The European Commission’s KIDS Act does far more than raise the minimum age for a TikTok account. It folds AI companions, video games and operating systems into one regulation, forces every large platform to prove its product is safe before a child touches it, and stakes its credibility on succeeding where Australia’s under-16 ban has struggled to hold.
On 17 September 2026, the European Commission adopted its proposal for the EU KIDS Act, formally the Keeping Internet Digital Spaces Accountable and Trustworthy Act. The headline that travelled fastest was the simplest one: children under 13 cannot hold a social media account, and no one under 15 can open one without a parent controlling it. That framing is accurate but incomplete. The regulation reaches into video games, app stores, operating systems, and — for the first time at EU level — AI companions and conversational chatbots, wrapping all of them into what the Commission internally brands “Social Media+.”
The choice of instrument matters as much as the content. Rather than a directive that member states transpose in their own words, the Commission chose a regulation, directly applicable and uniform once in force, and it bars member states from setting stricter minimum ages of their own. That decision is the thesis of the proposal: Brussels has concluded that a patchwork of national laws, France’s included, was legally unworkable, and that only one harmonised regime can survive contact with the Digital Services Act, the AI Act and the platforms’ lawyers. Whether it can also survive contact with actual teenagers, who have already shown regulators in Paris and Canberra how quickly a determined 14-year-old finds the gap in an age gate, is the question the Act cannot answer alone.
Age bands replace a single blanket ban
The proposal organises minors into four bands, and the obligations attached to each band are where the real engineering sits. Under three, a child is barred from social media and other high-risk services outright. From three to under 13, access is limited to video-sharing services specifically designed for that age group, reachable only through a guardian’s own account, with personalisation, recommenders and content search turned off unless a published impact assessment justifies otherwise, an hour-a-day cap, and nothing at all offered below age three. From 13 to under 15, autonomous accounts are prohibited; a provider may — not must — offer a guardian-created limited account, and if it does, guardian tools must stay active, with a daily cap of no more than an hour, pre-approval required for new contacts, and a ceiling on how many contacts the account can hold at all. Those accounts legally belong to the guardian, not the child. From 15 to under 18, teenagers can open their own account without parental sign-off, but the safety-by-design obligations continue to apply by default, and providers may depart from the child-protective experience only once they have established the user is an adult.
The KIDS Act reverses the legal default that has governed platform design since the DSA: providers must now demonstrate their products are age-appropriate and safe by design, rather than regulators having to prove harm after the fact. Commission President Ursula von der Leyen framed it plainly: “Our KIDS Act is reversing the burden of proof — it is for platforms to show they are safe by design.” Self-declaration of age is explicitly ruled out as insufficient; platforms must use a certified age-verification solution, most likely built on the Commission’s own open-source EU Age Verification Solution due for release by the end of 2026, or an equivalent certified national tool delivering a privacy-preserving proof-of-age attestation rather than a copy of an identity document. For the 13-to-14 band specifically, the provider must separately verify both the child’s age and that the adult opening the account genuinely holds parental responsibility for that particular child — an adult may self-declare the relationship initially, but the provider must make reasonable efforts to confirm it rather than accepting the claim at face value.
The rules are not limited to future sign-ups. Within six months of the regulation applying, providers must determine whether existing account holders are under 15, and where a user is under 15 or their age cannot be established, the account must be disabled unless it qualifies for a compliant guardian-controlled route into the 13-to-14 tier. An exception applies where a provider can show, with a high degree of confidence, that the account holder has already reached the applicable minimum age through other signals, such as how long the account has been active.
Social Media+ reaches well beyond the feed
The scope is the part of the proposal that separates it from the national laws it supersedes. France’s Digital Majority Law of July 2023 and its since-strengthened under-15 ban, along with comparable measures debated or adopted in Italy, Greece, Austria, Poland, Belgium and Denmark, targeted social networking services narrowly, using a definition borrowed from the Digital Markets Act. The KIDS Act instead defines “Social Media+” as social networks, video-sharing platforms, online games, app stores, operating systems, AI companions and general conversational chatbots. Account-creation restrictions apply specifically to services with features such as livestreaming, contact with strangers, profiling-based recommendations, uninterrupted consumption, or attention-recapturing notifications — which is why games, chatbots, app stores and operating systems are not swept into the under-15 account ban itself.
