Skip to content
CAADCAAB 2273NetChoice v. BontaCaliforniachildren's privacy

California's Age-Appropriate Design Code: What Still Applies

AB 2273, the NetChoice v. Bonta injunctions, which provisions have been enjoined, and what a product team should still build while the litigation runs.

Landfall Β· Published 5 September 2026

The California Age-Appropriate Design Code Act, AB 2273, was signed in September 2022 and codified at Civil Code sections 1798.99.28 to 1798.99.40. It was modelled on the UK Children's Code and was due to take effect on 1 July 2024. It has not operated as written. Parts of the Act have been the subject of preliminary injunctions in NetChoice v. Bonta since September 2023, and the litigation is ongoing at the time of writing. This article explains what the Act asks for, where the litigation has stood, and what a product team should still do while the outcome remains open. The reader must check the current status of the case before relying on any statement about which provisions are in force.

What the Act asks for

The Act applies to a business, as defined in the California Consumer Privacy Act, that provides an online service, product or feature likely to be accessed by children, meaning anyone under 18. Its duties in section 1798.99.31(a) include completing a data protection impact assessment before offering a new feature to the public, estimating the age of child users with a reasonable level of certainty appropriate to the risks or applying the protections to all users, configuring default privacy settings to a high level, presenting privacy information in language suited to the child's age, and giving the child an obvious signal when a parent or guardian is monitoring them.

Its prohibitions in section 1798.99.31(b) include using a child's personal information in a way the business knows or has reason to know is materially detrimental to the child's wellbeing, profiling a child by default, collecting or sharing more personal information than necessary, collecting precise geolocation by default, and using dark patterns to lead a child to provide unnecessary data or forgo privacy protections. Enforcement sits with the Attorney General, with civil penalties per affected child.

What happened in NetChoice v. Bonta

NetChoice, a trade association, sued in the Northern District of California in December 2022 on First Amendment and other grounds. In September 2023 the district court preliminarily enjoined the whole Act, finding NetChoice likely to succeed on its First Amendment claim. California appealed.

In August 2024 the Ninth Circuit affirmed the injunction as to the DPIA provisions, holding that they likely compelled speech in a way the First Amendment does not allow, and vacated the injunction as to the remaining provisions, sending the case back for the district court to consider whether those provisions could be severed and whether they were independently unconstitutional.

On remand, in March 2025, the district court again preliminarily enjoined the Act in its entirety, concluding that the remaining provisions were also likely unconstitutional and could not be cleanly severed. California appealed again. As of the time of writing that appeal remains before the Ninth Circuit, and the practical position is that the Act is enjoined pending the outcome. This is a summary of a moving case. The reader should confirm the current posture before making any decision that depends on it.

What that means, and what it does not

An injunction stops the Attorney General from enforcing the enjoined provisions. It does not repeal the Act, it does not resolve the merits, and it does not change any other law. Three things are worth keeping separate.

First, the Act may return in whole, in part or in amended form. A preliminary injunction is a prediction about likely success, not a final judgment. The legislature could also amend the Act to address the court's concerns.

Second, the substance of the Act's duties already lives elsewhere. The UK Children's Code imposes almost the same design duties on any service likely to be accessed by children in the UK, and is enforced now. COPPA governs collection from under-13s in the United States and was strengthened in 2025. The CCPA requires opt-in consent before selling or sharing the personal information of a consumer the business knows to be under 16. A product that ships to California almost certainly ships to the UK, and the design work is shared.

Third, the litigation is about the Act's mechanism, not about whether children's privacy matters. Courts, regulators and state legislatures have kept moving, and a design decision that was defensible under the Act is defensible without it.

What a product team should still do

Build the defaults. High-privacy defaults, geolocation off, profiling off, no dark patterns on consent and settings screens. These are the same decisions the UK AADC's fifteen standards require, and they are the least likely part of any children's code to be controversial. The high-privacy defaults guide sets them out feature by feature.

Keep a risk assessment, but be careful how you frame it. The DPIA provisions are the part of the Act the courts have found most problematic, because they required a business to assess and report on the harms its content might cause. A team can still run a privacy-focused impact assessment of its own data practices, as the UK code and the GDPR expect, without adopting the Act's framing. If the Act returns, the record will be useful; if it does not, the record is still good practice.

Decide the age question deliberately. Estimating age with reasonable certainty, or applying protections to everyone, is a choice the UK code asks for now. Make it once, record the reasoning, and apply the same answer across markets.

Track the case. Assign someone to check the docket at a set interval, and treat a change in status as a trigger to reopen the backlog rather than something to discover in a news headline.

