- Download bills/proposals table (CSV)
- Download watchlist table (CSV)
- Download full tracker (JSON)
- Methodology / verification note
Embed: <iframe src="#tracker" style="width:100%;min-height:480px;border:0"></iframe>
Age verification is being sold as child safety. The bigger pattern is internet identity control. This tracker follows KOSA, app store age checks, state ID laws, platform responses, and the policy pipeline pushing the open internet toward identity checkpoints.
Last updated: October 1, 2026
Current threat level: HIGH
- June 27, 2025: Supreme Court ruled 6-3 in Free Speech Coalition v. Paxton that state age verification for adult content is constitutional under intermediate scrutiny.
- March 5, 2026: Senate passed COPPA 2.0 (S.836) by unanimous consent. Now heads to the House.
- KOSA (S.1748) has 76 cosponsors (42 R, 33 D, 1 I) Senate Commerce ordered it reported Aug 5, 2026, poised for a full Senate vote. Separately, the House passed its KIDS Act version (H.R.7757) June 29, 2026, 267, 117 under suspension of the rules, first time any KOSA version has cleared the House.
- State age verification laws are spreading across the country.
- Some platforms already block users in certain states instead of collecting ID.
- Big Tech can absorb compliance costs. Smaller sites, forums, and open-source projects cannot.
- The core risk is not one bill. The core risk is normalizing ID checks for speech.
Cite this tracker
TheThriftyDev. “Age Verification Creep Tracker: KOSA, App Store ID Laws, and the Fight for Anonymous Speech.” Last updated October 1, 2026. https://thethriftydev.com/blog/age-verification-creep-tracker/
What changed recently
- August 16, 2026, Four updates: (1) SCOTUS declined to block Texas SB 2420 on July 6, 2026 (unsigned, no dissents), app-store age verification is enforceable while the merits case proceeds at the Fifth Circuit; (2) KOSA ordered reported by Senate Commerce Aug 5, 2026, and the House passed its KIDS Act version June 29, 2026 by 267, 117, first KOSA-adjacent bill to ever clear the House; (3) Iowa HF 864 added, signed June 1, effective July 1, 2026; (4) EU DSA minors guidelines + age-verification app prototype (July 2025) noted in What To Watch, end-2026 rollout clock.
- July 1, 2026, Confirmed: Louisiana ASAA did not activate on July 1, 2026. HB 977 (signed May 15, 2026) postponed enforcement to July 1, 2027. No Apple age-check activation for Louisiana occurred on this date.
- June 27, 2026, Correction: Louisiana HB 977 (signed May 15, 2026) postponed the Louisiana ASAA effective date from July 1, 2026 to July 1, 2027. Utah HB 498 similarly postponed Utah ASAA from May 6, 2026 to May 7, 2027. Apple’s Declared Age Range API enforcement for Utah and Louisiana reflects Apple’s implementation schedule, which operates on its own timeline. Tracker updated to reflect corrected legislative dates.
- June 21, 2026, Texas SB 2420 enforcement update: Fifth Circuit lifted injunction May 28, 2026; CCIA filed emergency SCOTUS challenge June 11, 2026 (pending, most significant active development). KIDS Act (H.R.7757) markup update: passed House E&C along party lines March 5, 2026; stalled on House floor with bipartisan talks ongoing; Democrats objected over weakened duty-of-care and broad state preemption. Louisiana postponed to July 1, 2027, HB 977 signed May 15, 2026 delays Louisiana ASAA by one year. Utah also postponed to May 7, 2027, HB 498 delayed Utah ASAA during legislative session. Apple’s Declared Age Range API enforcement for Utah (May 6) and Louisiana (originally July 1) reflects Apple’s implementation timeline, which may proceed independently of state legislative effective dates. West Virginia HB 4412 adult-site age verification law effective June 12, 2026. Massachusetts H.5295 passed House April 8, 2026, would ban social media for under-14s and require universal age verification for all users; currently in Senate. New: Parents Decide Act (H.R.8250) introduced April 13, 2026, mandates OS-level age verification with FTC enforcement, broader than app store laws. Litigation landscape updated with Texas SB 2420 SCOTUS emergency.
