Meta's defence is that kids shouldn't be on Instagram. Their age check is a birth date field where a 12-year-old types '2005.' A judge said design problems aren't protected by Section 230. Schools in 19 states are suing because Instagram affects children's ability to learn. Meta added a 'Take a Break' reminder. The algorithm pushing harmful content to vulnerable teens still runs. States had to pass laws because Meta wouldn't fix it. Those laws don't start until 2027.
What they claim: 'We've introduced new features to protect teen users.'
What we found: 'Take a Break' reminders easily circumvented. Core algorithm still maximises engagement through outrage/comparison. California (Sept 2024) and New York passed laws because voluntary measures failed. Laws don't take effect until 2027. Kids harmed now.
What they claim: Instagram claims to prioritize user safety and wellbeing with features like content warnings and time limit reminders.
What we found: In September 2022, UK coroner Andrew Walker ruled that Instagram contributed to the death of 14-year-old Molly Russell, who died by suicide in 2017 after viewing thousands of posts about self-harm and depression. The coroner found the content should not have been available to a child and that Instagram's algorithm actively recommended increasingly graphic material. Meta's response: it had already updated its policies. Molly's father Ian Russell said the platforms "helped kill my daughter."
What they claim: Instagram says it uses technology to detect and remove harmful content before people see it.
What we found: In 2023, the Wall Street Journal created test accounts posing as 13-year-olds and found Instagram's Reels algorithm served self-harm and eating disorder content within minutes of registration. The algorithm detected the teen accounts' interest in mental health topics and doubled down, filling the feed with progressively more disturbing content. Instagram's own internal research (leaked by Frances Haugen in 2021) showed the company knew "we make body image issues worse for one in three teen girls."
What they claim: Meta claims Teen Accounts "automatically protect teens and put parents in control"
What we found: European Commission preliminary finding (July 2026) that Instagram's infinite scroll, autoplay, push notifications, and personalised recommendation systems breach the Digital Services Act. The Commission found Meta ignored data showing how late into the night under-18 users remained on the platform, and that Reels and Stories were linked to compulsive engagement patterns. Faces fines up to 6% of global turnover — potentially billions of dollars.
What they claim: 'We care deeply about the safety and wellbeing of young people on our platforms.'
What we found: Meta's OWN research (Haugen leak 2021): 32% teen girls said Instagram made body image worse. 13.5% UK teen girls said it worsened suicidal thoughts. 17% said eating disorders worsened. Called 'distinctly worse than other social media.' Building 'Instagram Kids' while sitting on this. 1,867 lawsuits (MDL 3047, July 2025). Wrongful death claims. 33 AGs sued Meta.
What they claim: 'Instagram's algorithm shows you content you're interested in.'
What we found: Algorithm redesigned 2018 to weight emoji reactions 5x more than likes. Staff warned it would amplify outrage and harm. Engineers proved setting 'angry' weight to zero reduced misinformation -- kept it on. Creates rabbit holes from body image to eating disorders to self-harm for vulnerable teens.
What they claim: 'Instagram is a separate app with its own privacy controls.'
What we found: Fully integrated into Meta infra. Same Pixel (30%+ websites), SDK (32% apps), cross-platform profile (~52,000 traits), PRISM. Threads collects 45% more data than Twitter/X: health, financial, biometric, sexual orientation. Deleting Threads = deleting Instagram.
What they claim: Meta announced end-to-end encryption for Instagram DMs in December 2023, calling it "the most significant layer of protection" for private messages.
What we found: Meta has removed end-to-end encryption from Instagram direct messages. EFF documented this as a broken promise — the encryption that was marketed as protecting users from surveillance, data breaches, and Meta itself has been quietly stripped away. No public explanation for the reversal.
What they claim: Instagram's parent company Meta claims to prioritise user privacy.
What we found: Meta's internal Model Capability Initiative captures employee keystrokes and mouse clicks for AI training. If Meta treats its own employees as training data, the 2 billion people using Instagram have no reason to expect better. Employees protested the program. Meta's concession: a 30-minute pause button.
What they claim: Meta claims Instagram has robust safety features and age-appropriate experiences for young users.
