The proposed EU KIDS Act would introduce a more structured approach to children's access to high-risk online services. Its central idea is simple: social media and similar services should not treat a seven-year-old, a fourteen-year-old and an adult as if they face the same risks or need the same protections.
The proposal is not law yet. But it points to a clear policy direction in Europe and beyond: platforms may increasingly need to prove that their services are appropriate for young users, rather than relying on a date-of-birth field and general terms of service.
What is the EU KIDS Act?
The EU KIDS Act is a European Commission proposal for stronger protections for children using digital services. It would cover social media, video-sharing services, online games, AI chatbots and AI companions, while educational tools are expected to sit outside its main scope.
The proposal uses a graduated model rather than one single rule for everyone under 18:
| Age group | Proposed access model |
|---|---|
| Under 3 | No access to social media and other high-risk services |
| 3 to 12 | Child-friendly services only, through accounts controlled by a parent or guardian |
| 13 to 14 | Parent-created and supervised introductory accounts, with limited features, contacts and time controls |
| 15 to 17 | Independent accounts, but services must be safe by design for minors |
| 18+ | Standard adult access |
The headline rules are "no social media under 13" and "no personal account under 15". In practice, the proposal is less a blanket ban than a framework for age-appropriate access.
Why is the EU taking this approach?
The Commission is responding to concerns about harmful content, unwanted contact, compulsive design, recommender systems, targeted advertising, privacy risks and the impact of some online experiences on young people.
The important shift is responsibility. The proposal would move the burden towards providers. A platform would need to show that its design, controls and safeguards are suitable for the age group it serves.
This matters because age limits in terms of service have often been easy to bypass. A meaningful model needs more than an age gate. It needs an account design that changes what a child can see, who can contact them, which recommendations they receive, how much data is collected and how easily a parent or guardian can support them.
How does it fit with existing EU rules?
The EU already has rules that protect children online, but they do not set one general minimum age for social-media accounts.
The GDPR sets rules for children's consent to information-society services. The default age is 16, although EU Member States can set it as low as 13. The Digital Services Act requires online platforms accessible to minors to take appropriate and proportionate measures to ensure a high level of privacy, safety and security for children.
In 2025, the European Commission issued guidance under the Digital Services Act on protecting minors. It recommends age assurance that is accurate, reliable, robust, non-intrusive and non-discriminatory. It also distinguishes between age verification, where a service checks a precise age or threshold, and age estimation, where it assesses whether someone is likely to be within an age range.
The EU KIDS Act would build on this direction by setting clearer access categories and more explicit expectations for high-risk services.
How does it compare globally?
Countries are increasingly regulating children's online experiences, but they are not taking identical approaches. Some focus on account access. Others focus on data protection, harmful content, product design or parental controls.
| Jurisdiction | Main approach | Key age point | What it means for providers |
|---|---|---|---|
| European Union, proposed EU KIDS Act | Graduated access and safe-by-design duties across social media and other high-risk services | No social media under 13. Independent accounts from 15 | Design age-specific accounts, controls and safety features. Demonstrate protection for minors |
| Australia | Statutory minimum age for accounts on age-restricted social media | Under 16 | Take reasonable steps to stop under-16s creating or keeping accounts. The provider, not the child or parent, carries the compliance burden |
| United Kingdom | Online-safety duties, risk assessment and highly effective age assurance for relevant harmful content | No single general social-media age in the Act | Assess risks to children, enforce stated age limits and prevent children accessing pornography and other harmful content where required |
| United States, federal COPPA | Children's privacy and verifiable parental consent | Under 13 | Obtain parental consent before collecting, using or disclosing covered children's personal information. It is not a general social-media access ban |
| California | Age-appropriate design and high-privacy defaults for services likely to be accessed by children, subject to ongoing litigation | Under 18 | Consider children's privacy and well-being in product design, including protective defaults and age estimation requirements where enforceable |
| China | Device and app-level "minor mode" with parental controls and age-based limits | Under 18 | Provide child modes, content filters, time controls and parental mechanisms, with a more centrally directed model than in Europe |
Australia: the clearest account-access comparison
Australia is currently the closest operational comparison. Since 10 December 2025, age-restricted social-media platforms have had to take reasonable steps to prevent Australians under 16 from creating or keeping accounts.
The law places the obligation on platforms. Children, parents and carers are not fined for access. Platforms can face penalties of up to AUD 49.5 million if they fail to meet their obligations.
The EU proposal differs in one important respect. Australia's approach is largely based on a single account threshold. The EU proposal would create different account types and safeguards at different stages of childhood and adolescence.
United Kingdom: focus on risk and enforcement
The UK Online Safety Act does not create a universal ban on social-media access below one age. Instead, it requires services to assess risks to children, enforce the age limits in their own terms consistently and protect child users from harmful content.
For services that allow pornography, age assurance must be highly effective. Ofcom describes age assurance as including age verification, age estimation or both. The UK Government has also announced an intention to require social-media services to use highly effective age assurance to prevent under-16s from accessing them.
This approach is useful because it links age checks to the actual risks of a service. Its weakness is that the outcome can be harder for users and providers to understand when duties vary by service, content and risk assessment.
United States: privacy protection, not a general access rule
The United States has a long-standing federal rule, COPPA, which applies to online services directed at children under 13 and services that know they collect personal information from children under 13.
