On Monday evening, June 29, 2026, the U.S. House of Representatives passed H.R. 7757, the Kids Internet and Digital Safety Act, by a vote of 267 to 117, with 47 members not voting. The bill now moves to the Senate, where it faces a genuinely uncertain path. But before we get to what happens next, let’s slow down and look at exactly what this thing does because the surface-level pitch (“protect kids online, bipartisan win, Big Tech accountability”) and the actual statutory text are not telling the same story.

This is not a single bill. It is a package of roughly twelve separate pieces of legislation stitched into one vehicle, anchored by a revised version of the Kids Online Safety Act (KOSA) and a modernized Children’s Online Privacy Protection Act, known as COPPA 2.0. Each of the smaller bills inside the package has its own definitions, its own knowledge standard for determining who counts as a minor, and its own enforcement mechanism. That inconsistency is not a side detail. It is the entire reason civil liberties groups are sounding alarms, and it is the reason most platforms are going to respond the same way regardless of what Congress intended: verify everyone.
What happened on the floor
H.R. 7757 was introduced by House Energy and Commerce Committee Chairman Brett Guthrie (R-KY). The committee first advanced an earlier, Republican-only version of the package on a party-line 28-24 vote back in March. That version stalled. It preempted state laws, it used a weaker “actual knowledge or willful disregard” standard for identifying minors, and it could not get Democratic buy-in.
What changed things was a negotiation between Guthrie and Ranking Member Frank Pallone (D-NJ) that produced new text on June 22. The revised bill dropped KOSA’s preemption of stricter state laws, tightened the knowledge standard, folded in COPPA 2.0 and a federal data broker registry requirement, and picked up enough Democratic support to clear the floor under suspension of the rules, a fast-track procedure that skips normal committee markup and amendment debate but requires a two-thirds majority to pass. Getting 267 votes under a two-thirds threshold is not a narrow win. It means a large bloc of Democrats who have historically opposed KOSA’s “duty of care” language voted yes once that language was gone.
That detail matters more than it might seem. The Senate’s version of KOSA, which passed that chamber 91-3 back in July 2024 as part of a package called KOSPA, still contains a duty of care provision requiring platforms to exercise “reasonable care” in designing features to prevent and mitigate harm. The House version that just passed strips that out entirely and replaces it with a requirement to “establish, implement, maintain, and enforce reasonable policies, practices, and procedures” addressing a list of harms. Lawyers will tell you the difference between a duty of care and a policies-and-procedures requirement is the difference between being liable for what your product does and being liable for whether you wrote a document saying you’d handle it. Senate KOSA co-sponsors Marsha Blackburn (R-TN) and Richard Blumenthal (D-CT) have both publicly called the House version unacceptable. That sets up exactly the kind of inter-chamber standoff that tends to drag federal tech legislation out for years, except this time there’s a wrinkle: the White House is reportedly working with Blackburn on a Senate package that ties kids’ safety provisions to federal preemption of state AI laws, which could change the calculus entirely.
The titles, broken down
The bill’s structure matters because each title operates on a different legal trigger, and those triggers are the whole ballgame.
Title I, Shielding Minors From Obscenity (the SCREEN Act) – This is the one part of the package that explicitly requires age verification. Sections 101 through 106 require any platform where more than one-third of the content is “harmful to minors” to deploy a technological age verification measure determining whether a user is “more likely than not” under the relevant age threshold. This is functionally a federalized version of the age-verification statutes already in force in roughly twenty states, the kind upheld by the Supreme Court in Free Speech Coalition v. Paxton in June 2025, which applied intermediate scrutiny to a Texas porn-site age check law rather than the stricter standard that would normally apply to content-based speech restrictions. The SCREEN Act also imposes data minimization and retention limits on whatever verification data gets collected, which sounds protective until you remember the underlying problem: you cannot leak data you never collected, and forcing collection in the first place is the risk, not just what happens to it afterward.
Title II, the revised KOSA – Sections 211 through roughly 221 require covered platforms to enable the most protective safety and privacy settings by default for any user the platform “knows or should have known” is a minor, defined as under 13 for children and 13 to 16 for teens. This is the negligence-style knowledge standard EFF flagged, and it’s worth being precise about why it functions as a backdoor age-verification mandate even though the bill text says it isn’t one. A platform doesn’t need to actually know a user’s age to be liable. A court or the FTC can decide after the fact that the platform “should have known,” based on whatever signals existed: search history, content interactions, account creation patterns, anything. Once that determination is a courtroom question rather than a documented fact, every platform’s rational move is to eliminate the ambiguity up front by verifying age for all users, because losing a “should have known” argument after a minor was harmed is an existential legal and PR risk, while proactively gating access is just a UX cost.
