A briefing for state legislators and legislative staff · The American Fabric · July 2026 Funding, affiliations, and recusals disclosures are available from The American Fabric.


In brief: what this document argues

The Kids Online Safety Act (KOSA) is well-intentioned, and it is right about the problem. But intervention in this field comes in three layers — disclosure of what a recommender system optimizes for, user control over that system, and an enforceable duty of care in how it is designed — and these layers are not equally easy to legislate or equally sound constitutionally. KOSA reaches first for the hardest of the three — a duty of care — and reaches it least effectively, while leaving the two layers beneath it, the ones that are both more defensible and more direct, largely unbuilt. A duty of care with nothing beneath it is a standard with no yardstick: it asks platforms to act “reasonably” toward children without ever requiring them to disclose what their systems are actually built to do, or giving families the controls to do anything about it.

This document lays out the three layers in order, shows what each accomplishes, and identifies the narrow, precise mandates that strike at the root of the problem rather than at its symptoms. The argument is not that KOSA does too much — it is that KOSA aims at the top of the ladder before building the rungs, and that the most effective interventions are also the least constitutionally fraught. Do the narrow things fiercely, in the right order, and the hard thing becomes enforceable. Attempt the hard thing first, and it collapses under its own weight.

Key changes needed to KOSA

1. Mandate disclosure of recommender optimization targets — first and loudest. Require every covered platform to state, plainly and prominently, what its recommender system is built to maximize — the same disclosure instrument that governs securities (“tell the truth about what you’re selling”) and the tobacco label (“state what’s in the pack”). This is the single most important change, and the one KOSA omits entirely: KOSA discloses safeguards and effects, never the objective itself. Naming the objective is what ends the core deception — the parent and the child who have no way of knowing that the feed in front of them is engineered to maximize time-on-device, not their well-being. You cannot consent to, or protect a child from, an objective you were never allowed to see.

2. Put the content-rating levers back in people’s hands — granular for every user, sovereign for parents. Not a government ratings board, and nothing heavy-handed — the opposite. Platforms already classify content into hundreds of fine-grained suitability categories, and they already sell those controls to advertisers, so that no brand’s ad ever appears beside content it dislikes. The change is simply to hand the same levers to the people the feed is aimed at: choose what you want to see more of, exclude what you don’t, category by category, across the entire feed. Parents hold those dials for their children until 18; adults hold their own. No one is told what may be published — each person, and each family, simply decides what reaches them, with the same precision advertisers already enjoy. KOSA gestures at this for minors but stops short of a general exclusion right, offers nothing this granular, and never extends any control to adults at all.

3. Make the duty of care actually enforceable — through audits, against a disclosed objective. Keep KOSA’s duty of care, but give it the teeth it currently lacks: independent audits measured against the optimization objective that Change #1 puts on the record. A duty to design in a child’s best interest is unenforceable while the design goal stays secret and no auditor can test it. Built on top of disclosure and control, the duty becomes administrable — a real obligation with a real yardstick — rather than an aspiration a court cannot police. This is the hard rung KOSA tried to climb first; it holds only once the two beneath it are in place.


The wrong debate — and the real one

The public conversation about algorithms keeps arriving at two dead ends: ban the technology, or let it run unchecked. Banning fails on both fact and principle. Recommender systems are not a product that can be recalled — they are a technique, already woven through search, commerce, entertainment, and news, cheap to rebuild anywhere code runs; a jurisdiction that “bans the algorithm” will simply use worse ones without knowing it. And prohibition aims at the wrong object: the same machinery that today maximizes a teenager’s compulsion could tomorrow surface the job posting, the town-hall notice, the neighbor in need. The technology is not the enemy, any more than the printing press was the propaganda it sometimes carried. But surrender is no better: “unchecked” does not mean ungoverned — it means governed by default, by whoever owns the objective function.

So the real question is not whether these systems exist, but whose will they serve — and who sets the objective. Today the answer is: the operator, unilaterally and invisibly, optimizing for its own revenue. The task before legislatures is not to un-invent the machine; it is to do what American law has done with every previous instrument of concentrated power — make it visible to the people it acts on, steerable by them, and, where it touches children, bound to their interest. Shaped to the will of the people it serves, rather than the people being quietly shaped to its objective.

