Senate Committee Unanimously Advances KOSA and CHATBOT Act to Mandate Controls for AI Chatbots Used by Minors
The U.S. Senate Commerce Committee has advanced a sweeping legislative package that would require AI companies to build mandatory parental monitoring dashboards and limit memory retention for underage users. The bills face pushback from digital rights groups warning of universal age verification and severe privacy trade-offs.
By Ishani Patel
- Child Safety Advocates
- Argues that parents need structural tools to protect children from manipulative AI design and parasocial dependency.
- Digital Rights Groups
- Warns that the mandates will force universal age verification and create invasive surveillance records of teenagers' private conversations.
- Tech Industry Analysts
- Highlights the technical impossibility of deterministic compliance for probabilistic models and the burden of fragmented state laws.
Key points
- The Senate Commerce Committee unanimously advanced the CHATBOT Act and Youth AI Privacy Act to regulate minors' AI usage.
- The legislation mandates 'family accounts' for users under 13, giving parents a full record of chatbot conversations.
- A strict 30-day memory retention limit for minors' data was amended to allow parents to opt out of automatic deletion.
- Digital rights groups warn the bills will force universal age verification and compromise teenagers' privacy.
- The removal of a federal preemption clause means AI companies will face a patchwork of varying state-level regulations.
- 91-3
- Senate vote for KOSA in prior Congress
- 30 days
- Default AI memory retention limit for minors
- 13 years
- Age threshold for mandatory family accounts
The prevailing assumption about regulating artificial intelligence for minors is that lawmakers can simply extend existing social media restrictions to cover generative models. The technical reality is far more complex. Unlike static content feeds, AI chatbots generate dynamic responses, build parasocial memory, and adapt to user psychology in real time. Acknowledging this architectural difference, the U.S. Senate Commerce Committee unanimously advanced a sweeping legislative package on August 5, 2026, targeting the specific mechanisms of generative AI. The slate includes the CHATBOT Act and the Youth AI Privacy Act, advancing alongside a revived Kids Online Safety Act (KOSA). Rather than merely filtering content, the legislation attempts to mandate how AI models retain memory, interact with users, and verify age, fundamentally altering the infrastructure of consumer AI products.[1][2]
At the center of the regulatory effort is the CHATBOT Act, which dictates exactly how AI providers must structure access for minors. The bill requires companies to establish "family accounts" for users under 13 and mandates verifiable parental consent for teenagers. This is not a simple toggle switch; it forces developers to build comprehensive monitoring dashboards. Parents would gain access to a full record of their child's conversations and the ability to disable push notifications, reward incentives, and set strict time limits. By legally requiring these features, the legislation shifts the burden of AI safety from post-generation moderation to structural, default-on surveillance mechanisms designed to break the loop of prolonged engagement.[1][4]
The legislative push is driven by anecdotal reports and early behavioral observations of minors forming deep emotional dependencies on AI companions. However, the clinical evidence regarding the long-term psychological toll of anthropomorphic AI remains notably thin. Lawmakers have cited instances of chatbots facilitating suicidal ideation or isolating teenagers from human relationships, but comprehensive longitudinal data does not yet exist. Acknowledging this gap in the evidence pack, the committee also advanced the Children's Artificial Intelligence Toy Safety Act, which directs the National Academies of Sciences, Engineering, and Medicine to conduct a rigorous study on the emotional and educational outcomes of AI-embedded toys. Until that data matures, the regulatory framework is operating on the precautionary principle.[2][4]
The technical friction of these mandates is most evident in the debate over memory retention. The Youth AI Privacy Act originally proposed a strict 30-day limit on how long a chatbot could remember interactions with a minor, aiming to prevent systems from endlessly drawing on a child's personal data to shape highly personalized, addictive responses. However, during the markup session, an amendment successfully altered this provision to allow parents to opt out of automatic deletion. This compromise highlights a core tension in AI product design: the very memory features that make a chatbot useful and context-aware are the same mechanisms that privacy advocates warn could be used to profile and manipulate adolescent users.[2][4]
The technical friction of these mandates is most evident in the debate over memory retention.
