Published
- 21 min read
A Teen Chatbot Privacy Bill Could Make Everyone Prove Their Age
Stay Safe Online Without Making It Your Second Job
The Digital Fortress (Second Edition)
A warm, plain-English guide for people with real lives and finite patience. Learn the handful of habits that genuinely protect your money, accounts, and family, and get honest permission to ignore the rest.
For People Who Cannot Afford to Get Privacy Wrong
The Anonymity Playbook (Second Edition)
A practitioner’s field manual for journalists protecting sources, whistleblowers, and activists. It explains how the surveillance actually works, what each technique costs you, and exactly where it fails.
Write, Ship, and Maintain Code Without Shipping Vulnerabilities
Secure Software Development
A hands-on security guide for developers and IT professionals who ship real software. Build, deploy, and maintain secure systems without slowing down or drowning in theory.
Use AI Coding Agents Without Losing Control of Your Codebase
The Secure Harness
A calm, practical guide to letting agents do useful work inside boundaries you set, enforce, and audit. Ships with 15 copy-pasteable artifacts: hook scripts, permission configs, release gates, and MCP templates.
Stop Shipping Demos. Start Shipping Systems.
The AI Native Engineer
Sixteen hands-on chapters, one real product. Grow it from a single model call into a retrieved, tool-using, observable, production-grade system, with evaluation treated as a habit from the first feature.
A teenager opens an AI chatbot at midnight and types something they would not say at the dinner table. The conversation may cover school, sexuality, depression, family conflict, or a mistake they are afraid to admit. The proposed Youth AI Privacy Act tries to keep that exchange from becoming an advertising profile or a permanent ingredient in a model’s training data. Those are good aims.
The trouble arrives one step earlier. The bill gives special rules to users under 18, so a service needs some basis for deciding who is under 18. A company that cannot distinguish a 16-year-old from a 26-year-old cannot reliably apply two different privacy regimes. The clean promise of extra protection for teenagers can therefore produce a new demand on everyone: prove, estimate, or declare your age before you can speak.
That trade deserves more attention than the bill’s friendly name invites. On 5 August 2026, the US Senate Commerce Committee advanced the Youth AI Privacy Act in a voice vote, alongside several other bills about children and online services. The measure still needs action by the full Senate and House before it could become law. Congress.gov records that the committee ordered the bill reported with an amendment in the nature of a substitute, but as of 9 August 2026 the public text page still displays the introduced March version rather than a published committee substitute. (Congress.gov, IAPP)
This is a live proposal, not a finished rule. The exact wording can still change. The design problem will remain until lawmakers answer a blunt question: how does a chatbot know which private speaker qualifies for the special protection?
What the Senate committee advanced
Senator Edward Markey introduced S. 4199 on 25 March 2026. The introduced text applies to natural-language systems that simulate interpersonal interaction through text, audio, images, video, or other modes. It separates companies that build the underlying system from companies that make the chatbot available, while allowing one company to occupy both roles. (Congress.gov bill text)
For users the company knows are minors, the March text would require repeated disclosures that the user is talking to AI. The notice would appear at the beginning of every session and at least once every 30 minutes. It would also tell the Federal Trade Commission to bar certain engagement features for those users, including rewards based on time spent, most push alerts, typing indicators, and messages generated without a user first saying something. (Congress.gov bill text)
The privacy provisions go further. A chatbot company with knowledge that a user is under 18 could not profile that person from their personal data. It could not use the minor’s data to train an algorithm or transfer the data to another party for that purpose, subject to exceptions for testing and addressing risks of harm. The bill would also stop paid product promotion inside chatbot answers to known minors and limit how long prior conversation data could shape later replies. The FTC would set the precise permitted period through a rulemaking. (Congress.gov bill text)
Those are meaningful restraints. A private conversation with a chatbot should not quietly become an advertising dossier. A child should not have to discover months later that their intimate messages helped train a commercial system. A companion-style product should not manufacture the feeling of a waiting friend through typing bubbles and unprompted nudges simply to increase time on the service.