And legislators should be clear-eyed about the instrument in question. A modern recommender system is the most powerful tool for shaping human attention and appetite ever built: a learning machine running billions of trials a day, discovering each user’s specific psychological weak points, applying what it learns personally and at population scale — in service of an objective its operator chose. Set against it is one person’s self-control; most consequentially, a child’s. That contest is not fair and is not meant to be fair — the machine’s job is to fulfill the platform’s desire, not the user’s, and it is now routinely strong enough to overrule the user’s, particularly at thirteen. If a foreign adversary built a machine that could reliably overpower American children’s self-control and steer their appetites at scale, we would call it a weapon and legislate accordingly; we built it domestically and called it a feed. The nearest regulatory ancestor is the cigarette — engineered compulsion, documented internally, denied publicly, concentrated in the young — governed, in the end, not by prohibition but by a ladder of disclosure, limits, and duties that no one now regrets. This brief proposes that ladder for the feed, beginning with its most defensible rung.


Executive summary

Nearly every feed a constituent opens — social media, video, news aggregation — is assembled by a recommender system: software that selects and orders content to maximize a metric its operator chooses. That metric, the system’s optimization objective, is the single most consequential design decision on the modern internet, and it is currently invisible to users, unexaminable by researchers, and unaddressed by law.

This brief presents a three-tier framework for legislating recommender systems, sequenced from most defensible and least burdensome to most ambitious:

  • Tier 1 — Disclosure (“the label”). Platforms must state, in standardized plain language, what their recommender systems optimize for, and provide qualified researchers and enforcement agencies the access needed to verify it. Analogous to the nutrition, securities, or tobacco disclosure — the label on the food, the truth in the prospectus, and the warning on the pack. The strongest constitutional footing and the lowest compliance cost of any option in this space.
  • Tier 2 — Control (“the dials”). Users get three rights over the systems that mediate what they and their children see: the right to exclude (content-rating filters that actually bind), the right to tether (parent–child governance of a minor’s feed), and the right to tune (user authority over the ranking objective, including a non-profiling option). This regulates who decides, not what may be said, which is precisely the ground where states have fared best in recent litigation.
  • Tier 3 — Duty (“alignment”). Operators owe users — beginning with minors — a duty to design recommender systems consistent with users’ best interests rather than solely operator engagement metrics. The most ambitious tier, and the one that depends on the first two: a duty is only enforceable once disclosure makes objectives observable and control makes alternatives real.

The tiers are a ladder, not a menu. Each creates the evidentiary record and the technical infrastructure the next one requires. A state can begin climbing this year at Tier 1 with minimal fiscal impact and strong bipartisan precedent.

The one-sentence version: every feed has a boss — the metric it is instructed to maximize — and the law’s first job is to let people see who the boss is, its second to let them change it, and its third to make sure it isn’t working against them.


1. Background: the optimization objective, in plain language

A recommender system ranks a vast pool of candidate content and chooses what a specific user sees next. To do this it must be told what “best” means — a measurable target such as watch time, session length, probability of a click, probability of a share, or predicted advertising revenue. Engineers call this the objective function; this brief calls it the optimization objective or, colloquially, the boss of the feed.

Three facts make this a matter for legislation rather than consumer choice alone:

  1. The objective is chosen by the operator, not the user, and typically serves the operator’s revenue model. On advertising-funded platforms, revenue rises with attention; the dominant objectives are therefore engagement metrics. This is not a design accident that better ethics will correct — it is the business model operating as designed.
  2. The objective is invisible. No mainstream platform tells users, in terms a non-engineer can evaluate, what its feed maximizes. Users experience the output of the choice — what they and their children see for several hours a day — with no knowledge of the choice itself. A parent can read a food label and a mutual-fund prospectus; there is no equivalent for the system that occupies more of their child’s formative hours than any teacher.
  3. The objective has population-scale effects. A growing body of evidence — including the U.S. Surgeon General’s 2023 advisory on social media and youth mental health, platform operators’ own internal research made public through disclosures and litigation, and a decade of peer-reviewed work on engagement-optimized design — links engagement maximization to compulsive-use patterns and harms concentrated among minors. Researchers continue to debate effect sizes; legislators need not resolve that debate to conclude that a system with this reach should at minimum be legible to the people it acts upon.

State legislatures are already responding: more than 1,500 AI- and algorithm-related bills have been introduced across the states in the current wave. What most proposals lack is a coherent structure. The framework below supplies one.


