Post

Complexity Is Not a Price

In response to: “Meta Ordered to Pay $942 Million to Address Harm to Kids From Social Media” — The Wall Street Journal

Something about the New Mexico ruling against Meta is bothering me, and it isn’t the size of the number.

A state judge ordered Meta to create a $567 million abatement fund, on top of $375 million in civil penalties a jury assessed back in March. Judge Bryan Biedscheid explained the fund this way. It was “necessary, due to the wide-ranging impacts of the harm and the complex nature of the remedy.”1

Read that again. The remedy is complex, and therefore the fund is large.

That isn’t how complexity works in any other field. When you understand a problem poorly, the honest response is wider error bars, not a bigger point estimate. If a client were told that fixing something would cost $567 million because the work was complicated and nobody quite knew how to do it, the consultant would be fired, or at least would be sent back to produce a plan. Complexity is the reason you stage the money and instrument the result. Fund a cohort. Measure it. Expand what works, stop what doesn’t. Complexity is never the reason you write one check and walk away.

So what is the $567 million actually buying?

The word “abatement” is doing quiet work here. The term comes out of opioids, lead paint, and contaminated groundwater. In all three, the harm is a finite stock sitting somewhere in the world, and money removes it. You can point at the paint. You can count the wells. There is a state where the job is done, and the fund’s size is an estimate of the distance to that state.

Nothing like that exists here. What Meta is being asked to abate is an adversarial problem, which means people on the other side who adapt. Every defender in every adversarial domain lives with this. Spam, fraud, malware, sanctions evasion. Detection is signature-bound, so it is reactive by construction, and the attackers now have tooling that turns ten evasions into ten thousand. Nobody in any of those fields claims a terminal state, because there isn’t one. If the harm can’t be abated, what is the abatement fund abating?

That question doesn’t excuse Meta of anything. It just means the instrument doesn’t fit the problem, which is a category error rather than a pricing dispute.

Then there’s the mismatch between what the state proved and what the court ordered.

The strongest evidence in the case was the Attorney General’s decoy investigation. Accounts were created that stated an age under thirteen, and sexual content and adult contacts reportedly came to them anyway. That is concrete, demonstrable evidence in a domain where population-level causation gets argued forever. It concerns the recommender. It concerns which accounts get surfaced to which other accounts.

Now look at the remedies. Time limits on how long underage users in the state can stay in the apps. Like counts hidden by default. Disclosure of risk. Those address compulsive use and social comparison, which was the weakest causal ground in the entire case. So how would any of them change what a decoy account sees? Run the same investigation next month, under the order, and I think you get the same result. Nothing that was ordered touches the thing that was proved.

The like-hiding order is the strangest of the three, because the experiment has already been run. Instagram tested hiding like counts at scale for roughly two years and found the effect mixed enough that it shipped the feature as a user option in May 2021 rather than as a default. The academic literature is no more conclusive than the company’s own trial was.2 So a court has now mandated as a default the one thing its operator declined to make a default after two years of looking at the data.

There’s a second problem with the decoy evidence, and it’s the one I’d expect to see on appeal. Those accounts were built by a party with a case to win. A recommender is a steerable system. Seeded follows, dwell time, search history, profile settings, and discoverability all shape what comes back to you. There’s no disclosed control group, no base rate for an ordinary minor’s account, and no comparative run against Snap or TikTok or YouTube under the same conditions. Run a hundred decoys and report the worst and you’ve published a maximum, not an average.

I want to be careful here, because the objection has a limit. Disclosed investigative decoys are ordinary technique, used by NCMEC and by ICAC task forces and by journalists, and this evidence was subject to cross-examination. Decoys don’t become misconduct just because the party running them had a motive. But what they establish is that a determined operator could elicit that output. They don’t establish that a typical twelve-year-old runs into it. That’s a real finding and a narrower one, and the fund is priced as though the broader one had been proven.

Part of this ruling seems right, and saying so seems to sharpen everything else.

The liability finding is sound. The question the jury answered was whether Meta’s representations about its own platform tended to mislead, given what the company knew. That’s fact-finding about past conduct, which is what juries have always done. It doesn’t require a court to set engineering policy. And it doesn’t depend on anyone else’s behavior. What Meta said about its platform is not downstream of what users told Meta, or of which parent created which account. That claim survives every technical objection you can raise against the rest of the case.

