Jump to content

EU KIDS Act

From Consumer Rights Wiki
(Redirected from EU Kids Act)

The proposed EU KIDS Act would bar under-15s from social media accounts[1] & make platforms, games, chatbots & app stores apply child-safety rules until they establish a user is an adult.[2] The ban would cover social networking & video-sharing services with any listed risk feature, like contact with strangers or recommendations based on profiling (automated evaluation of people);[1][3] providers could allow guardian-opened limited accounts for 13- & 14-year-olds, capped at an hour daily.[1][4]

The European Commission's proposal, COM(2026) 681 final, is dated 17 September 2026[5] & is in the European Parliament's "Preparatory phase in Parliament",[6] with public feedback open until 26 November 2026.[7] Commission President Ursula von der Leyen said the act is "reversing the burden of proof",[8] while the digital-rights nonprofit Electronic Frontier Foundation (EFF) wrote it would "expand the use of intrusive age verification, and undermine the privacy of all users".[9]

Provisions

[edit | edit source]

Safety-by-design defaults

[edit | edit source]

Article 8(1) would cover providers of social networking services, video-sharing platforms, online games, AI companions (AI systems offering sustained, personalised interaction or companionship that "simulates or facilitates a social, emotional or interpersonal relationship with a user"),[10] general conversational chatbots & app stores "regardless of whether those services or systems are accessible with an account".[2] It continues:

Providers of such services or systems shall design those services and systems in accordance with the requirements laid down in this Chapter by default and shall only derogate from those requirements after they have established that the recipient of the service or the user of the system is an adult, by making use of age assurance in accordance with Chapter V.

[2]

Under Article 3, age assurance means the methods that can be used to "determine, estimate or verify the age of a natural person" but "excluding self-declaration by recipients of the service".[10] That age check under Article 8(1) would be waived for the providers that article covers & for app stores under Article 32(3), in the article headed "Existing accounts", where a provider can establish "with a high degree of confidence" that the recipient "is not a minor".[11]

Minimum ages for accounts

[edit | edit source]

Article 6(1) would bar providers of online social networking & video-sharing platform services from letting anyone under 15 create or use an account where the service "poses a risk to the privacy, safety or security of a minor below that age".[1] A service would count as risky if it meets any one of five listed conditions:

  • live transmission of content to "an indeterminate number" of other users;
  • contact with users outside a person's existing connections or subscriptions;
  • a recommender system based on profiling as defined in Regulation (EU) 2016/679, the General Data Protection Regulation,[1] meaning "automated processing of personal data" used "to evaluate certain personal aspects relating to a natural person";[3]
  • a recommender system that suggests or prioritises contact suggestions or information not provided by the person's existing connections or subscriptions; or
  • design features intended, or reasonably foreseeable, to enable uninterrupted content consumption, that incentivise interactions, or that send notifications "designed to prompt the user to initiate or resume use of the service".[1]

Within six months of the regulation applying, providers would have to establish whether existing account holders are under 15 & disable the accounts of those who are, or "in relation to whom the age cannot be established".[1] Article 32(2) would excuse them from verifying age where they can establish "with a high degree of confidence" that the user has reached the minimum age.[11] The Commission's press release says providers would estimate the age of existing users from "reasonable proxies (e.g. account creation date, credit card details)".[8]

Under Article 6(2), providers could let guardians set up accounts with limited features for children aged 13 & 14.[1][4] On those accounts the guardian tools would always be on, guardians could set a daily limit "which shall not exceed one hour per day", & they could pre-approve new contacts.[1]

According to the Commission's press release, children between 3 and under 13 could not access social media.[8] Article 7 would provide that video-sharing services designed specifically for children under 13 "may exceptionally enable a guardian" to give such a child limited access through the guardian's own account, but only "where all of the following conditions are met"; the conditions include that the provider expressly permits such access in its terms & conditions & has published an assessment of the impact of the service on minors within the specified age range.[12] Article 7 would not allow such access for a child "below the age of 3 years" & would cap it at one hour a day.[12]

Age verification and age assurance

[edit | edit source]

Age verification, one form of age assurance under Article 3, relies on "information derived from identification documents or other reliable, verified sources of identification".[10] For the account rules in Article 6, providers would have to "rely exclusively" on an "EU age verification solution" supplied by a third party & using an "EU proof of age attestation",[13] an electronic attestation confirming that its holder meets a given age, age threshold, or age range.[10]

Article 3 defines such a solution as one that meets the EU Age Verification Scheme, "is certified by a public authority" & is included in a European Union (EU) list after notification by a Member State.[10] European Digital Identity Wallets, which the Commission's staff working document says every Member State was required to provide to citizens, residents & businesses by 2026,[14] would be "deemed to be certified" if they are certified pursuant to Article 5c of Regulation (EU) No 910/2014 & comply with the requirements of the scheme.[13]

