Two weeks ago I closed part ten by noting that France's Constitutional Council had struck down the under-15 ban partly on the privacy grounds this series kept pressing, and that the honeypot argument had, for once, found a friend on the bench. I did not expect it to find two more friends quite so quickly — one in a courtroom in the United States, and one at the United Nations. This past week both stepped back from the ban. And yet the thing I have spent this whole series watching did not go away. It changed address.

What actually happened

On Tuesday, Meta settled the long-running child-safety lawsuit brought by almost every US state, agreeing to pay up to $18bn (about £13.3bn) to forty-eight states plus the District of Columbia and three territories, spread over a decade, and to build a set of child-safety features into Facebook and Instagram — without, it should be said plainly, admitting any wrongdoing (Washington Post). The features are behavioural, not prohibitive: a one-hour daily time limit for teenagers, an overnight "night mode", and prompts for children who have been scrolling too long, alongside firmer parental controls. Roughly a third of the money — some $5.3bn — is not owed at all unless YouTube and TikTok agree to adopt the same three measures, which is Meta's way of dragging its rivals into the settlement it just signed (CNBC). Florida rejected the deal; New Mexico was left out after an earlier case cost Meta $942m.

Two days either side of that, the UN's high commissioner for human rights, Volker Türk, made the political weather around it. Governments, he said, should "step up rather than wait for courts and companies to act", because "children should not have to wait for a lawsuit to be safe online". He was pointing back at his own office's ten-point framework from May, which asks for data privacy, safer platform design, curbs on addictive features and age verification done properly — and which explicitly declines to treat an outright ban as the answer (OHCHR).

So in the space of a week, the two loudest new voices in this debate both declined to raise a wall. That is the part everyone will celebrate, and I will come to it. But it is not the part I want you to watch.

The honeypot did not die. It moved house.

Read the settlement past the headline and you find, sitting quietly in the remedies, the same machinery this series has been circling for eleven parts. Meta must now use young people's personal data only to estimate their age; under-13s are to be removed, and 13-to-17-year-olds placed inside the extra protections. To do any of that at the scale of a global platform, you must first work out, continuously, how old everyone is. Meta calls this "strengthening its age-assurance technology". I call it what I called it in part six: to check an age, you must collect an identity, and to check every age you must collect every identity, forever.

Here is the move worth marking. Meta has used this settlement to reiterate its longstanding preference that age verification be carried out not by Meta but by the app stores — by Apple and Google — before you ever reach the platform. Framed as consumer convenience, it is one of the most consequential relocations in this entire story. The national honeypot France tried to build, and that its own court would not let it, does not vanish under the American model. It is simply consolidated into two private chokepoints that already hold the payment details, the devices and the identities of most of the planet. Privacy campaigners made exactly this point in the settlement's wake, and it is the point of this series: age-verification methods do not reduce the amount of personal data companies hold, they increase it. The Discord vendor that leaked around 70,000 government ID photographs last October did not do so because it was reckless. It did so because it was holding the documents in the first place. Move the holding from a French vendor to an American app store and you have not closed the honeypot; you have given it a better address and a longer lease.

That is why I will not join the celebration wholeheartedly. A design remedy that still runs on universal identity collection is a honeypot wearing a friendlier coat. The wall came down; the store of documents behind it did not.

The part I will give them: the ban lost the argument

Now the concession, because this series owes honesty in both directions.

For nine parts I argued that enforcing at the destination — a wall around every account, checked by third-party tools — buys you the largest circumvention surface available and the largest identity store as the price of admission, and that the better path runs through safer design and device-level controls that travel with the child. This week, a US courtroom and the UN's human-rights office both, in their different registers, said something close to that out loud. The US settled on behavioural design rather than prohibition. Türk's office put its name to "safe by design" and against the ban. After France's own court struck the wall down a fortnight ago, the intellectual weather has genuinely shifted, and I would be graceless not to say so. The ban model is not dead — Britain's is still coming — but for the first time it is the position on the back foot.

I take no victory lap, for two reasons. The first is the one above: the alternative they have reached for still smuggles the honeypot in through the app store. The second is that "behavioural design" is not automatically the gentler cousin of a ban. A one-hour timer and an overnight lockout are still enforcement, still dependent on knowing who is a child, and still, as the campaigners in this story keep saying, silent on the actual content. No one is claiming a silver bullet, and I am not going to pretend a settlement is one either.

Meta says the quiet part

There is one line in the settlement I would carve above the door of every bill in this series, because Meta said it, not me. Justifying its demand that YouTube and TikTok be held to the same rules, the company argued that "when teens are restricted on one app, they simply move to another".

That is the enforcement inversion — the whole circumvention argument of part one and part seven — conceded by the house. A restriction on one accountable platform does not delete the demand; it relocates the teenager to the next platform, and then to the less-accountable spaces beyond all of them. Meta frames this as a plea for a "level playing field", which is convenient for Meta. But strip the self-interest away and the mechanism it is describing is the exact one I have been describing: restrictions do not remove determined users, they move them. It is a strange feeling to have the argument proved by the party with the most to lose from it.

The UK reads the room

For a British reader, the practical read is that the pressure has just changed direction. The UK went further than any of this a while ago: an outright under-16 ban due in 2027, with curfews and hour-by-hour restrictions stapled to 16- and 17-year-olds. Where the US has now landed on design tweaks confined, for the moment, to two platforms and imposed by settlement rather than statute, Britain has chosen the wall and the switch-off.

The government says it is "following developments closely", and former insiders quoted this week expect it to "feel empowered to at least ask for the same" behavioural measures now that Meta has conceded them (BBC). That is the direction I would watch. The likeliest British outcome is not a choice between the ban and the American design menu, but both at once: the wall and the timers and the age checks — each justified by the others, and every one of them requiring the same thing underneath, which is that everyone keeps proving who they are.

The address book

So the direction of travel is unchanged, and only the geography has moved. Australia banned. France tried to and was stopped. Britain still intends to. And now the United States, declining to ban, has instead blessed a model in which the age check migrates to the app store — which is to say, in which the identity honeypot stops being a national project and becomes a platform-layer default across the entire Western internet. That is not a smaller honeypot. It is a more permanent one, held by fewer, larger hands, and normalised as the ordinary price of owning a phone.

The advice at the foot of every instalment does not change, because none of this changes it. When you are asked to prove your age online — and you increasingly will be, whether by a French vendor, a British statute or an American app store — treat your identity documents as the precious things they are, and prefer the providers that check and delete over the ones that check and keep. Keep doing the unglamorous thing that has quietly outperformed every statute and every settlement in this series: the device-level controls that travel with the child, and the conversation that travels further still.

I said in part nine that the number I would be watching most closely was how long a national identity store holds before something leaks out of it. The honeypot has just changed address; the question has not. I will keep watching, and I will report back here as it comes in.

This is part eleven of Regulating the Teen Internet. If you have arrived here first, the practical, do-it-this-weekend guide for parents is part eight, and it stands whatever any parliament, court or settlement does next.