The Kids’ Online Safety State Patchwork Status

As most state legislatures have adjourned for the year, they’re leaving behind an increasingly complicated patchwork of rules that are aimed at keeping young Internet users safe but create a variety of obligations, prohibitions, and compliance burdens for startups—especially for startups that don’t intend to, or knowingly interact, with young users.

Many of the proposals debated and, in some cases, passed at the state level this year focus on app store and operating system age verification mandates, outright bans for young users on Internet platforms, parental consent requirements for social media sites, chatbot regulations, and rules dictating the design of tech products. For startups, this could mean significant compliance costs, increased privacy and security risks, and potentially ruinous legal liability. 

Age verification comes with tradeoffs

Age verification mandates, app store accountability acts, design requirements, outright bans, and parental consent are common tools policymakers reach for in an attempt to make the Internet safer for children. These online safety measures are first predicated upon knowing the age of a given Internet user. If they don’t require age verification specifically, many measures include definitions of what it means to “know” the age of a user in ways that will, in practice, lead Internet services to rely on age verification technologies. 

These tools often come with tradeoffs: users have to hand over more—and likely more sensitive—data or risk limiting their ability to access information and express themselves online. That required disclosure carries an increased risk of harmful data breaches, and also risks pushing users who can’t or won’t comply to less-regulated, less safe corners of the Internet. For startups, they can create significant costs, erect operational hurdles, and dampen competitiveness. Policymakers must be honest about these unintended consequences, which can be much more burdensome to startups and small businesses, especially as a patchwork of state regulations pops up. 

Shift to app stores and operating systems 

Policymakers at the state level are passing app store accountability acts—laws that shift the responsibility of enforcing age verification onto app stores and require app developers to rely on age signals from the app stores. 

Currently, four states have passed such acts. Last year, Texas passed SB 2420, which requires app stores to verify users’ ages and obtain parental consent before minors can download mobile apps or make in-app purchases. A federal judge found that the law likely violates the First Amendment and paused enforcement of the law, but the Fifth Circuit Court of Appeals later ruled that Texas is allowed to enforce the law until judges rule on the law’s validity. Alabama, Louisiana and Utah advanced similar bills: HB 161, HB 977,  and HB 498, respectively. Utah’s act amended an earlier bill to allow app developers to voluntarily opt out or block a minor’s account from accessing their apps. The four app store accountability acts are structured similarly to federal legislation level that would eliminate state patchwork but still carries the same trade-offs. 

These laws also create some provisions for family accounts, which help protect access to those of age and bar access for underage individuals in households with both adults and minors. However, app stores face technical compliance challenges of checking that a minor’s account is linked to a legitimate parent’s or guardian’s account, which may require intrusive, continuous re-authentication. Furthermore, most of the Internet is accessible through websites—not just apps—so users can easily bypass blocked content on a web browser. 

Other states have taken a slightly different approach by shifting the burden of age verification from app stores onto operating systems (like Apple iOS for iPhones and Microsoft Windows for personal computers). California’s AB 1043—which passed into law in 2025—and Illinois’s HB 5511 hold operating systems accountable, meaning that device manufacturers are responsible for verifying age bracket signals and will be deemed to have actual knowledge of which users are minors. But operating system-level age verification fails to account for communal devices, like a family’s shared tablet or a smart television. A device configured by a parent would grant children unrestricted access to adult material; conversely, a minor’s profile would bar adults from features they should be able to use. Operating system age verification grants problematic access by assuming there is a user of only one age on a given device. 

Both the app store and the operating system approaches potentially infringe on First Amendment rights by limiting access to lawful speech. The acts also carry privacy risks by forcing the collection of age data, which increases the possibility of data breaches by bad actors and raises costs that could be passed onto consumers. 

Outright bans and parental consent for social media 

Some states have attempted to enact outright bans on social media accounts for minors and restrictions that require parental consent to open social media accounts. The strictest proposal, Texas’s HB 186, proposed a full ban on social media use for children under 18 but failed to become law after intense public pushback. HB 3 in Florida is in effect but currently faces a lawsuit on First amendment grounds. Still active legislation that would create bans includes H 5295 in Massachusetts, which would ban social media accounts for children under the age of 16. H 5366 in Massachusetts would prohibit minors under 14 from making social media accounts. 

