Bird & Bird: The EU KIDS Act, A new generation of rules for child online safety
Anna Morgan and Alex Guard
Bird & Bird outlines the EU KIDS Act and its proposed new rules for strengthening children’s safety and protection online.
On 17 September 2026, the European Commission published its proposal for the EU Keeping Internet Digital Spaces Accountable and Trustworthy Act (the KIDS Act) This is the EU’s response to the global conversation on social media bans and an attempt to prevent fragmentation across the EU that could arise from a plethora of diverging national level social media bans.
The KIDS Act builds on recommendations in a Report from the Commission-appointed Special Panel on Child Safety Online (the Special Panel) and takes a nuanced, graduated approach to children’s access to services described as “social media+” (this term is used to generally describe services available to children which contain age-inappropriate or risky features such as infinite scroll, autoplay, recommendation algorithms and persistent notifications). The EU approach contrasts with blunter strategies involving a blanket ban on children’s access to social media services below a threshold age (such as in Australia). It proposes that children’s access to such services should evolve gradually, in a protected space so that they can learn how to manage the risks posed by the online world.
The KIDS Act has three primary objectives:
- It establishes a harmonised minimum age of 15 for children to create autonomous accounts with online social networking services and video-sharing platform services that pose risks to the privacy, safety, or security of children;
- It imposes harmonised safety-by-design requirements on various categories of online services; and
- It introduces harmonised rules regarding age assurance.
While the KIDS Act is built onto the existing enforcement scaffolding of the Digital Services Act (DSA) and EU AI Act (AI Act) these changes herald a dramatic transformation of the EU regulatory landscape for children’s online safety. They expressly bring a broad range of services within the scope of the KIDS Act and introduce extensive compliance requirements which will necessitate wholesale redesign of service and systems architecture.
Scope of the KIDS Act
Under the KIDS Act, providers of the following services or systems accessible to children (i.e. any natural person under the age of 18) are in scope:
- Online social networking services;
- Video-sharing platform services;
- Software application stores;
- Online games;
- Operating systems;
- AI companions; and
- General conversational chatbots.
Many of the above categories of service use existing definitions within EU legislation, such as those within the Digital Markets Act and the Audio-visual Media Services Directive. However, other new categories of services are identified – e.g. ‘AI companions’ and ‘general conversational chatbots’.
The KIDS Act expressly excludes certain providers from its application, including not-for-profit educational and scientific repositories, and not-for-profit online encyclopaedias, amongst others. The Commission has the power, by way of a delegated act, to add or remove exempt service providers in the future.
Delayed access for children to social networking and video-sharing platform services
A graduated approach to access for under 15s
The KIDS Act bans providers of online social networking services and video-sharing platform services from allowing under 15s to create an account, or to access the service through an account created for, or attributable to, them where such services pose risks to children’s privacy, safety or security (Article 6(1)). Such risks are deemed to be present where any one of a list of certain features is available on that service. These include live streaming, open communications functions, profiling-based recommender systems, contact recommendation systems and engagement-driven design features.
However, a number of exceptions are allowed depending on the age of the child, the type of service, who the account holder is and applicable safeguards. The table below sets out how the prohibitions and exceptions apply.
| Age Range | Service Type | Restrictions
|
| U13 | Online Social Networking | No access. Social network providers must not allow children below the age of 13 to create an account or to access the service through an account created for or attributable to them.
|
| Video-sharing Platform | Limited access only via guardian’s own account. Video-sharing platforms can enable children aged 3 and below the age of 13 to access a service that is specifically designed for children, via their guardian’s own personal account only if it can be demonstrated that the service is age-appropriate and certain cumulative conditions are met (Article 7(1)). The provider must establish that the guardian who is the account holder has parental responsibility over the child (see section 6 below). The age of the child in question is declared by the guardian (Article 7(4)(b)); that age cannot be below 3 years.
The child’s guardian must be able to control the child’s access to the video-sharing platform service via a dedicated parental control tool, and must have the ability to, amongst other things, supervise the content displayed to the child and suspend access at any time.
| |
| 13 to U15 | Online Social Networking & Video-sharing Platform | Limited access via restricted child account. Service providers may allow children aged 13 and below 15 to access the service via a controlled account with limited features only if it has been set up by their guardian on their own account (Article 6(2)).
