Hello, and welcome to TechScape. I’m your host, Blake Montgomery, US tech editor at the Guardian. Today in tech, we’re discussing Meta’s legal danger in the US and the implications of artificial intelligence for cybersecurity in an era of private cyber-attacks.
Meta finds itself in jeopardy
Meta faces a lawsuit from more than half the states in the US, its home country. The trial starts on Tuesday in California.
Twenty-nine state attorneys general accuse the company of knowingly designing addictive products that harm the mental health of children.
The accusations are similar to a suit brought by an individual earlier this year, a young woman, that the company had negligently operated defective products. She won her case.
Another state, New Mexico, brought a suit to trial against Meta earlier this year, accusing the company of knowing of and allowing for child sexual exploitation on its social networks. Meta also lost that case, and a judge imposed a nearly billion-dollar fine over the phases of the trial. The accusations by New Mexico’s attorney general bear less resemblance to Tuesday’s case than the young woman’s, focusing on crimes committed on Facebook rather than damage to a person brought on by their own use of the social network.
Meta has denied the accusations in all three cases and plans to appeal both of the losing verdicts.
The legal jeopardy that the company faces is severe and growing more so by the day. The states’ legal officials are seeking $200bn in damages. The addiction lawsuit brought by the young woman was a so-called bellwether case, intended to demonstrate how thousands of others filed on similar grounds might play out. Those plaintiffs are now ready for their day in court, and they may multiply the $6m damages imposed on Meta by many times.
Though each set of plaintiffs may bring different authority to bear on their cases, each is seeking explicitly to change the way Meta’s sprawling, lucrative social networks draw users in. The young woman said she hoped to render Meta’s business as usual too expensive to continue. The attorneys general, should they win, have a more immediate route to enjoining the social media giant to eliminate features they deem harmful such as infinite scroll.
Meta itself is ringing the alarm over the threat posed by the trials, casting it as existential. In a court filing, the company claims that the trial’s damages could exceed $1.4tn, equal to Meta’s entire stock market value. The number may be a false alarm – the judge in the case has already called the estimation “unreasonable” – but Meta is still telling us that the cost of the case could be immense.
On the global scale, the potential penalties imperil Meta’s ambitions in the AI race. The company brings in $200bn in yearly revenue, and it’s spending that money hand over fist. With a whole year of revenue potentially wiped out, the company would find itself hard-pressed to spend tens of billions on datacenters the size of Manhattan.
AI is turning cybersecurity into a free-for-all
Artificial intelligence models with powerful cybersecurity capabilities and a new, more permissive policy toward hacking in the US are poised to add a horde of fearsome new cyber-attackers to the digital landscape.
The traditional order of the past saw nation-states and criminal gangs doing most of the hacking, with private companies left to defend themselves, always on the defensive. Anti-hacking laws in much of the world prohibit offensive cyber-attacks by private enterprises. That way of doing business is changing.
On Wednesday, Donald Trump deputized private companies to carry out cyber-attacks against foreign criminal entities. The president signed a national security presidential memorandum directing his administration to “leverage the capability and innovation of the private sector to help conduct these cyber operations under the direction, control and authority of the US government”.
There are some constraints, though. Trump’s memo does not give private firms unlimited ability to hack, but instead would authorize “limited cyber operations at the direction of the US government”. The companies will not be permitted to choose their own targets at the start and must mount their operations in conjunction with US government agencies, per Trump’s memo.
The change comes as labs on the frontier of AI’s development have devised models that can find and exploit deep weaknesses in the world’s digital architecture. Those tools are unruly. Meta disclosed earlier in the month that one of its AI agents – tools that carry out computer tasks autonomously – had broken containment and hacked a third party during safety testing. The list of rogue AI agents from major developers breaching other companies’ systems is growing. OpenAI and Anthropic made similar disclosures in the preceding weeks. OpenAI’s agent hacked into Hugging Face, an online community dedicated to machine learning, and Anthropic’s went after three different companies, including the online coding repository GitHub.
Select private companies, mostly in the US, have been granted access to these models. If they follow Trump’s directive, they won’t be using their new weapons solely for defense any longer. It is easy to imagine a list of companies vetted by the US for access to powerful AI overlapping with a list of organizations permitted to execute online assaults, though no list of private companies authorized to launch cyber offensives, with or without AI agents, has been made public yet. The Department of Homeland Security has 60 days to lay out the specifics of the program.
The geopolitical fault lines of the coming showdown are already drawn. On Friday, Reuters reported that the Trump administration has drafted a letter with an ultimatum for partner countries to choose a side in the AI race, US or China.
With strong new digital armaments in hand and the green light from the US president, private companies are poised to become a new threat vector. Arming the private sector heralds the beginning of a cybersecurity free-for-all that will see businesses waging miniature wars in cyberspace.
Read more: AI models have been going rogue in tests – how worried should we be?
The wider TechScape
Why the US government is banning Chinese robots – video explainer
Spotify to distinguish AI artists from real people – and stop recommending them
Bumble drops women-first chat rule as dating apps seek engagement boost
‘Nightmare fodder’: Roku’s AI slop channel is even worse than expected
Tesla paid Elon Musk 2.5m times more as CEO than its average worker in 2025