top of page

EU Social Media Ban Puts Under-13s Out and Platforms on Notice

2 hours ago
14 min read

The European Union proposed an EU social media ban that would exclude children under 13 and place strict limits on accounts for older minors. European Commission President Ursula von der Leyen announced the plan on September 16, 2026, during her annual address to the European Parliament.

The proposal goes further than asking parents to monitor screen time. It would determine which accounts children can open, what features those accounts offer, and how platforms must verify age. It would also extend protections beyond conventional social networks to some video services, games, AI chatbots, and conversational companions.

That scope creates the central conflict. Brussels wants platforms to prove that their products are safe for minors, while platforms have built their businesses around personalized feeds, notifications, recommendations, and continuous engagement. The policy therefore targets both access and the product mechanics that keep young users online.

The EU Social Media Ban Creates Three Age Tiers

The proposal replaces one loosely enforced age threshold with three distinct levels of access and protection.

Under von der Leyen’s plan, children younger than 13 would not be allowed to access covered social media services. Children aged 13 and 14 could use only limited accounts established and supervised by a parent or guardian.

Those supervised accounts, described as “mini accounts,” would provide fewer features and allow no more than one hour of use each day. Users could independently create personal accounts beginning at age 15.

Platforms would still carry special obligations for users aged 15 through 17. They would have to provide those minors with safer default settings and remove product features considered especially risky or compulsive.

Von der Leyen summarized the structure during her annual address: “No social media under the age of 13. No personal account under the age of 15.”

The distinction matters because the proposal is not a blanket prohibition for everyone below 15. It instead creates a graduated system based on age, parental involvement, account design, and platform responsibility.

That model also turns a familiar private rule into a public obligation. Facebook, Instagram, TikTok, and several other services already say users must be at least 13. However, entering a false birth date often lets younger children pass existing registration screens.

The proposed law would require more than a checkbox or an unverified birthday. Covered services would need a reliable process for determining whether a new user meets the relevant age threshold.

The Commission calls the proposal the EU Kids Act. Von der Leyen announced that the Commission would present it one day after her September 16 speech. A Commission proposal is only the beginning of the EU legislative process.

The European Parliament and the Council, which represents the EU’s 27 member states, would need to examine and negotiate the text. Their amendments could change the age thresholds, covered services, enforcement timetable, or technical obligations.

That process can take years, especially when a proposal affects fundamental rights, privacy, national regulation, and major international technology companies. The announcement therefore establishes a political direction, not an immediate account shutdown.

Still, the direction is unusually specific. Brussels is no longer asking whether children need more protection online. It is proposing exactly when they can gain access and what type of account they can hold.

The rules could cover more than services commonly described as social media. Reporting on the draft indicates that the Commission is considering a broader “social media+” category for high-risk digital services.

That category could include video-sharing platforms, certain online games, and conversational AI products. Educational services, public-sector tools, and professional or industrial AI systems would fall outside the intended scope.

The practical question is how lawmakers will define the boundary. A messaging app, multiplayer game, video platform, and AI companion can all include profiles, recommendations, user content, or private conversations.

If the law focuses on product functions rather than company labels, many services will need to assess individual features. A platform might face different obligations for public feeds, direct messages, live streams, and embedded chatbots.

The EU social media ban is therefore better understood as an age-based product regime. It regulates who enters, what they receive after entering, and which design choices platforms can expose to minors.

Why Brussels Is Acting Now

The political argument has shifted from parental control toward platform responsibility for predictable design risks.

Von der Leyen said young Europeans spend four to six hours a day looking at screens. She described children as being pulled into feeds engineered to keep them scrolling.

Her speech connected that behavior with sleep loss, anxiety, self-harm, cyberbullying, and exposure to increasingly extreme material. She also cited the misuse of girls’ photographs to create sexualized AI images.

These concerns are not confined to the youngest users. However, the Commission argues that children have less capacity to recognize persuasive design or manage repeated algorithmic prompts.

The EU’s approach builds on the Digital Services Act, or DSA. That law already requires large platforms to assess systemic risks, protect minors, and address harmful design practices.

The proposed Kids Act would make several expectations more explicit. Instead of relying mainly on risk reports and case-by-case enforcement, lawmakers would establish clear age gates and default rules.

The European Parliament had already pressed for a similar structure. Its 2025 digital age proposal recommended a default minimum age of 16, with parental consent allowing access between 13 and 16.

Parliament also supported an absolute minimum age of 13 for social media. It asked policymakers to consider comparable rules for video platforms and AI companions that present risks to children.

That earlier position gave the Commission a political foundation. A special panel on child safety then examined age limits, platform design, and the wider conditions shaping children’s online experiences.

