Resource guide

EU KIDS Act: Online Safety Rules, Age Tiers, and AI Chatbot Restrictions

The European Commission proposed harmonized online age tiers and mandatory safety standards for social media, games, and AI companions across Europe.

Last updated September 24, 2026 1796-word guide Editor Ban the Bots

On September 17, 2026, the European Commission presented a proposed regulation called the EU KIDS Act to strengthen online safety for children across the European Union (EU). The proposal establishes binding safety standards across the bloc. It restricts addictive features, limits stranger messaging, and requires platforms to verify user ages.

Negotiations remain pending. This proposal formally carries the title 'EU Keeping Internet Digital Spaces Accountable and Trustworthy,' as documented in the European Commission's digital strategy library. It would govern social networks, gaming services, video hubs, and conversational artificial intelligence (AI) systems.

Core Framework of the EU KIDS Act Proposal

The proposed EU KIDS Act establishes a unified legal baseline for child safety across digital services operating within the European Union. The measure targets systemic platform designs. Under the draft rules, digital platforms must alter their interfaces before young users encounter harmful content.

The measure is distinct from regional attempts elsewhere. For example, the United States has debated the Kids Safe AI Act, which focuses narrowly on algorithmic chatbot standards. By contrast, the European initiative covers social networks, video platforms, video games, and artificial intelligence chatbots under a single comprehensive framework.

Official announcement materials from the European Commission news release outline requirements for automated services and digital distribution stores. Compliance duties fall on technology providers. The European Commission presented the draft text on September 17, 2026, launching a legislative process that involves multiple European institutions.

Harmonized Age Tiers and Account Restrictions

The EU KIDS Act establishes three distinct, harmonized age tiers across all European Union member states to standardize how minors access online services. One standard replaces national differences. Children under 13 cannot hold their own social media accounts under the draft regulation.

Children in that youngest group may access child-friendly video-sharing services only through a parent-managed account. Direct registration is prohibited. Between the ages of 13 and under 15, adolescents receive a restricted setup known as a mini account.

A parent or guardian must oversee this mini account. The mini account enforces a strict 1-hour daily time restriction. It also locks down interaction tools, limits content recommendations, and restricts data sharing.

Young people gain autonomy at 15. From age 15, a user can create and manage an online account independently without mandatory guardian supervision. These defined thresholds replace discretionary vendor policies with legally binding categories.

Covered Services and Mandatory Safety by Design

The EU KIDS Act applies comprehensive safety-by-design mandates to social media platforms, video-sharing platforms, online games, and AI companions or chatbots. Four sectors face direct compliance requirements. Platforms must eliminate interface designs that manipulate user attention or encourage compulsive engagement.

Specifically, the draft rules restrict addictive features, including infinite scroll feeds, behavioral reward mechanics, and notifications delivered during sleeping hours. Accounts belonging to minors must default to private settings. Unsolicited contact from adult strangers is prohibited.

Services must provide straightforward blocking and muting tools to young users directly within the interface. AI companions face even stricter limitations. Platforms must disable AI chatbots by default for minors and eliminate interaction patterns that create emotional dependency. Readers can review related technical guardrails in Ban the Bots' guide to AI chatbot age requirements.

Technical Architecture of the EU Age Verification App

The proposal mandates the deployment of an EU age verification app that commercial platforms and app stores must integrate into their onboarding workflows. Privacy is central to this mechanism. The verification tool confirms whether a user meets specific age criteria without transmitting underlying identity documents to the destination service.

Digital platforms cannot store personal identification cards or biometric scans under this design. The system generates a cryptographic confirmation instead. This architectural choice attempts to resolve long-standing trade-offs between child safety mandates and user privacy rights.

App stores must support this verification layer directly. If a mobile app requires user age checks, the underlying operating system and application marketplace must support the handoff. Further context on credential systems appears in Ban the Bots' overview of digital ID frameworks and its breakdown of age verification laws.

