The Kids Online Safety Act requires age verification. Age verification requires identity verification. Identity verification requires a government-linked digital ID system that logs every adult who accesses the internet. On February 10, 2026, 40 state and territory attorneys general asked Congress to build exactly that, and they framed it as protecting children.
The National Association of Attorneys General (NAAG) published a bipartisan letter urging Congress to advance the Senate version of KOSA over the House version, H.R. 6484. The coalition spans red and blue states. Tennessee Attorney General Jonathan Skrmetti and Pennsylvania Attorney General Michelle Henry Sunday both issued individual statements backing the push. Their core objection to the House version: it preempts state laws, weakens the duty of care platforms owe to minors, and strips states of enforcement authority they have already built. The Senate version preserves all of that. On paper, this is a fight over federalism. In practice, it is a fight over who controls the surveillance apparatus that age verification will create.
What Age Verification Actually Requires
No one in this debate is being honest about the technical implications. To verify that a user is over thirteen, or sixteen, or eighteen, a platform needs proof. Not a checkbox. Not a self-reported birthday. Proof. That means a device-level verification system tied to government-issued identification. A driver’s license scan, a passport upload, a biometric check, or a third-party identity service that cross-references your face against a government database.
Every one of those mechanisms creates a record. Someone, whether it is Apple, Google, a third-party age verification vendor, or the platform itself, now holds a verified link between your real identity and your online activity. Multiply that across every website, app, and platform subject to KOSA’s duty of care provisions, and you have not built child safety. You have built a national digital ID system with surveillance capabilities that would make any intelligence agency envious.
The Electronic Frontier Foundation flagged this trajectory in their 2025 year-end review, titling it “the year states chose surveillance over safety.” Multiple states passed age verification laws in 2025. The pattern is identical everywhere: invoke children, mandate ID checks, create infrastructure that applies to all users regardless of age. The bipartisan nature of the NAAG letter only reinforces the point. This is not a partisan project. Both parties want the infrastructure. They just disagree on who gets to operate it.
The Playbook Is Global
This is not an American invention. Vietnam shut down millions of bank accounts that failed to complete facial verification requirements, using financial access as leverage to force citizens into biometric databases. Australia moved to ban minors from social media entirely, a policy that requires age verification for everyone to determine who qualifies as a minor. The logic is circular by design: to protect some users, you must identify all users.
The domestic version adds another layer. Companies like Flock Safety are already selling drone and camera surveillance systems to private businesses and municipalities, normalizing persistent monitoring as a public good. KOSA’s age verification mandates would extend that normalization into every digital interaction. The physical world gets license plate readers. The digital world gets ID checkpoints.
The strongest rebuttal is that children are genuinely harmed online and legislators have an obligation to act. Social media platforms have failed to self-regulate. Internal documents from Meta, TikTok, and others have repeatedly shown that these companies understood the damage their products caused to minors and chose engagement metrics over safety. The attorneys general are not inventing a crisis. They are responding to one. Privacy-preserving age verification methods do exist in theory: zero-knowledge proofs, on-device age estimation, token-based systems that verify age without transmitting identity. The Senate version of KOSA does not mandate any specific verification technology, which leaves room for implementations that protect both children and privacy. Dismissing the entire effort as a surveillance plot risks abandoning children to platforms that have proven they will not protect them voluntarily.
That rebuttal deserves serious weight, and it has a structural flaw. The privacy-preserving technologies it relies on do not exist at scale. No major platform has deployed zero-knowledge age verification. No government has certified an age estimation system that does not create identity records. The theoretical possibility of privacy-safe compliance does not change the practical reality: every age verification system deployed so far has required identity disclosure. Legislation built on technology that does not exist yet is legislation built on trust. And the entities asking for that trust, state attorneys general and federal legislators, have not earned it on surveillance questions.
The bipartisan consensus here is the tell. Forty attorneys general from both parties cannot agree on anything except expanding the power of the state to monitor digital activity. That should tell you everything about what this is actually about. Child safety is real. The kids are genuinely being harmed. But the solution being proposed is not proportional to the problem. You do not build a national digital ID system to keep a thirteen-year-old off Instagram. You build a national digital ID system because you want a national digital ID system, and “protect the children” is the one argument that makes it politically impossible to oppose.
What This Means for Everyday People
If the Senate version of KOSA passes, platforms will need to verify user ages. That means you will be asked to prove who you are before accessing services you currently use anonymously. The verification might be a license scan, a face check, or a third-party service. Regardless of the method, the era of pseudonymous internet use moves closer to ending.
The infrastructure does not come with an expiration date. Once built, digital ID systems expand. They get applied to new contexts. They get shared across agencies and jurisdictions. The system designed to keep a thirteen-year-old off Instagram becomes the system that verifies your identity for every digital interaction. Forty attorneys general just asked Congress to lay the foundation. Whether you trust the people who will build on it next is a question worth answering before the concrete sets.
For inquiries and analysis contact laterstack@proton.me