Senate Commerce Sends KOSA to the Full Chamber

The U.S. Senate Committee on Commerce, Science and Transportation has voted to advance the Kids Online Safety Act, or KOSA, along with a package of children's AI safety bills, to the full Senate for consideration. The committee vote marks another step forward for legislation that has been debated, revised, and reintroduced across multiple congressional sessions, and it puts KOSA closer to a floor vote than it has been in years.

At its core, KOSA would impose a "duty of care" on social media platforms and other online services likely to be used by minors, requiring them to take reasonable steps to prevent and mitigate certain harms, including exposure to content related to self-harm, eating disorders, and addictive design features. The bill also gives parents new tools to monitor and restrict their children's account settings and requires platforms to default young users into their strongest privacy and safety settings.

This committee action follows closely on the heels of an earlier markup where KOSA's duty of care clause cleared committee unanimously alongside a stalled companion bill, signaling that lawmakers across the aisle see enough consensus to keep pushing the legislation forward, even as questions about implementation remain unresolved.

Duty of Care and Age Verification: The Data Collection Question

The central tension in KOSA has never really been about its goals. Few lawmakers, advocacy groups, or parents dispute that children deserve protection from harmful online content and manipulative design. The disagreement is about mechanics: how do platforms actually know which users are minors without collecting more personal data than they currently do?

To comply with a duty-of-care standard, platforms may feel pressure to verify user ages more aggressively, whether through government ID uploads, biometric estimation, or third-party verification services. Each of these approaches requires collecting and storing sensitive information, information that becomes a target the moment it sits on a company's servers. Critics have long argued that age-verification mandates, even when framed as child-safety measures, tend to expand data collection footprints for everyone, not just the minors the law is meant to protect.

This is the same dynamic that played out in the related SCREEN Act discussion, where Senate markup on age-verification requirements drew warnings from privacy advocates about the broader implications for anonymous internet access. KOSA doesn't mandate a specific verification method outright, but the compliance pressure it creates could push platforms toward similar tools, particularly if regulators interpret the duty-of-care standard as requiring more certainty about user age.

Why Privacy Advocates Remain Wary

Privacy organizations have raised two recurring concerns as KOSA has moved through committee. The first is scope creep: a duty-of-care standard tied to vague categories of harmful content could give the Federal Trade Commission, or state attorneys general, significant discretion over what platforms must filter or restrict. Advocates worry this could be applied unevenly, potentially chilling legitimate speech or access to information that some officials find objectionable, even when it poses no real risk to minors.

The second concern is technical. Some digital rights groups have warned that stricter monitoring and content-scanning obligations could create pressure on platforms to weaken end-to-end encryption or build in scanning capabilities that undermine security for all users, not just the accounts of minors. Encryption experts have consistently argued that there's no way to build a backdoor or scanning mechanism that only bad actors can't exploit, which is why any bill touching on content moderation for minors draws close scrutiny over its encryption implications.

Supporters of KOSA counter that the bill has been narrowed through negotiation specifically to avoid mandating age verification or encryption-breaking measures, and that the duty-of-care standard is meant to target design choices, like infinite scroll or algorithmic amplification of harmful content, rather than the content itself. Whether that distinction holds up once the FTC begins enforcement is likely to be one of the defining questions if KOSA becomes law.

What This Means For You

If you're a parent, this committee vote doesn't change anything about your child's online experience today. KOSA still needs to pass the full Senate, reconcile with any House version, and get signed into law before platforms are required to change how they operate. If you're a privacy-conscious internet user of any age, the bigger signal here is that Congress remains focused on legislation that could reshape how platforms verify identity and manage user data across the board, not just for minors.

The practical takeaway is to watch how the bill's language evolves before it reaches a floor vote. Amendments at this stage often determine whether a bill's privacy tradeoffs are modest or substantial.

What To Watch Next

As KOSA and its companion AI safety bills head toward full Senate consideration, the details worth tracking include whether age-verification language gets added or narrowed, how the FTC's enforcement authority is defined, and whether encryption protections remain explicitly carved out. For readers who want the fuller legislative context, our earlier coverage of KOSA's duty-of-care provision clearing committee and the SCREEN Act's age-verification privacy risks lays out how these fights have unfolded so far.

The overall KOSA online privacy impact will ultimately depend on implementation details that haven't been finalized yet. Staying informed as the bill moves through the Senate, rather than reacting to headlines alone, remains the best way to understand what's actually changing and when it might affect you.