A worked example

Brightfold Games, a fictional company, runs a mobile puzzle game with an in-app chat and a leaderboard, rated for ages 9 plus and available across the United States and the UK. In 2024 the team paused its California work when the injunction was reported. On review it found that the same features were already in scope for the UK code, so the pause had only delayed decisions it still had to make. The team set leaderboards to show first names only, turned off precise location for all users, removed a "share your score" prompt that appeared on every level, and wrote a short impact assessment of the chat feature's data flows. It kept a one-page note on the California case with the date it was last checked. When the status changes, the note and the backlog are the starting point.

How Landfall helps

Landfall holds the California Act's obligations as structured entries with their section citations, alongside the UK code, COPPA and the other children's frameworks, so a team can see where a California duty is matched by a duty that is enforced today. The corpus records regulatory events, including litigation status changes, and a change to a source triggers re-evaluation of the affected mappings rather than a silent edit. Because the framework metadata marks the Act's enforcement status, the generated backlog can show which items rest on the enjoined Act alone and which are also required elsewhere. Browse the obligations in the CAADCA explorer.

Explore the underlying obligations

This article is grounded in the obligations Landfall maps from source legal text. Browse them yourself:

Questions this article answers

Is the California Age-Appropriate Design Code Act in force?
Not as written. It has been subject to preliminary injunctions in NetChoice v. Bonta since September 2023, and at the time of writing the litigation is ongoing on appeal. An injunction stops enforcement of the enjoined provisions; it does not repeal the Act. Check the current status before relying on any provision.
Which provisions did the Ninth Circuit address?
In August 2024 the Ninth Circuit affirmed the injunction as to the data protection impact assessment provisions, finding they likely compelled speech, and vacated it as to the remaining provisions, remanding for the district court to consider severability. In March 2025 the district court again enjoined the whole Act; that decision was appealed.
Does the injunction change COPPA or the CCPA?
No. COPPA still governs collection from under-13s and was strengthened in 2025, and the CCPA still requires opt-in consent before selling or sharing the personal information of a consumer the business knows is under 16. The UK Children's Code applies to the same product in the UK.
What should a product team do in the meantime?
Build the defaults the Act shares with the UK code: high privacy by default, geolocation and profiling off, no dark patterns, an obvious signal when a parent monitors. Keep a privacy-focused impact assessment of data practices, decide the age question deliberately, and assign someone to track the case.

Sources

For informational purposes only. This guide is summary-level, informational writing β€” not legal advice, not a risk score, and not regulatory approval. It does not create an attorney-client relationship. Always consult qualified legal counsel for compliance decisions about your specific product.

What Landfall Is NOT

Critical Boundaries

Understanding these boundaries is essential before using this product. Misuse of this tool for purposes outside its scope may create legal, regulatory, or commercial risk for your organization.

NOT Legal Advice

This product does not provide legal advice and does not create an attorney-client relationship.

Interpretations are informational analysis, not legal counsel. Always consult qualified legal professionals for compliance decisions.

NOT a Risk Score

We do not quantify, calculate, or certify your compliance risk level.

No numerical risk rating, compliance percentage, or safety score. Risk assessment requires human judgment about your specific context.

NOT Runtime Enforcement

This is a planning and mapping tool, not a runtime enforcement system.

Does not integrate with your production systems. Does not block, filter, or enforce compliance in real-time. Implementation is your responsibility.

NOT Regulatory Approval

Using this tool does not mean you are compliant with any regulation.

No certification, seal of approval, or compliance guarantee. Regulators will evaluate your actual implementation, not your use of this tool.

NOT Authoritative Interpretation

Our interpretations are not binding and may differ from regulatory guidance.

Only regulators and courts provide authoritative interpretation. Our analysis reflects our reading of requirements, which may be incomplete or incorrect.

NOT a Safe Harbor

This tool does not shield you from enforcement actions or liability.

Documentation of your process is valuable, but does not constitute a legal defense. Compliance is ultimately your organization's responsibility.

NOT an AI Compliance Agent

AI features assist analysis but do not make compliance decisions for you.

AI-generated interpretations require human review and approval. Automated suggestions are starting points, not final answers.

NOT Complete Coverage

We do not cover all regulations, all obligations, or all jurisdictions.

Regulatory landscape is vast and evolving. Gaps in our coverage do not mean those requirements don't apply to you.

What This Tool IS:

  • A structured workflow for mapping regulatory requirements to implementation tasks
  • A documentation system for compliance decisions (audit trail)
  • A collaboration platform for compliance, legal, and engineering teams
  • An informational resource for understanding regulatory obligations