Authors
The EU KIDS Act has landed
On 17 September 2026, the European Commission published its proposal for the EU KIDS Act (the snappily named ‘Keeping Internet Digital Spaces Accountable and Trustworthy’ Act). The proposals are to restrict minors’ access to certain high-risk services and impose child-specific product-design rules across a range of digital products. The headline measure is a prohibition on autonomous accounts for under-15s on qualifying social-networking and video-sharing services following a wave of national initiatives across Europe, with proposed age limits ranging from 13 to 16. It is a long and detailed text but key highlights below.
What has been proposed?
A directly applicable EU regulation covering what the Commission brands “Social Media+”: social networks, video-sharing platforms, online games, app stores, operating systems, AI companions and conversational chatbots. There are narrow educational and not-for-profit carve-outs.
The draft regulation applies to services offered in the EU regardless of where the provider is established as with equivalent regulations, and the principal age bands to which the provisions relate are under 13, 13–14, 15–17 and 18+. The regulation is designed to create a harmonised framework across the EU and expressly prohibits Member States from imposing stricter minimum age limits than those set out in the Act.
Who is in scope?
A product must fall within a regulated service category, but the specific features then determine which obligations apply.
Key account restrictions are limited to social-networking and video-sharing services with features such as livestreaming, contact beyond existing connections, profiling-based recommendations, uninterrupted consumption, incentivised interaction or attention-recapturing notifications. These don’t apply to games, AI companions, chatbots, app stores or operating systems, however, it looks like care will be needed as adding user-uploaded video, public profiles, comments, DMs or creator livestreams could move a product towards the social-networking or video-sharing definitions.
The proposed safety-by-design rules apply more broadly by default to social networks, video-sharing platforms, online games, app stores, AI companions and general conversational chatbots, including, crucially, for unregistered users. Providers can depart from the child-protective experience only after establishing that the user is an adult.
What restrictions are proposed for each age band?
- Under 13: no account at all on an in-scope social or video-sharing service. The exception is for video-sharing platforms specifically designed for this age group, which may allow guardian-controlled access through the guardian’s own account, subject to a published impact assessment, and the turning off of personalisation, recommenders and content search unless that assessment justifies otherwise. Additionally, the service must include an hour-a-day limit, and nothing at all may be provided below the age of three.
- 13 to under 15: no autonomous account is permitted, but a provider may – not must – let a guardian create a limited account. If it does, guardian tools must always be active, the guardian must be able to set a daily cap of no more than one hour and pre-approve new contacts and limit the number of contacts. These accounts belong to the guardian, not the child.
- 15 to under 18: teenagers can set up their own autonomous account without parental approval – but the safety-by-design obligations continue to apply to that account by default.
The proposal addresses autoplay, notifications, recommender systems, contacts, livestreaming, visibility settings, appearance-altering filters, virtual currencies and variable rewards. For AI companions and chatbots, the rules also address emotional dependency, persistent memory and how those products are presented to minors. For online games, in addition to prohibitions on addictive design, the proposal requires safeguards against enticements to off-platform contact.
What age assurance measures are expected?
Self-declaration is expressly insufficient. Many service providers must use a certified EU age-verification solution using an EU proof-of-age attestation delivered through the prescribed independent, certified architecture, however operating systems holding compliant age signals may (with consent) share them with other apps and services.
For 13–14 accounts, the provider must establish the child’s age through a prescribed verification framework. It must also separately establish that the adult exercises parental responsibility for that particular child. An adult may initially self-declare that relationship, but the provider must make reasonable efforts to verify it.
Do the proposed rules only apply to new users?
No. Within six months of application, providers must establish whether existing account holders are under 15. If a user is under 15 (or their age cannot be established), the account must be disabled, subject to any compliant route into a guardian-controlled limited account. It remains to be seen whether eligible 13–14 accounts could instead be converted to a parent-managed account rather than disabled. There is also an exception available where providers can establish with a high degree of confidence that the user has already reached the applicable minimum age.
How will compliance be supervised and enforced?
The proposal does not create one penalty regime for everyone. It creates new statutory duties and largely plugs them into the DSA, AI Act and GDPR machinery. A fast-track European Commission process is anticipated. A supervisory fee, capped at 0.03% of worldwide annual net income, is proposed to fund the Commission’s direct supervision. Many companies will be required to provide compliance plans which are independently audited at the provider’s expense by specialists.
How much of this is genuinely new?
There are already various texts in place in the EU and this new proposed Act definitely overlaps with many of these existing requirements:
DSA: Much of this will feel familiar to providers already implementing the Article 28 DSA minors guidelines. Addictive design, recommender systems, safer defaults, contact controls and transaction protections all have clear parallels. The challenge will be understanding what is genuinely new and how the various regimes fit together.
AVMSD: Video-sharing platforms already owe protective measures to minors. The additional lifts are likely to include age assurance, guardian controls, account architecture and the more prescriptive design rules.
GDPR: GDPR Article 8 and national digital-consent ages remain untouched. A 15-year-old may therefore hold an autonomous account while still being unable to consent to particular processing (although of course consent is typically avoided for this reason).
The commercial impact will vary sharply. Platforms already implementing the DSA minors guidelines, subject to the very large online platform and UK Online Safety Act rules can reuse much of that work. Services which do not currently qualify as online platforms under the DSA (such as many video games and chatbots) will face a big increase in compliance requirements.
What are the next steps?
It’s going to be a little while before this proposal becomes law. We expect various changes and consultations to follow.
/Passle/MediaLibrary/Images/2026-05-27-21-05-34-224-6a175c9e80478c2eb8505e6c.jpg)