Kids Online Safety Act (KOSA)
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
KOSA Age Verification + Inference
Section 2 of KOSA establishes the knowledge + inference standard for identifying minor users while balancing privacy and over-verification concerns. (1) Section 2 Knowledge Standard: (a) Covered platform must take reasonable steps to know or reasonably infer user age; (b) Higher standard than COPPA actual knowledge; (c) Lower standard than affirmative age verification; (d) Privacy-preserving inference encouraged; (e) Industry self-regulation per Section 9 Council guidance. (2) Section 2 Reasonable Steps Factors: (a) Risk of platform being accessed by minors; (b) Available technical capabilities; (c) Cost burden vs benefit; (d) User experience impact; (e) Privacy implications of verification method; (f) Accuracy vs over-reach trade-off. (3) Age Inference Methods - Knowledge Based: (a) User-provided age at registration (self-declaration); (b) Educational verification (student email); (c) A
- Age inference + Section 2 + records + per touchpoint + per method
- Reasonable steps + documentation + records + per risk + per technical capability
- Privacy-preserving + records + per method + PETs + audit
- Ageing up + transitions + records + per account + 13/16/17/18 + settings cascade
- Multi-jurisdiction + records + per region + harmonization strategy
- Age inference solely self-declaration (no reasonable steps)
- Privacy not preserved (excessive PII collected)
- Ageing up not implemented (settings stuck at registration age)
- Over-verification (ID required for all users)
- Multi-jurisdiction not coordinated
KOSA Default Safeguards
Section 4 of KOSA establishes mandatory default safeguards for known or reasonably inferred minor users. (1) Section 4(a) Mandatory Default Safeguards: All covered platforms must establish the following safeguards as DEFAULT for known minors and provide ability for parents to control: (a) Strong privacy settings - private account default + limit access to minor profile + no public discoverability; (b) Time management tools - default limits + notifications + parent controls; (c) Content filtering controls - inappropriate content blocking + reporting; (d) Restricted contact from unknown adults - default blocking + parent override; (e) Opt-out of personalized recommendations - non-personalized default + opt-in for personalization; (f) Geographic location default OFF - no precise location tracking + parent override; (g) Direct messaging restrictions - default disabled from non-followers + no
- Default safeguards + Section 4 + records + per setting + per minor account
- Strong privacy default + records + per account + re-default + annual + audit
- Personalization opt-out + records + per choice + persistent + cross-device
- Geographic location default off + records + per service + override only with consent
- Dark patterns + prohibition + records + per UI + per UX + audit ready
- Default safeguards not implemented (defaults remain permissive)
- Strong privacy not default (opt-in required)
- Personalization opt-out broken (persistent settings lost)
- Geographic location default ON
- Dark patterns persist in cancellation flows
KOSA Duty of Care
Section 3 of the Kids Online Safety Act establishes the foundational duty of care for covered platforms. (1) S.1409 Kids Online Safety and Privacy Act (KOSPA) introduced 16 February 2022 by Senator Richard Blumenthal (D-CT) and Senator Marsha Blackburn (R-TN) + bipartisan + reintroduced 2 May 2023 for 118th Congress + passed Senate 30 July 2024 by 91-3 vote + did not advance from House before session end + originated from 2021 Facebook leak by data scientist Frances Haugen via Wall Street Journal exposing Instagram negative effects on minors. (2) Section 2 Covered Platform Definition: (a) Online platform connecting users; (b) Including websites + mobile apps + games + messaging services; (c) Reasonably likely to be accessed by minors; (d) Knowledge or reasonable inference standard for age; (e) Excludes - common carriers + educational institutions + general internet services + email provi
- Duty of care + Section 3 + records + per harm category + reasonable measures
- Risk assessment + 9 harms + records + annual + systemic risk + foreseeable
- Reasonable care + documentation + records + per design + per decision
- Best interests of minor + records + per policy + balanced
- First Amendment + Section 230 + records + per decision + counsel
- Duty of care not implemented (default settings unchanged)
- Risk assessment perfunctory (no per-harm analysis)
- Reasonable care undocumented
- Best interests standard not applied
- First Amendment defense unprepared
KOSA Enforcement + FTC + State AG
Section 10 of KOSA establishes the enforcement framework limiting authority to FTC and State Attorneys General. (1) Section 10(a) FTC Federal Enforcement: (a) FTC has sole federal authority; (b) Treated as unfair or deceptive acts or practices per FTC Act Section 5; (c) Civil penalty authority; (d) Injunctive relief; (e) Restitution + disgorgement; (f) Cease and desist orders; (g) Compliance monitoring + reporting. (2) Section 10(b) State Attorney General Enforcement: (a) State AGs have concurrent enforcement authority; (b) Standing to bring action in federal court; (c) State court action also possible; (d) Civil penalty authority - amount per state law or KOSA cap; (e) Injunctive relief; (f) Restitution to state residents; (g) State AGs MUST provide notice to FTC of intent to bring action. (3) Section 10(c) Civil Penalty Framework: (a) UP TO USD 43,792 per violation (adjusted for inflat
- FTC + State AG cooperation + records + per inquiry + cure period awareness
- Cure period procedure + records + per notice + sub-threshold consideration
- Internal compliance + records + per quarter + Board reporting + Chief Trust Safety Officer
- Multi-state AG coordination + records + per investigation + counsel coordinated
- Compliance officer + Trust Safety Lead + records + designation + Board access
- FTC + State AG cooperation reactive (no proactive engagement)
- Cure period not utilised when available
- Internal compliance program absent or pro forma
- Multi-state AG coordination uncoordinated
