Skip navigation menu
Hero background image
REAL PARENTS. REAL SOLUTIONS.

Protecting Kids Online

Our mission is to protect children and defend parental rights by equipping families and citizens with the tools to keep kids safe online. We oppose government surveillance disguised as child safety legislation and seek to build an informed, independent, parent-led coalition to #ProtectKidsOnline.

What's the AI Chatbot Compliance Template?

Every few months, a new bill arrives promising to protect kids from predatory AI chatbots. Different sponsor, different state, different name: GUARD Act, CHATBOT Act, Florida’s AI Bill of Rights (SB 482), WA’s ESHB 2225. Read past the press release, and they all build the same thing.

At the core of every one of these bills is the same five-part structure: an identity gate, a categorical restriction for minors, an ongoing monitoring system, a data carve-out for the vendors who run it, and a definition of "AI chatbot" broad enough to cover almost anything with a text box. The names change, but the architecture does not.

The identity gate.

Before any of these bills can restrict what a minor does, they first have to establish who is a minor. That requirement takes different forms (government ID verification, parental consent at account creation, a "known minor" trigger), but the function is identical. You cannot enforce an age-based rule without first collecting the age of every user.

Some versions state plainly that they require age verification. Others state plainly that they don't, then build a "knows" standard instead: a platform is only obligated to act once it "knows," or once knowledge is "fairly implied," that a user is a minor. That sounds like a lower bar, but in practice it's the same gate wearing a different label. A platform that cannot demonstrate it knows its minor users faces the enforcement risk, so age-detection infrastructure gets built anyway, just without the word "mandate" attached to it.

The categorical restriction.

Once the gate exists, the bill uses it. Outright bans on AI companions for minors. Blocked content categories. Restricted "engagement techniques." Consent requirements before a minor can use a chatbot at all. This is the part of the bill that gets quoted in the press release, and it's the part that's easiest to support; nobody wants a fourteen-year-old in a romantic relationship with a chatbot.

But the restriction only exists downstream of the gate. Support the restriction, and you've already accepted the identity infrastructure required to enforce it.

The monitoring problem.

This is where these bills go further than most people realize. Beyond the one-time gate, the compliance architecture requires ongoing behavioral tracking: repeating AI disclosures on a timed schedule, retained conversation transcripts, parental dashboards, and crisis-detection protocols that flag anything read as an expression of self-harm or distress.

That last piece deserves its own scrutiny. A real-time system built to detect and report a minor's emotional state to a parent, or, in some cases, to a state agency, is a surveillance mechanism regardless of the intention behind it. None of these bills specify what happens to the underlying transcript once a flag is triggered, whether it becomes discoverable in a custody dispute, or whether the platform becomes a mandatory reporter based on what a child told a chatbot rather than what a child told a person.

The vendor exemption.

Every one of these bills contains data minimization language; encryption, retention limits, no selling of verification data. Read the next clause and the protections apply only to the platform itself, not to the third-party identity verification vendors the bill explicitly permits the platform to hire. The companies actually holding the government ID or biometric data operate under their own privacy policy, not the bill's. Several versions say nothing at all about whether transcript data can be used to train the AI model that generated it.

The elastic definition.

"AI chatbot" or "AI companion" is defined broadly enough in most of these bills to sweep in general-purpose tools such as a homework helper, a customer service bot, or a research assistant alongside the companion apps the bill is nominally targeting. That ambiguity isn't incidental. A narrow definition would require narrow infrastructure. A broad one requires the same identity and monitoring architecture to be built for every AI product a minor might touch.

What real protection would look like.

A bill built to protect kids from AI chatbots would target harmful design choices directly: sexualized companion products, manipulative engagement mechanics, deceptive human impersonation, without requiring an identity and behavioral-tracking system for every user, adult and minor, to get there. It would hold a company accountable when its product caused documented harm to a specific child. It would not require a permanent data architecture on every child as the price of catching the harm that architecture was supposedly built to prevent.

None of the bills built on this template do that. They deliver the identity infrastructure first and the child-safety outcome as a byproduct, if at all.

What parents can do today.

You don't need this architecture to protect your child from an AI chatbot right now. Device-level parental controls, app restrictions, and direct conversation about what your child is doing online are available today, with no new data collection on your family required. An engaged parent is still the most effective safeguard that exists. No compliance template, federal or state, replaces that.

If a legislature wants to act, the mechanism has to match the harm. So far, none of them have.