Smart glasses, AI cameras, classroom tools and connected devices can collect children’s faces, voices and behavior even when the child never opened an app, created an account or agreed to use the technology. That is exposing a gap in the way U.S. children’s privacy law has traditionally worked.
For more than 25 years, the basic model behind U.S. children’s online privacy law has been fairly straightforward.
A child visits a website, downloads an app, plays a game or uses an online service. The service collects information about that child. If the child is under 13 and the Children’s Online Privacy Protection Act applies, the operator generally must provide notice and obtain verifiable parental consent before collecting covered personal information.
Artificial intelligence is making that model much less tidy.
A student wearing AI-enabled glasses can potentially capture the faces and voices of an entire classroom. A school can deploy cameras capable of analyzing movement or behavior. A teacher can upload a child’s photograph into an AI application. An educational application may process students’ writing, voice, images or behavioral signals.
In many of those situations, the child whose information is collected is not actually the user of the technology.
The child is simply standing in front of it.
That distinction is emerging as one of the more difficult children’s privacy questions of the AI era.
In a September 1, 2026, IAPP opinion piece, Dona Fraser of BBB National Programs described the problem as a shift from protecting children only as users of technology toward recognizing children as subjects of technology. The examples include AI-enabled glasses, cameras and classroom applications capable of collecting or interpreting children’s images, voices, behavior and schoolwork.
That seemingly small distinction has significant consequences for privacy law, product design and AI governance.
The Child Who Never Agreed to Use the Device
Consider a fairly realistic classroom scenario.
A ninth-grade student walks into biology class wearing smart glasses. The glasses look much like ordinary eyewear but contain cameras, microphones and AI capabilities that allow the device to interpret what the wearer sees and hears.
There are 25 other students in the room.
Those students:
- did not buy the glasses;
- did not activate the device;
- did not create an account;
- did not accept its privacy policy;
- did not give the manufacturer their age;
- may not know recording is occurring; and
- may have no practical mechanism for opting out.
Yet their faces, voices, conversations and surroundings could potentially be captured because they happen to be within range of someone else’s device.
The same problem does not stop when class ends.
A wearable could accompany its owner through hallways, cafeterias, school buses, athletic facilities and after-school events. Children who have no relationship with the manufacturer could repeatedly enter the device’s camera or microphone range.
That is materially different from the privacy model that developed around websites and apps.
Traditionally, there is an identifiable interaction:
person → service → data collection.
AI-enabled wearables and ambient technologies introduce another possibility:
device owner → AI system → everyone around the device.
The people being analyzed may never interact with the company at all.
COPPA Has Been Built Around the Online Service
Congress enacted COPPA in 1998, and the FTC’s implementing rule originally took effect in 2000.
The law remains one of the most important federal privacy protections specifically directed at children under 13.
COPPA generally applies to operators of commercial websites and online services directed to children under 13 that collect personal information, as well as certain general-audience services that have actual knowledge that they are collecting personal information from children under 13. It can also apply to third parties such as advertising networks and plug-ins when they knowingly collect information through child-directed services.
Covered operators have substantial obligations.
Among other things, they may need to:
- provide an appropriate privacy notice;
- give parents direct notice of their practices;
- obtain verifiable parental consent;
- allow parents to access or delete their child’s information;
- limit retention;
- maintain reasonable data security; and
- restrict unnecessary collection.
The problem with ambient AI is not that COPPA suddenly becomes irrelevant.
The problem is determining where COPPA begins and ends when the child is not actually using the service.
COPPA is specifically tied to websites and “online services.” The IAPP analysis points out that a device operating entirely offline could potentially fall outside COPPA, while determining whether modern AI hardware constitutes an online service can require a much more detailed technical analysis.
Modern AI devices make that distinction especially complicated.
A pair of smart glasses might perform some processing locally while transmitting other information to a phone, cloud platform or AI model. Voice could be buffered temporarily. Images might be analyzed on-device but metadata transmitted elsewhere. Some functionality may operate offline while other features require connectivity.
Whether data technically reaches an “online service” can therefore depend on architecture that is invisible to the person being recorded.
COPPA Has Already Been Updated for Biometrics
The legal framework is not standing still.
The FTC substantially amended the COPPA Rule in 2025, and covered businesses were given one year from the April 22, 2025 Federal Register publication to come into full compliance with most of the amendments.
One important change was the expansion of COPPA’s definition of personal information to expressly include biometric identifiers.
The FTC also strengthened restrictions surrounding third-party disclosures and targeted advertising.
