KontorBund — Note
The EU Kids ActLast checked 4 October 2026
kontorbund.com/notes/eu-kids-act.html
The EU Kids Act: what the Commission proposed on 17 September 2026 — and the 26 November feedback deadline
The short version
On 17 September 2026 the Commission published a proposal for a
Regulation it calls the EU KIDS Act — COM(2026) 681,
procedure 2026/0286(COD). It would set EU-wide age rules for the
online services children use: seven categories of service in scope, no
account of your own under 13, a guardian-controlled account with a
one-hour daily cap at 13 and 14, an account of your own from 15,
and certified age assurance instead of a date-of-birth box. It
deliberately drops the small-enterprise carve-out the DSA gives its
youth-protection duties. None of this is law. It is a proposal with
Parliament and Council, any of it can change, and the Commission's feedback
window closes on 26 November 2026.
What was proposed
On 17 September 2026 the Commission published a proposal for a
Regulation whose full title is the EU KIDS Act — 'EU Keeping Internet
Digital Spaces Accountable and Trustworthy'. It carries the document
number COM(2026) 681 final, was given the legislative procedure
number 2026/0286(COD), and was submitted to the European
Parliament and the Council. Its legal basis is Article 114 TFEU, the internal
market article — so the argument for acting at EU level is that twenty-seven
national age rules would otherwise fragment the single market.
The Commission describes it as two halves. First, common age rules: who may hold an account on their own. Second, safety by design: how the services themselves have to be built. Alongside that, the proposal reverses the burden of proof for the largest platforms — those with 45 million or more monthly active users in the EU must file a compliance plan and have it checked by independent auditors, at their own expense, before the service reaches children under the new rules.
- Document
COM(2026) 681 final, published 17 September 2026, with the accompanying analysis of impactsSWD(2026) 681 final.- Procedure
2026/0286(COD)— the ordinary legislative procedure. The proposal is with the European Parliament and the Council.- What it would be
- A Regulation: directly applicable in every member state once adopted, with no national transposition. Not binding law today.
- If adopted, when it would apply
- Article 43 says twenty days after publication in the Official Journal it enters into force, and applies from six months later — written as a bracketed placeholder, so even that is not fixed. Article 5 would apply from entry into force; Articles 33 and 35 after twelve months.
- The one date that is real now
- 26 November 2026, midnight Brussels time — the end of the Commission's feedback period on the proposal. See the deadline section.
The seven categories in scope
Article 2(1) of the draft lists the services and systems it would cover — seven of them, and only those that are accessible to minors, a minor meaning anyone under 18 (Article 3):
- (a) Online social networking services
- The definition is taken from the Digital Markets Act (Article 2 of Regulation (EU) 2022/1925).
- (b) Video-sharing platform services
- Defined as in the Digital Markets Act. Along with social networks and app stores, it counts as an online platform for this Regulation (Article 3(2)).
- (c) Software application stores
- App stores. Defined as in the Digital Markets Act, and an online platform for this Regulation.
- (d) Online games
- A video game or a video gaming platform. The definitions are broad enough to reach a great deal, including titles that are not "social" in any obvious sense.
- (e) Operating systems
- Defined as in the Digital Markets Act.
- (f) AI companions
- A system providing sustained, personalised interaction that simulates or facilitates a social or emotional relationship.
- (g) General conversational chatbots
- General-purpose systems able to help across many tasks. Chatbots limited to one specialised job, such as customer service or technical support, are expressly excluded.
The duties are not the same for all seven. App stores, for example, get age-rating duties rather than the account rules; providers of operating systems have essentially one obligation in the draft — if they hold an age signal for a user, they must let that user consent to passing it on to in-scope providers (Article 29(6)) — plus the general anti-circumvention duty in Article 4.
Scope is extraterritorial in the DSA's sense: for the five service categories it attaches to providers offering their service to recipients who are established or located in the Union, not to where the service is accessed from. On a plain reading that follows an EU-based child on holiday outside the EU as well. Providers outside the EU are covered; Article 24 would additionally require a legal representative in a member state.