So the verdict rests on one thing and the remedy rests on another. The verdict is about representations. The fund is priced as if a design defect had been tried and proven. That gap is why the liability finding will probably survive and the fund shouldn’t.

The Attorney General said something after the ruling that I keep turning over. “New Mexico led the way in the courtroom. Now other states, and other countries confronting the same crisis, have a roadmap they can follow.”

That is a sentence about replication and leverage. It is not a sentence about New Mexico’s children. It isn’t improper, and it may well be true. But it’s the kind of thing you say when the number is the product. The next trial starts jury selection in Oakland with four state attorneys general, and Meta’s own filing says they’re asking for more than a trillion dollars. Meta spent $2.4 billion on legal proceedings in the second quarter alone. Whatever that river of money is doing, very little of it is arriving anywhere near a twelve-year-old. In fact, the AG’s wording seems to characterize the effort as successful gold digging.

A sympathetic reading of this is that everyone did their job and the institution simply lacked the instrument. There’s something to it, and some of the credit is real. The Attorney General’s office probably picked the right statute to secure “a win”. Consumer protection carries a lower burden than product defect and steps around Section 230, which had killed every previous theory. That’s lawyering, but a possible synonym is opportunism. They went first, alone, in state court, instead of waiting for the multi-state pack, and it worked. The judge kept liability and remedy separate, which is procedurally correct, and cut the fund below the state’s $779.5 million ask rather than rubber-stamping it.

Then think about what a court would have to do to write the standard everyone actually wants. Specify it technically and it’s obsolete the moment the signature changes, and worse, it becomes a compliance ceiling a company can meet while the problem moves elsewhere. Specify it behaviorally and you get nudges that miss the mechanism, which is exactly what happened here. Specify it by outcome and you’re demanding the elimination of an adversarial harm, which nobody in any domain has ever managed. There’s no fourth option available to a single-defendant proceeding with no comparative evidence and no way to revise itself next year.

So the institution is genuinely the wrong shape for the job. I believe that. I no longer think it excuses anybody, and I’ve come to find the excuse itself corrosive, because it is available every single time and it has been used every single time.

Start with the judge, who is not a passenger here.

That sentence about complexity is not a finding handed up by the jury. It isn’t a statutory floor, and the parties didn’t stipulate to it. It is the court’s own reasoning in the court’s own words, and it inverts the relationship between uncertainty and cost. You don’t need an engineering degree to catch that. Logic is the craft. It is the thing the office is for. If someone handed me a memo arguing that we should spend more precisely because we understood less, I’d send it back before I finished the page, and I’d expect a judge to be quicker about it than I am.

A court sitting in equity also had more room than this ruling used. He could have awarded less. He could have staged the fund against reporting requirements, releasing tranches as programs demonstrated something. He could have retained jurisdiction and revisited in two years, which courts do routinely in institutional-reform cases and which is the standard answer when the right amount is genuinely unknown. He could have declined the abatement fund altogether and let the $375 million penalty stand as the sanction for what was actually proved. Every one of those was available to him. What he chose was a lump sum with no costed program attached and no mechanism to revise it, landing somewhere between the state’s ask and something smaller by a route nobody has shown.

The like-hiding order is the part I find least defensible, and it isn’t close. A judge uncertain whether a remedy works can ask. Judges order supplemental briefing constantly. If the history of that experiment wasn’t in front of him, then a mandate was imposed without anyone asking the obvious question about whether it does anything. If it was in front of him, he mandated as a default the very thing its operator declined to make a default after watching two years of its own data. I don’t know which of those happened and I’d like to, but there’s no version of the fork where the reasoning holds.

And he had the record. This is what moves it from error to something I find harder to forgive.