COPPA requires verifiable parental consent before covered personal information is collected, used or disclosed. It is primarily a privacy law. It does not generally prohibit a child from holding a social-media account, and it does not create a graduated account model for teenagers.
This is an important distinction. A platform can comply with privacy consent rules while still offering an experience that is poorly designed for young users. The EU KIDS Act appears intended to address both access and product design.
China: a broader system of controls
China's "minor mode" uses device and app-level controls. It includes age-appropriate content filtering, usage limits, options to restrict communication with strangers and parental verification to change or exit certain settings.
It shares the EU proposal's interest in graduated protection and design controls. But it operates within a more centralised regulatory and content-governance environment. European implementation will need stronger safeguards for privacy, proportionality, children's rights and freedom of expression.
What will be difficult in practice?
The policy goal is understandable. The difficult question is how to implement it without creating a new system of routine identity surveillance.
Age assurance must protect privacy
A platform should usually need to know only whether a person meets a particular age threshold, not their full identity, home address or identity-document number. The most privacy-respecting systems should support a limited proof, such as "over 15", rather than a reusable record of who the person is.
The European Commission's age-verification work moves in this direction. Its stated aim is anonymous proof-of-age technology with strong privacy and data-protection safeguards. The EU's age-verification blueprint is intended to give Member States and providers a common technical starting point.
A date of birth is not enough
Self-declared age is easy to evade. But collecting identity documents or biometrics from every user can also create serious security and privacy risks. Providers will need a proportionate approach based on the service and the risk.
For example, a public platform that allows direct messages from strangers and uses engagement-driven recommendations may need stronger controls than a low-risk educational community with moderated groups and no behavioural advertising.
"Safe by design" must be measurable
Safe by design should not become a vague statement in a policy document. For young users, it should translate into decisions that can be tested and audited, such as:
- Private-by-default accounts for minors.
- Restricted contact from unknown adults.
- Limits on recommendation patterns that promote harmful or compulsive use.
- No targeted advertising based on a child's profile.
- Clear reporting, blocking and support routes.
- Child-friendly explanations of settings and risks.
- A documented process for assessing child-safety and data-protection risks before release.
What should platforms and organisations do now?
Organisations do not need to wait for the final text before improving their approach. The most useful preparation work is product, governance and evidence work.
- Map where children and teenagers can enter the service. Check sign-up, account recovery, direct messages, recommendations, advertising, payments, creator tools and AI features.
- Define age bands. Avoid treating all users under 18 as one group. Identify which features should be unavailable, limited, supervised or redesigned for each band.
- Review your age-assurance approach. Document why it is proportionate to the risk, how it minimises data collection, how long data is retained and how users can challenge an incorrect result.
- Make safety defaults real. Test privacy settings, contact controls, reporting flows and recommendation systems with young users and trusted child-safety experts.
- Connect privacy, product and security governance. Age assurance may involve sensitive data, identity providers, device signals or third parties. It needs data-protection impact assessment, supplier assurance, access controls, retention rules and incident planning.
- Keep evidence. Record risk assessments, design decisions, test results, complaints, safety metrics and changes made after incidents. "Safe by design" will need demonstrable evidence, not only good intentions.
What are the main conclusions?
The EU KIDS Act signals a move away from the false choice between unrestricted access and a single age ban. Its graduated model recognises that young people's needs change with age and that products should change with them.
Its success will depend on three things.
First, the final rules must be clear enough for families and providers to understand. A complicated set of overlapping age categories, national exceptions and platform-specific interpretations would be difficult to enforce fairly.
Second, age assurance must remain privacy-preserving. Measures intended to protect children should not make identity checks and personal-data collection routine for everyone.
Third, enforcement must look beyond sign-up. A child-safe service is not created by asking for a date of birth. It is created through the defaults, features, incentives and safeguards that shape the experience after the account is opened.
For organisations building digital products, the practical lesson is straightforward: design for age-appropriate use from the beginning, minimise the data needed to provide protection and keep evidence that the approach works.
How Boxfish Labs can help
Boxfish Labs works on practical cybersecurity, privacy and digital-safety capability. Its interactive awareness resources cover topics including scams, phishing, privacy, passwords, safer browsing and digital habits, using short scenarios, mini-games and guided learning content.
For organisations responding to child-safety and age-assurance expectations, this type of work can support the human side of compliance: helping teams, parents, educators and everyday users understand online risks and make safer decisions. It should complement, not replace, secure product design, privacy governance and effective platform controls.
FAQs
No. It is a proposal. The Commission still needs to publish and progress the legal text through the EU legislative process. The final scope, obligations, timetable and enforcement details may change.
Not in the same way for every age group. Under-13s would not have social-media access. Users aged 13 and 14 could use restricted, parent-supervised introductory accounts. From 15, minors could open their own accounts, subject to safe-by-design protections.
Not necessarily. The stated European direction is toward privacy-preserving age assurance. The appropriate method should depend on the risk and should aim to prove an age threshold without collecting more personal information than necessary.
Parental involvement can help, especially for younger teenagers. But consent alone does not make a product safe. Platforms still need appropriate defaults, limits on harmful features, clear safeguards and accountable design decisions.
Start with a simple child-safety review. Identify whether minors use the service, what data is collected, which adult-to-child contact paths exist, how recommendations work and whether defaults are genuinely protective. Then prioritise the highest-risk changes before adding complex age-assurance technology.