Supporters focus on those protections. The Electronic Privacy Information Center said on 5 August that the committee vote advanced federal privacy and safety rules for minors using AI chatbots. The Senate Commerce Committee’s own announcement said the bill would prohibit chatbot advertising to minors and address how long prior information may shape responses. IAPP independently reported that the measure passed the committee by voice vote. (EPIC, Senate Commerce Committee, IAPP)
The Electronic Frontier Foundation reaches a different judgment. EFF agrees that limits on training, profiling, and sharing chat logs are positive. It opposes making those limits depend on age, because services may respond by checking or estimating every user’s age. EFF also argues that vague permission to process a minor’s data for identifying or addressing “harm to users” could swallow part of the promised protection. (EFF)
Both sides are looking at real parts of the bill. The protections are not imaginary. Neither is the age-gate pressure. A serious reading has to hold both facts at once and then ask whether the law can keep the first without creating the second.
The trigger is knowledge, and knowledge has to come from somewhere
The introduced bill does not contain a sentence ordering every chatbot to scan a passport. Its obligations apply when a developer or deployer has “knowledge” that a user is a minor. The text defines knowledge as actual knowledge or knowledge fairly implied by objective circumstances. That phrasing matters because it moves the practical argument from the word “verification” to the evidence a company is expected to notice. (Congress.gov bill text)
Imagine a service that asks for a birthday during signup. It has actual information. Imagine another service that never asks, but its product has homework tools, cartoon companions, school integrations, and marketing aimed at teenagers. A regulator may decide the surrounding facts fairly imply that many users are minors. The company now needs a way to decide which sessions receive restricted personalization, no advertising, no push alerts, and short-lived conversational memory.
The company has several choices, none free. It can apply the stricter rules to everybody. It can ask every user for an age. It can demand documentary proof from some or all users. It can hire an age-assurance provider that estimates age from a face, voice, behavior, account history, or device signals. It can infer likely age itself. Or it can block access where it cannot become confident enough.
Applying the safer rules to everyone is the privacy-preserving answer. The bill does not require that outcome. Commercial pressure points the other way because long-term memory, targeted promotion, re-engagement messages, and detailed profiles are valuable product features. If the adult product earns more money or keeps users longer, the company has an incentive to separate adults from minors rather than give all users the minor setting.
That is how an indirect mandate works. Lawmakers can avoid the phrase “show your ID” while writing duties that are difficult to perform without sorting people by age. The legal text controls one group; the compliance system examines a much larger group to find its members.
EFF calls age-verification systems surveillance systems because the check itself can require identity data, biometric material, or third-party records. In its 3 August analysis of this bill, EFF warned that giving privacy protections only to minors encourages services to impose age gates on everybody. The organisation recommends applying the substantive privacy limits to all users instead. (EFF)
That recommendation deserves to be the starting point. If training on private chat logs is too intrusive for a 17-year-old, lawmakers should explain why it becomes acceptable on the morning of the user’s eighteenth birthday. If covert paid recommendations inside a trusted conversation are deceptive for a teenager, the same mechanism does not become clean because the speaker is 35.
An age check creates its own data trail
Age assurance sounds like a gate at the entrance. In practice it is a chain of observations, transfers, decisions, and records. The user presents something. A service or contractor evaluates it. A result returns. Someone keeps enough information to handle fraud, appeals, audits, regulator questions, and repeat visits.
The mildest version asks for a birth date and trusts the answer. That collects little, but it is easy to evade. A stricter version checks an identity document. Now the system may see a legal name, date of birth, photograph, document number, nationality, and address. Even if the chatbot receives only an over-18 token, another company may have processed the document to create it.
Face-based estimation collects a different kind of evidence. A camera image is used to estimate an age range, sometimes with a liveness check intended to stop a user from holding up a photograph. The vendor may promise to delete the image quickly. That promise still leaves questions about transmission, temporary storage, model improvement, error handling, subcontractors, and the record retained to prove that deletion occurred.
Behavioral estimation can be quieter and broader. A service might use account age, language, typing patterns, school-hour activity, social connections, content interests, purchase history, or previous interactions. The user never uploads a passport, yet the system watches more of their life. A wrong guess may be hard to see and harder to appeal.
No single method has to appear in S. 4199 for this risk to matter. The introduced text creates two versions of the product and attaches legal duties to the company’s knowledge of age. Services will need evidence supporting whichever version they deliver. EFF’s warning concerns that incentive structure, not a hidden passport clause. (EFF, Congress.gov bill text)
The resulting record can become sensitive even when it contains only a verdict. “Adult confirmed” reveals less than a passport scan, but it still links a person or device to an age category at a time and place. Repeated across services, those assertions can become a durable identity layer. A token designed to disclose one fact can also become a stable handle if systems reuse it carelessly.
