Opening statements began on August 18, 2026, in the US District Court for the Northern District of California, in Oakland. A coalition of 29 state attorneys general, led by California, Colorado, Kentucky and New Jersey, is litigating the trial against Meta. The case goes back further. A coalition of 33 state attorneys general filed the original complaint on October 24, 2023, alleging Meta violated federal child-privacy law and state consumer-protection statutes by employing harmful and psychologically manipulative platform features while misleading the public about their safety. Read that way, this is a familiar story: a tech giant accused of harming teenagers, dragged into court by state regulators.

It is worth slowing down on that framing. The states did not build this case around anything a Meta user posted, or anything the algorithm showed a particular child. Tech Policy Press reports that the states will show evidence of how the apps were designed to be addictive and Meta's awareness of it, rather than focusing on the content. That is a deliberate legal choice. In the United States, Section 230 shields a platform from liability for content its users post, not for how it designed the product they post into. By arguing design rather than content, the states route around the one defense that would otherwise end a case like this before it reached a jury.

The complaint gets specific about what "design" means. A DLA Piper client alert states the coordinated complaints name endless-content feeds, intermittent variable rewards, disappearing content, re-engagement notifications and algorithm-based content prioritization as the defective design, not any single video or post. Sue the machine that decides what to show, not the material it shows.

The states are suing Meta's product architecture, not its speech.

An old legal move, revived

This tactic is borrowed from a fight that took decades to win. A US Government Accountability Office report states that 46 states signed a settlement agreement in 1998 with the nation's largest tobacco companies, an agreement estimated to pay out $206 billion over its first 25 years. That settlement did not regulate cigarette advertising or ban tobacco outright. It used product-liability law, the same doctrinal category the Meta states are now reaching for, on a maker that had spent decades denying its product was built to addict anyone, to force a change in how that product was designed and sold. Whether the same path works on software instead of a combustible good is what the Oakland trial is testing.

Bar chart: 33 states filed the original Meta complaint in October 2023, versus 29 states litigating the trial that opened in August 2026.

What India can order, and what it cannot

The exposure is not abstract for India either. A survey by India's National Commission for Protection of Child Rights found that 37.8% of 10-year-olds it surveyed already had a Facebook account and 24.3% had an Instagram account, years below the 13-year-old minimum both platforms set for themselves. India's own toolkit for this category of harm looks different. The text of India's IT Rules, 2021, Rule 3, requires an intermediary to remove or disable access to unlawful information as early as possible, but in no case later than thirty-six hours from a court or government order, to keep its safe-harbour protection. That is a content power: what to take down, and how fast, once ordered. It says nothing about how the feed, notification system or recommendation engine that decides what a user sees, is built. A regulator can force one video off Instagram in India within 36 hours. Nothing in Rule 3 lets it order Meta to redesign the variable-reward notification system.

India's newer privacy law goes further, along a different axis: data, not design. The text of Section 9 of India's Digital Personal Data Protection Act, 2023, states that a data fiduciary shall not undertake tracking or behavioural monitoring of children or targeted advertising directed at children, and requires verifiable parental consent before a platform can process a child's data. That is a real constraint on how Meta handles a minor's data in India. But it is a consent-and-tracking rule, not a rule about whether an endless feed or a variable-reward notification is itself a defective design. And its penalty is fixed in advance. The Schedule to India's Digital Personal Data Protection Act, 2023, sets the maximum penalty for violating its children's-data provisions at ₹200 crore, about $24 million, payable to the state as a regulatory fine, not to any injured party as damages.

That gap is not abstract once the two numbers sit side by side. The 1998 tobacco settlement's $206 billion, by our calculation, runs to more than 8,500 times the roughly $24 million ceiling India's DPDP Act sets for a single violation.

Bar chart, US dollar million: the 1998 tobacco settlement totaled an estimated 206,000 million dollars over 25 years, versus India's DPDP Act maximum penalty of 24 million dollars per violation.

A regulator whose maximum fine is fixed by statute cannot replicate what an uncapped jury verdict did to tobacco, the structural difference the Oakland trial is built to exploit.

The word "product" does a lot of work

India does have a product-liability chapter, in the Consumer Protection Act, 2019, and on the surface it looks like the missing piece. The text of Section 2(33) of that Act defines a "product" as any article or goods or substance or raw material, capable of delivery either as wholly assembled or as a component part. That is tangible-goods language, written for a defective toaster, not a recommendation algorithm with no physical form to "deliver."

