EU KIDS Act Explained: Social Media Age Limits and Children's Rights
Introduction
The EU KIDS Act is a proposed European Union regulation that would restrict children’s access to certain social media and video-sharing services and establish wider online safety requirements. Under the proposal, children under 13 could not hold their own accounts on services covered by the age restrictions. Providers could offer limited, guardian-managed accounts to 13- and 14-year-olds, but they would not be required to do so. Independent accounts would be permitted from age 15. The account restrictions would apply to social networking and video-sharing services with specified features that pose risks to minors, rather than to every online service. An exception would allow children under 13 to access qualifying child-friendly video-sharing services through a guardian’s account, subject to safeguards (European Commission, 2026, arts. 6–7).
Presented by the European Commission on September 17, 2026, the proposal extends beyond account eligibility. It would impose requirements addressing potentially addictive design, privacy settings, unwanted contact, and age assurance. Other provisions would apply to online games, app stores, operating systems, AI companions, and conversational chatbots, although these services would not all be subject to the same age restrictions. The proposed regulation seeks to establish common standards across the EU while addressing differences in national approaches to children’s online access (European Commission, 2026, arts. 1–2, 8–20).
The EU KIDS Act would specify and complement the Digital Services Act and supplement the EU AI Act. Existing data-protection obligations, including those under the General Data Protection Regulation, would continue to apply. Its age-verification and parental-control requirements also raise questions about how children’s safety can be protected while respecting their privacy, access to information, and developing autonomy. The European Parliament and the Council must still consider the proposal and agree on a final text. Its additional restrictions and obligations are not yet binding law (European Commission, 2026, arts. 1–2; European Union, 2012, arts. 7–8, 11, 24).
1. Social Media Age Limits Under the EU KIDS Act
The EU KIDS Act would establish a common minimum age for independent accounts on certain social networking and video-sharing services. Its central restriction concerns accounts created for, or attributed to, children under 15. The proposal provides two forms of supervised access for younger users: limited accounts established by guardians for adolescents below that age, and access to qualifying child-friendly video-sharing services through an adult’s own account (European Commission, 2026, arts. 6–7).
These arrangements are legally distinct. A guardian-managed account remains an account through which a minor uses a service, subject to continuing controls. A younger child accessing a video-sharing service through an adult’s account would not become an account holder. The distinction determines which exception could permit access and who would retain responsibility for the account.
The restrictions would not apply automatically to every website with videos or social features. Article 6 targets social networking and video-sharing services presenting specified risks through their functions, including contact with unfamiliar users, profiling-based recommendations, live streaming, and designs that encourage uninterrupted use. Meeting any one of the listed conditions would bring a service within the proposed account restriction (European Commission, 2026, art. 6(1)).
The legislation would consequently regulate particular services and account arrangements rather than establish a universal minimum age for internet use. Educational resources, online games, and other digital services would have to be considered under the provisions applicable to them. Some would face separate safety requirements; others would fall within express exclusions from the regulation’s scope.
1.1 Children Under 13: Restricted Access
Under Article 6, providers of covered social networking and video-sharing services would have to prevent children under 13 from creating their own accounts or accessing the service through accounts created for, or attributed to, them. An adult could not avoid that restriction merely by registering an ordinary account in a child’s name. The provision addresses the account’s attribution and use, not simply the identity of the person completing the registration form (European Commission, 2026, art. 6(1)).
A limited exception would apply to video-sharing services specifically designed for children in this age group. Article 7 would allow a guardian to enable access through the guardian’s own account, provided the service expressly permitted it and satisfied the prescribed safeguards. The account would remain registered to and held exclusively by the adult. A child-specific profile or setting within that account would not constitute a separate account belonging to the minor (European Commission, 2026, art. 7(1)–(3)).
Parental permission alone would not be sufficient. A provider wishing to offer this arrangement would have to publish an assessment of its service’s effects on the relevant age group, identify content or behavior considered inappropriate or harmful, and prevent younger users from accessing that material. Available functions would have to be adapted to the child’s age. Compliance with the regulation’s general safety duties would not automatically establish that the risks of admitting children under 13 had been adequately addressed (European Commission, 2026, art. 7(1)).
Personalization would be subject to a particularly restrictive rule. Recommendation systems, other personalization features, and functions for searching content shared by users would have to remain disabled unless the provider’s assessment demonstrated that activating them served the child’s best interests without adversely affecting privacy, safety, or security. Guardians would also need tools to supervise content and interactions, suspend access, and set a daily limit of no more than one hour. The exception would not permit access by children under three (European Commission, 2026, art. 7(1), (4)).
Article 7 expressly preserves a provider’s ability to exclude children under 13. Neither a child nor a guardian would acquire a general right to use a service whose terms prohibit such access or for which a higher lawful minimum age applies. The exceptional arrangement would also end when the child reached 13; continued use would then have to satisfy the conditions governing the next age group (European Commission, 2026, art. 7(2), (5)).
1.2 Ages 13–14: Guardian-Managed Accounts
The European Commission describes the next stage as supervised access for 13- and 14-year-olds. Under the proposed exception, a provider could offer an account with limited features established by an adult holding parental responsibility. It would remain the provider’s choice whether to offer this arrangement. The legislation would not require every covered social networking or video-sharing service to admit users below 15 (European Commission, 2026, art. 6(2)–(3)).
