Could a bill in Congress lead to device lockouts?
What would HR 8250, the "Parents Decide Act," require and what are the risks?
Background
The bill was formally introduced in the House on April 13, 2026.
NSPM-7
The bill is sponsored by Josh Gottheimer (D-NJ) and Elise Stefanik (R-NY), two of the most outspoken supporters of a country whose Cyber Unit identifies “inflammatory” online content and issues takedown requests to platforms like Meta and YouTube. In 2024 alone, they sent over 9,500 requests, with high compliance rates from social media companies (source: the EFF).
The government could theoretically cross-reference these verified identities with the “domestic terrorism” lists generated under NSPM-7 (National Security Presidential Memorandum-7), which applies to individuals as well as groups.
If a user’s speech on a platform is flagged as violating the ideological standards of NSPM-7, the government could argue that the app or the OS now has knowledge of a security threat. This could trigger mandatory “safety” interventions, such as locking the user out of an app or their device.
These laws turn your phone from a private tool into a digitally tethered ID card. Though “safety” for children is the public-facing goal, the technical infrastructure it builds is a system of total identification that is vulnerable to both criminals and government overreach that ostensibly ends with lockout from phones, computers, and apps, leaving users in the wilderness as a result of online speech.
Per Ken Klippenstein’s summary of NSPM-7:
Mechanics of the bill
This bill would require operating system providers to collect a user’s date of birth before they can set up and account and use a device.
Because the way the language is written is so broad, the definition of devices with operating systems includes:
Smartphone software, laptop and desktop computer software, tablet software, smart TV software, video game consoles, virtual reality and augmented reality headsets, smartwatches and fitness trackers, car dashboard screens, independent computer systems like Linux, Chromebook software, smart home devices (like smart fridges or thermostats), and public touchscreens (like ATMs or self-checkout kiosks).
Once verified at the operating system level, the bill requires providers to develop an API (think of it as a tunnel) that allows third-party app developers to access this age data. Apps would then dip into the information stored at the operating system level to perform age checks.
Those apps are only supposed to store a signal that indicates the age grouping, but we’ve seen over and over that there is a high possibility that some will store all they have access to via that API and no one will be the wiser because no one is going to audit their servers.
In terms of the types of IDs that would be acceptable, the bill leaves it to the unelected body at the FTC to come up with the methodology within 180 days of enactment.
One obvious risk here is that this starts out requiring less information in order to get it on the books, but then grows, just as FISA warrantless surveillance grew significantly over time.
Verification options
Options the FTC would consider likely consider using for verification:
1. Uploading a photo of a driver’s license or passport
2. Using facial scans or AI-based age estimation (biometrics)
3. Verifying identity and age against credit bureau info
4. Parent or guardian verification, in which case the parent must also verify
Why would its existence be very risky from a purely technological perspective?
1. The obvious: the bill creates massive databases of linked identities that would be a goldmine for hackers
2. Historical breaches at verifiers like AU10TIX and platforms like Discord have already exposed thousands of user ID images
3. On compromised devices, hackers can often bypass local security gates. For example, UK-based security consultant Paul Moore found he could hack a similar EU age-verification app in under 2 minutes by editing local files to disable biometric requirements and reset security PINs.
4. Hackers could send phishing emails or show pop-ups that look like official OS age-verification prompts. Unsuspecting users might then verify their age by uploading their driver’s license directly to a hacker’s server
In terms of who has access to this data, let’s pick on Meta/Facebook/Zuckerberg as an example
In April 2018, Zuckerberg testified before Senate and House committees after it was revealed that the data of up to 87 million users was improperly harvested.
In July 2020, Zuckerberg appeared before a House subcommittee to discuss whether Facebook’s massive data collection gave it an unfair advantage over competitors.
In November 2020, Zuckerberg testified about how user data and platform algorithms were managed during the 2020 election cycle.
In April 2025, a former Meta director testified that executives had betrayed American values by allegedly allowing the Chinese government to access to user data.
Given this past behavior, Congress is willfully ignoring the evidence to pretend these companies will just store a signal.
Why that’s likely absolutely untrue - Persona
Peter Thiel-backed Persona Identities, a third-party identity verification vendor that was used by Discord for age verification trials in the UK, had left nearly 2,500 frontend code files publicly accessible on a US government-authorized (FedRAMP, ie, Federal Risk and Authorization Management Program) server.
The claim is that the Persona data was on a FedRAMP-authorized server because Persona was in the process of pursuing official government certification to expand its identity verification services to federal agencies.
According to a post-incident review by Persona, the exposure occurred on a non-production test environment, specifically a subdomain called onyx.withpersona-gov.com, used to validate infrastructure for government-specific work.
Security researchers at vmfunc.re argued that, though individual identities weren’t leaked this time, the code revealed a hidden surveillance pipeline that routes routine ID checks (like for OpenAI or Discord) into government watchlist databases and suspicious activity reporting systems.
Results:
1. Persona’s CEO reached out to vmfunc directly to discuss the findings, and even praised their “clear talent” though of course they expressed frustration with how the report was released
2. Discord immediately cut ties with Persona for its UK age verification trial once the report went viral
3. Major platforms like OpenAI and Anthropic faced renewed scrutiny over their use of the same watchlist infrastructure
Bottom line: A tool meant for a simple age check was actually a sophisticated surveillance engine.