Tobacco is the template, and the numbers are not in dispute. The Master Settlement Agreement of November 1998 committed the manufacturers to roughly $206 billion in payments to 46 states through 2025.3 In fiscal 2025, those states collected $22.1 billion from settlement payments and tobacco taxes and spent $764.8 million of it on tobacco prevention and cessation. That’s 3.5 percent. For fiscal 2026 the figure is 3.4 percent of $21.7 billion. Exactly one state, Maine, funds its program at the level the CDC recommends, and seventeen states fund below a tenth of it.4 The litigation produced an enormous transfer and no standard. What actually moved smoking rates afterward was taxation, clean-indoor-air laws, and the labeling regime, none of which came out of a courtroom.

Opioids ran the same play twenty years later using the same word. Settlements totaling roughly $50 billion over two decades, most of which permit states to spend up to 15 percent on things that don’t qualify as remediation at all. Of the money that flowed in 2022 and 2023, about a third was spent or committed, about a third was set aside, and the final third could not be tracked because jurisdictions never produced public reports. More than $240 million went to non-remediation purposes, the largest share of it to legal fees. Settlement dollars have bought body scanners, K-9 units, bulletproof vests and patrol trucks. One county sent its share to the road and bridge department.5

And here is the detail I’d put on the wall. When the Arizona legislature moved $115 million of opioid settlement money to the Department of Corrections to help close a $1.4 billion budget hole, the Attorney General went to court to stop it and won a temporary restraining order. A Maricopa County judge dissolved it days later, and the money went to the prisons.6

A judge did that. Which is the point.

None of this is obscure. It is the most thoroughly documented failure mode of the precise instrument this court reached for, and the court reached for it by name. “Abatement” is not a neutral technical term. It is the word from those cases. If you borrow the instrument you inherit its record, and the record says that large sums delivered to state treasuries under this theory substantially do not arrive where the theory said they would.

At which point it’s tempting to call this what it looks like, which is a shakedown. I want to resist that word, because it claims something the evidence doesn’t establish.

A shakedown asserts intent at the moment of filing. The diversion happens downstream, years later, and mostly at the hands of legislatures rather than of the attorneys general who brought the cases. Arizona cuts against the accusation rather than for it. Mayes went to court to stop the diversion and lost. She was fighting her own legislature to keep the money pointed at the harm. You can’t use that episode as proof that attorneys general file these cases to raise revenue, because in that episode the attorney general was the one objecting.

So the charge isn’t that anyone is digging for gold. It’s that everyone now knows exactly what happens to the gold and reaches for the same instrument anyway. That’s recklessness rather than opportunism, and given the size of the record behind it, recklessness is the worse of the two. Opportunism can at least plead ignorance.

Two things do suggest the number has become the product. The roadmap sentence is about replication and leverage, for other states and other countries. And the next case, the one starting in Oakland, asks for more than a trillion dollars. That second one I can’t explain away. No costed remediation program for this harm reaches a trillion dollars. Nothing does. A figure that size is a function of what the defendant can pay rather than of what a fix would cost, and when an ask is untethered from any program that could absorb it, the ask is not about a program.

I should be fair about the limits of this. New Mexico hasn’t spent its $567 million yet, so what I’m applying is a base rate, not a fact about this fund. And punishment is a perfectly legitimate purpose that carries no promise whatever about destination. The $375 million in civil penalties is supposed to be a sanction. Nobody should expect sanction money to reach a child.

Which locates the problem precisely, and it isn’t the money. It’s the word. Call something a penalty and the state owes no account of where it lands. Call it abatement and you have made a specific promise about destination, borrowed a remedial theory to justify the size, and inherited the record that word carries. This court chose the word that makes the promise. That promise has now been broken twice in living memory, in public, with the receipts published every year since.

Now the jury, and I don’t think they get a pass either, though the fault is partly upstream of them.

The $375 million is a per-violation calculation, which means the multiplicand was almost certainly a proxy like account count. That converts a finding into an arithmetic artifact of how somebody else defined a word in the instructions. Weeks of deliberation against a trillion-dollar defendant, driven by a narrative built from internal documents, is also the textbook setup for anchoring and defendant-wealth effects.

But a jury is we-the-people by proxy. That is the whole design. We put twelve ordinary people in the box precisely on the theory that ordinary reasoning is sufficient to the task, and if that’s true then ordinary reasoning was sufficient to ask why the remedies had nothing to do with the evidence. Nobody needs a technical background to notice that the proof concerned what the system showed children and the order concerned how long they could stay logged in. If ordinary reasoning is good enough to convict, it is good enough to be held to. We can’t claim the authority and decline the accountability.