These so-called “mini accounts” must be supervised by the child’s guardian via dedicated parental control tools. Amongst other things, guardians must be able to pre-approve potential new contacts on their child’s account, and control permissible levels of screen time (no more than one hour per day). The provider must verify that the guardian has parental responsibility (see section 6) and that the child has reached the age of 13 using age verification (see below).
|
| 15 and over | Online Social Networking & Video Sharing Platform | Autonomous accounts permitted. From age 15 and above, children may have autonomous accounts with online social networking and video sharing platform services. However, extensive safety by design requirements apply (see section 3 below).
|
How should age assurance be implemented for delayed access?
Implementation timeline:
New accounts: For any accounts which are created on or after the date of application of the KIDS Act, the rules regarding delayed access above will apply.
Accounts which are already in existence on the date of application of the KIDS Act: In order to comply with the above restrictions, within 6 months of the KIDS Act becoming applicable, providers of online social networking and video sharing platform services must establish whether existing holders of accounts on their service are below the age of 15 (Article 6(4)). Where such accounts are identified or where the age of the account holder cannot be established, they must be disabled.
However, service providers will not necessarily be required to conduct age verification across the whole of their account holder population. Where service providers can use other measures (such as the date on which the account was created) to establish with a high degree of confidence that an existing account holder is 15 or above, then age verification will not need to be conducted for them.
Implementation method: Chapter V of the KIDS Act prescribes requirements that must be satisfied by any age assurance method used by services to comply with the Act.
- General principles and data protection requirements. Any age assurance method used to comply with the KIDS Act is subject to the general principles in Article 27 of Chapter V which establishes that solutions must provide a high level of accuracy, reliability, security, robustness, non-intrusiveness, privacy and data protection, and non-discrimination. These principles largely mirror the principles established collectively by the EDPB in its Statement on Age Assurance and by the Commission in its Article 28 DSA Guidelines. In addition, Article 28 sets out more specific data protection requirements which data protection authorities will be responsible for enforcing in accordance with the GDPR regime. Notably, Article 28 requires all solutions to be zero-knowledge proof.
- Method of age assurance for delayed access must be age verification. “Age assurance” is defined by the KIDS Act to exclude self-declaration – reflecting a global regulatory trend whereby self-declaration is not perceived to provide effective age assurance in isolation. Further, for delayed access specifically, in-scope service providers must use age verification (a method which establishes whether the user meets the age threshold with a high degree of certainty on the basis of identification documents or other reliable and verified sources) in order to comply. (As noted earlier, the exception for this is for guardian-controlled video-sharing platform accounts for children aged 3 to below 13, in which case the parent can simply declare the child’s age when creating the account.) The Commission appears to be building on a conclusion it drew previously in its Article 28 DSA Guidelines, which rule out age estimation techniques for services posing risks to minors that cannot be mitigated as effectively as by age verification. However, it notably contrasts with jurisdictions such as the UK which have not yet ruled out age estimation in equivalent circumstances.
Further, Chapter V confirms that such age verification must be achieved using what the KIDS Act describes as an “EU age verification solution” provided by an independent third party. This is a solution that (i) meets the requirements of the EU Age Verification Scheme (which the Commission is developing following on from its non-binding recommendation from April this year); (ii) is certified as conforming to the scheme by a public authority; and (iii) is included in or verifiable against a Commission-published “list” of EU age verification solutions, and uses an EU proof of age attestation that is also separately listed. Providers may choose to rely on solutions rolled out by Member States in connection with the Commission’s “EU Digital Identity Wallet” initiative, which the Act deems to be certified for these purposes. Alternatively, they can rely on another independent third-party solution, so long as it is certified, included on the Commission’s list of approved age verification solutions, and uses a listed proof of age attestation. Any such listed solutions can be considered as providing valid proof of age, which will help ease providers’ vendor due diligence burden.
Safety by Design Requirements
The KIDS Act sets out stringent safety-by-design obligations which, for some services in scope, build upon existing regulations (such as Article 28 of the DSA and the AI Act framework, which remain unaffected by the KIDS Act).
At its core, it requires providers to take measures to ensure a high level of privacy, safety and security for children by default, i.e. to configure the design and settings of their service for any unregistered or unauthenticated user as if they were a child (Article 8). Only where it has been established that the user is older than 18 using age assurance (in accordance with chapter V requirements) can less protective features or settings be made available.
The exact measures to be embedded into the service design depend on the nature of the service, though some obligations apply across the different categories of providers. In many provisions, the proposed Regulation includes a general obligation applicable to specified services, which is then complemented with a list of minimal requirements for features or settings.
