A bipartisan bill just introduced would build an age check into the operating system of every phone and computer sold in America.
The Digital Age Assurance Act of 2026, S. 5090, from Senators Andy Kim, Cynthia Lummis, Adam Schiff, and John Barrasso, takes California's age-signaling law and makes it the national standard.
The bill was referred to the Senate Committee on Commerce, Science, and Transportation on July 22, 2026, and would take effect 18 months after enactment.
We finally obtained a copy of the bill text for you here.
With the proposals, an operating system cannot be used without an account, and the account requires the user to "indicate the date of birth and age of the user."
For now, the user gets to declare their own age. A "covered device" is any computer, mobile device or other general-purpose computing device capable of running an operating system, so the requirement reaches practically everything.
This is also backdated and accounts that already exist when the law takes effect are included.
The operating provider may skip the prompt where it already knows the age of the user from some other obligation, including a purchase authorization.
When a declaration is made into one of four brackets, under 13, 13 to 15, 16, or 17+. The system broadcasts only the bracket, which the bill defines as "non-personally identifiable data derived from a user's date of birth or age."
Apps, app stores, and even browsers would have to have the ability to request that bracket and use it as "the primary indicator of a user's age."
Some websites would be included in this too. A "covered internet website" is one already "required under Federal or State law to verify the age of a user," so the website obligations attach only where a state or federal age-verification mandate already exists.
With the first use of the browser on a device, it would request a signal from the operating system, and then it hands that signal to covered website operators on request. But the bill does not say how.
Under the proposals, a "browser provider" is anyone who "owns, maintains, or controls a browser for use on a covered device." No size threshold is attached. A small maintainer with a few thousand users would carry the same obligation as a big tech platform like Google.
Anyone under 17, which is the bill’s definition of a "child," has to "link their account to the account of a parent or legal guardian.” The only exception is for emancipated minors. There’s no trusted adult option that can override this. A 16-year-old in an abusive household, or one researching a parent's conduct, has no route that does not run through the person they need distance from.
It should be stated here that minors hold First Amendment rights of their own, something politicians often forget (or ignore) and Brown v. Entertainment Merchants Association (2011) is unfriendly to the idea that the state may deputize parental authority as a general instrument of speech control.
There are other constitutional elements here too. Anonymous speech and anonymous reading are both protected, and this bill installs a declared-age checkpoint under both, all baked into the operating system. Adults would get bracketed too, as the architecture has to be built for the entire population in order to sort the minority who are minors.
Section 4(b) turns the signal into a gate. It would now become unlawful to let a user access an application, or a feature of an application, or a covered website where the operator "has determined" that access would be inappropriate for a given bracket, and the operating system signal puts the user in that bracket.
The legal standard is whatever the company wrote in its own policy, revisable at will. That would clearly be federal liability attached to privately authored content rules, and it ratchets. That means that any voluntary age-differentiated policy a platform chose to adopt now becomes federally enforceable against it. The rational response to all this would be to gate broadly and defensively, or to abandon granular age policies altogether.
According to the bill, once an app or covered website has received a signal, it "shall be deemed to have actual knowledge of the age bracket data of such user across all platforms and points of access."
The federal bill is generally modeled on California's Digital Age Assurance Act, written by Assemblymember Buffy Wicks, signed in October 2025 and coming into force on January 1, 2027.
However, the two bills actually draw their brackets differently. California uses under 13, 13 to under 16, 16 to under 18, and 18 or older, so an adult there is anyone 18 or over.
This is where the federal bill inserts its digital ID trick. The Senate bill stops at 17 and older, which files 17-year-olds in with adults. Most state access laws draw their line at 18. Therefore, the federal signal cannot distinguish a 17-year-old from an adult, and a covered website complying with an 18+ mandate would receive a signal that does not give it enough information to comply with the law. It will need something further, which routes straight back to conventional ID check verification.
There is some lip service given to privacy in the bill. The bill bans developers, websites, and operating system creators from selling bracket data or sharing it with third parties. They may not use it "for profiling, engagement optimization, or targeted advertising," or combine it "with other personal or inferred information regarding a user."
The Federal Trade Commission and state attorneys general would be tasked with enforcing the terms. Fines can go up to $2,500 for each negligent violation and $7,500 for each intentional one, multiplied by the number of children affected. There are no carve-outs for small entities, and no revenue threshold or user-count threshold. A lone individual maintaining a single small app is a "developer," and that exposure is the standard engine of collateral censorship.
In her pitch for the bill, Lummis presented it as a privacy-safe option. "By keeping government IDs and facial scans out of the equation, the Digital Age Assurance Act gives parents real protection for their children," she said.
Kim tied it to his own family, citing "a lot of anxiety about keeping my two boys safe from dangers online."
The text does carry some of that promise, but we had to look through the details to see what's really going on. Section 10 says that nothing in the Act shall be construed to require "any person to verify the age of a user through" the collection of "a government-issued identification document, biometric information, or other sensitive personal information," or through "facial age estimation technology."
Keep that in mind, however, because there are three provisions in the bill that go on to qualify this. Section 3(d) says that where an OS provider receives "clear and convincing information" that a user's real age differs from the bracket it is signaling, the provider "shall verify the age of the user." A corrected signal would then go to everyone who received the old one. The bill never actually says how that verification is to be performed, and Section 10 closes by disclaiming any requirement of "a particular technological method of generating, transmitting, or verifying a signal."
What this is is a mandate to verify, with the methods left open. The bill is not a prohibition on ID checks and is still very much a big step toward them, regardless of what the bill's promoters like to say in their press releases. It is a clear instruction to find a way of doing something, issued alongside a promise that no particular way or doing it is being demanded.
Secondly, the alternatives that would let a device prove the accuracy of a bracket without handing over the actual date are optional. Verifiable credentials and zero-knowledge proofs do appear in Section 3, but only "where technically feasible." They are permitted, not required, and the provider decides. Most providers are going to go for the easy option of ID checks.
The third is all about structure. The assurance in Section 10(5) opens with the words "except as provided in sections 3, 4, and 5." Those three sections contain every operative requirement in the bill. The exception swallows the assurance it qualifies.
In case it’s not clear, this all means that the front door is self-attestation of age, and backed by a safe harbor in Section 8(c) for providers acting in good faith when a user lies at signup. The privacy risk arrives later, in the escalation path, and Section 4(c) builds a mandated reporting channel into it.
A developer that has "clear and convincing information" that a user's age differs from the self-attested signal legally must transmit that information upstream to the operating system provider, which triggers the verification duty.
Clear and convincing, if you didn’t already know, is an evidentiary standard that has a settled meaning in court. But here, a private party applies it to its own inferences, with nothing in the text of the bill prohibiting behavioral profiling or content-based inference and no way for the user to contest the determination that their behavior contradicts the age-bracket signal before it escalates.
Section 13 leaves the rest of the doors open. The Act preempts state law "only to the extent that such State law or regulation conflicts" with it, and it expressly preserves any state rule "at least as protective of individuals." This displaces nothing. The growing threat of state age-verification digital ID laws requiring document uploads or face scans survives intact, and are the very laws that define which websites the federal bill covers in the first place. What this bill builds is the national plumbing that actually makes the state verification regimes easy to enforce, then invites states to build on top of it.
Even without a mandated ID upload, every user would have to give an age to the device at setup, and for users under 17 the device also records who supervises them.
California's version of this bill has already drawn allegations that it is unconstitutional and the liability of this kind, up to $7,500 per affected child under the Senate bill, could push companies to verify ages rather than take a declaration at face value. That could be the hidden intention behind the bill, though. Verification of that kind requires documents and face scans, the system Lummis promised to keep out. It also holds sensitive data where it can leak.




