Insight

Protecting Kids Online: Government Mandates vs. Market Solutions

Executive Summary

  • As kids’ online safety remains a priority for policymakers and parents alike, lawmakers have introduced a number of legislative proposals that would change standards for how much digital platforms need to know about the age of users.
  • Changing these “knowledge standards” to presume platforms know more about user age would likely lead platforms to engage in identity verification of their users to minimize liability, creating new privacy risks for both minor and adult users as an unintended consequence; they would also redirect industry efforts already underway to increase kids’ safety features on platforms.
  • As the House and Senate consider different legislative packages that would effectively require age verification for various platforms, policymakers should consider the tradeoffs for privacy, speech, and innovation that heightened knowledge presumptions and age verification mandates would create for users and platforms.

Introduction

As kids’ online safety remains a priority for policymakers and parents alike, lawmakers have introduced a number of legislative proposals that would change standards for how much digital platforms need to know about the age of users.

Changing these “knowledge standards” to presume platforms know more about user age would likely lead platforms to engage in identity verification of their users to minimize liability. Because identity verification necessarily involves using facial or other biometric scans or providing government-issued identification (ID), it would create harms for both minor and adult users by increasing the risk of data leaks, identity theft, and chilling effects on speech. Moreover, they would redirect industry efforts already underway to increase kids’ safety features on platforms.

While the House and Senate are considering different legislative packages that would effectively require age verification for various platforms, policymakers should consider the tradeoffs for privacy, speech, and innovation that heightened knowledge presumptions and age verification mandates would create for users and platforms.

Background

In late 2021, The Wall Street Journal published the “Facebook Files,” a series of stories based on leaks from whistleblower Francis Haugen. Among the many revelations from the files were internal documents suggesting Facebook was aware of potential negative health effects from Instagram for teen girls.

In the wake of this and other emerging (now disputed) evidence that social media could be driving negative mental health effects for teens more broadly, policymakers in the United States and around the world began considering legislation to limit access to, or tailor content on, social media for minors. Many of these proposed or enacted laws do not explicitly require age verification but, as previous American Action Forum (AAF) research has discussed, set knowledge standards for violating the law in such a way that age verification is the only reliable way for them to avoid liability.

The Knowledge (Standard) Problem

Whether or not platforms would consider themselves effectively required to verify every user’s age is driven significantly by legal standards for how much a platform must know about a user’s age. “Actual knowledge” standards, such as the one used in the Children’s Online Privacy Protection Act (COPPA) of 1998, only trigger obligations to comply with requirements to limit access to, or tailor content for, users when they become aware that a user is a minor. “Constructive knowledge” standards, which appear in many recent proposed kids’ online safety bills including the Kids Online Safety Act (KOSA), COPPA 2.0, and Kids Internet and Digital Safety (KIDS) Act, trigger obligations to comply with requirements when a platform “should have known” or had “knowledge fairly implied on the basis of objective circumstances” that a user is a minor. In other words, under a constructive knowledge standard, a platform may be said to legally know a user is a minor if it has access to information that indicates a user might be a minor. Because people develop behaviorally and physically at different rates, many users may appear to be minors when they are not and vice versa, creating a high degree of uncertainty for platforms. Any rational platform seeking to avoid liability may find it necessary to confirm users’ ages before serving them. Some bills, such as the App Store Accountability Act (ASAA), explicitly require age verification.

As previous AAF research has detailed, the most reliable way to confirm a user’s age is to use facial or other biometric scans, require users to provide government-issued identification (ID), or both. Either option would necessitate users, whether adults or minors, turnover personally identifiable information (PII) to a platform or third-party age assurance service provider to fully access its features. While other age assurance mechanisms exist—including self-declaration and age estimation technologies—these alternatives would likely not provide platforms protection from liability under heightened knowledge presumptions either because they would be insufficient or because their error rates would be too high to be reliable. Even if a platform were to use age estimation as a primary method, these error rates likely mean that platforms would default to age verification using PII as a backup method under heightened knowledge presumptions.