In July 2026, von der Leyen publicly endorsed a phased approach. She compared social media access with other age-restricted activities and argued that childhood development warranted different rules at different stages.

National pressure also accelerated the debate. France, Spain, Portugal, and other countries have explored or adopted restrictions aimed at younger social media users.

Those efforts have produced a fragmented European landscape. One country might set the threshold at 15, another at 16, while platforms still apply their own nominal minimum of 13.

Fragmentation presents legal and operational problems. Major services usually operate across the EU through a common technical platform, but national laws can impose different account and verification requirements.

A bloc-wide law could create one framework for the single market. It would also let the Commission oversee major platforms through the enforcement system already established by the DSA.

Outside Europe, Australia provided the most visible precedent. Its legislation established a minimum age of 16 for accounts on designated social media platforms and placed compliance duties on providers.

Other governments have pursued different versions, including limits tied to parental consent or particular categories of services. This global policy trend has turned child access into a test of regulatory authority.

Yet the EU plan has an additional motive. Brussels wants to challenge the idea that engagement systems are fixed features of the internet.

Von der Leyen framed the problem as a transfer of power away from families. Parents can set household rules, but those rules compete with notifications, social pressure, personalized recommendations, and products available around the clock.

The EU Kids Act would intervene at the service level. A family would not need to negotiate separately with every platform’s default settings because certain safeguards would become mandatory.

That changes the political target. The proposal does not treat every harmful experience as a failure of parenting or individual self-control. It asks whether the platform created conditions that made the harm more likely.

The Fight Is Over Platform Design, Not Only Age

The most consequential part of the plan is its attempt to restrict the engagement machinery surrounding teenage accounts.

For users aged 15 through 17, the proposal would require safer design by default. Reported provisions target infinite scrolling, automatic video playback, engagement-focused notifications, and other features that encourage prolonged use.

Infinite scrolling continuously loads new content as the user moves through a feed. It removes the stopping point created by pages, menus, or a clear end to available material.

Autoplay creates a similar effect by beginning the next video without a deliberate request. Notifications can then pull a user back after they close the app.

Each feature appears small in isolation. Combined with personalized recommendations, they create a continuous loop of prompts, rewards, and new material.

The Commission’s draft’s wider scope reportedly applies the same reasoning to games and conversational AI. Games could face rules covering virtual currencies, microtransactions, and penalties for missing daily activity.

AI chatbots could be required to appear less intrusively and operate under age-appropriate settings. That issue has grown more urgent as conversational agents move into messaging services, social platforms, search products, and games.

These systems present a different risk from a public feed. A chatbot can produce personalized responses, remember conversation history, simulate emotional support, or continue an interaction indefinitely.

The system does not need to qualify as a social network to compete for a child’s attention. It can create its own engagement loop through conversation, reassurance, role-play, or repeated prompts.

This explains why a law announced as an EU social media ban may reach AI providers. The underlying concern is not only contact with strangers. It is exposure to digital systems that can influence behavior without age-appropriate safeguards.

The proposal also reverses the regulatory burden. Von der Leyen said platforms would have to prove their services were safe, rather than expecting families to document harm after it occurred.

That principle puts pressure on Meta, TikTok, YouTube, Snapchat, Roblox, and providers of AI companions. The final list will depend on the legal definition and individual service features.

Companies may need to create separate product experiences for children, supervised teens, older minors, and adults. They will also need to decide which capabilities disappear at each level.

A supervised account cannot be just a standard account connected to a parent’s email address. To satisfy the policy’s purpose, it would need meaningful limits on time, contact, content discovery, recommendations, and data use.

Those changes challenge the economics of engagement. Advertising, subscriptions, creator activity, and in-app purchases all benefit when users return frequently and remain active.

A one-hour daily limit for younger teens would place a hard boundary on that activity. Disabling endless feeds or persistent notifications would create additional stopping points.

The policy could therefore affect product metrics even if minors represent a limited share of reported users. Platforms would need to measure success against regulatory safety requirements, not only session length or retention.

This is the proposal’s real confrontation with Big Tech. The debate is no longer limited to removing illegal posts. It reaches into how interfaces are built and how recommendation systems behave.

Platforms are likely to argue that risk varies by service, feature, and user. A private family messaging tool does not operate like a public recommendation feed, even if both are available through one application.

Lawmakers will need to preserve those distinctions without creating easy loopholes. A definition that is too broad could capture useful services, while a narrow one could encourage companies to reclassify products.

The strongest version of the law would focus on measurable functions and risks. That could include public distribution, algorithmic recommendations, contact from unknown adults, compulsive design, monetized interaction, and emotionally responsive AI.