2. Why this warrants legislation: misalignment at scale

The structural problem: the user is not the customer

On an advertising-funded platform, the paying customer is the advertiser; the user’s attention is the inventory sold. The optimization objective follows the money — the system is instructed to maximize the thing the customer buys (attention) rather than the thing the user came for. No villainy is required for this to go wrong; misalignment is the equilibrium, produced by the business model operating exactly as designed. Legislators should be clear-eyed on the implication: this will not be corrected by better corporate intentions, because it was not caused by bad ones.

How an engagement objective converges on compulsion

An engagement-maximizing recommender is a learning system: it is not told what keeps each user engaged — it discovers it, per user, through billions of trials. Decades of behavioral research establish what such a search will find: variable-ratio reward schedules (the slot machine’s schedule) produce the most persistent compulsive behavior known to psychology; designs that remove natural stopping cues (autoplay, the infinite scroll) extend sessions past intention; socially-timed rewards and re-engagement notifications retrigger the loop. An optimizer pointed at engagement converges on these patterns for a simple reason: measured in minutes, compulsion is indistinguishable from delight. The system does not know the difference between a user who loves it and a user who cannot stop — and it is not asked to.

What makes this genuinely novel as a regulatory object is personalization at scale. Every prior mass product was uniform — a cigarette delivered the same nicotine to every smoker. A recommender fits itself to each user’s specific vulnerabilities — one user’s outrage trigger, another’s insecurity, a third’s loneliness — automatically, simultaneously, across hundreds of millions of people, under a single commercial objective chosen by a handful of unelected engineers. Mass-produced yet individually tailored influence has no precedent in consumer-protection history.

The gap the business model monetizes: first-order impulses vs. second-order preferences

Philosophers distinguish first-order desires (what you reach for) from second-order preferences (what you would choose on reflection — what you want to want). Self-governance, in a person as in a republic, is the capacity of the second to govern the first. Engagement metrics measure only the first order: the click is counted; the regret is not. And the revenue lives precisely in the gap — the wider the distance between what a user reaches for and what they would endorse on reflection, the more attention can be extracted from them.

The gap is not hypothetical; it is measured and felt. Majorities of teen users report both that they spend too much time on these products and that stopping is very hard. A paying market exists for software whose sole function is to block other software — consumers spending money to defeat products they nominally “prefer,” which is the clearest revealed second-order preference in modern commerce.

Law already knows this distinction, even if it rarely names it. Cooling-off periods, usury caps, and above all casino self-exclusion registries — state-administered lists by which a person may bind their impulsive self in advance — are all instances of the law siding with the reflective self against engineered exploitation of the impulsive one. Tier 2’s enforceable user controls are the same venerable instrument in digital form.

The tobacco parallel — offered with precision

The analogy is to the shape of the regulatory problem, not a claim of equivalent harm, and it holds on four points: (1) a mass consumer product engineered — and internally understood — to produce compulsive use; (2) public denial alongside internal research documenting the harms, a pattern the platform-document disclosures of recent years echo from the tobacco files; (3) harms concentrated among minors; (4) causality publicly contested for years while the population-scale association mounted. The regulatory response rhymes too, and its sequence is the instructive part: disclosure first (the 1965 warning label), then marketing and design restrictions, then coordinated state enforcement (the attorneys-general suits and the 1998 Master Settlement), then a federal capstone (2009). Nobody now regrets that the label came before scientific unanimity — and no one should propose waiting for unanimity now.

Quotable summary: the framework maps three classic remedies to three classic market failures — disclosure cures information asymmetry, control cures lock-in, and duty prices the externality. Consumer law has walked this exact staircase before.

What KOSA does and doesn’t reach

A federal bill already occupies part of this ground: the Kids Online Safety Act (S. 1748, 119th Cong.). KOSA is the right instinct aimed at a narrower target. It regulates design features and specific harms to minors — a duty of care against enumerated harms (§102), default safeguards and parental tools (§103), and a filter-bubble toggle between a platform’s personalized algorithm and a non-personalized one (Title II). What it never names is the thing this brief is built around: the optimization objective itself. KOSA asks platforms to mitigate the outputs of an engagement objective for minors; it never requires them to disclose what that objective is, never gives adult users any control over it, and never makes the objective legible to the researchers and regulators who would judge whether the outputs improved. The gap is structural, not incidental — KOSA governs the feed’s effects on children; this framework governs the boss of the feed for everyone, which is the record on which any duty (KOSA’s included) ultimately has to be enforced.

