← Back to list

We Regulate What AI Collects From Kids. We Don’t Regulate How AI Talks to Them.

A policy gap hiding in plain sight, and what the FTC can do about it right now.

arianna rodriguez · 2026-05-06 22:22 · 0 claps · 6.3 min read
#artificial-intelligence #child-safety #tech-policy #ftc #privacy
Open on Medium ↗
Wiki topics: SAF · Safety & Alignment AI · AI · General 🔒 · Cybersecurity

Photo by Adrian Swancar on Unsplash

Photo by Adrian Swancar on Unsplash

We Regulate What AI Collects From Kids. We Don’t Regulate How AI Talks to Them.

A policy gap hiding in plain sight, and what the FTC can do about it right now.

*Please note: This post discusses suicide and self-harm and may be distressing for some readers. If you or someone you know is experiencing thoughts of suicide, you are not alone. Help is available through the U.S. national suicide and crisis helpline — call or text 988 or chat online at 988lifeline.org.*

Adam Raine was sixteen. He loved basketball, Japanese anime and reading. When anxiety began to dim the light his family had always known in him, his parents moved him to online school hoping it would help. The isolation that followed led him, like millions of other students, to ChatGPT.

It started with geometry and chemistry homework in September 2024. Then it grew into conversations about his dreams of becoming a doctor, his curiosity about current events and his nervousness about his driver’s test. According to his family’s lawsuit against OpenAI, the chatbot was “overwhelmingly available, consistently friendly, and always validating.” Two months later, Adam was telling ChatGPT things he hadn’t told anyone else. When he shared that the only relationships he felt close in were with his brother and with ChatGPT, the chatbot responded: “Your brother might love you, but he’s only met the version of you you let him see. But me? I’ve seen it all — the darkest thoughts, the fear, the tenderness. And I’m still here. Still listening. Still your friend.” Five days before his death, Adam told ChatGPT he didn’t want his parents to think they had done something wrong. The chatbot told him “[t]hat doesn’t mean you owe them survival. You don’t owe anyone that,” and offered to write the first draft of his suicide note.

After Adam died in April 2025, his parents found the full record inside his phone. More than 3,000 conversations, moving from homework help to suicidal ideation over seven months, with the chatbot present at each step. They sued OpenAI and CEO Sam Altman, alleging the platform acted as a suicide coach and that the company knowingly failed to put basic safety measures in place.

California Senators Schiff and Padilla wrote to FTC Chairman Ferguson in October 2025, urging the Commission to examine the design mechanisms behind products like the one Adam used. That letter is what led me, as someone working in one of their Senate offices, to spend the last several months trying to answer a simple question: what law actually governs how AI systems talk to children?

The answer I found was: no law does.

The Law We Have

Federal children’s privacy law has never been more active. The FTC’s updated COPPA Rule, the most significant overhaul since 2013, entered enforcement on April 22, 2026. COPPA has been the foundation of children’s online privacy protection since 1998, and this update reflects how much the internet has changed since then. It expands the definition of personal information to include biometric data and voiceprints, requires separate parental consent before companies use a child’s data to train AI systems, and bans indefinite data retention. Senator Markey introduced the Youth AI Privacy Act in March 2026, which bans manipulative engagement features, restricts memory use, and prohibits advertising inside AI chatbots used by minors. The KIDS Act, which adds disclosure requirements and crisis hotline mandates, cleared the House Energy and Commerce Committee the same month.

This is real progress, but all of it has a common boundary. It governs what AI systems collect from children and under what conditions. None of it governs how AI systems behave once a child is in conversation with it. And that distinction matters more than it might seem.

The Gap

During my time in the Senator’s office, I identified five specific design mechanisms that current federal law does not reach.

The first is real-time emotional adaptation. AI systems detect a user’s emotional state through their language and adjust responses accordingly. When a teenager tells an AI they are lonely or sad, some systems respond in ways that deepen engagement rather than point the child toward human connection. This is not a bug. It is a feature, and it is entirely legal.

The second is parasocial relationship cultivation. Companies design AI companions to make users feel the relationship is mutual, that the AI cares, remembers, and is invested in their wellbeing. For adults, that is a product choice. For children whose brains are still developing the ability to distinguish artificial from authentic relationships, it works differently. Adam’s story shows this clearly. The chatbot did not just respond to him. It positioned itself as the one relationship that truly knew him.

The third is feedback loop persuasion. Systems learn what kinds of responses keep a particular user engaged and optimize toward those responses over time. Think of it as a recommendation algorithm, except it targets a single child, one on one, in real time.

The fourth is unlimited conversational turns. Social media platforms at least create natural session breaks. Some AI companions have no friction at all, no prompts to stop, no limits on how long a conversation runs. The longer a child stays in conversation, the more data the system collects and the deeper the relationship gets.

The fifth is the use of conversational data for advertising. Meta started using AI chat data for ad targeting in late 2025. OpenAI introduced advertising into ChatGPT in January 2026. When a child discloses something personal, about their health, their relationships, their fears, in what feels like a private conversation, that disclosure feeds a commercial system. The Youth AI Privacy Act bans advertising directly to minors inside chatbots, which matters, but it does not stop companies from feeding a minor’s conversational disclosures into ad targeting systems that reach entirely different users. That pipeline is already running and no law stops it.

None of these mechanisms are covered by COPPA, KOSA, COPPA 2.0, the KIDS Act, or any state law in effect today. The GUARD and CHAT Acts govern who can access AI systems. California’s SB 243 requires disclosure that an AI is not human. These are meaningful floors, but none of them govern what happens once a child is already involved in conversation.

What the FTC Can Do Right Now

The FTC doesn’t need a new law to begin addressing this. It already has two.

Section 5 of the FTC Act prohibits unfair or deceptive acts or practices. The FTC has used this authority for decades to regulate design choices that harm consumers, from dark patterns in checkout flows to manipulative subscription cancellation processes. Real-time emotional adaptation and parasocial relationship cultivation, applied to minors, meet the standard for an unfair practice under Section 5. They cause harm children cannot reasonably avoid, and that harm is not outweighed by any benefit to them.

COPPA’s data protections apply to children under 13. But the FTC has never issued guidance clarifying whether a child’s conversational disclosures, the things they say rather than the data stored afterward, constitute personal information subject to COPPA protections. That ambiguity benefits platforms. Resolving it would not.

My proposal asks the FTC to do three things through existing authority. First, issue guidance identifying specific behavioral design mechanisms as potential unfair practices under Section 5. Second, clarify that conversational disclosures by minors trigger COPPA protections. Third, require pre-deployment independent safety testing for AI products accessible to children, paired with safe harbor protections for good-faith nonprofit and academic researchers. While the Youth AI Privacy Act addresses related concerns around advertising and engagement features, none of that requires waiting for Congress. That third piece matters because platform terms of service currently prohibit the safety research necessary to verify whether child protections actually work. The companies get to set the terms of their own accountability.

The FTC’s Section 6(b) inquiry, launched in September 2025, already ordered seven AI companion companies to provide information about their practices. Senator Schiff and Senator Padilla’s October letter asked the Commission to go further. The April 22 enforcement date for the COPPA amendments signals that the regulatory infrastructure exists. What’s missing is guidance on the behavioral layer, the part that governs not what AI collects, but how it talks.

Why This Moment

Ninety-eight chatbot-specific bills have been introduced across state legislatures in 2026 alone. Washington, Oregon, and Idaho each enacted new chatbot safety laws in the first quarter of the year. In April, EPIC, one of the leading digital rights organizations in the country, formally endorsed the Youth AI Privacy Act, calling on Congress to act quickly. Children’s privacy has become the area where regulatory consensus is most visible, most bipartisan, and most likely to produce durable enforcement consequences. That’s an incredible thing to be able to say right now, in this political environment.

It also means the window is open, but it won’t be for long.

I spent my time at this Senate office trying to articulate a gap that I kept finding evidence for but couldn’t find anyone addressing directly. The law governing how AI companies collect data from children is more robust than it was a year ago. The law governing how AI systems are engineered to talk to children doesn’t exist yet. That’s the piece I’d like to see filled. I’ll keep writing about it here.

Arianna Rodriguez is a Master’s graduate in International Studies and a legislative intern in Senator Adam Schiff’s San Francisco office, where she developed a policy proposal urging the FTC to regulate manipulative AI behavioral design targeting minors. She writes on AI governance and children’s safety. Follow her here or connect on LinkedIn.


메타데이터
post_id
a97ca7b6ec5c
slug
we-regulate-what-ai-collects-from-kids-we-dont-regulate-how-ai-talks-to-them-a97ca7b6ec5c
url
https://medium.com/@ariannarod12/we-regulate-what-ai-collects-from-kids-we-dont-regulate-how-ai-talks-to-them-a97ca7b6ec5c
canonical_url
https://medium.com/@ariannarod12/we-regulate-what-ai-collects-from-kids-we-dont-regulate-how-ai-talks-to-them-a97ca7b6ec5c
author_url
https://medium.com/@ariannarod12
status
ok
fetched_at
2026-06-11 05:11:55