​​The EU KIDS Act: Europe moves online child safety beyond social media bans ​ | #childpredator | #kidsaftey | #childsaftey


On 17 September 2026 the European Commission (Commission) adopted its proposal for the EU KIDS Act to enhance the online safety of minors in the EU. With national minimum-age legislation for social media already in train or under discussion in many Member States (including France, Austria, Spain, Germany, Poland and Portugal), the EU-level proposal aims to prevent otherwise inevitable fragmentation. Taken as a whole, the proposal is considerably broader than the debate that preceded it. While political discussions have focused largely on introducing a minimum age for social media, the draft EU KIDS Act would establish a child-specific regulatory framework, covering not only social media and video-sharing platforms, but also AI companions and chatbots, online games, and, with a more limited scope of obligations app stores and operating systems. While the timing of adoption is uncertain – the average completion in similar cases is around two years – the EU KIDS Act would, once adopted, apply six months after entry into force.

The EU KIDS Act is built around four pillars: 

(1) Delayed access and age-based protection of minors online: (a) children under the age of 15 are not allowed to create their own accounts for social media and video-sharing services, but can have parent-supervised accounts with limited features and time restrictions; (b) account-based access to specifically-designed child-friendly video-sharing services for under 13-year-olds through their guardians’ accounts, if their guardian permits; (c) minors from 15 to 18 can set up own accounts, operating within a safe-by-design environment. 

(2) Safety-by-design obligations for services children use most, from social media and video platforms to games, AI chatbots and app stores (applying by default unless the user is established to be an adult). 

(3) Age assurance, requiring verification of user age at account creation as well as checks for users who already have an account. Age verification can be done via the EU Age Verification Solution or other third-party solutions that offer reliable, secure and privacy-preserving means to verify the user’s age.

(4) Enforcement as well as supervision which draw on the existing DSA and AI Act frameworks. Smaller providers would be overseen by local regulators and Very Large Online Platforms under the DSA would be supervised by the Commission.

For online platforms already in scope of the DSA this may create some tension with the existing DSA obligations under Article 28(1) to “put in place appropriate and proportionate measures to ensure a high level of privacy, safety, and security of minors on their service”. For a detailed overview on the Article 28 DSA requirements and the Commission Guidelines see our previous blogpost here.  

Regulatory context and analysis

Broad scope – going beyond the DSA. While the DSA applies to intermediary services, and Article 28 binds only providers of online platforms accessible to minors, the draft EU KIDS Act goes beyond this, setting out a list of seven categories of digital services in scope: online social networking services, video-sharing platforms, software application stores, online games, operating systems, AI companions and general conversational chatbots. Consequently, it would reach services that are typically not considered online platforms under the DSA, such as AI companions and general conversational chatbots, operating systems, and online games that do not disseminate third-party content publicly. In addition, and unlike much of the DSA, the draft EU KIDS Act deliberately does not exempt micro and small enterprises, on the basis that they may equally cause harm to minors. Instead, the draft regulation exempts by type,  not applying to (1) not-for-profit encyclopaedias, (2) educational and scientific repositories, (3) services designed primarily for educational purposes and operated by educational establishments, (4) research and public-authority services, and (5) open-source software-developing and sharing platforms (unless the platform itself is an AI system in scope of the AI Act). 

The tiered age approach. Users under 15 would be prohibited from holding an account on an online social networking or video-sharing platform service that poses a risk to a minor’s privacy, safety or security due to any of the following functionalities: real-time content transmission to an indeterminate audience; contact with users outside pre-existing connections, a profiling-based recommender system, a recommender system suggesting contacts or content from outside those connections, or design enabling uninterrupted consumption, incentivising interaction, or sending prompting notifications (Article 6(1)). Guardians may open limited accounts for users aged 13 to 15, with guardian tools always on, a one-hour daily cap and pre-approved contacts. Under 13s may access only video-sharing platform services “specifically designed” for children of that age group through the guardian’s own account subject to certain limitations (Article 7). Existing accounts must be screened within six months after the regulation becomes applicable (Article 6(4))  with providers required to disable accounts established to belong to users under 15 as well as  accounts where the user’s age cannot be established.

Age verification and assurance solutions. For compliance with the minimum-age requirements under Article 6, providers of online social networking and video-sharing platform services must rely exclusively on a certified EU age verification solution using a third-party proof of age attestation from the Commission’s lists (Article 29(2)); a certified European Digital Identity Wallet qualifies as such a solution (Article 29(3)). Existing accounts can be exempted where the provider can establish with high confidence that the holder is an adult (Article 32(2)).

