A new commentary on TechPolicy.Press asks whether the Kids Online Safety Act (KOSA) is the "social reckoning" many people have been waiting for. Author Karolina Mackiewicz argues that a true reckoning means prioritizing safety over engagement, without sacrificing privacy, agency, or free expression. For readers who care about encryption and anonymity, the debate over Kids Online Safety Act privacy comes down to one question: can lawmakers protect children without building tools that weaken everyone's online protections?

This post draws only on the commentary's summary and framing, plus publicly listed descriptions of the bill. The full text of the commentary was not available to us, so we focus on the central argument and the questions it raises.

What the Kids Online Safety Act would require

Public descriptions of KOSA say the bill aims to establish guidelines to protect minors from harmful material on social media platforms through a "duty of care" system. Supporters also point to provisions that would require platforms to enable the strongest privacy settings for kids by default and give parents new controls. Another listed requirement would let users see unmanipulated content on internet platforms.

The core idea behind Mackiewicz's framing is a shift in priorities. Rather than designing products to maximize time spent and engagement, platforms would be pushed to put the safety of young users first. That is a design question, not only a content question, and it is where much of the policy conversation is heading.

Where child safety and surveillance collide

The tension is easy to state and hard to resolve. Protecting children often seems to call for more information about users: who they are, how old they are, what they see, and who they talk to. Collecting and analyzing that information creates new privacy risks for minors and adults alike.

Mackiewicz's point, as summarized, is that safety should not come at the expense of privacy, agency, or free expression. Those four values are often treated as trade-offs, but the commentary suggests a credible reckoning must hold all of them at once. Rules that reduce harmful design patterns, such as engagement-maximizing feeds, may protect kids without requiring more surveillance. Rules that depend on identifying and monitoring users may not.

Age verification, encryption, and anonymity risks

The most sensitive area for privacy-minded readers is age verification. Related legislation has drawn scrutiny on this front: the Electronic Frontier Foundation has argued that provisions in the separate KIDS Act would push online services to verify all users' ages and require government-directed moderation. We note that as one organization's position, not a settled fact about KOSA itself.

The general concern is straightforward:

  • Age checks can end anonymity. If accessing a service requires proving age, users may have to hand over identity documents or biometric data.
  • Stored data becomes a target. Any database of verification records is a potential breach risk.
  • Content scanning can conflict with encryption. Mandates to detect harmful material can pressure services to inspect messages, which end-to-end encryption is designed to prevent.
  • Circumvention pressure follows. When access rules tighten, attention often turns to the tools people use to protect their privacy, including VPNs.

That last point has a recent real-world example. The UK government dropped a plan to restrict VPN use as part of its child online safety push after its own research undercut the reasoning behind it. You can read the details in our report on how the UK scrapped its VPN restrictions plan after its own research. It shows that evidence can change the direction of a child-safety policy.

What a privacy-respecting approach to kids' safety looks like

The commentary's framing points toward approaches that address harm at the source: product design. Several ideas fit that logic without requiring universal identity checks:

  • Safer default settings for minors, including strong privacy settings out of the box.
  • Limits on engagement-driven features that keep young users scrolling.
  • Transparent controls for parents that do not require platforms to read private messages.
  • Clear options for users to see content that has not been algorithmically manipulated.

These measures target how platforms are built rather than who is using them. Whether the final law reflects that balance depends on how its duties are written and enforced.

What This Means For You

If you are a parent, KOSA-style rules may bring stronger default protections and new controls over how your child uses platforms. Check what settings already exist and understand what data any new tool collects.

If you value anonymity or use encrypted services, watch for language on age verification, scanning, and moderation mandates. These provisions determine whether Kids Online Safety Act privacy protections are real or only nominal.

If you use a VPN, remember that lawmakers elsewhere have considered restricting them in the name of child safety. The UK example shows these proposals can be reversed, but it is a reason to stay informed.

Takeaways

  • Read how any child-safety bill defines age verification before judging it.
  • Treat requests for ID or biometric data with caution and ask how it is stored and deleted.
  • Favor platforms and policies that improve safety through design, not blanket surveillance.
  • Follow how KOSA and similar laws evolve, and weigh the privacy trade-offs in each version.

The debate over Kids Online Safety Act privacy is far from over. For a concrete look at how evidence can reshape these policies, revisit our coverage of the UK's decision on VPN restrictions, and keep watching how lawmakers balance protection with the rights of every user.