Four Kids "Safety" Bills, Supporting Online Digital ID Agenda, Hit Senate Floor

KOSA and the CHATBOT Act say they do not require age verification. Their duties still revolve on knowing a user's age.

The CHATBOT Act says that nothing in it shall be construed to require a company to "implement an age gating or age verification" system, or to "affirmatively collect any personal data with respect to the age of any individual that the covered entity is not already collecting in the normal course" of its business. The Kids Online Safety Act carries a version of the same promise, ruling out "the affirmative collection of any personal data with respect to the age of users" that a platform doesn't already gather.

But now read the rest of the same bills...

Yesterday, the Senate Commerce, Science, and Transportation Committee sent four children's online safety bills to the Senate floor, with parents who attribute the harm of their children to social media sitting right there in the room. KOSA went through on a unanimous voice vote. This obviously wasn't a place for a debate. The Youth AI Privacy Act from Senator Ed Markey advanced. So did the CHATBOT Act from Senator Ted Cruz, with Senators Schatz, Curtis and Schiff as co-sponsors. Senator Tammy Duckworth's bill makes four, and it orders the FTC and the Consumer Product Safety Commission to study AI-enabled toys, which turns on nothing a company has to know about a user. A fifth, the SCREEN Act, got a tally and no result, which we'll come back to.

KOSA passed the Senate in 2024 by 91 to 3, but the House never took it up. KOSA's "duty of care" is the provision that gets the attention. It requires platforms to "exercise reasonable care" in design features to prevent and mitigate a listed set of harms to minors, with the FTC enforcing, and the harms run from conditions with "clinically diagnosable symptoms" through patterns of use "that indicate compulsive" behavior to sexual exploitation. The House stripped it out. The Senate sponsors called that version dead on arrival.

The disclaimer and the duty

Every one of these bills turns on a company knowing something it has no way of knowing.

KOSA defines "know" as having "actual knowledge or knowledge fairly implied on the basis of objective circumstances." The CHATBOT Act uses the identical phrase. The Youth AI Privacy Act uses it too. And that definition does more than mark out a glossary entry, because almost every duty in these bills hangs off it. KOSA's safeguards apply to "a user that the covered platform knows is a minor." Its parental tools apply "in the case of a user that the platform knows is a child." The Youth AI Privacy Act's restrictions bind a deployer "with knowledge that a user of an AI chatbot is a minor."

KOSA says who determines what a company already knew. The Federal Trade Commission or a state attorney general "shall rely on competent and reliable evidence, taking into account the totality of the circumstances, including whether a reasonable and prudent person under the circumstances would have known" the user was a minor. The CHATBOT Act repeats the standard almost word for word. Violations are treated as unfair or deceptive acts under the FTC Act, and state attorneys general can sue on behalf of their own residents.

A company is liable for treating a minor as an adult. Treating an adult as a minor costs it nothing. The evidence of what it "should have known" gets assembled later, by a regulator or by an elected state attorney general, using a standard as elastic as the totality of the circumstances. The cheapest way to never be on the wrong side of that is to check everyone at the door and keep the receipt.

Others read it differently. The Age Verification Providers Association, whose members sell the checking, says KOSA sidesteps how a platform is meant to work out who is a minor, so that "the operative legal standard remains implied knowledge" and no service is obliged to install age-assurance technology.

Blumenthal calls KOSA "content neutral" and has said it would not let the FTC or state attorneys general sue over content or speech. That answers a different objection. Both answers leave an enforcer free to argue, after the fact, about what a company should have known about a user's age.

Congress left the words "check everyone" out of the text. Congress wrote a rule that only pays out one way, and then added a sentence saying it isn't requiring the obvious response to it.

So how is a company supposed to work out, without asking, which of its users a reasonable and prudent person would have known was fifteen?

The family account

The CHATBOT Act is the clearest case, because it needs three answers, not one.

A covered AI chatbot has to know whether a user is a child under 13, a teen who has "attained 13 years of age" but is not yet 18, or an adult. Children can only get in through a parent-managed family account. Teens need verifiable parental consent. The parent has to be a parent - a fourth thing the company has to establish about a stranger.

The Electronic Frontier Foundation's Joe Mullin put the consequence in a matter-of-fact way, writing that "the bill says it doesn't require age verification" and that "given the potential liability of getting something wrong, AI companies will likely require stricter forms of age verification to figure out who is under 13, a teenager, and who is a parent."

