Of the four bills the Senate Commerce Committee advanced yesterday, the Youth AI Privacy Act is the one worth taking apart in detail — because unlike the others, it contains a provision that privacy advocates have been demanding for two years, wrapped in a structure that undermines it.
The good provision
S. 4199 would prohibit AI companies from training on a minor’s chat logs, and from disclosing those logs to other companies.
This is correct. It is more than correct — it is the single most important substantive restriction anyone has proposed on conversational AI.
Consider what a chat log with an AI assistant actually contains. Not search queries, which are fragmentary and ambiguous. Full conversational disclosure: the thing the person is worried about, in their own words, at length, with follow-ups, in a context where they believe they are talking to something that is not judging them and not a person. Teenagers use these systems for homework, and they also use them for questions about their bodies, their sexuality, their families, their mental health, and things they have not told anyone.
That corpus, in a training set, is the most sensitive collection of adolescent disclosure ever assembled. In a disclosure pipeline to other companies, it is a product.
The bill would stop both. That deserves credit and it should not be lost in the criticism that follows.
The fatal structure
The prohibition applies only to minors.
Which means a service subject to the Act must determine which of its users are minors. Which means it must assess the age of every user. Which means it must collect identity-linked information from adults — an ID, a face scan, a credit card, a carrier attestation — in order to know whom the protections apply to.
A statute whose purpose is to reduce data collection about young people requires expanded data collection about everyone, including young people. That is EFF’s “privacy paradox,” and it is not a clever framing. It is the operational consequence of the drafting choice.
The alternative was available and is one line shorter: AI companies may not train on user chat logs or disclose them to third parties. No age determination. No identity checkpoint. Better protection for minors, because it applies to minors who did not get age-verified. Better protection for adults, who currently have none.
That version does not exist because it costs the AI industry its training corpus, whereas the minors-only version costs it a demographic that generates comparatively little revenue and cannot vote.
The “harm to users” carve-out
The second defect is narrower and more concerning on inspection.
The Act expressly permits AI companies to collect a known minor’s personal data for the purpose of testing, identifying, and addressing “harm to users.”
The exception has an obvious justification. A company genuinely needs to analyse conversations to detect a teenager in crisis, to catch grooming behaviour, to identify a model failure mode that is hurting people. Safety work requires looking at data. Nobody sensible wants a rule that makes crisis detection illegal.
But “harm to users” is not defined. And an undefined exception attached to a statute whose entire operative effect is a data restriction is not a narrow exception — it is a general-purpose authorisation with a safety-shaped label.
The practical reading: a company that wants to retain and analyse a known minor’s chat logs needs a harm-prevention rationale. Producing one is not difficult. Content safety, self-harm detection, abuse prevention, model quality as it bears on user wellbeing — every serious AI company already runs programs under all of those headings, and every one of them involves reading conversations.
So the bill’s structure is: you may not process a minor’s data, except for the purposes for which you were already processing it.
EFF’s specific worry is worth stating plainly: this authorises expanded collection on a population already disproportionately targeted for identity theft. Children’s identities are the most valuable to steal, because the fraud goes undetected for years — nobody checks a nine-year-old’s credit report. Concentrating verified-minor identity records inside AI companies, under an exception nobody has scoped, creates a target.
The First Amendment problem
The Act’s “safe design features” provisions regulate things like notifications and alerts — how the product is allowed to shape user attention.
These are government-mandated design restrictions on an expressive product, and the constitutional analysis here is not speculative. Federal courts have already blocked substantially similar state laws — California’s Age-Appropriate Design Code most prominently — as likely unconstitutional. The reasoning is that design mandates on how a service presents content are regulations of the presentation of speech, and they are not saved by being aimed at minors, because, as courts have repeatedly held, minors are entitled to a significant measure of First Amendment protection.
A federal statute inherits that analysis. Congress does not get a different First Amendment than Sacramento.
What a better bill looks like
The fix is not complicated, and the good provision survives all of it:
-
Apply the training and disclosure prohibition to all users. Delete the age qualifier. This is strictly better for minors and costs nothing in protection.
-
Define the harm exception. Enumerate the categories — imminent self-harm, child sexual exploitation, credible violence — and require documented, time-limited, audited access rather than a standing authorisation.
-
Prohibit age verification as a compliance mechanism. If protections are universal, no age determination is needed, and the statute should say the Act may not be construed to require or permit collecting identity documents.
-
Drop the design mandates. They are the provisions most likely to be enjoined, and their loss in litigation risks taking the good provisions down with them depending on severability.
What you can do now
While this is pending:
-
Assume every AI chat log is retained and reviewable. Whatever the retention policy says, safety review, legal hold, and abuse investigation are all standing exceptions at every major provider.
-
Turn off training on your conversations where the option exists. OpenAI, Anthropic, and Google all offer it in settings; on some consumer tiers it is on by default. It takes one toggle.
-
Use temporary or incognito chat modes for anything sensitive. These reduce retention meaningfully, though not to zero.
-
Talk to teenagers in your life about what these systems are. The most effective protection available right now is a fifteen-year-old understanding that the thing that feels like a private confidant is a logged product owned by a company. That conversation is worth more than S. 4199 as drafted.
-
If you want the good provision to survive, say so specifically. Contacting a Senate office to say “keep the chat log training ban, apply it to everyone, drop the age gate” is a more useful message than support or opposition to the bill as a whole.
The pattern
American privacy legislation has a persistent failure mode: it protects a sympathetic subgroup rather than a category of data.
Protecting a subgroup requires identifying who belongs to it, and identification is surveillance. Protecting a category of data — chat logs, biometrics, precise location — requires identifying nothing about anyone.
Every time Congress chooses the first shape over the second, it builds an identity infrastructure it did not intend to build, and it leaves the underlying practice legal for everyone outside the protected class. The Youth AI Privacy Act contains the best data restriction proposed in this Congress. It is attached to the wrong noun.