For the default-design rules in Article 8 & the app-store age checks, providers could use other age assurance methods if they can demonstrate that those methods meet the requirements of Articles 27 & 28.[13] Article 27 would require "a high level of accuracy, reliability, security, robustness, non-intrusiveness, privacy and data protection, and non-discrimination".[15] Article 28 would bar age assurance solutions from enabling identification of the user or being used to "locate, track, target, advertise to or profile recipients for any purpose", & states: "Any age assurance measure shall be zero knowledge proof."[16]

The Commission's question-and-answer page describes zero knowledge proof as technology "that cannot identify, locate, track or profile anyone" & says: "Platforms do not check identity documents and do not learn who you are."[4] The staff working document says age assurance solutions would share only "an anonymised yes/no answer to the age question".[14]

Providers referred to in Articles 8(1) & 16(4) could store at account level the age signal that a user has met a specific age threshold, "for the sole purpose of avoiding repeated age assurance".[16] Users would get a complaint mechanism, "by electronic means and free of charge", against an age check they consider incorrect.[13]

An operating system provider that has obtained a user's age signal through compliant age assurance would, "after obtaining consent of the user", have to enable sharing of that signal with in-scope providers that need it.[13] The operating-system obligations would be specified in a delegated act, which Article 30 describes as an act the Commission adopts "to supplement this regulation".[17]

Member States would have to make at least one certified EU age verification solution available to citizens & residents "free of charge",[18] & give guardians an electronic means of proving parental responsibility that is "free of charge for the guardian".[18] At least until a delegated act on parental responsibility is adopted, Article 26 would let providers "accept self-declaration by the adult with the parental responsibility", & a provider relying on such a self-declaration would have to "make reasonable efforts to verify that the adult making the self-declaration is exercising parental responsibility".[19]

Addictive design and AI companion rules

[edit | edit source]

Article 9 would bar social networking & video-sharing providers from designs intended or foreseeably likely "to encourage compulsive or excessive use" by minors.[20] It lists autoplay without regular breaks, notifications not triggered by the minor's own activity, incentives or rewards for sharing content or live streaming, & penalties for not engaging regularly.[20] It would also require time limits & usage interruptions designed to protect "school time and core sleep hours of minors".[20]

Article 13 would bar the same services from exposing minors to "variable reward systems", including when those systems are paid for with virtual currency bought with money, & would require purchases made with such currency to "display the corresponding monetary value" in the official currency of the user's Member State.[21] Recital 31 says those providers should prevent minors from being exposed to "loot boxes and other products, where they offer random or unpredictable outcomes or gambling-like features".[22]

Under Article 14, AI companions & chatbots would have to ensure that minors are not exposed to addictive designs by avoiding design features that "simulate interpersonal relations that are likely to create emotional dependencies", & children under 13 could reach them only through guardian tools.[23]

Online games and app stores

[edit | edit source]

Article 15 would require providers of online games to ensure "a high level of privacy, safety and security of minors", including by applying parts of the addictive-design, settings & contact rules.[24] Access for children under 13 would have to be "only enabled and controlled by means of the tools for guardians".[24] Video gaming platforms that let users create & upload games would need "software and organisational measures" so those games comply.[24] Each Member State would have to ensure that a competent authority is responsible for supervising providers of online games that are video games,[25] which the Commission's question-and-answer page describes as video games "that are not online platforms".[4] The competent authority of the Member State in which such a provider's main establishment is located would have "exclusive powers to supervise and enforce this Regulation".[25]

App stores would have to age-rate every app, block minors from accessing or buying apps "inappropriate for their respective age", & assess the age of users under the regulation's age assurance chapter.[26] Article 16(6) would require them to allow the certified EU age verification solution "to be offered in their store".[26]

[edit | edit source]

The proposal is drafted as a regulation of the European Parliament & the Council,[5] which would be "binding in its entirety and directly applicable in the Member States".[27] Article 1 says it "specifies and complements" Regulation (EU) 2022/2065, the Digital Services Act (DSA), & lists three things it would establish: a harmonised minimum age for accounts on social networking & video-sharing services, harmonised safety requirements, & "harmonised rules regarding age assurance online".[28][29]

Article 2 would apply to providers of seven kinds of service or system accessible to minors: online social networking services, video-sharing platform services, software application stores, online games, operating systems, AI companions & general conversational chatbots.[30] For the first five, it would apply wherever the provider is established, as long as the service is offered to recipients located or established in the EU.[30]

Article 3 takes its definitions of social networking services, video-sharing platform services & app stores from Regulation (EU) 2022/1925,[10] & defines "online games" as "a video game or video gaming platform".[10] Stefan Wintermeyer, who runs the business network vutuv on the Fediverse (the network of independent servers around Mastodon), identifies that regulation as the Digital Markets Act in an analysis for the German technology news site heise online.[31]

Under Article 2(4), the regulation would not apply to providers of:

  • not-for-profit online encyclopaedias,
  • not-for-profit educational & scientific repositories,
  • services & systems designed for primarily educational purposes & operated by educational establishments or organisations, or on their behalf,
  • open-source software-developing & -sharing platforms unless the platform is itself an AI system in scope of the regulation or of Regulation (EU) 2024/1689,
  • "services and systems specifically developed and operated for the sole purpose of scientific research and development", &
  • "services and systems designed, developed and operated by public authorities and for exclusive use of those public authorities or on their behalf".[30]