Breaches are only one failure mode. A database can be bought, compelled, repurposed, or linked with another database. Staff can query it. A contractor can change its terms. A government can expand the list of content that requires the same gate. A private system built for one narrow safety claim can become convenient infrastructure for many unrelated decisions.
This is familiar territory for privacy practitioners. Collection creates options for the collector and for anyone who later gains influence over it. The Anonymity Playbook describes the practical rule behind that problem: reduce the number of parties that can connect an activity to a durable identity. An age gate placed before a sensitive chatbot conversation can do the opposite. It may bind the conversation to fresh evidence about who the speaker is.
The cost falls hardest on people who need privacy most. A closeted teenager may avoid a service if access requires a family-controlled identity document. A young person in an unsafe home may not be able to request parental help. An adult exploring addiction, abuse, immigration, sexuality, or political dissent may refuse to place an ID check next to that inquiry. Journalists and sources may avoid a research tool if it begins with a personal proof ceremony.
A law intended to make private conversation safer should measure these dropouts. Access denied is visible. Self-censorship rarely is.
The bill contains protections adults need too
The strongest parts of the Youth AI Privacy Act do not depend on a theory that teenagers are uniquely entitled to confidential speech. They address business practices that are intrusive for anybody who uses a chatbot as a thinking partner, tutor, search tool, companion, or private notebook.
Start with training. The introduced text would bar processing or transferring a known minor’s personal data to train a covered algorithm, except for the stated harm-related exceptions. That is close to a sensible default for all private chatbot conversations. A user can choose to donate a conversation for research or improvement through a separate, informed action. Silence should not be treated as permission simply because a terms page contains a broad clause. (Congress.gov bill text)
Profiling deserves the same treatment. The bill defines profiling as processing data to detect or classify personality and behavioural characteristics. A chatbot can learn which reassurance works, which topic keeps someone engaged, and which emotional tone makes a recommendation persuasive. That power does not become harmless for adults. In a conversation that feels personal, profiling can be more intimate than the web tracking people already struggle to understand.
The advertising restriction is equally useful. The bill would stop a financially influenced promotion, recommendation, or endorsement inside an answer to a known minor. The mechanism is dangerous because the sales message can borrow the chatbot’s accumulated knowledge and conversational authority. An ordinary banner announces itself as an ad. A product suggestion woven into advice can feel like the conclusion of a trusted exchange.
Repeated disclosure that the speaker is talking to software also has value beyond childhood. Good design should make the machine status clear without interrupting every adult session on a fixed clock. A persistent label and honest product language can do that work. Services should be banned from pretending a model is a human, fabricating professional credentials, or designing false signs of human presence.
Some engagement controls need more careful treatment. Blocking time-based rewards and unprompted summons makes sense for companion products built around dependency. A blanket ban on every notification could also remove useful reminders chosen by the user. The right question is whether the feature serves the user’s stated purpose or the company’s engagement target. A medication reminder requested by a user differs from a lonely companion sending “I miss you” because activity has fallen.
The introduced bill asks the FTC to draw some of these lines after enactment. That can provide needed detail, but broad terms carry risk. The exception allowing a minor’s data to be processed for testing, identifying, and addressing harm does not define the boundary of harm with much precision. A company might genuinely need conversation samples to find suicidal responses or sexual grooming. It should have to narrow that use, separate it from product training, minimise access, publish retention periods, and face independent audit. “Safety” cannot become a storage category without an end date.
EFF and EPIC disagree about the bill’s overall merits, yet their public statements reveal common ground. EPIC praises privacy limits on AI chatbots. EFF acknowledges those limits as positive while arguing they should cover everyone. (EPIC, EFF)
Congress should use that overlap. Extend the clean privacy rules to every user. Then write narrow, additional protections for minors where age truly changes the risk, using methods that do not force identity collection from the general public.
Privacy-preserving age assurance still needs limits
Some lawmakers will decide that age-specific rules are unavoidable. If that remains the policy, the next task is to stop age assurance from turning into a general identity checkpoint. “Privacy-preserving” needs technical and legal content. It cannot survive as a label supplied by the vendor selling the check.
A well-designed assertion should answer the smallest possible question. For this bill, that may be whether the user belongs to a protected age band. The chatbot does not need a legal name, address, exact birthday, document number, or copy of an identity card. A yes-or-no attribute can be separated from the underlying evidence.
