Issue #66

Jury Verdict Holds Meta, Google Liable for App Design

A $6 million verdict against Meta and Google raises real questions about design liability, but it doesn't rewrite the rules for every platform.

BusinessJury Verdict Holds Meta, Google Liable for App Design

A Verdict Ordering Meta and Google to Pay $6 Million in Damages

On March 25, 2026, a jury in the Los Angeles Superior Court returned a verdict ordering Meta and Google to pay a combined $6 million in damages. The plaintiff, a 20-year-old woman who started using YouTube at age 6 and Instagram at age 9, argued that the design of both services had harmed her mental health. The jury found the companies liable for negligent design and operation, and for failing to adequately warn users of the risks.

The day before, on March 24, a jury in New Mexico handed down a separate verdict in a consumer-protection case, imposing $375 million in civil penalties on Meta. That case turned on the state attorney general’s claim that the company had misled consumers about platform safety — a different matter from the personal-injury damages at issue in the Los Angeles case.

What makes the Los Angeles case notable is that an actual jury held the companies accountable for their product design choices. That said, this verdict does not amend Section 230 or eliminate platform immunity across the board. Both companies have said they intend to appeal. Which design choices carry which liabilities remains very much an open, contested question.

Section 230 Deals With Liability for Content Other People Post

Section 2301 is a provision of the U.S. Communications Decency Act, enacted in 1996. Its core rule bars treating an internet service or its users as the publisher or speaker of information provided by another content provider. It’s the legal basis that has long limited claims seeking to hold platforms liable as publishers for what users write.

The provision reduced the legal exposure internet services face when handling third-party posts. That said, it isn’t a blanket immunity covering everything a platform itself does. The statute carries related carve-outs too, including federal criminal law and intellectual property.

Instagram and YouTube don’t just store posts — they also run features like recommendations, autoplay, and notifications. In litigation, the key question becomes whether claims about these features are really seeking to hold the company liable for publishing third-party content, or whether they’re challenging the company’s own design and operation.

Platform companies have defended lawsuits by invoking both Section 230 and First Amendment free-speech protections. Because these are distinct legal grounds, even claims where Section 230 doesn’t apply can still leave open questions of free speech, negligence, or causation.

Simply labeling something a “product defect” doesn’t automatically get you around immunity, either. In the 2017 case Herrick v. Grindr, the plaintiff argued the app lacked safety features to prevent impersonating profiles. In 2018, a federal district court found that the product liability claims, among others, ultimately sought to hold the platform responsible for content created by another user — and applied Section 230.

What Design Choices Did This Lawsuit Actually Target

The plaintiffs in the LA case didn’t focus solely on individual posts users had uploaded. Instead, they challenged whether the features designed to keep people using the service longer and more repeatedly, along with the safeguards for minors, were adequate.

The argument was that infinite scroll, autoplay, and notifications made it hard to stop using the platforms, and that the companies knew about this risk yet failed to sufficiently mitigate it. The mere existence of a specific feature doesn’t automatically create liability — courts have to determine whether there was negligence in design and operation, and whether that negligence contributed to the plaintiff’s harm.

In this case, the claims concerning design and operation went all the way to trial. The jury found that negligence by both companies was a substantial factor in causing the plaintiff’s harm. This conclusion was based on the evidence presented in this specific case — it’s not a general rule stating that every recommendation algorithm or notification system falls outside Section 230’s protections.

The damages awarded combined $3 million in compensatory damages with $3 million in punitive damages. Liability was split 70% to Meta and 30% to Google, translating to $4.2 million and $1.8 million respectively. The fact that punitive damages were awarded at all is a detail worth examining closely.

What should catch product teams’ attention is the question of what risks were reviewed during development. New Mexico’s Department of Justice stated that in a separate case, it had presented internal employee warnings and safety-related documents as evidence. What matters isn’t explaining a feature’s purpose after the fact — it’s what actions were actually taken once the risk was known.

Similarities and Differences with the Tobacco Lawsuits

There’s been discussion comparing social media lawsuits to the tobacco litigation of the past. I’ve also covered, both on YouTube and in offline lectures, the possibility that regulatory or taxation logic similar to what applies to tobacco and alcohol could eventually be applied to social media. That said, this verdict doesn’t necessarily lead directly to that kind of tax regime.

The parallels with the tobacco lawsuits include marketing to minors and how much the companies knew about the risks involved. The 1998 Master Settlement Agreement between tobacco companies and 46 states included payments of at least $206 billion over 25 years. Whether the social media cases will lead to a settlement of similar scale or structure remains unknown.

The relationship between social media use and mental health needs to be examined together with usage patterns, individual circumstances, and other life conditions. The American Psychiatric Association does not classify “social media addiction” as a formal disorder in the DSM-5-TR2. That doesn’t mean problematic use or harm doesn’t exist—but whether or not a diagnosis is listed in the manual can’t by itself determine legal causation in an individual case.

Social media also involves users’ rights to expression and to receive information, as well as platforms’ editorial judgment. So it’s hard to fully explain the legal issues at stake simply by analogizing to tobacco-style regulation.

