2026年9月11日

Vermont’s Proposed AADC Rules Would Force a Redesign of How Online Services Present Content to Minors, Reaching Far Beyond Social Media Companies

Share

In one of the most aggressive state-level moves yet to regulate how digital products interact with children and teens, the Vermont Office of the Attorney General (“Vermont AG”) has issued Proposed Rules for the Vermont Age-Appropriate Design Code Act, Act 63 (S.69) (“Vermont AADC”), which takes effect January 1, 2027.

At its core, the law imposes on covered businesses a “minimum duty of care” for Vermont users under the age of 18: companies’ use of a minor’s personal data, and the design of their online services, cannot cause reasonably foreseeable compulsive use, emotional distress, or specified forms of discrimination. The law also prohibits covered businesses from using a covered minor’s personal data to select, recommend, or prioritize media, subject to carve-outs for express requests.

But the Proposed Rules go well beyond personal data prohibitions, and also expressly forbid using behavioral data (essentially any interaction with the service) and inferences derived from that data to enact almost a complete ban on any personalization or “addictive” features, including autoplay, infinite scroll, engagement counts, rewards, streaks, and certain popularity indicators. User-directed experiences would remain available in specified circumstances. Compounding these challenges, the timeline provides little time for businesses to assess the final requirements and implement any necessary changes before the January 1, 2027 effective date.

The rules come in two parts. The first targets the features users interact with every day: personalized feeds, recommendation systems, most notifications, autoplay, infinite scroll, engagement (likes/comments), rewards, social pressure features like streaks, and interfaces that make leaving harder than staying. Some practices would be prohibited outright for covered minors; others would turn on their purpose, design, or likely effect on engagement. There is no parental consent override.

The second part governs age assurance: the methods a business uses to figure out which users are minors. Although at first blush these rules appear to propose a reasonable framework, the vagueness of these rules and their double-edged nature effectively allow the AG to pick and choose which companies are in violation.

Compliance with either part would demand changes to core product functionality, and because the Vermont AADC is not limited to social media companies, that burden could land on a wide range of consumer-facing online businesses.

This Legal Update breaks down the details of the law, who is covered, the proposed rules, and the steps that remain before they take effect.

Who is Covered: the 2% Threshold

The Vermont AADC applies to a “covered business,” which is a business that:

  • Conducts business in Vermont;
  • Earns most of its annual revenue from online services;
  • Offers products, services, or features reasonably likely to be accessed by an under-18 minor;
  • Collects consumers’ personal data, itself or through a vendor; and
  • Controls how that data is used.

The third factor decides most cases—and it is easier to satisfy than it sounds because a service need not be designed for minors, or even popular with minors, to be covered. A service qualifies if:

  • Competent and reliable evidence shows that minors ages 2-17 make up at least 2% of its audience;
  • Internal company research shows that composition;
  • The business knew or should have known that at least 2% of the audience consisted of minors ages 2-17; or
  • It is directed to children under the Children’s Online Privacy Protection Act (“COPPA”).

The statute includes several exclusions, including certain financial institutions, journalism entities, government entities, and specified health and research information. Whether an exclusion applies may depend on the entity, the data involved, or the context in which the data is processed.

The Duty of Care: A Broader Standard Than It Appears

Under 9 V.S.A. §2449c(a)–(b), a covered business that processes a covered minor’s data owes a minimum duty of care: the use of a covered minor’s personal data and the design of an online service must not result in reasonably foreseeable emotional distress, reasonably foreseeable compulsive use, or discrimination.

The statute prohibits certain practices outright, but §2449f(b) leaves to rulemaking the question of which design features amount to compulsive use. That gap is the central issue for clients.

The Vermont AADC defines “compulsive use” narrowly, as repetitive use that materially disrupts a major life activity such as sleeping or learning. The Proposed Rules (as discussed below) abandon that limitation entirely, treating a practice as compulsive wherever it relies on engagement optimization or is reasonably likely to prolong interaction. The effect is to convert a harm-based standard into a design-based one—which ordinary personalization would satisfy.

The Vermont AADC does include an exception for user-generated content. Under §2449c(c), the content of the media a covered minor views cannot itself establish emotional distress, compulsive use, or discrimination. §2449c(d) confirms that nothing requires a covered business to block access to specific media, and §2449i adds that nothing may prevent a covered minor from deliberately searching for or requesting any media.

Enforcement: Your Own Data as the Evidence Against You

The Vermont AG enforces both the statute and the Proposed Rules. A violation by a business or its vendor counts as an unfair and deceptive act under Vermont consumer protection law, opening the door to investigations, lawsuits, or negotiated commitments to stop.

But the more consequential concern is how violations get proven. In deciding whether a business broke the design rules, the Vermont AG may look at the company’s own internal testing, analytics, A/B tests, and product research. Practices that rely on behavioral prediction or engagement-based ranking are presumed to lead to compulsive use, and the business must rebut that presumption by clear and convincing evidence. The age assurance rule adds a presumption of its own: a business that cannot produce the required documentation is presumed non-compliant.

