Alessandro Del Ninno
News
EU KIDS Act: New Rules on Age Verification, Safety by Design and Online Protection of Minors.
INFORMATION TECHNOLOGY
17/09/2026

On 17 September 2026, the European Commission presented its proposal for a Regulation, the EU KIDS Act – “EU Keeping Internet Digital Spaces Accountable and Trustworthy” (COM(2026) 681 final), aimed at strengthening and harmonising the protection of minors when using digital services across the European Union. At this stage, the initiative remains a legislative proposal, which must be considered by the European Parliament and the Council and may therefore be amended during the legislative process.

The proposed framework goes well beyond the highly visible issue of establishing a minimum age for access to social media. It introduces a graduated access regime: children under the age of 13 would not be permitted to hold social media accounts; users aged 13 to 14 could access social media only through restricted accounts subject to parental or guardian supervision; from the age of 15, minors would be allowed to open and manage their accounts independently. Accounts held by 13- and 14-year-olds would be subject, among other requirements, to permanent parental-control mechanisms and a daily usage limit not exceeding one hour. Within six months from the date on which the new rules become applicable, the platforms concerned would also be required to verify existing accounts and disable those attributable to users under the age of 15, or where the user’s age cannot be established in accordance with the prescribed procedures.

Of particular significance for businesses is the principle of “safety by design”. Providers would no longer be able to rely solely on ex post control mechanisms; instead, they would be required to design services and functionalities with the risks to minors taken into account from the outset. Subject to differentiated obligations, the proposed rules would apply not only to social networks and video-sharing platforms, but also to online video games, app stores, AI companions and conversational chatbots. Measures identified by the Commission include restrictions on design techniques capable of encouraging compulsive use — such as infinite scrolling, continuous autoplay, certain types of notifications and “streak” mechanisms — together with more protective default settings, restrictions on contact by unknown users and specific requirements concerning recommender systems used in services accessed by minors.

A further key area concerns age verification. A mere self-declaration of the user’s date of birth would no longer be sufficient in the situations governed by the Regulation. The proposal instead envisages the use of certified age-assurance mechanisms, including the European age-verification solution and, subsequently, the European Digital Identity Wallet. At the same time, the architecture outlined by the Commission seeks to reconcile age verification with the data-minimisation principle: through “zero-knowledge proof” techniques, the service should be able to establish only whether the user is above or below a specified age threshold, without receiving the user’s identity or any additional personal data. The future framework will therefore also need to be interpreted and implemented in conjunction with the GDPR, as well as with the obligations already arising under the Digital Services Act.

Specific provisions are also envisaged for artificial intelligence systems intended for, or accessible to, minors. AI companions and chatbots should not use interaction techniques capable of creating emotional dependency through the simulation of human relationships. In addition, certain functionalities would have to be disabled by default, while providers would be required to assess risks to minors before making the system available and to monitor such risks thereafter. In this respect, the KIDS Act establishes a direct interface with the governance and supervisory framework laid down by the AI Act.

The proposed enforcement regime is also particularly stringent. For the largest platforms, the model outlined by the Commission would effectively require them to demonstrate compliance before enabling interactions involving minors: VLOPs would be required to prepare a detailed compliance plan and submit it to independent verification. The sanctions contemplated by the proposal may reach up to 6% of total worldwide annual turnover, relying, in respect of platforms and AI systems, on the supervisory structures already established under the DSA and the AI Act respectively.

From an operational perspective, the proposal already warrants close attention from businesses that design or provide digital services that may be used by minors. In particular, companies should assess whether their services are likely to fall within the future scope of application, map functionalities that depend on knowing or estimating a user’s age, review recommender systems, notifications, engagement mechanisms and in-app purchases, and consider the future integration of age-assurance and parental-control tools. Providers of AI systems will also need to coordinate this analysis with the classification and compliance requirements already arising under the AI Act; for all operators, the design of age-verification mechanisms will need to be accompanied by a specific assessment of the associated data-protection implications.

The proposal therefore does not merely introduce an “EU age threshold” for social media. Rather, it anticipates a broader regulatory model under which the protection of minors becomes a structural requirement in the design of digital products and services. Businesses potentially affected should therefore monitor the legislative process closely, particularly as regards service design, data governance and the interaction between the compliance obligations arising under the KIDS Act, the DSA, the GDPR and the AI Act.