The Digital Age Assurance Act of 2026 would conscript Apple and Google's operating systems into a nationwide age-verification infrastructure for the internet — a technical fix for child online safety with real risks of over-censorship and surveillance.
---
What It Does
S.5090 creates a three-layer compliance system for age on the internet. First, operating system providers — in practice, Apple (iOS) and Google (Android) — must collect a user's age at device or account setup and place that user into one of a set of age brackets. Second, those OS providers must make that bracket available through a standardized real-time application programming interface. Third, app developers, website operators, and browser providers that offer content with age-based restrictions must query that API for the bracket signal whenever a covered app is launched or a covered site is accessed. The bill bans targeted advertising directed at children, prohibits the sale or transfer of children's age data collected through this system, and includes data minimization requirements — meaning the OS shares only the bracket (e.g., "adult," "13–15," "under 13") rather than the precise age. The FTC and state attorneys general have enforcement authority. Safe harbor provisions protect businesses that act in good faith on the signal they receive. The bill does not mandate independent identity verification of the age users enter — it relies on self-reporting at device setup.
---
The Real Story
The fight underneath this bill is about *where* to put the chokepoint for child internet access: each app individually, or the operating system itself. App-level age verification (requiring each platform like TikTok or YouTube to check IDs) has failed repeatedly because it's easy to circumvent and privacy-invasive. This bill pushes the job onto Apple and Google, making iOS and Android the gatekeepers. The tech industry dislikes this because it hands enormous power to two companies and makes them federal compliance agents. Civil liberties groups oppose it because treating developers as legally responsible whenever they receive a "minor" signal pushes them to restrict content beyond what the law requires, chilling legal speech for everyone.
---
Who Benefits
- Parents and child safety advocates who want a structural, not just voluntary, mechanism to stop children accessing age-inappropriate apps and content — the bill promises a non-duplicative single verification point rather than requiring parents to police each app separately.
- American Psychological Association and children's mental health organizations (named supporters include APA, Mission Kids Child Advocacy Center, Digital Defenders United, The Arc of New Jersey, New Jersey Children's Alliance) who argue exposure to age-inappropriate content and social media design is documented harm.
- Mid-tier app developers who currently bear the full burden of age verification individually — offloading it to the OS layer would reduce their compliance costs.
- Senator Andy Kim (D-NJ) and the bill's cosponsors — Senators Adam Schiff (D-CA), Cynthia Lummis (R-WY), and John Barrasso (R-WY) — who gain political credit for a bipartisan child safety bill in an election-relevant environment.
---
Who Gets Hurt
- Apple and Google would be legally required to build, maintain, and defend a real-time age-signaling API across their entire OS ecosystems — implementation costs, legal exposure, and competitive questions about how they each implement the API are unspecified.
- Teenagers and young adults face over-restriction: because "deemed knowledge" liability incentivizes developers to block anything ambiguous, legal content accessible to 16- and 17-year-olds could get swept up by platforms defaulting to the most restrictive behavior.
- Privacy-sensitive users of all ages would have their age category broadcast to every covered app and website they open — a new data point in a tracking ecosystem that already has too much information.
- Free-speech and civil liberties organizations (EFF is the most prominent named opponent) argue the entire law framework is unconstitutional — that mandating age gates creates barriers to information and expression that violate the First Amendment.
- Google (which opposed the California version), Chamber of Progress, and TechNet have all pushed back on the model law this bill is based on.
- Small and international app developers outside Apple/Google ecosystems who have limited ability to build compliance around a signal standard designed for the two dominant U.S. OS platforms.
---
Red Flags
- Self-reported age is the mechanism. The bill requires operating systems to ask users their age at device setup — but nothing in the sources indicates a hard identity verification requirement is mandated. A child can simply enter a false birthday, limiting the law's practical reach for the determined bad actor while still imposing all the compliance infrastructure on everyone else.