There is an ambiguity at the lower age boundary. Article 6(2) describes eligible minors as being above 13 and below 15, whereas Article 6(3) requires verification that the child has reached 13. The Commission’s public explanation includes 13-year-olds. The intended age group is apparent, but the operative wording does not resolve eligibility precisely on a child’s thirteenth birthday.
A limited account would have to retain active guardian tools throughout its use. The adult would need to be able to set a maximum daily access period not exceeding one hour, approve new contacts before they were added, and limit the number of contacts associated with the account. These controls would affect how long the child could use the service and with whom the child could interact, rather than operating solely as an initial registration requirement (European Commission, 2026, art. 6(2)).
Before creating the account, the provider would have to take measures to establish that the adult holds parental responsibility under applicable national law and verify the child’s age. Article 26 identifies possible sources of information about parental responsibility, including official records, information already held by the provider, and adult declarations subject to reasonable verification efforts. An adult’s willingness to supervise a child would not itself establish the legal authority required to create the account (European Commission, 2026, arts. 6(3), 26).
The arrangement would preserve a role for the guardian without transferring the provider’s safety obligations to the family. The service would still have to comply with applicable requirements concerning privacy, harmful design, and unwanted contact. Nor would a supervised account become an independent account simply because the child had previously used it with parental approval.
1.3 Ages 15–17: Independent Accounts and Safeguards
Reaching 15 would remove the proposed minimum-age obstacle to creating an independent account on a service covered by Article 6. A minor of that age could register and manage an account without relying on the limited guardian-managed exception. This would not establish an unconditional right to join a particular platform: lawful service terms and other applicable legal requirements could still impose restrictions (European Commission, 2026, arts. 6–7).
Independent account ownership would not end the provider’s child-protection duties. The proposal defines a minor as a person under 18, and its safety-by-design requirements would continue to apply to users aged 15, 16, and 17. Features governing recommendations, contact requests, account visibility, and prolonged use would remain subject to the relevant safeguards. Permission to open an account would thus be distinct from permission to use every feature available to adults (European Commission, 2026, arts. 3, 8–12).
The distinction is especially clear in the rules on privacy settings. Article 11(2) would permit a provider to change specified protective defaults only where the minor was above 15, had been clearly informed, and had explicitly consented. That wording does not plainly include someone who has just turned 15. The proposed minimum age for an independent account and the threshold for changing those settings should not be treated as identical.
Existing accounts would require a separate assessment. Within six months after the regulation began to apply, providers covered by Article 6 would have to establish whether their account holders were below 15. They would then have to disable accounts belonging to users found to be under that age, as well as accounts whose holders’ ages could not be established. The proposal does not expressly guarantee that an existing independent account could be converted into a supervised one; any continuing access would have to satisfy the requirements of a permitted arrangement (European Commission, 2026, art. 6(2)–(4)).
Article 32 would qualify the need for fresh verification. A provider would not have to verify an existing account holder’s age again if it could establish with a high degree of confidence that the person had reached the applicable minimum age. This exception would concern the method of establishing eligibility, not an exemption from the minimum-age rule itself (European Commission, 2026, art. 32(2)).
2. Which Digital Services Would the Rules Cover?
The proposed regulation covers several categories of digital services, but it does not impose identical obligations on all of them. Article 2 identifies social networking services, video-sharing platforms, software application stores, online games, operating systems, AI companions, and general conversational chatbots. Article 6 reserves its account restrictions for qualifying social networking and video-sharing services. Other categories would face requirements directed at their particular functions, including safety by design and age-appropriate access (European Commission, 2026, arts. 2, 6, 8).
For social networking and video-sharing services, the restriction depends on the risks associated with specified features. A service would meet one condition if account holders could transmit content live to an indefinite audience. Other conditions include communication with users outside existing connections, recommendations based on profiling, suggestions involving unfamiliar accounts or content, and designs intended or reasonably foreseeable to encourage uninterrupted consumption or repeated engagement (European Commission, 2026, art. 6(1)).
The provision is concerned with what a service enables users to do. A platform’s description of itself as an entertainment application or video library would not settle whether its accounts were covered. Equally, the presence of video content alone would not establish that a service satisfied the account-restriction criteria.
Different obligations would apply to online games, app stores, and conversational systems. Games would face requirements concerning excessive use, protective settings, and contact with other users. App stores would have to assess applications for age appropriateness and restrict access accordingly. AI companions and general conversational chatbots would be subject to measures addressing risks arising from interactions with minors. None of these provisions would, by itself, extend the social media account threshold to every game or conversational service (European Commission, 2026, arts. 14–16).
Article 2 also contains express exclusions. They include nonprofit online encyclopedias, nonprofit educational and scientific repositories, qualifying services operated by or on behalf of educational establishments, certain open-source software platforms, services developed solely for scientific research and development, and systems operated exclusively for public-authority use. An online service would not qualify for an exclusion merely because some of its material had educational value. The proposal would also empower the Commission, subject to specified conditions, to amend the excluded categories through delegated acts (European Commission, 2026, art. 2(4)–(5)).
