New York finalizes SAFE for Kids Act rules, setting age-verification mandates for algorithmic feeds

New York Attorney General Letitia James and Governor Kathy Hochul released the final implementing rules for the SAFE for Kids Act on July 28, 2026, establishing operational requirements for social media platforms that must verify users' ages before granting access to algorithmic feeds and overnight notifications. (New York AG press release)
The law, formally codified as Article 45 of the New York General Business Law (GBL section 1500), was signed by Hochul in June 2024. SAFE stands for "Stop Addictive Feeds Exploitation." (Verge)
The final rules are largely similar to the Attorney General's initial proposal released in September 2025, which followed an August 2024 Advanced Notice of Proposed Rulemaking. A public comment period on the proposed rules closed on December 1, 2025. (Verge)
Several specific technical and procedural requirements are now locked in. Age verification methods must detect circumvention attempts 98 percent of the time. Platforms may accept government-issued ID but must offer at least one alternative method. All information collected for age verification must be immediately deleted or de-identified after use. (Verge)
The law applies to social media platforms with user-generated content where users spend at least 20 percent of their time on algorithmic feeds. That threshold is designed to capture the major platforms where recommendation-driven content drives engagement while excluding apps where algorithmic curation is incidental. (Verge)
Two core platform features trigger the age-gating requirement: access to algorithmic feeds and delivery of notifications between 12 AM and 6 AM. Minors under 18 must obtain parental consent to access these age-gated features, and parents must be notified of the consent request. Both parents and minors can withdraw consent at any time. (Verge)
The rules include several guardrails around the consent mechanism. Platforms cannot block minors from using non-age-gated parts of the app solely because parents have not consented to age-restricted features. Platforms are also not obligated to show parents their child's search history or content topics as part of the consent process. (Verge)
Non-compliance carries a penalty of up to $5,000 per violation. The law takes effect January 25, 2027, giving covered platforms roughly 18 months to build age-verification pipelines, parental-consent workflows, and notification-scheduling controls that satisfy the 98 percent circumvention-detection threshold. (Verge)
The broader legal context matters here. The US Supreme Court's decision upholding Texas's age-verification requirement for adult websites has materially shifted the constitutional landscape around age-gating online content. Where First Amendment challenges to online age verification might once have carried significant weight, the Texas ruling has narrowed the arguments available to platforms seeking to contest mandates like New York's. Whether the SAFE for Kids Act survives its own inevitable legal challenges will depend in part on how courts interpret the boundary between the adult-content precedent and a law targeting algorithmic feeds and notification timing.
For platform engineering teams, the 98 percent circumvention-detection standard is the most demanding element. Government-ID verification can meet that bar, but the requirement to offer at least one non-ID alternative pushes platforms toward age-estimation technologies such as facial-age inference or third-party credentialing services, each with its own accuracy and privacy trade-offs. The immediate-deletion mandate means platforms cannot retain age-verification data for downstream purposes, including model training or fraud detection. Parental-consent flows that gate specific features rather than entire apps will require granular access-control architecture, and the real-time withdrawability of consent adds a stateful dimension that most current platform permission systems are not built to handle.
The SAFE for Kids Act is part of a broader New York regulatory framework that includes the NY Child Data Protection Act, which was also the subject of a 2024 Advanced Notice of Proposed Rulemaking. Together, the two laws represent a state-level regulatory push that will force platforms operating in New York to build child-safety infrastructure at a depth that goes well beyond existing federal requirements under COPPA.
For an industry that has spent two decades optimizing for frictionless onboarding, the technical requirements here are not trivial. But the 18-month implementation window and the relatively clear scope of the rules give engineering teams a workable runway. The platforms that treat this as an architecture problem to solve early, rather than a compliance checkbox to meet at the deadline, will be better positioned for the multi-state regulatory environment that now appears inevitable.


