European Commission EU KIDS Act Plan Puts Age Gates Across the Internet
The European Commission reportedly plans to propose the EU KIDS Act on September 17, placing a proposed age threshold across several major categories of online services.
Leaked documents describe something broader than a conventional social media restriction. Video-sharing services, AI chatbots, digital companions, and online games would also face age checks under the reported plan.
That scope creates the central conflict. Brussels wants platforms to prove that users meet age requirements without turning routine internet access into an identity checkpoint. The proposal also shifts responsibility away from children entering birth dates and toward companies verifying them.
The Commission has not published the legislation, and its final language can still change. The age limits, covered services, enforcement powers, and privacy safeguards therefore remain reported provisions rather than enacted rules.
However, the reported plan follows years of EU policy work on platform design, age assurance, and child safety. It also arrives after national efforts exposed the legal and technical limits of simply banning younger users.
What the EU KIDS Act Would Change
The reported EU KIDS Act would replace scattered age policies with a common legal structure covering much more than social media.
According to documents reported by Euractiv, the Commission plans to create a minimum age of 15 for opening an autonomous account. Children below that threshold would face tiered restrictions based on their age and the type of service involved.
An autonomous account is one created and controlled without parental authorization. That distinction matters because the proposal reportedly does not treat every person under 18 in the same way.
Children younger than 15 would not necessarily disappear from every covered service. Instead, access could depend on parental consent, service design, and age-specific rules that have not yet been published in final form.
The reported category of “social media plus” widens the policy’s reach. It includes social networks and video-sharing platforms, but reportedly extends to AI chatbots, digital companions, and online games.
Social media and video services would reportedly verify age when someone creates an account. Gaming platforms would conduct checks before a user downloads a game, according to the leaked material described in the age-check report.
Those triggers would affect different businesses in different ways. A social network controls account creation, while a gaming marketplace may control downloads but not every later interaction inside a game.
AI services create another boundary problem. A chatbot can function as a tutor, search tool, creative assistant, or simulated companion, sometimes within the same product.
The law would need clear definitions to determine which systems receive the strictest treatment. Otherwise, similar products could face different rules because companies describe or distribute them differently.
The draft reportedly allows providers to use an EU age-verification tool or another publicly supported solution. It also points toward a new enforcement structure modeled on existing EU digital laws.
Services designated under the rules could reportedly pay a supervisory fee. Such a levy would help finance Commission oversight, resembling the way enforcement costs are allocated under other parts of the EU technology rulebook.
The Commission is expected to present the plan on Thursday, September 17. Presentation would begin a legislative process, not produce an immediate ban.
EU countries and the European Parliament would still need to negotiate the text. Definitions, thresholds, exemptions, enforcement authority, and implementation dates could all change during that process.
The distinction is crucial for families and technology companies. The EU KIDS Act is a reported proposal with substantial political momentum, but it is not yet a binding access rule.
Why Brussels Is Acting Now
The proposal arrives because voluntary age declarations and national experiments have failed to produce a consistent European system.
Many platforms already state that users must be at least 13. Yet a birth-date box usually does little to establish whether the person opening an account actually meets that requirement.
The Commission has spent several years moving from self-declaration toward age assurance. Age assurance is the broader set of methods used to estimate or verify a person’s age or age range.
In July 2025, the Commission published child-protection guidance under the Digital Services Act, or DSA. The DSA governs online intermediaries and gives the EU enforcement powers over major platforms.
Those minor-protection guidelines recommend private accounts by default, safer recommendation systems, stronger blocking tools, and limits on engagement features for children.
The guidance also addresses autoplay, streaks, read receipts, push notifications, and persuasive design. It recommends safeguards for AI chatbots integrated into online platforms.
Gaming appears in the same policy framework. The Commission identifies virtual currencies and loot boxes as commercial mechanisms that can exploit children’s limited understanding of spending and probability.
However, the guidelines are not a universal minimum-age law. Compliance with them is voluntary, although the Commission can use them when assessing whether platforms meet DSA obligations.
That gap helps explain the new proposal. Guidance can describe safer design, but a legal age threshold requires platforms to determine who receives which experience.
Political pressure has also increased. In 2025, the European Parliament backed a nonbinding call for a harmonized minimum age of 16 for social media, video-sharing platforms, and AI companions.
Parliament’s position would allow access between 13 and 16 with parental consent. It also called for restrictions on engagement-based recommendations, addictive interfaces, and gambling-like gaming features.
The resolution passed by 483 votes to 92, with 86 abstentions. Although it did not create law, the margin demonstrated broad support for stronger intervention.
The same Parliament resolution cited research indicating that 97 percent of young people go online daily. It said 78 percent of people aged 13 to 17 check their devices at least hourly.
