On September 17, 2026, the European Commission (EC) published a proposed “EU KIDS Act,” which would impose minimum-age requirements to access social media and video-sharing platforms, subject to mandatory age verification, as well as an obligation for covered entities, including providers of online games and AI chatbots and AI companions, to build specific safety features by design.
The proposal is still subject to change and has not been passed into law. Adoption is not guaranteed and even if adopted, the EU KIDS Act is unlikely to apply before 2028. In its current form, the EU KIDS Act would have significant implications for companies offering covered services to minors in the EU.
Background
There is currently no harmonized EU minimum age for accessing online services. Existing rules protecting children online are spread across a patchwork of EU and national laws, including the EU Digital Services Act (DSA), the EU Artificial Intelligence Act (EU AI Act), and the EU General Data Protection Regulation (GDPR).
In recent years, restricting minors’ access to social media has become a global trend. Australia led the way in late 2025 by barring under-16s from social media. France adopted a social media ban for under-15s, but it was struck down by the Constitutional Council before it took effect; a revised proposal is now underway. Several other European countries have similar measures in the pipeline, including Denmark, Spain, Austria, Portugal, and Norway. In the UK, a social media ban for under-16s was announced in June 2026 with the intention of becoming effective in early 2027, although legislation implementing this regulation has not yet been introduced (see here). The EC reports that similar legislation is being prepared in at least 17 EU countries.
Against this backdrop, the EC published its EU KIDS Act proposal for an EU-wide law imposing minimum age requirements to access social media and video-sharing platforms.
Who Could Be Affected?
The proposal targets a defined set of services and systems the EC calls “Social Media+,” deemed to pose the most risk to minors, including:
- social media services;
- video-sharing platforms;
- online games; and
- AI chatbots and AI companions.
In addition, the proposal imposes certain obligations on software application stores and operating systems, such as facilitating age-gating. The proposal explicitly excludes from its scope educational tools and public-authority services.
What Are the Key Obligations under the Proposal?
If adopted in its current form, the EU KIDS Act would impose substantial obligations on companies offering services such as social media, video-sharing, online games, and AI chatbots and AI companions. The three key obligations are listed below.
- Tiered, age-based access to social media and video-sharing platforms. Under the proposal, access to social media and video-sharing platforms is tiered across four age bands:
- Children under three: No access to social media and video-sharing platforms, alongside a broader recommendation against any screen use.
- Children aged three to under 13: No access to social media. Limited access to child-friendly video-sharing platforms through a guardian-controlled account, capped at one hour per day.
- Teens from 13 to under 15: Access to social media and video-sharing platforms, but not with an independent account. A guardian may set up a supervised account with a limited number of peer-only contacts, capped at one hour per day.
- Teens from 15 to under 18: Older teens may open their own accounts on social media and video-sharing platforms, provided the services meet the “safe by design” requirement (see #3 below).
Online video games and AI chatbots or companions are not prohibited for any age group, but they would need to meet the “safe by design” requirement to be provided to minors.
- Mandatory age verification. To provide age-based access, implement guardian controls, and “safe by design” features, providers of covered services and systems would need to verify users’ age as follows:
- For new accounts, providers of social media and video-sharing platforms would need to verify a user’s age using a solution from an approved list maintained by the EC, such as the EU age verification app. These tools are designed to be privacy-preserving: they confirm only whether a user meets an age threshold, without disclosing identity documents, biometric data, or the actual date of birth. Under the proposal, every EU country would need to offer at least one free way to verify age, including for people without a digital ID.
- For existing accounts, providers of social media and video-sharing platforms would have six months to estimate users’ age and disable the accounts of users under 15 or whose age cannot be established. The proposal provides that methods for such age estimation would need to provide “high confidence” that the minimum age has been reached, but stops short of mandating any specific methods. Such age estimation could, for example, be based on the account creation date or a linked credit card, rather than re-verification of all users.
- Providers of other covered services such as video games and AI chatbots or AI companions would need to verify age using a solution that provides “a high level of accuracy, reliability, security, robustness, non-intrusiveness, privacy and data protection, and non-discrimination,” to ensure minors have access to guardian controls and “safe by design” features. The proposal explicitly states that these services would be able to rely on mechanisms offered by software application stores or game stores to verify age.
- “Safe by design” obligations.In-scope services would be required to build in specific safety features from the outset, including:
- child accounts would need to be private by default, with their content and profiles only visible to accepted contacts, with push notifications, geolocation, microphone and camera access, account recommendations, and contact sync off by default;
- no infinite scrolling, “streak” mechanics, and notifications during sleeping hours;
- recommender systems would need to prioritize stated preferences over engagement signals, with a non-profiling option available to all users;
- AI companions and AI chatbots used by children may not be designed to simulate relationships in ways that create emotional dependency;
- no direct messages to children without pre-approval through guardian tools for a minor aged 13-15, or by the minor from 15-18;
- effective parental controls; and
- accessible, child-friendly reporting tools for minors.
The proposal includes several other obligations for providers of covered services. For example, social-media and video-sharing services designated as very large online platforms (VLOPs), services with 45 million or more monthly EU users, under the DSA would have to submit child-safety compliance plans verified through independent audits.
How Could the New Rules Be Enforced?
Under the proposal, infringement of the rules could lead to fines of up to 6 percent of a provider’s total worldwide annual turnover (revenue). The regulator responsible for enforcing the EU KIDS Act would be the same national regulator as the one responsible for enforcing the DSA or the EU AI Act, depending on the service. Social media, video-sharing and online gaming platforms designated as VLOPs under the DSA, and AI chatbots and AI companions considered general-purpose AI under the EU AI Act will be regulated directly by the EC.
Next Steps
The EU KIDS Act is a legislative proposal, not law. It must move through a complex and lengthy legislative procedure before passing into law, and it is unlikely to apply before 2028. Along the way, the proposal may undergo material changes, so providers of social media platforms, video-sharing platforms, software application stores, online games, operating systems, and AI chatbots and AI companions should continue monitoring these developments.
In the meantime, such providers should consider taking steps to assess the impact of the Proposal on their services, including:
- determining which services would fall within “Social Media+;”
- considering how the tiered age bands map to current sign-up flows;
- analyzing possible age verification solutions; and
- mapping these new obligations against existing minor-protection duties under current laws such as the DSA, the EU AI Act, and the GDPR.
For more information or if you have any questions regarding the EU KIDS Act, or EU technology regulation, please contact Cédric Burton, Laura De Boel, Yann Padova, or Nikolaos Theodorakis from Wilson Sonsini’s Data, Privacy, and Cybersecurity practice.
Rossana Fol, Tom Evans, Michaela Novakova, and Hugh Ó Laoide Kelly contributed to the preparation of this alert.
Recent Comments