Burden of Proof and Expedited Enforcement Timelines

The draft EU KIDS Act fundamentally alters enforcement dynamics by shifting the burden of proof directly onto very large online platforms. Regulators no longer bear the initial evidentiary hurdle. Instead, platform operators must proactively demonstrate that their digital environments are safe and child-centered by design.

This reversal removes lengthy procedural discovery obstacles for public authorities. A company must present internal safety documentation, algorithmic risk assessments, and behavioral audits upon regulatory request. The draft regulation also introduces an expedited enforcement mechanism.

Investigation timelines are compressed. The European Commission is expected to conclude formal inquiries into suspected violations within 90 days. This rapid timetable prevents tech companies from stalling regulatory action while harmful interface patterns remain live.

Legislative Status and the Existing Digital Rulebook

The EU KIDS Act is currently a legislative proposal that must clear negotiations with the European Parliament and the Council of the European Union before taking effect. It is not yet law. No official implementation or enforcement date has been set.

The proposal functions as an additive layer to the European Union's established digital rulebook. It builds upon the Digital Services Act (DSA), which already regulates illegal content and systemic online risks. It also operates alongside the General Data Protection Regulation (GDPR), which protects individual data privacy and consent standards.

Additional complementary frameworks include the EU AI Act, which classifies artificial intelligence risks. The proposal also intersects with the Digital Markets Act (DMA) and the Audiovisual Media Services Directive (AVMSD). Together, these statutes form a layered regulatory structure across European digital markets.

Digital Rights Criticisms and Legal Vulnerabilities

Civil liberties advocates have raised serious legal and technical objections to the mandatory age-verification mechanisms contained in the EU KIDS Act. The Electronic Frontier Foundation (EFF) published an extensive critique of the draft rules. The group argues that mandatory age gates establish a surveillance infrastructure that undermines general user privacy.

EFF highlights the absence of a comprehensive impact assessment prior to the proposal's introduction. The organization criticizes the draft's vague 'high degree of confidence' standard for age verification. Small platforms face unique dangers. Because the proposal lacks exemptions for small and medium-sized platforms, compliance costs could entrench the market dominance of massive tech conglomerates.

The draft does include specific carve-outs. Exemptions apply to non-profit organizations, scientific repositories, educational services, and open-source software platforms. Legal precedent also complicates blanket restrictions. In August 2026, a French court declared an undifferentiated social media ban unconstitutional. EFF cites that domestic ruling as evidence that blunt, all-or-nothing digital bans face severe constitutional challenges.

Enforcement Realities, Algorithmic Feeds, and Middleware Options

Historical precedent shows that legal mandates for safety by design often face protracted implementation delays from commercial platform operators. Corporate compliance rarely happens overnight. Analysis published by Tech Policy Press points out that tech firms have repeatedly stalled protective design rollouts until coerced by litigation.

A clear example involves Meta. In 2026, the company entered an agreement worth up to $17.1 billion with United States state attorneys general. Details released by the New York Attorney General confirmed that the settlement required Meta to build basic teen-safety features.

Those mandated reforms included default screen-time limits, a night mode, and stronger age verification. Meta also agreed to build a school mode that mutes notifications during instructional hours. The fact that a multi-billion-dollar enforcement action was required to secure basic features underscores why statutory language alone does not guarantee rapid deployment.

Technical challenges compound these enforcement hurdles. Automated content moderation systems remain imperfect, frequently over-moderating harmless speech while missing explicit harms, especially in lower-resource languages. Research cited by Tech Policy Press indicates that AI-generated harms disproportionately affect women, children, and LGBTQIA+ communities. Furthermore, young users currently lack meaningful controls over algorithmic feeds that deliver unrequested harmful material.

To solve this, policy analysts advocate for interoperable middleware. Under an interoperability framework, independent child-safety tools developed by organizations like Common Sense Media and 5Rights could plug directly into platform interfaces. This approach decentralizes moderation. However, strict parental controls create serious trade-offs. Excessively rigid filters risk cutting off LGBTQIA+ and minority youth from finding community, or blocking access to reproductive-health resources.

