Authors
On 17 September 2026, the European Commission published its draft proposal for the ‘Keeping Internet Digital Spaces Accountable and Trustworthy’ Act (well done to those who had already spotted that EU KIDS Act is an acronym!).
The headline measure is a prohibition on autonomous accounts for under 15s on social media and video-sharing platforms that pose specified risks. The proposal would also impose safety-by-design obligations on what the Commission brands “Social Media+” – social media, video-sharing platforms, online games, AI companions and general conversational chatbots, app stores and operating systems.
The EU KIDS Act forms part of a broader global trend toward stricter online safety for minors rules, aligning with similar efforts in the UK under the Online Safety Act 2023 (see one of our previous articles on the OSA here). Indeed, it follows a wave of EU member states’ proposals for national legislation – including in Italy, France, Norway, Greece, Austria, Poland and Belgium – which differ in terms of scope, age limits and restrictions imposed. One of the stated aims of the EU KIDS Act is therefore to set a consistent and harmonised approach across the EU.
In this article, whilst by no means exhaustive, we summarise the key elements of the proposal, and what it means for businesses operating in-scope services in the EU.
Which digital services are in-scope?
Online social networking services, video-sharing platforms, online games, AI companions and general conversational chatbots, app stores and operating systems are in scope, with the obligations differing between different services.
The definition of an ‘online social networking service’ is borrowed from the Digital Markets Act and means a platform that enables end users to connect and communicate with each other, share content and discover other users and content across multiple devices and, in particular, via chats, posts, videos and recommendations.
An ‘AI companion’ means an AI system, including a general-purpose AI system, that provides sustained, personalised interaction or companionship which simulates or facilitates a social, emotional or interpersonal relationship with a user. A ‘general conversational chatbot’ is defined as a general-purpose AI system with general conversational functionalities for direct interaction with users that is capable of providing assistance across multiple domains and tasks, but excludes AI systems whose conversational functionality is limited to a specialised service, task or pre-defined set of functions (e.g. customer service and tech support chatbots).
Notably, the definition of ‘online games’ is broad and includes both video games and video games platforms.
There are no exemptions for small or micro enterprises, with the Commission taking the view that businesses of any size can pose risks to minors online.
The list of exempted services is narrow and includes not-for-profit online encyclopaedias and educational or scientific repositories, services operated by educational establishments, open-source software platforms (unless the platform itself constitutes an in-scope AI system), and services developed exclusively by or for public authorities.
What does the EU Kids Act mean for in-scope services?
The proposed EU KIDS Act is built around four pillars, each targeting a different aspect of children’s online safety. Notably, the focus is on product design rather than content regulation and together, the pillars are intended to create a framework that goes well beyond age-gating and addresses the underlying design and operation of digital services used by children.
1. Social media delay: age-based access
The first pillar establishes an EU-wide minimum age framework for online social networking services and video-sharing platforms “whose services pose a risk to a child’s privacy, safety or security”. That means online social networking services and video-sharing platforms which include any of the following features:
- livestreaming, or otherwise enabling real-time transmission of content to an indeterminate number of recipients;
- enabling interaction with users outside a minor’s pre-existing connections or subscriptions;
- a recommender system based on profiling;
- a recommender system that suggests or prioritises content or contacts from outside a minor’s pre-existing connections or subscriptions; or
- features that enable uninterrupted content consumption, encourage interaction, or send automated notifications prompting a user to start or resume using the service.
Access to these services would be phased by age group:
- Under 3: No access at all.
- Under 13: Autonomous accounts on in-scope social media and video-sharing accounts would be prohibited. An exception is proposed for video-sharing platforms specifically designed for under-13s, under which a guardian may exceptionally enable access through the guardian’s own account, provided strict conditions are met:
- the service must be guardian-controlled through the guardian’s own account;
- the provider must have carried out and published an impact assessment demonstrating how risks to minors have been effectively mitigated;
- content and features must be adapted to the child’s age; and
- personalisation, recommendations, and search functions must be deactivated unless the provider can demonstrate their activation is in the minor’s best interests.
The service must include an hour a day limit and nothing at all may be provided below the age of three.
- 13 to 14: Guardians may set up limited “mini” social media and video-sharing accounts . The guardian would control and supervise the account via tools for guardians, including approving contacts, and the account would be subject to a cap of one hour per day.
- 15 to 17: Minors may create their own accounts independently, without requiring prior parental consent, provided these accounts operate within a safe-by-design environment.
