Key Takeaways
- The European Commission proposed the EU KIDS Act on September 17, 2026. If formally adopted, the EU KIDS Act would be directly applicable as an EU regulation and would establish the most comprehensive child-safety framework for children’s access to online services, social media, video-sharing platforms, online games, AI companions and chatbots, app stores, and operating systems.
- The proposal creates a tiered age-restriction system: Children under 13 are prohibited from holding social media or video-sharing platform accounts; 13- and 14-year-olds may access only parent-supervised “introductory accounts” with strict limits on screen time, contacts, and features; and minors aged 15 and above may hold independent accounts on platforms that comply with safety-by-design requirements.
- Safety-by-design requirements would ban addictive design features for minors, including autoplay, infinite scroll, push notifications, streak engagement, and profiling-based recommendations, and impose new obligations for AI companions and chatbots, as well as prohibitions on emotional-dependency design and requirements for pre-market risk testing.
- Social media and video-sharing platforms would be required to implement EU-certified age verification at account creation using zero-knowledge proof technology; self-declaration of age would be explicitly excluded as a permissible method.
- Enforcement would leverage the existing Digital Services Act (DSA) and AI Act, with fines of up to 6% of worldwide annual revenue, fast-track investigations (preliminary findings within 30 days, final decisions targeted within 90 days), and mandatory third-party compliance audits at platforms’ expense for Very Large Online Platforms (VLOPs).
- The EU KIDS Act is a legislative proposal that must still pass through the European Parliament and EU Council co-decision process; it is not yet final law. However, it signals a major regulatory change and follows similar recent moves in the U.K. and ongoing legislative efforts in the United States.
Overview of the EU KIDS Act
On September 17, 2026, the European Commission adopted the EU Keeping Internet Digital Spaces Accountable and Trustworthy (KIDS) Act, which is a proposed regulation aimed at fundamentally restructuring how online services interact with children across the EU. The proposal defines a “child” or “minor” as any natural person under the age of 18. As a proposed regulation (rather than a directive), the EU KIDS Act would be directly applicable in all 27 EU Member States without the need for transposition through national legislation or approval from local parliaments, creating a single, harmonized set of rules binding each Member State. The Commission framed the proposal as a response to purported harms that social media platforms, online games, and AI-powered services are causing to children and minors. The proposal builds on and supplements the Digital Services Act and the AI Act, layering child-specific obligations on top of those existing frameworks.
Services in Scope and Not in Scope
The proposal is extremely broad and captures the following services:
- Online social networking services (as defined in the Digital Markets Act);
- Video-sharing platform services (as defined in the Audiovisual Media Services Directive);
- Online games, including “video games” and “video game platforms”—terms that are very broadly defined to capture virtually any interactive digital entertainment product that connects to the internet, regardless of whether it is hosted on a traditional platform;
- AI companions and chatbots, defined as AI systems that provide sustained personalized interaction simulating social or emotional relationships;
- App stores; and
- Operating systems, meaning system software “that controls the basic functions of the hardware or software and enables software applications to run on it” (as defined in the Digital Markets Act).
The proposal excludes not-for-profit online encyclopedias, not-for-profit educational or scientific repositories, certain public authority services, open-source software developing and sharing platforms (unless they qualify as AI systems under the AI Act), and services designed primarily for educational purposes and operated by educational establishments.
Tiered Age Restrictions
The proposal establishes a three-tiered system of age-based restrictions, harmonized across the EU so that Member States cannot impose higher minimum ages.
- For children under 13, the proposal prohibits social media and video-sharing platform accounts outright. A narrow exception permits video platforms specifically designed for children under 13 to allow limited access through a parent’s account, subject to restrictions including no personalization, a maximum of one hour of screen time, and parental controls.
- For children aged 13 and 14, parents or guardians may set up “introductory accounts” with tightly limited features: a maximum of one hour of daily screen time, a capped list of pre-approved contacts, and parental controls that remain active at all times.
- For minors aged 15 and above, independent accounts are permitted, but only on services that comply with the regulation’s safety-by-design requirements.
Critically, existing accounts are not grandfathered: Within six months of the regulation taking effect, platforms must verify whether existing account holders are under 15 and must disable accounts belonging to underage users or accounts whose holders’ ages cannot be established. The proposal would not allow self-declared age and would instead require certified age verification.
