Washington periodically produces new bills promising to make the Internet safer for kids. The instinct behind them is easy to sympathize with—parents are anxious, headlines about AI chatbots and teenagers are unsettling, and lawmakers want action.
But two Senate bills moving this week through Congress—the CHATBOT Act (S.4407) and the Youth AI Privacy Act (S.4199)—are good intentions morphing into bad policy. Taken together, they would make young people’s experience of AI less private, less useful, and—paradoxically—less safe.
The primary responsibility for shepherding a child’s use of technology belongs with parents. American law already worked through another version of this liability question, and it’s landing on parents. After the Oxford High School shooting, a Michigan jury convicted the shooter’s parents, James and Jennifer Crumbley, of involuntary manslaughter. Similar legal outcomes happened in the tragic 2024 shooting at Apalachee High School in Georgia and the 2023 shooting in Newport News, Va.
Gunmakers faced no comparable liability; federal law has long shielded firearm manufacturers from liability for how their lawfully sold products are later misused. This leaves the duty to intervene where courts consistently place it: with the people who raise children and know them best.
That same logic ought to guide how Congress treats AI chatbots and kids. Yet that’s what both pending bills get backwards.
The Youth AI Privacy Act: Safety Rules That Undermine Safety
The Youth AI Privacy Act mandates “safe design” features for any chatbot minors might use—but it reveals a similar pattern of overreach. Start with the blanket ban on using youth conversational data for model training, even when that data is anonymized using state-of-the-art privacy techniques.
Ironically, to build models recognizing a teenager describing a mental health crisis or a grooming attempt, developers need data. Banned from appropriate training data, models become worse, not better, at catching the exact harms this bill aims to prevent.
The bill also requires persistent, repeated pop-ups reminding users they’re talking to a computer. A single clear disclosure up front makes sense. Repeatedly forcing this interruption simply breaks the experience for a generation of teenagers who already know they’re using software—it’s friction dressed up as safety.
Finally, the bill pairs FTC enforcement with a private right of action, opening the door to sweeping litigation risk. Facing that exposure, the rational move for many companies won’t be to build careful, youth-friendly products—it’ll be to block minors from their platforms entirely. This will cut teenagers off from tools helping with homework, research, and creative writing. Combined with a near-total restriction on session data retention (e.g., how long user information is temporarily kept before it is deleted), the bill also strips away the continuity that makes adaptive, personalized learning tools work.
The CHATBOT Act: ‘Solving’ Privacy by Undermining It
The CHATBOT Act intends to give parents visibility into whether their kids are talking to AI chatbots, and the ability to review those conversations. On its face, that sounds like useful parental oversight.
But to work, the bill requires platforms to enforce a verifiable way to determine—for every single user—whether they are a minor. In practice, that means collecting driver’s licenses, credit card numbers, or biometric scans from an enormous swath of the adult population—just so a smaller group of minors can be identified.
This forces a mass identity-verification regime onto the entire internet. Every data minimization principle privacy advocates have spent two decades fighting for gets thrown out the window, replaced by centralized repositories of sensitive personal documents sitting on corporate servers, waiting for the next breach.
There’s also a constitutional problem: Forcing companies to verify identity before granting access to information runs headlong into the First Amendment right to read, write, and speak anonymously. A bill meant to protect kids ends up chilling speech for everyone—adult and minor alike—by making anonymous access to AI tools functionally impossible.
There’s a better path. Instead of mandating identity checks for the entire population, Congress could encourage companies to build optional, flexible parental tools—the kind that allows parents in one family to set stricter limits than another—without requiring every adult in the country to prove their identity. Real family autonomy means giving parents options, not making surveillance infrastructure a condition of using a chatbot.
Two Bills, One Lesson
Both bills start from legitimate worries and arrive at counterproductive answers. The Youth AI Privacy Act trades functional, improving safety systems for compliance theater. The CHATBOT Act trades privacy for the appearance of parental control.
If Congress wants AI to be genuinely safer for young people, it should look past mandates that sound protective and ask whether they’ll actually make the technology safer—or just more surveilled and less accessible to the very people it’s meant to help.