It also reported that one in four minors display problematic or dysfunctional smartphone use. Those figures do not prove that every platform causes harm, but they help explain the political urgency.
The Commission created a Special Panel on Child Safety Online after Ursula von der Leyen’s 2025 State of the Union address. The panel included expertise in health, neuroscience, psychology, computer science, digital literacy, and children’s rights.
Its co-chairs delivered a final report in July 2026. The panel produced 39 recommendations and favored restrictions for children under 13 until providers demonstrate that their services are safe by design.
The reported EU KIDS Act appears to convert that policy momentum into a wider legislative system. Its proposed threshold differs from both Parliament’s preferred age of 16 and the panel’s baseline of 13.
That difference will become a major negotiation point. It also shows why the final age cannot be treated as settled before the Commission publishes its text.
Member states have another reason to support common rules. France, Spain, Greece, Denmark, and other governments have considered different limits, consent models, and verification systems.
A patchwork would force platforms to build country-specific account flows. It could also give children different rights and restrictions depending on which side of an internal EU border they live on.
A shared framework promises consistency. Whether it can deliver consistency without excessive data collection is the much harder question.
The EU KIDS Act Turns Safety Into an Identity Problem
The core tradeoff is not simply access versus safety. It is child protection versus the privacy, security, and usability costs of proving age at scale.
A meaningful minimum age cannot rely on a user selecting a convenient birth year. Platforms need a signal that is difficult for a child to falsify but reveals as little personal information as possible.
The Commission’s preferred answer is a privacy-preserving proof of age. Instead of sending a passport or full birth date to every service, a credential can confirm that someone exceeds a threshold.
The Commission released a technical blueprint in July 2025. It says the solution became feature-ready on April 15, 2026, allowing member states and market participants to customize it.
The system is sometimes called a mini wallet because it uses specifications compatible with future European Digital Identity Wallets. It is intended to answer a narrow question, such as whether a user is over 18.
According to the Commission’s verification blueprint, the tool can be adapted for ranges such as 13 and older. It should not disclose unrelated identity information to the service requesting proof.
That architecture offers a cleaner privacy model than uploading identification directly to each platform. It can separate the authority that establishes age from the service that receives the result.
Yet privacy depends on implementation, not only design documents. Issuers, wallet providers, platforms, operating systems, and verification services all become parts of the trust chain.
A poorly implemented system could expose metadata even if the age credential contains little information. Repeated requests might reveal which services a person uses, when checks occur, or which device presents the credential.
Security also matters because age systems attract valuable records and fraud attempts. Attackers could target credential issuers, compromise devices, trade adult attestations, or manipulate recovery procedures.
The EU says its design uses anonymous proof-of-age technology. Member states are expected to make an interoperable solution available by December 31, 2026.
A Commission recommendation calls for cybersecurity controls, privacy protections, and third-party scrutiny. It also proposes trusted lists for proof-of-age providers and verification solutions.
That framework is more developed than a vague instruction to “check IDs.” Still, the EU KIDS Act would test whether the technology works across millions of accounts, devices, and services with different risk profiles.
Accessibility creates another challenge. Not every user has the same identity documents, device capabilities, digital literacy, or relationship with public authorities.
Parents may also struggle with consent systems shared across households. Separated families, foster care arrangements, guardianship disputes, and children without conventional documentation require careful handling.
False results can harm both sides of the policy. A false adult classification exposes a child to services intended for older users, while a false minor classification blocks a lawful adult.
The scale of those errors matters more than a vendor’s laboratory accuracy claim. Even a small failure rate can affect many people when every new account or game download requires a decision.
Gaming illustrates the practical friction. A store might confirm age before a download, but games can include user-created content, private messaging, randomized purchases, or AI characters added after release.
A single age gate cannot evaluate every feature inside a changing product. Regulators must decide whether verification applies to the store, the game publisher, the platform operator, or all three.
Chatbots pose a similar problem. General-purpose AI systems can shift from homework assistance to emotional conversation without a user entering a separate service.
A rules-based boundary may encourage companies to remove features for younger users. It could also encourage them to create age-specific models, interaction limits, and escalation procedures.
Those changes would make age a product-design input, not merely a compliance field. Companies would need to connect verified age ranges with recommendation systems, messaging permissions, advertising controls, and content access.
The technical mechanism is therefore only the first layer. The harder task is deciding what each verified age should allow.
Platforms Face a New Enforcement Model
The reported proposal would pressure platforms through centralized oversight, compliance costs, and legal responsibility for failed age controls.
Under today’s common model, a company publishes a minimum age in its terms and asks users to state their date of birth. Enforcement often begins only after another signal reveals that an account belongs to a child.
