The KIDS Act: Implications for Online Age Verification and Privacy
The KIDS Act: Implications for Online Age Verification and Privacy
The KIDS Act creates systemic pressure for universal age verification
Although the KIDS Act contains disclaimers stating that age verification is not explicitly required, the legislation establishes a "knows or should have known" legal standard that effectively forces platforms to verify the age of all users to avoid liability. Because the law imposes specific protections and parental tools for users under 13 (children) and those between 13 and 16 (teens), platforms face significant legal risk if they fail to identify minors correctly.
To mitigate this risk, services are likely to adopt restrictive age-checking practices, including:
- Identity Documentation: Requesting passports or driver's licenses.
- Age Estimation: Using facial scans or behavioral analysis to guess a user's age.
These estimation systems are noted for their inaccuracy, particularly regarding children, people of color, people with disabilities, and trans or nonbinary individuals. Consequently, adults may be required to prove their age to ensure they are not misclassified as minors.
Broad moderation mandates threaten lawful speech
The revised Kids Online Safety Act (KOSA) section of the KIDS Act requires platforms to "establish, implement, maintain, and enforce" policies addressing broad categories of content. While some categories cover illegal activity (e.g., sexual exploitation), others cover lawful speech, including discussions regarding:
- Narcotic drugs, tobacco, cannabis, and alcohol.
- Gambling and financial fraud.
This creates a "chilling effect" where platforms may proactively remove lawful discussions—such as teens seeking help for addiction, recovery, or family gambling problems—to avoid the legal risks associated with failing to enforce these broad policies.
Encryption and private messaging are under threat
The KIDS Act introduces regulations for direct messages, ephemeral (disappearing) messages, and AI chat services. While the bill claims not to override strong encryption, it requires platforms to "address" harms to minors. This creates a fundamental technical contradiction: platforms cannot address content within encrypted communications they cannot read.
This contradiction may pressure service providers to:
- Weaken encryption standards to allow for monitoring.
- Limit the functionality of ephemeral messaging, which is currently used as a privacy feature to mimic real-world conversations.
Community Perspectives and Counterpoints
Public discussion regarding the KIDS Act reveals a deep divide between those prioritizing child safety and those prioritizing digital privacy.
Arguments Against the Act
Critics argue that the legislation is a vehicle for mass surveillance and a reversal of long-standing internet privacy norms.
"I remember when the advice was to NOT give out your personal information online. Now it's 'present your personal info when demanded or else'."
Some suggest that age restriction should be handled at the device level by parents rather than by the platforms or the government.
Arguments in Favor of the Act
Some proponents argue that the current lack of regulation allows harmful content to reach children unchecked and that parental responsibility has failed.
"Giving kids access to social media should have the same criminal penalties as giving them heroin... If parents won't parent, we must force their hand."
Technical and Legal Nuances
Some observers note that the bill's scope may be narrower than reported. One analysis suggests that "covered platforms" are specifically those that use personal information for advertising or content recommendations, meaning personal blogs or non-commercial sites might remain exempt.
Additionally, some suggest the government could implement a privacy-preserving alternative, such as a zero-knowledge proof system or a government-issued digital token that verifies age without revealing identity.