What they are swept into is something broader: a default requirement for safety-by-design principles across the entire category, applied even to unregistered or logged-out users, and lifted only once a provider has established that the person in front of the product is an adult. That default-on architecture, not the account-age threshold, is the mechanism through which the regulation reaches a video game studio or a chatbot developer that has never previously had to think of itself as a social media platform at all. For games specifically, the proposal goes beyond addictive-design prohibitions to require safeguards against enticements to move a conversation off-platform, a provision aimed at grooming pathways that begin inside a game’s chat function and migrate to less-monitored messaging apps. Appearance-altering filters, virtual currencies and variable-reward mechanisms — the design vocabulary of loot boxes and cosmetic microtransactions — are named individually rather than folded into a generic addictive-design clause.
The territorial reach mirrors the Digital Services Act’s own logic: the regulation applies to any in-scope service offered to users in the EU regardless of where the provider is incorporated, and narrow carve-outs exist only for services designed and operated for education or by public authorities, and for AI systems intended purely for office or industrial use. A chatbot built for enterprise document review is out of scope; the same underlying model, repackaged as a general-purpose assistant a teenager might turn to for company, is not.
The economics of reversing the burden of proof
Reversing the burden of proof is not a rhetorical flourish; it restructures who pays for compliance evidence and when. Very large online platforms, the category the Digital Services Act already uses to flag systemic risk, must submit compliance plans to the Commission and route any new product feature that could affect children through an independent audit, paid for by the provider, before it ships. The Commission can then issue corrective measures directly from the auditor’s findings, and investigations opened under the Act are meant to conclude within 90 days — a fast-track timeline that is itself an acknowledgment of how slowly ordinary DSA enforcement has moved against Meta and TikTok since 2024.
The cost of proving safety falls on the provider, not the regulator, and it falls before launch rather than after a scandal. A supervisory fee, capped at 0.03 percent of a company’s worldwide annual net income, is proposed to fund the Commission’s direct oversight of this regime, layered on top of DSA supervisory fees platforms already pay. Penalties for confirmed violations can reach 6 percent of global annual revenue — the same ceiling the Commission has already threatened Meta with in its ongoing Digital Services Act investigation into addictive design on Facebook and Instagram, a case that gives the KIDS Act’s fine structure a documented, live precedent rather than a hypothetical one.
That precedent matters because the KIDS Act does not create a single stand-alone penalty regime. It creates new statutory duties and plugs most of them into enforcement machinery that already exists: the Digital Services Act for very large platforms, the Audiovisual Media Services Directive for video-sharing services, the AI Act for chatbots and companions that qualify as AI systems, and GDPR for the underlying data processing. One seam is left deliberately open. GDPR’s Article 8 and the national digital-consent ages member states set under it remain untouched by the KIDS Act, so a 15-year-old could hold a fully autonomous social media account under the new regulation while still being legally unable to consent to certain kinds of data processing on that same account — a gap platforms will most likely route around by avoiding consent-based legal bases for minors’ data in the first place, as many already do.
AI companions enter statutory child-protection law for the first time
The inclusion of AI companions and conversational chatbots was not part of the Commission’s original framing when the expert panel convened by von der Leyen reported in July 2026; it was added after Spain and the Netherlands explicitly pushed for it in the fortnight before publication, according to the leaked draft that circulated on 15 September. The final proposal describes these products as “virtual tools that can give mental health and personal development advice to minors,” and the safety-by-design defaults that apply to social networks and games — covering addictive reward mechanisms, persistent memory and how a product is presented to a young user — extend to AI companions and general chatbots as well, by the same default-on, adult-verified-opt-out logic that governs the rest of the regulation.
This is the provision with the least regulatory precedent behind it. Where age-appropriate design codes for social feeds and video platforms already exist under the DSA’s Article 28 guidelines and the Audiovisual Media Services Directive, there is no comparable EU body of law for conversational AI aimed at children discussing emotional dependency, grief, or self-harm. The Act treats emotional attachment to a chatbot as a design risk on the same footing as an infinite scroll feed — a genuinely novel legal move, and one that will be tested first against products, such as general-purpose assistants used informally as companions, that were never built with a child user in mind.