Outside the strict Article 6 minimum-age regime, the safety-by-design obligations under Article 8 – applicable to online social networking services, video-sharing platform services, online games, AI companions and general conversational chatbots, and app stores – allow more flexible age assurance. Alternatives are allowed if they meet the general criteria, which are largely based on the Commission’s Article 28 DSA Guidelines: (i) no identification, tracking, targeting, advertising or profiling; (ii) no more personal data than strictly necessary; (iii) state of the art technology; and (iv) a zero knowledge proof (Article 29(4)). An age signal may be stored at account level to avoid repeat checks (Article 28(4)). In addition, establishing a free complaint mechanism against a wrong result is mandatory (Article 29(5)). 

Safety-by-design obligations. Safety by design applies by default, and may be switched off only once the user is established as an adult. The specific requirements largely reflect the Commission’s Article 28 DSA Guidelines and would elevate them to binding legal obligations, while extending their scope beyond the DSA scope. 

Online social networking and video-sharing platform services

  • Addictive design. Addictive design is prohibited, which covers autoplay without effective interruption, notifications unrelated to the minor’s activity, rewards for sharing or livestreaming, and streaks that penalise a child for not returning daily. Time limits must protect school time and core sleep hours (Article 9). 
  • Recommender systems. Recommender systems must give primary weight to stated preferences, disable implicit engagement signals by default, and offer a non-profiling option (Article 10).
  • Safe settings. Geolocation, camera, microphone, account recommendations and push notifications are off by default, changeable only by users over 15 with explicit consent. Features increasing social comparison or idealising a minor’s image must not be available (Article 11). 
  • Contact and interaction safeguards. Providers must put in place measures to ensure that strangers cannot initiate direct contact if the minor has not pre-approved such contact. Group additions require explicit agreement, minors are excluded from contact recommendations and livestreaming is off by default (Article 12).
  • Economic transactions. Transactions must be flagged in real time with virtual currency shown in real money, and variable rewards are off-limits (Article 13). 

AI companions and general conversational chatbots

  • AI companions and chatbots must avoid design likely to create emotional dependencies, and require pre-market risk evaluation and post-market monitoring. Where integrated into a social networking service, video-sharing platform or online game, they must not be activated automatically or displayed prominently, and minors must be able to opt out easily at any time (Article 14).

Online games

  • Online games must implement safeguards to prevent games being used to lure minors to establish contact on other services, while platforms hosting user-created video games must provide the technical and organisational means necessary to enable those games to comply with the applicable requirements (Article 15). 

Software application stores

  • App stores would be required to establish an age-rating system covering each app offered through their services, publish the methodology, criteria and sources underpinning that system, prevent minors from accessing or purchasing apps that are inappropriate for their age, and allow a certified EU age-verification solution to be offered through the store (Article 16). Notably, the Commission’s Article 28 DSA Guidelines contain no equivalent app-specific age-rating and access-control regime for app stores. These obligations therefore constitute a substantive addition to the Art. 28 DSA Guidelines

Operating systems

  • Where an operating system provider has obtained an age signal using a compliant age-assurance method, it must, with the user’s consent, enable that signal to be shared with in-scope providers where necessary for compliance with the regulation. The provision does not impose a general obligation on operating-system providers to collect age signals (Article 29(6)).

For businesses in scope of Article 28(1) DSA and the children’s safety duties under the UK Online Safety Act 2023, a number of these proposed safety requirements will look familiar, and many organisations will be able to leverage existing operational processes for their EU users.

Compliance plans and audits for VLOPs. Online social networking and video-sharing platform providers designated as Very Large Online Platforms (VLOPs) under the DSA must notify a compliance plan to the Commission (Article 5 ). That notification is due within four months of designation as a VLOP, or 30 days of application if already designated. VLOPs are required to commission an independent audit of their compliance plan, with audit reports due within two months and a summary of the findings made public. On a finding of shortcomings, a corrective action plan is due within 30 days and to be implemented within 60 days. None of this, however, would constitute a finding of compliance with EU KIDS Act or limit the Commission’s enforcement powers in relation to that provider. 