The rules would reach beyond companies established in the EU. For social networking, video-sharing, app-store, gaming, and operating-system services, the proposal would apply where the provider offered a covered service to recipients established or located in the Union. AI companions and general conversational chatbots would be subject to a separately framed territorial rule concerning systems placed on the market or put into service in the EU. A provider’s place of establishment would not, by itself, determine whether the regulation applied (European Commission, 2026, art. 2(2)–(3)).
3. Safety Requirements for Social Media Platforms
The proposed minimum ages would determine when a child could hold a particular account. Safety-by-design obligations would govern the service offered to minors who were permitted to use it. Article 8 would require covered providers to maintain a high level of privacy, safety, and security, including where a service could be accessed without an account. Providers could depart from the child-protective requirements only after establishing through the prescribed age-assurance process that the user was an adult (European Commission, 2026, art. 8).
For social networking and video-sharing platforms, these obligations would affect everyday features rather than account registration alone. Recommendation systems, notifications, contact requests, visibility settings, live streaming, and purchases would all be subject to specific requirements. A 15-year-old who could independently open an account would still be entitled to the protections applicable to minors.
The proposed duties take different forms. Some would prohibit features or practices considered harmful to children. Others would require protective defaults, usable controls, or measures to interrupt prolonged use. A provider could not necessarily satisfy a prohibition by giving minors the option to disable a feature themselves. The legal consequences would depend on the obligation attached to the particular design choice.
3.1 Addictive Design and Recommendation Systems
Article 9 would prohibit social networking and video-sharing providers from designing or operating services in ways intended, or reasonably foreseeable, to encourage compulsive or excessive use by minors. It identifies automatic playback and uninterrupted consumption without effective stopping points among the features covered. The provision also addresses notifications unrelated to a minor’s activity, rewards for sharing or livestreaming content, and incentives that encourage repeated engagement at specified intervals (European Commission, 2026, art. 9(1)–(2)).
Providers would have to implement effective measures for time-limited access and interruptions in use, designed to protect school time and core sleeping hours. Article 9 does not set a universal one-hour daily limit for every minor. That maximum belongs to the specific guardian-controlled arrangements for younger children. The general duty to limit and interrupt use would operate separately (European Commission, 2026, arts. 6(2), 7(4), 9(3)).
Recommendation systems would face obligations addressing how information is selected and prioritized. Article 10 would require providers to give primary weight to preferences expressly stated by minors and disable by default recommendations based on implicit signals from their online behavior. Recommendation systems could not rely on minors’ personal data collected outside the service. Providers would also have to evaluate the quality and safety of recommendations, including potential effects on mental health and the risks of repeated exposure to particular information (European Commission, 2026, art. 10(1)–(2)).
Minors would need accessible tools for controlling recommendation parameters and deleting previously identified preferences. At least one recommendation option would have to operate without profiling, and the interface could not steer younger users toward the profiling-based alternative. These provisions would regulate the methods used to select content rather than prohibit every form of personalization. A recommendation based on a user’s express preference would be treated differently from one inferred through continuous behavioral tracking (European Commission, 2026, art. 10(3)).
3.2 Privacy, Contacts, and In-App Spending
Protective settings would have to apply by default. Under Article 11, providers would initially disable geolocation and other tracking features, camera and microphone access, recommendations of other accounts, contact synchronization, and push notifications. The provision would also require notification design to protect school time and core sleeping hours (European Commission, 2026, art. 11(1)).
A provider could change those defaults only where the minor was above 15, had received clear information about the changes, and had explicitly consented. This threshold is distinct from the age of 15 specified for independent account creation. If an eligible minor enabled geolocation or another tracking feature, it would have to be disabled again when the session ended (European Commission, 2026, art. 11(2)).
Certain features would have to remain unavailable to minors rather than simply begin in a disabled state. Article 11(3) addresses settings or functions that pose risks to their privacy, safety, security, health, or well-being. It expressly includes features that intensify social comparison or misrepresent a minor’s appearance through disproportionate embellishment or idealization. Consent to change an ordinary default would not, by itself, authorize access to a feature prohibited under this separate requirement.
Contact safeguards would restrict who could approach a minor. Other users could not initiate direct contact unless the minor had approved it beforehand. Minors would be excluded from contact-recommendation features designed to help users expand their networks and could not be added to groups without their explicit agreement. Blocking would have to be straightforward and must not disclose the blocking user’s identity to the person blocked. Providers would also have to address attempts to manipulate minors into approving contact (European Commission, 2026, art. 12(1)–(2)).
The proposal would limit the visibility and further circulation of material shared by minors. Unapproved users would, by default, be unable to view their account information or uploaded content, and people without accounts would be denied access to that information. Personal contact details could not be disclosed to other users. Minors would need controls over the visibility of their content and interactions, while hosting livestreams would be disabled by default (European Commission, 2026, art. 12(3)).
Article 12(3)(e) would also require providers to prevent other users from downloading or taking screenshots of minors’ contact, location, or account information and shared content. The proposed text specifies the protection to be achieved but does not prescribe the technical method for achieving it. How providers could implement the requirement, and how compliance would be assessed, would consequently be questions for its application rather than guarantees established by the wording alone (European Commission, 2026, art. 12(3)(e)).
