KIDS Act Would Push Platforms to Verify Every User's Age

Marcus Vance
Marcus Vance
(Updated: )
Listen to this article0 / 0
Illustration of a smartphone displaying an age-verification screen with an "access denied" message in the background, symbolizing online age-check requirements.

Congress is moving to fast-track the KIDS Act, a sprawling package that folds a revised Kids Online Safety Act (KOSA) together with the SAFE BOTS Act and the SCREEN Act into a single, expedited vote. Supporters say none of the bills require age verification. A close read of the legal standard each one relies on suggests otherwise.

Why "Knows Or Should Have Known" Pushes Platforms Toward Universal Age Checks

The KOSA section of the package states plainly that it should not be read to require age verification. But that disclaimer sits alongside a separate legal trigger that runs through the whole bill: special protections, parental controls, and messaging restrictions all switch on whenever a platform "knows or should have known" that a user is a child under 13 or a teen between 13 and 16.

That phrase matters because it is a negligence standard, not an actual-knowledge standard. A platform does not need to be told a user's age to be exposed; a court or regulator can later decide, after a complaint or a lawsuit, that the platform "should have" figured it out. For a company facing that kind of after-the-fact judgment, the cautious move is not to guess. It is to start collecting age signals from everyone before any dispute exists, which is exactly the dynamic that turns a bill without an explicit mandate into one with a de facto one.

The compliance pressure is not limited to KOSA. The SAFE BOTS Act applies the same "knows or should have known" minor threshold to restrict certain AI chatbot features, and the SCREEN Act requires platforms hosting sexually explicit content to block users who are "more likely than not" minors. Three different legal tests, all converging on the same operational answer: check ages broadly, or accept open-ended liability.

How a negligence standard turns into universal age checksA four-step flow showing how the "knows or should have known" standard creates legal exposure that pushes platforms toward checking every user's age, not just minors'.From Legal Standard to Universal Age ChecksConceptual flow based on the KIDS Act's KOSA, SAFE BOTS, and SCREEN provisionsA user opens a covered platform or appNo age is declared or confirmed at this pointDuties trigger if the platform "knows orshould have known" the user is under 17KOSA, SAFE BOTS, and SCREEN each use this testGetting that judgment wrong creates legalexposure, decided after the fact by courtsActual knowledge is not required for liabilityLikely result: platforms default to checkingevery user's age, not just minors'Source: Electronic Frontier Foundation analysis of the KIDS Act, June 2026

For people, that broader sweep is not abstract. Age-estimation tools that scan faces or analyze account activity make mistakes most often for the groups least able to absorb being wrongly locked out: people of color, people with disabilities, and transgender or nonbinary users. A standard built to single out minors ends up burdening adults whose age the system simply estimates incorrectly.

How the Bundled Bills Expand Moderation Duties for Lawful Speech

The revised KOSA drops the original "duty of care" clause that drew the most criticism in earlier versions of the bill. In its place, the bill requires platforms to establish and actively enforce policies covering specific content categories: narcotics, tobacco, cannabis, gambling, alcohol, and financial fraud.

That sounds narrow until it meets how people actually talk about these subjects online. A teenager asking for help with a parent's gambling problem, a young adult discussing addiction recovery, or someone seeking advice after being scammed are all engaging in lawful speech that touches the bill's enumerated categories. The bill does not ban those conversations directly, but it puts platforms under enough legal pressure that the safer business decision is often to remove or restrict the discussion rather than risk getting the moderation call wrong. That pattern has shown up before with other content-liability laws aimed at online speech.

Three bills, one fast-tracked packageA structure diagram showing how KOSA, the SAFE BOTS Act, and the SCREEN Act are bundled into the KIDS Act, each with its own minor-identification trigger.The KIDS Act PackageThree separate bills moving as one expedited voteKIDS ActFast-tracked as a single vote, not debated separatelyKOSA (revised)Triggers on "knows or shouldhave known" user is under 17Drops the prior "duty of care"clause; adds enforcement dutiesSAFE BOTS ActSame "knows or shouldhave known" minor testRestricts AI chatbotfeatures for minorsSCREEN ActUses a "more likely thannot" minor standardApplies to sexuallyexplicit content hostsThree different legal tests, bundled into one expedited voteSource: Electronic Frontier Foundation analysis of the KIDS Act, June 2026

What the KIDS Act Means for Encrypted and Disappearing Messages

The package also reaches into private communication. It states that certain KOSA requirements should not be read to override strong encryption. But that carve-out is narrow: it covers specific features and messaging controls, not KOSA's separate, broader duty requiring platforms to "address" a list of harms to minors wherever those harms occur, including inside private and encrypted chats.

That leaves an unresolved question. A platform cannot address harmful content it cannot read. The practical pressure that creates is for providers to weaken encryption protections or scale back features like disappearing messages, which are a privacy tool rather than a design flaw, so that the platform retains enough visibility to claim compliance. Like the rest of the package, this provision still depends on a platform identifying who is a minor in the first place, feeding back into the same age-verification pressure described above.

The encryption carve-out's unresolved conflictA flow diagram showing how the bill's encryption protection and its harm-mitigation duty point in opposite directions for private messaging.A Carve-Out That Doesn't Resolve the ConflictHow the bill's encryption language and harm-mitigation duty collideBill text: certain KOSA provisionscannot override strong encryptionCarve-out applies to specific features onlySeparate duty: platforms must"address" harms to minors, includinginside private and encrypted chatsPlatforms can't address content theycannot read inside encrypted channelsThe bill does not answer how this duty is metResulting pressure: weaken encryption ordrop disappearing-message featuresSource: Electronic Frontier Foundation analysis of the KIDS Act, June 2026

None of this has happened yet. The KIDS Act has not passed, and how courts would eventually interpret "should have known" is untested. But the legislative text itself is what advocacy groups point to when arguing the bill's effects will reach far beyond the minors it is meant to protect, touching adult privacy, lawful speech, and the design of private messaging tools across the platforms it covers.

Comments (0)

Sort by:

No comments yet.

Be the first to share your perspective on this topic.