The EU KIDS Act would reportedly reverse that logic. Providers would have to verify eligibility at defined access points instead of waiting for evidence that a user lied.
For social media companies, the account-opening check would affect user acquisition. Every additional verification step can cause abandonment, particularly when users do not understand who receives their information.
Meta, TikTok, Snap, YouTube, and other large services would need to balance compliance with conversion. Smaller platforms would face similar engineering questions with fewer legal and technical resources.
The Commission’s existing DSA guidance excludes micro and small enterprises from its scope. The leaked legislative reporting does not establish whether the same exemption will appear in the EU KIDS Act.
That decision will shape competition. A broad exemption could send younger users toward smaller services with weaker safeguards, while uniform duties could impose disproportionate costs on new entrants.
Video platforms must also determine when viewing becomes account access. Many services allow people to watch public content without logging in, while comments, uploads, recommendations, and subscriptions require accounts.
If the law regulates account creation only, logged-out viewing could remain a large gap. If it regulates access to content, verification prompts could appear across a much wider portion of the web.
Game developers and distributors face a separate compliance chain. Console makers, mobile app stores, PC marketplaces, publishers, and individual games can each control part of the user journey.
Requiring verification before a download places responsibility near the distribution layer. Yet browser games, cloud gaming, sideloading, and cross-platform accounts do not always pass through one gatekeeper.
AI companies would need clarity about what qualifies as a chatbot or companion. Customer-service bots, search assistants, educational tools, role-playing characters, and mental-health applications present different risk profiles.
The Commission’s risk-based tradition suggests that obligations may vary by function and likely harm. The leaked material, however, reportedly describes an expansive category rather than settled exceptions.
Enforcement design will determine whether those distinctions remain meaningful. The DSA currently divides responsibilities between the Commission and national Digital Services Coordinators.
Very large platforms receive direct Commission scrutiny under parts of that framework. National coordinators supervise other providers and cooperate through the European Board for Digital Services.
The reported supervisory fee suggests that Brussels wants dedicated enforcement capacity for the new regime. Fees can reduce reliance on general budgets and place oversight costs on regulated services.
They also raise questions about designation. Lawmakers must decide which providers pay, how charges are calculated, and whether fees reflect revenue, user counts, risk, or enforcement workload.
The EU has already demonstrated that child safety can support direct platform action. In July 2026, the Commission said TikTok had not adequately protected the privacy of minors because some accounts remained too visible.
Commission spokesperson Thomas Regnier said children aged 13 to 15 could easily change private accounts to public settings. The Commission linked that design to risks including unwanted contact, grooming, and cyberbullying.
That case shows how the DSA focuses on product behavior after a young person enters a service. The EU KIDS Act would add an earlier question: whether that person should receive access in the first place.
The two systems could complement each other. Age gates would determine access, while the DSA would still govern safety for minors allowed onto a platform.
However, verification must not become a substitute for safer design. A service does not become harmless because it has correctly identified a 16-year-old.
The European Parliament made that point explicitly. Its resolution said age assurance does not relieve platforms of their responsibility to make products safe and age-appropriate.
That distinction will matter during lobbying. Platforms may prefer clear age checks over open-ended obligations covering interface design, algorithms, and emerging harms.
Regulators will likely resist an either-or approach. The reported proposal points toward both verified access and continuing design responsibilities.
Legal Challenges Could Redraw the Proposal
The strongest challenge is whether a broad age restriction can protect children without disproportionately limiting expression, privacy, and access to information.
France offers the clearest warning. French lawmakers passed an under-15 social media restriction in 2026, backed by President Emmanuel Macron.
On August 14, France’s Constitutional Council struck down the measure. It found that the provisions disproportionately infringed freedom of expression and communication and lacked sufficient legal guarantees.
The decision did not declare child-safety regulation illegitimate. It showed that lawmakers must connect restrictions to precise safeguards, definitions, and proportionality tests.
Macron said he remained determined to pursue a legally durable measure that accounted for both the constitutional decision and the European legal framework.
That French court decision gives the Commission a recent example of how a politically popular ban can fail under rights-based review.
EU legislation must comply with the Charter of Fundamental Rights, data-protection law, and broader principles of necessity and proportionality. Children hold rights to protection, privacy, expression, association, and information.
Those rights can conflict in specific cases. A restriction intended to prevent harmful recommendations might also block access to educational communities, health information, or peer support.
The term “social media plus” could intensify the challenge. A broad category may prevent companies from evading rules through labels, but it also risks treating unlike services as equivalent.
An online game with no messaging does not create the same risks as an anonymous social network. A homework assistant differs from an AI companion designed to sustain an emotional relationship.