Social Media Age Verification Is the Weak Link

The ban only works if platforms can distinguish age groups without building a new system for tracking everyone.

The Commission has spent more than a year developing a common technical foundation for age verification. It released a blueprint in July 2025 and declared the system feature-ready in April 2026.

The tool, sometimes called a mini wallet, is designed to let someone prove that they exceed an age threshold. A service should receive a yes-or-no answer rather than the person’s name, birth date, or identity document.

The Commission says the design can support thresholds such as 13+, 15+, or 18+. It uses specifications compatible with the European Digital Identity Wallets scheduled for rollout across member states.

Users can establish an age credential through an accepted identity source. The resulting proof can then be presented to a platform without repeatedly uploading a passport or identity card.

The official verification framework is open source and can be adapted by member states. The Commission says its privacy protections cannot be removed during national customization.

That architecture addresses one common objection to age checks. If every platform directly collects identity documents, companies and contractors acquire sensitive records that can be stolen, misused, or linked with browsing behavior.

Selective disclosure reduces that exposure. The platform learns that a threshold has been met but should not learn the underlying identity information.

EU recommendations also prohibit using age attributes as another method for locating, profiling, or tracking people. They call for cybersecurity controls, independent scrutiny, trusted providers, and interoperable national systems.

The Commission wants every member state to make an EU-compatible age-verification option available by December 31, 2026. It can operate as a stand-alone application or within a digital identity wallet.

The technical model is more privacy-conscious than repeatedly sending identity documents to social networks. It does not eliminate the enforcement problem.

Security researcher Paul Moore has publicly demonstrated methods that he says bypassed versions of the EU application. His criticism focuses on whether a browser or device can falsely report a successful age check.

A bypass does not automatically expose someone’s identity. It does show why privacy and reliability must be evaluated separately.

A perfectly private credential has limited regulatory value if children can evade it with a browser extension, borrowed device, altered software, or virtual private network. A rigid system can become invasive if authorities respond by demanding stronger identity binding.

That creates a difficult tradeoff. The EU wants proof strong enough to enforce age limits but minimal enough to preserve anonymity and avoid a record of people’s online activity.

Children can also use an adult’s device or credential. Parents could intentionally approve access, misunderstand the controls, or allow a child to operate an existing account.

The 13-and-14 age group adds another verification layer. A service must establish both the child’s age and the supervising adult’s authority to create the mini account.

Cross-border consistency presents another challenge. National identity systems differ, and not every resident has the same documents, device access, or ability to complete a digital verification process.

Any system must also accommodate migrants, people without current documents, shared family devices, and users with accessibility needs. Otherwise, verification can exclude lawful users.

False classification creates its own harms. An adult wrongly identified as a minor could lose access, while a child wrongly classified as an adult could receive fewer protections.

The Commission therefore needs evidence about accuracy, bypass resistance, appeal procedures, data minimization, and accessibility. Technical compliance alone will not establish that the system works in real homes.

Platforms also need rules for existing accounts. Checking only new registrations would leave millions of current profiles operating under self-declared ages.

Rechecking everyone would create a much larger rollout and privacy burden. The final legislation must explain whether providers can rely on existing signals, require new credentials, or phase verification across user groups.

These unresolved questions make social media age verification the proposal’s main pressure point. The legal age tiers are easy to state. Implementing them without normalizing identity checks across the internet is much harder.

A Ban Cannot Carry the Entire Child-Safety Strategy

Age limits can reduce exposure, but they cannot replace safer products, effective moderation, or support for young people facing harm.

The policy assumes that restricting access will reduce contact with addictive features, violent material, predatory behavior, harassment, and unsafe AI interactions. That assumption is plausible but not sufficient.

A child blocked from one service can move to another. Smaller platforms, private groups, unofficial applications, and foreign services may offer weaker moderation and fewer reporting tools.

Children can also encounter harassment through messaging, games, school communities, and offline relationships. Removing a public social account does not remove the social conflict behind the abuse.

The same limitation applies to harmful content. Search engines, websites, video services, and generative AI systems can all provide material outside a conventional social feed.

That is why safer design remains essential for older teenagers and adults. A narrow focus on the user’s birthday could let companies preserve risky mechanics for everyone who crosses the threshold.

The Commission appears to recognize this problem. The proposed protections for 15-to-17-year-olds focus on default design, while a separate Digital Fairness Act is expected to address addictive practices more broadly.

The EU Kids Act also faces a proportionality test. European courts and lawmakers must balance child safety against privacy, access to information, freedom of expression, and participation in public life.

Social media can expose children to serious harm. It can also provide educational material, peer support, creative communities, and contact for young people who feel isolated locally.