The section-by-section notes below mark, at each tier, exactly where KOSA already reaches and where it stops.


3. Tier 1 — Disclosure of the optimization objective

What it requires

  1. A standardized plain-language label. Covered platforms must publish, and present at account creation and within settings, a disclosure stating: (a) the principal metrics the recommender system is designed to maximize or optimize; (b) the principal user-data inputs it relies on; and (c) whether and how the objective differs for minors. The regulator publishes a fixed format — length-limited, plain-language, uniform across platforms — the way nutrition labeling fixed a format for food.
  2. Material-change notice. Changes to the disclosed objective require updated disclosure within a defined period.
  3. Verification access. Qualified academic researchers and the enforcing agency receive defined, privacy-protected access sufficient to audit whether the disclosure is accurate. A label no one can check is a press release.
  4. A truthfulness hook. An inaccurate disclosure is an enforceable deceptive practice under the state’s existing UDAP statute — no new liability theory required.

Precedent

The EU Digital Services Act (Article 27) already requires platforms operating in Europe to disclose the main parameters of their recommender systems — meaning large platforms have already built the compliance capacity a state would ask for. Federal proposals (e.g., filter-bubble and platform-accountability bills introduced in recent Congresses) contain similar disclosure cores. The deeper American lineage runs through two statutes: the 1933 Securities Act, which did not tell issuers what to sell but required them to tell the truth about it — and the 1965 cigarette warning label, the modest disclosure rung on which every subsequent tobacco intervention was built. Disclosure-first is not timidity; it is how the durable regulatory ladders in American history have all started.

Consequences and gaming risks

  • Compliance cost: low. Operators know their objectives; the cost is publication and audit interface, borne principally by the largest firms (see size thresholds, §6).
  • Primary gaming risk: disclosure theater — burying the objective in legalese or disclosing vague values (“we optimize for meaningful experiences”). Mitigation: the standardized format names permissible metric categories, and the audit right lets the agency test the label against the system’s actual training targets.
  • What Tier 1 alone will not do: change any feed. Its function is to create the public record — which platforms optimize for what, with what stated effects — on which Tiers 2 and 3, private ordering, and public debate all depend.

Constitutional footing

Compelled factual, uncontroversial commercial disclosure is reviewed under the most deferential First Amendment standard applicable in this space (Zauderer line). Disclosure mandates do not tell a platform what to carry or how to rank it; they tell it to describe its own commercial mechanism truthfully. Of everything in this field, this is the provision most likely to survive challenge intact — which is exactly why it belongs first on the ladder.

Quotable summary: Tier 1 asks platforms for nothing they don’t already know and nothing Europe hasn’t already made them build — it simply requires them to tell their users the truth about who the feed works for.

Where KOSA reaches this — and where it doesn’t

KOSA’s disclosure provisions stop short of Tier 1. KOSA §104 (“Disclosure”) requires notice to minors and parents about safeguards, parental tools, and personalized-recommendation-system options (§104(a)–(b)), plus advertising labels (§104(c)). KOSA §105 (“Transparency”) requires large platforms to publish an audited annual report describing, among other things, “whether and how the covered platform uses design features that increase, sustain, or extend the use of a product or service by a minor” (§105(c)(2)(B)) and how personal data feeds recommendation systems (§105(c)(2)(C)).

That is real transparency — but about features and effects, not the objective. Nowhere does KOSA require a platform to state, in a standardized user-facing label, the metric its recommender is designed to maximize. §105’s report is minors-scoped, audit-gated, and annual; Tier 1’s label is all-users, plain-language, and present at account creation. Contrast, briefly: KOSA tells parents what the safeguards are and tells auditors how design affects minors; Tier 1 tells everyone what the feed is for. The former describes the guardrails; only the latter names the driver. Tier 1 also supplies what KOSA’s own §102 duty of care most needs and lacks — a public, verifiable statement of the optimization objective against which “reasonable care” can actually be measured.

Takeaway: KOSA discloses the safeguards; Tier 1 discloses the objective. A duty of care with no disclosed objective is a standard with no yardstick.


4. Tier 2 — User control of the recommender

Tier 2 grants users three rights over the systems that mediate what they and their children see: the right to exclude, the right to tether, and the right to tune.

