The European Union is proposing one of its most significant interventions yet into how children use social media, online games, video platforms and artificial intelligence services.
Under the European Commission’s newly proposed EU KIDS Act, children under 13 would no longer be able to maintain social media accounts. Children ages 13 and 14 could access social platforms only through restricted accounts controlled by a parent or guardian. Teenagers would not be able to open fully independent social media accounts until age 15.
Platforms would also have to verify users’ ages rather than relying on a birthday entered during registration.
But the proposal goes considerably further than an age gate.
The Commission wants restrictions on infinite scrolling, autoplay, streaks and other features it considers capable of encouraging compulsive use by minors. Children’s accounts would receive stronger privacy settings by default. Unsolicited contact from strangers would be restricted. AI companions would face special controls designed to prevent children from developing unhealthy emotional dependence on them.
And for the largest technology platforms, the burden would effectively reverse: rather than regulators first having to demonstrate that a platform is unsafe for children, companies would have to provide evidence showing that their services are safe by design.
The proposal was formally adopted by the European Commission on September 17, 2026, one day after Commission President Ursula von der Leyen outlined the plan during her State of the Union address to the European Parliament. It must still be negotiated and approved by the European Parliament and EU member states before becoming law.
The EU Has Settled on 13 and 15 as the Critical Ages
Before the proposal was released, one of the largest unanswered questions was where Europe would place the age threshold.
That is now clear.
The Commission describes its system as a gradual or “staircase” approach to children’s online access.
Under age 13: children would not be permitted to create social media accounts.
Ages 13 and 14: a parent or guardian could establish a limited account for the child. Parental controls would remain active, contacts would require parental oversight and the account would be subject to a daily usage limit of no more than one hour.
Beginning at age 15: teenagers could create and manage their own accounts, although services used by minors would still have to comply with the KIDS Act’s safety-by-design requirements.
Under-13s would not be completely prohibited from accessing every online video service.
The proposal permits a limited exception for child-oriented video platforms accessed through a parent’s account. In that environment, personalized feeds and search would be disabled, the parent would retain control and daily access could be limited to one hour.
That distinction is important.
The Commission is not proposing that children under 13 be excluded from the internet.
It is trying to prevent independent participation in the type of personalized social-media environment that can continuously recommend content, collect behavioral signals and encourage prolonged engagement.
A Birthday Box Would No Longer Be Enough
The proposal also takes direct aim at one of the weakest points in existing age restrictions.
Today, many platforms prevent children below a minimum age from creating accounts by asking users to enter a date of birth.
A child who wants access can simply enter a different year.
The Commission says self-declared age would no longer be sufficient under the KIDS Act.
Social networks and video-sharing platforms would need to use certified age-assurance technology when new accounts are created, and existing accounts would eventually have to be checked as well.
Within six months after the relevant rules begin applying, platforms would need to determine whether existing account holders are under 15. Accounts belonging to users who are too young, or whose age cannot be established, would have to be disabled or otherwise brought into compliance with the age rules.
That could turn age assurance from a relatively obscure privacy issue into one of the largest identity-verification exercises ever conducted online.
But Europe Does Not Want Platforms Collecting Everyone’s Passport
Age verification creates its own privacy problem.
The easiest way to prove that someone is 18, 15 or 13 is to inspect a government-issued identity document.
But requiring millions of social-media users to upload passports, identity cards or driver’s licenses could create enormous new databases of sensitive identity information.
The Commission says that is not the model it wants.
Under the proposal, platforms would generally receive confirmation of whether a person satisfies the relevant age threshold without receiving the person’s identity.
The Commission says certified independent age-verification services, including its own EU age-verification application and eventually the European Digital Identity Wallet, could provide that proof.
The concept is effectively:
Prove my age without proving who I am.
The Commission says the system will use zero-knowledge-proof technology so the platform receives only the result required for the transaction, such as whether the person is above or below a particular age threshold.
According to the Commission, the system should not allow the age-verification mechanism to identify, locate, track or profile the individual. Each EU member state would also have to provide at least one free method of age verification, including an option for people who do not have a digital identity credential.
The EU Age Verification App Is Already Being Tested
This part of the KIDS Act is not purely theoretical.
The EU has already been developing an age-verification application, and Reuters reported that the technology is being piloted in seven countries ahead of a broader rollout expected by the end of 2026.
The architecture is designed to separate the organization that verifies someone’s age from the website or app asking for proof.
For example, a platform might learn that a person is older than 15 without receiving the person’s name, date of birth, passport number or a copy of the identity document used to establish that fact.
The same infrastructure could eventually be used in other contexts where online services need to distinguish between adults and minors, including access to adult content under the Digital Services Act.
If it works as intended, this could represent a meaningful shift in online identity systems.