A legal framework needs to distinguish those benefits from high-risk features. Otherwise, the policy may treat access itself as the problem while overlooking differences in content, context, and design.

France’s experience illustrates the legal risk. Its attempt to restrict social media access for children under 15 encountered constitutional objections related to fundamental freedoms.

An EU-wide regulation may resolve some internal-market conflicts, but it does not avoid fundamental-rights review. Lawmakers must show that the restrictions are necessary, proportionate, and accompanied by adequate safeguards.

The age bands also invite debate. Development does not change uniformly on a birthday, and children within the same age group can have different needs and levels of independence.

Clear thresholds make rules enforceable, but they remain policy choices. The Parliament previously favored independent access at 16, while the Commission proposal places that transition at 15.

Parents may object from opposite directions. Some will see the ban as overdue support against products they cannot realistically monitor. Others will see mandatory age checks and account controls as state intrusion into family decisions.

Technology companies may challenge the definitions, technical standards, and evidence supporting particular restrictions. They may also argue that app stores or device operating systems should share responsibility.

That distribution of responsibility matters. Apple and Google control mobile app distribution and provide family-account systems, while network operators and identity providers occupy other points in the access chain.

Making every participant responsible can improve coverage, but it can also create duplicated checks. Making only social platforms responsible can leave gaps as products converge.

The Commission should therefore judge success through outcomes, not merely completed verifications. Useful measures would include reduced unwanted adult contact, fewer harmful recommendations, faster responses to harassment, and lower exposure to age-inappropriate features.

Regulators should also monitor displacement. If children migrate to harder-to-observe spaces, a compliant decline in major-platform accounts might conceal new risks elsewhere.

The proposal’s strongest idea is that platforms must redesign unsafe experiences. Its weakest interpretation would reduce child safety to an identity checkpoint at registration.

Three Signals Will Show Whether the EU Plan Can Work

The next test is whether lawmakers convert a strong political announcement into precise duties, credible technology, and measurable safety improvements.

The first signal is the published EU Kids Act text. Readers should look for exact definitions of social media, AI companions, video-sharing services, and games.

The text must specify whether restrictions apply to individual features or entire products. It should also explain how supervised accounts work, who verifies parental authority, and which capabilities must be disabled.

A precise definition would strengthen the Commission’s case by showing that the proposal targets identifiable risks. A vague category of “social media+” would weaken it by creating uncertainty and uneven enforcement.

The legislative timetable matters too. The Parliament and Council can retain the three age bands, raise the independent-access threshold, or change the scope significantly.

The second signal is real-world performance of the age-verification system. Member states are expected to make compatible solutions available by the end of 2026.

Independent testing should measure whether the proof remains anonymous, whether platforms can link repeated checks, and how easily users can bypass the process. Testing should also cover accessibility and false results.

Strong results would support the EU social media ban by showing that privacy and enforceability can coexist. Widespread bypasses or identity leakage would undermine its central mechanism.

The third signal is how platforms redesign products before the law takes effect. Companies do not need to wait for final legislation to disable autoplay, reduce notifications, restrict unknown contacts, or test chronological feeds for minors.

Voluntary changes could show that safer design is technically practical. They could also influence the final rules by giving lawmakers evidence about which controls produce measurable results.

Resistance would reveal a different conflict. If platforms argue that the requested changes are impossible or disproportionate, regulators will need to separate genuine technical limits from objections tied to engagement and revenue.

AI providers deserve particular attention. Conversational systems are evolving faster than traditional account regulations, and their risks do not map neatly onto public posting or follower networks.

Providers should explain how they identify minor users, limit sexualized or manipulative exchanges, handle self-harm conversations, and prevent adults from creating unsafe companion experiences for children.

The EU social media ban ultimately asks a larger question: who should control the conditions under which children encounter persuasive digital systems?

Brussels has answered that families need enforceable limits and platforms must carry more of the burden. The announcement is clear, but legislation, verification, and product changes will determine whether that promise survives contact with everyday use.

For parents and technology users, the immediate action is to examine the defaults already available on children’s accounts. Check time controls, recommendation settings, direct-message permissions, location sharing, and connected AI features. Then watch whether the final EU Kids Act makes those protections automatic rather than optional. The decisive evidence will not be the number of age checks completed. It will be whether children encounter fewer harmful interactions without every user surrendering more identity data.

Give every agent the context to do better work

Connect your agents to the knowledge, decisions, and history already organized in remio.

remio currently supports Windows 10+ (x64) and Macs with Apple silicon.

Your AI Partner at Work
Get more done with remio

Plan. Create. Deliver.
All in one place.

bottom of page