Under the amended rule, covered operators generally must obtain separate verifiable parental consent before disclosing a child’s personal information to third parties for targeted advertising or other non-integral purposes. The rule also tightened data-retention requirements and states that children’s information cannot simply be retained indefinitely.
Those changes matter considerably in an AI environment.
Faces, voices and other biometric characteristics can now sit at the center of AI systems designed to recognize, categorize or infer information about individuals.
But adding biometrics to COPPA does not automatically solve the ambient-data problem.
The difficult question remains:
How does a parent provide meaningful consent when the company collecting the child’s biometric information does not have a relationship with either the parent or the child?
Smart Glasses Make Consent Architecturally Difficult
Consent mechanisms work relatively well when a company controls the interface.
A child wants to create an account.
The company can ask for an age.
It can interrupt the registration process.
It can request a parent’s information.
It can send the parent a notice and collect consent.
An AI wearable may have no equivalent interaction with the bystander.
Imagine that the glasses identify five students in a classroom.
How does the manufacturer know whether each child is 9, 12, 14 or 17?
How would it identify their parents?
How would the manufacturer know whether consent had previously been given?
What happens when the wearer enters a playground containing 60 children?
And what technical mechanism prevents processing before those questions are answered?
That is why the emerging issue is broader than writing a more detailed privacy policy.
The privacy problem is embedded in the architecture of collection itself.
Schools Cannot Solve the Problem Alone
Schools will inevitably become part of this debate.
Districts can restrict or prohibit smart glasses. They can control school-issued technology. They can establish acceptable-use policies for students and staff. They can impose contractual requirements on educational technology vendors.
But a school policy has limits.
A district can say that students cannot record classmates with AI glasses.
It cannot necessarily determine what happens after information reaches a third-party platform.
Nor can a school easily control every device that students, parents, visitors, contractors and staff members bring onto campus.
The IAPP article makes this distinction directly: a school may regulate whether a device can be used in the classroom while having considerably less control over where captured information travels or how the provider ultimately uses it.
This creates a vendor-governance problem as much as a student-device problem.
Schools adopting AI tools should increasingly be asking vendors questions such as:
- What information does the system collect?
- Does it process faces, voices or other biometric identifiers?
- Is processing performed locally or in the cloud?
- Is information used to train AI models?
- Which subprocessors receive the data?
- How long is information retained?
- Can data be deleted?
- Is information used for advertising or profiling?
- What happens when the system captures someone who is not an authorized user?
- How does the system distinguish children from adults?
Those questions should be answered before deployment, not after a privacy complaint.
The FTC Is Already Focused on Third-Party Collection
Businesses should also be careful about assuming that privacy responsibility belongs only to whichever third-party vendor physically receives the information.
FTC enforcement history says otherwise.
In September 2025, the FTC took action against robot-toy manufacturer Apitor Technology. The government alleged that an SDK integrated into the company’s companion application allowed a third-party developer to collect children’s precise geolocation information without the required parental consent.
The FTC’s position was clear: a company providing an online service to children cannot avoid COPPA obligations simply because a third party performs the collection.
The same concept appears in the FTC’s COPPA guidance.
The agency states that operators of child-directed properties remain responsible for personal information collected on their sites or services even when another entity performs the collection.
That principle should be familiar to companies implementing AI tools.
A school, app developer or child-focused service cannot assume that adding a third-party AI SDK, analytics product, computer-vision system or model API transfers privacy responsibility to the vendor.
Organizations need to understand what the integration actually does.
Disney’s $10 Million COPPA Case Shows the Stakes
The FTC has also shown that children’s privacy enforcement can carry meaningful penalties.
In December 2025, a federal court approved an order requiring Disney to pay a $10 million civil penalty to settle allegations that Disney improperly designated certain YouTube videos, allowing personal data to be collected from children viewing child-directed content without the appropriate COPPA protections.
The order also required a program for determining whether Disney videos should be marked “Made for Kids.”
The Disney matter involved conventional online content, not smart glasses.
But it provides an important lesson for AI deployments.
The company that creates or distributes content cannot necessarily rely on the platform’s technology to make the correct privacy determination.
Classification matters.
Age determination matters.
How a third party handles data matters.
Those same issues will increasingly appear in AI products.
Age Assurance Is Becoming Part of the Privacy Architecture
The FTC has also started addressing the tension between age verification and privacy.
Age assurance creates an obvious paradox.
A company may need additional information to determine whether someone is a child before it knows which privacy protections must apply.
