EU child online safety / age verification

The EU KIDS Act Gets the Design Problem Right but Bets Too Heavily on Mandatory Age Gates

The Commission's draft bans addictive design for minors, a sound proposal, but universal age verification and a hard one-hour cap risk privacy costs for every user.

EU KIDS Act at a Glance People of Internet Research · EU 6% Maximum fine Share of worldwide annual turnover… 1 hour Daily cap, ages 13-14 Maximum screen time on mini accoun… 13 Account ban below age No social media accounts for under… peopleofinternet.com
EU KIDS Act at a Glance People of Internet Research · EU 6% Maximum fine 1 hour Daily cap, ages 13-14 13 Account ban below age peopleofinternet.com

Key Takeaways

On 17 September 2026, Commission President Ursula von der Leyen and Executive Vice-President Henna Virkkunen presented the draft EU KIDS Act, formally COM(2026) 681 (the "Keeping Internet Digital Spaces Accountable and Trustworthy" Act). It is the most ambitious child-safety proposal the EU has produced. Its design rules are mostly well aimed. Its access rules, which depend on mandatory age verification, are much harder to defend.

What the draft does

According to the Council's registered copy of the proposal, the text was presented to the Committee of Permanent Representatives on 23 September 2026, together with a Commission staff working document. Law-firm summaries and press coverage describe a tiered model:

Press reports differ on where the upper boundary sits, so the final text should be checked before the thresholds are quoted in detail. Davis Wright Tremaine's analysis says the draft bans infinite scrolling, autoplay, re-engagement push notifications and streak mechanics for minors. It also requires profiling-based recommendations to be off by default and prohibits self-declared ages on social and video platforms. Fines can reach 6% of worldwide annual turnover, the same ceiling as the Digital Services Act. Providers would have six months after the rules apply to verify existing account holders and disable underage accounts.

The strongest case for the Act

The argument for acting is serious. Article 28 of the Digital Services Act already requires platforms to protect minors, and in July 2025 the Commission issued non-binding guidelines on how. Self-declared ages are trivially bypassed, and design features such as infinite scroll and autoplay are built to extend sessions, not to serve users. A binding regulation covering all 27 member states also avoids a patchwork of national age limits that would fragment the single market and burden smaller services most. Treating compulsive design as a product-safety problem, instead of a content problem, is also the right framing for a free-speech-friendly regime.

Where the design rules are sound

The bans on autoplay, streaks and engagement-optimised feeds for minors regulate how a product is built, not what people say. That is the most proportionate lever available. It does not require anyone to judge whether speech is harmful, and it targets features that platforms can change without removing lawful content. If the final text defines these features narrowly and leaves room for evidence-based exceptions, it should survive proportionality review.

Where the access rules overreach

The problem is the plumbing. A rule that no one under 13 may hold an account, and that self-declaration is banned, means every user of a covered service must prove their age. The Electronic Frontier Foundation argues that the scope reaches "virtually all mainstream services", including games, chatbots and app stores. It warns that age gates "undermine civil liberties, reduce safety, and create barriers to internet entry." Those are advocacy claims, but they point at a real tension. A universal checkpoint changes the internet for adults, not just for children.

The Commission's answer is privacy-preserving technology. Its age-verification blueprint, published on 14 July 2025, lets a service receive only a proof of age. Each proof is meant to be used once, to prevent cross-service tracking. The same page says zero-knowledge proofs were still under development, and that Denmark, France, Greece, Italy and Spain were the first countries piloting it. A mandate that takes effect on a legal timetable should not lean on a tool that was still in pilot at the time of the announcement. If the wallet is delayed or has poor coverage, services will turn to commercial age-estimation vendors that collect faces and documents. That is the outcome the Commission says it wants to avoid.

The one-hour cap for 13- and 14-year-olds raises a different problem. It is a clear, enforceable rule, but it treats an hour of video calls with family the same as an hour of passive scrolling. Parents can lower the cap but, as described, cannot raise it. That puts a statutory rule in place of a household decision and gives no weight to what the child is actually doing.

Enforcement is the third risk. The draft reportedly targets preliminary findings within 30 days and final decisions within 90. Fast timelines suit clear design violations. They suit contested age-assurance disputes much less, where a wrong call can shut a lawful service out of a market of roughly 450 million people.

What lawmakers should change

Parliament and Council must still approve the proposal, so the text is open to amendment. Three changes would keep the child-protection aims while reducing the costs:

The Act's design rules deserve support. Its access rules should be rebuilt around proportionality, so that protecting children does not require every adult in Europe to show their papers to read a feed.

Sources & Citations

  1. Council record of the EU KIDS Act proposal, COM(2026) 681
  2. European Commission: age verification blueprint (14 July 2025)
  3. EFF: EU Kids Act Won't Keep the Internet Accountable and Trustworthy
  4. Euronews: The EU's plan to make the internet safer for kids
  5. Davis Wright Tremaine: Commission proposes EU KIDS Act