On 29 July 2026, the final rules implementing New York’s Stop Addictive Feeds Exploitation (SAFE) for Kids Act were published in the State Register by Attorney General Letitia James, alongside Governor Kathy Hochul. Publication started the statutory 180-day implementation window, which closes on 25 January 2027.
The Attorney General’s framing at the announcement was blunt — platforms are, in her words, on notice. Compliance teams should read that literally. New York has now moved from statute to rules to a fixed date, and the intervening five months are the entire runway for what is, for most covered platforms, a substantial re-engineering of the recommendation stack and the notification pipeline for a segment of users the platform cannot currently identify with confidence.
What the Act actually requires
The SAFE for Kids Act imposes two operative restrictions on covered platforms in respect of users under the age of 18, absent verifiable parental consent:
1. No algorithmically personalised feeds. A covered platform may not provide an “addictive feed” — content recommended, selected or prioritised for the user based on information associated with that user or their device — to a minor. Minors must instead receive a non-personalised feed, in practice chronological content from accounts the user has affirmatively chosen to follow, plus content not selected on the basis of user-associated signals.
2. No overnight notifications. A covered platform may not send notifications to a minor between 12:00 a.m. and 6:00 a.m. Eastern Time.
Both restrictions are lifted only by verifiable parental consent, which the rules treat as an affirmative, revocable, documented act by a parent or guardian — not an unchecked box during signup and not a consent inherited from a general terms-of-service acceptance.
The three hard problems in the rules
The statute is short. The rules are where the compliance difficulty lives, and it concentrates in three places.
Determining who is covered
The rules establish criteria for which operators fall within the Act. This is not a simple user-count threshold. The determination turns on whether the service provides an addictive feed as defined, whether minors constitute a meaningful portion of the audience, and whether the operator has actual knowledge or should reasonably know that minors use the service.
That last limb matters enormously. A platform that has carefully avoided knowing the ages of its users cannot rely on that ignorance. The “should reasonably know” standard is the same architecture that has been imported into COPPA enforcement and into the UK Age Appropriate Design Code, and it is deliberately hostile to wilful blindness. Compliance teams whose position is “we do not collect age, therefore we do not have minors” should assume that position will not survive contact with the Attorney General’s office.
Age assurance
The rules set out standards for determining a user’s age. This is the single largest engineering and privacy burden in the regime, and it is genuinely difficult because two regulatory pressures point in opposite directions:
- The SAFE for Kids Act requires the platform to know, with reasonable confidence, which users are under 18.
- The New York Child Data Protection Act, the CCPA family of state privacy laws, and general data minimisation principles all penalise collecting more identity data than necessary.
Collecting government ID from every user resolves the first problem and creates a very large second problem: a platform-wide identity document repository is a breach liability of the first order, and one that regulators have been increasingly willing to treat as itself unreasonable. We have written before about the age verification compliance patchwork across US states and about the constitutional challenges that have struck down some of the more aggressive mandates.
The defensible middle path, and the one the rules contemplate, is proportionate age assurance: a tiered approach in which low-risk signals (self-declaration, behavioural signals, account age) are used first, escalating to stronger methods only where signals conflict or where the consequence of error is significant. Documented, tested, and reviewed — the documentation being the part that most organisations skip and the part an enforcement inquiry will demand first.
Verifiable parental consent
The rules set standards for obtaining parental consent. The lessons from two decades of COPPA enforcement apply directly: consent must be obtained from someone the platform has reasonable grounds to believe is actually the parent, the mechanism must be reasonably calculated to achieve that, and a checkbox stating “I am a parent” is not reasonably calculated to achieve anything.
Platforms should also build for revocation. A parental consent regime that is easy to grant and hard to withdraw is a consumer protection problem independent of the SAFE for Kids Act, and one that state AGs have shown consistent appetite to pursue as an unfair practice.
Recordkeeping
The rules impose recordkeeping obligations, and these deserve more attention than they typically receive.
Recordkeeping requirements in a regime like this are not administrative overhead — they are the enforcement mechanism. The Attorney General does not need to reverse-engineer your recommendation algorithm to bring an action. The office needs to ask for your records of age determinations, parental consents, and feed configuration decisions, and then compare them against the population of users the office believes to be minors.
An organisation that cannot produce, on request, an auditable record of how it determined a given user’s age and what feed treatment followed from that determination is in a materially worse enforcement position than one whose age assurance was imperfect but documented.
Practically, this means logging, per user and per determination:
- the age signal or signals relied upon and their timestamps,
- the resulting age band determination,
- any parental consent obtained, its verification method, and its status,
- the feed treatment applied and any changes to it,
- the notification window applied,
- and the retention and review cadence for each of the above.
