The Youth AI Privacy Act is a proposed federal bill that would stop AI companies from training on, profiling from, or selling your child's chatbot conversations, and on August 5, 2026 the Senate Commerce Committee voted to advance it. It is not law yet. It cleared one committee and still needs a full Senate vote, a House version, and a presidential signature before any of its rules bind a single company, so treat what follows as a proposal that describes where the fight is heading, not a protection you can rely on today.
For parents, the practical questions are simpler than the legislative process: does ChatGPT train on kids chats right now, what happens to the messages a child types into an AI companion, and what can you actually change this week regardless of any bill. This post answers those, explains the one part of the proposal that even privacy advocates are worried about, and separates what is real today from what is still a promise on paper.
What the Youth AI Privacy Act would actually do
The bill targets one thing above all: how AI chatbot data for minors is stored, reused, and monetized. Senator Ed Markey introduced the Youth AI Privacy Act earlier in 2026, and the version the Senate Commerce Committee advanced would bar AI companies from using a known minor's personal data to train their models, ban advertising aimed at minors inside chatbots, and forbid engagement features like push alerts designed to keep children coming back.
It would also narrow what a company is allowed to do with a child's data at all, restricting use to directly answering the minor or addressing a safety concern, and it would require the chatbot to repeatedly remind young users that they are not talking to a human. The Electronic Frontier Foundation, which analyzed the text, called these the bill's positive privacy provisions, singling out the limits on using chat logs for training, profiling, and disclosure to other companies.
The committee did not pass the bill unchanged. During markup, an amendment from Senator Ted Cruz reshaped the retention rules: the reported version keeps a 30 day default deletion window but lets parents opt out of automatic deletion or choose a different retention period. Markey opposed the change, warning that without a firm outer limit companies would push families toward the longest possible setting. Reporting on the markup also notes that lawmakers weakened the bill's private right of action, the clause that would have let parents and guardians sue directly, which leaves enforcement mainly with regulators such as the Federal Trade Commission and state attorneys general.
Why chat logs are the whole fight
Every meaningful provision in this bill circles back to one question: who keeps the chat logs, and what are they allowed to do with them. A chat log is not just a transcript. It is a record of what a child worried about at midnight, what they searched for help with, the names of their friends, their school, their insecurities, and the wording they used to describe all of it. That record is exactly what a model can be trained on, what a profile can be built from, and what a third party might pay for.
The EFF framed the core protection as prohibiting companies from using chat logs, including for training, profiling, and disclosing them to other companies for training. That is the heart of the matter. Once a conversation leaves a child's screen and lands in a company's training pipeline, it is very hard to pull back out, because model weights do not come with a delete button for one person's sentences.
There is a catch that parents should read carefully. The bill carves out an exception that lets companies collect a known minor's data to test for and address harm to users, and the EFF flagged that the term harm is not clearly defined. A vague safety exception can quietly become a wide door, because almost any data collection can be described as protecting the user.
The bill's protections apply to a known minor. That word known is doing heavy lifting, and it is the reason the next section exists.
The age-verification tradeoff, or the privacy paradox
Here is the contradiction that even supporters of child safety are uneasy about: to give minors special protection, a service first has to know who is a minor, and the only way to know that is to check the age of everyone. The EFF named this the privacy paradox. A law meant to reduce surveillance of children can end up requiring more identity checks for every single user, adult and child alike.
Age gates are not free. To prove someone is over or under 18, a service often asks for a government ID, a face scan, or a credit card, and that information has to be collected, transmitted, and stored somewhere. The EFF argues the cleaner answer is to give strong privacy protections to all users, so no service needs to sort people by age in the first place. Whether Congress agrees is an open question, and it is one worth watching as the bill moves.
For a parent, the takeaway is not to panic about the paradox but to understand it. A future where kids get protected only after proving their age is also a future with more identity data floating around. That is a real cost, and it is fair to weigh it against the benefit.
What is real today versus what is still a proposal
Nothing in the Youth AI Privacy Act binds any company yet. As of August 2026 it has cleared the Senate Commerce Committee and now awaits a vote by the full Senate, and it would still need to pass the House and be signed before it takes effect. Bills that clear committee can stall for months or die entirely, so no parent should assume these rules are protecting their child right now.
What is real today is whatever each chatbot's own settings and terms say. That means the burden currently sits with you, not with a federal rule. The good news is that the biggest levers, turning off training and limiting retention, are things many services already let you control, if you know where to look.
Does ChatGPT train on kids chats right now?
It depends on the account and the settings, which is exactly why the bill exists. Consumer chatbots generally allow conversations to be used to improve their models unless you turn that off, and controls vary by product and by whether the account is a personal, teen, or enterprise one. Because a child using a parent's logged-in account looks like an adult to the service, the protections a company reserves for teen accounts may never apply. The practical move is to open the data controls yourself and switch off model training rather than assume a child is covered.