As of March 26, Moody’s counted more than 4,000 lawsuits in the US related to addictive software design, targeting 166 companies. That figure includes not just social media but gaming, sports betting, and chatbots as well. Not all of these are follow-on suits filed after this verdict, nor will they all reach the same conclusion—but the number shows that similar allegations are being raised across many industries.

AI chatbot lawsuits have also raised design-responsibility questions

With AI chatbots, the issues at stake go beyond the conversation content itself—they include how the product hooks users, how it verifies age, and whether it intervenes in dangerous conversations.

One example is Garcia v. Character Technologies, filed in Florida in 2024, when the plaintiff’s son was 10 years old. The plaintiff argued that her teenage son’s use of Character.AI contributed to his death. In May 2025, the court found that product-liability3 doctrine could apply to claims targeting the app’s design flaws, and allowed some of those claims to proceed to trial. This was not a final ruling establishing causation or liability.

The court also examined whether the plaintiff’s claims against Google—that it was substantively involved in developing the underlying large language model (LLM)4 and the product itself—were specific enough to move forward. The court accepted some of these claims, but it did not rule that liability automatically extends to every company that merely supplies technology or cloud infrastructure. A settlement between the parties in this case was reported in January 2026.

Separately, legislative discussions are also underway. Senator Marsha Blackburn released a discussion draft of the TRUMP AMERICA AI Act on March 18, 2026. It includes a duty for AI developers to prevent foreseeable harm and a sunset clause for Section 230. Since this is only a discussion draft, it should not be read as law already in effect or as a finalized legislative direction.

Oswarld’s Lens

Watching this case, I keep coming back to the question of what standard product strategy should use for safety. Planners and designers need to be able to explain why they chose a given feature and what risks they reviewed. If the answer only exists to hold up in court, the product itself hasn’t changed.

Describing a service’s role as a “platform” doesn’t settle the question of design responsibility. What matters to product teams directly is looking at what behavior the product encourages in users, alongside what choices the company made.

Product teams routinely track metrics like usage frequency, session length, and return rate. But the fact that someone used a product for a long time doesn’t automatically mean it helped them. This is especially true for features aimed at minors — you need to check not just how long they were used, but what kind of experience those features actually created.

Wanting to boost engagement doesn’t, by itself, establish legal fault. Still, separate questions need answering: was harm foreseeable, were there alternatives that could have reduced the risk, and were warnings and protective measures adequate?

I’d suggest three things to product teams.

  1. Document the reasoning behind your design and the alternatives you considered. Keep records not just of goals, but of anticipated risks, test results, and any problems discovered — and how you responded — after launch.
  2. Look at usage time together with user experience. Check whether notifications can easily be turned off, whether usage can be stopped, and whether complaints about discomfort keep recurring.
  3. Build safety review into the design process. Alongside privacy protection, this means reviewing age-appropriate default settings, responses to risk signals, and warning and help-seeking features. The specific legal obligations will depend on the service and jurisdiction, so those need to be confirmed separately.

Closing

This verdict is a case where legal liability over product design led to an actual damages ruling. That said, statutory amendments, jury verdicts in individual cases, and settlements in other lawsuits are all separate processes.

  • The LA jury found Meta and Google liable for design and operational negligence, among other claims, and set total damages at $6 million.
  • Section 230 doesn’t shield every design decision, nor is it categorically excluded from every design-based claim. The outcome depends on what the claim is actually targeting.
  • Product teams should be able to explain not just a feature’s intended purpose, but the risks they anticipated, the safeguards they chose, and how they responded after launch.

In your next product review, it might be worth listing the difficulties users could encounter right alongside the feature’s success metrics. You can start simply by discussing alternatives that would reduce that risk.

Looking at the draft against the source, everything matches well: headings, links, image, footnotes, numbers, and no Hangul remains. The translation is accurate and idiomatic.

Your take shapes the next issue

What resonated most in this issue, or where has your experience been different?

Any registered reader can comment for free.

References & Further Reading

I referenced the materials below to confirm the details of the verdict, the relevant statutes, and the progress of each individual lawsuit.

The author is Oswarld (Kwangseob Ahn). Current roles: Adjunct Professor at Sejong University, Strategy Consultant at INLEVEL9. Career, research, books, and recent work are kept current on the About page. Latest · July 2026: HEMA-2: A Consolidation-Aware Tri-Memory Architecture with Multi-Channel Scheduling for Lifelong Conversational AI.

Footnotes

  1. Section 230 is a provision of U.S. federal law concerning how internet services handle third-party information. It does not mean immunity for every action a platform takes.

  2. The DSM-5-TR is the manual the American Psychiatric Association publishes for diagnosing and classifying mental disorders. Other systems, such as the International Classification of Diseases (ICD), also exist, so the absence of a condition from the DSM does not by itself rule out all clinical or legal judgments.

  3. Product liability is the legal doctrine that holds manufacturers and others responsible for harm caused by a defective product. The specific requirements, and how they apply to digital products, vary depending on the jurisdiction’s law and the nature of the claim.

  4. An LLM is a large language model trained on vast amounts of language data to generate text. The mere fact that a company developed or provided one does not automatically create liability for harm caused by every end service built on it.