Legislators will need criteria based on functionality, exposure, and risk. Without them, providers may struggle to predict whether a feature brings an entire service inside the strictest tier.
Parental consent presents another legal and practical issue. A consent path can preserve family choice, but it may offer little protection if approval becomes a routine button press.
Conversely, requiring strong parental identity checks could collect more family data than the child’s activity justifies. It could also disadvantage children whose guardians cannot use the chosen system.
Circumvention is unavoidable. Some minors will borrow credentials, use adult accounts, change device regions, or move toward services outside effective EU jurisdiction.
That does not automatically make the law ineffective. Most safety rules tolerate some evasion, but policymakers need evidence that compliant behavior produces meaningful benefits.
Measurement should therefore extend beyond the number of completed age checks. Regulators need to examine exposure to harmful content, unwanted contact, compulsive use, spending, migration, and access failures.
The evidence base will be contested. Research links certain patterns of social media use with poorer well-being, but outcomes vary by child, activity, platform design, and social context.
Policy must avoid turning correlation into a universal causal claim. It must also avoid using scientific uncertainty as a reason to ignore documented design and safety failures.
Privacy advocates are likely to focus on scope creep. An infrastructure built for child-safety checks could later support age gates across more content, transactions, or political communication.
The Commission’s formal age framework defines verification as confirming whether a person meets a threshold through electronic identification. It also emphasizes data protection and interoperability.
Those principles are significant, but legislation must turn them into enforceable limits. Users need to know what data can be requested, retained, combined, and audited.
Independent technical scrutiny will be essential. Open specifications can expose design weaknesses, while audits can test whether deployed systems match the privacy promises made on paper.
Appeal mechanisms matter too. Adults incorrectly blocked as minors and families denied valid consent need a fast route to challenge the result without surrendering additional sensitive data.
The EU KIDS Act will therefore face two tests. It must survive political negotiation, and its restrictions must survive legal and technical pressure after adoption.
Three Signals to Watch After Thursday
The proposal’s real significance will depend on its published definitions, its verification architecture, and the legislative response to its age thresholds.
The first signal is the Commission’s official text on September 17. Readers should look beyond the headline age and examine the exact definition of covered services.
The most important questions concern “social media plus.” The text must explain when an AI assistant becomes a companion, when a game becomes a regulated social space, and when video access requires verification.
It should also specify whether checks occur at account creation, installation, individual feature access, or several points. These triggers determine how often users encounter friction.
A narrowly defined framework would weaken claims that the law creates a universal internet identity gate. An expansive definition covering general-purpose services would strengthen those concerns.
The second signal is the technical and governance model for proof of age. Member states are already expected to provide compatible verification solutions by the end of 2026.
The Commission says its approach can prove that a user crosses an age threshold without disclosing other personal information. The EU KIDS Act should clarify whether platforms must accept that method and what alternatives qualify.
Watch for retention limits, restrictions on reuse, independent audits, trusted-provider rules, and remedies for incorrect classifications. These details will determine whether privacy protection is operational or aspirational.
Also watch how the law treats users who cannot access a wallet-based credential. A credible system needs alternatives without making identity documents the default submission for every platform.
Strong data-minimization rules would reinforce the Commission’s claim that safety and privacy can coexist. Broad provider discretion or vague technical standards would weaken it.
The third signal is the gap between the Commission, Parliament, and member states. Parliament previously favored 16 as the common threshold, with parental consent available from 13.
The expert panel emphasized restricted access under 13 until services prove they are safe by design. The leaked EU KIDS Act reportedly centers autonomous accounts at 15 and adds age tiers.
These are not small drafting differences. They reflect competing views about childhood development, parental authority, platform responsibility, and proportionality.
Negotiators must also respond to France’s constitutional setback. Provisions that ignore access to information and freedom of expression could invite similar legal challenges at the EU level.
Industry lobbying will reveal where implementation pressure is greatest. Social networks may focus on account conversion, game companies on distribution responsibility, and AI providers on category definitions.
Children’s-rights groups will likely test whether the proposal combines access controls with safer product design. Privacy organizations will examine whether age checks create new tracking or identification risks.
The EU KIDS Act is therefore not just a proposed social media ban. It is an attempt to make verified age a common input across social platforms, games, video services, and conversational AI.
If the final framework preserves narrow proofs, clear limits, and age-appropriate access, it could become a reference point beyond Europe. If it produces intrusive checks and unclear service categories, it could repeat the weaknesses exposed by national bans.
The immediate question for readers is practical: when the Commission publishes the proposal, does it explain how people can prove only their age, or does safety depend on revealing who they are?