For example:
- Article 9 addresses addictive design features. Under Article 9(1), there is a general prohibition on designing or operating services in a manner that encourages compulsive or excessive use. Under Article 9(2), several features are identified as falling within this prohibition. These include auto-play features or infinite scroll, undermining a child’s decision to stop using a service via push notifications, and incentivising children to share content to an indeterminate number of users, or to have more frequent engagement (through penalties or loss of benefits for less frequent engagement).
- Article 10 addresses the design of recommender systems in social networks and video-sharing platforms. Article 10(2) requires social networks and video-sharing platforms to ensure their recommender systems give priority weight to explicit user preferences and do not exploit a child’s vulnerability or attention. Amongst other things, providers must not rely by default on implicit engagement-based signals, use personal data collected from outside the service, or expose a child to harmful information.
- Article 11 addresses safe settings. Safe account settings mean that settings must by default be set to a high level of privacy, safety and security for children. At a minimum, geolocation and tracking features, access to microphone and camera, recommendations for other accounts and synchronisation of accounts must be off. Push notifications should be designed in a way that protects children’s core sleep hours and school time.
- Article 12 addresses contact and interaction safeguards. Social networks, video-sharing platforms, video games and video gaming platforms must put in place contact and interaction safeguards to ensure, amongst other things, other users on their services are not able to initiate direct contact with a child if the child has not pre-approved such contact (Article 12(1)). Further requirements involve preventing children being automatically added to contact groups and being included in contact recommendations made to other service users. Children should also be easily able to block other users anonymously.
- Article 13 addresses safety and security measures in economic transactions. These obligations include making it clear to children when an economic transaction is taking place (showing the cost of the transaction in real rather than virtual currency) and avoiding service design that could lead to excessive, impulsive or unwanted spending.
Articles 14 to 16 set out additional safety by design obligations specific to the different categories of service as follows: Article 14 (obligations for AI companions and general conversational chatbots), Article 15 (obligations for video games and video gaming platforms) and Article 16 (obligations for software application stores) (see also below). - Articles 14 to 16 set out additional safety by design obligations specific to the different categories of service as follows: Article 14 (obligations for AI companions and general conversational chatbots), Article 15 (obligations for video games and video gaming platforms) and Article 16 (obligations for software application stores) (see also below).
In the table below, we provide a non-exhaustive overview of the key categories of safety-by-design measures which respectively apply to each category of service (except for app stores and operating systems, which are dealt with separately below):
|
| Social networks | Video-sharing platforms | Online games | AI companions | General conversational chatbots |
| General obligation of safety-by-design (Art. 8) | X | X | X | X | X |
| Addictive design avoidance obligation (Art. 9(1)) | X | X | X | X | X |
| Addictive features prohibitions (Art 9(2)) | X | X | Partial application under Art 15(1)(a) |
|
|
| Time-limited access and interruptions (Art 9(3)) | X | X |
| X | X |
| Safe recommender system design (Art 10(1)) | X | X |
|
|
|
| Recommender features prohibitions (Art 10(2)) | X | X |
|
|
|
| Recommender system tools (Art 10(3)) | X | X |
|
|
|
| Default safe settings (Art 11) | X | X | Partial application under Art 15(1)(b) | X | X |
| Interaction safeguards (Article 12) | X | X | Partial application under Art 15(1)(c) |
|
|
| Safeguards to prevent children initiating contacts on other services that pose risks (Article 15(2)) |
|
| X |
|
|
| Safety and security of economic transactions (Article 13) | X | X |
| X | X |
| Prohibition of features that simulate interpersonal relationships (Article 14(1)(a)) |
|
|
| X | X |
| Risk testing and post-marketing monitoring of AI system (Article 14(1)(e)-(f)) |
|
|
| X | X |
| AI chatbot features disabled by default and minimized (Article 14(2)) | X | X | X |
|
|
Should age assurance be implemented for safety-by-design?
Chapter V confirms that unlike age assurance for compliance with the delayed access obligations, age assurance used for the purpose of complying with safety-by-design obligations may be implemented by alternative methods to age verification – including age estimation. As above, self-declaration will not suffice since this is explicitly excluded from the KIDS Act definition of age assurance; and any age assurance solution must comply with the general principles and data protection-specific requirements set out in Articles 27 and 28 (see the table below). Given there will be no separate list for age assurance solutions other than those which comply with the EU Age Verification Scheme, there will be more of an onus on service providers to conduct their own diligence with regard to age estimation and other alternative providers’ Article 27 and 28 compliance.
