Written by: Haim Ravia, Dotan Hammer
September 17, 2026, the European Commission adopted a proposal for a Regulation known as the EU KIDS Act (‘Keeping Internet Digital Spaces Accountable and Trustworthy’). The Commission’s position is that the existing legal framework is insufficient rather than absent: the DSA, GDPR, AI Act, and Unfair Commercial Practices Directive all bear on the protection of minors, but no EU instrument sets a minimum age for access to services with risky features, bans features such as endless scrolling and excessive notifications, harmonizes the treatment of addictive design, or supplies legal certainty on age verification. With national legislation being prepared or negotiated internally in 17 EU Member States, the proposal is also intended to pre-empt fragmentation.
The proposal applies to what the Commission calls ‘Social Media+’: online social networking services, video-sharing platforms, and online games posing specific design risks to minors, together with AI chatbots and AI companions, excluding services designed and operated for education or by public authorities, industrial AI, and AI office products.
Access is structured in tiers. Providers of social networking and video-sharing services may not allow a person under 15 to create or use an account where the service poses a risk to a minor’s privacy, safety, or security. The risk is deemed present when the service enables real-time transmission to an indeterminate number of recipients, enables contact outside the user’s pre-existing connections, uses a recommender system based on profiling, or deploys features intended or reasonably foreseeable to enable uninterrupted consumption. By derogation, guardians may set up limited accounts for minors aged 13 to 15, with guardian tools always activated, a guardian-set daily cap not exceeding one hour, and guardian pre-approval and capping of contacts.
The proposal also applies to existing accounts: within six months of application, providers must establish whether account holders are under 15 and disable the accounts of those who are, or whose age cannot be established.
Additionally, the proposal imposes safety-by-design obligations on all services in scope. These include a ban on addictive design features such as infinite scrolling, artificial notifications, or certain reward features; recommender systems that can be chosen, tuned, and controlled, that avoid rabbit-hole effects and that go beyond engagement-based signals; and safe default account settings.
The proposal aims to govern age assurance. Age assurance solutions must not enable identification of the recipient, nor locate, track, target, advertise to, or profile them. They must process no more personal data than strictly necessary, must not combine that data with data from other services, and — strikingly — must ensure that ‘any age assurance measure shall be zero knowledge proof.’ Providers must rely exclusively on an EU age verification solution certified under the EU Age Verification Scheme, with certified European Digital Identity Wallets deemed to qualify.
Click here to read the Commission’s Communication explaining the EU approach to online child safety.
Click here to read the proposed EU KIDS Act Regulation.