- June 9, 2026, Added the June 27, 2025 SCOTUS ruling in Free Speech Coalition v. Paxton, COPPA 2.0 (S.836) Senate passage by unanimous consent on March 5, 2026, KIDS Act (H.R.7757) House Energy & Commerce advancement along party lines on March 5, 2026, Apple Declared Age Range API enforcement timeline (international Feb 24, 2026; Utah May 6, 2026, postponed to May 7, 2027 by HB 498; Louisiana July 1, 2026, postponed to July 1, 2027 by HB 977), Google Play US state-law developer guidance, NetChoice v. Carr preliminary injunction against Georgia SB 351 (June 26, 2025), April 20, 2026 federal court block on the reworked Arkansas minor-social-media law, 76-cosponsor status for KOSA, and a litigation landscape update covering at least 8 states sued.
- May 24, 2026, Added S.1748 status, app-store age verification risk, platform response framing, and privacy-first alternatives.
Quote this
Age verification does not stay age verification. Once platforms must prove who is a minor, adults get dragged into the identity layer too.
The core risk is not one bill. The core risk is normalizing ID checks for speech.
A privacy-first child safety policy should punish exploitation and data abuse, not force every lawful speaker through an identity checkpoint.
X / Twitter: Age verification does not stay age verification. Once platforms must prove who is a minor, adults get dragged into the identity layer too. That is how “protect kids” becomes “show ID to speak.” Tracker: https://thethriftydev.com/blog/age-verification-creep-tracker/
Nostr: KOSA and age-verification laws are not just child-safety policy. They are building pressure toward identity checkpoints for speech. Track the pattern here: https://thethriftydev.com/blog/age-verification-creep-tracker/
Congressional email subject: Oppose age verification mandates; support privacy-first child safety
Congressional email body: Please protect kids online without creating an ID-check internet. I oppose age verification mandates or liability schemes that pressure platforms to identify users before they can speak, search, learn, or join communities. Support privacy-first child safety instead: data minimization, limits on behavioral targeting, anti-dark-pattern rules, enforcement against predators, and protections for anonymous and pseudonymous speech.


Why This Tracker Exists
There are real online harms affecting kids. Sextortion, predatory adults, algorithmic amplification, bullying, self-harm content, addictive feeds, and data harvesting are not imaginary. Parents are right to be angry, and lawmakers are right to care.
The problem is the tool. Age verification sounds narrow until you ask how it works at internet scale. If a platform must treat minors differently, it needs a way to know who is a minor. If it cannot reliably know who is a minor, it checks more users. If checking more users becomes the safe legal path, adult speech gets dragged into the same identity layer.
That is age verification creep: a child safety proposal becomes a compliance system, the compliance system becomes an identity checkpoint, and the identity checkpoint becomes the default gate for speech, search, social media, communities, apps, and eventually payments.
The Short Version
- Protecting kids online matters.
- Age checks sound limited.
- But platforms cannot separate minors from adults without checking users.
- That creates pressure for ID vendors, device-level age signals, app-store verification, and more intrusive account systems.
- The people hurt first are not criminals. They are abuse survivors, whistleblowers, dissidents, religious minorities, activists, journalists, LGBTQ users, and teenagers seeking help.