The explanatory memorandum states that "small and micro enterprises are not exempted from this Regulation", because they "may equally provide harms to minors".[32] The Commission's July 2025 guidelines on protecting minors under the DSA apply to all online platforms accessible to minors "with the exception of micro and small enterprises".[33]

Enforcement and fines

[edit | edit source]

Supervision of social networking services, video-sharing platforms, video gaming platforms & app stores would run through Chapter IV of the DSA,[25] the chapter on implementation, cooperation, penalties & enforcement.[29] AI companions & chatbots would be supervised under Regulation (EU) 2024/1689, with fines "not exceeding 6 % of the total worldwide annual turnover" where the provider acted intentionally or negligently.[25] The proposal names that regulation the Artificial Intelligence Act,[34] & the Commission's question-and-answer page states more generally: "Fines can reach 6% of total worldwide annual turnover."[4] Data protection authorities could fine infringements of the data protection obligations in Articles 27, 28 & 29 in line with Article 83 of Regulation (EU) 2016/679, up to the amount in its Article 83(5), & national authorities could not take decisions running counter to a Commission decision under the regulation.[25]

The largest social networking & video-sharing platforms, which the Commission's question-and-answer page describes as those with "45 million or more active monthly users in the EU",[4] would have to notify the Commission of a compliance plan & have it audited by independent auditors "at their own expense".[35] In proceedings against them, Article 35 would have the Commission "endeavour to" send preliminary findings within a bracketed "[30]" working days & adopt a final decision within 90 working days.[36] An annual supervisory fee for those providers could not exceed 0.03% of worldwide annual net income.[37]

Legislative history and status

[edit | edit source]

Earlier EU measures

[edit | edit source]

Article 28(1) of the DSA already requires online platforms accessible to minors to ensure "a high level of privacy, safety, and security of minors", & Article 28(3) says compliance does not oblige platforms to process additional personal data to assess whether a user is a minor.[29] On 14 July 2025 the Commission published guidelines on the protection of minors under the DSA, stating that following them "is voluntary and does not automatically guarantee compliance".[33] The explanatory memorandum says the proposal would set those specifications in "hard law",[32] & Article 2(6) would deem social networking, video-sharing & video gaming platforms subject to DSA Article 28(1) that comply with the regulation to comply with that Article "for matters covered by this Regulation".[30]

On 11 February 2025 the European Data Protection Board adopted a statement on age assurance, warning that, given increasing legal pressure to implement age assurance, "the occurrence of security breaches should be expected".[38] According to the explanatory memorandum, the Jutland Declaration of October 2025, "signed by 25 Member States", called for age verification.[32] On 26 November 2025 the European Parliament called for "a harmonised European digital age limit of 16" as the default for social media unless parents or guardians authorise otherwise.[39] The memorandum adds that Parliament called for a limit of 13 "under which no minor can access social media platforms".[32]

The Commission's staff working document says that in 2026 the Commission preliminarily found TikTok & Meta in breach of the DSA "over addictive design features and inadequate safeguards for minors", & notes that preliminary findings are an intermediate step in an investigation.[14] Von der Leyen convened a Special Panel on Child Safety Online of more than 60 experts, which was first convened in March 2026, met three times & delivered its report in July 2026.[8]

National age limits

[edit | edit source]

The memorandum lists Italy, France, Norway, Greece, Austria, Poland & Belgium as having notified draft laws in 2025 & 2026 that limit minors' access to certain digital services.[32] Euronews reported in September 2026 that 23 of the 27 EU Member States were drafting, debating or enacting such laws, & that Estonia had rejected blanket bans.[40]

On 14 August 2026 France's Constitutional Council held that Article 1 of the French law barring under-15s from online social network services was contrary to the Constitution.[41] The Council found that a general ban made without regard to the minor's situation or the risks of each service infringed freedom of expression & communication, & that the ban meant every person, adults included, would have to prove their age while the law set no conditions or limits on how.[41] Euronews reported that France submitted a revised plan to the EU on 14 September 2026, replacing a total ban with feature restrictions & parental controls for children aged 13 to 15.[40]

Proposal and procedure

[edit | edit source]

The proposal's full title expands KIDS as "EU Keeping Internet Digital Spaces Accountable and Trustworthy".[5] In her 2026 State of the Union address, von der Leyen said: "Tomorrow, the Commission is proposing the EU KIDS ACT."[42] The Commission's press release announced that the Commission "has adopted the EU KIDS Act".[8] The proposal itself is dated 17 September 2026,[5] & the Parliament's Legislative Observatory records the "Legislative proposal published" on that date.[6]

Under the ordinary legislative procedure, the file runs as 2026/0286(COD), with "TFEU 114" (Article 114 of the Treaty on the Functioning of the European Union) as its legal basis.[5][6] The Commission says the European Parliament & the Council will negotiate & decide on the final text before it becomes law.[43] As of 3 October 2026 the Legislative Observatory lists the responsible committee as "Pending final decision on the referral".[6] In the Council, the Audiovisual and Media Working Party was scheduled to hear a "Presentation by the Commission" on the proposal on 2 October 2026, with delegates from the telecommunications & youth working parties invited.[44]

