The Senate Commerce Committee moved four internet bills on August 5, 2026:

  • KOSA — the Kids Online Safety Act
  • The SCREEN Act
  • The Youth AI Privacy Act (S. 4199)
  • The CHATBOT Act

All four advanced. None has passed the full Senate. Each is framed as protecting minors, and each has a different sponsor coalition and a different nominal target. Read them together and they are one bill with four titles, because they share a single load-bearing requirement.

Every one of them requires a service to know how old its users are.

The mechanism nobody wants to name

You cannot apply different rules to minors without identifying minors. You cannot identify minors without assessing the age of everyone who shows up. And you cannot assess age without collecting something — a government ID, a face scan estimated against an age model, a credit card, a phone carrier attestation, or a third-party identity check.

So a law that says “platforms must protect users under 17” operationally says: every user must prove they are not under 17.

That is the paradox, and it is not a rhetorical flourish. It is the actual compliance path. A statute intended to reduce data collection about children mandates an identity checkpoint in front of every user, which is the largest possible expansion of data collection about everyone.

EFF’s characterisation of the four-bill package is that they move “toward more information being collected, more surveillance, and less privacy for internet users of all ages.” That is a description of the mechanism, not a prediction about intent.

What each one does

KOSA is the oldest and most amended. It imposes a duty of care on covered platforms with respect to design features affecting minors, plus default settings requirements and parental tools. The duty of care has been narrowed repeatedly across successive drafts in response to First Amendment objections — the concern being that a duty to prevent harm to minors, enforced by state attorneys general, gives officials leverage over what content platforms carry. Narrowing has reduced but not eliminated that.

The SCREEN Act targets access to sexual content, requiring age verification technology to block minors. This is the most direct age-verification mandate of the four, and the closest to statutes already being litigated.

The Youth AI Privacy Act (S. 4199) requires AI companies to establish privacy rules for minors and implement “safe design features.” Substantively, it restricts how firms process minors’ personal data — notably prohibiting training on chat logs or disclosing them to other companies. Those are genuinely good restrictions. They apply only to minors, which is what creates the age-gate requirement.

The CHATBOT Act regulates conversational AI aimed at or accessible by minors, including mandates around how chatbots handle certain interactions and what disclosures they make.

The part worth being fair about

The problems these bills respond to are real. Recommender systems optimised for engagement do surface harmful content to teenagers. Chatbots have been involved in documented tragedies. AI companies training on the chat logs of thirteen-year-olds is genuinely indefensible.

Anyone dismissing this legislative wave as manufactured panic is not paying attention. Parents are angry for reasons that hold up.

The objection is not that the problems are fake. It is that the chosen instrument does not solve them and creates a new one.

Why age verification fails on its own terms

Three things are true simultaneously, and any honest assessment has to hold all three.

It doesn’t work on the kids it targets. Age verification stops the incurious. Teenagers who want around it use a VPN, borrow an older sibling’s credentials, or use a service that ignores US law. The population most at risk — kids in unstable homes, kids seeking information about sexuality or abuse or mental health that they cannot ask an adult about — is disproportionately the population that routes around the gate, and disproportionately the population that loses access to help when a service decides compliance is too expensive and geoblocks instead.

It creates a breach target. Age verification systems accumulate government IDs and face scans, at scale, at companies whose core competence is not identity security. We have already watched this fail: age verification providers have been breached, and the resulting exposure ties a real legal identity to a browsing record. That is a worse privacy outcome than anything the underlying statute was addressing. Researchers at Black Hat and DEF CON this week demonstrated the point in some detail.

Courts keep blocking it. Age verification and minor-design laws in California, Texas, and Arkansas have been substantially enjoined on First Amendment grounds. The doctrine is well-established: adults have a right to access lawful speech without identifying themselves, and minors are themselves entitled to significant First Amendment protection. A federal statute does not escape that analysis by being federal.

What would actually help

EFF’s counter-proposal is the one privacy advocates have been making for a decade, and it has the virtue of not requiring anyone to prove their age:

Pass a comprehensive national privacy law that protects everyone. Data minimisation applied universally protects thirteen-year-olds without needing to identify them as thirteen-year-olds. A prohibition on training AI models on chat logs — full stop, all users — achieves the Youth AI Privacy Act’s best provision with none of its age-gate machinery.

Ban behavioural advertising. Most of the engagement-optimisation harm these bills target exists because attention is monetised through behavioural targeting. Remove the revenue model and the incentive to build compulsive recommender systems for teenagers largely evaporates. This is the structural fix, and it is the one that never gets a committee vote.

The reason universal protections keep losing to minor-specific ones is not that they work less well. It is that they impose costs on the entire advertising industry rather than on a politically undefended subset of it.

What to watch

These four bills advanced out of committee. That is a real milestone and not a formality — KOSA has cleared committee before and stalled — but full Senate floor time, House action, and reconciliation all remain.

If any of them becomes law, expect immediate First Amendment litigation, and expect the age verification provisions to be the target. The state-level precedents are favourable to challengers.

In the meantime, the practical advice is unchanged: do not upload a government ID to a website that is not your bank or your government. If a service demands one to view lawful content, that is a data collection event with permanent consequences, and the fact that a statute compelled it does not make the resulting database any less breachable.

The pattern

There is a recurring structure in internet legislation where a real harm to children is used to authorise an architecture that applies to adults.

Nobody in the Commerce Committee wants a national identity layer for the internet. But four bills that each require knowing every user’s age, passed together, build one — not as policy, but as the accumulated compliance artifact of four separate good intentions.

The infrastructure outlasts the intent. It always does.