Aug 07, 2026 · 6 min read
KOSA Clears Senate Panel With 3 Kids AI Bills
On August 5, 2026 the Senate Commerce Committee advanced the Kids Online Safety Act alongside the Youth AI Privacy Act, the CHATBOT Act and the Children's Artificial Intelligence Toy Safety Act. EFF and NetChoice oppose the package; Fairplay backs it. All four now head to the full Senate.
Every law that promises different treatment for children contains a hidden requirement it rarely states out loud: somebody has to sort the children from everyone else. That sorting step is where the privacy objection lives, and on August 5 the Senate Commerce Committee advanced four bills that all depend on it.
Key Takeaways
- The Senate Commerce Committee advanced four children's online safety bills on August 5, 2026: KOSA, the Youth AI Privacy Act, the CHATBOT Act and the Children's Artificial Intelligence Toy Safety Act.
- KOSA imposes a duty of care on platforms to mitigate alleged harms to minors and requires protective defaults and limits on addictive design features. An earlier version passed the full Senate 91 to 3 in a prior Congress.
- An amendment from Sen. Ted Cruz to the Youth AI Privacy Act passed 15 to 13 along party lines, loosening the bill's original 30 day cap on chatbot memory in favour of longer retention subject to parental choice.
- EFF argues the package produces a privacy paradox: protections that apply only to minors force services to age gate everyone, which means collecting identity data from adults who were never the subject of the bill.
- Verification methods contemplated in practice include government ID checks, facial age estimation and bank record checks, each of which creates a new database that can be breached, misused or subpoenaed.
What Did the Senate Commerce Committee Actually Pass?
Four separate bills, three of them by voice vote, in a single markup.
- The Kids Online Safety Act (KOSA). Establishes a duty of care obliging covered platforms to mitigate harms to minors, and requires social platforms to restrain addictive features and turn on protective defaults for young accounts.
- The Youth AI Privacy Act (YAIP), sponsored by Sen. Ed Markey. Governs how AI chatbot providers retain and process data from young users, and bars processing their chat logs for model training, profiling and disclosure to third parties.
- The CHATBOT Act, formally the Children's Health, Advancement, Trust, Boundaries, and Oversight in Technology Act. Requires family account structures and verifiable parental consent before a minor can use a covered service.
- The Children's Artificial Intelligence Toy Safety Act. The narrowest of the four, directing the National Academies to study AI in children's toys.
The IAPP's account of the markup notes that the toy study bill, the CHATBOT Act and YAIP all cleared on voice votes, with the only recorded division being on the Cruz amendment.
Why Do Privacy Groups Say KOSA Creates a Privacy Problem?
Because a duty of care owed specifically to minors is unenforceable unless the platform first identifies which users are minors.
EFF's position, set out in its call for the Senate to reject KOSA, is that the bill pushes platforms toward age verification or age estimation systems, and that those systems demand "the handing over of more sensitive data, simply to access lawful online speech and services." The methods available in practice are government ID upload, facial analysis, bank record checks and similar identity signals. Each one, EFF writes, creates "new databases of personal information that can be breached, misused, or demanded by governments."
The second objection is about speech rather than data. Faced with liability for harms that are defined loosely, EFF argues, "the safest response is to remove lawful speech or shut down forums discussing those topics altogether." A platform hosting a support forum for eating disorder recovery has no cheap way to prove it mitigated harm, and shutting the forum is cheap.
NetChoice, an industry trade group, also opposes the bill. Fairplay, a children's advocacy organisation, supports it. That alignment has held for several years and did not shift in this markup.
What Is the Youth AI Privacy Act's Privacy Paradox?
It is EFF's name for the trap that catches every minor specific mandate, and its analysis of YAIP states it in one line: "if a bill requires that online services offer protections to minor users, the services will respond by imposing age gates."
Follow the logic. YAIP restricts what an AI provider may do with a young user's chat logs. To comply, the provider must know which users are young. To know that, it asks everyone. The result is that a bill written to reduce data collection from teenagers increases data collection from adults, and increases it in the most sensitive category there is, identity documents.
EFF raises a second concern specific to this bill: it permits AI companies to collect minors' personal data for the loosely defined purpose of detecting "harm to users." That is an exception written into a privacy statute, aimed at a population EFF describes as already being targets of data theft and identity fraud. The net effect, in its reading, is "less privacy, not more."
EFF does credit the bill's core prohibitions. Barring chat logs from training data, profiling and third party disclosure is a genuine protection. Its argument is that it should not be rationed by age.
What Did the Cruz Amendment Change?
It replaced a hard retention limit with a parental decision, and it was the only contested vote of the markup.
As introduced, YAIP capped how long a chatbot could retain a young user's conversation memory at 30 days. The amendment from Sen. Ted Cruz allows longer retention where a parent opts in. It carried 15 to 13, on party lines.
A fixed deletion deadline is auditable from outside: either the record exists after day 31 or it does not. Consent based retention is auditable only against the consent records, which are held by the same company that benefits from the retention. That is a meaningful change in enforceability, whatever one thinks of parental choice as a principle.
EFF separately warns that YAIP's mandated "safe design features," which restrict notifications and push alerts, closely resemble state age appropriate design codes that federal courts have largely blocked on First Amendment grounds.
Where Does This Leave Anonymous Users?
Worse off, and the people most affected are not children.
An age gate is a chokepoint at which a pseudonymous account becomes a verified identity. For a source contacting a newsroom, a domestic abuse survivor researching options or an employee assembling a whistleblower disclosure, that chokepoint is the risk. We covered the same structural problem when the KIDS Act raised the prospect of ending anonymous whistleblowing, and again when Illinois HB 5511 proposed pushing ID checks down to the device layer.
The United Kingdom has already run the experiment at national scale, and the resulting identity checks drew mass surveillance objections of exactly this shape. The verification vendor becomes a single, extremely attractive target holding scans of government issued documents linked to browsing behaviour.
What Happens Next?
All four bills go to the full Senate, and KOSA arrives with unusual momentum: an earlier version passed the chamber 91 to 3.
If you want to track this rather than read about it later, three things are worth watching. First, whether the floor text keeps or drops explicit language disclaiming an age verification mandate, since that disclaimer is what determines whether platforms feel obliged to build one anyway. Second, whether the Cruz retention change survives. Third, whether any of the four bills acquire a data minimisation requirement covering the verification data itself, which none of them currently carries.
The courts are not waiting for Congress either. A New Mexico judge ordered Meta to pay $567 million and capped youth usage at 90 hours a month, imposing by injunction several things these bills only propose.
Protecting children online is not a fringe goal, and nobody serious argues otherwise. The open question is whether a country can build the sorting machine these bills require without also building the most complete identity database it has ever had.