The Senate Commerce Committee is poised to consider the
Youth AI Privacy
Act
, a bill that would require AI companies to create kids-only privacy rules and implement so-called “safe design features,” which would
—
like three other bills under consideration this week—require more data collection and make it harder for people to access lawful speech online.
While the bill is narrower than some other proposed chatbot bills, it still has massive data
security implications because it protects information for only certain users. This creates a problem we’ve cited many times before: if a bill requires that online services offer protections to minor users, the services will respond
by imposing age gates
to know which users should receive them. A better approach would be to offer the same privacy protections to all users. That way, we would avoid the services having to collect data on everyone to know a users’ age.
This bill also contains a problematic and vague provision that expressly allows AI companies to collect a known minor’s personal data for the purpose of testing, identifying, and addressing "harm to users”—without being clear on what exactly that means. Either way, services will need to collect even more information from young people, who are
already targets
of data theft and identity fraud. The Youth AI Privacy Act will give young people less privacy, not more.
The Youth AI Privacy Act does include some positive privacy provisions around prohibiting the processing of personal information, like limiting what companies can do with people’s chat logs, including training, profiling, and disclosing them to other companies for training. But a general privacy bill must set these limits for everyone, not just minors.
Mandating Design is Regulating Speech
The bill also requires the use of “safe design features,” which would restrict how online services providers design their systems and would deny teenagers the ability to use features like push aler
… [more]