Enforcement and penalties
The Attorney General may bring an action to enjoin violations and seek civil penalties of up to $5,000 per violation, alongside other remedies.
As with California’s AI Transparency Act, the arithmetic is what matters. “Per violation” in a platform context is not naturally read as “per company.” A plausible enforcement theory counts violations per affected minor, or per non-compliant notification sent. A platform with a hundred thousand New York minors receiving personalised feeds after 25 January 2027 is exposed to a number that is not survivable as a rounding error.
The New York OAG has also been among the more active state offices on children’s online safety, and the SAFE for Kids Act sits alongside the New York Child Data Protection Act, which imposes separate restrictions on processing minors’ data. Compliance work on one should be scoped to satisfy both.
How this fits the wider landscape
New York is not acting alone, and the compliance burden is cumulative rather than substitutable:
- Connecticut expanded its CTDPA protections in July 2026 with prohibitions on processing minors’ data for targeted advertising, restrictions on addictive design features, geolocation limits, and consent requirements for profiling.
- California’s Age Appropriate Design Code has been through extensive litigation, with parts enjoined on First Amendment grounds.
- Texas, Utah, Arkansas, Ohio and others have enacted parental consent or age verification regimes at various stages of legal challenge.
- The EU’s Digital Services Act imposes minor-protection duties on very large online platforms with a different structure again.
There is no single control set that satisfies all of these. What there is, and what mature programmes are converging on, is a capability: reliable, proportionate, well-documented age banding, plus a configuration layer that can apply per-jurisdiction feed, advertising, notification and data-processing rules to each band. Build the capability once; configure it per jurisdiction. Building per-statute point solutions produces a system that no one can reason about by the fourth statute.
First-Amendment risk, and why it should not stop the work
Several state minor-protection laws have been enjoined or struck down on First Amendment grounds, including the Texas app store age verification law and Louisiana’s age verification law. It is reasonable to expect litigation against the SAFE for Kids Act.
It is not reasonable to make that expectation the compliance plan. The Act’s core mechanic — restricting algorithmic personalisation rather than restricting access to content — was deliberately drafted to survive the challenges that felled broader access-restriction statutes. The state’s position is that regulating recommendation systems is conduct regulation rather than speech regulation. That argument may or may not prevail, but it is substantially stronger than the arguments that lost in Texas and Louisiana, and no rational programme bets a $5,000-per-violation exposure on an injunction that has not been sought, let alone granted.
Plan for the rules to apply on 25 January 2027. Track the litigation. Adjust if the landscape changes.
A five-month plan
August–September 2026 — scoping and gap analysis
- Determine whether each of your services is a covered platform under the rules’ criteria. Document the analysis, including the “should reasonably know” assessment.
- Estimate the New York minor population per service, and the confidence interval on that estimate.
- Map every surface that recommends content and every surface that sends notifications.
- Identify the data flows that feed personalisation, and confirm you can switch them off per user.
October 2026 — age assurance design
- Design a proportionate, tiered age assurance approach. Do not default to ID collection.
- Run a data protection impact assessment on the age assurance system itself.
- Design the parental consent flow, including verification method and revocation path.
- Specify the recordkeeping schema.
November 2026 — build
- Implement the non-personalised feed path and test it end to end.
- Implement the 12:00 a.m.–6:00 a.m. Eastern notification suppression, including correct handling of users whose device timezone differs from their jurisdiction.
- Implement age banding, parental consent capture, and the audit log.
December 2026 — test and evidence
- Test with synthetic minor accounts across every surface. Personalisation leaks through recommendation modules that nobody remembered were recommendation modules — related content, “people you may know,” search ranking, ad selection.
- Validate that the audit log can answer the question an enforcement letter will ask: for user X on date Y, what age did you determine, on what basis, and what treatment followed?
- Brief the board and the incident response function.
January 2027 — go live before the deadline
- Deploy no later than mid-January. Do not deploy on 25 January.
- Monitor for personalisation leakage and notification-window violations as production alerts, not as quarterly reviews.
The takeaway
The SAFE for Kids Act asks platforms to do something they have spent fifteen years building infrastructure not to do: treat a subset of users differently on the basis of an attribute — age — that the platform has deliberately avoided determining.
The engineering to turn off a feed is trivial. The compliance work is in knowing, defensibly and on the record, which users to turn it off for, and being able to show your reasoning five months from now to an Attorney General who has already said you are on notice. That work starts with the age assurance design and the recordkeeping schema, and it does not compress well. Five months is enough time. Four will not be.
This article is provided for informational purposes only and does not constitute legal advice. Organisations should consult qualified counsel regarding their specific obligations under the New York SAFE for Kids Act, the New York Child Data Protection Act, and applicable state and federal law.