App store-level age assurance
The KIDS Act is significant in setting out the Commission’s views on the debate regarding app store-level age assurance.
Providers of software application stores are subject to a general obligation to ensure a high level of privacy, safety and security of children, but this obligation is only exemplified by two explicit requirements: (i) to implement a mandatory and transparent age-rating system of apps offered via the store and (ii) to ensure users demonstrate that they meet the relevant age threshold to access or purchase these apps.
To comply with these obligations, Article 16(4) provides that app stores must conduct age assurance in accordance with Chapter V, including by means of the tools for guardians. Self-declaration will again not suffice, but app stores may rely on alternative methods to age verification including age estimation, provided they comply with the Article 27 and 28 requirements. Article 16(2) confirms that age assurance obligations on app stores shall not detract from age assurance obligations on providers of social networks and video-sharing platforms under Article 6; rather the obligations on each set of providers co-exist, creating a “tiered” approach.
Role of operating systems
Providers of operating systems themselves are not per se subject to a general obligation to ensure a high level of privacy, safety and security of minors. However, they may be required (subject to user consent) to share age signals of users with other categories of providers, thereby enabling these other categories of providers to meet their obligations under the proposed Regulation. The age assurance used to obtain this age signal must comply with the general principles in Article 27.
Age assurance in the KIDS Act - a summary
The table below is a high-level summary of age assurance implementation requirements, as discussed above, under the KIDS Act.
For more information on existing EU privacy & online safety regulatory attitudes to different age assurance methods, as well as an international comparison, see Bird & Bird’s Age Assurance Guide.
| Category of KIDS Act obligation | Permitted age assurance methods | Requirements applicable to all age assurance solutions
|
| Delayed access (social networks, video sharing platforms) | Delayed access rules must be implemented via age verification, using an “EU age verification solution”. Cannot be age estimation or self-declaration.
The exception to this requirement is the creation of guardian accounts for children aged 3 to under 13 on video-sharing platforms, where the guardian declares the child’s age (Article 7(4)(b)).
For existing account holders, service providers must have assessed their age within 6 months of the KIDS Act becoming applicable and take an action to shut down accounts where required (see above). Age verification not required for existing account holders where there is a high degree of confidence they are aged 15 or above.
| Article 27 general principles - must provide a high level of accuracy, reliability, security, robustness, non-intrusiveness, privacy and data protection, and non-discrimination.
Article 28 data protection requirements - shall not enable user identification nor locate, track, target, advertise to or profile users; processing limited to that which is strictly necessary, without further processing, sharing or combination activities (although providers complying with safety-by-design requirements may store a limited account-level age signal to avoid repeated age assurance); must use state-of-the-art technology and be zero-knowledge proof.
Providers must facilitate an effective complaints mechanism in respect of allegedly incorrect age assurance outcomes.
|
| Safety by design (social networks, video sharing platforms, online games, AI companions, general conversational chatbots) | Can be either age verification using an “EU age verification solution”, or an alternative form of age assurance including age-estimation. It cannot be self-declaration.
| |
| App store age assurance (software application store providers) | Can be either age verification using an “EU age assurance solution”, or an alternative form of age assurance including age estimation. It cannot be self-declaration.
|
Controls for Children
All in-scope providers (save for app stores and operating systems) must ensure that their safety-by-design features are easy-to-use and accessible for children (Article 18). In particular, they must have access to effective tools which help them to control, and give feedback on, search results, content, prompts, and information presented to them, with immediate results. Children must also have access to tools which enable them to control settings that govern the content they create and interact with on the service. These tools should include warning signals, explanations, temporary setting changes and an easy return to default settings.
Parental verification and parental tool
Under the KIDS Act, guardians - i.e. any person holding parental responsibility of a child in accordance with national laws - often will act as a supervisor of, and intermediary between, a child and the service provider. Before a guardian can act in this capacity, providers must first establish whether the person holding themselves out as guardian of the child in question has parental responsibility for them (Article 26).
The KIDS Act sets out three mechanisms by which this can be achieved:
- Firstly, the provider may be able to use signals of parental responsibility already in their possession from past engagements.
- Secondly, the provider can use signals (i.e. evidence) of parental responsibility based on national online databases or interfaces made available by a member state. In this regard, the KIDS Act provides for the establishment of measures at member state level which will enable guardians to obtain an electronic attestation of parental responsibility in respect of a child which can be used for the purposes of proving parental responsibility. The Commission is empowered to adopt a delegated act which will specify what types of signals would indicate parental responsibility.