Separation helps only if the pieces cannot be quietly joined. The age provider should not receive the chatbot topic, conversation, or full destination URL. The chatbot should receive no stable identifier from the age provider. Two checks by the same person at different services should not carry a reusable number that allows those services to recognise the shared user. Cryptographic proofs can support some of these properties, but deployment choices decide whether the promise holds.
Retention must be short and testable. “We delete your selfie” leaves out when deletion occurs, what backups contain, whether derived embeddings survive, whether fraud systems keep a copy, and what an appeal requires. The law should set deletion deadlines for raw evidence and derived data, require public retention schedules, and allow independent auditors to test the process.
Purpose limitation also needs teeth. An age result collected to apply chatbot privacy settings should not be used for advertising, credit, employment, insurance, law enforcement fishing, account enrichment, or cross-service tracking. A provider should not sell the result or use the evidence to train a commercial face model. These restrictions should follow the data through contractors and successors.
Users need a route around automated mistakes. A 19-year-old with a young face should not have to upload ever more intimate evidence to reverse a machine’s guess. A 16-year-old should not lose access to lawful health or educational information because a vendor cannot process their document. Appeals should offer more than one method, explain the decision, and delete rejected evidence.
Anonymous and pseudonymous access should remain possible where the service can apply the safer setting by default. A user who declines to prove adulthood can receive the privacy-protective version. That turns uncertainty into less collection and less persuasion, rather than total exclusion. It also changes the company’s incentive: failing to identify an adult no longer means losing the user entirely.
Lawmakers should prohibit compelled reuse. Once an age-check network exists, other industries will want it. The statute can bar a chatbot assertion from becoming a universal login or a token demanded for unrelated websites. It can also forbid services from storing a durable history of where the assertion was presented.
These controls do not remove every risk. The safest identity record is the one never created. They can reduce how much the gate learns and how far the result travels, which is the right threat model when legislators insist on sorting users by age.
What parents, users, and builders can do now
The committee vote changed the bill’s status, but it did not create immediate duties for families or companies. As of 9 August 2026, S. 4199 has not passed the full Senate or House, and Congress.gov has not published the committee substitute on the bill’s text page. Nobody needs to rush into an identity product because of this vote. (Congress.gov)
You can still reduce the risk the bill is trying to address. The useful steps begin with the conversation itself, not with a perfect prediction about federal law.
-
Treat chatbot messages as records that may leave your device. Before typing a full name, school, address, diagnosis, legal problem, source identity, or family secret, ask whether the answer needs that detail. Replace names with roles. Remove dates and locations when they do not change the question. A useful answer rarely needs the complete story attached to a durable identity.
-
Check the service’s current data controls. Look for settings covering model training, chat history, personalisation, deletion, temporary sessions, and human review. These controls change, so date your check. Turning off training is useful when offered, but it may not stop every form of retention needed for abuse monitoring or account operation. Read the limit, not just the button label.
-
Give teenagers a no-shame exit. A young person who has already disclosed something sensitive needs help reducing further exposure, not punishment for using the tool. Show them how to delete conversations where possible, change the detail level, and move urgent medical or safety questions to a qualified person. Keep the door open. Secrecy grows when adults make disclosure expensive.
-
Do not upload identity evidence casually. If a service asks for an ID or face scan, find out who performs the check, what the chatbot receives, what the verifier keeps, and how to appeal. Prefer a method that reveals only an age band and does not create a reusable identifier. If the service cannot answer basic retention questions, consider the privacy-protective setting or another service.
-
Builders should make the stricter privacy mode available to everyone. Do not wait for a final statute. Offer temporary chats, default training opt-out for private conversations, short retention, export and deletion, clear machine disclosure, and advertising separated from advice. If age is uncertain, apply the less intrusive mode rather than collecting more evidence by default.
-
Security teams should map the age-data path. Document every processor that sees an image, document, date of birth, inferred age, challenge result, or appeal. Record where data is stored, how long it survives, which staff can query it, and whether the same identifier appears at multiple services. Test deletion through backups and derived features, not just the front-end account record.
-
Policy teams should ask for universal privacy before age detection. When commenting on the bill or a future FTC rule, support the limits on training, profiling, covert advertising, and manipulative engagement. Ask lawmakers to extend those protections to adults. Where an age distinction remains, demand data minimisation, unlinkable proofs, strict deletion, purpose limits, and a non-biometric route.
