Insights

|

Share

After Meta: Why "We Didn't Know Who Was on Our Platform" Is No Longer a Defence

On 26 August 2026, Meta agreed to pay up to $17.1 billion to settle child safety lawsuits brought by 47 US states. It is the largest single settlement in Meta's history and the biggest tech-industry payout ever recorded in a single case.

Three weeks earlier, a New Mexico court had ordered Meta to pay $942 million for creating a "public nuisance" — finding that the company had concealed what it knew about the dangers its platforms posed to children while making misleading claims about their safety.

The combined exposure, approaching $18 billion, before any future regulatory action, is extraordinary. But the finding with the longest reach is not the number. It is what the courts and regulators have now made explicit: platforms cannot claim ignorance of who uses them or what happens to those users.

The concealment problem

The legal findings against Meta rest on a specific set of facts. The company knew from its internal research that its platforms posed risks to minors. It knew that children were accessing services designed for adults. It knew the behavioural consequences. And it chose not to disclose what it knew, publicly denying the dangers while internally documenting them.

This is not primarily a technology failure. It is an accountability failure. And the courts have framed it accordingly.

As part of the settlement, Meta is required to implement "age assurance measures"—a legal obligation to know and be able to demonstrate who is actually using its platforms. The era of constructive ignorance — of operating at scale while claiming not to know — is ending, at least in the US and increasingly across Europe.

Why this matters beyond social media

Meta is a consumer social media company. YEO's customers are banks, payment platforms, and regulated digital services. The connection may not be immediately obvious.

But the regulatory logic that has just produced an $18 billion settlement is not confined to platforms that serve teenagers. It is a principle: organisations that handle users at scale have an obligation to know who those users are — not just at the point of access, but throughout their use of the platform.

For banks and payment providers, the equivalent obligation is already embedded in regulation. FCA Consumer Duty requires firms to demonstrate outcomes for customers, including protection from foreseeable harm. APP fraud reimbursement obligations require banks to show what steps they took at the point fraud occurred. FFIEC guidance in the US has long established that layered controls — not just login-level authentication — are the appropriate standard for digital banking.

The Meta ruling is the most visible signal yet of where regulatory and legal expectations are heading for any platform that handles real users in a context where something can go wrong.

The identity gap that the session creates

The practical question, for any platform, is what "knowing who your users are" actually requires at a technical level.

For most digital platforms today, including many banks, the answer is: a verified login event. A user authenticates. A session opens. And from that point forward, the platform proceeds on an assumption: that the verified person is still present, still in control, and still the one taking the actions attributed to their account.

That assumption fails in predictable ways. Session cookies can be stolen by attackers who resume an authenticated session without triggering a new login. Shared devices mean a verified account is operated by a different person entirely. Coaching fraud, where a legitimate account holder is manipulated into completing a fraudulent transaction, authenticates correctly and then proceeds under external instruction.

In none of these cases does the platform know what it claims to know. The login was verified. The session was not.

What verification inside the session looks like

Closing the session-level identity gap requires verification that operates continuously, not as a series of interruptions to the user experience, but as a persistent signal running alongside the session itself.

YEO's CFR SDK does this using a three-layer verification model: advanced facial mapping that establishes a precise baseline for the verified user; anti-spoofing liveness detection that distinguishes a real present individual from a photograph, video, or replay; and depth verification that defeats three-dimensional spoofing attempts, including masks and AI-generated face replicas.

All three layers operate on the user's device. No biometric data is transmitted to external servers or held in a central database. The output is a continuous presence signal, available to the platform at any point in the session, particularly during moments of highest risk: a large payment approval, a new beneficiary addition, or an account recovery request.

For a genuine user, this is invisible. For a session that has been compromised or handed to a different person, it is decisive.

The accountability shift

Meta's settlement requires the company to demonstrate, going forward, that it knows who is on its platforms. The $17 billion figure is what the cost of not knowing looks like, once regulators, courts, and 47 state attorneys general have finished counting.

For platforms operating in regulated environments, the question is no longer whether continuous identity verification is technically feasible. It is. The question is whether the session layer, the space between a verified login and the actions that follow, is currently protected to the standard that regulators, courts, and customers will increasingly expect.

The Meta ruling did not create that expectation. It confirmed it.

YEO's CFR SDK adds continuous session-level identity verification to any platform that requires authentication of biometrics or age — passive, on-device, and integrated, without displacing existing authentication controls. Learn more at yeomessaging.com/cfr-sdk.

Related reading:

Get the

Document

Share

About us

We stopped asking "who logged in." We started asking "who's still there." YEO began as a secure messaging app. Today we build the patented continuous identity verification infrastructure that regulated industries trust to prove who's really there.