Economic transactions would be regulated separately. Before a minor completed a purchase, the service would have to make clear, in real time and comprehensible language, that an economic transaction was taking place. Purchases using virtual currency obtainable with money would have to display the corresponding monetary value in the official currency of the minor’s Member State of habitual residence. Providers would also be prohibited from designs that could lead to excessive, impulsive, or unwanted spending, including exposing minors to variable reward systems (European Commission, 2026, art. 13).
4. AI Chatbots, Online Games, and App Stores
Children can encounter risks on digital services without holding a conventional social media account. They may converse with an AI system, participate in a networked game, or obtain applications through an app store. The EU KIDS Act would address these activities through requirements adapted to the service involved, rather than treating them all as subject to the minimum age for independent social media accounts (European Commission, 2026, arts. 2, 8).
The obligations would reflect different functions. A conversational system may simulate a personal relationship with a user. An online game may encourage repeated participation or enable contact with unfamiliar people. An app store determines which applications are available for installation and can restrict access according to age ratings. Each activity presents different questions about provider responsibility.
The proposal would also distinguish between the provider of a function and a service incorporating it. An AI companion offered independently would be subject to the obligations governing that system. A social networking service, video-sharing platform, or online game that incorporated a chatbot would have additional responsibilities concerning how the feature was presented and activated. The existence of an underlying provider would not necessarily relieve the host service of its own duties (European Commission, 2026, arts. 8(3), 14).
4.1 AI Companions and Emotional Dependency
Article 3 distinguishes an AI companion from a general conversational chatbot. An AI companion provides sustained, personalized interaction or companionship that simulates or facilitates a social, emotional, or interpersonal relationship. A general conversational chatbot can assist users across multiple domains and tasks. The latter category excludes systems whose conversational functions are confined to specified specialized services, including certain customer-service, technical-support, and educational applications (European Commission, 2026, art. 3(5)(c)–(d)).
Article 14 would require providers of both covered categories to protect minors’ health, safety, fundamental rights, well-being, and development. Its provisions concerning emotional dependency address design features and system behavior that simulate interpersonal relationships likely to produce that effect. They would not prohibit every conversational exchange that appears friendly or supportive; the relevant issue would be whether the design exposed minors to the risks identified in the proposal (European Commission, 2026, art. 14(1)(a)).
Protective settings would also govern the use of information from earlier conversations. By default, a system could not use information or analysis derived from a minor’s previous interactions in later exchanges, except where necessary to protect the minor’s safety or give effect to the prescribed protective settings. Providers would have to evaluate and test systems for relevant risks before placing them on the market or putting them into service, then implement appropriate safeguards (European Commission, 2026, art. 14(1)(b), (e)).
Article 14(1)(f) would additionally require post-market monitoring to identify, assess, and, where appropriate, mitigate harm and emerging risks, including serious incidents involving minors. The express exception for qualifying micro and small enterprises concerns this post-market monitoring requirement alone. It would not exempt those enterprises from the other duties imposed by Article 14, including protective design, applicable default settings, and pre-market evaluation (European Commission, 2026, art. 14(1)).
Access by children under 13 would have to be enabled and controlled through the prescribed guardian tools. Where a social networking service, video-sharing platform, or online game incorporated an AI companion or general conversational chatbot, the feature could not be activated automatically or displayed prominently to minors. The host service could not encourage minors to use it and would have to provide an easy means of opting out at any time (European Commission, 2026, art. 14(1)(d), (2)).
These requirements would complement the EU AI Act, not replace it. The KIDS Act draws on the existing AI framework’s definitions while proposing additional safeguards directed at minors’ interactions with particular conversational systems. Which obligations apply to a provider would depend on the system’s characteristics and the respective scope of each legal instrument (European Commission, 2026, arts. 1–3, 14).
4.2 Online Games and Age-Rated Applications
Online games would face requirements addressing excessive use and unsafe contact. Article 15 would apply specified restrictions on engagement incentives, require protective default settings, and impose safeguards governing interactions between minors and other users. Children under 13 could access covered games only through the prescribed guardian tools. These duties would regulate the gaming environment without establishing a general prohibition on game accounts for everyone under 15 (European Commission, 2026, art. 15(1)).
The proposal would also address attempts to move contact beyond a game. Providers would have to introduce safeguards against games being used to entice minors into initiating interactions on other services that could threaten their privacy, safety, or security. Video gaming platforms that permit users to create and upload games would need software and organizational measures supporting compliance by those games. Responsibility would not be confined to titles developed by the platform operator itself (European Commission, 2026, art. 15(2)–(3)).
App stores would have a different role. Article 16 would require an age-rating system covering every application offered through the store. Providers would have to publish clear information about the methodology, criteria, and sources used in their ratings and prevent minors from accessing or purchasing applications classified as inappropriate for their age. Where applicable, EU or lawful national legislation imposed a higher minimum age, the store would have to respect that threshold in the Member State concerned (European Commission, 2026, art. 16(1)–(3), (5)).
Age assessment would support these restrictions, while guardian tools would control access to app-store services by children under 13. App stores would also have to make qualifying EU age-verification solutions available through their stores. An application’s age rating would not displace duties imposed directly on the service delivered through it. A covered social networking platform, for example, would remain subject to Article 6 even if its application had been assigned an age rating (European Commission, 2026, art. 16(2), (4), (6)).