The Commission's "Have your say" feedback period runs from 1 October to 26 November 2026, eight weeks in total; the Commission says it will summarise the feedback & present it to the Parliament & the Council.[7] If adopted, the regulation would enter into force on the 20th day after publication in the Official Journal & would apply from a date the text gives in brackets as "[same day as entry into force plus 6 months]", except that Article 5 would apply from entry into force & Articles 33 & 35 from "[same day as entry into force plus 12 months]".[27] Article 42 would require a Commission review report by "[31 August 2030]", covering among other things the regulation's impact on "the right to freedom of expression and information".[45]

Commission's analysis of impacts

[edit | edit source]

A staff working document titled "Analysis of impacts", SWD(2026) 681, accompanies the proposal.[14] The memorandum describes it as "an accompanying analytical Staff Working Document" covering a problem definition, the approach taken & an assessment of impacts.[32] European Digital Rights (EDRi), a network of digital-rights organisations, said the proposal was presented "without an appropriate impact assessment",[46] the EFF wrote that it "has not gone through a full impact assessment process",[9] & Wintermeyer wrote in heise online that the Commission had not presented a formal impact assessment.[31]

Evidence cited

[edit | edit source]

The staff working document cites a Eurobarometer survey run between March & April 2026 of "more than 26,000 13-18 years old and more than 12,000 parents" in all 27 Member States, & a 2026 research report finding that 73% of children aged 11 to 17 had been exposed to at least one type of harmful content over a four-week period.[14] The memorandum states: "Only half of children aged 9-16 across Europe say they feel safe online."[32] In its press release, the Commission cites a Special Eurobarometer in which 92% of Europeans named stronger online protection for children & young people as a top policy priority.[8] Without the regulation, according to the staff working document, providers would likely face "up to 27 different sets of age restrictions and safety by design rules".[14]

Costs and risks the Commission acknowledges

[edit | edit source]

The staff working document states: "Age assurance is likely to represent the most significant incremental compliance cost for some providers."[14] It cites an external study's estimate that integrating third-party solutions would cost most small & medium-sized services "in the hundreds of euros or low thousands of euros", adding "although the evidence base remains limited".[14] It also cites an Australian government estimate of EUR 0.39 per check per user, about EUR 33 million to check 21 million Australians with four social media accounts each, & findings by the UK communications regulator Ofcom of a median cost "around EUR 0.07" per check.[14] The memorandum says it is "not possible to conclusively determine" the adjustment costs for the "potentially large number of small and micro providers" not previously subject to Article 28 of the DSA, & adds that those costs are mitigated by the EU age verification solution.[32]

On rights, the staff working document notes that age verification solutions typically require users to enrol with "a qualifying hard identifier – normally a passport or a national ID card", & that, in theory, this could unfairly exclude people who lack such documents or "a smartphone with an in-built NFC chip".[14] It states that "no age assurance system is completely circumvention-proof",[14] & that early evidence after Australia set a minimum age of 16 in December 2025 suggests that "a substantial proportion of minors subject to the ban have nevertheless remained on social media".[14] The memorandum says age assurance "can potentially have important implications" for privacy, freedom of expression, participation & non-discrimination.[32]

EU age verification app

[edit | edit source]

The Commission's press release says services "can, for example, use the EU age verification app", which it says "does not retain identity documents or biometric data".[8] According to the Commission, it made a blueprint for an age verification solution available on 14 July 2025, the solution became "feature ready" on 15 April 2026, & its development was supported by a contract awarded to Scytáles & T-Systems.[47]

A second version in October 2025 added passports & identity cards as ways to obtain a proof of age, with proofs "issued in batches, for one-time use only" to prevent transactions being linked.[48] On 15 April 2026 von der Leyen said the app was "technically ready" & named France, Denmark, Greece, Italy, Spain, Cyprus & Ireland as front runners planning to integrate it into their national wallets.[49]

Device integrity checks

[edit | edit source]

The blueprint's implementer checklist tells production implementers to add device integrity checks to every issuing flow, naming hardware-backed key attestation, the Play Integrity API on Android & App Attest on iOS as examples.[50] The blueprint's threat model treats the mobile operating system & browser as trusted & states that "A fully compromised device defeats any app running on it".[51] In July 2025 the app's documentation listed app & device verification based on the Google Play Integrity API & Apple App Attestation among features to be introduced in future versions;[52][53] Anna Seddigh, a co-founder of the app's developer Scytáles, told the Dutch technology website Tweakers that the app would support the Play Integrity API but not as the only way to verify the device.[53]

Bypass reports

[edit | edit source]