What it requires

1. The right to exclude — content-rating filters that bind. Covered platforms must (a) classify content along a published attribute taxonomy (machine classification expressly permitted — modern models make rating user-generated content feasible at a scale 1996 broadcasting could never have imagined), and (b) expose user-facing exclusion controls against those categories, honored across every ranked surface — feed, recommendations, search suggestions, advertising — above a narrow, non-negotiable safety floor.

The drafting key is the advertiser-parity rule. Every major platform already classifies essentially all content along granular suitability taxonomies — for advertisers, under industry brand-safety frameworks, so that no brand’s ad appears next to content the brand dislikes. The statute simply requires that users receive suitability controls at least as granular, and at least as strictly enforced, as those the platform offers its advertisers. This one provision defeats the infeasibility objection with the platform’s own product sheet: the classification machinery exists, it is sold commercially today, and the only question is whether citizens may use what advertisers already enjoy.

An anti-placebo requirement completes it: an exclusion, once set, must be verifiable under the Tier 1 audit right. “Not interested” must mean something measurable.

2. The right to tether — parent–child governance of a minor’s feed. Platforms must offer a robust supervisory link between a verified parent or guardian account and a minor’s account: age-banded default presets; per-category exposure dials reading the same rating taxonomy as the exclusion right; time, autoplay, and notification settings; non-bypassable without the governing adult; default-on for known minors; and a defined path by which the minor ages into full self-governance at majority.

The drafting lesson from live litigation is sharp: statutes structured as parental permission to be online (access gates) have been repeatedly enjoined; statutes structured as parental tools and protective defaults have fared far better. Tether is tools, not gates — the child is not barred from the public square; the parent simply holds the dials the platform currently holds. The protective-defaults tradition is older than the internet: the driving age, the tobacco age, and the national minimum drinking age (1984) all set age-based defaults on products lawful for adults. Tethered feeds extend that tradition; they do not invent one. Tethering does presuppose knowing who is a minor; recent precedent has strengthened states’ footing on age assurance, and the brief recommends method-flexible age-assurance language rather than statute-frozen technology.

3. The right to tune — user authority over the ranking objective.

  • The floor: a non-profiling feed option (chronological, subscription-only, or explicit-preference-based), reachable in no more taps than the default, persistent across sessions, and not punitively quality-degraded.
  • The dial: for the largest platforms, user-adjustable ranking preferences — up- and down-weighting stated interests and content classes — that demonstrably alter output. The anti-placebo audit applies here with full force: a control that does not measurably change the feed’s distribution is an enforceable deceptive practice.
  • The ceiling (optional, forward-looking): delegated access for accredited third-party ranking providers — “middleware” — converting algorithmic choice from a toggle into a market. The most innovation-positive lever available, already live in protocol form on open networks; states may reasonably stage it as a study-and-report provision.

Precedent

  • The V-chip is the direct ancestor. The Telecommunications Act of 1996 required (a) an industry content-rating system and (b) a user-controlled filtering device in every television sold in America. Congress has already required rate-and-exclude once, at national scale; the difference today is that machine classification makes rating user-generated content genuinely feasible in a way 1996 broadcasting never was — and the platforms have already built it for their advertisers.
  • Section 230 itself blesses user control. 47 U.S.C. §230(b)(3) declares it the policy of the United States “to encourage the development of technologies which maximize user control over what information is received.” Tier 2 is that declared policy, made enforceable — drafted, in effect, in the platforms’ favorite statute.
  • DSA Articles 27(3) and 38 (recommender options and a non-profiling alternative for the largest platforms) — compliance capacity already built in Europe. The federal Filter Bubble Transparency Act proposal centered the same alternative.
  • Existing voluntary family-pairing features (major platforms already ship parental-supervision modes) prove tethering’s technical feasibility; their weakness — optional, shallow, easily bypassed — is precisely what the statute cures. State parental-tools statutes (Texas, Florida) and the enjoined access-gate statutes (Utah, Arkansas) together supply the tools-not-gates drafting lesson. COPPA remains the under-13 floor.