The political pressure that forced Brussels’ hand
The KIDS Act did not emerge from a routine legislative cycle; it emerged from a year of national governments moving faster than the Commission and of the Commission’s own enforcement record looking thin by comparison. In July 2026, the Commission’s preliminary findings against Meta concluded the company had failed to adequately assess the risks of infinite scrolling, autoplay and personalised recommendations for children — a finding Meta publicly disputed while saying it would engage “constructively.” A month later, when Meta agreed to pay up to 16.7 billion dollars to a coalition of US states and accept sweeping new teen-safety limits, including an automatic nighttime block and a two-hour daily cap across its apps, 52 members of the European Parliament wrote directly to von der Leyen arguing that American courts had moved faster than Brussels and that “European children are worth no less than American ones.” The Commission’s own spokesperson conceded the point publicly, telling reporters “the ball is in Meta’s court” and that Brussels expected “at least equally good protection for our kids here in the European Union.”
That pressure converged with a parallel problem: national laws were multiplying faster than the Commission could reconcile them with EU law. France’s Conseil d’État had already forced the National Assembly to rewrite its under-15 bill once, and a special expert panel convened by von der Leyen delivered recommendations in July 2026 that fed directly into the September proposal. Nine EU governments — France, Greece, Austria, Denmark, Spain, Belgium, Italy, Germany, Poland and the Netherlands — were by then considering or actively advancing national legislation, and it was Spain and the Netherlands’ late request to fold in AI companions that pushed the proposal’s scope past what earlier drafts had anticipated. The KIDS Act reads less like a single considered policy and more like Brussels absorbing nine simultaneous national experiments into one regulation before any of them could diverge further, which explains both its unusual breadth and the speed — barely ten weeks from the expert panel’s report to a full legislative text — with which it was assembled.
Who absorbs the compliance cost, and who reuses work already done
The commercial impact splits along a line that has nothing to do with how risky a service actually is to children and everything to do with which EU rulebook a company was already complying with. Platforms already implementing the DSA’s Article 28 minors guidelines, and already subject to the very large online platform designation, can fold much of that existing work — addictive-design mitigation, recommender-system adjustments, contact controls — directly into KIDS Act compliance. Meta and TikTok, both already under open DSA investigations for exactly these features, are the clearest examples of firms with a head start, however reluctantly earned.
Video game studios and chatbot developers face a steeper climb. Most do not currently qualify as “online platforms” under the DSA and have built no equivalent compliance infrastructure — no auditor relationships, no age-assurance integration, no documented safety-by-design review process. For this second group, the KIDS Act is not an incremental update to an existing obligation; it is a first-time regulatory relationship with Brussels, arriving with a 90-day fast-track enforcement clock attached from the outset. Operating systems and app stores occupy a middle position: Apple and Google already run age-rating and parental-control infrastructure for other purposes, but the Act’s requirement that compliant age signals be shareable, with consent, across apps and services is a new plumbing job even for them.
The counterevidence: what Australia and France already learned
The strongest argument against the KIDS Act’s design is that two of its closest real-world analogues have already run into the same wall. Australia’s under-16 social media ban, in force since December 2025, produced an early fall in the share of children holding accounts — from 52.4 percent to 42.1 percent in its first three months, according to the eSafety Commissioner’s tracking study — but a peer-reviewed survey of 408 adolescents published in The BMJ found that more than 85 percent of under-16 participants were still using social media three months after the ban began, mostly through their own existing accounts rather than a parent’s. Age-verification checks, where they occurred at all, were commonly a self-declared birth date or a selfie, not the certified attestation the KIDS Act proposes to require.
France offers the opposite lesson, about legal fragility rather than behavioural evasion. Its Digital Majority Law and the subsequent under-15 bill were repeatedly found by the European Commission and by the Conseil d’État to conflict with the Digital Services Act’s ban on member states imposing platform obligations beyond what EU law already sets, and with proportionality requirements protecting minors’ own digital rights. France’s difficulty is precisely the gap the KIDS Act is built to close — a single EU regulation cannot be challenged for exceeding what a national law was allowed to do, because it sets the ceiling itself. What neither France’s legal victory nor Australia’s early enforcement struggle answers is whether certified, EU-wide age assurance will actually stop the account-switching, VPN use and alternative-app migration that Australian teenagers demonstrated within weeks of that country’s ban taking effect.
Compliance choices facing platforms, parents and developers now
For very large platforms already inside the DSA’s systemic-risk category, the practical task starts immediately: map every product feature named in the KIDS Act’s prohibited list — infinite scrolling, profiling-based recommender feeds, personalised advertising to minors, overnight push notifications, unsolicited contact from strangers — against current settings, and prepare the compliance-plan documentation the Commission will expect once the regulation applies, since a live DSA investigation already shows what an under-resourced response costs. For game studios and chatbot developers newly inside scope, the decision is more foundational: whether to build age-assurance and safety-by-design review capacity in-house, on a timeline still to be fixed by the Parliament and Council negotiations, or to wait for co-regulatory industry codes that the proposal explicitly leaves room for in these newer categories.
