EU KIDS Act: EU Commission Publishes Proposal on Child Protection Online
Key POINts:
- Access to social-networking and video-sharing platforms for under-15s is restricted, following a staggered approach.
- Providers of a broader range of services — including AI chatbots and companions — would be required to implement comprehensive safety-by-design measures.
- Supervision and enforcement mechanisms rely on existing frameworks under the DSA and the AI Act, including fines for AI chatbot and companion violations of up to 6% of global annual turnover, and potential for civil claims.
On September 17, 2026, the European Commission (Commission) published its proposal for the EU KIDS Act (the Draft Act), aiming to provide comprehensive protection for children in digital spaces and to prevent national-level fragmentation on age restrictions for social media access.
Services in Scope
The Draft Act covers providers of the following categories of services and systems accessible to minors:
- Online social-networking services
- Video-sharing platform services
- Software application stores (1-3 are as defined in the Digital Markets Act)
- Online games (video games and video gaming platforms)
- Operating systems
- AI companions and general conversational chatbots
The Draft Act applies to services / systems provided on the EU market, regardless of the provider’s place of establishment.
Exemptions apply to nonprofit, scientific, educational, and public authority services, as well as open-source platforms. The Draft Act does not include any exemption for small and medium-sized enterprises.
Age-Based Access Restrictions
Tiered Restrictions
The Commission proposes harmonized, tiered age-based access restrictions applicable to online social-networking services and video-sharing platform services that pose risks to minors based on a definitive list of factors set out in the Draft Act, including: enabling live streaming to an unspecified audience, contact with users outside of existing connections, profile-based recommendation systems, recommendations of content or contacts outside of existing connections, and design features that enable uninterrupted consumption.
Existing User Accounts
The Draft Act proposal requires providers of in-scope online social-networking services and video-sharing platform services to establish whether existing account holders are aged 15 years or older within six months of the Draft Act’s application. They would need to disable accounts that cannot be verified as compliant. If a provider has already reliably established that an existing user is over 15 (e.g., credit card details, account creation date, etc.), it would not need to age-check or verify that account.
Age Assurance
A key element of the Draft Act is the requirement for certified age assurance. Simply providing one’s own date of birth is not sufficient for this purpose. Providers of online social networking services and video-sharing platform services would be required to use EU-certified age verification solutions.
For other service providers (such as online games, AI companions, and software application stores), alternative age-assurance solutions would be permitted, provided they comply with general principles of accuracy, reliability, security, robustness, data protection, and non-discrimination. For example, age assurance should be zero-knowledge proof and must not enable identification or profiling.
Safety-By-Design Obligations
Providers of all in-scope services must implement certain safety-by-design obligations when providing services to users under the age of 18. Providers may only deviate from these protective requirements once they have established, by means of age assurance, that the user is at least 18 years old.
Service-Specific Obligations
VLOPs
The Draft Act would require providers designated as Very Large Online Platforms (VLOPs) under the Digital Services Act (DSA) to submit a compliance plan to the Commission within four months of designation. For platforms already designated at the time the Draft Act enters into force, the deadline is 30 days from the date of application.
VLOPs would be required to commission an independent audit of their compliance plans by qualified experts and publish a summary of the auditor’s report. Any shortcomings identified by the Commission must be remedied within 60 days.
App Stores
The Draft Act also contains sector-specific rules for software application stores. These stores must establish an age-classification system, implement age-verification measures, and block access to apps that are unsuitable for the user’s age.
Supervision and Enforcement
SA and the AI Act Frameworks
The Draft Act builds on the existing enforcement structures of the DSA and the AI Act, with supervision depending on the type of service:
- Online social-networking services, video-sharing platforms, video gaming platforms, and app stores would fall under the DSA. National digital services coordinators hold primary supervisory competence; for VLOPs, the Commission enforces compliance directly. Maximum fines reach up to 6% of worldwide annual turnover for VLOPs.
- AI companions and conversational chatbots would fall under the AI Act. The EU Commission and AI Office hold exclusive supervisory competence, with fines of up to 6% of global annual turnover for intentional or negligent violations.
- For standalone video games, Member States must designate a competent authority and set national-level penalties.
In parallel, Member States’ data protection supervisory authorities remain competent to enforce obligations under the EU General Data Protection Regulation (GDPR) in relation to the processing of personal data in the context of the Draft Act. GDPR fines may reach up to 4% of global annual turnover.
Right to Lodge a Complaint and Collective Actions
The Draft Act gives minors, guardians, and nonprofit bodies/associations authorized to act on their behalf, a right of complaint to the relevant supervisory authority regarding alleged violations.
The Commission further proposes to extend the scope of the Representative Actions Directive to include the Draft Act. Such extension would enable qualified entities (typically consumer organizations, child protection organizations, etc.) to bring collective damages actions in Member State national courts against providers under the Draft Act on behalf of relevant users.
Interaction With the DSA, GDPR, and AI Act
The Draft Act is designed to supplement and clarify the existing framework under the DSA, AI Act, and GDPR, not to replace it. While the interplay between these frameworks appears broadly coherent, some areas of potential tension or overlap may emerge.
For example, compliance with the Draft Act creates a presumption of compliance with certain of the DSA’s minor-protection requirements, but not the DSA as a whole.
In relation to the GDPR specifically, the Draft Act states that its age restrictions apply in parallel to the GDPR’s parental/guardian consent requirements for minors online and the national digital ages of consent. A 15-year-old may therefore be able to create their own account under the Draft Act without necessarily being able to validly consent to relevant data processing under national data protection law.
The Draft Act complements the AI Act’s risk-based framework — including the prohibition on exploiting age-related vulnerabilities — by adding specific safety-by-design requirements tailored to the protection of minors for AI companions and general conversational chatbots.
Outlook
The Commission’s proposal is the first step in a lengthy legislative process requiring agreement with the European Parliament and the Council of the EU. The Draft Act is expected to undergo significant negotiation, and providers should monitor developments as well as broader global regulatory trends around child safety online. The general direction of travel is toward greater protection for minors, building on existing frameworks such as the DSA, UK Online Safety Act, and US COPPA. However, novel regulations across jurisdictions — including age-based social media restrictions and age-appropriate design codes — are not necessarily aligned and require careful navigation by global providers.