Beyond consideration of what knowledge standards platforms must use and whether they require age verification, legislative proposals vary on which platforms would bear the burden of confirming (and possibly sharing) users’ age. For example, KIDS and KOSA place their knowledge requirements directly on a mix of social media, video game, and chatbot platforms—meaning that users must submit PII to each covered platform they use. ASAA, on the other hand, places the obligation on app stores over a certain size to verify the age of all their customers and then share an age-range signal with all app developers (even those with no social component on their platform, such as news, educational, or health apps). Notably, ASAA would effectively require app developers to accept this signal—even if they did not want to out of concern for minimizing data collection about their users—or risk losing their liability safe harbor.

The Drawbacks of Age Verification

In theory, age verification can provide platforms more certainty on the age of their users than self-declaration or other methods, but only if users choose to fully comply with the regime. In the context of social media age-checks in other countries, users have discovered and shared a variety of methods for evading identity checks (or other social media restrictions) but still using the underlying platform, including using someone else’s ID, creating fake accounts, switching devices, tricking biometric scan systems with disguises, and using systems such as virtual private networks to mask their location.

Age verification has its own harms for users as well. If users do comply, age verification would require sharing PII with platforms, creating additional privacy harms for users at a time when Congress is looking to expand federal data privacy protections including data minimization. Unlike having an ID checked in a grocery store when buying alcohol or tobacco, the platform would have to create a digital record of a user’s ID or biometric scan, even if only temporarily, that could be a prime target for identity thieves and fraudsters. Multiple platforms and third-party vendors engaged in identity verification for online platforms have already experienced data breaches that have put their customers’ PII at risk, in one case leading to a mass public leak of users’ home addresses. Identity theft has grown in recent years, thanks in part due to data breaches, costing 18 million Americans $27 billion in 2024, and age verification could create new opportunities for identity thieves to steal more PII.

No system will be perfect, and some regulated online activities may be so harmful for minors that age verification would be worth the above drawbacks. But policymakers must weigh any harms they wish to address with age verification against the competing harms that would be caused by age verification, alongside other factors such as the constitutional protections that exist for non-adult content on digital platforms and the benefits of social media use.

Market Solutions for Kids’ Online Safety

The current legislative proposals for regulating kids’ online safety are also running into the “Pacing Problem,” or the tendency of technology regulation to fail to keep pace with technological innovation. In part due to public pressure from both policymakers and parents, many platforms have been adding and improving their teen safety and parental control offerings. For example, major social media and app store platforms have introduced new account types for kids and teens with expanded safety features, supervision tools for parents, and more precise age rating systems for apps. Social media platforms are also submitting to rating by independent organizations on the substance and ease of use of their new safety and parental controls, much like the film, music, and video game industries pursued and implemented independent rating systems for their content.

By offering these features and participating in independent ratings systems, they are not only responding to market demand but also subjecting themselves to existing federal and state laws addressing “unfair and deceptive” acts and practices. The Federal Trade Commission (FTC) or state attorneys general could use these voluntary commitments to investigate and report on whether companies’ claims about their safety features are accurate, as the FTC has with participants of the video game industry’s voluntary Entertainment Software Rating Board. These reports provide useful information to parents who want to understand companies’ compliance with voluntary standards, and would supplement efforts the FTC is undertaking to educate parents on best practices for using parental controls.

In pursuing heightened knowledge standards and age verification mandates, policymakers run the risk of draining resources away from larger platforms’ efforts to create these new features. Furthermore, age verifications systems are costly to acquire and run, and while many larger platforms would be able to bear this cost, many smaller competitors likely would not.

Legislative Outlook

Last week, the House passed a compromise version of the KIDS Act, which includes both a heightened knowledge presumption that would effectively mandate age verification and a requirement that platforms develop their own policies for tailoring certain content the bill deems harmful to minors. Key senators, who are currently negotiating with the White House over a broader AI regulation framework that could include KOSA, criticized the House’s content tailoring requirement as too weak. Meanwhile, House leadership remains concerned that the Senate’s proposed standard for how content must be tailored for minor users would lead to removal of too much lawful, unharmful content. Furthermore, the Senate passed an update to COPPA earlier this year that changes the knowledge standard in that law from “actual knowledge” to a constructive knowledge standard.

While the House and Senate continue to debate various kids’ online safety proposals, policymakers should consider the tradeoffs for privacy, speech, and innovation that heightened knowledge presumptions and age verification mandates would create for users and platforms.

Disclaimer