The closest India's consumer-protection regime has come to policing platform design is not a product-liability case at all. India's Central Consumer Protection Authority has, under its Prevention and Regulation of Dark Patterns Guidelines, 2023, fined nine digital platforms (Zepto, IndiGo, Physics Wallah, FirstCry and SpiceJet among them) roughly ₹20 lakh for deceptive checkout-flow and subscription prompts as of August 2026. That action reaches manipulative interface prompts, things like pre-ticked donations and fake urgency timers, not a recommendation algorithm, and it has never named a social media platform. It confirms rather than closes the gap: India's regulators have shown they will act on deceptive design when they find it, just never on the feed itself.

Contrast that with the European Union. Directive (EU) 2024/2853, adopted October 23, 2024, explicitly defines software and AI systems as "products" subject to strict liability, per a Reed Smith LLP legal analysis. A user in the EU harmed by a defectively designed algorithm now has, by statute, the kind of claim a US state is currently trying to construct through litigation instead. India has not made that legislative choice. Its statutory "product" still means an assembled good.

Four instruments, one gap in the middle.

InstrumentJurisdictionWhat it reachesMaximum exposure
IT Rules, 2021, Rule 3IndiaContent takedown, within 36 hours of an orderLoss of safe harbour; no monetary cap
DPDP Act, 2023, Section 9 and ScheduleIndiaParental consent; ban on tracking and ads to childrenAbout $24 million per violation
Consumer Protection Act, 2019, Section 2(33)IndiaTangible goods (physical product defects)Product-liability damages, goods only
Product Liability Directive 2024/2853European UnionSoftware and AI explicitly defined as productsStrict liability, uncapped design-defect claims

Source: India's IT Rules, 2021; India's Digital Personal Data Protection Act, 2023; India's Consumer Protection Act, 2019; the EU's Product Liability Directive, via Reed Smith LLP. Compiled by The Signal.

The honest objection

The strongest case against all of this is that the theory being tried in Oakland is exactly that: a theory, untested. Opening statements in the 29-state trial only began on August 18, 2026, and no jury has yet found Meta's product design defective, or awarded a dollar in damages on that theory. Until a verdict lands, "design, not speech" is a claim being argued, not a doctrine proven on software the way it eventually worked on cigarettes. On that view, it is premature for India to legislate around an unproven theory. Courts have not even agreed among themselves on the underlying premise. In a separate case, K.G.M. v. Meta, a Los Angeles County Superior Court sustained Meta's own argument that a social media platform is a service rather than a product, reasoning that platforms are not products because "one cannot reach out and touch them," and dismissed the product-liability counts on that basis, months before Oakland's version of the same question reached a jury.

That case is real, but it answers the wrong question. The EU did not wait for a verdict out of Oakland. It had already defined software as a product subject to strict liability by October 2024, nearly two years before this trial opened. Whether the American theory wins or loses changes nothing about whether India's statute book has a route to the same claim. It does not, regardless of how Oakland comes out.

The Signal

The Oakland trial is not really a referendum on Meta. It is a test of a legal tool: can a country's civil-liability system reach into a platform's product architecture the way the tobacco settlement once reached into a cigarette's chemistry. If the states win, expect the EU's statutory version of that tool to look prescient, and pressure on other jurisdictions to build their own. India's regulators can currently order a post taken down within 36 hours, and fine a company up to roughly $24 million for mishandling a child's data. Neither power touches the feed, the notifications, or the ranking model a jury in California is, this month, being asked to call defective. The gap closes only if India writes "product" to mean what the EU already wrote it to mean, or it waits for the next design-based harm with no statute built to reach it.

Reporting basis: the trial's opening and the 29-state coalition litigating it, and the original October 2023 filing by 33 states, are per the California Attorney General's office. The design-over-content litigation strategy is per Tech Policy Press's tracker; the specific features named in the complaints are per a DLA Piper client alert. The 1998 tobacco settlement and its $206 billion estimate are per a US Government Accountability Office report. The text of India's IT Rules, 2021, its DPDP Act, 2023 (Section 9 and Schedule), and its Consumer Protection Act, 2019, Section 2 is as reproduced on Indian Kanoon, which mirrors gazetted statutory text. The EU's Product Liability Directive is per a Reed Smith LLP analysis. The NCPCR figures on 10-year-olds' Facebook and Instagram accounts are per The Asian Age's report on the commission's study. The CCPA's dark-patterns enforcement action is per the Free Press Journal. The K.G.M. v. Meta ruling is per a SCOCAblog analysis published by the California Constitution Center at Berkeley Law. The ratio between the tobacco settlement and India's DPDP ceiling is The Signal's calculation.