Instead of outright bans, other states are seeking parental approval for social media accounts for minors. Mississippi passed HB 1126, and Tennessee passed HB1891, both requiring parental consent before a minor under 18 creates a social media account. Ohio passed a similar law, HB 33, that mandates parental approval for children under 16. 

Similar comparable parental consent laws have faced legal scrutiny. Just five months after being passed, a federal judge permanently blocked SB 396 in Arkansas—which required parental consent for minors to create social media profiles—due to First Amendment violations. Louisiana’s SOCIAL Act was also blocked due to free speech concerns and overly broad language. That law required large social media companies to verify age and ensure parental permissions for users under 16 to create and maintain accounts. 

States pivot from bans on access to dictating the structure of products

Some states are imposing design-side mandates on social platforms, including data minimization, privacy-by-default settings, and bans on aspects of algorithmic feeds such as infinite scroll and “streaks”; many of these bills also include parental consent directives. For startups, laws like these are very costly to implement, and they create incentives to over-moderate (taking down legal content in an attempt to avoid expensive litigation and fines). 

California’s SB 976 and New York’s S 7694 are prime examples of a design-side mandate; they prohibit algorithmic feeds and instead mandate chronological feeds.  While these laws are facing challenges in federal court, other states have attempted to follow the lead of California and New York. Pending legislation in Massachusetts under SB 3164 would disable algorithmic feeds, autoplay features, and infinite scrolling for minors; mandate usage reminders; and turn off push notifications at night. 

In failed attempts to limit algorithmic feeds and impose other restrictions on social media for children, SB 611 in Arkansas and SB854 in Virginia were both blocked from taking effect due to legal challenges. Colorado’s HB 24-1136 and a Minnesota law require pop-up warnings on social media sites, but a federal judge blocked them from taking effect. Washington attempted to pass two bills, SB5708 and HB1834, both of which failed to advance. 

[Chatbots and AI: State lawmakers have been quick to legislate around chat-based AI interfaces. In 2026, almost 100 bills regulating chatbots have been introduced across states and there are well over a dozen states with enacted rules. These are often aimed at safety for young users specifically and some necessitate determining the age of the user, meaning they carry tradeoffs discussed above. Engine earlier examined chatbot bills in a recent blog post on state AI legislation.

What comes next

The magnitude of state-level action on kids’ safety bills shows the need for a unified, federal framework that takes unintended consequences—especially of both explicit and implicit age verification requirements—into account. Policymakers should address the growing state patchwork of legislation, which is especially harmful to startups, who have less resources than large tech incumbents to comply with complex regulations across borders. 

At the federal level, Congress is considering several pieces of legislation that, unfortunately, largely fail to grapple with the tradeoffs in this space. In June, the House of Representatives passed a package called the KIDS Act, an omnibus composed of multiple bills, including legislation on kids’ safety, privacy updates, and AI chatbot rules. Some of the component bills differ starkly from the Senate versions, including the Kids Online Safety Act, where senators insist on including a “duty of care” provision that will push Internet platforms to remove legal (and in some cases important) user content out of an abundance of caution. All of the bills in both the House and Senate create incentives for companies to perform age verification by holding them liable if they “should have known” that a user was a minor. Without a uniform approach to online safety bills, startups will struggle to comply, wasting their limited resources instead of furthering American innovation. 

In August, litigation over youth online safety involving most state attorneys general and Meta led to a settlement that includes many of the requirements in the above discussed state bills, and is likely to factor heavily in the debate moving forward. The company agreed to age verification and design measures limiting the availability of certain features, like beauty filters and like counts, creating the ability to opt out of algorithmic recommendations and autoplay, and restricting time of use and timing of notifications. Meta used the settlement structure to try to get its competitors to also adopt these terms. The settlement is likely to frame the debate going forward although it extends beyond changes that have enough support to become federal law—and likely what’s permissible under the First Amendment.

Previous
Previous

Startup News Digest 09/11/26

Next
Next

#StartupsEverywhere: Coupeville, Wash.