POLITICO Europe reported on 17 April 2026 that security consultant Paul Moore found the app "would store sensitive data on a user's phone and leave it unprotected", & that Moore "claimed to have hacked the app in under 2 minutes".[54] The cybersecurity news site Cybernews described the reported methods: deleting PIN values from the app's configuration files to set a new PIN while keeping existing credentials, a rate-limit counter stored in the same editable file, & biometric authentication "controlled by a single boolean flag".[55] The Commission told POLITICO that the hackers had probed an earlier "demo version" of the app & that the vulnerability "was fixed"; Moore said his tests had been run on the latest version of the EU's code online.[54]

The developer released fixes on 17 April 2026.[56][57] The release notes for the 17 April 2026 Android version said the app checks device integrity on startup & refuses to run on rooted or jailbroken devices.[58] Rooting a phone modifies its software.[53] A commit to the reference Android app on 28 April 2026 removed its basic check for rooted devices, stating that "Device integrity checks are now an implementer responsibility."[59]

In July 2026 Cybernews reported that Moore had bypassed the updated app a second time using an AI-generated Chrome extension.[60]

Reactions

[edit | edit source]

Support

[edit | edit source]

Von der Leyen said in the Commission's press release:

Our KIDS Act is reversing the burden of proof - it is for platforms to show they are safe by design.

[8]

Executive Vice-President Henna Virkkunen said platforms "must prove their services do not harm".[8] In her State of the Union address, von der Leyen said: "What we are witnessing is a great capture of our children."[42]

According to heise online, the German federal government approved of the plan in principle.[61] Justice Minister Stefanie Hubig said the announcement had to be followed quickly by action & that children & young people deserve protection from manipulation, addictive algorithms & digital bullying.[61] Euronews reported that a core group of Member States led by France & Denmark, with support from Greece, Spain & Austria, is pushing the act.[40]

The children's rights organisation Eurochild welcomed the proposed act.[62] Its senior policy officer Francesca Pisanu said, according to Euronews, that parental controls "must complement, not replace, strong protections that apply automatically to every child", & asked for the minimum age for autonomous access to AI chatbots to be reconsidered.[40] Leanda Barrington-Leach, executive director of the 5Rights Foundation, a children's digital-rights organisation, welcomed the proposal "as a solid basis for an EU law".[63] Missing Children Europe, a European federation of organisations working on missing & sexually exploited children, welcomed the proposal's "gradual and tiered approach",[64] & Iratxe García Pérez, president of the Socialists and Democrats (S&D) group in the European Parliament, called it "a good first step".[65]

Ramona Pop of the German consumer federation Verbraucherzentrale Bundesverband also welcomed an EU-wide rule & called for a European Digital Fairness Act setting standards for consumers of every age, according to heise online.[61] HateAid, a non-profit organisation that works against digital violence, supported a European approach but warned that a new law must not give platforms an excuse to delay compliance with the DSA further.[61]

Digital-rights groups

[edit | edit source]

EDRi policy advisor Simeon de Brouwer said in an email quoted by the cybersecurity news site The Record:

If the EU really wants to protect children, it should make platforms prove that they are safe, not make children and everyone else prove that they are old enough to exercise their fundamental rights online

[66]

EDRi wrote that services "would have to treat users as children by default unless they prove their age", & that compliance "is likely to be complex and demanding, particularly for smaller services and open-source projects".[46] The EFF wrote that "no exceptions are foreseen for small and medium-sized enterprises", which it said would favour large technology companies, & that some of the measures "seem poorly suited, if at all, to the decentralized architecture of the Fediverse".[9]

Commenting on a leaked draft published by the German digital-rights news site netzpolitik.org, Elina Eickstädt, spokesperson for the hacker association Chaos Computer Club, said it realised almost all of the club's concerns about online age checks & would mean the end of free & anonymous internet use.[67] Svea Windwehr, co-chair of the German digital-policy association D64, said the EU app did not meet basic privacy requirements & threatened to exclude millions of people without access to digital identities.[67] netzpolitik.org also wrote that zero knowledge proof was not yet mandatory even in the EU's own age verification app.[67]

The Austrian civil-rights organisation epicenter.works argued that the act does not spare small platforms & would mean age verification for every individual server in the Fediverse, according to heise online.[68][31] In the same piece, Wintermeyer wrote that a single risk feature, such as letting users contact strangers, is enough to bring Mastodon within the account rules, but that whether a private, non-commercial hobby server is covered depends on how the specific service is legally classified, & that the claim that every instance is covered goes too far.[31]

Consumer groups and lawmakers

[edit | edit source]

Agustín Reyna, director of the European Consumer Organisation, told The New York Times that age verification "is not a silver bullet" & would raise privacy & data protection concerns of its own, according to the IAPP.[69] The consumer organisation Euroconsumers told Euronews: "Our survey shows that age limits are already widely circumvented."[40] Member of the European Parliament Alex Agius Saliba (S&D) said age verification "needs to be carried out in a privacy-preserving way",[65] & Kim van Sparrentak of the Greens/EFA group said that if children were banned without changing how platforms operate, "Musk and Zuckerberg will be popping champagne".[70]

Industry groups

[edit | edit source]

The Computer & Communications Industry Association (CCIA) Europe, whose members include Google & Meta according to Reuters,[71] said that if platforms have to distinguish minors from adults, adults "must also prove their age when signing up for platforms or services".[72] Its head, Daniel Friedlaender, said collecting age information, identity credentials & data linking children with parents at this scale "would undoubtedly create an attractive target for cybercriminals".[72] CCIA Europe's Mitchell Rutledge said in an email quoted by The Record that the Commission was "kicking those critical decisions down the road to future implementing and delegated acts".[66]

Video Games Europe, a European video games industry group, said in a statement:

We caution against sweeping age assurance measures applicable to every game and player in Europe. This would depart from the risk-based approach adopted in the DSA Article 28 Guidelines.

