
BILL ANALYSIS
Parents deserve tools that protect their kids — not federal systems that quietly build identity infrastructure for minors. The TOTAL Screen Time Act (H.R. 9692) introduced by Rep Harrigan, is being marketed as a simple, bipartisan bill to “help parents manage screen time.”
But when you read the text closely, the bill does something very different.
It creates the first federal technical standard for cross‑device parental controls — and that standard requires identity binding, device‑level enforcement, and cross‑platform synchronization. Under the PKO Digital Safety & Identity Architecture Framework, this bill is an automatic OPPOSE.
Here’s why.
PKO has four red lines; any one of which is enough to oppose a bill. Harrigan’s bill triggers all four.
The bill requires:
“an authentication and authorization model for minors and the parents or guardians of such minors.”
You cannot build this without verifying and binding the parent‑child relationship. That is identity infrastructure.
The bill requires:
“a screentime limit across covered devices.”
Cross‑device enforcement is identity propagation. It requires shared identifiers, shared permissions, and shared enforcement logic.
To enforce limits “for minors,” the system must classify the user as a minor and link them to a parent. Device behavior changes based on identity classification.
That is identity‑conditioned access.
NIST must convene:
device manufacturers
international standards bodies
federal agencies
medical organizations
privacy boards
This is not a “tool for parents.” It is a multi‑agency, multi‑vendor identity ecosystem.
Even without the auto‑oppose triggers, the bill fails the PKO framework.
Here’s the breakdown.
1. Identity verification for minors? YES — required for enforcement.
2. Identity verification for parents? YES — required for authorization.
3. Persistent identity tokens for minors? YES (implied) — needed for cross‑device sync.
4. Identity bound to device use? YES — enforcement depends on identity classification.
5. Permissions propagated across devices/platforms? YES — core function of the bill.
Category 1 score: 5 out of 5 (all negative for PKO)
6. New data flows between devices/vendors? YES — devices must share enforcement data.
7. New data retention obligations? NO — not specified.
8. New data aggregation points? YES — identity/auth infrastructure across devices.
9. Surveillance creep risk? YES — architecture can be repurposed beyond “screen time.”
10. Third‑party vendor involvement? YES — device manufacturers, standards bodies, and federal agencies.
Category 2 score: 4 out of 5
11. Device‑level enforcement required? YES — required by the bill.
12. Cross‑device enforcement required? YES — required by the bill.
13. Interoperability between manufacturers/platforms? YES — federal standard + international standards bodies.
14. Control shifted from parents to vendors/federal agencies? YES — parents act through a federally defined architecture.
Category 3 score: 4 out of 4
15. Protects minors without identity binding? NO — identity binding is required.
16. Avoids persistent child identifiers? NO — architecture implies them.
17. Avoids identity‑conditioned access? NO — enforcement depends on identity classification.
18. Avoids surveillance expansion? NO — architecture enables expansion.
Category 4 score: 0 out of 4
Score: 4 / 18 → 22% → OPPOSE Auto‑Oppose Triggers: YES (all four)
The TOTAL Screen Time Act is not a parental‑control bill. It is a federal identity architecture bill disguised as a parental‑control bill.
Under the PKO framework, it fails because it:
requires identity binding
requires cross‑device enforcement
requires identity‑conditioned access
creates an interoperability ecosystem
expands surveillance architecture
shifts control from parents to vendors and federal agencies
PKO position: OPPOSE.