The legislation, introduced by Senators Andy Kim, Cynthia Lummis, Adam Schiff, and John Barrasso, was referred to the Senate Committee on Commerce, Science, and Transportation on July 22, 2026. It marks a dangerous escalation from California's state-level age-signaling law, transforming a voluntary code into a federal mandate that controls how every citizen accesses information. This is not about parental oversight; it is about constructing a persistent identity checkpoint that will be used to control user behavior as more surveillance is activated.
Key points:
The architecture of this bill is deceptive. On the surface, it appears to offer a privacy-safe solution where users simply "indicate the date of birth and age of the user" to their operating system. The system then broadcasts only an age bracket, defined as "non-personally identifiable data." This is the front door, designed to reassure the public. However, the back door is where the true threat lies. The operating system cannot be used without an account, and that account is tied to a permanent identity, not a local profile. This is a radical shift from current computing models where users can operate devices without mandatory cloud-linked identities.
The brackets themselves are a ruse. The federal bill uses categories of under 13, 13-15, 16, and 17+. California's version uses under 13, 13-16, 16-18, and 18+. By stopping at 17+, the federal signal cannot distinguish a 17-year-old from a 20-year-old. For any website that must comply with state laws requiring an 18+ threshold, this signal is useless. The site will need "something further," which routes straight back to conventional ID check verification. The bill builds the plumbing for these checks while pretending they are unnecessary.
Senator Lummis has pitched the bill as a privacy-safe option, stating, "By keeping government IDs and facial scans out of the equation, the Digital Age Assurance Act gives parents real protection for their children." This is a carefully crafted lie. While Section 10 of the bill says nothing shall require the collection of government IDs, biometrics, or facial age estimation, this assurance is hollow. Section 3(d) contains a trap that destroys that protection. It states that where an OS provider receives "clear and convincing information" that a user's real age differs from the stated bracket, the provider "shall verify the age of the user."
The bill never specifies how this verification should occur, but it is a clear instruction to find a way. The "clear and convincing" standard, a legal threshold normally reserved for courts, is here applied by private companies to their own inferences. There is nothing in the text prohibiting behavioral profiling to determine if a user acts older or younger than their signal. A developer who has this "clear and convincing information" is legally mandated to transmit it upstream to the operating system provider, triggering the verification duty. This is a reporting channel for surveillance, not a protection mechanism.
The bill offers lip service to privacy by banning the sale of bracket data and its use for targeted advertising. However, the exceptions swallow the rule. The assurance in Section 10(5) opens with the words "except as provided in sections 3, 4, and 5." Those sections contain every operative requirement in the bill. The privacy protections are subordinate to the operational demands of the surveillance system.
Furthermore, Section 13 preserves state laws that are "at least as protective of individuals," displacing nothing. This means the growing threat of state age-verification digital ID laws, which require document uploads or face scans, remains fully intact. This federal bill is designed to be the national plumbing that makes those state regimes easy to enforce. It invites states to build on top of the federal backbone, creating a patchwork of surveillance where the federal government provides the identity layer and states provide the restrictions.
The constitutional violations are glaring. Minors hold First Amendment rights of their own, a fact established in Brown v. Entertainment Merchants Association (2011), which rejected the idea that the state may deputize parental authority as a general instrument of speech control. Anonymous speech and anonymous reading are protected, but this bill installs a declared-age checkpoint under both, baked into the operating system. Adults would get bracketed too, as the architecture must be built for the entire population to sort the minority who are minors. The entire population is subjected to a digital leash to police the few, and the fine structure, up to $7,500 per intentional violation per child, will push companies to verify ages through documents and face scans rather than take a declaration at face value. That is the hidden intention. Verification requires sensitive data, and sensitive data eventually leaks. The system Lummis promised to keep out is the system this bill will inevitably deliver.
Sources include: