On 17 September 2026, the European Commission (Commission) published its proposal for the EU KIDS Act – Keeping Internet Digital Spaces Accountable and Trustworthy (KIDS Act).
The proposal follows a summer marked by significant momentum in the child online safety space, which we explored in our earlier article on emerging child online safety developments in the EU and beyond (see [here]). If adopted, the KIDS Act would establish one of the most prescriptive child-safety frameworks yet proposed at EU level, carrying far-reaching implications for the design, operation, and governance of digital services available to, or accessible by, minors (i.e. anyone under 18 years of age).
The KIDS Act represents an effort to harmonise child-safety standards across the EU, seeking to stem an emerging fragmented landscape in which individual Member States have already begun to pursue divergent social media age restrictions and bans. The proposal responds to significant political momentum. This includes the Jutland Declaration (signed by 25 Member States in October 2025, calling for age verification and a safer online environment) and the European Parliament’s November 2025 resolution calling for a harmonised digital age limit.
The proposal also draws on the work of the Commission’s Special Panel on Child Safety Online (Panel), whose July 2026 report introduced the “Social Media+” concept. That concept signals a broad regulatory perimeter. The Panel recommended extending child-safety measures beyond conventional social media to other digital services, including online games, AI companions and app stores. For providers operating across multiple markets, a harmonised EU-wide framework with this expanded scope would offer greater regulatory certainty and simplify planning for consistent pan-EU compliance measures.
This article explains who is in scope of the KIDS Act, what the principal obligations could mean in practice, how the proposal interacts with existing EU rules, and what providers can do now in anticipation of being in-scope of this new legal framework. If adopted as a regulation (as it is currently proposed), the substantive rules of the KIDS Act would apply across Member States without national transposition.
Structure of the Proposed Legislation
The KIDS Act contains 43 articles across nine chapters. The commercially significant obligations are built around four pillars:
- Chapter II contains the access delay obligations;
- Chapter III contains safety-by-design requirements, which are the rules that will drive the largest product changes;
- Chapter V creates the age assurance framework that forms the basis of pillars 1 and 2; and
- Chapter VII sets out the enforcement architecture, including the expedited procedure and fines of up to 6% of worldwide annual turnover.
The remaining chapters address general provisions, parental responsibility verification, national support strategies, and delegated powers.
Who is in Scope?
The proposal would apply to any provider whose service or system is accessible to minors and falls within one of the following seven categories:
- online social networking services;
- video-sharing platform services;
- software application stores;
- online games;
- operating systems;
- AI companions; and
- general conversational chatbots.
There are certain categories currently excluded from the scope of the proposal, namely: not-for-profit online encyclopaedias; not-for-profit educational and scientific repositories; services operated purely for educational purposes within schools; open-source software development platforms; scientific research services; and services developed by and for public authorities.
The proposal does not provide an exemption for small or micro enterprises. The Commission’s stated rationale for this position is that harm to minors does not depend on the provider’s size.
Pillar One: The Social Media Delay
The centrepiece of the proposal is the graduated, age-based access model for social media and video-sharing platforms. It can be summarised as follows:
- Children under 13 would not be able to access social networking services or video-sharing platforms through their own accounts. However, where a video-sharing platform is specifically designed for minors under 13, the provider may allow a guardian to give the child limited access through the guardian’s own account. Access would need to be controlled through guardian tools, limited to a maximum of one hour per day, and would not be available to children under 3.
- For children between the ages of 13 and 15, guardians would be able to create what the Commission describes as “mini accounts”. These would be accounts with limited features created on behalf of the minor, with guardian tools activated by default. Guardians would again be able to set a daily time limit of up to one hour, pre-approve contacts and set a maximum number of contacts on the account.
- From age 15, a minor would be able to create an autonomous account. The safety-by-design obligations in Chapter III would still apply, but parental approval would not be required.
If adopted, in-scope services and platforms will have six months to determine whether they have any account holders under the age of 15. Where existing account holders are under 15, their accounts will need to be shut down or disabled. These measures will also be necessary where the age of a user or account holder cannot be established. Self-declared age-assurance measures will not satisfy the KIDS Act’s requirements.
