What the Commission actually proposed
On 17 September 2026 the European Commission adopted the EU KIDS Act. According to the Commission's announcement, the proposal bars social media platforms from accessing children under 13 and sets an EU-wide minimum age of 15 for opening an account of one's own. Children aged 13 and 14 may use "mini accounts" set up by a parent or guardian, with safeguards such as limited social contacts and screen time capped at one hour per day. The proposal targets infinite scroll, reward mechanisms and night-time push notifications. AI companions must be off by default and may not simulate relationships in ways that create emotional dependency. The text now goes to the European Parliament and the Council.
The strongest case for the Act
The case for acting is serious. Platforms have spent a decade optimising for engagement, and the existing approach, where children self-declare their age and regulators must prove harm after the fact, has plainly not worked. The Act reverses that logic. In the Commission's words, service providers will have to show that their services are age-appropriate and safe by design. A rule that shifts the burden onto the party that controls the product design, and that can run the experiments, is defensible. It also helps that the Commission is not building a new enforcement system. According to the Commission's FAQ, the Commission supervises very large platforms and AI chatbots, while national authorities cover other services, following the Digital Services Act model.
Parents also face a real collective-action problem. A 14-year-old who is the only one in the class off an app bears a social cost, so a uniform legal floor can help families who cannot hold the line individually.
Where the design goes wrong
Certified age verification for everyone
The weakest element is the gate. The Commission's FAQ states that self-declared age is explicitly not enough and that access must be gated by certified age verification, including through a free EU app or the Digital Identity Wallet using zero-knowledge proofs. The Commission says these tools can confirm age without identifying or tracking the user, and that is a real technical advance over uploading a passport to a platform.
But the mandate has to be judged by how it will operate in practice. Verification happens at the service level, so every adult who wants to use a covered service must also prove their age. The Electronic Frontier Foundation argues that because the Act's scope is broad, spanning social media, video-sharing, games and AI companions, most companies are well advised to play it safe and use privacy-unfriendly age checks. Zero-knowledge proofs are only as private as the weakest implementation a platform chooses to certify. The architecture also leaves a gap: users without a smartphone, a wallet or a compatible ID are the ones most likely to be locked out, and these are often the marginalised users the EFF highlights.
A compliance burden that favours incumbents
The Commission's FAQ does not address special treatment for small and medium enterprises. The EFF notes that the Act exempts nonprofits and educational services but has no SME exceptions, which it warns will only foster the dominance of resource-laden tech companies. Penalties of up to 6% of worldwide annual turnover are calibrated to deter the largest platforms. For a small European social or gaming startup, the same exposure plus a mandatory child safety plan reviewed by independent auditors is a barrier to market entry. The likely result is that Europe's youth-safety rules are met by the firms best able to absorb them, which are mostly American.
Safe by design shades into content control
The obligation to prevent "rabbit holes" of harmful content through recommender systems sounds modest. But the EFF cautions that deciding what counts as safe design can easily become a question of what content people can access or share. Regulators should keep design rules, which target mechanics such as autoplay, streaks and notification timing, separate from rules that effectively require platforms to judge lawful speech. The first is proportionate. The second invites over-removal, and young people's access to information on health, identity and politics is the likely casualty.
What Parliament and Council should do
The design-based provisions are the strongest part of the proposal and should be preserved: restrictions on infinite scroll, engagement rewards and manipulative notifications, and the default-off rule for AI companions. They address the product, not the user, and they impose no identity check.
The age-assurance architecture needs three amendments:
- Proportionality by risk. Strict verification should apply only to services with demonstrable high-risk features, not to every service that falls within a broad definition.
- SME relief. Provide phased obligations or reduced audit requirements for small providers, with clear liability when a provider relies on a certified third-party verifier.
- Hard data limits. Certified solutions must be legally barred from retaining or reusing age-check data, with independent testing before certification. The Commission describes the EU age verification app as privacy-preserving by design, and the law should make that a binding condition, not a marketing claim.
A fourth question is whether a hard age-15 floor is the right instrument at all, given that the mini-account model already puts parents in charge for 13- and 14-year-olds. Lawmakers should ask for evidence that the extra restriction improves outcomes beyond the design bans before locking it in.
Bottom line
The KIDS Act correctly identifies engagement-maximising design as the core harm and places the burden of proof on those who build the product. It should not make identity-adjacent verification the entry ticket to the open internet for all users. Parliament and Council have time to separate the two, and a version that keeps the design rules and narrows the gate would protect children without taxing everyone else's privacy.