EU KIDS ACT: Commission announces new restrictions on children's access to social media, gaming, video and AI services
Published on 17 September 2026
A new regulation will set age-based account restrictions, safety-by-design rules and age-assurance obligations for social media, gaming, AI and other digital services aimed at children
At a glance
Providers face tiered account restrictions and parental controls depending on a child's age and the type of service offered.
Services must build in safety-by-design features, including limits on addictive functionality and recommender systems.
Age assurance obligations vary by service, with stricter requirements for social media and video-sharing platforms.
With no social media accounts for under 13s, parental controls for various features of accounts for minors between 13 and 15, contact restrictions, recommender system limitations and more, the EU KIDS ACT (EU Keeping Internet Digital Spaces Accountable and Trustworthy), announced on 17 September 2026, is an ambitious legislative proposal affecting a wide range of digital services, mandating age-verification for some services and assurance for others, all aimed at improving children's safety online.
What is in scope?
The regulation aims to protect "minors" or "children", both defined as any natural person under the age of 18. It applies to a wide range of digital services: online social networking services, video-sharing platform services, app stores, online games, operating systems, AI companions and chatbots.
"Online social networking services", a definition taken from the Digital Markets Act (DMA), covers social media but also web boards and various kinds of online communities.
"Video-sharing platform services", a definition taken from the Audiovisual Media Services Directive (AVMSD), includes standalone services, as well as those embedded within other digital services.
"Online games" means both "video games" and "video game platforms", two new concepts that are very broadly defined, and whose current wording could even extend to interactive video functionality (of the "choose your adventure" style).
"AI companion" is defined as an AI system that "provides sustained, personalised interaction or companionship which simulates or facilitates a social, emotional or interpersonal relationship with a user". Yet personalisation of an AI chatbot can already be said to facilitate an interpersonal relationship with a user if the personalisation persists across user sessions.
What is not in scope?
Not-for-profit online encyclopaedias, not-for-profit educational and scientific repositories are exempt, as are certain public authority services and systems and open-source software developing and sharing platforms (unless the platform in question is an AI system within the scope of the EU AI Act).
Services and systems that are "designed for primarily educational purposes, and operated by educational establishments or organisations, or on their behalf" are also exempt. This may raise significant questions, as many services can be shown to be educational, from historic or strategic video games to skill-focused or learning platforms. Absent a definition of "educational establishments or organisations", some might claim to be educational, while those not recognised as such might claim that the criteria are arbitrary or discriminatory.
Account restrictions per service and per age group
The regulation would require online social networking services and video-sharing platform services to ensure that no user under the age of 15 can create an account on that service, where the service "poses a risk to the privacy, safety or security of a minor below that age".
Such "risk" would arise where the service:
- Allows contact with other users not part of a user's pre-existing connections or subscriptions.
- Deploys a recommender system based on profiling.
- Deploys infinite scrolling functionality or is designed to keep a user engaged with the site for longer or deploys push notifications designed to prompt the user to re-engage with the service.
- Allows users to transmit content in real-time to an indeterminate number of other users, including through live streaming.
For children between the ages of 13 and 15, parents and guardians (who the provider must verify as being the holder of parental responsibility over the child) may set up introductory accounts for online social networking and video-sharing platforms, which must have strictly limited features, including enabling parents and guardians to:
- Set a maximum limit on the amount of screen-time on the site, which must not exceed one hour.
- Pre-approve potential new contacts and set a maximum limit on the number of other users in the account's contacts.
For children below the age of 13, but older than three, video-sharing platform services that are specifically designed for children under 13 may "exceptionally" allow access by a child under 13 through the parent's or guardian's own account, but only if certain conditions are met, such as disabling all personalisation features and recommender systems.
Overall, the regulation aims to provide a harmonised set of restrictions across the EU and does not allow Member States to increase any of the minimum ages it sets out. This is deliberate to avoid fragmentation and uncertainty.