Pillar Two: Safety by Design
Chapter III of the proposal seeks to govern platform design, rather than content, making child safety a legally binding product requirement. Article 8 of the proposal seeks to impose a general obligation on all in-scope providers to ensure that a high level of privacy, safety, and security for minors is built in by design. The detailed rules would differ by service type. The most prescriptive rules would apply to social networking and video-sharing providers, covering the following five areas:
- Addictive design
Providers would not be permitted to design their services to encourage compulsive or excessive use by minors. Uninterrupted content consumption without effective breaks, notifications unrelated to the minor’s own activity, rewards for sharing content to large audiences, and features penalising minors for not returning regularly would all be caught. Streak mechanics and daily login rewards would fall within these prohibitions too, while time-management tools would need to protect core sleep hours and school time.
- Recommender systems
Next is the proposed requirement that providers would be obliged to optimise safety and mental health, rather than user engagement. The proposal provides that profiling-based recommendations must be switched off by default, and that personal data relating to individuals that is inferred or obtained from outside the service cannot be used to feed recommendations to minors. Minors would also need to be able to control and reset their recommendations.
- Safe settings
The proposal further provides that geolocation, camera, microphone, account recommendations, contact synchronisation and push notifications must all be switched off by default. These default settings can be changed only where the minor is at least 15 years of age and has given explicit consent. Location settings will also need to be turned off after each session, and features that distort a minor’s image or increase social comparison will be entirely inaccessible.
- Contact and Interaction safeguards
Other users cannot initiate contact unless the minor has pre-approved it, and adding a minor to a group would require the minor’s explicit agreement. Minors must also be able to block other users easily and anonymously. Livestreaming must also be off by default, while personal contact details cannot be shared.
- Safety and security of economic transactions
Minors would need to be told clearly and in real time before any purchase is made. Virtual currency would need to display its monetary value in the relevant official currency, and variable reward systems, including loot boxes, would be prohibited.
The KIDS Act seeks to introduce two new definitions into EU law: “AI companions” and “general conversational chatbots”. Article 14 of the proposal seeks to prohibit features that simulate relationships likely to create emotional dependencies vis-à-vis AI companions and/or general conversational chatbots. Persistent conversational memory must be off by default. Pursuant to the proposal, pre-launch testing would be mandatory and post-market monitoring would be required, although micro and small enterprises would be exempt from the monitoring obligation. Where deployed within a social networking service, a video-sharing platform or an online game, an AI feature would not be permitted to activate automatically or be promoted to minors, and minors would need to be able to opt out at any time. Online games and app stores would also each have dedicated obligations under the KIDS Act.
Pillar Three: Age Assurance
For new accounts on social media and video-sharing platforms, the proposal seeks to require providers to use an EU age-verification solution relying on an EU proof-of-age attestation certified under the EU Age Verification Scheme. No other age-verification methods will satisfy the proposed age-based access-delay obligations (e.g. self-declaration or age estimation will not be permitted).
For the safety-by-design obligations in Chapter III, providers may use alternative age-assurance solutions, but only where they can demonstrate that those solutions meet the standards of accuracy, reliability, privacy and non-discrimination set out in Articles 27 and 28 of the KIDS Act.
The proposal requires age assurance using zero-knowledge proof to confirm only whether a user meets a given age threshold, without disclosing identity, exact age or other personal data. Any such framework would also need to comply with the EDPB Statement 1/2025 on Age Assurance, adopted on 11 February 2025, which sets out high-level data protection principles for the processing of personal data in age-assurance systems under the GDPR.
Article 32 of the proposal makes clear that it would not require blanket retrospective verification. Providers could rely on a derogation to establish, with a high degree of confidence, that the user had reached the minimum age, with formal verification required only where that confidence could not be established.
The KIDS Act seeks to require each Member State to make available at least one free means of proving age, including for people without a digital ID. Ireland has already been active in this area. The Data Protection Commission (DPC) published its Fundamentals for a Child-Oriented Approach to Data Processing guidance in 2021, and in October 2025 Coimisiún na Meán (the Media Commission) and the DPC signed a cooperation agreement and issued a joint statement committing to advance the safety of children and the protection of their personal data online. Ireland is also building towards a digital identity wallet, which we wrote about in our earlier article on Ireland’s digital age-assurance plans [here].
Answering a parliamentary question on 28 July 2026, the Minister for Culture, Communications and Sport, Patrick O’Donovan, confirmed that, in line with the National Digital and AI Strategy, his Department is working with the Office of the Government Chief Information Officer to deliver an age-verification tool within the Government Digital Wallet. The tool will operate on a zero-knowledge basis, confirming only whether a user is over 18, with no other information, including date of birth, disclosed to the platform or retained.
Pillar Four: Enforcement
The KIDS Act would reverse the burden of proof, such that providers would need to demonstrate compliance rather than regulators needing to prove harm first.