- Safety-by-design requirements. The proposal mandates that all in-scope services implement “safety by design” for minors.
- Addictive design. The proposal specifically bans a range of addictive design features when presented to children, including autoplay of content, infinite scrolling, push notifications designed to re-engage users, rewards for sharing or live broadcasting, and streak mechanics that penalize non-engagement.
- Recommender systems must not exploit a child’s vulnerability; profiling-based recommendations must be disabled by default; and platforms must not use personal data collected from outside the service to inform recommendations to minors.
- Safe settings. Default privacy settings must disable microphone and camera access, switch off geolocation and tracking, and turn off push notifications.
- Contact and interaction safeguards require that strangers cannot contact a child without prior parental or guardian pre-approval, children cannot be added to groups without their explicit consent, and anonymous blocking must be available.
- Economic transaction protections guard against excessive or impulsive spending by minors. Services must also provide time management tools that protect school time and core sleep hours.
Requirements for AI Companions and Chatbots
The proposal introduces specific obligations for AI companions and chatbots—i.e., AI systems that provide sustained, personalized interaction simulating social or emotional relationships. Such systems may not be designed in a manner likely to simulate interpersonal relations that create emotional dependencies in children. They may not use information from previous interactions with a child (unless necessary for safety purposes), preventing the accumulation of persistent conversation data by default. Providers must conduct pre-market testing and evaluation for risks to children’s health, safety, fundamental rights, and well-being, and must implement post-market monitoring. Where AI features are embedded within social media or video-sharing platforms, those features must not auto-activate, must not be pushed at children, and must be easy for the child to turn off. These obligations would be enforced under the AI Act regime rather than the DSA.
Age Verification and Privacy
Age verification is central to the EU KIDS Act’s architecture. Social media and video-sharing platforms would have to implement EU-certified (or equivalent) age verification at the point of account creation. As noted above, the proposal prohibits self-declaration of age for social media and video-sharing services. Instead, the proposal requires zero-knowledge proof technology, which is a cryptographic method that allows a trusted third-party verification service to confirm to a platform whether a user is above or below a given age threshold (a simple yes-or-no answer) without disclosing the user’s actual date of birth, name, identity documents, or any other personal data. The technology would have to be designed so that it cannot identify, locate, track, target, advertise to, or profile users and be certified as conforming with the EU Age Verification Scheme.
The Commission envisions two principal tools: the EU Digital Identity Wallet (EUDI Wallet), which is planned as the long-term solution, and an EU open-source age verification app as an interim measure (although the Commission has acknowledged that while the app is technically ready, there are security issues that need resolution). Every Member State must offer at least one free method for users to prove their age.
For services other than social media and video-sharing platforms (such as online games, app stores, and operating systems), alternative age assurance solutions are acceptable provided they are accurate, reliable, secure, robust, non-intrusive, non-discriminatory, and maintain a high level of privacy. Industry groups and privacy advocates have flagged that collecting age information, identity credentials, and parent-child relational data at scale creates significant cybersecurity risks, and that age verification alone may not be a comprehensive solution to child safety online.
Enforcement and Penalties
The proposal leverages existing enforcement mechanisms. Most in-scope services would fall under the DSA’s enforcement regime, while AI companions and chatbots would be subject to enforcement under the AI Act. Noncompliance could result in fines of up to 6% of total worldwide annual turnover, consistent with the DSA’s existing penalty framework. Very Large Online Platforms (VLOPs) (defined as platforms having more than 45 million monthly active users in the EU) would face additional obligations: they must submit a detailed compliance plan within four months of their designation (or within 30 days of the regulation coming into effect, if they are already designated under the DSA). VLOPs must also undergo third-party compliance audits at their own expense, monitor, test, and evaluate the effectiveness of their compliance measures as part of their DSA risk assessments, submit a separate age-verification compliance plan, and pay an annual compliance monitoring fee (in addition to the existing DSA supervisory fee). The Commission envisions a fast-track investigation process for services it directly supervises: preliminary findings would be issued within 30 days, with final decisions targeted within 90 days. For video games not subject to DSA supervision, Member States are required to designate national regulators. Notably, the burden of proof is reversed: platforms must demonstrate that they are safe, rather than regulators having to prove that they are not.