- "Deemed to know" liability trap. EFF warns that because developers who receive an age signal are treated as having "actual knowledge" of a user's age, they face legal incentive to over-restrict access to any content that could be problematic for minors — meaning legal, adult-oriented content could be blocked beyond what the law requires. This is a censorship-by-incentive dynamic.
- Apple and Google as federal age-surveillance infrastructure. The bill would require two private companies to build and maintain a real-time API broadcasting all their users' age categories to every app and website. There is no public debate in the bill text (per available sources) about what security requirements govern that data pipeline or what happens if it's breached.
- Duplication and conflict with the KIDS Act. The House-passed KIDS Act already contains age verification provisions now pending in the Senate. Two parallel Senate tracks could produce conflicting mandates or allow the Senate to cherry-pick only one — leaving the other's provisions unaddressed.
- Ambiguity on what happens with no signal. The bill does not (per sources) clarify how apps should treat users for whom no age signal is received — creating potential for developers to default to treating all signal-absent users as minors, effectively reversing the presumption of adulthood online.
- No specific federal penalty amounts confirmed in sources. California's analogous state law sets civil penalties per affected child, but those figures belong to that state law, not S.5090. The federal bill's specific penalty structure was not detailed in available sources, leaving enforcement teeth unclear.
---
Hidden Riders
- Anticompetitive practice restrictions are written into the bill. Given that Apple and Google *are* the OS gatekeepers the bill relies on, provisions restricting their anticompetitive conduct in administering the age signal system could shape their app store business practices far beyond the child safety goal — potentially limiting how they can preference or restrict apps that do or don't integrate the age API.
- Browser providers are pulled in. The bill covers not just apps but browser providers — meaning companies like Google (Chrome), Apple (Safari), Mozilla (Firefox), and Microsoft (Edge) would separately need to query age signals, imposing browser-level compliance requirements that go well beyond app stores.
---
Current Status
S.5090 was introduced on July 22, 2026 by Senator Andy Kim (D-NJ) with three cosponsors — Senators Adam Schiff (D-CA), Cynthia Lummis (R-WY), and John Barrasso (R-WY). The bill was read twice in the Senate and referred to the Senate Committee on Commerce, Science, and Transportation, which is the standard first step for a new Senate bill. No committee hearings, markups, or floor votes have been scheduled as of the bill's introduction. The bill is early in the legislative process — it has not yet cleared committee, meaning it must first be voted out of committee before being eligible for a full Senate floor vote. The House-passed KIDS Act, which covers overlapping ground, is simultaneously awaiting Senate action, creating a potential merger or competition dynamic that will define this bill's path forward.
---
Sources:
- [S.5090 - Digital Age Assurance Act of 2026 | Congress.gov](https://www.congress.gov/bill/119th-congress/senate-bill/5090?s=1&r=8)
- [Senators Kim, Schiff, Lummis, Barrasso Introduce Bill | Senator Andy Kim](https://www.kim.senate.gov/press_release/senators-kim-schiff-lummis-barrasso-introduce-bill-to-protect-children-online-through-new-age-reporting-requirements/)
- [New Bill: Senator Andy Kim introduces S.5090 | Quiver Quantitative](https://www.quiverquant.com/news/New+Bill:+Senator+Andy+Kim+introduces+S.+5090:+Digital+Age+Assurance+Act+of+2026)
- [S5090 U.S. Senate: Digital Age Assurance Act of 2026 (Introduced) | Amendment.app](https://www.amendment.app/oversight/federal/bill/s5090)
- [California Digital Age Assurance Act | Wikipedia](https://en.wikipedia.org/wiki/California_Digital_Age_Assurance_Act)
- [California Enacts Digital Age Verification Law | Alston & Bird](https://www.alstonprivacy.com/california-enacts-digital-age-verification-law/)
- [The KIDS Act Would Require Age Checks To Get Online | EFF](https://www.eff.org/deeplinks/2026/06/kids-act-would-require-age-checks-get-online)
- [Age Verification Is Coming For the Internet | EFF](https://www.eff.org/deeplinks/2025/12/age-verification-coming-internet-we-built-you-resource-hub-fight-back)
- [The KIDS Act clears House | NBC News](https://www.nbcnews.com/tech/tech-news/kids-internet-and-digital-safety-act-passes-house-free-speech-concerns-rcna352341)
- [Wave of Federal "Online Safety" Legislation Hits Congress | Davis Wright Tremaine](https://www.dwt.com/insights/2026/01/federal-online-safety-legislation-hits-congress)
- [FTC Issues COPPA Policy Statement on Age Verification | FTC](https://www.ftc.gov/news-events/news/press-releases/2026/02/ftc-issues-coppa-policy-statement-incentivize-use-age-verification-technologies-protect-children)
- [California's Digital Age Assurance Act: A novel parental control | AVPA](https://avpassociation.com/thought-leadership/californias-digital-age-assurance-act-a-novel-parental-control-but-its-not-age-verification/)
The Digital Age Assurance Act of 2026 would conscript Apple and Google's operating systems into a nationwide age-verification infrastructure for the internet — a technical fix for child online safety with real risks of over-censorship and surveillance.
