A Senate hearing room with an empty witness chair and a smartphone displaying a privacy settings menu, warm overhead lighting, documentary style
News

The US Bill That Protects Kids' AI Privacy by Collecting More of Their Data

A bill meant to protect children from AI privacy harms may require more data collection, not less. The EFF warns that age-gating AI services creates surveillance infrastructure that affects all users — and the First Amendment concerns are already being litigated in three states.

AI RegulationPrivacyChildrenUS SenateEFF

The US Senate Commerce Committee is preparing to consider the Youth AI Privacy Act, a bill that would require AI companies to create kids-only privacy rules and implement “safe design features” for minors. The Electronic Frontier Foundation calls the bill a privacy paradox: to protect children’s data, the law would require AI services to identify who is a child — which means collecting more data from everyone.

🔍 THE BOTTOM LINE

The bill, S.4199, introduces some genuine privacy protections — limiting what AI companies can do with chat logs, banning profiling of minors, and restricting training on children’s data. But it also requires services to determine which users are minors, which in practice means age verification for everyone. The EFF argues this creates the same surveillance infrastructure that has already been struck down by federal courts in California, Texas, and Arkansas.

What the Bill Actually Does

The Youth AI Privacy Act has two main components. First, it requires AI companies to create separate privacy rules for users under 18 — prohibiting the processing of personal information for profiling, training, or disclosure to third parties. Second, it mandates “safe design features” that would restrict how online services design their systems for minors, including limiting push alerts and notifications for teenage users.

The bill is narrower than other proposed chatbot legislation. It does not ban AI companions for minors outright — unlike New York’s S9051, which we covered in June. But its scope is broader in one respect: it applies to any AI service a minor might use, not just companion chatbots.

The positive provisions are real. Limiting what companies can do with children’s chat logs, banning profiling, and restricting training on minors’ data are protections that don’t currently exist under US federal law. The Children’s Online Privacy Protection Act (COPPA) covers children under 13, but the 13-17 gap has been a regulatory void.

The Privacy Paradox

The EFF’s core objection is structural: you cannot protect minors’ privacy without first identifying who is a minor. And identification requires data collection.

“If a bill requires that online services offer protections to minor users, the services will respond by imposing age gates to know which users should receive them,” the EFF writes. “A better approach would be to offer the same privacy protections to all users.”

This is not a theoretical concern. Age verification systems — whether ID scanning, facial age estimation, or credit card checks — are surveillance systems. They require users to hand over sensitive personal data to prove their age, and that data must be stored, processed, and protected. The EFF has previously documented how age verification disproportionately affects marginalised users and creates data breach risks.

The bill also contains a provision that allows AI companies to collect a known minor’s personal data for the purpose of testing, identifying, and addressing “harm to users” — without defining what that means. The EFF flags this as a vague loophole that could justify broad data collection under the banner of safety.

The First Amendment Problem

The “safe design features” mandate runs into constitutional trouble that is already being litigated. Federal courts have largely blocked similar laws in California, Texas, and Arkansas because they likely violate the First Amendment rights of both internet users and the online services they regulate.

The Supreme Court has repeatedly ruled that “minors are entitled to a significant measure of First Amendment protection.” The EFF’s argument is that Congress cannot impose a one-size-fits-all government default that restricts how all internet users — including teenagers — access information online.

This is the same legal terrain we’ve covered before. New Zealand’s own age verification debate reached similar conclusions: the technology to verify age online exists, but deploying it at scale creates privacy risks that may outweigh the protections it offers.

What New Zealand Can Learn

New Zealand has no equivalent to the Youth AI Privacy Act. The Privacy Act 2020 covers personal information generally, and the Privacy Commissioner has issued guidance on AI, but there is no minors-specific AI privacy framework. The NZ government’s AI Blueprint for Aotearoa, released in May 2026, mentions children’s safety but does not propose legislation.

The US debate offers two lessons for NZ policymakers. First: the protections in the Youth AI Privacy Act — limiting training on children’s data, banning profiling, restricting chat log disclosure — are worth considering, and they could be applied to all users, not just minors. Second: the age verification trap is real. If NZ drafts a children’s AI privacy bill, it should avoid making age identification the enforcement mechanism.

The EFF’s alternative is simple: offer the same privacy protections to all users. That way, services don’t need to know who is a minor, and the surveillance infrastructure never gets built.

❓ FAQ

What is the Youth AI Privacy Act? A US Senate bill (S.4199) that would require AI companies to create kids-only privacy rules and implement “safe design features” for users under 18. It’s heading to the Senate Commerce Committee for consideration.

Why does the EFF oppose it? The EFF supports the privacy protections but objects to the age verification requirement. To know which users are minors, services must collect age data from everyone — creating surveillance infrastructure that affects all users, not just children.

How is this different from New York’s chatbot companion ban? New York’s S9051 banned AI companion features for minors outright. The Youth AI Privacy Act is broader — it applies to all AI services, not just companions — but narrower in its restrictions, focusing on data practices rather than banning specific features.

Could this affect NZ users? Indirectly. US legislation shapes global platform behaviour — if AI companies build age-gating systems for US compliance, NZ users will likely encounter the same systems. NZ’s own AI privacy framework is still developing, and the age verification debate is relevant here too.

🔍 THE BOTTOM LINE

The Youth AI Privacy Act contains real protections that US law currently lacks. But the mechanism — identifying minors to protect them — replicates a surveillance pattern that courts have already blocked in three states. The EFF’s alternative is cleaner: protect everyone’s data, and you don’t need to know who’s a child. Whether Congress listens is another question.

📰 Sources

Sources: Electronic Frontier Foundation, Congress.gov, US Supreme Court