[73]

The group also called for a public consultation process.[73] According to heise online, the German IT industry association Bitkom considers a social media ban the wrong approach.[61] Bitkom's chief executive Bernhard Rohleder said the act contains some good approaches but in part overshoots on age limits & bureaucracy.[74] According to heise online, Ben Brake of the online-platform association DOT Europe[75] said the act should complement the DSA rather than create double regulation.[61]

Gaming campaigns

[edit | edit source]

The consumer campaign Stop Killing Games called the act "the biggest threat Stop Killing Games has ever faced" in the description of a September 2026 video.[76] The technology news site Notebookcheck reported that the campaign based its assessment on a leaked version of the proposal & described its claims as a warning about possible effects rather than established law.[77] Stop Killing Games & organisations including the Open Rights Group formed Stop Killing the Internet in June 2026.[78] A European Citizens' Initiative titled "Stop Killing The Internet: No Digital ID & No Age Verification", registered on 22 July 2026 & collecting signatures until 25 August 2027, asks for digital identity & age assurance systems to "remain voluntary, privacy-preserving and non-discriminatory".[79]

See also

[edit | edit source]

References

[edit | edit source]
  1. ↑ 1.0 1.1 1.2 1.3 1.4 1.5 1.6 1.7 1.8 European Commission (2026-09-17). "Proposal for a Regulation of the European Parliament and of the Council EU KIDS Act - 'EU Keeping Internet Digital Spaces Accountable and Trustworthy' (COM(2026) 681 final)". EUR-Lex. Article 6. Archived from the original on 2026-10-03. Retrieved 2026-10-03.
  2. ↑ 2.0 2.1 2.2 European Commission (2026-09-17). "Proposal for a Regulation of the European Parliament and of the Council EU KIDS Act - 'EU Keeping Internet Digital Spaces Accountable and Trustworthy' (COM(2026) 681 final)". EUR-Lex. Article 8. Archived from the original on 2026-10-03. Retrieved 2026-10-03.
  3. ↑ 3.0 3.1 "Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)". EUR-Lex. 2016-04-27. Article 4(4). Retrieved 2026-10-03.
  4. ↑ 4.0 4.1 4.2 4.3 4.4 4.5 European Commission (2026-10-02). "The KIDS Act explained". Shaping Europe's digital future. Archived from the original on 2026-10-03. Retrieved 2026-10-03.
  5. ↑ 5.0 5.1 5.2 5.3 5.4 European Commission (2026-09-17). "Proposal for a Regulation of the European Parliament and of the Council EU KIDS Act - 'EU Keeping Internet Digital Spaces Accountable and Trustworthy' (COM(2026) 681 final)". EUR-Lex. Cover page and title. Archived from the original on 2026-10-03. Retrieved 2026-10-03.
  6. ↑ 6.0 6.1 6.2 6.3 European Parliament. "Procedure File: 2026/0286(COD)". Legislative Observatory. Retrieved 2026-10-03.
  7. ↑ 7.0 7.1 European Commission. "Child online safety – keeping digital spaces accountable and trustworthy (EU Kids Act)". Have your say. Archived from the original on 2026-10-02. Retrieved 2026-10-03.
  8. ↑ 8.0 8.1 8.2 8.3 8.4 8.5 8.6 8.7 8.8 European Commission (2026-09-17). "EU KIDS Act to restrict social media platforms' access to children in the EU". European Commission Press Corner. Retrieved 2026-10-03.
  9. ↑ 9.0 9.1 9.2 Christoph Schmon (2026-09-21). "EU Kids Act Won't Keep the Internet Accountable and Trustworthy". Electronic Frontier Foundation. Archived from the original on 2026-09-28. Retrieved 2026-10-03.
  10. ↑ 10.0 10.1 10.2 10.3 10.4 10.5 10.6 European Commission (2026-09-17). "Proposal for a Regulation of the European Parliament and of the Council EU KIDS Act - 'EU Keeping Internet Digital Spaces Accountable and Trustworthy' (COM(2026) 681 final)". EUR-Lex. Article 3. Archived from the original on 2026-10-03. Retrieved 2026-10-03.
  11. ↑ 11.0 11.1 European Commission (2026-09-17). "Proposal for a Regulation of the European Parliament and of the Council EU KIDS Act - 'EU Keeping Internet Digital Spaces Accountable and Trustworthy' (COM(2026) 681 final)". EUR-Lex. Article 32. Archived from the original on 2026-10-03. Retrieved 2026-10-03.
  12. ↑ 12.0 12.1 European Commission (2026-09-17). "Proposal for a Regulation of the European Parliament and of the Council EU KIDS Act - 'EU Keeping Internet Digital Spaces Accountable and Trustworthy' (COM(2026) 681 final)". EUR-Lex. Article 7. Archived from the original on 2026-10-03. Retrieved 2026-10-03.