- No designated KOSA officer or Trust Safety Lead
KOSA Independent Audit
Section 8 of KOSA mandates annual independent audits of covered platforms by qualified third-party auditors. (1) Section 8(a) Annual Independent Audit: (a) Covered platform must commission annual third-party audit; (b) Audit fiscal year + calendar year alignment options; (c) First audit within 18 months of effective date; (d) Subsequent audits annually; (e) Material change re-audit (significant feature launch + acquisition + policy change). (2) Section 8(b) FTC-Approved Auditor Requirements: (a) FTC publishes list of approved audit firms + criteria; (b) Independent from covered platform - no conflicts of interest; (c) Demonstrated expertise in minor online safety + algorithm audit + privacy + content moderation; (d) Reasonable engagement standards; (e) Diversity of qualified firms; (f) Regular review + recertification of auditors. (3) Section 8(c) Audit Scope: (a) Section 3 Duty of Care
- Annual independent audit + Section 8 + records + per year + audit ready
- FTC-approved auditor + independence + records + per engagement + no conflicts
- Audit scope + Sections 3-9 + records + comprehensive + methodology
- Public summary + records + annual + compliance status + redacted appropriate
- Remediation + findings response + records + per finding + timeline + verification
- Annual audit missing or delayed
- Auditor independence compromised (consultation services)
- Audit scope superficial (excludes algorithms)
- Public summary excessively redacted
- Remediation tracking absent
KOSA Parental Tools
Section 5 of KOSA mandates that covered platforms provide parental tools enabling parents and guardians to support minor users. (1) Section 5(a) Required Parental Tools: (a) Account Privacy Controls - parent ability to view and modify minor account privacy settings; (b) Time Management Controls - parent ability to set time limits + bedtime restrictions + view usage; (c) Spending Limits - parent ability to set or block in-app purchases + monitor spending; (d) Notification Settings - parent notification of minor account activities + content reports + safety alerts; (e) Account Privacy Override - parent ability to enable/disable certain features; (f) Linked Accounts Mechanism - secure linking of parent and minor accounts; (g) Education and Awareness Resources - parental guides + safety tips + reporting instructions. (2) Section 5(b) Minor Account Identification: (a) Platform must clearly id
- Parental tools + Section 5 + records + per tool + account linkage
- Linked accounts + verification + records + per linkage + COPPA-equivalent
- Parental dashboard + records + per parent + cross-platform consideration
- Minor privacy + balance + records + notification of parent access + autonomy progressive
- Multi-caregiver + family + records + per scenario + custody coordination
- Parental tools fragmented (no unified dashboard)
- Verification weak (false parental claim accepted)
- Minor privacy not preserved (parent surveillance excessive)
- Older minor autonomy ignored
- Multi-caregiver scenarios unsupported
KOSA Researcher Access
Section 7 of KOSA establishes a framework for qualified researcher access to covered platform data for public interest research. (1) Section 7(a) Qualified Researcher Definition: (a) Affiliated with accredited higher education institution + non-profit research organisation + government entity; (b) Demonstrated expertise in subject area (e.g. minor online safety + adolescent mental health + algorithm research); (c) Compliance with research ethics including IRB Institutional Review Board approval; (d) Conflict of interest disclosure; (e) Privacy + security training. (2) Section 7(b) Public Interest Research Scope: (a) Research advancing understanding of minor safety + welfare online; (b) Research on platform design impacts; (c) Research on algorithmic effects; (d) Research on content moderation effectiveness; (e) Research on parental tool effectiveness; (f) Research on demographic disparit
- Researcher approval + Section 7 + records + per application + Council guidance
- Data sharing + PETs + records + per engagement + per method
- Privacy protection + sandbox + records + per access + audit trail
- Research output + records + per engagement + published + cited
- DSA Article 40 + international + records + per jurisdiction + harmonization
- Researcher access program absent (no application channel)
- Data sharing limited to commercial researchers (academic excluded)
- Privacy protection weak (re-identification possible)
- Research output not tracked
- International coordination absent
KOSA Transparency Reporting
Section 6 of KOSA mandates comprehensive transparency reporting by covered platforms. (1) Section 6(a) Annual Public Transparency Report: (a) Covered platform must publish annual report on safety practices; (b) Submitted to FTC + State AGs + made publicly available; (c) Plain English language; (d) Multi-language for non-English markets; (e) Accessibility compliance per ADA; (f) Searchable + downloadable. (2) Section 6(b) Report Content - Risk Assessment Findings: (a) Annual systemic risk assessment per Section 3; (b) Per-harm category assessment - mental health + substance use + suicide + eating disorders + sexual exploitation + bullying + addictive design + predatory marketing + violence; (c) Methodology disclosure; (d) Affected populations analysis; (e) Mitigation actions identified + implemented; (f) Outstanding risks. (3) Section 6(c) Report Content - Reporting Mechanism Statistics:
- Annual transparency report + Section 6 + records + per year + public + FTC + State AG
- Risk assessment findings + per harm + records + per category + methodology
- Content moderation metrics + records + per quarter + per platform
- Independent audit summary + Section 8 + records + per audit + remediation
- Researcher access reports + Section 7 + records + per engagement + output references
- Annual report missing or perfunctory
- Risk assessment findings aggregated (no per-harm breakdown)
- Content moderation metrics absent or selective
- Audit summary brief or redacted excessively
- Researcher access not reported
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Kids Online Safety Act (KOSA) framework page.