- What Article 2(4) exempts
- Not-for-profit online encyclopaedias (the reference is understood to mean Wikipedia); not-for-profit educational and scientific repositories; services and systems that are primarily educational and run by educational establishments; open-source software-developing and sharing platforms unless the platform is itself an in-scope AI system; services developed and operated solely for scientific research; and systems operated by public authorities for their own use.
- What that exemption does not do
- It does not exempt a social network because its software is open source. A Mastodon instance is a social network, not a development platform. Likewise, not-for-profit status is a factor in the exemptions above, not a general defence.
- And it does not exempt your size
- Unlike the DSA, there is no carve-out for small and micro enterprises. That is the section most worth reading — it is the point of the proposal, not an oversight.
The three age tiers
The age rules in Article 6 do not apply to everything in scope. They attach to online social networks and video-sharing platforms that show at least one of the risk features the article lists. A single one is enough. The listed features include letting account holders stream live to an indeterminate audience, letting them contact people outside their existing connections, using a recommender system built on profiling, suggesting contacts or content from outside those connections, and designs that encourage uninterrupted consumption or pull the user back with notifications.
- Under 13
- No account of their own. One narrow route remains, and only on video-sharing services designed specifically for young children: a guardian may allow limited access through the guardian's own account, with no account attributed to the child, personalisation and recommender features off, a daily limit of up to one hour, and the guardian able to stop access at any time (Article 7).
- 13 up to 15
- A guardian may set up a limited-features account. The guardian's tools are always on, the guardian can set a daily time limit that may not exceed one hour per day, and the guardian pre-approves new contacts and can cap how many contacts the account has (Article 6(2)). The provider must check that the person opening the account actually holds parental responsibility (Article 26).
- 15 up to 18
- A young person may hold an account of their own without prior parental consent — but the service must by law be safe for them. Protections still run to the eighteenth birthday.
- Existing accounts
- Within six months of the rules applying, providers must establish whether existing account holders are below 15, and disable the accounts of those who are, or whose age cannot be established (Article 6(4), with Article 32). Where a provider can already tell with high confidence that a user is an adult, no new check is required — so most adults would notice nothing.
Age assurance and the EU app
A date-of-birth box would not be enough under this draft — the Commission says self-declared age is explicitly not sufficient. Article 29 requires the providers covered by Article 6 to use an EU age verification solution with an EU proof of age attestation, provided by a third party, certified against the EU Age Verification Scheme and listed by the Commission (Article 30). App stores must also assess the age of the user to keep age-inappropriate apps away from minors (Article 16(4)).
The privacy architecture is unusually explicit for a draft. Article 28 says age assurance "shall not enable the identification of the recipient nor locate, track, target, advertise to or profile recipients", forbids keeping or combining more data than necessary, and says in terms that any age assurance measure shall be zero knowledge proof. The Commission is building the scheme itself as open-source technical requirements for a stand-alone mobile age verification app, and points to the European Digital Identity Wallet as a later route.
- What the service learns
- Whether the user is above or below the age threshold — no name, no date of birth, no identity documents.
- What a member state must provide
- Under Article 31(5), at least one certified EU age verification solution must be available to citizens and residents free of charge. The guardian route is separate: member states must also provide a free, privacy-preserving way to attest parental responsibility (Article 31(1)).
- Where the age check happens
- When a new account is opened. For games, the age question is pushed to the app store — see below.
Safety by design
The larger half of the draft is not about who gets in but about what the service does once they are there. Article 8 sets the general duty; Articles 9 to 12 and 20 specify it. The Commission names the techniques rather than describing them in general terms:
- Addictive design
- For minors, services may not be designed to encourage compulsive or excessive use. The explainer lists what that means: endless autoplay and infinite scrolling without real breaks, notifications designed to pull a child back, rewards for posting or streaming to mass audiences, and streaks that penalise a child for not returning daily.
- Settings, on by default
- Article 11 requires high privacy, safety and security settings for minors by default — geolocation and other tracking off, microphone and camera access off, contact recommendations and contact sync off, and push notifications off and in any case timed to protect sleep hours and school time. A provider may only change those defaults where the minor is above 15.