  13. ↑ 13.0 13.1 13.2 13.3 13.4 European Commission (2026-09-17). "Proposal for a Regulation of the European Parliament and of the Council EU KIDS Act - 'EU Keeping Internet Digital Spaces Accountable and Trustworthy' (COM(2026) 681 final)". EUR-Lex. Article 29. Archived from the original on 2026-10-03. Retrieved 2026-10-03.
  14. ↑ 14.00 14.01 14.02 14.03 14.04 14.05 14.06 14.07 14.08 14.09 14.10 14.11 European Commission (2026-09-17). "Commission Staff Working Document: Analysis of impacts Accompanying the document Proposal for a Regulation of the European Parliament and of the Council EU KIDS ACT - 'EU Keeping Internet Digital Spaces Accountable and Trustworthy' (SWD/2026/681 final)". EUR-Lex. Archived from the original on 2026-10-03. Retrieved 2026-10-03.
  15. ↑ European Commission (2026-09-17). "Proposal for a Regulation of the European Parliament and of the Council EU KIDS Act - 'EU Keeping Internet Digital Spaces Accountable and Trustworthy' (COM(2026) 681 final)". EUR-Lex. Article 27. Archived from the original on 2026-10-03. Retrieved 2026-10-03.
  16. ↑ 16.0 16.1 European Commission (2026-09-17). "Proposal for a Regulation of the European Parliament and of the Council EU KIDS Act - 'EU Keeping Internet Digital Spaces Accountable and Trustworthy' (COM(2026) 681 final)". EUR-Lex. Article 28. Archived from the original on 2026-10-03. Retrieved 2026-10-03.
  17. ↑ European Commission (2026-09-17). "Proposal for a Regulation of the European Parliament and of the Council EU KIDS Act - 'EU Keeping Internet Digital Spaces Accountable and Trustworthy' (COM(2026) 681 final)". EUR-Lex. Article 30. Archived from the original on 2026-10-03. Retrieved 2026-10-03.
  18. ↑ 18.0 18.1 European Commission (2026-09-17). "Proposal for a Regulation of the European Parliament and of the Council EU KIDS Act - 'EU Keeping Internet Digital Spaces Accountable and Trustworthy' (COM(2026) 681 final)". EUR-Lex. Article 31. Archived from the original on 2026-10-03. Retrieved 2026-10-03.
  19. ↑ European Commission (2026-09-17). "Proposal for a Regulation of the European Parliament and of the Council EU KIDS Act - 'EU Keeping Internet Digital Spaces Accountable and Trustworthy' (COM(2026) 681 final)". EUR-Lex. Article 26. Archived from the original on 2026-10-03. Retrieved 2026-10-03.
  20. ↑ 20.0 20.1 20.2 European Commission (2026-09-17). "Proposal for a Regulation of the European Parliament and of the Council EU KIDS Act - 'EU Keeping Internet Digital Spaces Accountable and Trustworthy' (COM(2026) 681 final)". EUR-Lex. Article 9. Archived from the original on 2026-10-03. Retrieved 2026-10-03.
  21. ↑ European Commission (2026-09-17). "Proposal for a Regulation of the European Parliament and of the Council EU KIDS Act - 'EU Keeping Internet Digital Spaces Accountable and Trustworthy' (COM(2026) 681 final)". EUR-Lex. Article 13. Archived from the original on 2026-10-03. Retrieved 2026-10-03.
  22. ↑ European Commission (2026-09-17). "Proposal for a Regulation of the European Parliament and of the Council EU KIDS Act - 'EU Keeping Internet Digital Spaces Accountable and Trustworthy' (COM(2026) 681 final)". EUR-Lex. Recital 31. Archived from the original on 2026-10-03. Retrieved 2026-10-03.
  23. ↑ European Commission (2026-09-17). "Proposal for a Regulation of the European Parliament and of the Council EU KIDS Act - 'EU Keeping Internet Digital Spaces Accountable and Trustworthy' (COM(2026) 681 final)". EUR-Lex. Article 14. Archived from the original on 2026-10-03. Retrieved 2026-10-03.
  24. ↑ 24.0 24.1 24.2 European Commission (2026-09-17). "Proposal for a Regulation of the European Parliament and of the Council EU KIDS Act - 'EU Keeping Internet Digital Spaces Accountable and Trustworthy' (COM(2026) 681 final)". EUR-Lex. Article 15. Archived from the original on 2026-10-03. Retrieved 2026-10-03.
  25. ↑ 25.0 25.1 25.2 25.3 25.4 European Commission (2026-09-17). "Proposal for a Regulation of the European Parliament and of the Council EU KIDS Act - 'EU Keeping Internet Digital Spaces Accountable and Trustworthy' (COM(2026) 681 final)". EUR-Lex. Article 34. Archived from the original on 2026-10-03. Retrieved 2026-10-03.
