Skip to content
All posts
ai-briefingai-regulationkids-online-safetyus-policy

The Senate Just Moved Four Kids-and-AI Bills at Once. The Hard Part Is the Sorting Machine.

The Senate Commerce Committee advanced KOSA and three children's AI bills on August 5, and every one of them depends on knowing which users are minors.

On August 5, 2026, the Senate Commerce Committee advanced four children's online safety bills in a single markup. Three passed on voice votes. The package is the most significant federal AI legislative movement in months, and it landed the week before the Senate's August recess.

The four bills, per reporting from Broadband Breakfast and the IAPP:

  • The Kids Online Safety Act (KOSA), sponsored by Sens. Marsha Blackburn and Richard Blumenthal. It imposes a duty of care on covered platforms to prevent and mitigate specified harms to users under 17: suicide, eating disorders, sexual exploitation, bullying, substance abuse, addictive design. It requires the most protective privacy and safety settings by default for minors. Blackburn told the committee the bill now has 75 Senate co-sponsors.
  • The Youth AI Privacy Act, from Sen. Ed Markey. It bars AI chatbot providers from processing minors' chat logs for model training, profiling, or third-party disclosure. As amended in committee, it sets a 30-day default limit on how long a chatbot can retain a minor's conversation memory, with parents able to extend that through verifiable consent.
  • The CHATBOT Act, from Committee Chair Ted Cruz and Sen. Brian Schatz. It requires parental controls and verifiable parental consent before minors use covered AI chatbot services.
  • The Children's Artificial Intelligence Toy Safety Act, from Sen. Tammy Duckworth. The narrowest of the four: it directs the National Academies to study privacy and safety risks in AI-enabled toys.

A fifth bill, the SCREEN Act, mandating age verification for adult content, failed to advance when a 15-13 tally fell short of quorum. Ranking Member Maria Cantwell said she could not support it as written.

One detail from the markup matters for anyone building AI products. Markey's bill originally gave the FTC rulemaking authority over chatbot data retention; the committee substitute stripped it in favor of the fixed 30-day default. Markey fought to keep the cap, warning that chatbots could otherwise build "effectively permanent memories of minors' personal disclosures," per Broadband Breakfast. The cap survived. The FTC's open-ended authority did not.

Why practitioners should care

KOSA is not a new bill, and it is not a fringe one. An earlier version passed the full Senate 91-3 in 2024 before stalling in the House. Blackburn used the markup to draw a hard line against the House version passed earlier this summer, calling it "toothless" and "a pale imitation" of the Senate approach. If you ship a consumer platform or an AI chatbot with teenage users, the design implications are concrete: protective defaults, limits on engagement-maximizing features for minor accounts, and documentation that you exercised reasonable care. Duty-of-care regimes are proven with records, not intentions.

The retention cap in the Youth AI Privacy Act is smaller in scope but more immediately architectural. A 30-day default on conversational memory for minors is a data-lifecycle requirement. If your product does not currently partition retention by user age, it will need to.

The case for

The supporters' argument is simple and has numbers behind it. Fairplay, the children's advocacy group, called the Senate version of KOSA "the most protective, popular, and bipartisan of all children's online safety legislation under consideration" and said it would be "the most important new law to protect kids online in nearly 30 years." The 91-3 Senate vote in 2024 and 75 current co-sponsors suggest that is not just advocacy copy.

The substantive case: platforms already know how to build protective defaults; they deploy them when regulation or litigation forces the issue. The Electronic Privacy Information Center and more than a dozen coalition organizations urged the committee to advance the package, per Broadband Breakfast, citing provisions that limit manipulative chatbot design, restrict targeted advertising to minors, and keep minors' data out of training sets. EPIC backing a privacy bill while EFF opposes it tells you the protections are real, even if the critics' structural objection is too.

There is also a judicial backdrop. As gblock.app noted, a New Mexico judge recently ordered Meta to pay $567 million and capped youth usage at 90 hours a month, imposing by injunction several things these bills only propose. Legislation that channels this energy into uniform rules arguably beats fifty state judges improvising.

The case against

The opposition is unusually well aligned across the political spectrum, and it converges on one mechanism: sorting.

EFF's argument, laid out in its analysis of the package, is that a duty owed only to minors is unenforceable unless the platform can identify which users are minors. So the platform asks everyone. Age verification in practice means government ID uploads, facial age estimation, or bank record checks, each of which, in EFF's words, creates "new databases of personal information that can be breached, misused, or demanded by governments." A bill written to reduce data collection from teenagers ends up increasing it for adults, in the most sensitive category there is. EFF calls this the privacy paradox, and it credits the Youth AI Privacy Act's core prohibitions while arguing they should not be rationed by age.

The second objection is speech. EFF argues that loosely defined harm categories push platforms toward the cheapest compliance strategy: removing lawful speech or shutting down forums, including things like eating-disorder recovery communities. Sen. Markey himself flagged a version of this concern in his statement after the markup, noting he has "concerns about how this legislation could be weaponized against LGBTQ+ young people."

Industry opposition came from both NetChoice and the Computer & Communications Industry Association, whose members include Google, Meta, and Amazon. CCIA argued the bills replace parental discretion with "prescriptive federal mandates" built on vague standards, raising constitutional concerns. Worth noting that federal courts have already blocked several state age-appropriate design codes on First Amendment grounds, and EFF warns the package's mandated "safe design features" resemble those blocked statutes. The constitutional track record is not encouraging.

One more technical point from gblock.app's analysis: a fixed deletion deadline is auditable from outside, while consent-based retention is auditable only against consent records held by the company that benefits from the retention. The compromise that passed keeps the 30-day default but weakens enforceability at the margins.

What to watch

All four bills now head to the full Senate, where KOSA's 91-3 history gives it real momentum. Three things to track. First, whether the floor text keeps explicit language disclaiming an age verification mandate, since that disclaimer determines whether platforms build one anyway. Second, whether the 30-day retention default survives floor amendments. Third, whether any bill acquires a data-minimization requirement covering verification data itself. None currently has one.

Sources