\n\n

On 17 September 2026, the European Commission unveiled its proposal for the EU KIDS Act (EU Keeping Internet Digital Spaces Accountable and Trustworthy), a harmonised EU framework designed to reshape how children engage with online services. The proposal goes well beyond age verification requirements and seeks to fundamentally change the design of digital services used by minors, placing greater responsibility on technology providers to create age-appropriate digital environments. It builds on existing legislation such as the EU Digital Services Act (DSA) and the EU AI Act but introduces more specific rules focused on child safety.

Which Services Are Covered?

The KIDS Act imposes extensive obligations on a broad range of online services. Its scope extends beyond social media platforms to encompass a wide range of online services, including:

  • online social networking services;
  • video-sharing platform services;
  • app stores;
  • online games;
  • operating systems;
  • AI companions; and
  • general conversational chatbots.

Summary of key requirements

The proposal is built around four core themes:

  1. EU-wide minimum age for social media accounts

A key feature of the proposal is the establishment of common age-based rules governing children’s access to social media and certain video-sharing platforms across the EU. The Commission’s objective is to introduce a gradual and age-appropriate pathway into the online environment, reflecting growing concerns about the impact that social media and algorithm-driven content can have on children’s wellbeing and development. The Commission emphasises the need for a harmonised framework to avoid a fragmented landscape of national age thresholds and access requirements.

Under the proposal:

  • Children under 13 will be prohibited from accessing social media services. They would, however, be able to access specially designed child-friendly video-sharing services through an account managed by a parent or guardian.
  • Children aged 13 and 14 will only be able access social media and certain video-sharing services through parent-managed “mini accounts”. These accounts would offer limited functionality, enhanced parental controls and restrictions on use, including a daily screen-time limit.
  • From age 15, minors will be permitted to open and manage their own social media accounts and access covered video-sharing services independently.

In addition, under the proposal, providers would be required to determine whether existing account holders are under the age of 15. Accounts belonging to users identified as under 15, or whose age cannot be verified, would need to be disabled. Providers designated as Very Large Online Platforms (VLOPs) under the DSA would face additional obligations, including submitting a compliance plan demonstrating, through robust technical and evidentiary measures, a “high degree of confidence” that users have reached the age of 15.

  1. Safety-by-design obligations

While the age-based access rules have attracted the greatest public attention, the KIDS Act’s broader ambition is to address the design choices that can encourage excessive use, amplify harmful content, or expose minors to inappropriate interactions. In doing so, it reflects a growing regulatory view that children’s online safety cannot be achieved through parental controls and age verification alone, but must be embedded into the architecture of the services themselves.

To achieve this, the proposed KIDS Act requires a wide range of online services used by minors, including social media platforms, video-sharing platforms, online games, AI companions and chatbots, to implement extensive safety-by-design measures. These include:

  • Restrictions on addictive features such as infinite scrolling, autoplay functionality, reward mechanisms and engagement-driven notifications, particularly during sleeping hours.
  • Safer recommender systems that provide minors with greater control over how content is suggested and reduce the risk of being drawn into harmful “rabbit holes” through profiling-based recommendation algorithms.
  • Privacy-protective default settings, including private accounts by default and limits on the collection and use of children’s personal data.
  • Strong protections against unwanted contact from strangers, cyberbullying and other forms of harmful interactions.
  • Child-friendly reporting, blocking and support tools that are easy for young users to access and understand.

The proposal also introduces specific safeguards for AI companions and chatbots. This includes requiring AI companions to be disabled by default for minors and avoid design features and system behaviours that simulate interpersonal relations that are likely to create emotional dependencies, manipulate behaviour or otherwise exploit children’s vulnerabilities.

  1. Age verification and parental controls

The proposal introduces specific age assurance obligations requiring providers to establish whether users are above or below relevant age thresholds and to ensure that children are provided with experiences, features and protections that are appropriate for their age. The proposal also introduces a framework for verifying parental responsibility where an adult seeks to create or manage an account on a child’s behalf.

The proposal acknowledges that effective age assurance must be balanced with users’ privacy and data protection rights. As a result, it emphasises that age verification and age estimation mechanisms should be designed in a privacy-preserving manner, minimising the collection and retention of personal data and avoiding the introduction of de facto identity verification for access to online services. The proposal requires age to be verified through certified solutions independent of the platforms, including a free EU age verification app. The proposal requires Member States to offer at least one free way to prove age, including for people without digital ID.

To strengthen the effectiveness of these safeguards, social media services and video-sharing platforms are required to verify users’ ages at the point of account creation.

Parents and guardians will also be given enhanced control tools, including screen-time management, contact supervision and account-setting controls.

The proposal goes beyond the GDPR’s specific rules on children’s consent. Its age assurance and age-appropriate design obligations are not limited to processing based on consent but may also affect services that rely on other legal bases, such as contractual necessity or legitimate interests.

  1. Compliance, Oversight and Penalties

    Primary responsibility for supervising the largest services would rest with the European Commission, building on the model established under the DSA. In-scope providers could face substantial penalties for non-compliance, including fines of up to 6% of their worldwide annual turnover and, in the most serious cases, temporary restrictions on the provision of services within the EU.

    The proposal also introduces proactive compliance obligations, particularly for VLOPs. The KIDS Act shifts the burden from regulators to providers, requiring VLOPs to proactively demonstrate, through a Commission-facing compliance plan and independent audits at their own expense, that they can meet obligations before their services are made available to children. The KIDS Act also introduces a supervisory fee, capped at 0.03% of a provider’s worldwide annual net income, to fund oversight and enforcement activities. The fee would apply not only to in-scope VLOPs, but also to certain providers of AI companions, general conversational chatbots and video gaming platforms.

    Timing

    The EU KIDS Act must now pass through the EU legislative process before it can be adopted. Several aspects of the proposal are likely to attract significant debate, particularly the age assurance requirements and the proposed age threshold of 15. While the European Commission has called for the legislation to be prioritised, adoption is unlikely to be immediate. Once adopted, most of the Act’s obligations would begin to apply six months after coming into force, giving providers a relatively short window to implement what are likely to be substantial compliance changes.

    What does this mean for organisations?

    Although the proposal is primarily aimed at online platforms and digital services used by children, its implications are likely to be far-reaching. Organisations operating consumer-facing digital services will need to assess whether their services fall within the scope of the Act and, if so, whether existing product designs, recommendation systems, engagement features and age assurance mechanisms are compliant.

    The proposal also reinforces a growing regulatory expectation that children’s safety should be embedded into product development from the outset. Businesses may therefore need to revisit governance structures, risk assessments, design processes and compliance programmes to ensure that child safety considerations are integrated across the product lifecycle.