Senator Marsha Blackburn published an op-ed this week making the case that the Kids Online Safety Act (KOSA) succeeds where Australia's social media ban failed. Her argument is straightforward: instead of locking young people out of platforms entirely, KOSA would force tech companies to build safer products from the ground up. It's a compelling pitch on the surface. But the details of how platforms would actually deliver on that promise deserve more scrutiny than a op-ed headline allows, especially for anyone who cares about how much data gets collected, stored, and shared in the name of protecting kids.

The Op-Ed That Reignited the Debate

Blackburn's piece frames Australia's approach as a blunt instrument: ban young users from social media outright and call it a day. Her counter-argument is that KOSA offers a more nuanced path, one that keeps platforms accessible while imposing a legal duty on companies to design their products with young users' wellbeing in mind. That framing has helped KOSA build broad, bipartisan support over the past several legislative sessions.

But "duty of care" language, however well-intentioned, tends to translate into very concrete engineering requirements once it reaches the platforms that have to comply. Somebody has to determine who is a minor, somebody has to build systems that flag or restrict certain content for those users, and somebody has to document and report on whether those systems are working. Each of those steps requires data. And that's where the privacy conversation actually starts, well past the point where most op-eds stop.

What Age Verification and Monitoring Actually Require

Any law that asks platforms to treat minors differently from adults first needs a reliable way to know who is a minor. That's a harder technical problem than it sounds, and it's already playing out in real regulatory disputes. In the UK, Ofcom is investigating TikTok's biometric age-inference tool over concerns that the system doesn't reliably meet the standards required under that country's Online Safety Act. That case is instructive: even a well-funded platform building purpose-made age-estimation technology is drawing regulatory scrutiny over accuracy and privacy.

KOSA doesn't operate in a vacuum from that broader trend. Any US framework that expects platforms to identify minors and tailor their experience accordingly will eventually run into the same fork in the road that UK regulators are wrestling with now: either collect more identifying information (IDs, biometric scans, device fingerprints) to verify age with confidence, or rely on inference tools that are prone to error and easy to circumvent. Neither option is privacy-neutral, and neither is free of unintended consequences for adults who get swept into the same verification systems.

The Encryption and Monitoring Problem

The part of this debate that gets the least attention in political op-eds is what "duty of care" design requirements mean for encrypted and private communication. If a platform is legally obligated to detect and mitigate harmful content reaching minors, it faces enormous pressure to monitor content more closely, which sits in direct tension with end-to-end encryption. Encrypted messaging works precisely because the platform itself cannot see the content passing through it. A legal mandate to identify and act on harmful material pushes companies toward scanning content before or after encryption, weakening the privacy guarantee that encryption exists to provide in the first place.

This is the same tension that shows up whenever governments propose content moderation mandates, data retention rules, or restrictions aimed at anonymizing tools like VPNs. The stated goal is almost always safety. But the technical reality is that safety mandates and privacy protections often pull in opposite directions, and the compromise usually lands on the side of more monitoring, not less. Consumers who rely on encrypted messaging, private browsing, or VPN services to protect sensitive communications should pay close attention to how any "kids safety" bill defines platform obligations, because those obligations rarely stay narrowly scoped to minors in practice.

What This Means For You

If you're a parent, KOSA's supporters are right that today's platforms often fall short on safety by design, and legislative pressure can push companies to build better default protections for younger users. That's a legitimate goal worth supporting in principle. But if you're a privacy-conscious adult, or simply someone who values encrypted communication, it's worth reading past the headline framing. Age verification systems and content monitoring requirements built for minors have a track record of expanding scope, generating new data collection points, and creating friction for adult users who get caught in the same net.

The honest answer is that KOSA isn't simply a safety upgrade with no trade-offs, the same way Australia's ban wasn't simply a safety failure with no upside. Both approaches carry real costs. The Kids Online Safety Act debate deserves an honest accounting of those costs, not a framing that only compares it favorably to the one alternative it happens to look better next to.

Key Takeaways

  • Read KOSA's actual text and any amendments rather than relying on op-ed summaries from either side.
  • Pay attention to how age verification is implemented in any platform you or your family uses, and whether it depends on identity documents or biometric inference.
  • Understand that content monitoring mandates aimed at protecting minors can weaken encryption guarantees for everyone on a platform.
  • Watch how regulators handle age-verification disputes elsewhere, since those outcomes often shape how US platforms respond to similar legal pressure.
  • Support privacy-preserving safety measures, like on-device parental controls, over centralized data collection whenever platforms offer a choice.