---
Why now
The political pressure on Congress to "do something" about children online has been building for years, but hit a new peak in 2024-2025 after Jonathan Haidt's bestseller *The Anxious Generation* and a Surgeon General advisory calling for cigarette-style warnings on social media. California responded first, signing its own Digital Age Assurance Act (AB 1043) into law in October 2025, effective January 1, 2027 — making it a live national model that advocates immediately pushed Congress to copy. The House then passed the KIDS Act on June 29, 2026 (267–117), a sweeping children's internet safety package that put immediate pressure on Senate members to show a competing or complementary vehicle. S.5090 was introduced just weeks later, on July 22, 2026.
---
The real story
The fight underneath this bill is about *where* to put the chokepoint for child internet access: each app individually, or the operating system itself. App-level age verification (requiring each platform like TikTok or YouTube to check IDs) has failed repeatedly because it's easy to circumvent and privacy-invasive. This bill pushes the job onto Apple and Google, making iOS and Android the gatekeepers. The tech industry dislikes this because it hands enormous power to two companies and makes them federal compliance agents. Civil liberties groups oppose it because treating developers as legally responsible whenever they receive a "minor" signal pushes them to restrict content beyond what the law requires, chilling legal speech for everyone.
---
Red flags
▸ Self-reported age is the mechanism. The bill requires operating systems to ask users their age at device setup — but nothing in the sources indicates a hard identity verification requirement is mandated. A child can simply enter a false birthday, limiting the law's practical reach for the determined bad actor while still imposing all the compliance infrastructure on everyone else.
▸ "Deemed to know" liability trap. EFF warns that because developers who receive an age signal are treated as having "actual knowledge" of a user's age, they face legal incentive to over-restrict access to any content that could be problematic for minors — meaning legal, adult-oriented content could be blocked beyond what the law requires. This is a censorship-by-incentive dynamic.
▸ Apple and Google as federal age-surveillance infrastructure. The bill would require two private companies to build and maintain a real-time API broadcasting all their users' age categories to every app and website. There is no public debate in the bill text (per available sources) about what security requirements govern that data pipeline or what happens if it's breached.
▸ Duplication and conflict with the KIDS Act. The House-passed KIDS Act already contains age verification provisions now pending in the Senate. Two parallel Senate tracks could produce conflicting mandates or allow the Senate to cherry-pick only one — leaving the other's provisions unaddressed.
▸ Ambiguity on what happens with no signal. The bill does not (per sources) clarify how apps should treat users for whom no age signal is received — creating potential for developers to default to treating all signal-absent users as minors, effectively reversing the presumption of adulthood online.
▸ No specific federal penalty amounts confirmed in sources. California's analogous state law sets civil penalties per affected child, but those figures belong to that state law, not S.5090. The federal bill's specific penalty structure was not detailed in available sources, leaving enforcement teeth unclear.