Cruz's bill does say so twice over. Alongside the general disclaimer, it provides that nothing in the consent section requires a teen or a parent to hand over government-issued identification, either to prove the relationship or to give consent.

Then it names the safe harbor. A covered entity, the text says, "shall be deemed compliant with the requirements of this subsection if the covered entity is in compliance with the requirements of the Children's Online Privacy Protection Act of 1998" and its rules "to use reasonable efforts (taking into consideration available technology) to provide a parent with direct notice and to obtain verifiable parental consent." The FTC's COPPA Rule lists what counts. One of the listed options is "having a parent submit a government-issued photographic identification that is verified to be authentic and is compared against an image of the parent's face taken with a phone camera or webcam using facial recognition technology and confirmed by personnel trained to confirm that the photos match," on condition that the ID and the images are "promptly deleted by the operator from its records after the match is confirmed."

That means government ID plus a face scan, matched by a human being. That is what the same bill, under the same sponsor, points companies toward on the page after it tells them nobody has to produce a government ID for anything.

And what the family account then holds is not a permission slip. Where a parent takes up the option, which is theirs to take for a teen and the only route in for a child under 13, Congress would be creating a record of teen AI conversations.

What Section 107 orders up

KOSA orders a study of age verification systems, and the questions it tells the agencies to answer include "what information may need to be collected to create this type of age verification system," the accuracy of such systems, how one "could verify age while mitigating risks to user privacy," and the technical feasibility "including the need for potential hardware and software changes, including for devices currently in commerce and owned by" the public. The result goes to Senate Commerce and to House Energy and Commerce.

But what about devices already in your hands? Congress is asking what it would take to rebuild them so they can tell a website how old you are before you type anything.

KOSA does exclude a long list of services from its reach, among them virtual private networks, schools, libraries, and video streaming that predominantly carries news, sports, or entertainment. Section 107 asks its question about everything else.

The Youth AI Privacy Act

Markey's bill is the narrowest of the three but lands in the same place. A deployer that knows a user is a minor may not process that minor's data to profile them, may not train a model on it or pass it to a third party for training, and may not use engagement features such as badges for time spent or outputs generated when nobody asked. A fact sheet from Markey's office adds a ban on push alerts and a requirement that chatbots disclose they are not human.

Its rule of construction does one job only, which is to tell enforcers to weigh the totality of the circumstances and ask what a reasonable and prudent person would have known. It carries no sentence disclaiming age verification at all.

If you’re tired of censorship and surveillance, join Reclaim The Net.
Subscribe

Every one of those limits applies only to minors. The bill's own findings note that in 2025 roughly two-thirds of teenagers reported using AI chatbots. The way to give those teenagers a special privacy regime is to find them, and the way to find them is to sort everybody.

The one that says it out loud

Then there's the SCREEN Act, which doesn't bother with the disclaimer at all.

It requires covered platforms to adopt "technology verification measures" that determine whether it is "more likely than not" that a user is a minor, and it forecloses the polite version in a single line. Requiring a user "to confirm that the user is not a minor shall not be sufficient." Ticking a box is out. A platform may hire a third party to do the checking, and the bill says that doing so "shall not relieve the covered platform of its obligations under this Act or from liability under this Act." Verification data must be kept "no longer than is reasonably necessary," a limit with no number in it.

It went nowhere anyway. It hit a 15-to-13 tally, but only because a majority of the committee has to be physically present to vote and a majority wasn't.

What happens next

The House passed its own package on June 29, 2026, the KIDS Act, by 267 to 117, and it contains a House version of KOSA without the duty of care. Senator Marsha Blackburn told Wednesday's hearing that "the Senate cannot and will not accept the version that the House passed earlier." The Senate versions go further; the Senate leaves for a month-long recess at the end of the week, and Congress returns in September with a few weeks before it has to fund the government past Sept. 30.

Blackburn also said that "we're sending a message to Big Tech that the era of Big Tech profiting off of our children is over." Senator Richard Blumenthal, her co-author, said that he sees "enormously powerful momentum."

What an adult loses is the ability to read a page, watch a movie, or type a question without first proving, to a company that decides for itself how long to keep the proof, who you are.

Explore more on these topics