Parents gain concrete levers under the proposal — daily time caps, contact pre-approval, guardian-controlled mini-accounts — but the Australian evidence suggests these tools only bind if enforcement is resourced to catch account-switching and cross-border access, not merely to certify a sign-up flow. The consumer-facing promise of “parents back in the driving seat” depends on enforcement capacity that the proposal funds through a fee capped at a fraction of a percent of platform revenue, a sum whose adequacy against companies posting tens of billions in annual turnover has not yet been tested.
A conditional judgment on a regulation still years from force
Nothing in the KIDS Act is law yet. The proposal now enters the European Parliament and the Council of the EU for negotiation, and legal analysts following the file already flag the pivotal age threshold — 13, 15 or 16 — and the exact boundary of “Social Media+” as the two fights most likely to reshape the final text. Given the pace of comparable EU digital files, adoption before 2028 is considered unlikely by specialists tracking the process, which means the version that eventually applies could diverge meaningfully from what the Commission published in September 2026.
What will not change, regardless of how the age bands are redrawn, is the structural bet the Act represents: that a single, directly applicable regulation covering identity verification, advertising, recommendation systems, interface design and conversational AI can succeed where a dozen national laws and one high-profile Pacific experiment have each partly failed. The evidence available now argues for cautious optimism about the legal architecture and real scepticism about behavioural compliance — Australia shows that certified age assurance changes account-holding rates only modestly against motivated teenagers, and France shows that a fragmented approach cannot survive EU law at all. The Act that emerges from Parliament and Council negotiation will be judged less on its stated age limits than on whether its enforcement fee and 90-day investigation clock can actually compel a platform with the resources of Meta or TikTok to change a recommender system before the next generation of users has already found the workaround.
Questions readers are asking about the EU Kids Act
The EU KIDS Act, formally the Keeping Internet Digital Spaces Accountable and Trustworthy Act, is a European Commission regulation proposed on 17 September 2026 to restrict minors’ access to social media, video-sharing platforms, online games, app stores, operating systems, and AI companions and chatbots, while imposing child-specific safety-by-design requirements across those services.
Fifteen. Children under 13 cannot hold a social media account at all, except for guardian-managed access to video-sharing services designed for that age group. Those aged 13 and 14 can use a limited account created and controlled by a parent or guardian, with a daily time cap of no more than one hour and pre-approval required for new contacts.
Yes. The proposal extends default safety-by-design obligations — addressing emotional dependency, persistent memory, and how a product presents itself to minors — to AI companions and general conversational chatbots, alongside social networks, video-sharing platforms and online games. This is the first time EU law has addressed conversational AI specifically as a child-safety category.
France’s Digital Majority Law and subsequent under-15 bill applied only to social networking services and were repeatedly found by the European Commission and the Conseil d’État to conflict with the Digital Services Act and proportionality requirements. The KIDS Act is a directly applicable EU regulation that bars member states from setting stricter national age limits, closing the legal gap that made France’s approach vulnerable to challenge.
Confirmed violations can bring fines of up to 6 percent of a company’s global annual revenue, the same ceiling the Commission has already invoked in its ongoing Digital Services Act investigation into Meta’s Facebook and Instagram. Investigations under the KIDS Act are meant to be fast-tracked and concluded within 90 days.
Very large online platforms must submit compliance plans to the Commission and have new products or features that could affect children reviewed by an independent auditor at the provider’s own expense, before those features can be deployed to minors.
Self-declaration is explicitly insufficient. Providers must use a certified age-verification solution, most likely built around the Commission’s open-source EU Age Verification Solution, expected to be released by the end of 2026, or another certified national equivalent, delivering a privacy-preserving proof-of-age attestation rather than raw identity documents.
It applies to both. Within six months of the regulation taking effect, providers must establish whether existing account holders are under 15; if a user is under 15, or their age cannot be established, the account must be disabled unless it qualifies for a compliant guardian-controlled route.
Only partially. Australia’s under-16 social media ban, in force since December 2025, cut the share of under-16s with accounts from 52.4 percent to 42.1 percent in its first three months, but a University of Newcastle study published in The BMJ found more than 85 percent of under-16 participants were still using social media three months after the ban began, mainly through their own existing accounts.
