A Coordinated Push, Not a Single Bill
On June 29, 2026, the House passed the KIDS Act, H.R. 7757, by a bipartisan 267-117 vote — a package that folds 14 separate child-safety proposals into one bill, according to the International Association of Privacy Professionals (IAPP). The Senate is taking a different route. On August 5, the Senate Commerce Committee, chaired by Ted Cruz, marked up five standalone bills in one session: the Kids Online Safety Act (KOSA, S. 1748), the SCREEN Act (S. 737), the Youth AI Privacy Act (S. 4199), the CHATBOT Act (S. 4407), and the Children's Artificial Intelligence Toy Safety Act (S. 5171), per Cyberscoop's reporting on the markup.
The split matters more than the vote count. The House version notably stripped out KOSA's original "duty of care" standard — the provision requiring platforms to design around foreseeable harms to minors, not just disclose them. Senators Blumenthal and Blackburn, KOSA's own sponsors, said the House text was "dead on arrival" in the Senate without it. The Senate markup restores that language. That single clause is the fault line the rest of this fight runs along.
The Case for Acting
The steelman here isn't hard to make. Research tying heavy adolescent social-media use to anxiety and depression has accumulated for years, and parents have limited tools to intervene once a platform's default settings and recommendation engine are already tuned for engagement. A "reasonable care" standard that forces default-on privacy settings, restricts algorithmic targeting of minors, and gives parents visibility into a child's account is a modest ask next to what several states have already enacted. The SCREEN Act's backers make an equally plain case: minors reach explicit content with a checkbox today, and a federal age-verification floor closes a gap that content filters alone haven't.
Where the SCREEN Act Overshoots
The SCREEN Act's problem isn't its goal — it's its blast radius. As EFF detailed in its analysis of the bill, the mandate applies to any "commercial interactive computer service" that hosts even a single piece of content deemed harmful to minors, which by the bill's text sweeps in Netflix, Reddit, Discord, and Bluesky alongside dedicated adult sites. The bill also explicitly bars self-attestation — "requiring a user to confirm that the user is not a minor shall not be sufficient" — meaning identity-linked verification becomes the baseline, not an option. It further singles out traffic from known VPN addresses for mandatory verification, which functionally discourages the privacy tools millions of ordinary users, journalists, and activists rely on for reasons that have nothing to do with age.
This is the general failure mode of age-verification law: there is no way to confirm a user's age online that is both accurate and privacy-preserving. Every method — government ID upload, facial-age estimation, credit-header checks — creates a new database linking real identity to browsing history, on a mainstream platform, for a purpose unrelated to why that platform holds any other data about you. A single breach turns a compliance requirement into a permanent record of who looked at what.
KOSA's Duty of Care Cuts the Same Way
The restored duty-of-care standard raises a parallel problem. When platforms face liability for content connected to anxiety, eating disorders, or substance use, the economically rational response isn't careful curation — it's blanket removal, because a false negative carries legal risk and a false positive carries none. EFF has flagged this exact dynamic: search results and support communities for the very topics KOSA targets, including addiction recovery and eating-disorder support groups, are among the first things platforms deprioritize under a duty-of-care regime, because they discuss the harmful behavior in order to help people escape it. A standard meant to protect vulnerable teens can end up cutting them off from the resources they're searching for.
The Better Trade
None of this means Congress should do nothing. The COPPA enforcement gap for teens 13-17 is real, and the FTC has already signaled — in its February 2026 COPPA policy statement — that it wants operators using narrower, purpose-limited age-verification technology paired with mandatory data deletion once the check completes, not indefinite retention. That is the right template: verification scoped to the specific service and the specific age question, with hard deletion requirements and no exemption for VPN suppression dressed up as child safety. Congress should decouple the AI-specific transparency rules in the Youth AI Privacy Act and CHATBOT Act — which target a narrower, more defensible harm in chatbots collecting and monetizing minors' data — from the SCREEN Act's platform-wide identity mandate and KOSA's duty-of-care liability, which invite exactly the overreach EFF is warning about. A markup that treats five bills as one undifferentiated "kids safety" vote will produce the broadest version of each, not the most proportionate one.