Safe by design
All providers will have to ensure that their services are safe by design and default, in that they have actively introduced certain safety features set out in the legislation.
These safety features differ according to the service in question, but always with the overall aim of ensuring a high level of privacy, safety and security of children. The safety feature requirements in the legislation are without prejudice to the tiered age restrictions.
Online social networking and video-sharing platform services
These services are subject to the strictest rules. While the draft legislation is not always entirely clear to what extent the restrictions apply only to minors or to all users, the overall thrust of the regulation suggests that they do not apply to users over the age of 18.
- "Addictive" design
Providers must ensure that the design of their services is not "addictive". Features deemed addictive include:
- Auto-play of content and infinite scroll.
- Undermining the child's decision to discontinue use of the service or not allowing them to make that decision through push notifications.
- Incentivising or rewarding children to share content or to broadcast live content to an indeterminate number of other users.
- Incentivising engagement frequency through penalties or the loss of benefits for not engaging regularly.
Providers of these services must also put in place effective time-management tools that protect school time and the core sleep hours of children.
- Recommender systems
Recommender systems must be designed so as not to exploit a child's vulnerability or attention by, for example, disabling by default the recommendation of information based on the child's engagement and behaviour online, and ensuring that no personal data is captured from outside the service.
Certain default settings must also be applied, including disabling access to the microphone and camera of the device being used, switching off geolocation and tracking features, and ensuring no push notifications are delivered.
- Contact and interaction
Strangers must not be able to contact the child, unless pre-approved by the child, and children should only be able to be added to a group if they have explicitly consented. It must also be easy for children to anonymously block other users.
- Economic transactions
The legislation also puts in place requirements around economic transactions to prevent excessive, impulsive or unwanted spending by children when using online social networking or video-sharing platform services. Provisions on this issue were expected to be introduced by the Digital Fairness Act, a legislative proposal which is anticipated this autumn, but have instead been introduced here.
- AI companions and chatbots
Providers of AI companions and chatbots will have to comply with many of the features applicable to online social networking services and video-sharing platforms, plus various additional features, including:
- Avoiding design features and system behaviours that simulate interpersonal relations likely to create emotional dependencies.
- Ensuring that the system does not use information from a child's previous interactions, unless necessary to protect their safety.
- Before any system is put on the market, performing "state-of-the-art" evaluations and testing of the system for risks to health, safety and fundamental rights, as well as the well-being and development of children, and putting safeguards in place to address the risks.
- Once a system is on the market, monitoring it to identify risks and mitigate harms.
In online social networking services and video-sharing platforms, AI companion or chatbot features must not be automatically activated or displayed prominently, and children must not be encouraged to use the feature.
- Online games
Providers of online games and video game platforms, where users create and share their own games and experiences within a broader online environment, must ensure a high level of privacy and safety by, for instance, not encouraging addictive use of the game and putting in place safeguards to prevent the game being used to entice children to initiate contacts on other services.
- App store providers
App store providers will have to put in place an age-rating system, which takes into account the development of children, to establish the age-appropriateness of apps in their store. They must not allow children to access or buy inappropriate apps, based on the age-rating system in place.
Age assurance
Everything in the regulation is underpinned by the use of age assurance, even if the specific requirements differ between the different categories of services.
Online social networking services and video-sharing platform services in scope of the access restrictions will have to deploy EU-certified or equivalent age-verification solutions at the moment an account is created. Other forms of age assurance, such as age estimation, will not be sufficient, and self-declaration is expressly excluded even from the definition of age assurance for the purpose of this legislation.
However, other service providers within scope of the regulation seeking to comply with the obligation to ensure a high level of privacy, safety and security by meeting the safety by design requirements, will be permitted to use alternative age assurance solutions instead of age verification, provided those solutions are accurate, reliable, secure, robust, non-intrusive, non-discriminatory and provide a high level of privacy.