Then the legislatures, who are the ones with the actual instrument and have now declined to build it three times, each time after watching the previous attempt fail in public and in print.

And then us.

We bought the devices. We handed them to children whose ages we knew, and in many cases we created the accounts ourselves. We are the control point that actually works, because a child not on the platform is fully protected from it, and no verdict changes that. We also watched two decades of settlement money get spent on road and bridge departments and said very little, because the headline number felt like justice and reading the follow-up reporting is work. Every one of us who took the $206 billion as a win and never asked what happened next is part of why the third one looks exactly like the first two.

An institution missing an instrument is a problem. An institution shown three times that it is missing the instrument, reaching for the wrong one anyway, while the people it answers to applaud the size of the number, is not a problem. It is a series of choices with names attached, and one of the names is ours.

What makes this genuinely sad is that the standard is writable. It just has to be aimed at architecture instead of at content.

Almost every proposed rule for platforms founders on the same rock: enforcing it requires understanding language and intent, in context, over time. Relationship and history and intent mostly aren’t in the text, and no model is going to put them there. I’ve spent the last couple of years building things on top of these models, and my confidence about that has gone up rather than down. It’s a ceiling, not a defect waiting on better technology. So content-level enforcement is permanently incomplete, and everyone arguing about it is arguing about a thing that can’t be finished.

What would a rule look like that didn’t require reading anyone’s mind?

Structural constraints are the answer, and they escape the problem entirely. Take a rule like this one: adults sharing no connection with a minor cannot initiate contact with an account registered as a minor. That rule reads no messages. It judges nobody’s character. It requires no moral code, which matters enormously for a company operating across cultures that don’t agree on one. And it works against attack vectors nobody has articulated yet, which content rules by definition cannot. It will be leaky in implementation, because the invariant lives as a predicate scattered across call sites nobody has fully enumerated. Leaky and not requiring intent inference is still categorically better than requiring intent inference, which has no working version at any price.

Around a rule like that you can build the rest of a regime. Mandatory incident reporting. Third-party audits of the default settings on minor accounts. Published detection latency and response times. Safe harbor for good-faith internal disclosure, so that writing down a safety problem stops being an act of self-incrimination. That last one matters more than it sounds. Right now every honest internal document becomes trial evidence, which teaches companies not to look. Aviation solved that problem decades ago with no-fault NTSB disclosure. This ruling intensifies the exact dynamic that produced the documents it rests on.

None of that is exotic. It’s what aviation built, and what the FFIEC built for banks. It’s ex ante, technical, iterative, and industry-wide. It produces no headline number, which may be precisely why we got a $567 million fund instead.

And here is the part the industry ought to sit with. Codified standards protect defendants. Complying with FFIEC guidance is a defense. Meeting the building code is a defense. FDA approval preempts most design-defect litigation outright. I’ve done technology diligence for twenty-five years, and in regulated sectors the first thing to ask for is the evidence of compliance, because a company that can produce it has already answered half the questions requiring answers. Platforms can’t produce anything like it. So the standard gets constructed in a courtroom, retrospectively, by a jury with no baseline to compare against. Fifteen years of successfully resisting sector-specific regulation left the industry with nothing to comply with, and therefore nothing to point at. The regulatory vacuum they won is exactly what made them litigable.

Someone will read all this as a defense of Meta. It isn’t. Meta said things about its platform that a jury found misleading, and it should own that. But a $942 million transfer to a state treasury builds no parental capacity, closes no architectural gap, and produces no rule that the next company can be measured against. Forty other states are now holding a roadmap to the same result. The number will get bigger and the standard will still not exist.

We know how this is supposed to go, because we’ve done it before in every field where things fall down and people get hurt. Building codes don’t anticipate every failure. They’re incomplete by construction. What makes them work isn’t foresight, it’s that a collapse produces a revision. The failure gets written down, and the next builder inherits it whether he was paying attention or not.

Incompleteness is survivable. Absence is what produces a $567 million figure with no theory behind it.