Title II, Subtitle B, the Safe Messaging for Kids Act – Sections 231 through 238 ban disappearing-message features for users under 17 entirely and ban direct messaging outright for users under 13. Section 235 requires parental controls for teen direct messaging, activated through verifiable parental consent. Section 236 is the encryption carve-out, and it is worth quoting the actual operative language rather than paraphrasing it, because the wording is doing a lot of quiet work: platforms must comply with these messaging restrictions “to the maximum extent technically feasible, through means that do not compromise the integrity of strong encryption.” That phrase, “to the maximum extent technically feasible,” is a feasibility qualifier, not a prohibition. It does not say encryption cannot be touched. It says providers have to try not to break it while still complying with restrictions that, in an end-to-end encrypted system, are mathematically impossible for the platform to enforce without some form of client-side scanning, metadata analysis, or key escrow, because the provider cannot read the message content to know whether a “disappearing message feature” or a banned conversation is happening. This is the same structural problem that has dogged the UK’s Online Safety Act and the EU’s proposed CSAM scanning regulation: you cannot require a platform to police content it has deliberately engineered itself not to see, without either weakening that engineering or building detection around the edges of it.

Title II, Subtitle C, the SPY Kids Act – This is genuinely the best-drafted piece of the package from a privacy standpoint. It bars platforms from conducting market or product-focused research on users they actually know are minors, using the narrower “actual knowledge or willful disregard” standard rather than “should have known.” Public Knowledge specifically praised this distinction, because a tighter knowledge trigger here doesn’t hand platforms an incentive to verify everyone’s age just to figure out who they’re legally barred from studying.
Title III, the GAMING Act – Applies to interactive online video game providers, including social gaming platforms like Roblox. Requires default-on parental controls limiting who can message a minor, blocking minor profile recommendations to adult users, capping playtime, and restricting in-game financial transactions, all manageable through a single parental interface.
Title IV, the SAFE BOTs Act – Covers consumer-facing AI chatbots, carved out from customer-service bots that are incidental to a platform’s primary function. Chatbot providers cannot claim to be licensed professionals, must disclose they are AI at the start of a conversation and whenever asked, must surface crisis and suicide hotline resources when appropriate, and must encourage a break after roughly three hours of continuous use. Notably, this title explicitly does not require age verification and includes a rule of construction stating it doesn’t mandate affirmative collection of age data beyond what a provider already gathers in the normal course of business. Several advocacy groups, including Public Knowledge, have actually called this the most reasonably scoped title in the whole package.
On top of these are COPPA 2.0, which extends existing under-13 privacy protections up to age 17, bans targeted advertising to minors, mandates an “eraser button” for deleting a minor’s data, and stands up a new Youth Marketing and Privacy Division inside the FTC; a federal data broker registry requirement for any broker holding minors’ data; and several pure study-and-report titles, including a four-year longitudinal study on social media’s mental health effects and a mandated FTC/FDA report on how minors access fentanyl through social media.
Why the knowledge-standard problem is the whole story
Here’s the part that gets lost in press releases from both parties. Three different titles in this same bill use three different legal standards for figuring out who’s a minor: KOSA’s “knows or should have known,” the SCREEN Act’s “more likely than not,” and the SPY Kids Act’s “actual knowledge or willful disregard.” A platform operating across all four titles, which describes basically every major social network, gaming platform, and AI chatbot provider, now has to satisfy the strictest standard among them just to avoid the worst-case legal exposure on any single title. That strictest standard is the SCREEN Act’s affirmative verification requirement. Once you’ve built verification infrastructure to satisfy that title, there’s no incentive to limit it to porn sites, because the same infrastructure resolves your “should have known” exposure under KOSA for free. This is exactly the dynamic EFF described: a bill that technically avoids mandating age verification in two of its four major titles, while structurally guaranteeing that companies build it anyway because the cost of guessing wrong is unbounded and the cost of just checking everyone is a fixed, predictable engineering line item.
