Blog

The Commission proposes the “EU KIDS ACT”: a minimum age of 15 for creating social media accounts and new safety-by-design obligations for services accessible to minors
I. INTRODUCTION
On 17 September 2026, the European Commission presented Proposal COM (2026) 681 final for a Regulation of the European Parliament and of the Council (2026/0286(COD)), known as the “EU KIDS ACT” (EU Keeping Internet Digital Spaces Accountable and Trustworthy), which lays down harmonised rules for the protection of minors online.
The proposal sets a harmonised minimum age of 15 for creating an account on certain social networking and video-sharing services. It also imposes safety-by-design requirements on a range of services much broader than social media, including AI companions, general conversational chatbots, online games and software application stores, and it regulates age assurance systems. It builds on Regulation (EU) 2022/2065 (Digital Services Act, “DSA”) and Regulation (EU) 2024/1689 (AI Act), without prejudice to either.
The proposal is not yet binding. It is a legislative proposal that must still go through the ordinary legislative procedure, and its content may change significantly along the way.
II. THE BACKGROUND TO THE PROPOSAL
The proposal follows the recommendations of the Special Panel on Child Safety Online, whose co-chairs presented their report to the President of the Commission in July 2026. It also reflects calls made by the European Council and the European Parliament, as well as the Jutland Declaration of October 2025.
The other driver is regulatory fragmentation. The explanatory memorandum notes that Italy, France, Norway, Greece, Austria, Poland and Belgium have notified draft national legislation restricting minors’ access to certain digital services, with age thresholds ranging from 13 to 16. The Commission considers that this divergence threatens the Single Market, reduces legal certainty and increases compliance costs. It therefore relies on Article 114 TFEU as the legal basis and opts for a regulation as the legal instrument.
III.SCOPE AND DELAYED ACCESS TO SOCIAL MEDIA
The proposal applies to providers of online social networking services, video-sharing platform services, software application stores, online games, operating systems, AI companions and general conversational chatbots. It has extraterritorial reach, since it applies irrespective of where the provider is established, and it does not exempt small and micro enterprises. It does exclude, among others, not-for-profit online encyclopaedias, services designed for educational purposes and services developed solely for scientific research.
Article 6 prohibits providers of social networking and video-sharing services from allowing persons under 15 to create an account, or to access the service through one, where the service poses a risk to the privacy, safety or security of minors below that age. The proposal considers that risk to exist where the service has certain features, such as live streaming to an indeterminate number of recipients, the possibility of interacting with users outside the user’s existing connections, recommender systems based on profiling, or designs that encourage uninterrupted consumption.
The proposal provides for two exceptions. First, gatekeepers may set up accounts with limited features for minors aged 13 and 14. In those accounts the guardian tools must always be activated, daily use may not exceed one hour, and guardians must be able to pre-approve new contacts. Second, minors under 13 may exceptionally be given limited access through the guardian’s own account on video-sharing platforms specifically designed for that age group, subject to a published impact assessment (Article 7).
Within six months of the Regulation becoming applicable, providers must establish whether the holders of existing accounts are under 15. They must disable the accounts of those identified as minors below that age, as well as those whose age cannot be established (Article 6(4)).
IV. SAFETY BY DESIGN
Chapter III turns into binding law much of what is currently contained in the Commission’s Guidelines on the protection of minors adopted under Article 28 DSA. Social networking and video-sharing services may not be designed to encourage compulsive or excessive use by minors and must offer time-management tools that protect core sleep hours and school time. Their recommender systems must be designed to ensure a high level of privacy, safety and security for minors, default settings must be set to a high level of protection and contact with strangers must be limited. Economic transactions must be transparent, and variable reward systems may not be used with minors.
AI companions and general conversational chatbots must avoid features likely to create emotional dependency, prevent harmful interactions, and carry out testing and post-market monitoring. Online games must prevent their services from being used to entice minors to initiate contact on other services that pose a risk to them. Software application stores must
put in place an age-rating system and may not allow minors to access applications that are not age-appropriate.
The proposal also requires child-friendly reporting mechanisms and effective tools for guardians, and it recognises the right of minors and guardians to lodge complaints with the competent authority and to mandate a body, organisation or association to exercise those rights on their behalf (Article 21). Providers of social networking and video-sharing services designated as very large online platforms must notify a compliance plan to the Commission and have it audited independently (Article 5).
V. AGE ASSURANCE AND ENFORCEMENT
Chapters IV and V require age assurance systems to be accurate, reliable, robust, non-intrusive and respectful of privacy and non-discrimination. Self-declaration is not sufficient (Article 27). To implement the delayed access, providers must rely on age verification solutions. Member States must ensure that at least one EU age verification solution is available free of charge, together with an electronic means of attesting parental responsibility (Article 31).
As regards enforcement (Article 34), the proposal relies on existing structures. Social networking and video-sharing services, online games, as well as software application stores, are subject to Chapter IV DSA. AI companions and general conversational chatbots are subject to Chapter XII of the AI Act, with fines of up to 6% of total worldwide annual turnover. Data protection authorities are competent to monitor the processing of personal data linked to age assurance.
Where the Commission opens proceedings against very large online platforms, it shall endeavour to communicate its preliminary findings and to adopt a final decision within accelerated timeframes (Article 35). Article 41 also adds the future Regulation to the annex of Directive (EU) 2020/1828, which would allow representative actions to be brought for its infringement.
VI. CONCLUSIONS
The proposal rests on two dimensions. On the one hand, it introduces an access restriction with a single minimum age across the Union, with which the Commission seeks to replace the patchwork of national rules. On the other, it makes safety-by-design and age assurance requirements directly enforceable and extends them to services that have so far received less regulatory attention, such as AI companions and operating systems.
From a preventive perspective, it is advisable for providers to start assessing whether their services have the features that trigger the age restriction, and which age verification systems
they could deploy. Providers should also bear in mind that the reinforcement of complaint mechanisms and representative actions is likely to increase their exposure to claims.
The Regulation would enter into force on the twentieth day following its publication in the Official Journal and would apply six months later. The exceptions are Article 5, which would apply from entry into force, and Articles 33 and 35, which would apply after twelve months.
The Commission is to review its application by 31 August 2030.