Consequences and gaming risks

  • The buried toggle and the placebo dial: technically compliant controls that are hard to find, easy to lose, or that barely alter output — platforms have shipped “not interested” buttons with negligible measured effect. Mitigations: prominence/persistence parity, and the effect-size audit (a control must demonstrably change the feed’s distribution).
  • Rating disputes (who decides what counts as category X?): set the taxonomy by delegated rulemaking with industry and civil-society input, modeled on the co-regulatory rating regimes — film, television, games — that have functioned for decades. Platforms may exceed the taxonomy’s granularity; they may not fall below it.
  • Honest cost: meaningful minorities choosing non-profiled feeds and aggressive exclusions reduce advertising yield; expect opposition framed as infeasibility. The advertiser-parity rule bounds the rebuttal to one sentence: the machinery exists, because you sell it.
  • Interaction with Tier 1: control without disclosure is a dial with no markings. The label tells users what they are turning off; the audit verifies the off-switch works.

Constitutional footing

Tier 2 occupies the strongest ground in the entire field, because the government restricts nothing — it arms private choice. United States v. Playboy teaches that user-controlled blocking is the constitutionally preferred less-restrictive alternative to government content restriction, and §230(b)(3) states the same policy affirmatively. The Moody/NetChoice line protects a platform’s own expressive curation — but mandating an additional, user-directed option alongside the platform’s curated default is materially different from commandeering the curation itself. The care points: the compelled-classification component should lean on the advertiser-parity structure (requiring parity with the platform’s own existing commercial classifications is factual-commercial in character, not state-scripted opinion), tether must stay tools-not-gates (the access-gate statutes are the cautionary record), and minors’ provisions bind tightest when tied to design features and data practices rather than content categories — the central lesson of the design-code litigation. On age assurance, recent precedent upholding verification requirements for content harmful to minors has strengthened the state’s footing, though its scope should not be overclaimed.

Quotable summary: Tier 2 gives every user the controls platforms already sell to advertisers, gives every parent the dials the platform currently keeps for itself, and makes real the user control that Section 230 has promised since 1996. It doesn’t tell any American what to see — it returns the deciding to them.

Where KOSA reaches this — and where it doesn’t

This is where KOSA comes closest — and where the gaps are most instructive across the three rights.

  • Exclude. KOSA has no general content-exclusion right. It restricts advertising of specific illegal products to minors (§103(d)) and lets minors “limit types or categories of recommendations” (§103(a)(1)(D)(ii)), but there is no user-facing filter across all ranked surfaces, no published attribute taxonomy, and — critically — no advertiser-parity rule. Tier 2’s central lever (citizens get suitability controls at least as granular as advertisers already enjoy) has no KOSA analog.
  • Tether. KOSA reaches this squarely and is tools-not-gates by design: default safeguards for known minors, parental tools to manage settings and restrict purchases and time, default-on for children (§103(a)–(b)). On this right KOSA and Tier 2 largely agree — Tier 2’s tether is, in effect, KOSA §103 written for a state statute. Where Tier 2 adds value is coupling those dials to the same content-rating taxonomy as the exclude right, which KOSA lacks.
  • Tune. KOSA offers a binary, not a dial. Its Title II filter-bubble provision requires platforms using an “opaque algorithm” (one built on user data not expressly provided) to give notice and let users “easily switch between the opaque algorithm and an input-transparent algorithm” (§§201–202). That is the floor of Tier 2’s tune right — a non-profiling option — and KOSA deserves credit for it, and for applying it to all users, not just minors. But it is only the floor: KOSA has no adjustable ranking preferences (the “dial”), no anti-placebo effect-size audit, and no middleware/third-party-ranking pathway (the “ceiling”). KOSA lets a user turn personalization off; Tier 2 lets a user turn it toward what they actually want — and requires proof the controls bite.

Takeaway: KOSA gives minors an off-switch and parents a set of dials; Tier 2 gives every user a full console — exclude, tether, and tune — and, via the advertiser-parity rule and the effect-size audit, makes the controls verifiable rather than decorative.


5. Tier 3 — A duty of alignment to the user’s best interest

What it requires

The ambition tier: covered operators owe users a duty of loyalty in recommender design — an obligation not to deploy optimization objectives known to be adverse to users’ material well-being, beginning with minors.