The track record on age verification mandates is also not great from a privacy-engineering standpoint, regardless of which side of the policy debate you’re on. NetChoice and the Computer & Communications Industry Association have spent the last three years litigating nearly identical state-level laws in Arkansas, Florida, Georgia, Louisiana, Mississippi, Ohio, Texas, and Utah, with genuinely mixed results: they won permanent injunctions in Louisiana and a preliminary injunction in Texas against the App Store Accountability Act, but lost ground in the Eleventh Circuit on Florida and Georgia’s social media laws, and lost outright at the Supreme Court on Texas’s porn-site verification statute. The technical argument NetChoice has made consistently across all of these cases is that there is no age-verification system that isn’t also a deanonymization system. Whether that’s implemented through government ID upload, facial age estimation, or behavioral inference, the result is the same: a third party now holds a verified link between a real identity and an online account, and that link is a target. Existing facial age-estimation systems also have documented accuracy problems that fall disproportionately on people of color, people with disabilities, and trans and nonbinary users, which is a genuinely bad failure mode for a law whose stated purpose is protecting a vulnerable population, when the verification system is most likely to misfire against vulnerable subpopulations within that population.
The content-moderation liability nobody’s talking about
KOSA’s reasonable-policies-and-procedures requirement covers a list of harms that includes the sale or use of narcotic drugs, tobacco, cannabis, gambling, and alcohol, plus financial fraud. None of that targets illegal conduct specifically. It targets topics. A platform now needs documented, enforced moderation policy covering any minor discussion that touches those categories, regardless of whether the speech itself is lawful, harm-reduction-oriented, or genuinely protective. A 16-year-old posting in a recovery support community, a teenager asking how to talk to a parent with a gambling addiction, a harm-reduction account explaining fentanyl test strips, all of that is fully lawful speech that now sits inside a category platforms are under legal pressure to police. The bill doesn’t ban any of it outright. It just makes the legal risk of leaving it up outweigh the legal risk of taking it down, for any platform without the resources to fight an FTC inquiry or a state AG suit. That’s the same mechanism that drove the speech-chilling effects of FOSTA-SESTA in 2018, and it’s a well-documented pattern at this point: raise the liability ceiling around a content category, and platforms over-remove rather than risk being wrong.
Enforcement and the politics of who’s holding the gavel
Enforcement runs primarily through the FTC under its Section 5 unfair-or-deceptive-acts-or-practices authority, the same mechanism that’s produced COPPA penalties running as high as $53,088 per violation in past cases, and which the FTC used to extract a $150 million settlement from a major platform in 2022 for COPPA violations alone. State Attorneys General retain authority to enforce most of the bill’s provisions but are explicitly barred from enforcing KOSA’s core reasonable-policies requirement while an FTC action against the same defendant is pending, which concentrates the most consequential enforcement lever in a single federal agency. Groups including 5calls.org have specifically flagged the risk of that concentration given the current FTC’s commissioner makeup and its documented willingness to pursue politically motivated investigations, arguing that a “protect the children” framing has historically been an effective vehicle for ideologically selective enforcement against disfavored speech, regardless of which administration is doing the selecting.
What happens next
The bill now sits in the Senate, where Commerce Committee Chair Ted Cruz has been coordinating with the House on parts of the package, while Blackburn negotiates separately with the White House over a deal that may bundle Senate KOSA with federal preemption of state AI regulation and possibly the App Store Accountability Act and the NO FAKES Act. Blumenthal has indicated the Senate is unlikely to accept the House’s gutted duty-of-care language as-is. That means one of three things happens from here: the Senate passes its own stricter version and the two chambers go to conference to hash out a compromise, the Senate amends H.R. 7757 directly and sends it back to the House, or the whole effort stalls the way KOSA has stalled in some form since 2022, while individual states keep filling the vacuum with their own, increasingly varied age-verification and design-code laws, litigated piecemeal in courts that keep reaching different conclusions about what the First Amendment allows.
Whatever the final shape, the technical reality underneath all of it doesn’t change. A patchwork of differing knowledge standards inside a single statute pushes every covered platform toward the most invasive compliance posture available, encryption carve-outs that say “to the maximum extent technically feasible” don’t survive contact with systems engineered specifically so the provider can’t read the content, and liability built around topic categories rather than illegal conduct produces over-removal of lawful speech as a predictable, mechanical outcome rather than an edge case. None of that requires bad faith from anyone who voted for this bill. It just requires understanding how the incentives actually work once the statute leaves the floor and lands on a compliance team’s desk.