This sequence avoids two common mistakes. One is panic, which pushes families toward invasive verification products before any rule exists. The other is passivity, which leaves intimate chats exposed while Congress argues about wording. You can reduce what the chatbot learns today and still demand better legislation tomorrow.
What a better law would measure
A useful privacy law should be judged by the records it prevents, not by the number of warning screens it creates. The Youth AI Privacy Act points toward several records worth preventing: training copies of private chats, personality profiles, covert advertising decisions, and long-lived conversational memory used to shape a vulnerable speaker.
Its age-specific structure may create a second set: identity documents, face images, age estimates, challenge outcomes, provider tokens, and appeal files. That second set does not automatically outweigh the first. It does have to appear in the accounting.
Congress should require that accounting before the bill reaches a final vote. The public needs the committee substitute, a clear explanation of what changed, and an answer to how companies can comply without checking every user’s age. If the intended answer is universal privacy defaults, the statute should say so. If the answer is age assurance, the statute should set limits on evidence, linking, retention, reuse, and denial of access.
The law should also distinguish a service knowing a user’s age from a service designing for a youthful audience. A knowledge standard that is too weak lets companies ignore obvious child users. A standard that is too broad pressures every general-purpose tool to inspect every visitor. Legislators need to define the objective circumstances that matter and provide a safe harbour for services that apply the protective rules without identifying the user.
Enforcement matters after that. The introduced text gives the FTC authority, allows state attorneys general to act, and creates a private right of action for parents or guardians of minors. Those routes can make duties real. They can also intensify pressure to collect evidence of age if companies believe they must defend every product decision in court. A safe harbour for data-minimising, protective defaults would push compliance toward less collection rather than more proof. (Congress.gov bill text)
Research funding in the bill can help if it studies more than chatbot engagement. The March text would authorise $50 million in each fiscal year from 2027 through 2030 for research related to children’s media and technology, and would add chatbot questions to national health and behavioural surveys. Researchers should also measure who abandons age-gated services, which groups face higher error rates, how often identity evidence is retained, and whether young people move to less accountable tools when blocked. (Congress.gov bill text)
A warning every 30 minutes is easy to count. A teenager who chooses silence because the gate asked for a face scan is harder to count. Good policy has to look for both.
The privacy setting should follow the conversation
The Senate committee’s 5 August vote moved S. 4199 forward, and reporting from IAPP, EPIC, EFF, Politico, and the committee itself agrees on that basic event. They do not agree on whether the bill protects privacy overall. That disagreement turns on the system needed to identify the people who receive its protections. (IAPP, EPIC, EFF, Politico)
The cleanest way through is to protect the conversation first. Do not train on private chatbot messages by default. Do not build personality profiles from them. Do not hide paid influence inside advice. Give every user short-lived sessions and meaningful deletion. Restrict engagement tricks that imitate a needy person rather than serving a user-chosen task.
Those rules remove much of the reason to identify age. They also protect the adult who is grieving, the source testing a line of inquiry, the worker asking about discrimination, and the parent looking for help. Privacy belongs to the situation, not only to a birthday.
Children may still need extra safeguards. Build those additions on the smallest possible age signal, keep the verifier away from the conversation, prevent cross-service linking, and delete the evidence. Let an unknown user choose the safer mode without handing over a passport. The system should spend uncertainty by collecting less.
The bill is unfinished. That is an opportunity. Senators can preserve its strongest limits and close the path from a private chat to a general identity checkpoint. Protecting teenagers should not require everybody else to leave papers at the door.
If you want practical privacy and security analysis without the daily alarm cycle, subscribe to the newsletter. One email per month.
Sources
Sources
- Congress.gov: S. 4199, Youth AI Privacy Act status and actions, accessed 2026-08-09
- Congress.gov: Introduced text of S. 4199, accessed 2026-08-09
- US Senate Committee on Commerce, Science, and Transportation: Commerce Committee Advances Kids Online Safety Legislation, accessed 2026-08-09
- IAPP: US Senate Commerce approves KOSA, children’s AI safety bills, accessed 2026-08-09
- Electronic Privacy Information Center: Senate Commerce Committee Advances Youth AI Privacy Act, accessed 2026-08-09
- Electronic Frontier Foundation: The Youth AI Privacy Act’s Privacy Paradox, accessed 2026-08-09
- Politico: Senate panel’s vote for kids’ safety rules throws gauntlet to House, accessed 2026-08-09