EU Kids Act Puts Platform Design Under the Microscope
The EU Kids Act would set age limits, strip addictive features and require age checks. Its hardest test may be proving age without sacrificing online privacy.
Written by AI. Zara Chen

The European Commission proposed the EU Kids Act on Thursday, with rules that would reach from a teenager’s social feed into app stores, games and AI companions.
Its headline is built for maximum parental-group-chat velocity: children under 13 couldn’t use social media, 13- and 14-year-olds would get parent-managed “mini accounts,” and autonomous accounts would start at 15. The supervised services would have limited contacts and a daily cap of one hour.
Those ages will dominate the political argument. The proposal’s deeper intervention sits inside the product itself. For users under 18, platforms would have to remove infinite scroll, tracking-based feeds, reward tricks, nighttime notifications and unsolicited messages from strangers. Profiles would be private by default, while location, camera and microphone access would start switched off. AI chatbots would also start off and couldn’t be designed to create emotional dependency.
That package turns the Kids Act into a test of whether governments can regulate engagement mechanics rather than waiting to challenge individual pieces of harmful content. Brussels is effectively pointing at the autoplay-scroll-notification combo and saying: yes, the little dopamine casino counts as a policy choice.
A Safety Case Before the Launch Button
Under the proposed enforcement system, major platforms would have to send the Commission and an independent auditor a safety plan before launching a new service or feature. The Commission could require changes, fast-track investigations would have to finish within 90 days, and fines could reach 6% of global annual revenue.
Commission President Ursula von der Leyen describes this as reversing the burden of proof. Platforms would need to demonstrate that their services are safe for minors, instead of leaving regulators to establish harm after deployment.
That distinction changes the sequence of platform governance. Regulators usually meet a product after its recommendation system, notifications and growth loops have already reached millions of people. The Kids Act would insert a review point before large platforms release new features. Its effectiveness would still depend on how auditors define safety, what evidence companies must provide and whether regulators can examine systems that change continuously after launch.
The proposal also travels beyond the usual social-media suspects. App stores would have to age-rate every app and game using a published methodology, while online games, video-sharing services, AI companions and chatbots would face new obligations. PocketGamer.biz reports that default-off geolocation creates uncertain consequences for location-based games such as Pokémon Go. Users might be allowed to switch location sharing back on, but the draft’s practical treatment of that choice remains unclear.
Scope matters here. A rule covering TikTok-style feeds is one project. A rule covering social networks, app stores, multiplayer games and emotionally responsive chatbots is an ecosystem project. It asks several industries with different functions and risks to operate through one age-assurance layer. That could reduce loopholes between services, or create a compliance maze if regulators apply the same assumptions everywhere.
The 13-and-15 Split is a Political Fossil
The two age thresholds preserve the argument that produced them. Before the draft appeared, Commission experts supported 13 while France wanted 15. The resulting structure uses both: exclusion below 13, supervised access at 13 and 14, then independent accounts at 15.
The draft grew out of work by a panel of more than 60 experts established by von der Leyen in March. The Commission also cites a Eurobarometer result in which 92% of Europeans considered stronger online protection for children a top priority. That figure shows broad demand for action, although it doesn’t establish agreement on age checks, daily limits or the treatment of older teenagers.
Member states and Parliament still have to approve a final text. Estonia and Belgium have opposed blanket age-based bans, while the European Parliament previously called for a threshold of 16. The Commission’s compromise therefore begins negotiations with critics pulling in opposite directions: some reject age bans, while others want the line moved higher.
The enforcement architecture has its own history. Engadget’s account of the draft says Brussels would use structures established under the Digital Services Act, including penalties of up to 6% of global annual turnover. The Kids Act would layer prescriptive design requirements and faster investigations onto that machinery.
Bernhard Rohleder, CEO of German technology industry association BITKOM, argues that this overlap is a flaw. “Age verification remains a technical challenge, and parallel regulation to existing laws like the Digital Services Act is problematic and unnecessary,” he said.