Impact on Social Media Companies
Social media platforms would face the most sweeping set of new obligations under the proposal. Such platforms must implement EU-certified age verification at sign-up for every new account. They must ban accounts for all children under 15 (except for the narrow “introductory account” exception for 13- and 14-year-olds set up by a parent or guardian). Within six months of the regulation taking effect, platforms must retroactively verify the ages of existing account holders and disable underage accounts or accounts where age cannot be established. Platforms may need to redesign core product features for all users under 18: Addictive design features such as autoplay, infinite scroll, push notifications designed to re-engage, streak engagement, and reward-for-sharing systems must be disabled or removed. Recommender systems must be reconfigured to avoid profiling-based personalization for minors by default. Stranger contact must be blocked unless pre-approved by a parent or guardian. For introductory accounts (ages 13-14), platforms must provide robust parental tools including always-on parental controls, a one-hour daily screen time maximum, and a limited, pre-approved contact list. VLOPs (which include all major social media companies under current DSA designations) would face additional obligations including mandatory compliance plans, third-party audits, and annual compliance monitoring fees. The overall effect would be a fundamental product and engineering overhaul for social media companies operating in the EU, requiring changes across account creation flows, recommendation algorithms, notification systems, user interfaces, privacy defaults, and content moderation.
Impact on Video Game Companies
The proposal brings online games squarely within the scope of comprehensive child-safety regulation for the first time at the EU level. The very broad definition of “online game” means that virtually any internet-connected interactive entertainment product is captured, from massive multiplayer online games and mobile free-to-play titles to console games with online features. Games accessible only through physical media without an online component would not be subject to the EU KIDS Act.
The proposal explicitly states that small and micro enterprises would not be exempted from the regulation because they “may equally provide harms to minors.” Accordingly, smaller game studios and indie developers would face the same safety-by-design and age assurance obligations as major publishers, with potentially disproportionate compliance costs. These obligations include:
- Safety-by-design. Game companies would be required to comply with safety-by-design requirements, including banning addictive design features for minors (such as loot box-style randomized reward mechanics, streak penalties, and push notifications to re-engage) and implementing safeguards against enticement to other services.
- Broad definitions. A key risk is the breadth of the definitions: the terms “video game” and “video gaming platform” are arguably broad enough to cover a wide range of services and platforms beyond what one might typically consider to be a video game—for example, films allowing user interaction could fall within scope—and the use of “online game” as an umbrella term for both individual games and the platforms that host them would create definitional confusion. Companies operating at the boundary of interactive entertainment may need to evaluate carefully whether their products are captured, and some providers may face pressure to withdraw certain services from the EU market to avoid triggering restrictive design obligations.
- Virtual currency. The proposal takes a more tailored approach to games than to social media. Article 15 specifically cross-references only certain subsections of the addictive design rules, safe settings, contact protections, and mandatory guardian tools, and it does not cross-reference Article 13 on economic transactions and virtual currencies. This means that, as currently drafted, game providers would not be subject to the same binding virtual-currency transparency requirements that apply to social media and video-sharing platforms. However, this could create significant regulatory uncertainty: The recitals state that minors playing online games should be protected against unwanted spending linked to virtual currencies and variable-reward systems, including gambling-like features, and should be shown the real monetary value of transactions, but those protections are not reflected in the binding articles. It is possible that virtual-currency transparency requirements may resurface in a future legislative proposal, potentially with direct application to in-game purchases. Companies relying on free-to-play monetization models, microtransactions, or in-game virtual currencies should monitor the Digital Fairness Act closely, as it could include binding requirements that could materially affect revenue models.
- Age assurance. Unlike social media and video-sharing platforms, which would have to use EU-certified age verification at account creation, game providers could use alternative age assurance methods, provided those methods meet the requirements described in Article 27 and Article 28 (i.e., are accurate, reliable, secure, robust, non-intrusive, non-discriminatory, and privacy-preserving). This flexibility avoids a one-size-fits-all approach and may allow game companies to leverage existing age-rating frameworks rather than implementing entirely new verification infrastructure. In that regard, Article 17 of the proposal explicitly recognizes industry-led self- and co-regulatory age-rating systems, including the Pan European Game Information system (PEGI), and the Commission will facilitate EU-level codes of conduct for age rating and online games within one year of the regulation’s application. Adherence to an adequate code of conduct may serve as evidence of compliance with Article 15 obligations for providers of online games—a significant potential benefit for companies already participating in PEGI or similar systems. The codes of conduct will be assessed for adequacy by the Commission after 42 months and would cover criteria including mutual recognition of age ratings across Member States, common methodologies for assessing age-appropriateness of content (including violent, sexual, gambling, and self-harm content, as well as in-app purchases, contact risks, and addictive design features), and harmonized age-rating labels. Similarly, the proposal’s support for default-off settings for certain features and parental tools that account for a child’s maturity, rather than blanket feature bans, gives game companies some design flexibility to balance child safety with gameplay experience.