Not soon. The proposal must now be negotiated between the European Parliament and the Council of the EU, with the exact minimum age and the precise scope of “Social Media+” among the most contested points. Specialists following the file consider adoption before 2028 unlikely, meaning the final regulation could differ substantially from the September 2026 proposal.
Author:
Jan Bielik
CEO & Founder of Webiano Digital & Marketing Agency

This article is an original analysis supported by the sources cited below
EU KIDS Act to restrict social media platforms’ access to children in the EU
The European Commission’s official 17 September 2026 press release announcing adoption of the proposal, including the burden-of-proof reversal and the von der Leyen quote on safety by design.
Proposal for EU KIDS Act – ‘EU Keeping Internet Digital Spaces Accountable and Trustworthy’
The Commission’s library page hosting the proposal and supporting documents, establishing the regulation’s stated objectives around minors, the digital single market and enforcement coherence.
EU KIDS Act: helping children navigate a safer online world
The Commission’s explanatory publication detailing the age-band structure, including the under-13 video-sharing exception and the hour-a-day access limits.
The EU KIDS Act has landed
Reed Smith’s 18 September 2026 legal analysis, the most detailed public breakdown of the age bands, AI companion provisions, age-assurance architecture, supervisory fee and DSA/AVMSD/GDPR overlap.
European Commission unveils EU KIDS Act
IAPP’s coverage confirming the 6 percent global revenue fine ceiling, the 90-day fast-track investigation timeline, the EU Age Verification Solution, and reaction from CCIA Europe and the European Consumer Organisation.
‘Enough is enough’: EU moves toward restricting social media access for under-15s
Euronews’ report on the leaked draft two days before publication, establishing the late addition of AI companions and games to scope at Spain and the Netherlands’ request, and the “risky settings disabled by default” language.
EU Kids Act – Wikipedia
Background reference summarising the proposal’s core age thresholds and citing the Reuters report on the Commission’s pre-publication announcement.
EU Kids Act: the EU Commission takes the lead on the protection of minors online
Legal analysis noting the national laws preceding the EU proposal, the divergence between member states on the pivotal age, and the assessment that adoption before 2028 is unlikely.
French digital majority law compels social network service providers to move beyond age gating into age verification
Baker McKenzie’s analysis of France’s 7 July 2023 Digital Majority Law, its definition of social networking services and its age-verification obligations.
What France’s under-15 social media ban means for Europe
Tech Policy Press’s account of the Conseil d’État’s proportionality objections to France’s bill and the legislative rewrite forced by conflict with the Digital Services Act.
EU Commission objects to French under-15 social media bill
MLex’s report confirming the European Commission’s formal opinion that amendments to the French bill were incompatible with EU law.
French lawmakers race to introduce an under-15 social media ban before the new school year
Associated Press coverage of the French legislative negotiations and the Commission’s compatibility findings ahead of the bill’s passage.
France Becomes First in the EU to Ban Social Media for Children Under 15
Wire report confirming passage of the French law by both parliamentary chambers on 23 July 2026, with comparison to Australia’s earlier ban.
Social media use among Australian under-16s falling since ban implemented
Xinhua wire coverage of the eSafety Commissioner’s first tracking data showing the fall in under-16 account-holding from 52.4 to 42.1 percent.
Australia moves to strengthen under-16 social media ban amid evidence of enforcement concerns
Jurist’s report on the University of Newcastle study published in The BMJ finding more than 85 percent of under-16 participants still using social media three months after Australia’s ban began.
After US settlement, EU says Meta must ‘protect our kids too’
Coverage of the European Commission’s response to Meta’s US state settlement, confirming the DSA investigation into Meta and the existing 6 percent global turnover fine threshold.
EU lawmakers demand Brussels force Meta to protect European children
AFP report on the cross-party letter from 52 MEPs pressing the Commission to act on Meta’s addictive design findings, part of the political pressure preceding the KIDS Act.
| Citing this article? Brief excerpts are welcome. Please credit Webiano.digital, name the author where stated, and include a link to https://webiano.digital and to this original article. Full or substantial republication requires prior written permission. Read our Copyright and Content Use Policy. |
This article was prepared with the assistance of artificial intelligence tools. The content underwent expert human review, and Webiano Digital & Marketing Agency assumes editorial responsibility for its final version and publication.















