The House Energy and Commerce Committee just moved forward with a package of online child safety bills, signaling that Congress is serious about pushing age verification and content restriction mandates onto tech platforms. The committee’s post on X confirmed the markup session advanced multiple measures targeting how minors interact with online services. This isn’t a drill anymore. The legislation is picking up real momentum.
At the center of this push is the Kids Online Safety Act, better known as KOSA, along with companion bills that would impose new duties of care on platforms serving users under a certain age. The basic premise sounds uncontroversial: protect children from harmful content online. But the implementation details are where things get thorny — and where privacy advocates, developers, and civil liberties organizations have been raising alarms for months.
The core problem hasn’t changed since the Senate passed its version of KOSA last year. To enforce age-based restrictions, platforms need to know how old their users are. And that means some form of age verification. As WebProNews previously reported, the privacy implications are enormous. Age verification systems typically require government-issued ID uploads, biometric facial analysis, or third-party identity checks — all of which create new data collection pipelines that didn’t exist before. You don’t make the internet safer for kids by building a massive identity surveillance apparatus that applies to every user, including adults.
That’s the tension Congress hasn’t resolved.
The Energy and Commerce Committee’s latest action builds on bipartisan enthusiasm for child safety measures, but the specific legislative text matters enormously. Previous iterations of KOSA gave the FTC and state attorneys general broad authority to determine what constitutes content harmful to minors, which critics argued could be weaponized to suppress constitutionally protected speech. LGBTQ+ advocacy groups, digital rights organizations like the Electronic Frontier Foundation, and First Amendment scholars have all warned that vague definitions of “harmful content” hand regulators a tool to censor based on political preferences rather than genuine child safety concerns.
And the compliance burden is real. Small and mid-size developers face the same obligations as trillion-dollar platforms under most versions of these bills. There’s no carve-out that meaningfully accounts for scale. A three-person startup building a social app faces the same duty-of-care framework as Meta. That’s not theoretical — it’s the actual text of the proposals. As WebProNews covered regarding California’s AB 1043, state-level age-gating legislation already demonstrates how these mandates create impossible compliance scenarios for smaller developers. The federal versions threaten to do the same thing nationwide.
So what exactly did the committee advance? The markup session covered several bills in the child safety package. Details on final amendment language are still emerging, but the committee signaled strong bipartisan support for moving the measures to a full House vote. Chairman Brett Guthrie and ranking members framed the action as overdue. The political calculus here is straightforward: nobody wants to be seen voting against child safety. That dynamic makes it extremely difficult to raise legitimate technical and constitutional objections without being painted as indifferent to kids.
But the objections are legitimate.
Age verification technology doesn’t work the way legislators seem to think it does. No system currently available can reliably verify age without collecting sensitive personal data. The two main approaches — ID-based verification and facial age estimation — both introduce serious risks. ID-based systems create honeypots of identity documents. Facial estimation tools, which use AI to guess a user’s age from a selfie, have documented accuracy problems across different demographics and raise biometric privacy concerns under state laws like Illinois’ BIPA. Neither approach is privacy-preserving in any meaningful sense, despite vendor marketing claims to the contrary.
There’s also the question of enforcement against platforms operating outside U.S. jurisdiction. Domestic companies will bear the compliance costs. Foreign operators, including many of the most problematic actors when it comes to child exploitation, will simply ignore the requirements. The bills don’t solve this asymmetry.
Industry groups have offered mixed responses. Some large platforms have publicly supported the concept of federal child safety standards, partly because a single federal framework is preferable to a patchwork of state laws — and partly because compliance costs function as a moat against smaller competitors. The Internet Association’s successor groups and NetChoice have raised concerns about specific provisions while endorsing the broad goal. The real opposition comes from civil liberties organizations and privacy-focused technologists who see the bills as structurally incompatible with an open internet.
The timing matters too. This legislative push is happening alongside active FTC rulemaking on children’s privacy under COPPA, state-level age verification laws already facing court challenges (Texas and California both have measures tied up in litigation), and a Supreme Court that has shown increasing interest in how the First Amendment applies to online platforms. A federal age verification mandate could face immediate constitutional challenge.
For industry professionals, the practical implications are clear. If these bills reach the president’s desk in anything close to their current form, every platform, app, and website that could reasonably be accessed by minors will need to implement age-gating mechanisms. That’s virtually everyone. The compliance timeline, technical requirements, and enforcement mechanisms are still being debated, but the direction of travel is unmistakable. Companies should be pressure-testing their data collection practices, evaluating age verification vendors, and — critically — engaging with the legislative process now, before the text is finalized.
Congress wants to do something about kids online. The question isn’t whether legislation passes. It’s whether the legislation that passes actually protects children without creating a surveillance mandate that affects every person who uses the internet. Right now, the answer to that second question isn’t encouraging.


WebProNews is an iEntry Publication