- Contact and visibility
- Nobody may open direct contact with a minor who has not pre-approved it. Minors do not appear in contact suggestions, cannot be added to groups without explicit agreement, and can block anyone without their identity being disclosed (Article 12(1)). By default only people the minor has accepted can see their account or content, and people without an account cannot access a minor's content at all (Article 12(3)). Others must not be able to download or capture a minor's content.
- Feeds
- Recommender systems must be optimised for safety, quality and mental health rather than engagement; recommendation based on engagement signals is off by default, and minors must be able to choose at least one recommender option that is not based on profiling (Article 10).
- AI companions and chatbots
- Article 14 forbids designs that simulate relationships in ways likely to create emotional dependency, bars carrying a child's earlier conversations into later ones by default, and requires testing before launch and monitoring afterwards. Built into a platform or a game, a companion or chatbot may not switch on automatically, may not be pushed at children, and must be easy to turn off.
- Guardian tools
- Article 20 requires effective guardian tools on every service in scope — screen time, seeing and approving contacts, managing settings, and reporting harmful content on the child's behalf. On the 13-and-14 accounts they are always on. The tools complement the provider's own duties; they do not replace them.
No small-business exemption
This is the part of the proposal that matters most to small operators, and it is not an accident. The explanatory memorandum says it in one sentence:
In the Commission's own words
"At the same time, small and micro enterprises are not exempted from this Regulation, since they may equally provide harms to minors. It would undermine the objective of this proposal to exclude them from scope."
That is a deliberate departure from the DSA, which keeps micro and small enterprises out of its youth-protection duties. The Commission's memo acknowledges that many small providers "were previously not subject to Article 28 of the Digital Services Act".
- What a size test would have done
- Nothing here turns on turnover, headcount or user numbers for the core duties. A five-person game studio and a platform with a hundred million users read the same obligation.
- The one carve-out that survives
- Article 14 exempts micro and small enterprises from the post-market monitoring duty for AI companions and general conversational chatbots. It is the only such exemption we found in the operative text.
- Where size does still matter
- The compliance-plan and audit regime applies to very large online platforms — 45 million or more monthly active users in the EU. The Commission notes those duties should in principle not touch SMEs, whose user base does not reach that scale.
- Enforcement
- For online platforms the draft builds on the DSA's enforcement machinery; for AI companions and chatbots on the AI Act; for video games that are not online platforms, on national authorities designated by member states. Fines can reach 6% of total worldwide annual turnover, with an expedited procedure for Commission-supervised services — preliminary findings within 30 days and a final decision targeted within 90.
What it would mean for games
Online games are one of the seven categories, defined as a video game or a video gaming platform. Their obligations come mainly through Article 15 and the app-store rules in Article 16.
- Safety by design, applied to a game
- Providers must ensure compulsive or excessive use is not encouraged, apply high-privacy default settings, put contact safeguards in place between minors and other players, and give guardian tools — with access by under-13s only enabled and controlled through those guardian tools.
- Per-game age ratings, enforced at the store
- Article 16 requires every app store to run an age-rating system covering each software application it offers, to refuse minors access to or purchase of applications inappropriate for their age, and to assess the user's age in order to do so. In practice the age recommendation for a game is checked by the store before the download, not inside the game after it.
- Monetisation
- The standalone rules on economic transactions in the draft apply to social networks and video-sharing platforms, not to games. Monetisation practices in games are left to codes of conduct, which Article 17 also uses for age rating.
- What the industry says
- Video Games Europe cautioned against "sweeping age assurance measures applicable to every game and player in Europe". We quote the trade body's criticism as it was reported; it is not our characterisation of the draft.
The definition is wider than "online game" sounds
The draft's definitions of video game and video gaming platform are broad enough to reach far beyond always-online titles — including, on a commentator's reading, games with a classic online multiplayer mode, and older titles that still have a server. Nothing in the text we have read limits the duties by release date or by the size of the player base, and there is no grandfathering clause. That is a reading of draft wording, not a settled outcome, and it is exactly the sort of thing the parliamentary process could change.
What it would mean for small servers
The Fediverse — the network of independent servers running software such as Mastodon — is where the removal of the size exemption bites hardest in practice, and the criticism is concrete.