▸ --
Who benefits
• Parents and child safety advocates who want a structural, not just voluntary, mechanism to stop children accessing age-inappropriate apps and content — the bill promises a non-duplicative single verification point rather than requiring parents to police each app separately.
• American Psychological Association and children's mental health organizations (named supporters include APA, Mission Kids Child Advocacy Center, Digital Defenders United, The Arc of New Jersey, New Jersey Children's Alliance) who argue exposure to age-inappropriate content and social media design is documented harm.
• Mid-tier app developers who currently bear the full burden of age verification individually — offloading it to the OS layer would reduce their compliance costs.
• Senator Andy Kim (D-NJ) and the bill's cosponsors — Senators Adam Schiff (D-CA), Cynthia Lummis (R-WY), and John Barrasso (R-WY) — who gain political credit for a bipartisan child safety bill in an election-relevant environment.
• --
Who gets hurt
• Apple and Google would be legally required to build, maintain, and defend a real-time age-signaling API across their entire OS ecosystems — implementation costs, legal exposure, and competitive questions about how they each implement the API are unspecified.
• Teenagers and young adults face over-restriction: because "deemed knowledge" liability incentivizes developers to block anything ambiguous, legal content accessible to 16- and 17-year-olds could get swept up by platforms defaulting to the most restrictive behavior.
• Privacy-sensitive users of all ages would have their age category broadcast to every covered app and website they open — a new data point in a tracking ecosystem that already has too much information.
• Free-speech and civil liberties organizations (EFF is the most prominent named opponent) argue the entire law framework is unconstitutional — that mandating age gates creates barriers to information and expression that violate the First Amendment.
• Google (which opposed the California version), Chamber of Progress, and TechNet have all pushed back on the model law this bill is based on.
• Small and international app developers outside Apple/Google ecosystems who have limited ability to build compliance around a signal standard designed for the two dominant U.S. OS platforms.
• --
What it does
S.5090 creates a three-layer compliance system for age on the internet. First, operating system providers — in practice, Apple (iOS) and Google (Android) — must collect a user's age at device or account setup and place that user into one of a set of age brackets. Second, those OS providers must make that bracket available through a standardized real-time application programming interface. Third, app developers, website operators, and browser providers that offer content with age-based restrictions must query that API for the bracket signal whenever a covered app is launched or a covered site is accessed. The bill bans targeted advertising directed at children, prohibits the sale or transfer of children's age data collected through this system, and includes data minimization requirements — meaning the OS shares only the bracket (e.g., "adult," "13–15," "under 13") rather than the precise age. The FTC and state attorneys general have enforcement authority. Safe harbor provisions protect businesses that act in good faith on the signal they receive. The bill does not mandate independent identity verification of the age users enter — it relies on self-reporting at device setup.
---
Hidden riders
- Anticompetitive practice restrictions are written into the bill. Given that Apple and Google *are* the OS gatekeepers the bill relies on, provisions restricting their anticompetitive conduct in administering the age signal system could shape their app store business practices far beyond the child safety goal — potentially limiting how they can preference or restrict apps that do or don't integrate the age API.
- Browser providers are pulled in. The bill covers not just apps but browser providers — meaning companies like Google (Chrome), Apple (Safari), Mozilla (Firefox), and Microsoft (Edge) would separately need to query age signals, imposing browser-level compliance requirements that go well beyond app stores.
---
Precedent
COPPA (Children's Online Privacy Protection Act, 1998) was the first federal attempt to protect children online; it required parental consent for data collection from under-13 users but didn't touch content access and was widely worked around via age self-attestation (children clicking "I am 13" on signup pages). Congress has been trying to upgrade it ever since: COPPA 2.0 and the Kids Online Safety Act cleared the Senate 91–3 in July 2024 but stalled in the House when Republicans raised First Amendment concerns and killed a planned markup. California's Digital Age Assurance Act (AB 1043), signed October 2025 and effective January 1, 2027, is the direct model for S.5090 — moving the burden from platforms to the OS layer is the structural innovation this bill federalizes. No OS-level age gating system has yet been tested in court.
