web analytics
Sector Rules

COPPA and AI

Children's Data in AI Systems

The one-paragraph answer

COPPA AI compliance applies to AI systems that collect, use, or disclose personal information from children under 13. COPPA (Children's Online Privacy Protection Act) requires verifiable parental consent, data minimization, security safeguards, and deletion rights. It applies to operators of websites, apps, and online services directed at children, and to operators of general-audience services that have actual knowledge they are collecting information from children under 13. AI features do not exempt anyone from COPPA.

The pain COPPA AI compliance is causing our customers

Consumer AI products (chatbots, tutoring assistants, gaming companions, education apps) are used by children, sometimes intentionally, sometimes not. When AI collects information from a child under 13, COPPA obligations kick in immediately. The pain is that AI companies often do not know when children are using their products, and "we did not know" is not a defense once actual knowledge is established. FTC enforcement has produced multi-million-dollar settlements against consumer AI companies for COPPA failures.

What COPPA AI compliance requires

Verifiable parental consent

Before collecting personal information from a child under 13, operators must obtain verifiable parental consent. Simple age gates are not sufficient. Approved methods include payment card verification, government ID verification, video conference, or knowledge-based authentication.

Notice

Operators must post a clear COPPA-compliant privacy policy explaining what information is collected, how it is used, whether it is shared, and how parents can review or delete it. Direct notice to parents is also required.

Data minimization

Only information reasonably necessary for the child's participation in the activity may be collected. AI systems that collect broader data for training or improvement need specific parental consent for those uses.

Security

Reasonable procedures to protect the confidentiality, security, and integrity of children's information.

Parental rights

Parents can review information collected from their child, refuse further collection, and request deletion.

Special AI issues under COPPA

AI training on children's data is scrutinized. FTC has ordered "algorithmic disgorgement" (deletion of AI models built with children's data collected without consent) in multiple cases. Voice AI that captures children's voiceprints raises additional issues under COPPA and state biometric privacy laws. Generative AI that produces content depicting children raises separate concerns.

Why COPPA AI compliance matters to you

Any consumer-facing AI product with any chance of use by children under 13 needs COPPA analysis. Products directed at children require compliance from launch. General-audience products need policies that respond to actual knowledge of child users. Penalties can be substantial: FTC has imposed civil penalties in the tens of millions of dollars for COPPA violations.

What the research says about COPPA AI

The academic literature on COPPA AI is ahead of most corporate practice, and it is unusually blunt. Two findings are worth putting in front of any executive who thinks this is a compliance formality.

“concerns about their impact on individual and societal wellbeing, particularly due to the lack of transparency and accountability”

That is the gap between having AI and governing it. The second finding is the one that tends to change the room.

“all those who are involved in the research, development and maintenance of AI systems have social and ethical responsibilities”

Neither of these is a fringe position. Both come from peer-reviewed work, and both describe the condition most organisations are actually in when the question about COPPA AI arrives from the board, the buyer, or the regulator.

How to get compliant with COPPA and AI: a 5-step path

This is the sequence that works, and it is not the sequence most organisations choose. They start with the framework and work backwards toward reality. Start with reality.

  1. Inventory the AI in scope. List every AI system that could fall under COPPA AI. Record what it does, what decision it influences, what data it touches, and who owns it. You cannot govern AI you cannot name, and almost every organisation we assess is running more AI than its leadership believes.
  2. Determine whether you are actually in scope. Work out precisely which of your AI systems and activities COPPA AI reaches, and write the determination down with its reasoning. Do this in writing. A documented scope determination, right or wrong, is defensible. An undocumented assumption is not.
  3. Assign one accountable owner. Name a person, not a committee, with the authority to stop a deployment. Governance without someone who can say no is documentation, not control.
  4. Build the evidence file. Assemble the documentation COPPA AI expects: the scope, the risk assessment, the controls, the testing evidence, and the incident record. Assemble it before anyone asks. Reconstructing it under a regulator's deadline costs several times more and looks exactly like what it is.
  5. Set a review cadence and hold it. Re-run the assessment on a schedule and after any material change to the model, the data, or the use case. Alignment decays. A control tested once is a snapshot, not a control.

Done in this order, COPPA AI becomes tractable. Done out of order, it becomes a document nobody uses and a control nobody exercises.

Frequently asked questions about COPPA AI compliance

Does COPPA apply to a general-audience AI product?

Yes, if the operator has actual knowledge that children under 13 are providing personal information. "Actual knowledge" can be inferred from usage patterns, complaints, or product design.

What is "verifiable parental consent"?

A method reasonably designed to ensure the person providing consent is the child's parent. Simple age gates or check-the-box are not sufficient.

Can we train AI on data collected from children?

Only with specific parental consent for that use. General consent for the service is not sufficient.

Where does COPPA AI compliance fit in SRJ's work?

The consumer product addendum in Volume III of The Operating Discipline for AI Library™ addresses COPPA-specific AI compliance.

The actual-knowledge trap in COPPA AI compliance

Most consumer AI companies believe they are outside COPPA because their product is not aimed at children. That belief is worth very little. The statute reaches any operator with actual knowledge that it is collecting personal information from a child under 13, and actual knowledge can be established from things you already have: support tickets from parents, age data users volunteer, usage patterns, or the simple fact that your product is obviously appealing to children. Once knowledge attaches, every prior collection becomes a violation.

Algorithmic disgorgement is the remedy that hurts

The FTC's most consequential COPPA AI remedy is not the fine. It is the order to delete the model. If a model was trained on data collected from children without verifiable parental consent, the Commission has required the model itself to be destroyed, along with the data. That converts a privacy failure into the loss of the asset the company was built on. No insurance policy covers it.

What to do if children might be using your AI

Decide deliberately rather than by default. Either build the consent infrastructure, which is real work and includes verifiable parental consent, direct notice, minimisation, and deletion rights, or build genuine age assurance and enforce it. What you cannot do is leave the question open and hope the issue never surfaces, because the moment it surfaces, actual knowledge attaches and the exposure is retroactive.

Primary sources on COPPA AI

The authoritative texts and agency pages behind this summary. We keep this page current, but where a compliance decision turns on exact wording, read the source. Anything concerning COPPA AI that carries legal consequence should be confirmed against the enrolled text or the issuing body, not against a secondary summary, including this one.

Ready to see where you stand?

The AI Business Enablement Audit™ measures your organization against every framework in this library, including COPPA and AI, and delivers a defensible governance dossier. Start or finish your audit below.

Start or finish your AI Audit →
Schedule a Free AI Consultation