We’ve had three collapses now, and we keep rebuilding to the same drawings. The drawings are ours.


  1. Background on the ruling itself, including the $567 million abatement fund, the $375 million in jury-assessed civil penalties, Judge Bryan Biedscheid’s stated reasoning, the state’s $779.5 million request, Attorney General Raúl Torrez’s “roadmap” statement, and the pending Oakland trial in which four state attorneys general are reported to be seeking more than $1 trillion: “Meta Ordered to Pay $942 Million to Address Harm to Kids From Social Media”, The Wall Street Journal. ↩

  2. Instagram began testing hidden like counts in 2019 and, after roughly two years, reported that the change was beneficial for some users and unwelcome to others; it launched the setting as a user-controlled option for Instagram and Facebook in May 2021 rather than imposing it as a default. See TechCrunch, “Instagram’s new test lets you choose if you want to hide ‘Likes’”, and NBC News, “Instagram rolls out option for users to hide likes”. The independent research is likewise unsettled; for one experimental treatment see “Hiding Instagram Likes: Effects on negative affect and loneliness”, Personality and Individual Differences. ↩

  3. The Tobacco Master Settlement Agreement was signed November 23, 1998 by the four largest U.S. tobacco manufacturers and the attorneys general of 46 states, the District of Columbia and five territories, and requires annual payments totaling approximately $206 billion through 2025. Four states (Mississippi, Florida, Texas and Minnesota) had settled separately for more than $40 billion over the first 25 years. See the National Association of Attorneys General, “The Tobacco Master Settlement Agreement”; U.S. Government Accountability Office, “Tobacco Settlement: States’ Use of Master Settlement Agreement Payments”; and “Tobacco Master Settlement Agreement” for general background. ↩

  4. Campaign for Tobacco-Free Kids and partner organizations, Broken Promises to Our Children: A State-by-State Look at the 1998 Tobacco Settlement and Tobacco Use, issued annually since the settlement. In fiscal 2025 the states collected $22.1 billion in settlement payments and tobacco taxes and spent $764.8 million of it, or 3.5 percent, on tobacco prevention and cessation; the fiscal 2026 figure is 3.4 percent of $21.7 billion. Maine is the only state funding its program at CDC-recommended levels, and seventeen states fund below ten percent of that level. Report landing page; see also the January 2026 release, “New Report: States Should Increase Tobacco Taxes to Reduce Tobacco Use”, and American Lung Association, “States Shortchange Tobacco Prevention Programs Proven to Save Lives”. ↩

  5. KFF Health News, “Payback: Tracking the Opioid Settlement Cash” and “How Are States Spending Opioid Settlement Cash? We Built a Database of Answers”. Payouts are expected to total roughly $50 billion over nearly two decades, and most settlements permit states to spend up to 15 percent of their funds on purposes that do not qualify as opioid remediation. Of the more than $6 billion received in 2022 and 2023, roughly one third was spent or committed, one third was set aside, and the remaining third could not be tracked because many jurisdictions failed to produce public reports. More than $240 million went to non-remediation purposes, the largest share of it to legal fees; documented purchases include body scanners, K-9 units, bulletproof vests and patrol trucks, and one county directed funds to its road and bridge department. On the practice of using settlement money to fund existing programs so that budgeted money can be redirected elsewhere, see also Legislative Analysis and Public Policy Association, “Spending Opioid Settlement Proceeds” (March 2025), which describes it as supplantation. ↩

  6. Arizona’s budget moved $115 million in national opioid settlement funds to the state Department of Corrections as part of closing a deficit of nearly $1.4 billion. Attorney General Kris Mayes obtained a temporary restraining order blocking the transfer, which Maricopa County Superior Court Judge John Hannah dissolved days later. Mayes has since said an Auditor General report supports her original position that the diversion violated the settlement’s terms. See Arizona Mirror, “Judge blocks use of opioid settlement money to balance Arizona’s budget deficit” and “Judge allows AZ opioid settlement money to go to state prisons”; Arizona Capitol Times, “Mayes weighs challenge against allegedly misspent opioid settlement”. ↩

This post is licensed under CC BY 4.0 by the author.