EU child online safety regulation

The EU KIDS Act Gets the Burden of Proof Right but Builds It on Universal Age Checks

The Commission's KIDS Act rightly makes platforms prove safety, but mandatory age verification for every user creates privacy risks the design duties could avoid.

EU KIDS Act at a glance People of Internet Research · EU 15 Age for autonomous accounts One EU-wide minimum age for own so… 1 hour Mini-account daily limit Cap for 13-14s on parent-managed a… 90 days Target for final decision Working days; preliminary findings… 6% Maximum AI provider fine Of worldwide annual turnover for c… peopleofinternet.com
EU KIDS Act at a glance People of Internet Research · EU 15 Age for autonomous accou… 1 hour Mini-account daily limit 90 days Target for final decision 6% Maximum AI provider fine peopleofinternet.com

Key Takeaways

On 17 September 2026 the European Commission published its proposal for the EU KIDS Act, short for 'Keeping Internet Digital Spaces Accountable and Trustworthy'. It is the most ambitious attempt yet to set one child-protection standard across the single market. The proposal has two halves. One is a set of platform duties we should welcome. The other is an age-gating mechanism that carries costs regulators have not fully priced.

The strongest case for the Act

The case for acting is serious. National rules on minors online have diverged, and platforms have had years to show that voluntary controls work. The Commission says the proposal 'harmonises diverging national rules', giving 'legal certainty and a similar level of protection for all children in the European Union' (Commission digital strategy page). A single EU age of 15 for autonomous accounts is easier for a start-up to comply with than 27 different ones. Anyone who has watched a child get pulled into infinite scroll and stranger contact can see why lawmakers want to act.

What the proposal does

According to the Commission's announcement, children under 13 would not be able to access social media services. Children aged 13 to 14 could use only 'a mini account managed by a parent or guardian, with limited features and a time restriction of 1 hour per day'. From 15, teenagers open and manage their own accounts (Commission news item).

The scope goes beyond social networks to video-sharing platforms, online games and AI companions. AI chatbots must be off by default and must not foster emotional dependency. Providers must test systems for risks to children before deployment, according to MediaNama's summary of the text. Under-15 limits apply where services use particular features: livestreaming to an indeterminate audience, contact from outside a user's existing connections, profiling-based recommendations, and designs that encourage uninterrupted use.

The Commission also 'shifts the burden of proof from regulators to platforms'. Very large platforms must demonstrate that their services are safe for children. They must submit compliance plans that are independently audited, by auditors with expertise in child rights, paediatrics and age assurance. The Commission aims for preliminary findings within 30 working days and a final decision within 90 working days. Certain AI providers face fines of up to 6% of worldwide annual turnover (MediaNama).

Where the design is strongest

The safety-by-design layer is the best part of the proposal. Defaults that switch off autoplay, profiling-based recommendations, location tracking and push notifications aim at the mechanisms that produce harm, not at the fact that a child is online. Because the duties attach to specific features, a plain messaging or educational service is not caught merely for having young users. Reversing the burden of proof is also a proportionate use of information asymmetry: platforms hold the data on their own systems and can be asked to produce evidence about them. Fixed decision deadlines of 30 and 90 working days would also give firms predictable timelines instead of open-ended proceedings.

Where it overreaches

The weak point is that a rule with an age line has to check everyone. Self-declaration is not enough; services must use an EU age-verification solution based on a third-party proof-of-age attestation, certified under the EU Age Verification Scheme (MediaNama). The Commission says such tools should protect privacy, and the intent is for them to reveal only that a threshold is met, not identity or birthdate. But every adult who opens an account is still pulled into the system, and the tool's reliability at scale is unproven. Industry and consumer groups have said so. The European Consumer Organisation said age verification is not a 'silver bullet' and raises 'serious privacy and data protection concerns'. CCIA Europe warned that collecting age information and credentials at this scale would create 'an attractive target for cybercriminals' (IAPP).

There is a free-speech cost as well. Mandatory attestation ends casual pseudonymous participation on covered services, and pseudonymity matters for teenagers exploring sensitive questions, for whistleblowers, and for users in places where speech is risky. A 13-year-old's mini account controlled by a guardian also raises a rights question: a young person seeking information their guardian would not approve loses a channel that exists today.

The design duties and the age gate are separable. If the burden of proof works as intended, a platform that must show a service is safe for a child will change the recommender and contact features that cause harm. That reduces the case for a gate every user must pass. Legislators could make certified age assurance a fallback for high-risk features instead of a precondition for every account. They could also require that any attestation scheme be independently tested for privacy before it becomes mandatory.

What to watch

This is a proposal, and it must still pass the EU legislative process (MediaNama). Three questions matter most. First, whether Parliament and Council keep the feature-based trigger or widen it to whole categories of service. Second, whether age verification is tested for privacy and accuracy before becoming mandatory. Third, whether the 30- and 90-working-day deadlines survive contact with litigation from platforms.

The Commission is right that platforms should carry the burden of showing that they are safe for children. It should not shift that burden onto every user's identity.

Sources & Citations

  1. European Commission: EU KIDS Act news item (17 Sep 2026)
  2. Commission digital strategy: Proposal for EU KIDS Act
  3. MediaNama: What's in the EU KIDS Act
  4. IAPP: European Commission unveils EU KIDS Act