EU Kids Act: European Commission Set to Propose Limits on Minors’ Access to Social Media, AI Companions and Games

On 17 September 2026, the European Commission is expected to present the “EU Kids Act”, a legislative proposal on minors’ access to online services. Commission President Ursula von der Leyen and Executive Vice-President Henna Virkkunen are due to present it a day after the State of the Union address, which Ms von der Leyen gives to the European Parliament in Strasbourg on 16 September. Draft texts reported by the press set out age-based access tiers for social media, video-sharing platforms, AI chatbots and companions, and online games, together with “safe by design” duties and EU-wide age verification. Most reports put the age for an independent account at 15, but in at least one leaked version the figure was still blank, so it may change before publication.

How the situation developed

In her State of the Union address of 10 September 2025, Ms von der Leyen said she was following Australia’s under-16 social media ban and announced an expert panel to advise on the EU approach. The Special Panel on Child Safety Online published its report on 13 July 2026. It recommended an EU-wide restriction for children under 13 until services show they are safe by design, with staged use by age: no screens under three, supervised use from 3 to 12 and growing autonomy from 13 to 18. The panel also wanted games and AI chatbots covered alongside social media, and left member states free to set a higher age.

The European Parliament had gone further. In its resolution of 26 November 2025, adopted by 483 votes to 92 with 86 abstentions, it called for an EU-wide digital minimum age of 16 for social media, video-sharing platforms and AI companions, with access from 13 allowed with parental consent and 13 as the absolute floor. MEPs also asked for a ban on engagement-based recommender systems and the most harmful addictive practices for minors, and wanted the future Digital Fairness Act to deal with dark patterns and persuasive design.

The technical groundwork started in July 2025, when the Commission released the first version of its open-source age-verification blueprint, piloted by Denmark, France, Greece, Italy and Spain. Zero-knowledge proofs came in later versions, so a platform receives only confirmation that the user has reached the required age. In April 2026 the Commission declared the app technically ready, and its Recommendation of 29 April 2026 asks every member state to offer at least one such solution by 31 December 2026, either as a stand-alone app or inside the European Digital Identity Wallet.

Member states have not waited for Brussels. On 14 August 2026, France’s Conseil constitutionnel, in Decision No. 2026-911 DC, struck down the blanket under-15 ban in Article 1 of the law adopted on 21 July. The Council held that the ban was not necessary, appropriate and proportionate as a limit on freedom of expression, and it found no legal safeguards for the age checks the ban required. Paris has since prepared a narrower text, reported to bar children under 13 and let 13- to 15-year-olds in with parental consent, and President Macron is now pressing for an EU-wide rule. Denmark sent its under-15 bill to consultation in September 2026 with a planned start on 1 July 2027. Austria is consulting on an under-14 limit, Greece has announced an under-15 ban from 1 January 2027, and Spain’s under-16 bill is still in parliament. Italy, Slovenia and Poland are at earlier stages, while a German expert commission recommended 13 in June 2026. On 11 September 2026, the Netherlands and Spain circulated a joint proposal for a harmonized EU minimum age that would also cover games and AI chatbots.

The Commission has used the notification procedure under Directive (EU) 2015/1535 to question several of these national measures, and the prospect of 27 different regimes is one of the main arguments for an EU act.

Outside the EU, Australia’s under-16 ban has applied since 10 December 2025, and by mid-January 2026 more than 4.7 million accounts had been deactivated, removed or restricted. Norway plans to let children join social media from 1 January of the year they turn 16. In the United States, Meta agreed on 26 August 2026 to settle claims brought by 51 attorneys general, including those of 47 states, over allegedly addictive design. The settlement is worth up to USD 17.1 billion over ten years, of which about USD 12.1 billion is guaranteed and the rest depends on other platforms accepting similar terms. Meta denies the allegations.

What the draft proposes

Scope. According to the leaked drafts, the act would cover social media, video-sharing platforms, AI chatbots and companions, and online games that pose risks to children. Education services, services run by public authorities and AI tools for office or industrial use are reported to be excluded.

Tiered access. There would be no access below the age of three. Children aged 3 to 12 could use only child-friendly services through parent-controlled accounts. At 13 and 14, parents could open “introductory” accounts with limited contacts, time limits and parental controls, and from 15 teenagers could hold their own accounts, still protected by the safe-by-design rules until 18. The top threshold remains disputed. The expert panel proposed 13, France and Greece favor 15, and Spain and the European Parliament have backed 16. Estonia opposes access bans and wants platform obligations enforced instead. Belgium, the only other member state that did not sign the October 2025 Jutland Declaration, objected to the proportionality of age verification, although the Flemish government has since set its own minimum age of 13.