Operating systems would contribute through age-signal sharing rather than by applying every service’s substantive restrictions themselves. Under Article 29(6), an operating-system provider that had obtained a user’s age signal would have to enable its sharing with a covered provider when the signal was needed for compliance, provided the age-assurance method met the relevant requirements, and the user had consented. Possession of an age signal alone would not authorize its unrestricted transmission (European Commission, 2026, arts. 27, 29(6)).
5. Age Verification and Parental Responsibility
The EU KIDS Act’s proposed age restrictions would depend on providers establishing whether a person has reached the threshold for a particular account or feature. Age would also determine when protective settings intended for minors must apply. An incorrect assessment could deny an eligible person access or allow a child to use functions from which the proposal seeks to protect them (European Commission, 2026, arts. 6, 8, 27–29).
Age assurance and age verification serve related but distinct purposes. Under the proposal, age assurance encompasses methods used to determine, estimate, or verify a person’s age. Age estimation produces an approximate result, while age verification establishes with a high degree of certainty whether someone has reached a specified age or threshold, using identification documents or other reliable, verified sources. A user’s unsupported declaration of their own age would not qualify as age assurance (European Commission, 2026, art. 3(5)(h)–(i)).
Establishing parental responsibility requires a separate assessment. An adult may be old enough to act as a guardian without holding parental responsibility for the particular child seeking access. Providers offering guardian-managed accounts or parental controls would have to establish that relationship according to the applicable national law.
Responsibility for these arrangements would be shared but differentiated. Service providers would have to implement compliant age-assurance measures. Third parties could issue proof-of-age attestations, public authorities would certify qualifying verification solutions, and Member States would have to ensure that verification methods were available. The Commission would maintain lists supporting recognition of certified providers and solutions across the Union (European Commission, 2026, arts. 29–31).
5.1 Proof of Age Without Unnecessary Identification
The proposal would require providers subject to the social media account restrictions to use a particular form of age verification. Under Article 29(2), they would have to rely on a certified EU age-verification solution using a proof-of-age attestation supplied by a third party. The solution and attestation would have to meet the requirements of the EU Age Verification Scheme and be included in, or verifiable against, the relevant EU lists (European Commission, 2026, art. 29(1)–(3)).
Other age-related obligations would allow greater flexibility. Providers seeking to comply with specified general safety and app-store requirements could use alternative age-assurance methods if they demonstrated that those methods satisfied Articles 27 and 28. The proposal would thus distinguish verification needed to enforce a particular account threshold from age assurance used for other protective purposes.
Accuracy would not be the only requirement. Article 27 calls for age-assurance solutions to provide a high level of reliability, security, robustness, non-intrusiveness, privacy, data protection, and non-discrimination. These safeguards would be relevant both to protecting children and to preventing eligible users from being excluded because a system could not assess their age correctly (European Commission, 2026, art. 27).
The proposal seeks to establish age eligibility without unnecessarily disclosing identity. A proof-of-age attestation could establish that its holder meets a threshold without revealing the holder’s name, full date of birth, or identification number to the requesting service. Article 28 would prohibit age-assurance solutions from enabling identification, location tracking, advertising, or profiling through the verification process. Providers and other participating entities could process no more personal data than strictly necessary to determine whether the relevant threshold had been met (European Commission, 2026, arts. 3(5)(o), 28(1)–(2)).
Article 28(3) would require age-assurance measures to use state-of-the-art technology and provides that every such measure must use a zero-knowledge proof. The intended distinction is between proving that an age condition is satisfied and disclosing the underlying personal information. The proposal does not, however, settle every technical question involved in applying that requirement across the permitted methods of age assurance. Article 30 anticipates further implementing and delegated acts specifying the technical, organizational, privacy, and security requirements of the EU scheme and alternative solutions (European Commission, 2026, arts. 28(3), 30).
A limited exception would permit certain providers to retain an account-level signal confirming that a user had satisfied an age threshold. That signal could be kept solely to avoid repeated age-assurance checks and would have to contain the minimum information necessary for that purpose. It would not authorize retention of a complete identity record or reuse of verification data for unrelated activities (European Commission, 2026, art. 28(4)).
Incorrect results would be subject to challenge. Article 29(5) would require relevant providers to offer an effective internal complaint mechanism through which users could contest an age-assurance outcome electronically and free of charge. Qualifying online platforms could use the complaint-handling mechanism established under Article 20 of the Digital Services Act. The availability of a complaint would provide a route to correction, although it would not eliminate the immediate consequences of an erroneous access decision (European Commission, 2026, art. 29(5)).
5.2 Guardian Verification and Children's Autonomy
A provider offering a limited account to a younger adolescent would have to establish that the adult creating it holds parental responsibility for the child. The same issue would arise where a guardian enabled access to a qualifying video-sharing service for a child under 13 or exercised parental tools. Article 26 permits several ways of establishing that relationship, reflecting the fact that family circumstances and relevant records differ across Member States (European Commission, 2026, art. 26(1)).
