On 17 September 2026, Commission President Ursula von der Leyen and Executive Vice-President Henna Virkkunen presented the draft EU KIDS Act, formally COM(2026) 681 (the "Keeping Internet Digital Spaces Accountable and Trustworthy" Act). It is the most ambitious child-safety proposal the EU has produced. Its design rules are mostly well aimed. Its access rules, which depend on mandatory age verification, are much harder to defend.
What the draft does
According to the Council's registered copy of the proposal, the text was presented to the Committee of Permanent Representatives on 23 September 2026, together with a Commission staff working document. Law-firm summaries and press coverage describe a tiered model:
- Children under 13 may not hold accounts on social media or video-sharing platforms.
- Children aged 13 and 14 may hold only parent-supervised "mini accounts" with restricted contacts and a maximum of one hour of daily screen time.
- Users from 15 may hold independent accounts, but only on services that meet safety-by-design duties.
Press reports differ on where the upper boundary sits, so the final text should be checked before the thresholds are quoted in detail. Davis Wright Tremaine's analysis says the draft bans infinite scrolling, autoplay, re-engagement push notifications and streak mechanics for minors. It also requires profiling-based recommendations to be off by default and prohibits self-declared ages on social and video platforms. Fines can reach 6% of worldwide annual turnover, the same ceiling as the Digital Services Act. Providers would have six months after the rules apply to verify existing account holders and disable underage accounts.
The strongest case for the Act
The argument for acting is serious. Article 28 of the Digital Services Act already requires platforms to protect minors, and in July 2025 the Commission issued non-binding guidelines on how. Self-declared ages are trivially bypassed, and design features such as infinite scroll and autoplay are built to extend sessions, not to serve users. A binding regulation covering all 27 member states also avoids a patchwork of national age limits that would fragment the single market and burden smaller services most. Treating compulsive design as a product-safety problem, instead of a content problem, is also the right framing for a free-speech-friendly regime.
Where the design rules are sound
The bans on autoplay, streaks and engagement-optimised feeds for minors regulate how a product is built, not what people say. That is the most proportionate lever available. It does not require anyone to judge whether speech is harmful, and it targets features that platforms can change without removing lawful content. If the final text defines these features narrowly and leaves room for evidence-based exceptions, it should survive proportionality review.
Where the access rules overreach
The problem is the plumbing. A rule that no one under 13 may hold an account, and that self-declaration is banned, means every user of a covered service must prove their age. The Electronic Frontier Foundation argues that the scope reaches "virtually all mainstream services", including games, chatbots and app stores. It warns that age gates "undermine civil liberties, reduce safety, and create barriers to internet entry." Those are advocacy claims, but they point at a real tension. A universal checkpoint changes the internet for adults, not just for children.
The Commission's answer is privacy-preserving technology. Its age-verification blueprint, published on 14 July 2025, lets a service receive only a proof of age. Each proof is meant to be used once, to prevent cross-service tracking. The same page says zero-knowledge proofs were still under development, and that Denmark, France, Greece, Italy and Spain were the first countries piloting it. A mandate that takes effect on a legal timetable should not lean on a tool that was still in pilot at the time of the announcement. If the wallet is delayed or has poor coverage, services will turn to commercial age-estimation vendors that collect faces and documents. That is the outcome the Commission says it wants to avoid.
The one-hour cap for 13- and 14-year-olds raises a different problem. It is a clear, enforceable rule, but it treats an hour of video calls with family the same as an hour of passive scrolling. Parents can lower the cap but, as described, cannot raise it. That puts a statutory rule in place of a household decision and gives no weight to what the child is actually doing.
Enforcement is the third risk. The draft reportedly targets preliminary findings within 30 days and final decisions within 90. Fast timelines suit clear design violations. They suit contested age-assurance disputes much less, where a wrong call can shut a lawful service out of a market of roughly 450 million people.
What lawmakers should change
Parliament and Council must still approve the proposal, so the text is open to amendment. Three changes would keep the child-protection aims while reducing the costs:
- Tie verification to risk. Require strong age assurance for high-risk features and services, and not for every product with a user account.
- Make the wallet a precondition. Delay the age-verification duty until the privacy-preserving tool has been shown to work at scale, and ban retention of verification data in the text itself.
- Write an evidence review into the law. Require the Commission to publish outcome data on teen wellbeing and circumvention within two years, and to adjust the caps accordingly.
The Act's design rules deserve support. Its access rules should be rebuilt around proportionality, so that protecting children does not require every adult in Europe to show their papers to read a feed.