---
Current status
S.5090 was introduced on July 22, 2026 by Senator Andy Kim (D-NJ) with three cosponsors — Senators Adam Schiff (D-CA), Cynthia Lummis (R-WY), and John Barrasso (R-WY). The bill was read twice in the Senate and referred to the Senate Committee on Commerce, Science, and Transportation, which is the standard first step for a new Senate bill. No committee hearings, markups, or floor votes have been scheduled as of the bill's introduction. The bill is early in the legislative process — it has not yet cleared committee, meaning it must first be voted out of committee before being eligible for a full Senate floor vote. The House-passed KIDS Act, which covers overlapping ground, is simultaneously awaiting Senate action, creating a potential merger or competition dynamic that will define this bill's path forward.
---
Sources:
- [S.5090 - Digital Age Assurance Act of 2026 | Congress.gov](https://www.congress.gov/bill/119th-congress/senate-bill/5090?s=1&r=8)
- [Senators Kim, Schiff, Lummis, Barrasso Introduce Bill | Senator Andy Kim](https://www.kim.senate.gov/press_release/senators-kim-schiff-lummis-barrasso-introduce-bill-to-protect-children-online-through-new-age-reporting-requirements/)
- [New Bill: Senator Andy Kim introduces S.5090 | Quiver Quantitative](https://www.quiverquant.com/news/New+Bill:+Senator+Andy+Kim+introduces+S.+5090:+Digital+Age+Assurance+Act+of+2026)
- [S5090 U.S. Senate: Digital Age Assurance Act of 2026 (Introduced) | Amendment.app](https://www.amendment.app/oversight/federal/bill/s5090)
- [California Digital Age Assurance Act | Wikipedia](https://en.wikipedia.org/wiki/California_Digital_Age_Assurance_Act)
- [California Enacts Digital Age Verification Law | Alston & Bird](https://www.alstonprivacy.com/california-enacts-digital-age-verification-law/)
- [The KIDS Act Would Require Age Checks To Get Online | EFF](https://www.eff.org/deeplinks/2026/06/kids-act-would-require-age-checks-get-online)
- [Age Verification Is Coming For the Internet | EFF](https://www.eff.org/deeplinks/2025/12/age-verification-coming-internet-we-built-you-resource-hub-fight-back)
- [The KIDS Act clears House | NBC News](https://www.nbcnews.com/tech/tech-news/kids-internet-and-digital-safety-act-passes-house-free-speech-concerns-rcna352341)
- [Wave of Federal "Online Safety" Legislation Hits Congress | Davis Wright Tremaine](https://www.dwt.com/insights/2026/01/federal-online-safety-legislation-hits-congress)
- [FTC Issues COPPA Policy Statement on Age Verification | FTC](https://www.ftc.gov/news-events/news/press-releases/2026/02/ftc-issues-coppa-policy-statement-incentivize-use-age-verification-technologies-protect-children)
- [California's Digital Age Assurance Act: A novel parental control | AVPA](https://avpassociation.com/thought-leadership/californias-digital-age-assurance-act-a-novel-parental-control-but-its-not-age-verification/)
What to watch
The most consequential near-term decision is whether the Senate folds S.5090's provisions into the KIDS Act already passed by the House, or attempts to advance it as a standalone bill through the Commerce, Science, and Transportation Committee. If the Senate uses the KIDS Act as the vehicle, S.5090's specific OS-layer mechanism could be merged, modified, or dropped in conference. The bill's bipartisan sponsorship (two Democrats, two Republicans) is a real political asset in a Senate where children's internet safety is one of the few issues that still crosses party lines. Citizens watching this bill should pay attention to Commerce Committee hearings and whether EFF or other civil liberties groups file preemptive First Amendment challenges — that legal track could run parallel to the legislative one and ultimately determine the law's fate.
---
Follow this bill
This decode is a snapshot. Bills change. Get emailed when this one is amended, voted on, or signed.
No spam. Unsubscribe anytime.
LegisPlain is free. Decoding costs aren't. Support us so we can support you.