Federal Bills To Watch
| Bill or proposal | Status | Supporter framing | Age verification risk | Speech/privacy risk |
|---|---|---|---|---|
| KOSA, S.1748 | 76 cosponsors (42 R, 33 D, 1 I). Introduced May 14, 2025. No Senate Commerce markup to date. | Design duties and safeguards for minors | High | Platforms may over-filter sensitive lawful content and seek age assurance |
| COPPA 2.0 | Passed Senate by unanimous consent March 5, 2026 (21 cosponsors). Awaiting House action. | Stronger protections for children and teens | Medium | Depends on implementation and how platforms determine age |
| House online safety packages | KIDS Act (H.R.7757) passed House E&C along party lines March 5, 2026. Strips the Senate KOSA “duty of care”; adds broad federal preemption. Stalled on House floor, bipartisan negotiations ongoing; Democrats object over weakened knowledge standard and state law preemption. No floor vote scheduled. | Parental controls and child safety accountability | High | Could shift age checks to app stores, operating systems, or device layers |
| Parents Decide Act, H.R.8250 | Introduced April 13, 2026. Mandates OS-level age verification (Apple, Google, Microsoft) with FTC enforcement, broader than app store laws, covers every device. In House committee, no markup scheduled. | Device-level child safety accountability | Severe | Shifts age checks from apps to OS layer; could affect every desktop and mobile device nationally |
| Phone or SIM identity proposals | Separate but related identity pressure | Fraud, trafficking, and crime prevention | Severe | Turns basic communication into a permissioned identity event |


The Compliance Incentive Problem
Supporters often say KOSA does not directly require every user to upload ID. That is an important distinction. But direct mandates are not the only way policy changes behavior. Liability changes incentives.
If a platform can be punished for failing to protect minors from certain harms, the platform needs a defensible way to show which users are minors, which settings applied to them, and what content or features they were allowed to access. A small site owner, open-source developer, Nostr client, forum admin, or indie app team does not have a legal department to litigate fine distinctions. The safe response is to block users, remove features, over-filter speech, or outsource age checks to vendors.
That is how “we do not require ID” can still become “show ID to participate.”
State Age Verification Laws To Watch
State laws matter because they create the test cases. One state passes an age check. Another expands it. Courts rule on pieces of it. Platforms react by blocking regions, adding compliance vendors, or changing product design nationally.
| Category | What to watch | Why it matters | Risk |
|---|---|---|---|
| Adult-site age verification | State laws requiring ID or age assurance for sexual content | Creates legal precedent and vendor infrastructure | High |
| Social media minor laws | Parental consent, account limits, and age checks for social platforms | Pushes identity checks into general-purpose speech platforms | Severe |
| App store age verification | Apple/Google or app-store-level age signals | Centralizes age identity at the operating-system or app-store layer | Severe |
| Device-level age systems | Age signals built into phones, browsers, or operating systems | Could follow users across apps and websites | Severe |
| Social media age verification (state) | Iowa HF 864: adult-site age verification signed June 1, 2026, effective July 1, 2026 (one-third-harmful-content threshold; digital ID or transactional-data methods). West Virginia HB 4412: adult-site age verification effective June 12, 2026. Massachusetts H.5295: House-passed April 8, 2026, would ban social media for under-14s and require universal age verification for all social media users; currently in Massachusetts Senate. |
West Virginia creates new enforcement precedent; Massachusetts would be one of the strictest laws in the nation | Severe |
Litigation landscape (June 2026): At least 8 states have been sued over age verification for children. Courts have preliminarily halted laws in Arkansas (reworked law blocked April 20, 2026) and Georgia SB 351 (preliminary injunction June 26, 2025). Pending challenges remain in Florida, Louisiana, Mississippi, and Tennessee. Tennessee classifies age-verification violations as Class C felonies. September 2026 litigation updates: a federal judge blocked the VPN-related portion of Utahs age-verification law pending the legal challenge (the state will not enforce while the case proceeds), and Tennessee could not shake the Free Speech Coalition First Amendment suit over its law. New state AV bills are moving in at least 10 more states in 2026.
Texas SB 2420, SCOTUS emergency (most significant active development): The Fifth Circuit lifted the district court’s injunction on May 28, 2026, allowing Texas’s App Store Accountability Act to take effect. CCIA filed an emergency injunction request with the U.S. Supreme Court on June 11, 2026, SCOTUS declined to block the law on July 6, 2026, unsigned order, no noted dissents; the constitutional question remains open on the merits. If SCOTUS declines to intervene, other states’ app store laws (Louisiana July 1, future states) will accelerate. If SCOTUS intervenes and blocks Texas, the entire app-store-age-check pipeline faces a major setback.
Platform Responses Are The Early Warning System
App stores have started enforcing. Starting February 24, 2026, Apple began blocking users in Australia, Brazil, and Singapore from downloading apps rated 18+ unless confirmed to be adults, the same enforcement model now rolling out to US states. Apple’s Declared Age Range API shares age categories with developers. New Apple’s Declared Age Range API enforcement for Utah went live May 6, 2026. However, Utah’s state law (ASAA) was subsequently postponed to May 7, 2027 (HB 498). Louisiana’s state law (ASAA) was postponed to July 1, 2027 (HB 977, signed May 15, 2026). Apple’s API enforcement may proceed on its own timeline independent of state legislative dates. Texas SB 2420 is enforced. The Fifth Circuit lifted the injunction May 28, 2026; SCOTUS declined to block the law July 6, 2026 (emergency docket, unsigned). The merits fight continues on expedited track at the Fifth Circuit. Google has published US-specific developer guidance for the same wave of state app-store age-verification laws.
When a platform blocks a state instead of collecting ID, that is not just a business decision. It is a warning signal. It means the compliance burden, liability risk, or privacy risk is too high for that platform to operate normally.
EFF has documented how age gates can become a windfall for Big Tech and a death sentence for smaller platforms. Large companies can pay lawyers, vendors, auditors, trust and safety teams, policy teams, lobbyists, and compliance engineers. Small communities cannot. If the cost of running a forum becomes identity verification infrastructure, the open web loses.


Why Anonymous And Pseudonymous Speech Matters
Pseudonymous speech is not a loophole. It is a safety feature.
People use pseudonyms to report abuse, talk about addiction, explore religion, research health issues, organize politically, question powerful institutions, build communities, and separate public speech from private life. Teenagers may need access to information they cannot safely ask for at home. Abuse survivors may need resources without alerting an abuser. Whistleblowers may need to speak without attaching their legal name to every sentence.
An ID-check internet chills all of that. Even if the government never reads the database, the database exists. It can be breached, sold, subpoenaed, misused, shared, or quietly normalized until refusal itself looks suspicious.
The Big Tech Compliance Moat
Regulation sold as anti-Big-Tech can accidentally entrench Big Tech. That is the compliance moat.
Meta, Google, Apple, TikTok, and other giants can absorb age assurance vendors, policy audits, legal challenges, and reporting requirements. A small Mastodon instance, Nostr client, indie forum, hobby project, or privacy-first tool cannot. The likely result is less competition, more centralization, and fewer escape routes from the platforms lawmakers claim to be disciplining.
That matters for builders. A sovereign web needs small services, open protocols, self-hosted tools, and low-friction publishing. Identity compliance moves the web in the opposite direction.


Better Child Safety Without ID Checkpoints
The choice is not “do nothing” or “verify everyone.” Better options exist:
- Ban behavioral advertising to minors.
- Enforce data minimization for all users.
- Ban manipulative dark patterns and addictive product loops.
- Require simple chronological feed options.
- Improve reporting, takedown, and appeals systems.
- Fund investigations and enforcement against predators and extortion networks.
- Support family-level tools that do not require every website to collect ID.
- Require privacy-preserving age signals only if they are voluntary, minimal, audited, open, and not tied to browsing history.
What To Tell Congress
Here is the clean message:
Protect kids online, but do not create an ID-check internet. Oppose age verification mandates and any bill that pressures platforms to identify users before they can speak, search, learn, or join communities. Pass privacy-first child safety instead: data minimization, limits on behavioral targeting, anti-dark-pattern rules, better enforcement against predators, and protections for anonymous and pseudonymous speech.
What Privacy-Minded Readers Should Do Now
- Contact your senators and representatives. Ask whether they support age verification mandates or privacy-first child safety.
- Use pseudonymous accounts where appropriate. Do not attach your legal identity to every public opinion.
- Support decentralized and smaller platforms before the compliance moat gets worse.
- Move some social activity to Nostr and other exit-ramp systems.
- Reduce dependence on identity-linked accounts where possible.
- Share this tracker when someone says, “It is only about protecting kids.”