In-scope services will be required to implement an EU age verification solution, certified as compliant with the EU Age Verification Scheme, to verify users have reached the minimum age or whether the creation of a parental account is necessary.
The proposal also addresses existing accounts. Within six months of the rules coming into force, social media and video-sharing platforms whose services pose a risk to a child’s privacy, safety or security would need to verify whether existing account holders are under the age of 15. Where they are, or where the user’s age cannot be established, those accounts would need to be disabled.
Regardless of age, all online services would need to adhere to the safety-by-design principles discussed below.
2. Safety by design
The second pillar would require in-scope services to follow strict safety-by-design principles and these obligations apply to a wider range of services. This is arguably the most far-reaching element of the proposal, as it governs how services are built and operated, not just who can access them. The following are examples of the key proposed obligations.
Social media and video-sharing platforms:
- Addictive design. The proposal would prohibit design practices that:
- enable automatic or uninterrupted content play and infinite scrolling without effective breaks;
- undermine a child’s decision to stop using the service, such as through notifications designed to pull the child back;
- incentivise or reward minors for sharing content or livestreaming to mass audiences;
- use ‘streak’ mechanics which penalise a child for not returning within specified timeframes; and
- use effective time-management measures protecting school time and core sleep hours (at least eight consecutive hours between 22:00 and 08:00 local time); push notifications must not be sent during those periods, except for urgent security alerts or interactions with guardians;
- Recommender algorithms. Service providers would need to ensure that:
- content recommendations prioritise what the child has explicitly asked for, rather than what the algorithm infers from their behaviour;
- personalised recommendations based on tracking are switched off by default; and
- personal data collected from outside the service is not used to tailor content.
- Contact and interaction safeguards. Under the proposal:
- content would be kept private by default;
- nobody could message a child without pre-approval (with additional safeguards against manipulation);
- children would not appear in contact suggestions and could not be added to groups without agreement;
- children could block anyone anonymously;
- children’s content would be visible only to accepted contacts, and their contact details would never be disclosed;
- children’s content could not be downloaded or screenshotted; and
- minors could not livestream.
- Safe default settings: Geolocation and tracking features, access to microphone and camera, recommendations of other accounts and contact synching and push notifications must be turned off by default for minors.
- Easy-to-use parental controls to set screen time limits, see contacts, receive warnings about repeated searches of harmful content, manage settings, and report harmful content on the child’s behalf.
- Transparency of economic transactions. The proposal would require minors to be told clearly and in real time when a transaction is taking place. Purchases made with virtual currencies would have to display their corresponding value in the national currency of the Member State where the minor is habitually resident. Providers would also need to avoid designs that could lead to excessive, impulsive or unwanted spending, including exposing minors to variable reward systems such as loot boxes and products with random or gambling-like features.
AI companions and general conversational chatbots:
- AI companions and general conversational chatbots accessible to minors would be subject to a range of requirements. These include, for example:
- prohibition on addictive design features (see above), including those that are likely to create emotional dependency;
- safe default settings (see above) and restrictions on using data from prior conversations;
- transparency of economic transactions (see above);
- access for under 13s must be enabled and controlled only via tools for guardians;
- pre-launch state-of-the-art safety testing and risk assessments, and requirement to implement safeguards to address risks, and
- post-market monitoring for emerging harms.
Where a chatbot is embedded within a social media platform, video-sharing service, or online game, it would not be permitted to be activated automatically or promoted to minors, and children would need to be able to opt out easily at any time.
Online Games:
- Providers of online games would be subject to the following requirements:
- Ensuring that compulsive or excessive use of the game by minors is not encouraged. In particular, the following will not be permitted: undermining or preventing a minor’s decision to stop playing and incentivising engagement at regular times or with greater frequency, including through penalties or loss of benefits.
- Safe default settings (see above);
- Implementing certain contact and interaction safeguards (see above);
- Access for under 13s must be enabled and controlled via tools for guardians;
- Implementing safeguards to prevent the game from being used to entice minors to initiate contact on other services; and
- Where a video gaming platform allows users to create and upload games, it would need to put in place the necessary software and organisational measures to ensure that those user-created games comply with the proposed safety-by-design rules.
App stores
- App stores would be subject to the following requirements:
- Requirement to implement an age-rating system for all apps distributed through their store.
- Prevent minors accessing or purchasing apps that are inappropriate for their age under this system.