Providers of online social networking services and video-sharing platform services designated as very large online platforms (VLOPs) under the Digital Services Act (DSA), meaning those with at least 45 million monthly active EU users, would need to notify the Commission of a compliance plan describing how they would comply with the obligations in Chapters II to V of the KIDS Act. An independent auditor, paid by the provider, would be required to assess each plan.
The Commission would retain direct supervisory authority over VLOPs. Under Article 35, the Commission would be required to endeavour to communicate preliminary findings within 30 working days and adopt a final decision within 90 working days. Fines could reach 6% of total worldwide annual turnover.
For online platforms, video gaming platforms and app stores that are not VLOPs, enforcement would follow the existing DSA structures through national Digital Services Coordinators, with Coimisiún na Meán serving as the coordinator in Ireland. For video games that are not online platforms, the competent authority of the Member State where the provider is established would have exclusive supervisory power. For AI companions and chatbots, enforcement would follow the framework under the EU AI Act. Data protection authorities will retain full competence over personal data processing under the KIDS Act.
Interaction With Existing EU Frameworks
Providers within the scope of the KIDS Act may already be building compliance programmes for other EU digital regulations. The proposed framework is designed to complement, not replace, these existing obligations, but it will add to them.
The KIDS Act would sit alongside the DSA’s Article 28 duty to ensure high levels of safety for minors, codifying much of the Commission’s October 2025 Guidelines on child safety measures under Article 28(4) of the DSA (which we explored in our earlier article on the DSA Guidelines, [here]). It would also layer child-specific requirements onto the AI Act while avoiding duplication, and would apply without prejudice to the GDPR. The Commission has further signalled the forthcoming Digital Fairness Act and a revision of the Audiovisual Media Services Directive as complementary instruments that strengthen protections for minors.
For providers, this layering entails managing overlapping obligations across multiple frameworks. Rather than treating each instrument in isolation, providers should map their requirements against the KIDS Act, DSA, AI Act, and GDPR to identify overlaps and build an integrated compliance programme.
Timelines and Next Steps
The KIDS Act is a Commission proposal that will now proceed through the ordinary legislative procedure, requiring consideration and adoption by both the European Parliament and the Council. Its text may be amended during that process, and the adoption timeline will depend on the pace of negotiations between the co-legislators.
If adopted, the KIDS Act would enter into force 20 days after publication in the Official Journal and apply six months later. The compliance-plan obligation for designated VLOPs would take effect on entry into force, with those already designated required to notify within 30 days of the application date. By six months after application, platforms would need to have checked existing accounts against the minimum-age requirements. Under Articles 33 and 35 of the KIDS Act, national support strategies and the expedited enforcement regime would take effect 12 months after entry into force, and a formal review would be scheduled for 31 August 2030.
What Should Providers Do Now?
The KIDS Act is still a proposal, but the political appetite for action on online child safety is undeniably strong, and we anticipate it will remain on the legislative agenda. Providers should start preparing now to make informed product, budget and governance decisions before the final requirements are known. We recommend that providers take the following actions:
- Assess your scope and regulatory exposure: Providers should assess whether their service falls within the “Social Media+” perimeter and, if so, which chapters, and thus which obligations of the KIDS Act would apply. Then, conduct a gap analysis against the proposed safety-by-design requirements, using work already undertaken for the Commission’s DSA Guidelines on the protection of minors as a baseline. Starting this exercise early will help identify likely product changes, allocate budget for compliance costs, and reduce the risk of costly last-minute redesigns.
- Prepare for age assurance and review product design: Providers should evaluate EU age-verification solutions under the EU Age Verification Scheme and assess which existing data could establish age with the required degree of confidence. Providers should also audit recommender algorithms, notification policies and engagement features against the KIDS Act’s proposed prohibitions. Early testing would help expose technical and operational issues while there is still time to address them.
- Engage with the legislative process and plan for implementation: Providers may wish to work through industry associations and respond to consultations during negotiations to advocate for workable standards. We recommend that those within the scope of the KIDS Act monitor developments closely, as age thresholds, exemptions and implementing acts, including those on age verification, may evolve before adoption. Internal planning should begin now so providers are not forced into expensive, reactive compliance once the regulation is finalised.
William Fry’s Technology team continue to closely monitor developments in this space. If you would like to find out more about what these developments mean for your organisation, please contact Laura Casey, Rachel Hayes, or your usual William Fry contact to discuss.
Contributed by Anny Svinti.