Safe by design. The drafts would prohibit infinite scroll, streaks, artificial notifications and certain reward mechanics for minors, require recommender systems that do not lead children into “rabbit holes”, make minors’ accounts private by default and block contact from unknown users. The largest platforms would reportedly need the Commission’s approval before launching new features that could affect children. All of this would come on top of Article 28 of the DSA, which already prohibits advertising based on profiling to users known to be minors.

Age verification. Services would check age when an account is opened and, for games, at the point of download from an app store. The accepted tools are reported to be the EU app, national solutions and equivalent public tools such as digital identity wallets, all of which confirm age without revealing other data. Existing accounts would be checked proportionately. The leaked texts do not list commercial facial age estimation or ID uploads among the accepted methods.

Enforcement and fees. Reuters quotes the draft as providing for “a supervisory fee to fund regulators’ enforcement and supervision”. Press reports describe a DSA-style split, with the Commission supervising the largest platforms and national authorities handling the rest. If the fee copies the DSA model, the drafters will have to take into account the General Court’s judgments of 10 September 2025 in T-55/24 Meta and T-58/24 TikTok, which annulled the Commission’s DSA fee decisions because the calculation method should have been laid down in a delegated act.

Legislative status. The text published on 17 September will be a proposal, not law in force. It must pass the ordinary legislative procedure in Parliament and the Council, where Ireland holds the presidency until the end of 2026. The legal form (regulation or directive), the legal basis and the transition periods have not been confirmed, and adoption before 2027 looks unlikely.

Open questions and pushback

Four points will decide how much the proposal changes in practice: the final age threshold, the balance between access limits and design duties, whether age checks sit with each service or with app stores and operating systems (the approach Meta has backed since 2025), and what the act adds to the Commission’s pending DSA cases against Meta and TikTok.

Civil society is split. EDRi and more than 130 other organizations oppose access bans, and EDRi argues that age verification should not be built at all. Its fallback position is that, if age gates come, the zero-knowledge-proof model should be mandatory for national versions of the app rather than merely recommended. The app’s security has also been questioned. In April 2026, security researcher Paul Moore bypassed the demo version in under two minutes; the Commission answered that it was still a demo.

Regulatory context

The proposal builds on Article 28 of the DSA and the Guidelines on the protection of minors of 14 July 2025. The guidelines are non-binding, but the Commission already uses them as its enforcement benchmark. In 2026 it issued preliminary findings against TikTok on addictive design (6 February) and on minors’ default settings (24 July), against Pornhub, Stripchat, XNXX and XVideos for failing to keep minors away from adult content (26 March), against Meta for not keeping under-13s off Instagram and Facebook (29 April) and against Meta again on addictive design (10 July). It also opened formal proceedings against Snapchat on 26 March. None of these cases has yet ended in a non-compliance decision, which can carry a fine of up to 6% of worldwide annual turnover.

On 31 August 2026, the Commission designated ChatGPT as a very large online search engine and Roblox and Reddit as very large online platforms, so AI chatbots and games are already moving into the DSA’s risk-assessment regime.

The new act will also have to be read with the GDPR, in particular the data minimization principle and the EDPB’s Statement 1/2025 on age assurance, and with the Digital Fairness Act, which the Commission plans to propose by the end of 2026 to tackle addictive design and dark patterns. How the two proposals will fit together is not yet clear. Until the Commission adopts its text, everything above rests on leaked drafts and press reports.

REVERA Recommendations

  1. 1. Map which of your products (social networks, video-sharing features, AI chatbots and companions, games with chat or social functions) could fall within scope, and which age groups actually use them. Obligations will depend on the type of service and the age of its users.
  2. 2. Review age-assurance options against the leaked text, which points to the EU app, national tools and public digital identity wallets rather than commercial facial scans or ID uploads. A proprietary tool built now may have to be replaced, and collecting more data than needed creates GDPR exposure.
  3. 3. Audit features used by minors, such as infinite scroll, streaks, push notifications, autoplay and personalized recommendations, against the July 2025 Guidelines. The Commission is enforcing them under Article 28 of the DSA today, without waiting for the new act.
  4. 4. If your launch plans rely on a national rule in France, Denmark, Austria, Greece or Spain, check how an EU act could replace or reshape it.
  5. 5. Follow the legislative procedure instead of planning compliance around one draft. The age threshold, the split of enforcement powers and the fee are all still open.

REVERA’s Arbitration & IT Disputes practice has previously written on regulatory requirements for digital platforms, including the FTC action on deceptive subscriptions. We are ready to assess your company’s risks under the EU Kids Act and review your products and data flows against the DSA and the GDPR

Write to us










    Send request