The Senate Commerce Committee is voting this week on four bills that would fundamentally reshape how the internet verifies who you are—and what data platforms collect about you in the process.
The stakes are framed as child protection. But the mechanism is mass surveillance. KOSA, the SCREEN Act, the Youth AI Privacy Act, and the CHATBOT Act all claim to protect teenagers from dangerous online content and behavior. The problem: they would require age-gating systems that don’t yet exist at scale, forcing platforms to collect, store, and verify identity data on every user—adult and teenager alike. What Congress is calling protection looks, to privacy advocates, like a blueprint for unprecedented behavioral tracking.
- Four Bills, One Infrastructure: KOSA, the SCREEN Act, the Youth AI Privacy Act, and the CHATBOT Act each target a different platform type, but together they would compel the construction of a unified age-verification and identity-data collection system across the internet.
- The Privacy Paradox: To protect minors, these bills require collecting identity data on every user—including the hundreds of millions of adults who have committed no violation and sought no exemption.
- The Surveillance Precedent: Age-verification infrastructure, once built, does not remain limited to its stated purpose—stored identity data becomes accessible to advertisers, law enforcement, data brokers, and political campaigns through subpoenas, breaches, or terms-of-service updates.
The Senate Commerce Committee will vote on all four bills this week. Each targets a different slice of the online ecosystem—social platforms, adult websites, AI chatbots, and algorithmic recommendation systems—but together they send a single message to the technology industry: verify age, or face legal liability.
KOSA, the Kids Online Safety Act, is the broadest. It would require platforms to take “reasonable measures” to protect minors from harmful content and would hold companies liable if they fail. The SCREEN Act targets adult websites specifically, requiring age verification before access. The Youth AI Privacy Act would restrict how AI systems collect and use data from users under 18. The CHATBOT Act would force chatbot providers to adopt specific safety guardrails for young users. For a deeper look at how LGBTQ+ data privacy is already compromised by existing platform architectures, the structural risks these bills introduce are not hypothetical.
Why Age Verification Creates a Surveillance Problem
None of these bills explicitly mandate a single age-verification technology. But they create legal pressure to implement one. And here’s where the privacy problem emerges: age verification at scale requires collecting identity information—government IDs, biometric data, or behavioral patterns that reveal age—and storing it somewhere. That data becomes a target.
The Electronic Frontier Foundation, which opposes all four bills, sent a letter to the Committee this week laying out the core tension. These bills, EFF argues, would “create sweeping new privacy and data security problems” while forcing platforms to adopt “unconstitutional restrictions on the content they host, for both adults and teenagers.” The organization notes that instead of age-gating, Congress should focus on a national consumer privacy bill that protects all internet users, or on banning behavioral advertising—the tracking infrastructure that follows you across the web. The foundational principles behind that alternative approach are detailed in privacy by design, a framework that embeds data minimization into system architecture from the outset rather than layering surveillance onto existing platforms.
But the bills being voted on this week move in the opposite direction. More information collected. More surveillance. Less privacy for everyone.
• Age-verification systems can require government ID, biometric facial analysis, or behavioral profiling — each method generates persistent identity records that outlast the verification event itself
• The Electronic Frontier Foundation identifies all four bills as creating new data security vulnerabilities, not reducing existing ones
• Platforms implementing age-gating would gain the technical capability to verify and log every user’s identity on every login — a dataset with no current legal restriction on secondary use
Is This the Cambridge Analytica Playbook Repackaged as Child Safety?
The structural parallel here is worth naming directly. In 2016, Cambridge Analytica built a psychographic profiling machine by harvesting behavioral data—what people clicked, liked, and searched for—and using it to infer intimate details about their personalities, vulnerabilities, and political leanings. The company didn’t need explicit consent or even awareness. The data was already flowing. What CA did was weaponize it. Age-verification systems proposed in these bills follow the same logic: collect behavioral and identity data at scale, store it centrally, and use it to make inferences about users. The stated purpose is protection. The infrastructure is surveillance.
Once that infrastructure exists, the data becomes available for other uses—law enforcement requests, data brokers, political campaigns. History suggests the mission creep is inevitable. This pattern—legitimate-sounding data collection that quietly enables behavioral profiling at scale—is precisely what our analysis of surveillance infrastructure in Meta’s Threads documents in a contemporary context.
The bills don’t explicitly propose a single verification method, which is part of the problem. Platforms could use government ID verification, which requires storing copies of driver’s licenses or passports. They could use biometric age estimation, which requires analyzing facial features or gait. They could use behavioral inference, which requires building detailed profiles of how you use the internet. Each method has different privacy costs. None of them disappear once the age-gate is built.
• The Electronic Frontier Foundation’s formal submission to the Senate Commerce Committee argues that age-gating legislation creates the conditions for unconstitutional content restriction alongside new data security vulnerabilities — a dual harm that child-safety framing obscures
• Privacy researchers have consistently noted that behavioral inference systems built for one purpose — such as age estimation — generate data profiles that are technically indistinguishable from those built for advertising targeting or political profiling
• The absence of a prohibition on secondary data use in any of the four bills means that identity records created for age verification carry no legal barrier to commercial exploitation
What Does This Mean for Teenagers — and for Everyone Else?
For teenagers, the impact is immediate and visible. Age-gating would restrict access to lawful speech and information—news sites, health resources, political organizing tools, LGBTQ+ support communities. Platforms would have to make content decisions based on age, which means either removing content or requiring verification to see it. Either way, teenagers lose access or lose privacy.
For adults, the impact is more subtle but broader. Age-verification systems don’t vanish once they’re built. They become infrastructure. Platforms that implement them to comply with KOSA or the SCREEN Act will have the capability to verify age on every user, every login. That data—your age, your identity, your login patterns—becomes part of your profile. It can be sold, subpoenaed, breached, or repurposed. Advertisers want to know your age. Insurance companies want to know your age. Law enforcement wants to know your age. Once the system exists, everyone wants access.
This is the surveillance paradox at the heart of child-protection legislation. To protect children, you must collect data on everyone. To enforce age restrictions, you must build infrastructure that enables tracking. The bills don’t require platforms to use that data for anything other than age verification—but they don’t prohibit it either. And once the data exists, the incentives to use it are overwhelming. Research on digital platform adoption consistently finds that data collected for one institutional purpose migrates toward commercial and administrative uses as the technical capability matures — a pattern documented across healthcare, finance, and social media alike.
How Close Is This to Becoming Law?
The Committee is voting this week, which means the bills could move to the full Senate floor within days. There’s no clear timeline for when they might pass or take effect, but the momentum is real. Tech platforms are already preparing for the possibility. Some have begun testing age-verification systems. Others are lobbying for language that would reduce their liability or clarify what “reasonable measures” means.
What you should know: if any of these bills pass, your next login to a social platform, a news site, or an adult website might require age verification. You might be asked for a government ID, a credit card, a phone number tied to your identity, or permission to analyze your face. That data will be stored somewhere. It will be protected by whatever security measures the platform implements—which, based on the history of data breaches, is often inadequate. And it will exist in a legal gray zone where platforms can use it for purposes beyond age verification, as long as they disclose it in a terms-of-service update you’ll never read.
The Senate Commerce Committee votes this week. The full Senate could vote within weeks. The question is whether Congress will build the behavioral profiling at scale first and worry about privacy later—or whether it will listen to the growing chorus of privacy advocates, civil liberties organizations, and security researchers who say there’s a better way.