  26. ↑ 26.0 26.1 European Commission (2026-09-17). "Proposal for a Regulation of the European Parliament and of the Council EU KIDS Act - 'EU Keeping Internet Digital Spaces Accountable and Trustworthy' (COM(2026) 681 final)". EUR-Lex. Article 16. Archived from the original on 2026-10-03. Retrieved 2026-10-03.
  27. ↑ 27.0 27.1 European Commission (2026-09-17). "Proposal for a Regulation of the European Parliament and of the Council EU KIDS Act - 'EU Keeping Internet Digital Spaces Accountable and Trustworthy' (COM(2026) 681 final)". EUR-Lex. Article 43. Archived from the original on 2026-10-03. Retrieved 2026-10-03.
  28. ↑ European Commission (2026-09-17). "Proposal for a Regulation of the European Parliament and of the Council EU KIDS Act - 'EU Keeping Internet Digital Spaces Accountable and Trustworthy' (COM(2026) 681 final)". EUR-Lex. Article 1. Archived from the original on 2026-10-03. Retrieved 2026-10-03.
  29. ↑ 29.0 29.1 29.2 European Parliament and Council of the European Union (2022-10-19). "Regulation (EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022 on a Single Market For Digital Services and amending Directive 2000/31/EC (Digital Services Act)". EUR-Lex. Archived from the original on 2026-10-03. Retrieved 2026-10-03.
  30. ↑ 30.0 30.1 30.2 30.3 European Commission (2026-09-17). "Proposal for a Regulation of the European Parliament and of the Council EU KIDS Act - 'EU Keeping Internet Digital Spaces Accountable and Trustworthy' (COM(2026) 681 final)". EUR-Lex. Article 2. Archived from the original on 2026-10-03. Retrieved 2026-10-03.
  31. ↑ 31.0 31.1 31.2 31.3 Stefan Wintermeyer (2026-10-02). "Stirbt Mastodon an Europas neuem Jugendschutz?". heise online (in Deutsch). Retrieved 2026-10-03.
  32. ↑ 32.0 32.1 32.2 32.3 32.4 32.5 32.6 32.7 32.8 European Commission (2026-09-17). "Proposal for a Regulation of the European Parliament and of the Council EU KIDS Act - 'EU Keeping Internet Digital Spaces Accountable and Trustworthy' (COM(2026) 681 final)". EUR-Lex. Explanatory memorandum. Archived from the original on 2026-10-03. Retrieved 2026-10-03.
  33. ↑ 33.0 33.1 European Commission (2025-07-14). "Commission publishes guidelines on the protection of minors". Shaping Europe's digital future. Archived from the original on 2026-09-29. Retrieved 2026-10-03.
  34. ↑ European Commission (2026-09-17). "Proposal for a Regulation of the European Parliament and of the Council EU KIDS Act - 'EU Keeping Internet Digital Spaces Accountable and Trustworthy' (COM(2026) 681 final)". EUR-Lex. Recital 8, footnote 5. Archived from the original on 2026-10-03. Retrieved 2026-10-03.
  35. ↑ European Commission (2026-09-17). "Proposal for a Regulation of the European Parliament and of the Council EU KIDS Act - 'EU Keeping Internet Digital Spaces Accountable and Trustworthy' (COM(2026) 681 final)". EUR-Lex. Article 5. Archived from the original on 2026-10-03. Retrieved 2026-10-03.
  36. ↑ European Commission (2026-09-17). "Proposal for a Regulation of the European Parliament and of the Council EU KIDS Act - 'EU Keeping Internet Digital Spaces Accountable and Trustworthy' (COM(2026) 681 final)". EUR-Lex. Article 35. Archived from the original on 2026-10-03. Retrieved 2026-10-03.
  37. ↑ European Commission (2026-09-17). "Proposal for a Regulation of the European Parliament and of the Council EU KIDS Act - 'EU Keeping Internet Digital Spaces Accountable and Trustworthy' (COM(2026) 681 final)". EUR-Lex. Article 36. Archived from the original on 2026-10-03. Retrieved 2026-10-03.
  38. ↑ European Data Protection Board (2025-02-11). "Statement 1/2025 on Age Assurance" (PDF). European Data Protection Board. Retrieved 2026-10-03.
  39. ↑ European Parliament (2025-11-26). "European Parliament resolution of 26 November 2025 on the protection of minors online (2025/2060(INI))". European Parliament. Retrieved 2026-10-03.
  40. ↑ 40.0 40.1 40.2 40.3 40.4 Elisabeth Heinz; Leticia Batista Cabanas (2026-09-22). "EU Kids act: The EU's plan to make the internet safer for kids". Euronews. Archived from the original on 2026-10-03. Retrieved 2026-10-03.{{cite web}}: CS1 maint: multiple names: authors list (link)
  41. ↑ 41.0 41.1 Conseil constitutionnel (2026-08-14). "Décision n° 2026-911 DC du 14 août 2026". Conseil constitutionnel (in français). