16 CFR § 312.2 (definitions, as amended 2025)
Personal information now includes biometric identifiers
The amended Rule expands personal information to include biometric identifiers that can identify a specific child, such as fingerprints, voiceprints, and facial templates, alongside the existing categories: name, contact details, persistent identifiers, photos, audio, and geolocation.
AI features are heavy consumers of exactly these new categories: voice assistants process voiceprints, camera features process face data, and chat tools collect free text that children salt with names, addresses, and school details. An organization running AI on children's inputs must treat the model pipeline as a collection of personal information under the Rule, with consent, notice, and retention obligations attached to every input channel.
16 CFR § 312.5 (verifiable parental consent, as amended 2025)
Separate opt-in consent for third-party disclosure and AI training
Operators must obtain verifiable parental consent before collection, and the 2025 amendments require a separate, specific opt-in before disclosing children's personal information to third parties, including for targeted advertising. The FTC's accompanying commentary states that using a child's data to train or develop AI is not integral to providing the service and therefore needs its own consent.
This is the provision that changes AI product design: a general consent to use the service does not cover feeding children's data to models. Operators need a distinct, unbundled consent flow for AI training, and the service cannot be conditioned on the parent agreeing to it. Organizations buying AI-powered children's products should demand contract terms confirming inputs are excluded from training unless that separate consent exists.
16 CFR § 312.10 (data retention, as amended 2025)
Retention limits and a mandatory written retention policy
Children's personal information may be retained only as long as reasonably necessary for the specific purpose it was collected for, indefinite retention is prohibited, and operators must establish, maintain, and publish a written data retention policy covering children's data.
AI systems tend to hoard: chat logs, embeddings, and training corpora persist by default. Under the amended Rule, keeping children's prompts or generated profiles around because they might be useful later is a violation on its face. Organizations must set purpose-bound retention schedules for every AI data store that touches children's information and be able to show deletion actually happens.
16 CFR § 312.11 (safe harbor programs, as amended 2025)
Tightened oversight of COPPA safe harbor programs
FTC-approved safe harbor programs, which certify operators as compliant, face new transparency obligations: publicly listing their certified members, reporting to the FTC in more detail, and demonstrating their oversight is effective.
Organizations relying on a vendor's safe harbor seal should know the seal is now easier to check and harder to hide behind. Membership lists are public, so buyers can verify a claimed certification, and a certification does not cover AI practices the program never reviewed. Due diligence on an AI vendor for children's products should include what the safe harbor assessment actually examined.
16 CFR § 312.5(c) and FTC ed-tech policy (school authorization)
School consent in the ed-tech context
The FTC permits schools to authorize collection of students' personal information in the place of parents, but only where the data is collected for the use and benefit of the school and for no other commercial purpose. The 2025 amendments and FTC policy statements reinforce that this authorization cannot stretch to advertising or unrelated uses.
For AI ed-tech, school authorization covers the educational service and nothing else: not model training for the vendor's general benefit, not advertising, not product development on identifiable child data. Districts consenting on parents' behalf take on the duty to verify those limits in contracts, and teachers using unapproved AI tools with under-13 students can create collection no one consented to at all.