How the approaches to kids' chat data compare
The choices in front of a parent fall into three broad buckets: rely on the proposed law, rely on a mainstream chatbot's own settings, or use a tool built so that personal data is isolated per user and never trained on by default. Each has a different answer to the question that matters, which is what happens to the words your child types.
| What happens to the chat data | Youth AI Privacy Act (proposed) | Typical consumer chatbot today | Private-by-architecture tool |
|---|---|---|---|
| Used to train the AI model | Would be banned for known minors, if enacted | Often allowed unless you opt out in settings | Not trained on user data by design |
| Built into an ad or marketing profile | Advertising to minors would be prohibited | Possible, depending on the product and terms | No advertising model attached to your data |
| Legal force behind it | None yet: passed one committee, not law | Governed by the company's own policy | Enforced by how the system is built, per-user isolation |
| Who has to act | Regulators, after any future passage | You, by changing the settings yourself | You choose the tool, isolation is the default |
No single row makes the decision. A mainstream chatbot with training switched off can be a perfectly reasonable choice, and the proposed law, if it passes, would raise the floor for everyone. The table is meant to show that the safest posture does not wait on a bill: it comes from either configuring the tools you use or picking ones that isolate personal data by default.
What parents can do now, regardless of the bill
You do not need to wait for Congress. A handful of settings and habits cover most of the risk the bill is trying to address.
- Open the AI app's data controls and turn off using your conversations to train or improve the model. On most consumer chatbots this is a single toggle, often labeled something like improve the model for everyone.
- Set up a proper account for your child instead of letting them use yours. A service can only apply teen protections to an account it knows belongs to a teen.
- Turn on chat history deletion or a short retention window where the app offers it, and clear old conversations periodically.
- Look for and use any export or delete-my-data option so you can remove a child's history if you switch services.
- Talk about what not to type: full name, home address, school, phone number, passwords, photos of themselves or friends, and anything about a mental-health crisis that belongs with a trusted adult or a hotline, not a bot.
- Prefer tools that state plainly that they do not train on your data, and read the one paragraph in their policy that says so rather than trusting a marketing headline.
Do the settings check together with your child, out loud. Kids who understand why a home address or a selfie should not go into a chatbot make better calls when a parent is not in the room.
Screenshot the training and retention settings after you change them. Apps reset preferences during updates, and a dated screenshot makes it quick to spot when a toggle has quietly flipped back on.
Where a private-by-architecture tool fits
The entire dispute in Washington comes down to a single design decision: who retains your conversations and whether they are used to train a model. That is the exact problem MemX was built around. MemX is a personal memory app for storing documents, photos, voice notes, and messages so you can ask a question later and get the answer with its source. It is built to be private by architecture: your data is isolated per user, encrypted at rest, kept under customer-managed keys, and not used to train models.
MemX is not a children's product and it is not COPPA-certified, so it is not a substitute for the account controls and supervision a child's chatbot needs. What it does show is that the consumer answer to this fight does not have to wait on a bill. When a tool treats no-training and per-user isolation as the default rather than a setting you have to find, the question of who profits from your conversations stops being your problem to police. That principle holds for a parent, a professional, or anyone who would rather their words not become someone else's training data.
The lesson of the Youth AI Privacy Act is not that a law will fix this soon. It is that data used for training is nearly impossible to claw back, so the choices you make about which tools you trust today matter more than the vote that has not happened yet.
Frequently asked questions
01Is the Youth AI Privacy Act a law yet?
No. As of August 2026 the Senate Commerce Committee advanced it on August 5, but it still needs a full Senate vote, House passage, and a presidential signature. Advancing out of committee is an early step, and nothing in the bill currently binds any company.
02Does ChatGPT train on kids chats?
It can, depending on the account type and settings. Consumer chatbots often use conversations to improve their models unless you opt out, and a child on a parent's logged-in account looks like an adult. Open the data controls and switch off model training to be sure.
03What would the bill do about AI chatbot data for minors?
As reported, it would bar training on a known minor's data, ban advertising to minors, restrict data use to answering the child or addressing safety, and set a 30 day default retention that parents can adjust. Reporting on the markup says lawmakers weakened the clause that would have let families sue directly.
04Is ChatGPT safe for kids?
There is no flat yes or no. ChatGPT and similar chatbots are not built as children's products, and by default many use conversations to improve their models unless you opt out. How safe it is comes down to the settings you choose: turn off model training, give your child their own account instead of yours, enable history deletion, and talk through what personal details should never go into a chatbot. Supervision and the right controls matter more than the app's name, which is also why lawmakers and the EFF are still debating how far a bill like the Youth AI Privacy Act should go.
05How do I stop an AI app from training on my child's conversations?
Open the app's data or privacy controls and turn off the option to use chats to train or improve the model, give your child their own account rather than yours, enable history deletion or a short retention window, and favor tools that state plainly they do not train on your data.