Providers could use relevant information from official online databases or interfaces made available by a Member State. They could also rely on information already held through previous dealings with the adult and child. The proposal additionally permits a declaration by the adult, subject to reasonable efforts to verify that the declarant exercises parental responsibility. It empowers the Commission to specify relevant parental-responsibility signals through a delegated act; the precise relationship between that future measure and continued reliance on declarations is not fully resolved in the proposed wording (European Commission, 2026, art. 26(1)–(5)).
Verification would have to preserve family privacy. Article 26(4) prohibits additional personal-data processing that would enable a provider to determine the location of the adult or child or to track, target, or profile either person. Information establishing parental responsibility could not become a separate source of behavioral or commercial data.
Member States would have to provide at least one privacy-preserving electronic means by which a guardian could obtain and present an attestation of parental responsibility. It would have to rely on authentic sources under national law, be free for guardians, and disclose no more than confirmation that the relevant relationship exists. The proposal also requires accessibility for people with disabilities, limited digital access, or other vulnerabilities, and alternative procedures where conventional civil-status documents cannot establish parental responsibility (European Commission, 2026, art. 31(1)–(3)).
Parental involvement would remain subject to the child’s rights. Article 20 requires guardian tools to take account of a minor’s gradual development, respect privacy and agency, and avoid disproportionate restrictions. Children would have to be informed when those tools were activated. Supervision could assist with managing contacts, screen time, and settings, but it would not justify treating children of different ages and circumstances as having identical needs (European Commission, 2026, art. 20(1)–(2)).
The guardian’s role would not displace the provider’s responsibilities. Parental tools would operate alongside requirements concerning protective defaults, harmful design, and unwanted contact. A provider could not treat a guardian’s failure to activate an optional control as a general exemption from the safety obligations applicable to its service.
6. The Proposal Within Existing EU Law
The EU KIDS Act would enter an established framework governing digital services, personal data, and AI systems. The Commission proposes Article 114 of the Treaty on the Functioning of the European Union as its legal basis. That provision permits the European Parliament and the Council, acting through the ordinary legislative procedure, to adopt measures approximating national laws for the establishment and functioning of the internal market (European Union, 2012, TFEU, art. 114).
The Commission’s stated concern is that differing national approaches to children’s access to digital services create regulatory fragmentation for providers operating across borders. A common minimum age and harmonized safety obligations are intended to reduce those differences while establishing a high level of protection for minors. Article 114(3) requires Commission proposals concerning health, safety, environmental protection, and consumer protection to take a high level of protection as their basis (European Commission, 2026; European Union, 2012, TFEU, art. 114(3)).
Harmonization would not automatically displace every national rule concerning children’s online activities. The proposal preserves the operation of other EU legislation and recognizes higher minimum ages imposed by applicable EU or lawful national rules in specified contexts, including guardian-controlled access and app-store restrictions. Those provisions do not amount to a general authorization for Member States to introduce any additional age restriction regardless of its compatibility with EU law (European Commission, 2026, arts. 2, 7, 16).
The extent of permissible national regulation would depend on the final text, the matters it harmonizes, and the applicable rules of EU law. Existing obligations would continue to operate unless and to the extent that an adopted measure lawfully changed their relationship. The proposed KIDS Act specifies and complements the Digital Services Act and complements the EU AI Act; it does not replace either instrument (European Commission, 2026, art. 1).
6.1 The Digital Services Act, GDPR, and AI Act
The Digital Services Act already requires online platforms accessible to minors to adopt appropriate and proportionate measures ensuring a high level of privacy, safety, and security. Article 28 also prohibits advertising based on profiling when a provider knows with reasonable certainty that the recipient is a minor. It does not establish a universal minimum age for social media accounts (European Union, 2022, art. 28).
The proposed KIDS Act would add specific account restrictions and detailed requirements for service design. Article 2(6) provides that certain platforms complying with its obligations would be deemed to comply with Article 28(1) of the Digital Services Act for matters covered by the new regulation. That relationship would be limited to those matters. Providers would remain subject to other applicable obligations under the Digital Services Act, including requirements addressing risks outside the KIDS Act’s scope (European Commission, 2026, art. 2(6)).
The two instruments also approach age assurance differently. Article 28(3) of the Digital Services Act states that compliance with its child-protection duties does not, by itself, require platforms to process additional personal data to determine whether a recipient is a minor. If adopted, the KIDS Act would establish more specific age-assurance obligations for services within its scope, accompanied by restrictions on identification and further data processing. The existing DSA provision does not establish a general prohibition on age checks required by another applicable EU measure (European Union, 2022, art. 28(3); European Commission, 2026, arts. 27–29).
The General Data Protection Regulation addresses a different question. Article 8 governs conditions for relying on a child’s consent as the legal basis for processing personal data in relation to information society services offered directly to children. It sets the relevant age at 16 while permitting Member States to provide for a lower age that cannot fall below 13. It neither grants a general right to open a social media account nor establishes a universal minimum age for using digital services (European Union, 2016, art. 8).
The GDPR would continue to govern personal-data processing associated with age assurance and parental verification. Its requirements concerning lawfulness, purpose limitation, data minimization, and security would remain relevant. The KIDS Act’s additional safeguards would operate alongside them, while data-protection supervisory authorities would retain their competence over processing falling within the applicable framework (European Union, 2016, arts. 5–6; European Commission, 2026, arts. 28, 34(6)).
The EU AI Act provides another point of connection. It prohibits specified manipulative and exploitative AI practices and establishes transparency obligations for certain systems designed to interact directly with individuals, subject to the relevant conditions and application dates. The proposed KIDS Act would add requirements directed specifically at minors’ interactions with AI companions and general conversational chatbots. A provider could fall within both instruments, but its obligations would have to be identified under each instrument’s scope and applicable provisions rather than treated as interchangeable (European Union, 2024, arts. 5, 50; European Commission, 2026, art. 14).
6.2 Children's Rights and Proportionality
The EU Charter of Fundamental Rights provides an essential legal framework for assessing the proposal. Under Article 51(1), the Charter binds EU institutions and binds Member States when they are implementing EU law. It consequently governs the Union’s legislative action and is relevant to national authorities applying EU requirements. The Charter does not extend the Union’s competences beyond those conferred by the Treaties (European Union, 2012, Charter, art. 51).
Article 24 recognizes children’s entitlement to protection and care, requires their best interests to be a primary consideration, and provides for their views to be considered according to age and maturity. Those requirements support attention to risks arising from digital services while recognizing that children possess rights independently of their parents or guardians. Protection and developing autonomy must both inform the legal assessment (European Union, 2012, Charter, art. 24).
Age restrictions may also affect freedom of expression and information under Article 11. Social networking and video-sharing services can provide access to news, educational material, cultural expression, and relationships with others. The Charter does not establish an unconditional right to hold an account with a particular commercial provider. Restrictions on access to widely used channels of communication nevertheless warrant examination for their effects on protected freedoms (European Union, 2012, Charter, art. 11).
Verification and parental supervision raise related questions under Articles 7 and 8, which protect private and family life and personal data. Measures intended to protect children could themselves interfere with those rights if they required unnecessary identification, disclosed family relationships, or enabled tracking. The proposal’s data-minimization and privacy requirements respond to those risks, although their practical effectiveness would depend on the systems and procedures ultimately implemented (European Union, 2012, Charter, arts. 7–8; European Commission, 2026, arts. 26–31).
Article 52(1) establishes the conditions under which Charter rights may be limited. A limitation must be provided for by law, respect the essence of the affected right, and satisfy proportionality. It must also be necessary and genuinely meet an objective of general interest recognized by the Union or the need to protect the rights and freedoms of others. The protection of children is relevant to that assessment, but the protective objective alone does not establish that every proposed restriction satisfies the test (European Union, 2012, Charter, art. 52(1)).
The proportionality inquiry would require attention to the scope of the age restrictions, the evidence supporting them, and the availability of less restrictive measures capable of achieving the intended protection. Questions include whether the age categories sufficiently reflect differences in development, whether supervised access addresses the effects of exclusion, and whether verification can operate without unnecessary disclosure or discriminatory barriers. The proposal’s legality cannot be determined solely from either its stated protective purpose or the existence of possible effects on children’s rights.
7. Enforcement and Platform Accountability
The EU KIDS Act would draw on existing supervisory structures rather than establish an entirely separate enforcement system. Proposed Article 34 would apply the Digital Services Act’s supervision and enforcement framework to covered social networking services, video-sharing platforms, video gaming platforms, and app stores. AI companions and general conversational chatbots would be supervised through the relevant framework of the EU AI Act. The competent authority and available powers would depend on the service or system involved (European Commission, 2026, art. 34(1)–(4)).
Member States would have to ensure that designated national authorities could supervise providers within their competence. Online games that are video games, rather than video gaming platforms, would have a distinct arrangement: the competent authority in the Member State of the provider’s main establishment would hold exclusive supervisory and enforcement powers under the proposal. Data-protection authorities would oversee personal-data processing necessary for compliance, particularly processing associated with age assurance (European Commission, 2026, art. 34(5)–(6)).
Designated very large online platforms offering covered social networking or video-sharing services would face additional scrutiny. Article 5 would require them to notify the Commission of a detailed compliance plan addressing the obligations in Chapters II–V. Providers already designated as very large online platforms would have to submit their plans within 30 days after the regulation began to apply. Providers designated subsequently would generally have four months from notification of their designation (European Commission, 2026, art. 5(1)).
Those providers would also have to commission independent audits of their compliance plans at their own expense. Auditors would need expertise relevant to children’s rights and safety, including developmental science, age assurance, interface design, and data protection. Their reports would identify shortcomings and inform the Commission’s assessment. Where the Commission found a plan deficient, corrective measures and subsequent verification would follow the procedure set out in Article 5 (European Commission, 2026, art. 5(2)–(7)).
An audit would not constitute approval of a platform’s entire service. Article 5(8) expressly provides that an audit report, or the Commission’s action or inaction concerning it, would not amount to a finding of compliance or restrict the Commission’s enforcement powers. Submission of a plan could not be treated as immunity from later investigation. Continuing monitoring and reporting would remain relevant to designated very large online platforms (European Commission, 2026, arts. 5(8)–(9), 22).