Looming over the specific AI bills is the broader umbrella of KOSA, which imposes a "duty of care" on covered platforms to actively mitigate foreseeable harms to minors. While KOSA previously passed the Senate 91-3 in the prior Congress, applying a duty of care to generative AI introduces unprecedented engineering challenges. Social media companies can theoretically tune recommendation algorithms to demote harmful content, but guaranteeing that a generative model will never produce a harmful output dynamically is a mathematically unsolved problem. The legislation demands that companies prioritize child safety over engagement, but the exact technical threshold for "reasonable care" in a probabilistic text generator remains undefined in the statutory language.[1][2]
Digital rights organizations argue that the evidence supporting these mandates ignores the severe privacy trade-offs required to enforce them. The Electronic Frontier Foundation warns that because the CHATBOT Act's obligations depend on knowing a user's age, the bill effectively pressures all AI platforms to implement universal age verification systems. Furthermore, privacy advocates argue that mandating a centralized, permanent record of teenagers' private conversations with AI creates a massive new vulnerability. Adolescents frequently use chatbots to ask sensitive questions about mental health, physical development, and identity—topics they may feel unsafe discussing with parents. Creating a federally prescribed surveillance architecture for these interactions could chill lawful speech and expose highly sensitive data to breaches.[3][5]
The structural limits of the legislation were further complicated by a critical amendment that stripped the CHATBOT Act of its preemption clause. Originally, the bill would have overridden state-level AI regulations, but that language was removed at the request of committee Democrats. Industry analysts warn this omission will create a deeply fragmented compliance landscape. More than ten states have already enacted their own AI chatbot laws, meaning developers will soon face a patchwork of contradictory regulations where a model must behave differently in California than it does in Texas. For frontier AI companies, building a single product that dynamically complies with dozens of varying state-level memory and consent mandates may prove technically unfeasible.[4]
The path forward for the legislative package relies on a complex reconciliation process. The House of Representatives has already passed its own version of a children's safety package, but significant partisan divides remain over KOSA's "duty of care" standard, which critics argue could be weaponized by state attorneys general to censor politically contentious speech. Whether the Senate is willing to negotiate the duty of care language will likely determine if the package reaches the President's desk. As the technology outpaces the legislative process, the debate underscores the difficulty of regulating a probabilistic system: lawmakers are attempting to write deterministic rules for machines that are inherently unpredictable.[5]
How we got here
March 2026
The Youth AI Privacy Act is introduced to establish federal privacy protections for minors using AI.
April 2026
A bipartisan coalition introduces the CHATBOT Act to mandate parental controls and family accounts.
June 2026
The House passes its own children's safety package, setting up a clash over the 'duty of care' standard.
August 5, 2026
The Senate Commerce Committee unanimously advances the AI and online safety legislative package.
What we don’t know
- How AI companies will technically implement verifiable parental consent without forcing universal age verification.
- The exact psychological and developmental impacts of long-term parasocial relationships between minors and AI chatbots.
- Whether the House and Senate can reconcile the controversial 'duty of care' standard before the end of the legislative session.
Sources
[1]U.S. SenateChild Safety AdvocatesCruz, Schatz, Curtis, Schiff Introduce Bipartisan CHATBOT Act
Read on U.S. Senate →
[2]IAPPDigital Rights GroupsSenate Committee advances KOSA, AI chatbots bills
Read on IAPP →
[3]Electronic Frontier FoundationDigital Rights GroupsThe CHATBOT Act Will Pressure AI Companies To Check Users' Ages
Read on Electronic Frontier Foundation →
[4]VitalLawChild Safety AdvocatesSenate Commerce Committee advances KOSA, AI chatbot bills
Read on VitalLaw →
[5]Information Technology and Innovation FoundationTech Industry AnalystsDon't Regulate Time Limits: Analyzing the CHATBOT Act
Read on Information Technology and Innovation Foundation →
Comments
Every angle. Every day.
Get ai stories with full source coverage and perspective breakdowns delivered to your inbox.