Practical Steps for Families and Digital Rights Observers

Because the EU KIDS Act remains an unadopted proposal, families cannot rely on its statutory protections to manage online exposure today. Parents must take active measures under current rules. Families navigating these challenges can consult Ban the Bots' resources for parents and its dedicated guidance on social media management.

Guardians can use existing legal mechanisms under the Digital Services Act to demand content explanations and appeal automated account restrictions. Many social networks also provide built-in screen-time and night-mode settings negotiated through recent legal settlements. Activating these tools manually provides immediate protection while legislative negotiations proceed.

The legislative process will take considerable time. Citizens and privacy advocates can track amendments through the European Parliament and Council of the European Union to monitor changes to the proposed age-verification architecture.

FAQ

What is the EU KIDS Act?

The EU KIDS Act is a proposed regulation presented by the European Commission on September 17, 2026, aimed at strengthening online child safety across the European Union. It introduces harmonized age tiers, restricts addictive platform features like infinite scroll, and mandates child-centered interface designs. The proposal covers social media, video platforms, online games, and AI chatbots.

Does the EU KIDS Act apply to AI chatbots?

The proposed regulation explicitly covers conversational AI companions and chatbots alongside social media and gaming services. Platforms must disable AI chatbots by default for minors under the draft rules. Services are also prohibited from deploying conversational designs that create emotional dependency in young users.

How is the EU KIDS Act different from the US Kids Safe AI Act?

The EU KIDS Act is a proposed European Union regulation with broad jurisdiction over social networks, video sites, online games, and AI systems. In contrast, the Kids Safe AI Act is a separate United States legislative proposal focused specifically on algorithmic standards for artificial intelligence. The European proposal establishes comprehensive age tiers and an official verification app that do not appear in the American bill.

How would age verification work under the EU KIDS Act?

The proposal requires commercial platforms and mobile app stores to support an official EU age verification app. This tool confirms whether a user meets legal age thresholds without transferring identity documents or biometric data to the digital platform. The mechanism is intended to verify age cryptographically while protecting user privacy.

Is the EU KIDS Act law yet?

The EU KIDS Act is not currently law. It is a regulatory proposal that must undergo negotiations between the European Parliament and the Council of the European Union. No formal implementation date or enforcement timeline has been finalized.

Frequently asked questions

▸ What is the EU KIDS Act?
The EU KIDS Act is a proposed regulation presented by the European Commission on September 17, 2026, aimed at strengthening online child safety across the European Union. It introduces harmonized age tiers, restricts addictive platform features like infinite scroll, and mandates child-centered interface designs. The proposal covers social media, video platforms, online games, and AI chatbots.
▸ Does the EU KIDS Act apply to AI chatbots?
The proposed regulation explicitly covers conversational AI companions and chatbots alongside social media and gaming services. Platforms must disable AI chatbots by default for minors under the draft rules. Services are also prohibited from deploying conversational designs that create emotional dependency in young users.
▸ How is the EU KIDS Act different from the US Kids Safe AI Act?
The EU KIDS Act is a proposed European Union regulation with broad jurisdiction over social networks, video sites, online games, and AI systems. In contrast, the Kids Safe AI Act is a separate United States legislative proposal focused specifically on algorithmic standards for artificial intelligence. The European proposal establishes comprehensive age tiers and an official verification app that do not appear in the American bill.
▸ How would age verification work under the EU KIDS Act?
The proposal requires commercial platforms and mobile app stores to support an official EU age verification app. This tool confirms whether a user meets legal age thresholds without transferring identity documents or biometric data to the digital platform. The mechanism is intended to verify age cryptographically while protecting user privacy.
▸ Is the EU KIDS Act law yet?
The EU KIDS Act is not currently law. It is a regulatory proposal that must undergo negotiations between the European Parliament and the Council of the European Union. No formal implementation date or enforcement timeline has been finalized.

Latest related briefings