Instead of every website conducting its own identity check, an independent credential could confirm only the attribute the service actually needs.
The KIDS Act Is Much More Than a Social Media Ban
The age limits will probably generate the most headlines.
But the Commission itself stresses that the proposal is primarily about how services used by children are designed.
It applies more broadly to services including social media, video-sharing platforms, online games, app stores, AI chatbots and AI companions.
The Commission argues that merely establishing an age threshold would leave many of the underlying risks unchanged.
A 15-year-old allowed onto a social platform could still encounter a system engineered to maximize screen time.
So the legislation attempts to regulate product architecture as well.
Infinite Scroll, Autoplay and Streaks Would Face Restrictions
For minors, the proposed law specifically targets interface designs associated with prolonged engagement.
The Commission’s explanatory material identifies several examples:
- infinite scrolling without meaningful breaks;
- endless autoplay;
- notifications designed to pull children back into an application;
- rewards tied to posting or streaming to large audiences; and
- “streak” mechanisms that penalize users for failing to return every day.
Services would also be expected to provide meaningful time limits and breaks intended to protect school and sleeping hours.
This represents a different type of technology regulation.
Rather than regulating only which information companies can collect, Europe is increasingly examining how interfaces influence people’s behavior.
The EU’s forthcoming Digital Fairness Act is expected to address addictive design more broadly, while the KIDS Act would apply specific protections to minors.
Children’s Recommendation Algorithms Would Have to Change
The KIDS Act would also reach into recommendation systems.
For minors, the Commission proposes that feeds be designed around safety, quality and wellbeing rather than simply maximizing engagement.
Content that a child deliberately chooses to follow would receive priority.
Personalization based on tracking would be disabled by default.
Platforms could not use information collected from outside the service to personalize a minor’s feed under the proposed rules.
Children would also have to be offered a simple way to reset their recommendations and at least one feed option that does not rely on profiling.
For privacy professionals, this portion of the law could be just as important as the age restriction.
It links children’s privacy directly to recommender-system architecture.
Children’s Accounts Would Become Private by Default
The Commission also wants stronger restrictions around social contact.
Under the proposed framework, strangers generally would not be able to contact children without approval.
Children would not appear automatically in contact suggestions, could not simply be added to groups without agreement and would receive stronger blocking tools.
Their content would generally be visible only to accepted contacts, and livestreaming would be disabled by default.
The broader theme is privacy by default.
Rather than expecting a child to discover a complicated privacy menu and change settings manually, the safer configuration would have to be applied from the beginning.
AI Companions Are Specifically Included
One of the more interesting parts of the KIDS Act is that it does not treat social media as the only emerging risk.
AI companions and conversational chatbots are explicitly covered.
The proposal says AI systems accessible to minors should not be designed in ways likely to create emotional dependency by simulating human relationships.
For minors, AI companions would generally be disabled by default when integrated into another service such as a social platform or video game.
They could not be pushed toward children as a default feature and would need to be easy to turn off.
The Commission also proposes limiting long-term conversational memory involving children.
By default, an AI companion would not be able to carry a child’s previous conversations forward indefinitely into future interactions.
Developers would need to test AI services for risks to children before launch and monitor them for harms afterward.
This comes at a time when governments and regulators are increasingly examining whether highly personalized AI companions can manipulate vulnerable users or encourage children to treat software as though it were a trusted human relationship.
Online Games and App Stores Are Included Too
The proposed law reaches beyond traditional social networks.
Online games would also face safety-by-design obligations.
App stores would be required to age-rate applications using a published methodology and prevent minors from accessing or purchasing applications inappropriate for their age.
The Commission also expects app stores to support the EU age-verification infrastructure.
This could make app stores important gatekeepers in the age-assurance system.
Instead of requiring every small developer to independently verify a child’s identity, some age information could potentially be handled at the platform or operating-system layer.
The Largest Platforms Would Have to Prove They Are Safe
One of the proposal’s most consequential concepts is what von der Leyen describes as reversing the burden of proof.
Very Large Online Platforms, the category used under the Digital Services Act for services reaching at least 45 million monthly users in the EU, would face additional obligations.
Before coming into contact with children under the new regime, those companies would have to submit detailed compliance plans explaining how they intend to satisfy the KIDS Act.
Those plans would then be assessed by independent auditors paid for by the platform. The European Commission would be able to object where it believes the auditor lacks sufficient independence.
The Commission’s theory is straightforward.
Parents should not have to prove that a platform harmed a child before regulators investigate whether the product was safe.
The provider should have evidence showing that its design satisfies the law.
Von der Leyen summarized the approach when the proposal was announced: “it is for platforms to show they are safe by design.”
