
How Does AB 2273 Compare to Other Kids’ Privacy Laws?
AB 2273 is broader, more structurally demanding, and reaches older children than any prior U.S. federal law. It most closely resembles the UK’s Age-Appropriate Design Code — and was explicitly modeled on it — but faces unique First Amendment constraints that the UK’s regulatory framework does not.
| Law | Jurisdiction | Age Covered | Core Mechanism | Enforced By | Status (2026) |
|---|---|---|---|---|---|
| California AB 2273 (CAADCA) | California, USA | Under 18 | DPIA + design-by-default | Attorney General | Mostly enjoined |
| UK Age-Appropriate Design Code | United Kingdom | Under 18 | 15 design standards | ICO | Fully in force |
| COPPA | Federal, USA | Under 13 | Parental consent | FTC | In force |
| Kids Online Safety Act (KOSA) | Federal, USA | Under 17 | Duty of care | FTC | Proposed |
| Maryland AADC (HB901) | Maryland, USA | Under 18 | DPIA + design rules | AG | Enacted, similar status |
| Connecticut AADC (HB6253) | Connecticut, USA | Under 18 | Design-by-default | AG | Introduced |
The UK code, enforceable since September 2021, offers the clearest real-world preview of what AB 2273 might achieve if it survives its legal challenges. Following the UK code’s implementation:
- TikTok and Instagram disabled direct messaging between children and adults they don’t follow
- Google Play blocked users under 18 from accessing adult-rated applications
- Multiple platforms restructured notification settings for child accounts by default
Because California is home to most of the world’s largest technology companies, and those companies have already adapted to the UK code, compliance infrastructure often already exists. The CAADCA was expected to accelerate that adaptation globally.
Common Mistakes and Misconceptions About AB 2273
Businesses make consistent errors when interpreting AB 2273 — usually by either dismissing it because of the ongoing litigation or over-narrowing the scope of who it covers. Both mistakes carry real risk.
Mistake 1: Assuming the Injunction Means No Compliance Action Is Needed
The current injunction blocks enforcement of most provisions — but not all. Several unchallenged provisions remain enforceable now. Beyond that, the injunction is preliminary, meaning courts have not ruled on the merits. The law could survive in amended or narrowed form, and the legal landscape will keep shifting. Businesses that build compliance into their design now avoid a scramble later.
Mistake 2: Thinking the Law Only Applies to Social Media
AB 2273 explicitly covers a broad range of digital services. Online games, streaming apps, educational platforms, virtual assistants, and connected devices are all potential covered services. If any of these are used by a meaningful number of users under 18, the law likely applies.
Mistake 3: Treating Age as Binary
The law does not simply split users into “child” and “adult.” It identifies five distinct developmental stages and expects communications and design choices to reflect the realities of those stages. A privacy policy written for a 16-year-old is not the same as one written for a 7-year-old — and the law requires businesses to recognize this.
Mistake 4: Treating the DPIA as a One-Time Task
The DPIA must be reviewed every two years. Every new product or feature likely to be accessed by children triggers a fresh DPIA. Businesses that treat this as a compliance checkbox rather than an ongoing process expose themselves to both regulatory and reputational risk.
Mistake 5: Conflating AB 2273 With COPPA
COPPA covers children under 13 and only applies where the operator knows or is directed at child users. AB 2273 covers anyone under 18 and applies wherever child access is “likely.” These are materially different standards. A platform that has concluded it is COPPA-compliant may still be subject to AB 2273.
Frequently Asked Questions About California AB 2273
Does AB 2273 apply to my business?
If your business meets the CCPA’s definition of a “business” and offers any online service, product, or feature likely to be accessed by children under 18, yes. The threshold is not whether you target children — it is whether children are reasonably expected to access your service. Platforms with broad general audiences that include a significant number of minors are covered, even if children are not the primary intended user.
Is AB 2273 currently enforced in 2026?
Most provisions remain blocked by a federal preliminary injunction following the Ninth Circuit’s March 2026 ruling in NetChoice v. Bonta. Five of six challenged substantive provisions are enjoined. However, several provisions were never challenged and remain enforceable. The litigation is ongoing, and the legal status of the law may shift again as the case proceeds toward a final ruling on the merits.
What must a DPIA under AB 2273 include?
A DPIA must identify the purpose of the online service and how it processes children’s personal information; evaluate risks of material harm to children from data management practices; assess algorithmic systems and targeted advertising; analyze design features that could extend time on platform or compel data sharing; and produce a timed mitigation plan for any identified risks. It must be reviewed every two years and produced to the Attorney General within five business days of a written request.
How is AB 2273 different from COPPA?
COPPA, the federal Children’s Online Privacy Protection Act, applies only to operators of services directed at children under 13 or that have actual knowledge of collecting data from children under 13. AB 2273 applies to anyone under 18 and triggers wherever a service is “likely to be accessed” by children — regardless of operator intent or knowledge. AB 2273 also focuses on design and defaults, while COPPA primarily governs data collection consent.
What are “dark patterns” under AB 2273?
Dark patterns are interface designs that lead or pressure users into making choices against their own interests. Under AB 2273, prohibited dark patterns include any design element the business knows, or has reason to know, is materially detrimental to a child’s physical health, mental health, or wellbeing — such as confusing settings that default to maximum data sharing, pressure tactics to share location, or deceptive flows that make opting out of tracking unnecessarily hard.
Can individual users sue a company under AB 2273?
No. The Act does not include a private right of action. Only the California Attorney General can bring civil enforcement actions under AB 2273. This limits enforcement to the AG’s office but also concentrates it — a single AG action against a large platform could involve millions of “affected children” and correspondingly massive per-child penalties.
Will AB 2273 influence laws in other states?
Yes — it already has. Maryland, Connecticut, and other states have introduced or enacted similar legislation modeled on California’s law. Even if the CAADCA is ultimately narrowed by the courts, it has set the template. Federal proposals like the Kids Online Safety Act (KOSA) borrow similar design-first logic. The direction of travel in U.S. children’s privacy law is clearly toward AB 2273’s framework.
What is the relationship between AB 2273 and the UK Age-Appropriate Design Code?
AB 2273 was explicitly modeled on the UK’s Age-Appropriate Design Code, which became enforceable in September 2021. Both laws apply to services “likely to be accessed” by users under 18 and require privacy-by-default design. The UK code is enforced by the Information Commissioner’s Office (ICO) and can impose fines up to 4% of global annual turnover — higher proportional exposure than AB 2273’s per-child model. Because major tech companies already adapted to the UK code, many have existing compliance infrastructure that partially overlaps with AB 2273’s requirements.
Conclusion
California AB 2273 is a historic piece of legislation — not because it has been smoothly implemented, but because of what it represents: a fundamental argument that children deserve products designed with their safety in mind, not retrofitted with a privacy policy drafted for adults.
The legal battles around the law are real and ongoing. As of July 2026, most of its provisions remain blocked. But the constitutional argument is not resolved, and similar laws are actively advancing in other states and at the federal level. Businesses that wait for legal certainty before acting on children’s privacy will find themselves perpetually behind.
The practical steps are clear: audit which of your services are likely accessed by children under 18; document a DPIA process and make it repeatable; set privacy defaults high; audit your interfaces for dark patterns; and write your privacy communications as if a 10-year-old will read them — because one probably will.
That work is not just legal protection. In a marketplace where trust has become a differentiating factor, it is also good product strategy
Stay two steps ahead with our trend-focused content updated regularly.
