background image blur
background image
  • Blog
    >
  • News
    >
  • The EU KIDS Act Explained: What It Does and What It Means

The EU KIDS Act Explained: What It Does and What It Means

Image of author
By Tech Writer and VPN Researcher Gintarė Mažonaitė
clock icon
Last updated: 28 September, 2026
A woman using her ID card to prove her identity online

Key Takeaways

  • The EU KIDS Act — Keeping Internet Digital Spaces Accountable and Trustworthy — was announced on September 16th and proposes binding EU-wide rules on how online services can be designed for and accessed by minors.
  • Under-13s would have no social media accounts. Ages 13 to 14 would access platforms through parent-supervised accounts with a one-hour daily limit and parental approval of contacts. From 15, young people can open independent accounts on services required by law to be safe for them.
  • The law covers social media, video-sharing platforms, online games, AI companions and chatbots, and app stores — banning addictive design features including infinite scrolling, streak mechanics, and notifications designed to pull children back.
  • Self-declared age would no longer be sufficient: certified age verification is required, using a free EU age verification app or the European Digital Identity Wallet, with "zero knowledge proof" technology that tells the platform only whether a user is above or below the age threshold — not who they are.

The Two Things This Law Does

We covered the announcement within hours of von der Leyen's State of the Union address. Now that the Commission has published its full FAQ, the picture is clearer — and it's worth separating what the law actually contains from how it's been characterized.

The EU KIDS Act does two distinct things. The first is the age staircase: no social media accounts for under-13s, parent-supervised limited accounts for 13- and 14-year-olds, and independent accounts from 15 on services the law requires to be safe. The second is a safe-by-design mandate that applies across social media, video-sharing, games, AI chatbots, and app stores — banning specific design techniques that exploit children's psychology regardless of age.

The Commission's own FAQ is direct: age limits alone would leave the real underlying problem untouched, because the harm comes from services built to maximize children's time and attention. The two halves are intended to work together. Children gain access to the online world gradually as they grow up, and the services they access must be built for them rather than against them.

What Changes for Under-13s, Teens, and Existing Accounts

  • Under-13s have no social media accounts. One narrow exception exists: on video platforms designed specifically for young children, a parent may allow limited access through the parent's own account — no account for the child, no personalized feeds, no search, a parental time limit of up to one hour, and the parent can revoke access at any time. This exception ends at 13.
  • For 13 and 14-year-olds, a parent sets up the account, parental controls are always on, contacts require parental approval, and a daily time limit of at most one hour applies. From 15, young people can open accounts independently, but the platforms they use must comply with the law's safe-by-design requirements.
  • Existing accounts aren’t exempt. Within six months of the rules applying, platforms must check whether existing account holders are under 15 and disable the accounts of those who are, or whose age can't be established. Where a platform can already tell with high confidence that a user is an adult — from signals like account creation date or credit card details — no new check is required.

What "Safe by Design" Actually Bans

The design obligations are more specific than the usual vague "safe by design" language. For minors, services may not use: endless autoplay and infinite scrolling without real breaks; notifications designed to pull children back unrelated to anything they did; rewards for posting or streaming to mass audiences; or streak mechanics that penalize a child for not returning every day.

Recommender systems for minors must be optimized for safety, quality, and mental health — not engagement. What a child actively chose to follow comes first. Personalization based on tracking is off by default. No data from outside the service may be used. No rabbit holes. Children get an easy feed reset and always at least one option without any profiling.

On contact: nobody can message a child without pre-approval. Children don't appear in contact suggestions, can't be added to groups without agreement, and can block anyone anonymously. Their content is visible only to accepted contacts. Minors can't livestream by default.

AI companions and chatbots get specific treatment: they may not simulate human relationships in ways likely to create emotional dependency, can't carry earlier conversations into later sessions by default, must be tested for risks to children before launch, and must be easy to turn off when built into a platform or game.

The Age Verification Question

The Commission's answer to the anonymity concern is worth examining. Platforms don't check identity documents and don't learn who you are, the FAQ says. Age is verified through certified solutions independent of the platforms — a free EU age verification app and, eventually, the European Digital Identity Wallet — using "zero-knowledge proof" technology that communicates only a yes or no. Every member state must offer at least one free way to prove age, including for people without digital ID.

That's a more considered design than most national age verification schemes, which have tended to collect considerably more than a yes/no signal. Whether zero-knowledge proof technology can be deployed at the scale the regulation requires, and whether every member state can actually deliver a functional free option, are implementation questions the proposal hasn't fully answered yet.

The EFF published a detailed critique of the proposal on September 21st, which we covered, arguing that the mechanisms will impose costs on all users — not only minors — and that the proposal bypassed a full impact assessment. Those concerns are worth taking seriously alongside the Commission's own account, and we covered them separately.

Enforcement and What Comes Next

For very large online platforms — those with 45 million or more monthly active users in the EU — the burden of proof is reversed. Before their services come into contact with children under the new rules, they must submit a detailed compliance plan and have it verified by independent auditors at their own expense. The Commission can object to an auditor whose independence isn't ensured.

Fines can reach 6% of total worldwide annual turnover. For services supervised directly by the Commission, a 30-day preliminary findings deadline and a 90-day final decision target apply — fast by regulatory standards.

The full legislative text is still being developed. What von der Leyen announced on September 16th is the framework; the detailed rules on what exactly constitutes sufficient age verification, how the design prohibitions are tested, and what the compliance plans must contain will be worked out in the months ahead. We'll cover it as it develops.


Share on
Facebook share Twitter share Reddit share Linkedin share

Be part of the resistance, quietly.

Get Mysterium VPN Arrow icon
awareness campaign banner img
Image of author
Gintarė Mažonaitė
Tech Writer and VPN Researcher

Gintarė is a cybersecurity writer at Mysterium VPN, where she explores online privacy, VPN technology, and the latest digital threats in editorial pieces. With hands-on experience researching and writing about data protection and digital freedom, Gintarė makes complex security topics accessible and actionable.

Read our editorial policy here.

Read more by this author
© Copyright 2026 UAB "MN Intelligence"