The CHATBOT Act: A Mandate for AI Surveillance and New Privacy Risks for Teens
The proposed **CHATBOT Act** aims to regulate how minors interact with AI, but critics argue it imposes a one-size-fits-all parental monitoring system that could compromise user privacy. By extending a nearly 30-year-old children's privacy law to teenagers, the bill mandates invasive surveillance tools and creates significant new data security risks for families.
# The CHATBOT Act: A Mandate for AI Surveillance and New Privacy Risks for Teens
Artificial intelligence is rapidly reshaping education and information access. While the need for Congress to examine AI's impact on minors is clear, the recently advanced **CHATBOT Act** (**S. 4407**) proposes a solution that raises significant concerns among privacy advocates like the **EFF**.
Passed by the Senate Commerce Committee on August 5, 2026, the bill mandates a federally prescribed parental monitoring system for AI use by teenagers, a move the **EFF** continues to oppose.
## The Bill Requires AI Companies to Build Family Monitoring Systems
Families approach AI use with varying levels of supervision and rules. However, the **CHATBOT Act** would remove this decision-making autonomy from both families and AI providers.
Instead, it would compel every covered AI chatbot to implement a standardized "family account" system. This system requires AI companies to provide parents with a "full record of the conversations and activity" of teen users, alongside tools to "monitor, analyze, and understand, at scale" these interactions. It also mandates alerts if a teen attempts to bypass or disable parental controls.
This isn't an optional feature. The bill requires the development of this monitoring infrastructure as an integral part of the parental consent process, effectively imposing a single, highly invasive model for supervising teenage AI use.
## The CHATBOT Act Creates New Privacy Risks for Families
The bill's mandated data collection effectively requires AI providers to build the same monitoring architecture for users of vastly different ages, from younger teens to high school seniors. This approach overlooks the nuanced expectations parents have for varying age groups.
More critically, this centralized data collection will create new privacy and security risks. By requiring AI companies to maintain a permanent, centralized record of teen AI conversations for parental review, the bill establishes a valuable vault of extremely personal information. This raises serious questions about the implications of account compromises, family disputes, or other security failures.
These vast archives of conversations will become attractive targets for hackers, identity thieves, civil litigants, and other malicious actors. The **CHATBOT Act** mandates their existence but fails to address the inherent security vulnerabilities they present.
## The CHATBOT Act Applies a Children's Law to Teenagers
The **CHATBOT Act** fundamentally extends the structure of **COPPA** (the **Children's Online Privacy Protection Act**), a nearly 30-year-old law designed for children aged 12 and under, to older teenagers. This constitutes a dramatic expansion of the law's scope.
**COPPA** was enacted to prevent websites from collecting detailed personal information from young children without verifiable parental consent. For decades, this has led many online services, including **Instagram**, **TikTok**, **X**, **YouTube**, **Snapchat**, **Discord**, **Spotify**, **WordPress**, **Microsoft Co-Pilot**, **Google Gemini**, and **ChatGPT**, to bar users under 13. **Anthropic** even restricts users under 18 from its **Claude** AI model.
Ironically, while **COPPA** already provides privacy protections against collecting personal information from minors, the **CHATBOT Act** risks inverting this by potentially leading AI services to collect *more* information about young users. It extends **COPPA's** parental-permission model to high school students, mandating specific, invasive surveillance tools that go far beyond existing **COPPA** requirements.
By requiring providers to offer these "family accounts" with specific features as a default for teenagers, the **CHATBOT Act** treats a high school senior similarly to an elementary school student. While supporters may argue that creating a family account is optional for parents of teens, every family with a teenager would still be subjected to the bill's parental-consent process before AI use. This necessitates practical methods for providers to verify parental identity. Furthermore, for children under 13, the bill offers no option other than creating a family account.
Extending the **COPPA** parental-permission model to millions of older teenagers would be detrimental. The government does not require **COPPA**-style parental permission for a 17-year-old to check out a library book, use **Wikipedia**, search on **Google**, or read a newspaper online. It should not impose such requirements simply because the same information is sought from an AI assistant.
## The CHATBOT Act Will Pressure AI Companies to Check Usersβ Ages
Despite claims that the bill does not require age verification, it imposes obligations contingent on a company knowing whether a user is under 18. Specifically, AI systems must either disable access for young kids, obtain parental consent, or facilitate the creation of a family account if they have reason to believe a user is a minor. This standard means services could be held liable even without actual knowledge of a user's age, creating significant pressure for age-checking mechanisms.