Enforcement and the supervisory fee. Supervision  and enforcement provisions  draw on the existing DSA and AI Act frameworks. Chapter IV DSA applies to social networking, video-sharing, video gaming platforms and app stores, including the penalty regime under Article 52 DSA, while Chapter IX AI Act covers AI companions and chatbots, with fines of up to 6% of the provider’s worldwide annual turnover. National competent authorities would supervise other services, including online games that do not qualify as online platforms. In addition, data protection authorities would retain competence over age assurance mechanisms, including the power to impose fines under Article 83(5) GDPR. 

For in-scope providers of VLOPs and AI systems supervised by the Commission under Article 75 AI Act, an expedited procedure aims  for preliminary findings within 30 working days and a final decision within 90 working days.  Commission supervision and the EU Age Verification Scheme would be funded through an annual supervisory fee capped at 0.03% of each provider’s worldwide annual net income.

Notably, the EU KIDS Act would also be added to Annex I of the Representative Actions Directive, meaning that qualified entities could bring representative actions seeking injunctive or redress measures for infringements harming consumers’ collective interests.

Interplay with existing EU data, media, platform, consumer and product safety laws.  As noted above, the draft regulation would apply in addition to Article 28(1) DSA by largely codifying as hard law the measures contemplated by the Commission’s Article 28 Guidelines. The impact assessment presents the EU KIDS Act as building on, rather than replacing, the Guidelines, with material additions including, in particular, the rules on AI companions and chatbots, the extension to online games and the obligations imposed on app stores. Compliance with the EU KIDS Act would be deemed compliance with Article 28(1) DSA for matters covered, but pending Article 28(1) DSA proceedings would remain unaffected, and the Guidelines would continue to provide the relevant benchmark until the regulation becomes applicable. In addition, the draft EU KIDS Act is without prejudice to other relevant EU legislation such as the AVMSD, consumer and product safety law, the GDPR and the e-Privacy Directive. It also expressly complements the AI Act’s ban on exploiting age-related vulnerabilities and the UCPD’s protection of minors as vulnerable consumers. It remains to be seen, however, how the complex and already foreseeable questions concerning the delineation of these overlapping regimes will be addressed during the (further) legislative process.

Implementation. As of the current draft, the EU KIDS Act would apply six months after its entry into force. The compliance plan and audit duty would apply immediately, while national support measures and the expedited procedure would follow after twelve months. Notably, the age threshold may be an area of contention: national drafts already span ages 13 to 16 across France, Greece, Austria, Italy, Belgium and Norway. The proposal also grants the Commission extensive delegated powers, including the ability to amend key substantive requirements relating to addictive design, recommender systems, default settings and protections for AI companions and chatbots, as well as the list of exempt services.

The Commission is candid that the proposed rules will not work overnight. It points to Australia, where a minimum age of 16 has applied since December 2025 and most minors who already held accounts still have them, having never been asked to prove their age. Accordingly, the Commission’s approach is to start now, even if it may take time for the benefits to come to fruition. 

Next steps: an increasingly global content moderation regime

The draft regulation joins an already crowded regulatory landscape beyond Article 28 DSA. Australia’s under-16 ban has applied since December 2025, and the UK’s Online Safety Act children’s safety duties have been live since July 2025, with Ofcom’s Protection of Children Codes, highly effective age assurance, and an enforcement programme on children’s risk assessments opened in April 2026, as well as a proposed social media ban and associated safety by design obligations. Much of the EU KIDS Act draws from these regimes: age assurance, safe defaults, recommender controls, limits on addictive design and documented risk work, but it takes a novel approach in other areas, including in relation to AI companions, online games and app stores. 

The US is moving in a similar way: while there is no federal counterpart – the Kids Online Safety Act remains stalled, and the primary federal regime is still COPPA on the privacy side – the main equivalents to the KIDS Act are at state level; age-appropriate design codes in Maryland, Nebraska, South Carolina and Vermont, and app store age verification and parental consent duties in Texas and Utah. 

If your products and services are in scope of the emerging regimes in the UK, US, or Australia, your existing operational processes may be able to be leveraged for your EU users. However, we expect the KIDS Act to catch a number of services out of scope of current content moderations laws; if that is your organisation, our global content moderation team has extensive experience of bringing products and services into compliance with safety requirements of this kind.

The proposal of the KIDS Act now passes to the European Parliament and the Council under the ordinary legislative procedure. While the timing of adoption is uncertain , we expect, at least, a two year negotiation according to the average time of this process.

***

 



Source link

——————————————————–


Click Here For The Original Source.