+40-31 437 80 13
office@baciupartners.ro

EU KIDS Act: new standards for the protection of minors online

September 2026

by Adela Nuță

On 17 September 2026, the European Commission presented its proposal for the EU KIDS Act. This new Regulation would add a distinct layer of protection for minors on top of the architecture already established by the Digital Services Act (“DSA”) and the AI Act.

The 15-year threshold is, inevitably, what draws the most attention. The proposed change, however, is considerably broader. The KIDS Act seeks not only to set the age at which a minor may create an account on their own, but to change the way digital services are designed for minors.

The proposal comes against the backdrop of a proliferation of national initiatives on the protection of minors online. These initiatives are built around age thresholds and design standards that differ from one Member State to another. In this context, the Commission seeks to establish a harmonised framework at Union level that would replace these divergent approaches with a common set of rules, directly applicable in all Member States.

A scope broader than social media

The KIDS Act would cover online social networking services, video-sharing platform services, software application stores, online games and operating systems, as well as AI companions and general conversational chatbots, insofar as they are accessible to minors.

For digital services, a provider established outside the Union is not taken outside the scope of the Regulation where the service is offered to recipients of the service located in the Union. A similar rule applies to providers placing AI companions and general conversational chatbots on the market or putting them into service in the Union. The exemptions include, among others, not-for-profit online encyclopaedias, certain educational and scientific research services, open-source software-developing and -sharing platforms, and certain services and systems operated by public authorities.

15 as the new threshold for autonomous accounts

The central rule prevents minors below the age of 15 from creating their own account on online social networking services and video-sharing platform services that pose a risk to their privacy, safety or security. Such services include those that enable real-time transmission of content, including live streaming, contact with recipients outside the minor’s pre-existing connections, recommender systems based on profiling, or uninterrupted content consumption. Between 13 and 15, a guardian may set up an account with limited features. Such an account has the tools for guardians always activated, allows the guardian to pre-approve new contacts and is subject to a daily limit of no more than one hour. Below 13 there are no accounts, save for one exception. That exception is guardian-controlled access through the guardian’s own account to video-sharing platform services specifically designed for minors below the age of 13, from the age of 3. Existing accounts must be checked within 6 months of the date of application of the KIDS Act. The accounts of recipients established to be below 15, or whose age cannot be established, will be disabled.

From “privacy by default” to “child safety by default”

The most significant practical change is that in-scope services must be designed by default in accordance with the safety by design requirements for all recipients of the service. The provider may derogate from those requirements only after it has established, by means of age assurance, that the recipient of the service is an adult. On online social networking services and video-sharing platform services, addictive design is prohibited. This covers automatic play of content without effective interruption moments, notifications designed to prompt the minor to resume use of the service, and “streak” mechanics. Recommender systems relying by default on engagement-based signals are prohibited, as are variable reward systems in economic transactions. Purchases made with virtual currency must also display the corresponding monetary value in the national currency. Geolocation, camera, microphone and push notifications are turned off by default. Other recipients of the service cannot initiate direct contact with a minor without the minor’s pre-approval, and minors cannot, by default, host live streaming.

Monetisation also comes under the Regulation’s scrutiny

The KIDS Act treats the minor not only as a recipient of a digital service but also as a vulnerable consumer. Before an economic transaction takes place, the minor should therefore be made aware, clearly and in real time, that it is an economic transaction. For virtual currency purchasable with funds, the corresponding monetary value should also be displayed in the relevant official currency. For certain services, the proposal also seeks to prevent design, organisation or operation choices that may lead to excessive, impulsive or unwanted spending, including exposure to variable reward systems.

AI companions: emotional dependency becomes a regulated design issue

For AI companions and general conversational chatbots, the proposal introduces obligations that go well beyond mere transparency on the use of artificial intelligence. Systems would have to be designed so that minors are not exposed to design features and system behaviours that simulate interpersonal relations likely to create emotional dependencies. By default, the system could not use, in subsequent interactions, information or analysis derived from a minor’s prior interactions. The only exceptions are where this is necessary to protect the minor’s safety or to give effect to the safe settings.

Providers would also have to carry out evaluations and testing of these systems prior to placing them on the market or putting them into service. In the cases provided for by the Regulation, they would also have to carry out post-market monitoring to identify risks to minors. Where an AI companion or general conversational chatbot is deployed as a functionality of an online social networking service, a video-sharing platform service or an online game, it should not be activated automatically and minors should not be encouraged to use it. Minors should also be able to opt out easily and at any time.

Age verification without turning it into an identification mechanism

A system based solely on the question “Are you over 15?” would no longer suffice. For the 15-year threshold, providers must rely exclusively on EU age verification solutions provided by third parties and certified as conforming with the EU Age Verification Scheme. These include European Digital Identity Wallets. The solutions are based on zero knowledge proof and do not enable the identification, location or profiling of the recipient of the service. Providers of operating systems will be required to enable the sharing of the age signal with in-scope providers, after obtaining the user’s consent.

Member States, in turn, would have to ensure that citizens and residents have access, free of charge, to at least one EU age verification solution. They would also have to establish a privacy-preserving electronic means by which a guardian can obtain and present an attestation of parental responsibility.

Enforcement and sanctions within the DSA and AI Act architecture

The KIDS Act relies largely on the supervision and enforcement mechanisms already established under the DSA and the AI Act. For online social networking services and video-sharing platform services designated as very large online platforms, providers would have to notify the Commission of a compliance plan audited by independent auditors. In cases falling within the Commission’s direct competence, the proposal also provides for an expedited procedure. Under this procedure, preliminary findings are communicated within 30 working days and a final decision is adopted within 90 working days.

Depending on the category of provider and the applicable regime, fines could reach up to 6% of the total worldwide annual turnover. Data protection supervisory authorities would also remain competent for the processing of personal data in connection with age assurance.

What comes next

The KIDS Act is at the beginning of the EU legislative process and may be amended in the negotiations between the European Parliament and the Council. As currently drafted, the Regulation would in principle apply six months after its entry into force, although this timeline is not yet final. Beyond the legislative calendar, the direction is already clear. For in-scope providers, compliance would require not only adjustments to age assurance processes but also changes to product design, recommender systems, default settings and monetisation mechanisms.


Details about our Data Privacy practice are available HERE.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.