- Enforcement. Online games that do not qualify as VLOPs or video-sharing platform services will not be directly supervised by the Commission; instead, Member States must designate national regulators. While this avoids direct Commission oversight for most game companies, it introduces the risk of uneven enforcement across Member States, as the quality and aggressiveness of national supervision may vary. Additionally, some of the regulation’s prescriptive product-design mandates could pose unforeseen engineering challenges, particularly for live-service games, user-generated content platforms, and titles with complex social features that were not designed with the EU KIDS Act’s framework in mind.
Comparison With U.K. Law
The EU KIDS Act follows closely on the heels of the U.K.’s announcement of its own social media restrictions for children. On June 15, 2026, then-U.K. Prime Minister Keir Starmer announced a ban on social media for children under 16, with implementation planned for Spring 2027, following Australia’s December 2025 ban on social media for children under 16. The U.K.’s measures, to be implemented through secondary legislation under the Online Safety Act 2023 and enforced by Ofcom, also ban livestreaming and stranger communication for children under 16 on a broader set of services including gaming, and impose default-on restrictions for 16- and 17-year-olds including curfews, muted push notifications, and limits on autoplay and personalized feeds. The U.K. has also announced a ban on sexualized AI chatbots for users under 18.
Several key differences exist between the U.K. and EU approaches. First, the U.K. sets its independent-account age threshold at 16, versus 15 in the EU, meaning that 15-year-olds in the U.K. would remain subject to a full social media ban while their EU counterparts could access independent accounts. Second, the U.K.’s restrictions on gaming services, including the ban on stranger communication and livestreaming, are in some respects broader than the EU’s approach, which differentiates obligations depending on whether a game qualifies as a social media or video-sharing platform. Third, the EU KIDS Act is a proposed harmonized regulation that, once adopted, would apply uniformly across all Member States, whereas the U.K.’s approach relies on secondary legislation under the existing Online Safety Act 2023, giving Ofcom implementation flexibility but also providing less legal certainty during the rulemaking phase.
Comparison With U.S. Law
The United States presents a starkly different landscape: fragmented, piecemeal, and constitutionally constrained. At the federal level, the Children’s Online Privacy Protection Act (COPPA), enacted in 1998, remains the primary federal statute, but it applies only to children under 13 and focuses narrowly on data collection and parental consent rather than platform design or safety-by-design obligations. Federal legislative momentum has accelerated in 2026, however: the Senate Commerce Committee voted to advance an amended version of the Kids Online Safety Act (KOSA, S.1748) on August 5, 2026, and the House passed the Kids Internet and Digital Safety (KIDS) Act (H.R. 7757) on June 29, 2026, which incorporates KOSA provisions together with COPPA 2.0 and the Shielding Children’s Retinas from Egregious Exposure on the Net Act (SCREEN Act). However, these bills have not yet been reconciled. KOSA would impose a duty of care on platforms, require safety-by-default settings, mandate parental tools, provide algorithmic opt-out for minors, and ban targeted advertising to minors. COPPA 2.0 would extend protections to teens under 18, ban targeted advertising to minors, and impose data minimization requirements.
At the state level, the landscape is even more fragmented. Florida bans social media accounts for children under 14 (with parental consent required for 14- and 15-year-olds). California enacted the Age-Appropriate Design Code Act (AB 2273), which faced ongoing legal challenges and was repealed and replaced by AB 2246, which was signed into law on September 10, 2026. California also enacted the Digital Age Assurance Act (AB 1043), effective January 2027. New York requires chronological feeds and overnight notification blocks for children. Utah, Arkansas, Maryland, and Texas have each enacted their own age verification or age-appropriate design laws, many of which face First Amendment challenges in federal courts. No single comprehensive federal law exists that is comparable in scope to the EU KIDS Act. The contrast is stark: The EU’s approach is a unified, directly applicable regulation, while the U.S. relies on a patchwork of federal proposals and state laws, many of which face significant constitutional constraints on age-gating under the First Amendment. Enforcement in the U.S. is primarily through the Federal Trade Commission (FTC) (for COPPA) and state attorneys general, rather than through direct regulatory supervision by a central authority comparable to the European Commission’s role overseeing VLOPs under the DSA.