Two drafting architectures exist, and the choice between them is the central Tier 3 decision:

Architecture Description Strengths Risks
Design-code duty (UK Children’s Code model) Enumerated obligations: best-interests assessments for design changes affecting minors, prohibitions on specific engagement-extending design features for minors, data-minimization defaults Concrete, auditable, litigation-tested abroad; ties to design, not content Enumerations age; requires periodic regulatory update
Fiduciary/loyalty standard (information-fiduciary model) A general duty: operators processing user data to personalize experiences may not use that data in ways adverse to the user’s interests Adapts as technology changes; matches the intuition (doctors and advisors owe this already) Vagueness challenges; needs safe harbors to be administrable

The pragmatic synthesis most likely to survive: a general loyalty duty for minors, given content through an enumerated design code, with safe harbors for operators who (a) publish accurate Tier 1 disclosures, (b) provide functioning Tier 2 controls, and (c) undergo periodic independent design audits. Compliance with the first two tiers becomes the affirmative defense — which is what welds the ladder together and rewards early movers.

Why Tier 3 depends on the first two tiers

A best-interest duty is unenforceable against an invisible objective: courts and agencies cannot police alignment they cannot observe. Tier 1 makes the objective observable and creates the documentary record (what the operator said its system does) against which loyalty is judged. Tier 2 establishes the feasible alternative (the non-profiling feed) that defeats the “compliance is impossible” defense. Legislatures that attempt Tier 3 first — as some early state efforts did — draw the hardest constitutional fire with the thinnest record. Sequence is strategy.

Constitutional footing

The honest statement: this tier is contested ground. Duties keyed to content exposure invite strict scrutiny; duties keyed to design features, data practices, and commercial loyalty stand on the same footing as product-safety and fiduciary law generally, which states have regulated for a century. The design-code litigation to date teaches one lesson above all: draft the duty around what the system does with data and design, never around what speech it carries.

Quotable summary: Tier 3 states a principle every professional already lives under — if you hold power over someone because you hold their data, you may not use it against them — and applies it to the most powerful personalization systems ever built, starting with the children who never consented to be optimized.

Where KOSA reaches this — and where it doesn’t

KOSA is, at its core, a Tier 3 instrument — and its structure is this brief’s argument in miniature. KOSA §102 imposes a duty of care: a covered platform must “exercise reasonable care in the creation and implementation of any design feature to prevent and mitigate” enumerated harms to minors (§102(a)) — a design-code duty keyed to design features, not content, which is exactly the constitutionally durable framing §5 recommends. On architecture, KOSA and Tier 3 agree: duty tied to design and data, not speech.

Two contrasts matter. First, scope: KOSA’s duty runs only to minors; Tier 3 begins with minors but frames a general loyalty duty, and KOSA supplies no adult loyalty obligation at all. Second, and more important, sequence: KOSA legislates the duty (the hardest rung) without first mandating the disclosure and control rungs beneath it. KOSA §102’s “reasonable care” must be judged against an optimization objective KOSA never requires anyone to disclose, and its “contributing factor” test presupposes a non-engagement alternative KOSA never requires platforms to offer to adults. This brief’s §5 (“Why Tier 3 depends on the first two tiers”) is precisely the caution KOSA’s drafting invites: a duty is only as enforceable as the objective is observable and the alternative is real. Tier 1 and Tier 2 build the evidentiary record and the feasible alternative that make a KOSA-style duty administrable rather than merely aspirational.

Read the safe-harbor synthesis in this section as, in effect, a friendly amendment to KOSA: keep the design-code duty, but let compliance with a real disclosure label and functioning user controls be the affirmative defense — which is what welds the ladder together and rewards the platforms that move first.

Takeaway: KOSA is the duty without the ladder beneath it. Tier 3 is the same duty, built on the disclosure and control that make it enforceable — and extended past minors to every user the feed acts on.


6. Drafting considerations (all tiers)

  • Definitions. “Recommender system” should be defined functionally (software selecting/ordering content per-user from a candidate pool) to avoid capture of simple chronological or search-relevance ordering. “Optimization objective” should reference the metrics a system is designed or trained to maximize — a factual, discoverable matter.
  • Thresholds. Apply Tiers 1–2 to platforms above a substantial user threshold (e.g., 1M+ state residents or a national MAU floor) to spare startups and local forums; Tier 3 minors’ duties may reasonably reach further down.
  • Enforcement. Agency/AG enforcement with civil penalties is the defensible core. A private right of action multiplies deterrence and opposition in equal measure; several states have traded it away for passage (the CCPA compromise — narrow PRA, broad AG authority — is the working template).
  • Rulemaking. The standardized label format and audit protocols belong in delegated rulemaking, not statute — formats must evolve with the technology.
  • Severability. Essential. Litigation will target the most ambitious provisions; the ladder is designed so lower tiers stand alone if upper ones are enjoined.
  • Preemption posture. A federal preemption effort against state technology laws is actively underway. Disclosure-and-consumer-protection framing (traditional state police power, UDAP lineage) is the strongest ground on which to hold; provisions drafted as consumer disclosure and product design rather than speech regulation both litigate better and preempt harder.