What we found: In March 2026, a New Mexico jury hit Meta with a $375 million verdict for endangering children on Instagram and Facebook. One day earlier, a California jury awarded $6 million in the first-ever US verdict finding Meta liable for a young woman's depression and anxiety from childhood Instagram use. 2,527 pending MDL actions and 42 state AGs are pursuing Meta.
What they claim: Meta previously promoted end-to-end encryption for Instagram DMs as a privacy feature
What we found: In May 2026, Meta removed end-to-end encrypted DMs from Instagram — 11 days before the Take It Down Act took effect requiring platforms to remove CSAM. Meta said "very few people were opting in." The timing suggests Meta chose compliance convenience over user privacy. Messages that were private are now readable by Meta and available to law enforcement without a warrant.
What they claim: Meta says its AI support system provides "faster, more efficient account recovery" for Instagram users
What we found: Hackers used prompt injection on Meta's AI support chatbot to attach attacker-controlled emails to accounts they didn't own, then received verification codes and completed password resets. The Obama White House Instagram account, the Chief Master Sergeant of the US Space Force's account, and Sephora's account were all hijacked. Security researcher Jane Wong also had her account taken over. Videos of the technique circulated openly on Telegram.
What they claim: Meta says it provides robust support channels for Instagram users experiencing account issues
What we found: Victims whose accounts were hijacked through the AI chatbot reported no way to escalate to a human support agent. The same AI system that enabled the takeover was the only avenue for recovery. Meta replaced human support with AI, and when the AI became the attack vector, there was no fallback.
What they claim: Meta claimed its AI-powered "High Touch Support" account recovery tool was "rigorously tested with safeguards built in" at launch in March 2026.
What we found: The tool never verified that the email requesting a password reset matched the account's registered email. Attackers exploited this to hijack 20,225 Instagram accounts over 7 weeks (April 17 – May 31, 2026). Exploit instructions circulated on Telegram. Meta disclosed the breach on June 5, 2026.
What they claim: Meta states users have control over how their data and content are used
What we found: Muse Image (launched July 7, 2026) let anyone type a prompt referencing any public Instagram account and generate AI images using that person's photos — including their face, likeness, and children who appeared in their photos. Every public account was opted in by default with no notification. SAG-AFTRA condemned it as "an utter miscalculation." Privacy International called it exploitation. Meta pulled the feature after 3 days.
What they claim: Instagram says it works to protect young users from exploitation and unwanted contact.
What we found: A nationwide sextortion epidemic on Instagram has been documented by the FBI, NCMEC, and multiple state AGs. In 2023, a 17-year-old named Jordan DeMay from Michigan died by suicide after being sextorted through Instagram DMs. The scammers demanded $1,000 within an hour. Jordan was dead within six hours of first contact. Meta was aware of the sextortion crisis and had received reports of similar cases before Jordan's death. The FBI reported a 1,000% increase in sextortion reports between 2021 and 2023.
What they claim: 'We take strong action to keep people under 13 off Instagram.'
What we found: No meaningful age verification -- children enter false birth date. Meta told courts kids 'shouldn't be on the platform' as defence. Judge ruled (Oct 2024) design defects not protected by Section 230. School districts in 19 states suing for educational impact. California/New York passed laws because voluntary measures failed.
What they claim: Instagram promotes two-factor authentication as a strong security measure and encourages all users to enable it
What we found: The AI support chatbot bypassed normal verification processes entirely. Accounts without 2FA were completely unprotected — but the real failure is that Meta's own AI agent had no rate-limiting or authentication enforcement before acting on reset requests. OWASP's Top 10 for LLM Applications had specifically warned against giving AI agents "excessive agency" — the ability to trigger irreversible actions without human confirmation.
What they claim: Meta claims it invests in security and protects user data
What we found: On June 6, 2026, a logic bug in Instagram's web-based password reset flow was found to expose unredacted email addresses and phone numbers for any account — including Mark Zuckerberg's. Separately, Meta disclosed a related account recovery flaw (April 17, 2026) affecting 20,225 people, reported to Maine AG.
Events detected by our automated monitoring of CVE databases, regulatory agencies, and breach trackers.