Copy/Paste This
If you want to explain the issue fast, use this:
Age verification does not stay age verification. Once platforms must prove who is a minor, adults get dragged into the identity layer too. That is how “protect kids” becomes “show ID to speak.” Tracker: https://thethriftydev.com/blog/age-verification-creep-tracker/
Related TheThriftyDev Reading
- KOSA Is Not Just a Kids Safety Bill. It Is an Age Verification Creep Bill
- Mandatory ID Is Coming for Phones and Social Media. Here’s How to Move to Nostr Before the Gate Closes
- Google AI Search Privacy: Better Alternatives to Protect Your Searches
- What Is the Sovereign Builder Protocol?
Sources
EU (added Aug 16, 2026): Under the DSA minors guidelines, the European Commission presented an age-verification app prototype (July 2025) and urged member-state readiness by end-2026. The design is privacy-structured (platforms see an age signal, not an ID), but it is also the rail every EU platform can standardize on. If it ships broadly, the EU effectively builds the western world’s largest opt-in age-verification network. Watch December 2026.
- GovTrack: S.1748 Kids Online Safety Act
- GovInfo: S.1748 bill text
- Sen. Blackburn release on KOSA reintroduction
- ACLU on kids online safety bills and speech protections
- EFF: age gates, Big Tech, and smaller platforms
- R Street on social media age verification problems
- The Intercept on anonymity, KOSA, and age verification
- SCOTUS: Free Speech Coalition v. Paxton opinion (June 27, 2025)
- Wikipedia: FSC v. Paxton case background
- EFF on the SCOTUS age-verification decision
- EFF: 2025 in review, Congress’s crusade to age-gate the internet
- GovTrack: COPPA 2.0 (S.836), passed Senate March 5, 2026
- Sen. Markey: COPPA 2.0 unanimous Senate passage
- GovTrack: KIDS Act (H.R.7757)
- IAPP: KIDS Act advances to full House vote
- Apple Developer: age requirements for Brazil, Australia, Singapore, Utah, Louisiana (Feb 24, 2026)
- Google Play Console Help: changes for US state app store age-verification bills
- NetChoice v. Carr (Georgia SB 351)
- NetChoice 2025 Litigation Wrapped
- CCIA: Emergency SCOTUS filing against Texas SB 2420 (June 11, 2026)
- Congress.gov: Parents Decide Act (H.R.8250)
- Massachusetts Legislature: H.5295 social media age verification
- The Texas Tribune: Texas age verification law now enforced (June 4, 2026)
- SCOTUSblog: Supreme Court app store age verification emergency (June 11, 2026)
Update: who writes the language, link by link
Every instrument in this tracker came from somewhere, and the somewhere is documented. This section follows the chain from a UK amendment to a global standard, quoting each link from its own text. None of these instruments was written by a body the public votes for.
1. The amendment that started the pattern
During the passage of the Data Protection Act 2018, a crossbench peer, Baroness Beeban Kidron, tabled Amendment 109, recorded in the parliamentary record under the title “Age appropriate design code” and marked agreed. That amendment is the origin of the duty now in section 123 of the Act, and section 123(4)(b) requires the code to have regard to the United Kingdom’s obligations under the UN Convention on the Rights of the Child. The House of Lords is appointed, not elected. Once enacted, the duty binds.
2. The committee that interprets it
General Comment No. 25, published by the UN Committee on the Rights of the Child on 2 March 2021, sets out how the Convention applies in the digital environment. The Committee’s own page describes its output as recommendations. Its members are independent experts, not elected officials, and a general comment is advisory rather than binding. Its reach is not trivial all the same, because the UK code carries a statutory duty to have regard to it. 5Rights Foundation’s own advocacy page states that it “played a pivotal role in the development of General comment No. 25”.
3. The standard that names its own inspiration
IEEE 2089-2021 carries the title “Standard for an Age Appropriate Digital Services Framework Based on the 5Rights Principles for Children”. IEEE is a private standards body. Nobody elects it, and its standards are voluntary until a law or a contract references them.