Age-assurance technology is currently facing privacy concerns because in order to assess a user's age, various personal data have to be collected from the user and stored by the provider. The Digital Services Act (DSA) and the General Data Protection Regulation (GDPR), already require age verification to protect children online, but so far there is no definitive technological solution that absolutely ensures privacy.
Eventually, it is envisaged that the EU Digital Identity Wallet (EUDI) will provide a secure solution that does not result in the disproportionate processing of data and protects privacy. However, it is still in development. As an interim solution, the EU has also built an open source age verification tool that is technically ready, but it has faced issues around security with a number of vulnerabilities being identified. The EU app tool will, in theory, be a harmonised, cross-border tool that will function with the EUDI when it is deployed.
The proposed regulation addresses privacy issues, but only in a broad sense, providing that age assurance solutions must not enable the identification of the user or locate, track, target, advertise to, or profile users for any purpose.
VLOPS
As with the DSA, some platforms designated as Very Large Online Platforms, will have additional obligations to:
- Send to the Commission, within four months of being designated as a VLOP and, if already a VLOP, within 30 days from the regulation coming into effect, a detailed compliance plan.
- At their own expense, conduct third-party audits of their compliance plans.
- Monitor, test and evaluate the effectiveness of the compliance measures implemented as part of the risk assessments they are already obliged to undertake under the DSA.
- Submit a separate plan to the Commission setting out how they intend to comply with age-verification requirements.
- Pay an annual compliance monitoring fee, in addition to the fee payable under the DSA.
Enforcement
The existing DSA enforcement regime will apply to providers of most services, other than providers of AI companions and chatbots, which are instead subject to the AI Act's regime. Providers that infringe could be subject to fines of up to 6% of their total worldwide annual turnover.
For video games, being games available online but that are not video game platforms subject to the DSA, Member States will each have to identify a regulator to supervise compliance.
Other provisions
The regulation also contains provisions for codes of conduct to be drawn up at EU level, to be prepared by the Commission alongside providers of in-scope services. In addition, it contains general obligations on services to provide empowering tools for both children and parents/guardians that are easily accessible and easy to understand.
Providers must also ensure that children can easily provide feedback, report harmful content, complain to the regulator of any infringements by providers, and control the content they view.
The position in the UK
In the meantime, the UK government under Andy Burnham has confirmed that it will go ahead with the social media ban for under-16s that Keir Starmer announced before he left office. It intends to lay regulations on this before the end of 2026.
It also said that it will proceed with legislation to introduce the additional restrictions on risky functionalities, such as stranger communication and livestreaming across a wider range of services for under-16s, and default-on restrictions for 16-17-year-olds, which will include gaming services, that the former prime minster also announced before leaving office. It will also go ahead with the plan to introduce default protections for 16-17-year-olds on social media (curfews, muted push notifications and limits on autoplay and personalised feeds), and proceed with the Keir Starmer government announcements on AI chatbots.
Osborne Clarke comment
The proposal may be welcomed by some as a step in the right direction and preferable to a Member State patchwork of different age limits and restrictions, but in its present state it presents many challenges to covered service providers.
Some required measures are similar to child protection measures already called for in the European Commission guidance on Article 28 DSA, providing a welcome bit of coherence. However, legislators playing product designer often create unforeseen and unintended engineering and functionality issues for concerned services.
Some aspects of the draft seem to sow unnecessary confusion and are hardly practical, such as the obligation to verify the status of guardians. This is implicitly also required under Article 8 GDPR, but there is no obvious way to achieve this in a privacy-preserving manner.
Finally, some of the terminology is equally puzzling. The draft uses the terms "minor" and "child" synonymously and interchangeably, and posits "online game" as an umbrella term for games themselves and for the platforms that contain them, which is confusing and not consistent with the usual terms for these very different concepts.
The draft is not final and is subject to refinement and political negotiation between the EU co-legislators. We will keep a close eye on future developments.