By Dan Cooper, Dita Charanzová, Jadzia Pierce, Anna Sophia Oberschelp de Meneses, Shona O’Donovan, Sam Jungyun Choi, Virginie de France & Edwin Djabatey on September 21, 2026
Posted in Children’s Privacy, European Commission, Online Safety
On September 17, 2026, the European Commission (the “Commission”) published its proposal for a new EU framework on child safety online (the “KIDS Act”). The proposed Regulation aims to introduce EU-harmonized age-based account restrictions, safety-by-design rules, and age-assurance obligations across a broad range of digital services and systems.
The proposal is the latest of a growing body of initiatives aimed at strengthening children’s safety and privacy in the digital world, both in the EU and globally, as discussed in our recent blog post.
This post summarizes some of the KIDS Act’s key features.
Scope
The KIDS Act, as proposed, would have broad extraterritorial reach and apply to the following services (collectively, “Covered Services”):
- online social networking services;
- video-sharing platform services;
- software application stores (i.e., app stores);
- online games;
- operating systems;
- AI companions (i.e., AI systems, including general-purpose AI systems, that provide sustained, personalized interaction or companionship and simulate or facilitate social, emotional or interpersonal relationships with users); and
- general conversational chatbots.
The proposal also establishes some exclusions for services and systems that, in the Commission’s view, are unlikely to pose significant risks to children (i.e., any natural person under the age of 18). These include certain open-source software development and sharing platforms, and services and systems specifically developed and operated exclusively for scientific research and development.
The Framework
The proposal “specifies and complements” the EU Digital Services Act (“DSA”) (particularly Article 28) and “complements” the EU AI Act. The KIDS Act would establish two main sets of obligations for in-scope digital service providers operating in the EU: (1) delaying children’s access to certain social networking and video-sharing platform services; and (2) embedding child safety into the design and operation of in-scope digital services.
1. Delaying children’s access to certain social networking and video-sharing platform services
The KIDS Act would generally prohibit users under the age of 15 from creating accounts with and having access to certain social networking and video-sharing platform services, with limited exceptions. The applicable exceptions would depend on the child’s age and, in some cases, require a parent or guardian to authorize and manage their child’s access to the service. Where a parent or guardian creates or manages an account for a child, the provider would be required to take measures to verify that the adult holds parental responsibility for that child.

How Would Age and Parental Responsibility Be Verified?
Providers of Age-Restricted Services would be required to rely exclusively on third-party EU age verification solutions using EU proof-of-age attestations certified under the “EU Age Verification Scheme” for purposes of complying with the under-15 ban and its derogation for 13-14 year olds. The Commission would maintain and publish EU-wide lists of certified age verification solutions and providers of proof-of-age attestations. The proposal further provides that European Digital Identity Wallets certified under the eIDAS framework and compliant with the EU Age Verification Scheme are deemed certified for these purposes. For purposes of compliance with the more broadly applicable safety-by-design obligations and app store requirements, providers are permitted to use alternative age-assurance solutions so long as they meet certain standards (to be further specified by delegated acts).
Notably, within six months of the KIDS Act taking effect, providers of Age-Restricted Services would be required to establish whether holders of existing accounts are under the age of 15. These providers would need to disable accounts where the user is determined to be under 15, as well as accounts where the user’s age cannot be established. Those providers designated as Very Large Online Platforms (“VLOPs”) under the DSA would also be required to submit a detailed compliance plan that, per Recital 62 of the KIDS Act, must corroborate, from a technical and robust evidentiary perspective, the “high degree of confidence” standard for determining whether the recipient has reached the age of 15.
The KIDS Act proposal also establishes a framework for verifying parental responsibility where a user seeks to create or manage an account on behalf of a child. Providers may rely on public registries, existing parental relationship signals, or (for a time) self-declarations subject to reasonable verification measures, provided that the process remains privacy-preserving and does not enable the provider to track, profile, or geolocate the adult or child concerned.
2. Embedding Child Safety into Product Design
All providers of Covered Services (except operating systems) would generally be required to implement a range of measures aimed at ensuring a high level of privacy, safety and security for children. The applicable requirements would vary depending on the type of service.

What about Operating Systems?
Unlike other Covered Services, operating systems would not be subject to the general safety-by-design obligations described above. Instead, where a provider of an operating system has obtained an age signal through age assurance that complies with the KIDS Act proposal’s requirements, it would be required, with the user’s consent, to enable the sharing of that age signal with providers of Covered Services where necessary for compliance with the KIDS Act proposal.
What Other Rights, Governance and Compliance Obligations Would the KIDS Act Proposal Introduce?
The proposal would also introduce a number of measures aimed at strengthening children’s control (so-called “agency”) over their online experience. These measures would vary depending on the type of service concerned.
- Greater transparency and control for children. Providers of online social networking services, video-sharing platform services, online games, AI companions and general conversational chatbots would be required to present information, warnings, settings and user controls in a child-friendly and accessible manner. These providers would also be required to offer tools enabling children to influence the content and recommendations they receive, manage their settings, and easily revert to safer default configurations.
- Codes of conduct. The Commission would facilitate the development of voluntary, EU-level codes of conduct. Codes specifically addressing age-rating and online games (Article 17) should be drawn up within one year of the date of application (i.e., approximately 18 months after entry into force). The proposal identifies the Pan-European Game Information (“PEGI”) age-classification system and code of conduct as potential examples, subject to a finding that they provide an adequate level of protection for children. As part of the release of the KIDS Act, the Commission also announced plans to develop a child-safety code of conduct for AI, focused specifically on designing algorithms suitable for children.
- Additional governance obligations for VLOPs. One of the most significant changes in the KIDS Act is the shift in the compliance burden—rather than relying on regulators to identify and prove that a service is unsafe or non-compliant, the proposal requires certain providers to demonstrate proactively how they comply with the child-safety requirements. For DSA-designated VLOPs that are online social networking services or video-sharing platform services, this means being required to submit compliance plans to the Commission and engage independent experts to audit those plans, with corrective action plans required within 30 days where deficiencies are identified (a process that the Commission itself has referred to as a reversal of the burden of proof). The proposal would also introduce a supervisory fee for in-scope VLOPs as well as certain providers of AI companions, general conversational chatbots, and video gaming platforms, capped at 0.03% of worldwide annual net income.
Enforcement
The KIDS Act proposal would largely rely on the existing enforcement frameworks under the DSA and AI Act, with the applicable framework depending on the service or system concerned.

Collective complaints
Children and their guardians would be able to flag suspected violations of the KIDS Act by most providers, including through complaints submitted to national authorities and, for AI companions and general conversational chatbots, the European AI Office. They could also appoint qualified representative bodies to exercise their rights on their behalf, as the proposal would bring the KIDS Act within the scope of the Representative Actions Directive (Directive (EU) 2020/1828).
Looking ahead
The proposal is a high political priority for the Commission and is likely to attract significant attention as it is negotiated in both the European Parliament and the Council. Given the political momentum around the protection of children online, we can expect efforts to move the negotiations forward relatively quickly.
If adopted, the Act would require covered providers to change account architecture, implement age-assurance processes, adjust recommender systems, add parental-control tools and develop product-development governance procedures (among other things). We will continue to monitor the KIDS Act and report on its progress.




