4. The workshop agreement, named correctly
CEN and CENELEC published CWA 18016:2023, a CEN/CENELEC Workshop Agreement. A workshop agreement is not a European Standard and it is not law. The distinction matters, because a workshop agreement is produced by a narrower set of participants than an EN, and secondary coverage tends to blur the two labels together.
5. Where a voluntary standard becomes binding
In the EU, standards become enforceable through citation. Commission Implementing Decision (EU) 2025/138 cites harmonised standards EN 18031-1, EN 18031-2 and EN 18031-3 of 2024, adding them with restrictions to Annex I of Implementing Decision (EU) 2022/2191, which gives them the legal effect of presumption of conformity under the Radio Equipment Directive 2014/53/EU. That is the documented mechanism in one sentence: private bodies write the technical rules, and an executive act turns them into a legal presumption. No voter votes on the citation.
6. The cross jurisdiction finding, with its year
UNICEF’s 2025 brief “Keeping Children Safe Online: Trends in Online Platform Regulation and Emerging Lessons” compared six jurisdictions, Australia, the European Union, India, Kazakhstan, South Africa and the United Kingdom, and found that “eight common business obligations are emerging across jurisdictions”. Name the year every time. UNICEF published a separate brief in June 2026 covering a different set of jurisdictions and reporting a five element finding. Both documents exist, they are not the same document, and the difference has already been used to dismiss careless citations of the eight obligation finding.
7. The convening layer
WeProtect Global Alliance publishes the Model National Response, a template governments adopt when building child protection systems, and it runs the Global Age Assurance Standards Summit. The Age Check Certification Scheme describes itself as a “not-for-profit company limited by guarantee” with company number 11493870, and its 2026 communique sets out a six point call to action. The standards named in that work for cross border interoperability are ISO/IEC 27566-1:2025, “Age assurance systems, Part 1: Framework”, and IEEE 2089.1.
What the chain does and does not establish
Every link above is quoted from the document itself. What the record establishes is a sequence of instruments, plus overlapping personnel and shared funders across jurisdictions. What no document reviewed for this page establishes is coordination or intent. No source says these bodies act together on a plan, and this page does not claim it. Read the chain, check each link, and decide for yourself. The people named here are public officials and charity officers acting in published roles, and every seat described is one their own organisation lists.
Update: unelected, and what kind of power each one holds
Unelected is not one thing. A regulator enforcing a statute that an elected parliament passed is different in kind from a body no elected body can move past, and both differ from a private standards committee whose work becomes binding only when an executive act cites it. Here is the map, one line per body, with the instrument class named exactly.
| Body | Elected? | Binding or advisory | What it decides in this stack |
|---|---|---|---|
| European Commission | Unelected, appointed | Binding | It is the only body that can propose EU legislation (Article 17(2) TEU), it adopts implementing and delegated acts, and it contracted and published the EU age verification app |
| Commission Recommendation (EU) 2026/1035 of 29 April 2026 | Unelected author | Advisory in form | Asks member states to have an EU age verification solution available by 31 December 2026. Adopted under Article 292 TFEU; Article 288 TFEU states that recommendations “shall have no binding force” |
| Ofcom | Unelected, board appointed by the Secretary of State | Binding | Enforces the Online Safety Act 2023 age assurance duties, including children’s safety confirmation decisions, with penalties it determines and a criminal offence carrying up to two years for breach |
| House of Lords, Baroness Kidron (Crossbench) | Unelected | Binding once enacted | Amendment 109 created the age appropriate design code duty now in section 123 of the Data Protection Act 2018 |
| UN Committee on the Rights of the Child | Unelected experts | Advisory | General Comment No. 25 interprets the Convention for the digital environment, and the UK code has a statutory duty to have regard to it |
| European Data Protection Board | Unelected | Advisory, binding only in GDPR Article 65 consistency disputes | Statement 1/2025 on age assurance, plus guidelines |
| ISO | Private, unelected | Voluntary until referenced by law | ISO/IEC 27566-1:2025, Age assurance systems, Part 1: Framework |
| IEEE | Private, unelected | Voluntary until referenced | IEEE 2089-2021, the framework subtitled “Based on the 5Rights Principles for Children” |
| CEN and CENELEC | Private associations, unelected | Voluntary, binding effect once cited | EN 18031-1, EN 18031-2 and EN 18031-3 of 2024, cited to confer presumption of conformity under Directive 2014/53/EU |
| The app consortium, Scytales AB and T-Systems International GmbH | Private, unelected | No legal force of its own | Built the technical artefact the Commission recommendation points member states toward |
The structural point that gets lost in argument: Ofcom and the Information Commissioner are unelected, but the duties they enforce were enacted by an elected Parliament and can be repealed by it. The Commission’s position is different in kind, because no elected body can put EU legislation to a vote until the Commission has proposed it. Standards bodies are a third case again, private and non majoritarian, with force that arrives through an act of an unelected executive.
Two bills, one acronym, two legal orders
Two different instruments, in two different legal orders, sharing a four letter acronym in the same year. Keep them apart when you read anything about either.
- United States, H.R. 7757. Short title, exactly as filed: “Kids Internet and Digital Safety Act”. Introduced 3 March 2026, passed the House 267 to 117 on 29 June 2026, referred to the Senate Committee on Commerce, Science and Transportation on 13 July 2026. It consolidates language from roughly fourteen bills including KOSA and COPPA 2.0, and the duty of care was stripped out in section 213(c)(2).
- European Union, COM(2026) 681 final. Full title: “EU Keeping Internet Digital Spaces Accountable and Trustworthy”. Proposed by the Commission on 17 September 2026 on the legal basis of Article 114 TFEU. It is a proposal, not law. It would ban accounts for under 13s, require guardian managed mini accounts with a one hour daily default between 13 and 15, grant autonomy from 15, reach video sharing platforms, games, app stores, operating systems and AI companions, keep companion features off by default and bar them from simulating dependency, require platform funded independent audits, and allow fines up to 6 percent of global turnover. Adoption before 2028 is unlikely on the current timetable.
Both short titles reduce to KIDS in the same year. That is a fact about the naming, and it is the reader’s to weigh. Whether the naming was coincidental or authored is an argument rather than a citation, so treat it the way this page treats every other argument: the documented record is the sequence of instruments, the shared personnel and the shared funders set out here.
Who is in the room, according to their own filings
- 5Rights Foundation. Its own transparency page states: “5Rights Foundation is a registered charity in England, Wales, and Scotland”, company number 11271356, Charity Commission number 1178581, Scottish charity number SC049882, with 5Rights EU registered in Belgium as an ASBL, enterprise number BE 1013.028.507. Its published board lists Baroness Beeban Kidron as “Founder and Honorary President”, Sir Peter Wanless as chair, Mie Oehlenschlaeger as EU President, and trustees including a former UK Information Commissioner, Elizabeth Denham, and a former chair of the UN Committee on the Rights of the Child, Mikiko Otani. On funding it states: “We do not accept funding or in-kind donations from tech companies or their charitable or philanthropic arms.” Its published funder lists name the Council of Europe, the Oak Foundation, Safe Online, the Digital Freedom Fund, the Garfield Weston Foundation, the Rothschild Foundation, the Indigo Trust, the Prudence Trust and others, with IEEE SA named in 2023 and 2024, the Council of Europe in 2024 through 2026, and the Lego Foundation in 2024. It publishes names only, not amounts.
- WeProtect Global Alliance. Its audited 2024 financial statements are headed “Stichting The WePROTECT Global Alliance”, a Dutch foundation. The same audited statement records income from other not for profit organisations of 1,964,082 euro for 2024, and records “Government grants” as nil. Its project funding liabilities note names Stichting Benevolentia, the EU, the Oak Foundation, Together for Girls, the New Venture Fund, Snapchat, the Calf Fund and the Children Investment Fund. Its own site states that over 350 member organisations are part of the alliance.
- ECPAT International. A Dutch stichting, KVK 34139743. Its audited accounts for the year ended 30 June 2025 record grants of 5,108,995 US dollars, with each funder and amount listed.