- Until such time as the Commission’s delegated act is adopted and member states are able to provide access to freely accessible signals of parental responsibility, providers can rely on self-declaration by the adult that they have parental responsibility. However, the provider must still make reasonable efforts to verify that the adult in question has parental responsibility. What this means in practice is unclear; similar requirements for verifying parental responsibility in connection with the provision of parental consent under the General Data Protection Regulation (GDPR) continue to pose practical challenges for data controller.
Separately, the KIDS Act also requires providers to implement effective, accessible and user-friendly parental control tools (i.e. software applications and product features) that allow guardians to, amongst other things, ensure time-limited access by a child to the services, control safety settings and contact interaction, and report harmful content, accounts and behaviour on behalf of their child (Article 20(4)). These tools must respect children’s agency and privacy and must not disproportionately affect their rights.
Enforcement
The supervisory and enforcement framework under the KIDS Act draws heavily upon the existing enforcement frameworks under the DSA, the AI Act and the GDPR. As a result, existing rules and procedures meant to ensure coordination and consistency, and avoid conflicting decisions between the different regulators, will also apply. This begs the question whether the KIDS Act will pass the decisive test of real and efficient enforcement once it becomes applicable. At this stage, a few points deserve the attention of in-scope service providers.
First, available sanctions and penalties under the DSA and the AI Act remain fully applicable: thus, chapter IV of the DSA will be applicable to all operators covered by the KIDS Act, and references to compliance with the DSA will be deemed to include the KIDS Act as an integral part of the body of substantial DSA obligations. As an illustrative example, the Commission may impose fines up to 6 per cent of the total annual turnover of a VLOP that fails to comply with the KIDS Act.
Next to regulatory oversight, private enforcement could also play a significant role under the KIDS Act. Providers can be exposed to complaints by individuals (minors and guardians) but also by mandated bodies or organisations incorporated to ensure compliance with the proposed Regulation and operating on a not-for-profit basis.
Providers will remain subject to the same competent authority that already regulates them under the DSA or the AI Act respectively. Thus, providers of online social networks, video-sharing platforms, video gaming platforms and software application stores will be subject to either the competent authority in the member state of their main establishment, or to the exclusive powers of the Commission when they qualify as VLOPs or VLOSEs.
Similarly, relevant market surveillance authorities under the AI Act will be competent for obligations applicable to AI companions and general conversational chatbots under the KIDS Act. National data protection authorities under the GDPR are competent to monitor the processing of personal data necessary to comply with the obligations under the KIDS Act, in particular concerning age assurance requirements.
In practice, the Commission takes an even more central role, not only because of its exclusive oversight powers for VLOPs and VLOSEs, but also because of its powers to extend key substantial obligations, for instance regarding recommender systems, default settings or measures to ensure protection of minors accessing AI companions or online games.
The Commission clearly intends for the KIDS Act to produce swift and effective compliance. To that end, the proposal includes a broad anti-circumvention rule prohibiting conduct that would undermine the effectiveness of its obligations. It also imposes early compliance planning and independent audit requirements. Such compliance plans must be notified to the Commission within 30 days of Article 5 of entering into application (see below) on providers of very large online platforms offering social networking or video-sharing services, including corrective action plans where shortcomings are identified. These audit obligations, inspired by the DSA, do not limit the Commission’s investigative or fining powers.
Conclusion
The KIDS Act is set to revolutionise the regulation of child online safety within the EU. Its obligations are far-reaching, and in some respects, entirely novel. In the case of many services, compliance with the KIDS Act will call for fundamental reconfiguration of service architecture. The EU has moved with extraordinary speed to bring this proposal for the KIDS Act forward and it does not appear that this momentum will slow down. If adopted, the current timing for the KIDS Act means that it becomes applicable 6 months and 20 days after its publication in the Official Journal. However, the audit requirements for VLOPs under Article 5 mentioned above would become applicable a mere 20 days after its publication. Given the lengthy average lead-in times for technical changes across systems infrastructure, services which are in scope should start to plan now for compliance.

This article is written by Anna Morgan (partner, Ireland), Benjamin Docquir (partner, Belgium), Heather Catchpole (senior associate, UK), Lisa Gius (associate, Belgium), and Alex Guard (associate, Ireland).