7. Anticipated objections, answered briefly

  • “This burdens innovation.” Tier 1 requires publishing a fact operators already possess; the largest operators already built these capacities for Europe. The size thresholds exempt startups entirely — indeed, a disclosure regime helps insurgent platforms that compete on user-aligned design by making the incumbent’s objective visible.
  • “The First Amendment forbids it.” It forbids some things proposed in this space — which is why this framework leads with factual commercial disclosure and user empowerment, and ties duties to design and data rather than content. The ladder is ordered by constitutional durability on purpose.
  • “Parents, not government, should manage this.” Tier 2’s entire function is to give parents and users the tools to do exactly that — tools the market, structured on engagement economics, has declined to provide. Disclosure and control are the prerequisites of parental responsibility, not substitutes for it.
  • “Platforms will game it.” Some will attempt to; §§3–5 name the gaming vectors (disclosure theater, buried toggles) and the mitigations (standardized formats, parity rules, audit rights). A law that anticipates evasion in its text is a law drafted by people who understood the industry.

8. Summary for the member

Three questions, in order, that a legislature can put to any platform operating on its residents:

  1. What does your algorithm work for?Say it plainly, and let us verify it. (Disclosure)
  2. Can my constituent exclude what they don’t want, tether their kids, and tune the feed?Real dials, not buried toggles — the same controls advertisers already get. (Control)
  3. When it acts on a child, whose interest does it serve?If the answer is “the advertiser’s,” the law has something to say. (Duty)

A state can enact the first this session, the second alongside or next, and build the record that makes the third durable. The technology is not slowing down; the question is not whether recommender systems will be governed, but whether the governing is done by the people’s representatives or left, by default, to the systems’ owners.


Appendix: precedent index (selected)

  • EU Digital Services Act Arts. 27 (recommender parameter transparency), 38 (non-profiling option for very large platforms)
  • U.S. Surgeon General, Social Media and Youth Mental Health advisory (2023)
  • California minors’ addictive-feed statute (SB 976) and Age-Appropriate Design Code (AB 2273) — including the injunction record as drafting guidance; New York SAFE for Kids Act
  • UK Age-Appropriate Design Code (“Children’s Code”) and Online Safety Act duty-of-care structure
  • Federal proposals: Filter Bubble Transparency Act; Kids Online Safety Act (duty-of-care architecture)
  • User-control lineage: Telecommunications Act of 1996 (V-chip + mandated TV content-rating system — the rate-and-exclude precedent); 47 U.S.C. §230(b)(3) (declared policy of maximizing user control); United States v. Playboy Entertainment Group (2000) (user-controlled blocking as preferred less-restrictive alternative); FSC v. Paxton (2025) (age verification upheld for content harmful to minors — scope caveats apply); industry brand-suitability frameworks (GARM and successors — the classification infrastructure the advertiser-parity rule references); state parental-tools statutes (TX SCOPE Act, FL) vs. enjoined access-gate statutes (UT, AR)
  • Regulatory lineage: Federal Cigarette Labeling and Advertising Act (1965) — disclosure-first sequencing; tobacco Master Settlement Agreement (1998) — coordinated state-AG enforcement; National Minimum Drinking Age Act (1984) — age-based protective defaults; state casino self-exclusion registries — law enforcing second-order preference
  • Scholarship: information-fiduciary literature (Balkin et al.); middleware/algorithmic-choice literature (Fukuyama et al.); first-order/second-order preference literature (Frankfurt); the securities-disclosure analogy (1933 Act structure)
  • Litigation to track: Moody v. NetChoice line (platform curation and state power); design-code challenges (NetChoice v. Bonta line) — statuses evolving; verify current posture before hearings.

Prepared July 2026. This brief presents legislative options and their consequences; verify current litigation status and bill numbers before relying on specific citations. The American Fabric discloses funding, affiliations, and recusals on request.