The Commission would facilitate voluntary Union-level codes of conduct for age-rating systems and online games, building where appropriate on pan-European systems such as PEGI.
Very Large Online Platforms (VLOPs)
For platforms designated as Very Large Online Platforms (“VLOPs”) under the Digital Services Act, the proposal would reverse the burden of proof. Under the proposed EU Kids Act, the platform would need to demonstrate that its services are safe by design. VLOPs would be required to submit a compliance plan to the Commission showing how they meet each obligation, and these compliance plans would need to be independently audited at the VLOP’s cost.
Beyond the compliance plan, VLOPs would face additional ongoing obligations. They would need to monitor, test, and evaluate the effectiveness of their safety-by-design measures on a continuing basis. VLOPs would also need to ensure their guardian tools are interoperable with third-party parental control tools, and would be required to make relevant information available in the official language(s) of each Member State where the service is provided. Finally, VLOPs supervised by the Commission would be subject to an annual supervisory fee, capped at 0.03% of worldwide annual net revenue.
3. Age assurance and parental responsibility
The third pillar addresses one of the most difficult practical challenges in online child safety: how to verify a user’s age reliably without compromising their privacy.
In-scope social media and video-sharing services will be required to implement EU certified age verification solutions to verify users have reached the minimum age to access those services, or where applicable, if the creation of a parental account is necessary. In other cases, other age assurance solutions are permitted. Self-declaration of age is expressly insufficient.
Every Member State would need to offer at least one free way to prove age, including for people without a digital ID. Age assurance tools would be required to use “zero knowledge proof” technology. This means they would tell the platform only whether the user is above or below the relevant age threshold, and would not be able to identify, locate, track, or profile anyone.
Where an operating system provider has obtained a compliant age signal from a user, it must (with the user’s consent) enable that signal to be shared with other in-scope providers who need it for their own compliance.
In-scope services will also have to implement measures to verify parental responsibility.
4. Enforcement and supervision
The enforcement framework would operate through existing regimes. For online social networking services, video-sharing platform services, video gaming platforms and software application stores, enforcement would proceed under the DSA. For AI companions and general conversational chatbots, it would proceed under the EU AI Act.
Under this proposal, VLOPs would be supervised directly by the Commission, while national authorities would supervise other in-scope providers.
The proposal also includes an expedited timeframe for proceedings, under which the Commission will endeavour to communicate its preliminary findings to the provider within 30 working days from opening the proceedings and to adopt a final decision within 90 working days. This would represent a material change from the enforcement timeframes we have seen to date under the DSA.
Next steps
The EU KIDS Act remains a draft proposal and will now be considered by the European Parliament and the Council of the EU under the normal legislative procedure. The text is very likely to change before it becomes law.
Legal and compliance teams should monitor the legislative process and any consultations closely, as negotiations may refine key definitions, thresholds and obligations. Given the potential scale of the changes—particularly for product and engineering teams—businesses should nevertheless begin assessing now how the proposed requirements could affect their services.
Conclusion
The proposed EU KIDS Act goes well beyond an age-based social media ban. It would impose detailed requirements on service design and platform features. The proposal is likely to attract close scrutiny during the legislative process, particularly over its scope, proportionality and balance between child safety and other rights and freedoms.
The EU KIDS Act would add to an increasingly complex EU digital regulatory framework. In-scope services are already subject to the GDPR and EU consumer law, and many also fall within the Digital Services Act, the EU AI Act and the Audiovisual Media Services Directive. We also expect the first draft of the Digital Fairness Act in a few weeks. This expanding body of overlapping requirements sits uneasily with the Commission’s stated aim of simplifying regulation and reducing burdens to strengthen EU competitiveness.
Online platforms already implementing the DSA Article 28 guidelines will recognise many of the proposed requirements. Their first step should be to compare existing DSA controls with the EU KIDS Act proposal and identify genuinely new obligations. The greatest implementation burden is likely to fall on online games and AI chatbots that are not currently subject to the DSA. Even so, all in-scope services face additional compliance layers, substantial product redesign and significant engineering work.
A distinctive feature of the proposal is its detailed focus on platform design and user experience—areas not usually regulated so prescriptively in primary legislation. Rules that dictate product design may not fully account for engineering constraints or functional trade-offs. Because digital services evolve rapidly, highly specific requirements may also become outdated.
We will continue to monitor the EU KIDS Act and report on significant developments. If you have questions about how the proposal may affect your business, please contact our team.