A proposal that regulates platforms, not tunnels
On 17 September 2026 the European Commission proposed the EU KIDS Act, COM(2026) 681. It would bar children under 13 from social media. It would also set 15 as the age for opening an independent account. Children aged 13 to 15 would get supervised "mini accounts" capped at one hour a day. According to the Commission's announcement, platforms would have to restrict infinite scroll, reward mechanics and overnight push notifications. They would also have to block unsolicited contact from strangers. The EU's age verification app, which the Commission says does not retain identity documents or biometric data, is held up as the privacy-preserving way to check age.
The anti-circumvention rule in Article 4 is aimed at provider-side conduct. That means non-neutral design choices and nudging minors toward secondary accounts. The Commission's announcement page does not mention circumvention or VPNs, and neither did the text of the proposal we reviewed. The Commission has said it is not planning a VPN crackdown. Even so, the political question is open: what happens when a 14-year-old simply routes around an age gate?
The strongest case for worrying about VPNs
Regulators have a fair point. A law that sets a minimum age is only as strong as its weakest bypass. A January 2026 European Parliamentary Research Service briefing records "a significant surge" in VPN use to bypass age verification in countries that have mandated it. It also notes that some stakeholders propose restricting VPN access to users above the digital age of majority. If minors can switch jurisdictions with one tap, the argument runs, the Act's protections are cosmetic.
That concern explains why Executive Vice-President Henna Virkkunen was asked about VPNs at the press conference for the age verification app. As Euronews reported in its May fact-check, she said no technology is foolproof. She later told Finnish broadcaster Talousaamu that the aim was to make safeguards harder to bypass, not to prohibit VPNs. Her office said there is "absolutely no crackdown on VPNs."
Why targeting VPNs would be the wrong fix
The case against VPN restrictions is stronger, for four reasons.
- VPNs are security infrastructure. Journalists, dissidents, remote workers and ordinary users on public Wi-Fi depend on them. A rule aimed at minors would catch all of these users.
- Enforcement would require surveillance. Telling a minor's VPN session from an adult's means either verifying every VPN user or inspecting traffic. The first creates a new identity checkpoint for the open internet. The second is deep packet inspection by another name. Neither is proportionate to a risk that platform-side duties can address.
- The Act already puts the burden on providers. Under Article 6(4), as described by trade press, providers must establish within six months whether existing account holders are under 15. They must disable accounts that are under 15 or whose age cannot be established. That is an account-level check. A user who logs in from a Dutch or Japanese IP address still has to clear it.
- The proposal is thinly evidenced. EFF notes that it arrives without a full impact assessment, which would normally test alternative policy options and consult stakeholders. Adding a VPN restriction without that evidence would compound the problem.
The risk is in the drafting gap
Silence in the text is not the same as a commitment. The Parliament's own research service has already put VPN-provider age checks on the table as an idea. The Commission has so far offered only verbal reassurance that it will not follow that path.
The proposal will now be examined by Parliament and the Council. Amendments that quietly widen "circumvention" beyond provider conduct are the likely route to a VPN obligation. A rule against "facilitating circumvention" could be read to cover VPN providers. That is exactly how a measure framed as child safety turns into a general-purpose access control.
The sensible line is to keep Article 4 limited to what platforms do. Providers should not design interfaces that steer minors to second accounts. They should not treat a VPN connection as proof of adulthood. They should apply stricter defaults where signals suggest a minor is present, such as device-level age signals, account history and behavioural indicators, without collecting more identity data.
What lawmakers should do
First, Parliament should add a recital or operative clause stating that nothing in the regulation obliges VPN providers, or other general-purpose privacy tools, to verify users' ages or to block users. That would turn the Commission's spokesperson's assurance into law.
Second, the co-legislators should commission the missing impact assessment. It should include measured evidence on how often minors actually bypass age checks and what that bypass costs in harm reduction. The EPRS briefing documents surges in VPN downloads, but downloads are not a measure of child harm.
Third, platform liability should be tied to outcomes and good-faith design rather than perfect prevention. Under the proposal's enforcement structure, which borrows the Digital Services Act's fining framework, a provider could face penalties for leakage it cannot technically stop. Proportionality means judging whether a platform took reasonable steps, not whether any teenager anywhere found a workaround.
The EU can protect children without turning privacy tools into suspects. The Commission has so far kept VPNs out of its text. Parliament should write that restraint into the final law.