Proposed Rule 1: Prohibited Data and Design Practices

Personalized Feeds, Autoplay, and Infinite Scroll

As discussed above, the Vermont AADC’s core prohibition hinges on a single input: a covered minor’s personal data cannot be used to select, recommend, or prioritize media, subject to carve-outs for express requests, user-selected settings, and search.

The Proposed Rules keep that prohibition and layer on two additional inputs: “behavioral data” (clicks, scrolls, dwell time, viewing history, navigation patterns) and “inferred preferences” (predictions drawn from that activity). They also broaden the definition of “prioritizing media” to include filtering and amplifying. There is no exception for user or parental consent.

Neither autoplay nor infinite scroll appears in the statute. The Proposed Rules would ban both—and crucially, would do so regardless of whether any data is involved, meaning that disabling personalization for covered minors would not fix the problem. The autoplay ban prohibits both automatic playback and auto-advancing content. For infinite scroll, the rules prohibit interfaces that load additional media in response to ordinary scrolling or swiping, and would require “a discrete and intentional action beyond ordinary scrolling or navigation,” something like a “Load More” button.

The rules do preserve room for user-directed experiences. A covered business may still show a covered minor media from a specific account, feed, or creator the minor requests; a category the minor selects; media similar to what the minor affirmatively chose to view; or search results. Privacy, accessibility, and display settings the minor configures are also permitted. Subscription feeds, chronological ordering, and search functions therefore remain the most defensible product designs—though each permitted request must be specific and contemporaneous, not inferred from prior activity.

Notifications, Rewards, and Social Pressure Features

The Vermont AADC already bars push notifications to covered minors between midnight and 6 a.m. and makes suppression the default. The Proposed Rules go significantly further: a covered business could not deploy any notification feature designed or reasonably likely to encourage, increase, prolong, or reinitiate engagement through personal data, behavioral data, or inferred preferences. Any push notification based on personal data, activity, or behavioral data would also be prohibited. The rules would preserve notifications needed to provide a requested service, as well as transactional, safety, and account-related communications that are not designed to increase engagement. In practice, this eliminates most engagement messaging to covered minors.

The Proposed Rules would also prohibit variable or intermittent rewards (e.g., likes, badges, points), social pressure features (e.g., streaks, popularity indicators), and interfaces that make staying on a service easier than leaving it.

Proposed Rule 2: Age Assurance

The second Proposed Rule tackles age assurance—how a covered business determines whether a user is a covered minor. While the Vermont AADC reaches only minors a business actually knows are minors, the Proposed Rules go further, reaching minors the business has reason to know are minors, a standard deemed met whenever the service is one minors are likely to use or whenever the business collects or infers information indicating a user’s minority status.

The Rules use a tiered approach for age assurance, organized around one main principle: use the least intrusive method that is still accurate enough. A business must start at the lowest of three tiers, and may escalate only when the level below falls short:

  • Low-intrusion: Asking users their age with reasonable safeguards, using age signals the business already has, or drawing on account or session indicators.
  • Moderate-intrusion: Estimating age from device data, account information, or usage patterns is permitted only where a low-intrusion method is not reasonably available or sufficient.
  • Higher-intrusion: Checking credentials is permitted only where lower methods are neither available nor sufficient, and where the service poses a reasonably foreseeable risk of material privacy, safety, or accessibility harm to minors.

A business can be faulted for choosing a method more intrusive than necessary, and equally for one that misjudges too many minors. Yet the rule defines neither threshold. We expect that ambiguity to draw significant comment, particularly given § 2449g(b)(2)(A), which directs the Vermont AG to prioritize privacy and accessibility over accuracy.

The rule also imposes detailed obligations around the age determination itself:

  • Before escalating to a higher tier, a business must evaluate a lower-intrusion alternative and document why it falls short.
  • It must test its method’s error rates at least annually, including whether errors fall disproportionately on particular groups of minors.
  • It must delete the underlying data as soon as the determination is made, subject to narrow security, legal, and audit exceptions.
  • It must offer a backup method if the first process fails, an appeals process reviewed by a person independent of the original decision, and a written assessment before launch.
  • Missing documentation is itself presumed non-compliance.

Where a vendor performs age assurance, the business remains on the hook—and may rely on that vendor only after vetting its processes, requiring compliance by contract, and monitoring performance.

What Comes Next

The Proposed Rules remain open for comment until October 2, 2026, and §2449f(b) directs the Vermont AG to adopt final rules on or before January 1, 2027—the same date the Vermont AADC takes effect. Clients should plan for little or no gap between the final rules and the compliance date.

Comments filed before October 2 are the practical opportunity to push back on the expansions discussed above. Given the breadth of these rules and the speed of the timeline, that window matters.

関連サービスと産業

最新のInsightsをお届けします

クライアントの皆様の様々なご要望にお応えするための、当事務所の多分野にまたがる統合的なアプローチをご紹介します。
購読する