The California Age-Appropriate Design Code Act, AB 2273, was signed in September 2022 and codified at Civil Code sections 1798.99.28 to 1798.99.40. It was modelled on the UK Children's Code and was due to take effect on 1 July 2024. It has not operated as written. Parts of the Act have been the subject of preliminary injunctions in NetChoice v. Bonta since September 2023, and the litigation is ongoing at the time of writing. This article explains what the Act asks for, where the litigation has stood, and what a product team should still do while the outcome remains open. The reader must check the current status of the case before relying on any statement about which provisions are in force.
What the Act asks for
The Act applies to a business, as defined in the California Consumer Privacy Act, that provides an online service, product or feature likely to be accessed by children, meaning anyone under 18. Its duties in section 1798.99.31(a) include completing a data protection impact assessment before offering a new feature to the public, estimating the age of child users with a reasonable level of certainty appropriate to the risks or applying the protections to all users, configuring default privacy settings to a high level, presenting privacy information in language suited to the child's age, and giving the child an obvious signal when a parent or guardian is monitoring them.
Its prohibitions in section 1798.99.31(b) include using a child's personal information in a way the business knows or has reason to know is materially detrimental to the child's wellbeing, profiling a child by default, collecting or sharing more personal information than necessary, collecting precise geolocation by default, and using dark patterns to lead a child to provide unnecessary data or forgo privacy protections. Enforcement sits with the Attorney General, with civil penalties per affected child.
What happened in NetChoice v. Bonta
NetChoice, a trade association, sued in the Northern District of California in December 2022 on First Amendment and other grounds. In September 2023 the district court preliminarily enjoined the whole Act, finding NetChoice likely to succeed on its First Amendment claim. California appealed.
In August 2024 the Ninth Circuit affirmed the injunction as to the DPIA provisions, holding that they likely compelled speech in a way the First Amendment does not allow, and vacated the injunction as to the remaining provisions, sending the case back for the district court to consider whether those provisions could be severed and whether they were independently unconstitutional.
On remand, in March 2025, the district court again preliminarily enjoined the Act in its entirety, concluding that the remaining provisions were also likely unconstitutional and could not be cleanly severed. California appealed again. As of the time of writing that appeal remains before the Ninth Circuit, and the practical position is that the Act is enjoined pending the outcome. This is a summary of a moving case. The reader should confirm the current posture before making any decision that depends on it.
What that means, and what it does not
An injunction stops the Attorney General from enforcing the enjoined provisions. It does not repeal the Act, it does not resolve the merits, and it does not change any other law. Three things are worth keeping separate.
First, the Act may return in whole, in part or in amended form. A preliminary injunction is a prediction about likely success, not a final judgment. The legislature could also amend the Act to address the court's concerns.
Second, the substance of the Act's duties already lives elsewhere. The UK Children's Code imposes almost the same design duties on any service likely to be accessed by children in the UK, and is enforced now. COPPA governs collection from under-13s in the United States and was strengthened in 2025. The CCPA requires opt-in consent before selling or sharing the personal information of a consumer the business knows to be under 16. A product that ships to California almost certainly ships to the UK, and the design work is shared.
Third, the litigation is about the Act's mechanism, not about whether children's privacy matters. Courts, regulators and state legislatures have kept moving, and a design decision that was defensible under the Act is defensible without it.
What a product team should still do
Build the defaults. High-privacy defaults, geolocation off, profiling off, no dark patterns on consent and settings screens. These are the same decisions the UK AADC's fifteen standards require, and they are the least likely part of any children's code to be controversial. The high-privacy defaults guide sets them out feature by feature.
Keep a risk assessment, but be careful how you frame it. The DPIA provisions are the part of the Act the courts have found most problematic, because they required a business to assess and report on the harms its content might cause. A team can still run a privacy-focused impact assessment of its own data practices, as the UK code and the GDPR expect, without adopting the Act's framing. If the Act returns, the record will be useful; if it does not, the record is still good practice.
Decide the age question deliberately. Estimating age with reasonable certainty, or applying protections to everyone, is a choice the UK code asks for now. Make it once, record the reasoning, and apply the same answer across markets.
Track the case. Assign someone to check the docket at a set interval, and treat a change in status as a trigger to reopen the backlog rather than something to discover in a news headline.
A worked example
Brightfold Games, a fictional company, runs a mobile puzzle game with an in-app chat and a leaderboard, rated for ages 9 plus and available across the United States and the UK. In 2024 the team paused its California work when the injunction was reported. On review it found that the same features were already in scope for the UK code, so the pause had only delayed decisions it still had to make. The team set leaderboards to show first names only, turned off precise location for all users, removed a "share your score" prompt that appeared on every level, and wrote a short impact assessment of the chat feature's data flows. It kept a one-page note on the California case with the date it was last checked. When the status changes, the note and the backlog are the starting point.
How Landfall helps
Landfall holds the California Act's obligations as structured entries with their section citations, alongside the UK code, COPPA and the other children's frameworks, so a team can see where a California duty is matched by a duty that is enforced today. The corpus records regulatory events, including litigation status changes, and a change to a source triggers re-evaluation of the affected mappings rather than a silent edit. Because the framework metadata marks the Act's enforcement status, the generated backlog can show which items rest on the enjoined Act alone and which are also required elsewhere. Browse the obligations in the CAADCA explorer.