- Thorn. A US 501(c)(3), EIN 27-0943677, reporting 16,355,617 US dollars of revenue for its 2024 financial year and describing its own funding model as dual, taking both philanthropic and technology sector money.
- NCMEC. A US 501(c)(3), EIN 52-1328557, reporting 66,813,108 US dollars of revenue for the year ending December 2025, including a grant line from the Office of Juvenile Justice and Delinquency Prevention.
- Internet Watch Foundation. A charity and company limited by guarantee, registered charity 1112398, describing itself as funded primarily by the internet industry together with a grant from Nominet.
- Digital Futures Commission. Not a legal entity. It states that it is funded by 5Rights Foundation with funding in kind from the London School of Economics, and it lists fourteen commissioners.
Two things need saying plainly about that list. First, the LEGO item is a live discrepancy rather than a neat fact: 5Rights states it accepts nothing from technology companies or their charitable arms, its own 2024 list names the Lego Foundation, and a search of the LEGO Foundation annual reports for 2021 and 2022 shows no grant to 5Rights, while the 2023 to 2025 appendices are not machine readable, so that check is inconclusive. A discrepancy is not a finding, which is why it is written here as one. Second, the published funder lists name organisations that also sit in this policy space, including a standards body and the Council of Europe. Money moving between organisations in the same field is not inducement and this page does not allege it.
The seats, and the door
The same people hold seats across several of these bodies at once, and every seat below is published by the organisation itself on its own governance page. WeProtect Global Alliance lists its chair as Ernie Allen, whom Thorn’s board page describes as the founding chairman of WeProtect and who is also a Thorn board member. That same page lists Thorn’s chief executive, Julie Cordua, ECPAT International’s executive director, Guillaume Landry, and two UNICEF child protection figures: Sheema Sen Gupta, Director of Child Protection, and Cornelius Williams, a former Director of Child Protection, who also chairs ECPAT International’s Supervisory Board.
It also lists the seats held by the companies and governments in the same room: the Global Head of Platform Safety at Snap Inc, the Child Safety Manager at Google, the chief executive of the Children’s Investment Fund Foundation, a representative of the European Commission’s Directorate General for Migration and Home Affairs, a deputy director from the UK Home Office, the Australian eSafety Commissioner, a director general from the United Arab Emirates Ministry of Interior, and the peer Baroness Joanna Shields, recorded as a founder of WeProtect. Two of the largest platforms whose conduct this policy area addresses sit on the governing body of the alliance that publishes the Model National Response. That is a fact published by the alliance, and it is not proof of anyone’s intent. Shared funders across the cluster include the Oak Foundation, Safe Online, the Children Investment Fund and the New Venture Fund.
Seats and funders are facts. What they add to is a judgement, and no source reviewed for this page states that these organisations coordinate with each other on a plan, so this page does not assert that they do.
On the regulator’s side, Ofcom’s own response to a freedom of information request disclosed multiple recruits from Meta into its online safety group, and Ofcom has appointed a former Meta public policy official as Director of Online Safety Policy. That movement of personnel is a matter of public record. It is not evidence of anyone’s motives, and this page makes no claim that a job or a grant buys an outcome.
More on keeping your own data yours is collected in the Privacy and Digital Rights Hub.
Related reading
- The Same Bill In Every Country: How Age Verification Became the On Ramp To Digital ID puts this chain next to the two KIDS Acts and sets out what the record does and does not establish.
Read next
What Frontier AI Actually Costs, and What Each Provider Keeps: The September 2026 Price and Privacy Table
15 min read·Published Sep 29, 2026NostrXFacebookRedditTelegramSMSCopyOn this page▾The price table: hosted inference, per million tokensThe retention table: what each provider’s own documents…
Open Weights Licensing in 2026: What You Can Actually Ship
0 0 votes Article Rating Part of Start Here This article is not legal advice. It is a survey of published license…
The Local Model VRAM Tracker
0 0 votes Article Rating Part of Start Here Data in this page is as of 29 September 2026. Prices move fast,…