Complaints would provide a further route for addressing alleged infringements. Article 21 would allow eligible minors and guardians to complain to the competent authority and authorize qualifying nonprofit bodies or associations to exercise rights on their behalf. These complaints would be distinct from the internal procedure for challenging an incorrect age-assurance result. The two mechanisms would address different decisions, although the same circumstances might give rise to more than one form of complaint (European Commission, 2026, arts. 21, 29(5)).
Potential penalties would depend on the applicable enforcement framework. For specified infringements by providers of AI companions and general conversational chatbots, proposed Article 34(2) provides for administrative fines not exceeding 6 percent of the undertaking’s total worldwide annual turnover in the preceding financial year where the provider acted intentionally or negligently. Other services would be subject to the relevant Digital Services Act arrangements. Data-protection authorities could impose fines within their competence in accordance with the GDPR. None of these penalties would follow automatically from an allegation of infringement (European Commission, 2026, art. 34).
Article 35 would establish an expedited procedure for certain Commission investigations involving very large online platforms or AI systems under its exclusive supervision. The Commission would endeavor to reach a final decision within 90 working days after proceedings began. The proposed period for communicating preliminary findings remains provisional in the Commission’s text. Neither timetable would guarantee that every investigation ended within a fixed period, and both would remain subject to the legislation ultimately adopted (European Commission, 2026, art. 35).
8. When Could the EU KIDS Act Take Effect?
The European Commission presented the EU KIDS Act on September 17, 2026, as a proposal for a regulation. It must still be considered by the European Parliament and the Council under the ordinary legislative procedure. Those institutions may amend the text before agreeing on legislation. The Commission’s proposal does not itself make the new account restrictions or additional provider duties legally binding (European Commission, 2026).
Even after adoption, entry into force and application would be separate events. A final regulation would first have to be published in the Official Journal of the European Union. Proposed Article 43 provides for entry into force on the twentieth day following publication, followed by general application six months later. These are proposed relative periods, not established calendar dates (European Commission, 2026, art. 43).
The proposal contains exceptions to its general application timetable. Article 5, concerning compliance plans and independent audits for specified very large online platforms, would apply from entry into force. Articles 33 and 35 would apply 12 months after entry into force. Article 33 concerns national measures to support minors, including assistance channels and digital-literacy information; Article 35 establishes the expedited enforcement procedure. The dates in Article 43 remain provisional until the final legislative text is agreed (European Commission, 2026, arts. 5, 33, 35, 43).
Existing accounts would be subject to a further transitional period. Article 6(4) would give providers six months after the regulation began to apply to assess whether existing account holders were below 15 and disable accounts where the prescribed conditions required it. This period would be separate from the interval between entry into force and general application. It would not create a general exemption from the restrictions governing newly created accounts once those restrictions applied (European Commission, 2026, arts. 6(4), 43).
No final implementation date can presently be assigned to the proposed obligations. Their timing depends on completion of the legislative process, publication of the adopted measure, and its final transitional provisions. Until the new requirements become applicable, the Digital Services Act, GDPR, AI Act, and other relevant laws continue to govern the services and activities within their respective scope.
Also read
Conclusion
The proposed EU KIDS Act would establish age-based account restrictions for certain social networking and video-sharing services while imposing broader safety obligations on digital products used by minors. Its approach distinguishes independent accounts from supervised arrangements and extends protection beyond account registration to service design, interactions, and age assurance. The proposal’s different requirements would not amount to a universal prohibition on internet access for children (European Commission, 2026, arts. 2, 6–8).
The legal consequences would depend on the service involved and the rules applicable to its functions. Age verification would support access restrictions but would itself be subject to data-protection safeguards. Guardian participation would supplement providers’ responsibilities without replacing them. Existing EU legislation would remain applicable alongside any additional obligations introduced by an adopted KIDS Act.
The measure remains a Commission proposal. Its age thresholds, technical requirements, enforcement arrangements, and application periods may change during consideration by the European Parliament and the Council. The distinction between existing legal duties and proposed additional restrictions remains essential to understanding what the EU KIDS Act would—and would not—require.
References
European Commission (2026) Proposal for a Regulation of the European Parliament and of the Council: EU KIDS ACT – ‘EU Keeping Internet Digital Spaces Accountable and Trustworthy’, COM(2026) 681 final, 17 September [online]. Available at: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=COM%3A2026%3A681%3AFIN
(Accessed: 17 September 2026).
European Commission, Directorate-General for Communication (2026) EU KIDS Act: helping children navigate a safer online world [online]. Available at: https://commission.europa.eu/news-and-media/news/eu-kids-act-helping-children-navigate-safer-online-world-2026-09-17_en
(Accessed: 17 September 2026).
European Union (2012a) Charter of Fundamental Rights of the European Union, Official Journal of the European Union, C 326, 26 October, pp. 391–407.
European Union (2012b) Consolidated version of the Treaty on the Functioning of the European Union, Official Journal of the European Union, C 326, 26 October, pp. 47–390.
European Union (2016) Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), Official Journal of the European Union, L 119, 4 May, pp. 1–88.
European Union (2022) Regulation (EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022 on a Single Market For Digital Services and amending Directive 2000/31/EC (Digital Services Act), Official Journal of the European Union, L 277, 27 October, pp. 1–102.
European Union (2024) Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act), Official Journal of the European Union, L, 2024/1689, 12 July. As amended; consolidated version of 27 July 2026.




