Children's Data in AI Systems
The one-paragraph answer
COPPA AI compliance applies to AI systems that collect, use, or disclose personal information from children under 13. COPPA (Children's Online Privacy Protection Act) requires verifiable parental consent, data minimization, security safeguards, and deletion rights. It applies to operators of websites, apps, and online services directed at children, and to operators of general-audience services that have actual knowledge they are collecting information from children under 13. AI features do not exempt anyone from COPPA.
Consumer AI products (chatbots, tutoring assistants, gaming companions, education apps) are used by children, sometimes intentionally, sometimes not. When AI collects information from a child under 13, COPPA obligations kick in immediately. The pain is that AI companies often do not know when children are using their products, and "we did not know" is not a defense once actual knowledge is established. FTC enforcement has produced multi-million-dollar settlements against consumer AI companies for COPPA failures.
Before collecting personal information from a child under 13, operators must obtain verifiable parental consent. Simple age gates are not sufficient. Approved methods include payment card verification, government ID verification, video conference, or knowledge-based authentication.
Operators must post a clear COPPA-compliant privacy policy explaining what information is collected, how it is used, whether it is shared, and how parents can review or delete it. Direct notice to parents is also required.
Only information reasonably necessary for the child's participation in the activity may be collected. AI systems that collect broader data for training or improvement need specific parental consent for those uses.
Reasonable procedures to protect the confidentiality, security, and integrity of children's information.
Parents can review information collected from their child, refuse further collection, and request deletion.
AI training on children's data is scrutinized. FTC has ordered "algorithmic disgorgement" (deletion of AI models built with children's data collected without consent) in multiple cases. Voice AI that captures children's voiceprints raises additional issues under COPPA and state biometric privacy laws. Generative AI that produces content depicting children raises separate concerns.
Any consumer-facing AI product with any chance of use by children under 13 needs COPPA analysis. Products directed at children require compliance from launch. General-audience products need policies that respond to actual knowledge of child users. Penalties can be substantial: FTC has imposed civil penalties in the tens of millions of dollars for COPPA violations.
The academic literature on COPPA AI is ahead of most corporate practice, and it is unusually blunt. Two findings are worth putting in front of any executive who thinks this is a compliance formality.
“concerns about their impact on individual and societal wellbeing, particularly due to the lack of transparency and accountability”
That is the gap between having AI and governing it. The second finding is the one that tends to change the room.
“all those who are involved in the research, development and maintenance of AI systems have social and ethical responsibilities”
Neither of these is a fringe position. Both come from peer-reviewed work, and both describe the condition most organisations are actually in when the question about COPPA AI arrives from the board, the buyer, or the regulator.
This is the sequence that works, and it is not the sequence most organisations choose. They start with the framework and work backwards toward reality. Start with reality.
Done in this order, COPPA AI becomes tractable. Done out of order, it becomes a document nobody uses and a control nobody exercises.
Yes, if the operator has actual knowledge that children under 13 are providing personal information. "Actual knowledge" can be inferred from usage patterns, complaints, or product design.
A method reasonably designed to ensure the person providing consent is the child's parent. Simple age gates or check-the-box are not sufficient.
Only with specific parental consent for that use. General consent for the service is not sufficient.
The consumer product addendum in Volume III of The Operating Discipline for AI Library™ addresses COPPA-specific AI compliance.
Most consumer AI companies believe they are outside COPPA because their product is not aimed at children. That belief is worth very little. The statute reaches any operator with actual knowledge that it is collecting personal information from a child under 13, and actual knowledge can be established from things you already have: support tickets from parents, age data users volunteer, usage patterns, or the simple fact that your product is obviously appealing to children. Once knowledge attaches, every prior collection becomes a violation.
The FTC's most consequential COPPA AI remedy is not the fine. It is the order to delete the model. If a model was trained on data collected from children without verifiable parental consent, the Commission has required the model itself to be destroyed, along with the data. That converts a privacy failure into the loss of the asset the company was built on. No insurance policy covers it.
Decide deliberately rather than by default. Either build the consent infrastructure, which is real work and includes verifiable parental consent, direct notice, minimisation, and deletion rights, or build genuine age assurance and enforce it. What you cannot do is leave the question open and hope the issue never surfaces, because the moment it surfaces, actual knowledge attaches and the exposure is retroactive.
The authoritative texts and agency pages behind this summary. We keep this page current, but where a compliance decision turns on exact wording, read the source. Anything concerning COPPA AI that carries legal consequence should be confirmed against the enrolled text or the issuing body, not against a secondary summary, including this one.
The AI Business Enablement Audit™ measures your organization against every framework in this library, including COPPA and AI, and delivers a defensible governance dossier. Start or finish your audit below.
Start or finish your AI Audit →