EU child online safety

The EU Kids Act Fixes a Real Design Problem With a Universal Identity Mandate

Brussels' child-safety bill bans accounts under 13 and mandates age checks for every user, adult or minor, across social media, games and AI chatbots.

The EU Kids Act's Tiered Age Regime People of Internet Research · EU 15 Minimum age, own account Independent social media accounts … 13–14 Parent-supervised account band Thirteen- and fourteen-year-olds m… 45M+ Very large platform threshold Platforms above this EU monthly-us… peopleofinternet.com
The EU Kids Act's Tiered Age Regime People of Internet Research · EU 15 Minimum age, own account 13–14 Parent-supervised account band 45M+ Very large platform thresho… peopleofinternet.com

Key Takeaways

What the Commission actually proposed

On September 17, 2026, Commission President Ursula von der Leyen and Executive Vice-President Henna Virkkunen unveiled the EU Kids Act, a tiered access regime for anyone under 18 online. Under-13s are barred from opening social media or video-sharing accounts outright. Thirteen- and fourteen-year-olds can use only parent-managed "mini accounts" nested inside a guardian's account. Independent accounts become available at 15 (European Commission). The scope is broad by design: social networks, video platforms, online games, app stores, and — notably — AI chatbots and companion apps, which the Commission says cannot be allowed to "simulate human relationships in ways creating emotional dependency" (Digital Strategy FAQ).

The enforcement mechanism is where the bill becomes structurally different from the UK's Online Safety Act or Australia's under-16 social media law: self-declared age is explicitly rejected. Platforms must use "certified age verification," built around a free, Commission-run app using zero-knowledge-proof cryptography that is supposed to confirm someone is over or under a threshold without disclosing identity documents or biometric data, with the European Digital Identity Wallet layered in later (Digital Strategy FAQ). Very large platforms — those crossing the Digital Services Act's 45-million-monthly-EU-user threshold — must submit compliance plans and pass independent audits before the Commission can order corrective action, with the burden of proof flipped: platforms must show their design is safe, not regulators show it isn't (European Commission).

The strongest case for it

Before picking this apart, it's worth stating the case fairly. Infinite scroll, autoplay, engagement-optimized ranking, and push notifications tuned to maximize return visits were not built with a 12-year-old's judgment in mind, and platforms have had a decade to self-regulate around youth wellbeing with underwhelming results. A patchwork of national age laws — several EU member states have already floated or passed their own social-media restrictions — creates exactly the kind of single-market fragmentation the Commission exists to prevent; a harmonized EU standard is, on its own terms, a more coherent outcome than 27 divergent ones. And shifting the compliance burden onto platforms rather than parents or regulators is a defensible allocation of responsibility: the companies control the design choices that make a feed addictive.

Where the mandate overshoots

The problem is that verifying a child's age requires verifying everyone's age. As the Electronic Frontier Foundation put it, safety-by-design obligations only ease up for a service "if they use age assurance to establish that the user is an adult" — meaning the regime that starts as child protection becomes a universal identity check for the entire EU internet population (EFF). That is a real cost, not a hypothetical one: it narrows anonymous and pseudonymous participation for journalists' sources, domestic-abuse survivors, LGBTQ+ users in hostile jurisdictions, and ordinary adults who simply don't want a platform holding a verified link between their identity and their account.

Industry's objection, while self-interested, points at a genuine engineering hazard. CCIA Europe's Daniel Friedlaender warned that requiring "sensitive information about children, adults, and family relationships... will create serious risks for everyone," and flagged that linked age-and-family-relationship data becomes "an attractive target for cybercriminals" (CCIA Europe). A centralized or semi-centralized proof-of-guardianship system is a single high-value breach target in a way that today's fragmented, sloppier self-declared-age systems simply are not. CCIA also flags a compounding regulatory problem: the Kids Act's obligations sit on top of the AI Act and the Digital Services Act without clear sequencing, risking "conflicting obligations, parallel enforcement tracks, and legal uncertainty" that smaller EU competitors to Meta, Google, and TikTok will struggle to absorb — precisely the compliance-moat dynamic that has already entrenched incumbents under GDPR and the DSA.

The proportionate alternative was available

A narrower bill could have required safety-by-design defaults (no autoplay, no engagement-optimized feeds, private accounts by default for verified minors) without forcing every adult through an age gate to use it. Device-level or app-store-level age signals — Apple and Google already collect birthdate at account setup — could satisfy most of the child-protection goal with far less new data collection than a bespoke EU-wide verification app layered across every social network, game, and chatbot. The zero-knowledge cryptography the Commission is building is a genuine technical improvement over crude ID-upload age gates elsewhere in Europe, and deserves credit for that. But cryptographic elegance doesn't resolve the underlying policy choice: this bill trades a real, narrow problem (children on adult-designed platforms) for a real, broad one (a verified-identity layer under the entire EU internet). Parliament and Council negotiations over the next 12–18 months should narrow the mandate's edges — chatbots and app stores in particular look scoped more by anxiety than by evidence — rather than wave the trade-off through because the cryptography is well-built.

Sources & Citations

  1. European Commission: EU KIDS Act announcement
  2. European Commission: Kids Act explained (FAQ)
  3. EFF: EU Kids Act Won't Keep the Internet Accountable and Trustworthy
  4. CCIA Europe: EU Online Age Checks Make Privacy Trade-Offs Unavoidable
  5. netzpolitik.org: leaked EU Kids Act draft