The Austrian digital rights organisation epicenter.works published its analysis on 22 September 2026, under a heading of "Bye Bye Fediverse". Its argument: billion-euro corporations such as Meta, Google and Apple face the same requirements as small European providers; Wikipedia and Codeberg get their exemption, a decentralised network such as Mastodon does not. That means age verification for every single instance and every software marketplace, with all the administrative weight attached — infrastructure a server with a few hundred users cannot afford, while a Meta or TikTok pays it from petty cash. Their conclusion is blunt: the smaller operators either shut down or throw young people out of the open, privacy-friendly parts of the internet.
There is a genuine technical conflict behind that, not just a political one.
Article 12(3) requires that recipients without an account must not be
able to access a minor's content, and that by default only previously accepted
users can. In ActivityPub, the protocol under most of the Fediverse, a post
addressed to the special Public recipient must be accessible
without authentication — that is what the W3C recommendation says. A minor's
account could therefore not address posts to Public. Because the
protective defaults apply to every account that has not been established as an
adult, that would reach beyond minors until the age check has happened.
- Who owes the duty
- The operator of the instance, not the Mastodon project or the people who wrote the software.
- Whether an exemption applies
- Open-source development and sharing platforms are exempted; a social network running open-source software is not. This is the point on which epicenter.works' criticism rests and it follows from Article 2(4)(d).
- What federation cannot fix
- An origin server controls what it delivers and to whom, not what a remote server does with it afterwards. A screenshot cannot be unfederated. On a central platform the operator enforces its rules across the whole service; in a federated network it enforces them on its own server.
- Where the criticism goes further than the text
- The claim that every private instance will have to check ages does not follow automatically. Whether a private, non-commercial hobby server is even a covered social network depends on how the EU-law notion of an "information society service" — services normally provided for remuneration — applies to it. That is an open legal question, not a settled one, and the restricted account for 13-and-14-year-olds is something a provider may offer, not something it must.
How it fits with the DSA
The KIDS Act does not replace the Digital Services Act. The Commission's memorandum describes it as putting into hard law specifications it had already published as guidelines on the protection of minors under Regulation (EU) 2022/2065, and as particularising the Article 28 DSA duty to keep minors safe where that concerns safety by design and age assurance. The point of legislating, in the Commission's framing, is that guidelines are not enforceable in the same way.
- Who supervises what
- Social networks, video-sharing platforms and app stores are classed as online platforms for this purpose, and a video gaming platform too. Their KIDS Act obligations are supervised and enforced through the DSA machinery rather than a new regime. AI companions and chatbots fall under the AI Act. Video games that are not online platforms fall to national authorities.
- What large platforms gain
- An expanded set of duties: a compliance plan, independent audit, corrective action the Commission can order, enhanced age-verification requirements and interoperability of guardian controls.
- The age-verification app
- The EU age verification solution in Article 29 is the same technical scheme the Commission has been building separately — open-source requirements for a stand-alone app, with each member state obliged to make at least one certified solution available free of charge.
- The wider package
- The Act is one part of a child safety package that also includes a Digital Fairness Act and revisions to the Consumer Protection Cooperation Regulation and the Audiovisual Media Services Directive.
What we could not establish
We would rather say what we could not check than write around it.
- A campaign quote we are not repeating
- Several reports say the gaming-preservation campaign Stop Killing Games warned that the Act could "implode the whole video games industry". We could not open the original coverage or the campaign's own statement — the pages refused our requests and their press page is not published — so we do not quote it here. If you have the primary statement, send it and we will add it.
- Whether a private hobby server is in scope
- This turns on the meaning of an "information society service" and on facts about the individual server. No official answer exists yet, and we are not going to invent one.
- Whether open-source operating systems are covered
- The operating-system definition comes from the Digital Markets Act; whether free and open-source distributions fall inside it is not settled by the draft's text. Outside the EU that same question has already been answered in law, in opposite directions: see Age checks move into the operating system and the explainer Age verification and age assurance.
- What it will cost
- Nobody has a defensible number. The Commission's own analysis says the costs cannot be conclusively determined, especially for the many small providers involved, and works with a range of a few hundred to a few thousand euros for a ready-made age check.
- What the final text will say
- Everything above is the Commission's proposal as published. Parliament and Council amend; this file could look very different in a year.
The 26 November deadline
The Commission is collecting feedback on the proposal until 26 November 2026, midnight Brussels time. Its own explainer says the aim is to hear from children, parents, guardians, teachers and educators, as well as from the online platforms the proposal would cover. The Commission says the responses will be summarised and presented to the European Parliament and the Council to feed the legislative debate — which is why the window matters even though the file is already with the co-legislators.
- What it is not
- It is not a vote and it does not change the text by itself. It is evidence put on the record while Parliament and Council are still forming positions.
- What is useful in a response
- The Commission has to justify the impact. A concrete number — what an age check, an age-rating system or a compliance plan would cost your business, with the work it implies — is harder to argue with than a position. That is the same kind of figure our Observatory collects.
- If you miss it
- The legislative process continues without you. National and industry consultations, and the Parliament's own committee work, are the later doors — and they open less predictably.
Do not treat any of this as settled
Nothing in this note is legal advice, and nothing in it is a duty you owe today. The age tiers, the seven categories, the missing size exemption, the app-store enforcement and the application date are all draft. Plan what you can control — the design choices you would have to change, the age data you would have to handle — and read the text again when the Council position is published.
Sources
The proposal text, the Commission's press release and the Commission's own explainer are the backbone; everything interpretive is attributed to whoever said it. Where a source is secondary, we say so. We have read the proposal, the press release and the explainer for this page.
-
COM(2026) 681 final — Proposal for the EU KIDS Act (EUR-Lex) The authentic draft, 17 September 2026. Source for the scope in Article 2, the age tiers in Article 6, the safeguards in Articles 8–12, games and app stores in Articles 15–17, age assurance in Articles 28–32, the application date in Article 43 and the explanatory memorandum. Read in full for this page
-
European Commission — EU KIDS Act to restrict social media platforms' access to children in the EU The press release, 17 September 2026. Source for the publication date and for the reversal of the burden of proof
-
European Commission — The KIDS Act explained The Commission's own FAQ, last updated 2 October 2026. Source for the 26 November 2026 feedback deadline, the free EU age verification app, the named addictive-design techniques, the six-month check on existing accounts, and the 6% fine ceiling
-
European Commission — Proposal for EU KIDS Act and supporting documents The document library: the proposal, the analysis of impacts and the factsheet
-
Pinsent Masons — The scope of the proposed KIDS Act Secondary, legal analysis, 2 October 2026. Source for the seven-category list as a list, the exemptions, the operating-system duty, the DSA classification, and the Video Games Europe quotation
-
heise online — Age verification in the Fediverse: How the KIDS Act challenges Mastodon Secondary, technical analysis, 2 October 2026. Source for the ActivityPub conflict with Article 12, the verdict on the "every instance" claim, the cost estimate in the analysis of impacts and the role of the operator
-
epicenter.works — Zwei Fronten, ein Irrweg (German) The Austrian digital rights organisation's own analysis, 22 September 2026. Source for the criticism attributed to them — "age verification for every single instance", the Wikipedia and Codeberg comparison and the "Bye Bye Fediverse" argument
-
Hunton Andrews Kurth via National Law Review — European Commission Unveils Proposal for EU KIDS Act Secondary, 2 October 2026. Cross-check of the three age tiers and the app-store enforcement of game age recommendations
-
NoobFeed — EU Kids Act Could Put New Regulatory Costs on European Games Opinion piece, 3 October 2026. Listed only because we correct it: it calls the text "leaked" and reports an unattributed cost figure that we do not repeat
-
PubAffairs Bruxelles — Commission seeks feedback on EU KIDS Act Carries the Commission's own news item on the feedback period, including that responses will be summarised and presented to Parliament and Council. Secondary reproduction of a Commission text
Tell us what we got wrong
This file will move. If you find the Commission's impact analysis, a Council position, a national implementation note, or a cost figure with a name attached to it, bring it in — a source we can open beats ten pages of commentary, and we will correct this page in public if it turns out we have something wrong.