A bill pitched as a child-safety measure is drawing sharp warnings from privacy advocates who say it would do something far more sweeping: build a permanent surveillance infrastructure for the entire internet. In a recent opinion piece, Electronic Frontier Foundation policy analyst India McKinney argues that the KIDS Act is "way worse than digital carding," and that lawmakers even considering it should serve as a wake-up call for anyone who values privacy and free expression online.
The core problem, according to McKinney, isn't that the bill targets bad actors or harmful content. It's that the mechanisms required to enforce it, universal age checks, government-directed content moderation, and platform-level monitoring, don't disappear once implemented. They become permanent fixtures of how Americans access the internet, regardless of age.
What the KIDS Act Would Actually Require
At its core, the KIDS Act would push online platforms toward verifying the age of every user, not just those suspected of being minors. That means adults would also need to prove who they are, often through government ID, facial scans, or third-party verification services, just to access ordinary websites and apps. The bill also includes provisions for government-directed moderation, effectively giving regulators influence over what content platforms allow, even for adult users.
This is a meaningfully different approach than a simple age gate on a specific product. Instead of a targeted checkpoint, it's a structural requirement baked into how online services operate. Once platforms build the systems to collect and verify identity data at scale, that infrastructure exists indefinitely. It can be repurposed, expanded, or subpoenaed long after the original child-safety justification fades from public conversation.
How Age Verification Becomes a Surveillance System
The leap from "verify age" to "mass surveillance" isn't hypothetical. Age verification systems require platforms to collect sensitive identity data, government ID numbers, biometric scans, or behavioral data used to estimate age, and store or transmit that data somewhere. Every additional data point collected is another asset that can be breached, subpoenaed, or misused.
This concern isn't unique to the KIDS Act. A research paper from the Center for Growth and Opportunity, which warns that age verification risks privacy, lays out evidence that age-verification systems consistently create privacy exposure even when designed with good intentions. The paper's findings echo what McKinney argues: once you require identity checks to access the internet, you've built a surveillance apparatus whether or not that was the stated goal.
The scale matters too. A narrow, product-specific age gate affects a small slice of the internet. A federal mandate that applies broadly to "covered platforms" affects nearly everyone who goes online, adults included. That's the distinction McKinney is drawing when she says this goes beyond digital carding: it's not a checkpoint, it's an entry requirement for the internet itself.
The Connection to Chat Control and Encryption Backdoors
The KIDS Act doesn't exist in isolation. It's part of a broader pattern playing out across multiple jurisdictions where child-safety legislation becomes the vehicle for expanded government access to online activity. The European Union's Chat Control proposal and the UK's Online Safety Act follow a similar template: mandate scanning or verification in the name of protecting children, and in the process, build tools that weaken encryption and expand monitoring capability for everyone.
As covered in our breakdown of Chat Control, the Online Safety Act, and the KIDS Act, these three efforts share a common thread: encryption itself becomes a target. Content-scanning requirements often can't function alongside true end-to-end encryption, which means platforms face pressure to either weaken their security models or build backdoors that undermine privacy protections for all users, not just minors.
The UK's own experience is instructive here. Regulators there ultimately rejected VPN restrictions under the Online Safety Act after recognizing the practical and political difficulty of banning privacy tools outright. That decision came alongside research showing that children primarily use VPNs for privacy reasons, not to bypass age checks, undercutting one of the central justifications regulators had used to consider restricting VPN access in the first place.
What This Means For You
If the KIDS Act or similar legislation advances, expect verification requirements to touch far more than adult content sites. Social media, forums, and general-purpose platforms could all be required to confirm your identity before granting access. For everyday users, that means handing over sensitive personal data just to use services you already use today.
This is likely to accelerate interest in VPNs, encrypted messaging apps, and other privacy tools as people look for ways to reduce their exposure to identity collection systems. That's a rational response, but it's also a sign of how policy in this space tends to create exactly the kind of workaround behavior that regulators claim to be trying to prevent. The UK's experience already suggests that heavy-handed verification mandates push users toward privacy tools rather than away from them.
Key Takeaways
The KIDS Act debate is a reminder that child-safety framing doesn't automatically mean child-safety outcomes. Before this or similar legislation moves further, it's worth understanding what's actually being built: a verification infrastructure with implications well beyond its stated purpose.
For readers wanting the fuller regulatory picture, our explainer on Chat Control, the Online Safety Act, and the KIDS Act walks through how these three efforts intersect on encryption. And for anyone wanting the evidence-based case against mandatory age verification, the CGO research paper on age verification privacy risks is a useful resource for understanding what's actually at stake before these systems become permanent.