Comparative Overview: EU KIDS Act vs. U.K. vs. U.S.
Feature | EU KIDS Act | United Kingdom | United States |
Minimum age for independent social media account | 15 (introductory accounts at 13-14 with parental supervision) | 16 (social media ban for under-16s; default-on restrictions for 16-17) | No federal minimum; state laws vary (Florida: 14; COPPA: 13 for data collection only) |
Age verification requirement | EU-certified verification with zero-knowledge proof; self-declaration excluded | Yes, to be specified by Ofcom under Online Safety Act | No federal requirement; some state laws mandate verification (many enjoined on First Amendment grounds) |
Safety-by-design mandate | Yes; bans autoplay, infinite scroll, push notifications, streak engagement for minors | Yes; default-on restrictions for under-18s including curfews, muted notifications, limits on autoplay | KOSA (if enacted) would require safety-by-default; California AADC faces legal challenges; no comprehensive federal mandate |
AI chatbot regulation | Yes; bans emotional-dependency design; pre-market testing required; enforced under AI Act | Bans sexualized AI chatbots for under-18s | No federal AI chatbot regulation for children |
Gaming regulation | Yes; broad “online game” definition; safety-by-design; Member State regulators | Broader restrictions including bans on livestreaming and stranger contact in gaming for under-16s | No comprehensive federal gaming regulation for children; industry self-regulation (ESRB) |
Enforcement authority | European Commission (VLOPs); Member State regulators (others) | Ofcom (under Online Safety Act 2023) | FTC (COPPA); state AGs; no central federal authority for design/safety |
Maximum penalty | Up to 6% of worldwide annual turnover | Up to 10% of qualifying worldwide revenue (Online Safety Act) | COPPA: up to ~$51,744 per violation (FTC); state laws vary |
Current status | Proposed Regulation; must pass European Parliament and EU Council co-decision | Announced June 2026; regulations to be laid before end of 2026; implementation Spring 2027 | KOSA passed the Senate (July 2026); KIDS Act passed the House (June 2026); not yet reconciled or enacted; multiple state laws, many facing litigation and injunction |
Next Steps and Legislative Timeline
The EU KIDS Act is a legislative proposal adopted by the European Commission and is not yet law. The proposal must now proceed through the European Parliament and the Council of the European Union under the ordinary legislative procedure (co-decision). Both institutions will conduct their own readings, propose amendments, and agree on a common version of the text before the regulation can be formally adopted. Because negotiations over the specific requirements are expected, the final text may differ significantly from the Commission’s proposal. The timeline for enactment is uncertain but based on prior experience with major digital regulation (the DSA took approximately two years from proposal to adoption), organizations should expect a multi-year legislative process.
If adopted, the EU KIDS Act would set out a phased implementation timeline with concrete planning milestones. From the date of application, safety-by-design obligations and age verification requirements would take effect, and platforms would need to comply. Six months after the date of application, platforms would have to verify whether existing account holders are under 15 and disable accounts that are underage or whose age cannot be established. Twelve months after the date of application, parental account features would have to be enabled, AI companion and general conversational chatbot rules take full effect, codes of conduct for age rating must be facilitated, and the expedited enforcement regime becomes operational (with 30 days for the Commission to reach preliminary findings and 90 days for final decisions). In the meantime, the DSA’s existing Article 28 obligations regarding the protection of minors remain in effect and may be further clarified through Commission guidance. Organizations subject to the current DSA framework should treat the EU KIDS Act as a strong signal of the direction of European regulatory policy and begin assessing the operational, product, and compliance implications now.
We will continue to monitor these developments, including the progression of the EU KIDS Act through the co-legislative process, related enforcement actions under the DSA and AI Act, and parallel developments in the U.K. and the United States.
+++
Apurva Dharia is an associate in DWT’s Washington, D.C. office, Maya Yamazaki is a partner in the firm’s Seattle office, and Nancy Libin and Robert Stankey are partners in our Washington, D.C., office. For any questions or more insights, please reach out to the authors or another member of our technology + privacy & security and communications teams. To stay informed, sign up for our alerts.
