Youth AI Privacy Act Would Mandate Age Verification, EFF Warns
Senate bill intended to protect minors from AI services contains design mandates that courts have already blocked in multiple states.
A bill moving through the Senate Commerce Committee this week would require AI companies to implement special privacy protections for minors—a goal that would force the collection of more personal data, not less, according to digital rights advocates.
The Youth AI Privacy Act mandates that AI services create separate privacy rules and "safe design features" for users under 18. But the Electronic Frontier Foundation warns the legislation contains a fundamental flaw: services can only apply age-specific protections if they first verify which users are minors.
"If a bill requires that online services offer protections to minor users, the services will respond by imposing age gates to know which users should receive them," EFF staff technologist Maddie Daly wrote in an analysis published this week. The organization argues a better approach would extend the same privacy protections to all users, eliminating the need for age verification entirely.
Vague harm-prevention language expands data collection
The legislation includes a provision allowing AI companies to collect personal data from known minors for purposes of testing, identifying, and addressing "harm to users"—language EFF describes as problematic and vague. This exception could require services to gather even more information from young people, a demographic already vulnerable to data theft and identity fraud.
The bill does include some positive elements, according to the analysis. It would prohibit AI companies from using chat logs for training, profiling, or sharing with other companies. But EFF maintains these protections should apply universally rather than only to minors.
Design mandates face First Amendment challenges
The Youth AI Privacy Act's "safe design features" requirement would restrict how online services design their systems, including blocking teenagers from receiving push alerts and notifications. Similar provisions in state laws—sometimes called "age appropriate design codes"—have been enacted in California, Texas, and Arkansas, but federal courts have largely blocked their enforcement on First Amendment grounds.
These laws interfere with both users' rights to access speech online and services' rights to determine how they present information, according to court rulings. The Supreme Court has repeatedly held that minors retain significant First Amendment protections, even as parents maintain authority to set rules for their own families.
Why it matters
The Youth AI Privacy Act represents a growing trend of age-gating legislation that creates a privacy paradox: laws intended to protect young people's data actually mandate collecting more personal information from all users. As courts continue striking down similar state laws on constitutional grounds, the Senate approach suggests Congress has not absorbed those legal lessons. For AI companies already navigating complex compliance requirements, the bill would add verification burdens that security experts warn create new attack surfaces for data breaches—precisely the opposite of its stated privacy goals.
The Senate Commerce Committee is expected to consider the Youth AI Privacy Act alongside three other bills this week. Details were first reported by the Electronic Frontier Foundation.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call