Fines Could Reach 6% of Worldwide Revenue
The KIDS Act would use much of the enforcement structure already created under the Digital Services Act and EU AI Act.
The European Commission would directly oversee the largest online platforms and widely used AI systems covered by the legislation, while national authorities would supervise other covered services.
Violations could result in fines reaching 6% of a company’s total worldwide annual turnover.
For Commission-supervised services, the proposal also contemplates an accelerated enforcement process, with preliminary findings targeted within 30 days and final decisions within approximately 90 days.
That would be considerably faster than many traditional EU privacy investigations.
Why Europe Wants One Rule Instead of 27
The legislation is also an attempt to stop national age-restriction laws from fragmenting the EU’s digital market.
Several European governments have been pursuing their own approaches to children’s social-media access.
France has attempted national age restrictions, while Spain, Greece and other governments have been examining their own measures. France’s Constitutional Council previously blocked one version of its domestic legislation, illustrating some of the legal complexity surrounding restrictions on online access and freedom of expression.
The Commission argues that allowing every member state to establish a different minimum age or verification standard would eventually produce 27 different compliance regimes.
The KIDS Act therefore proposes a single EU-wide age threshold and enforcement structure.
That matters to technology companies as well as governments.
A platform would no longer need one age architecture for France, another for Spain and another for Ireland if the regulation ultimately establishes harmonized European rules.
The Privacy Tradeoff Around Age Verification Will Be Closely Watched
The proposal nevertheless creates a real tension.
To protect children, services need a reliable way to distinguish children from adults.
To protect privacy, companies should collect as little identity information as possible.
Poorly designed age verification can solve one privacy problem by creating another.
A centralized database containing millions of passports, facial scans or birth dates could become an attractive target for hackers and create opportunities for tracking users across services.
The Commission is attempting to avoid that outcome through independent verification and zero-knowledge technology.
Whether that architecture functions as intended at the scale of Europe’s online population will become one of the proposal’s most important technical questions.
Adults Should Not Necessarily Have to Reverify Themselves Everywhere
The Commission also says the KIDS Act is not intended to force every adult European to repeatedly prove their age whenever they open an app.
If a provider already has sufficiently reliable signals indicating that an existing user is an adult, the service may not need to conduct another age-verification process.
The Commission gives examples such as account history and payment information that may already provide confidence about age.
That could become an important implementation issue.
There is a substantial difference between requiring age assurance for uncertain accounts and requiring hundreds of millions of users to submit new credentials.
This Is Still a Proposal
Despite the specificity of the Commission’s plan, none of these requirements is yet final law.
The European Commission adopted the legislative proposal on September 17.
The European Parliament and the Council of the European Union, representing member-state governments, will now negotiate the text.
Age limits, technical requirements, enforcement provisions and implementation timelines can all change during that process.
This distinction is especially important because the pre-announcement reporting originally described the age thresholds as unresolved.
They were unresolved when Euractiv reported on the expected legislation September 14. By the time the Commission formally introduced the proposal September 17, it had selected under 13, 13-14 and 15-plus as the core access tiers.
The KIDS Act Signals a Larger Change in Children’s Privacy
The most significant part of the proposal may not ultimately be the social-media age limit.
For years, online children’s privacy law has focused heavily on information collection.
Did the company collect information about a child?
Did the parent consent?
Was the privacy notice accurate?
The KIDS Act moves much deeper into product design.
Was the feed optimized to keep a child scrolling?
Could strangers contact them?
Was personalization based on behavioral tracking?
Could an AI companion encourage emotional dependence?
Was livestreaming enabled automatically?
Did the service verify that the person opening the account was old enough?
Could the company prove before launch that the service was designed safely?
Those are not questions that can be answered by a privacy policy alone.
They require engineers, product teams, privacy professionals, safety teams and AI governance personnel to work from the same set of rules.
The EU Is Trying to Make Age a Technical Control, Not a Checkbox
The basic weakness in today’s system is easy to understand.
A platform says users must be 13.
A 10-year-old says they were born in 2005.
The platform accepts the answer.
The child receives essentially the same product as everyone else.
The KIDS Act attempts to break that model at several points.
The age has to be verified.
The account features depend on the age.
The recommendation engine has to behave differently for minors.
Privacy settings have to change.
AI companions have to operate differently.
Parents receive additional controls.
And the largest platforms have to produce evidence showing regulators how the system works.
That is why describing the proposal simply as an “EU social media ban” misses much of what Brussels is attempting.
The KIDS Act is really an attempt to build age into the technical architecture of online services.
If the European Parliament and member states ultimately approve something close to the Commission’s proposal, companies serving European users will have to know whether a user is a child without unnecessarily learning who that child is, and then make the entire digital experience behave differently as a result.
That would be a much larger change than adding another age checkbox to a signup screen.