That is the strongest administrative objection in the available debate. If the DSA can already compel platforms to assess and reduce risks to minors, another law could duplicate filings, oversight and enforcement. The Commission’s answer, embedded in the proposal’s structure, is that broad risk duties haven’t settled concrete questions such as whether minors should receive infinite scroll, nighttime alerts or chatbot relationship simulations. One regime asks companies to manage risks; this proposal would pre-decide several design choices.
Age Verification is Where the Neat Diagram Gets Messy
Every age tier depends on platforms knowing who belongs in it. New accounts would face age checks. Providers could estimate the ages of existing users through “reasonable proxies,” including account creation dates or credit-card details, and would have six months after the rules took effect to determine whether account holders were under 15.
The Commission’s proposed verification app uses zero-knowledge proofs, according to earlier reporting on the plan. In principle, that lets someone prove they meet an age threshold without handing an identity document to every platform. Apps would also have to avoid retaining identity documents or biometric data.
The privacy logic is coherent: reveal the eligibility result, withhold the identity. Implementation brings harder questions. The available reporting doesn’t establish the app’s error rate, its resistance to borrowed credentials, how appeals would work, or how reliably proxies such as credit cards distinguish teenagers from adults. A privacy-preserving system can still exclude eligible users or admit ineligible ones. It can also protect the verification transaction while platforms infer age from other account data.
France offers the closest warning. Its Constitutional Council blocked an under-15 national effort in August amid concerns reported as including proportionality, freedom of expression and inadequate protection of user data. President Emmanuel Macron then asked Brussels for an EU-wide rule. Australia’s under-16 restriction supplies another comparison, although reporting on the Kids Act cites Australia mainly as evidence that age verification remains difficult rather than providing enough detail to judge outcomes.
The French and EU approaches share an age threshold and the need to identify minors, but Brussels is trying a broader regulatory package and a different privacy architecture. Its zero-knowledge system appears designed to answer the data-protection weakness identified in France. That doesn’t establish that courts will accept the EU version, especially when the proposal also limits access and product features. It shows where the Commission has placed its bet.
The design rules may prove easier to audit than the ban. An investigator can check whether a minor account receives nighttime notifications or infinite scroll. Determining whether millions of users supplied an accurate age, without building a giant identity checkpoint, is a gnarlier assignment.
So the Kids Act’s fate won’t turn only on whether Europe chooses 13, 15 or 16. It will turn on whether Brussels can make platforms recognize childhood without making everyone surrender more of their identity at the door.
More Like This
EU AI Act: How to Tell If Your AI Is High-Risk
The EU AI Act's high-risk classification isn't just about what your AI does—it's about how it's deployed. Here's what organizations need to understand now.
Family Rules for Safer AI Use: What Kids Actually Need
A Psychology Today column argues kids need rules for AI: privacy, verification, disclosure, and asking an adult. Here is how that holds up for real households.
AI Compiler Writes 4,000 Commits: GitHub's Latest Tools
GitHub's trending projects reveal AI-generated compilers, censorship circumvention tools, and automation systems that raise regulatory questions.
UK's AI Chatbot Regulation: A Closer Look
Exploring UK's proposed AI chatbot regulations and their impact on children's online safety.
Age Verification Laws Are Coming for Your Operating System
California and other states are passing laws requiring age verification at the OS level. Open-source developers are scrambling to respond.
Steam's Australian Credit Card Age Check Locks Out Adult Players
Steam's Australian age check now requires a credit card and nothing else. Millions of adults lack one, and players are angry about being locked out of R18+ games.
GNU Coreutils Now Run Natively on Windows
Microsoft has ported GNU Coreutils to Windows as native binaries. Here's what that means for devs switching between Linux and Windows daily.
iOS 27 Beta 1 Hands-On: Cool Features, No Siri
iOS 27 Beta 1 is here with Photos AI tools, Liquid Glass tweaks, and Wallet upgrades — but the new Siri everyone wants? Still on a waitlist.