In February 2026, the FTC announced an enforcement policy designed to encourage certain age-verification technologies.
Under the policy, the Commission said it would not bring COPPA enforcement actions against qualifying operators that collect and use personal information solely to determine age, provided they comply with conditions including purpose limitation, prompt deletion, appropriate security and restrictions on third-party disclosure.
That policy is particularly relevant to AI.
Future systems may increasingly need privacy-preserving ways to determine whether a person in front of a camera, chatbot or connected device is a minor without unnecessarily creating another sensitive identity database in the process.
Age assurance therefore cannot simply mean “collect more information.”
It needs to be designed around minimization.
Congress Is Already Looking at Children and AI
Federal lawmakers are also beginning to address AI and children more directly.
On August 5, 2026, the Senate Commerce Committee advanced several measures dealing with children, online services and artificial intelligence.
They included:
- the Kids Online Safety Act;
- the Youth AI Privacy Act;
- the CHATBOT Act; and
- the Children’s Artificial Intelligence Toy Safety Act of 2026.
The Youth AI Privacy Act would impose privacy safeguards on AI chatbots used by minors, while the CHATBOT Act contains provisions directed at parental control and minors’ use of AI chatbot services. Neither committee approval nor introduction means these proposals have become law; as of September 1, they remain part of an active federal legislative debate.
What is notable is the direction of travel.
Children’s privacy regulation is no longer centered exclusively around websites, mobile applications and behavioral advertising.
Lawmakers are now considering AI companions, chatbots and AI-enabled toys.
Wearables and ambient AI are an obvious next question.
From “User” to “Subject”
One of the most useful concepts in the IAPP piece is the distinction between a child who uses technology and a child who becomes the subject of technology.
A user initiates the interaction.
A subject may not.
That distinction becomes increasingly important when AI can:
- recognize a face;
- transcribe a conversation;
- classify an emotion;
- interpret behavior;
- infer age or identity;
- analyze schoolwork;
- remember previous encounters; or
- combine observations with information from other sources.
A child can become part of an AI system’s data environment without opening an application at all.
And unlike a cookie, which generally follows a browser or device, ambient AI can collect information from a human being simply because that person enters a physical space.
The IAPP article argues that lawmakers need to consider passive exposure to technologies collecting children’s images, voices and biometric information, rather than limiting protections to situations where the child directly interacts with the provider.
That is likely to become an important distinction well beyond COPPA.
AI Governance Programs Need to Account for Bystanders
For businesses, schools and technology providers, there is a practical compliance lesson here already.
An AI impact assessment should not ask only:
Who uses this system?
It should also ask:
Who can this system observe?
That second question may produce a completely different risk profile.
A company deploying cameras, microphones, wearables, facial analysis or other AI-enabled sensors should map more than registered users.
It should identify:
- Direct users — people intentionally interacting with the product.
- Incidental users — people who use the system indirectly.
- Bystanders — people whose information may be captured without any interaction.
- Children and other protected populations within each category.
The organization can then evaluate collection, legal basis, notice, consent, retention, security, model training, third-party sharing and deletion for each group.
That should increasingly become part of an AI privacy impact assessment.
Data Minimization May Be the Most Practical Guardrail
There may never be a workable consent mechanism for every bystander encountered by an AI device.
That makes minimization particularly important.
A privacy-conscious system might, depending on its purpose and technical requirements:
- perform processing locally rather than uploading raw recordings;
- avoid storing bystander information;
- automatically blur unidentified faces;
- discard audio after completing a defined task;
- prevent biometric identification unless specifically authorized;
- separate necessary functionality from model training;
- prohibit behavioral advertising using captured information; or
- provide obvious recording indicators and physical controls.
Not every measure will work for every device.
But the starting question should be whether the information needs to be collected at all.
That is especially important when the person being observed is a child who never chose to participate.
Children’s Privacy Is Moving Beyond the Screen
For decades, the central children’s privacy scenario involved a child sitting in front of a computer, phone or tablet.
That is no longer enough.
AI is moving into glasses, toys, vehicles, cameras, classrooms, homes and other physical environments. The devices can increasingly interpret the world around them rather than merely responding to information a user deliberately enters.
That creates a new compliance question.
A privacy program cannot focus exclusively on the person who clicked “I agree.”
Organizations also need to understand whose data their technology can collect before anyone gets the chance to click anything at all.
For children’s privacy, that may become one of the defining legal questions of the next generation of AI regulation.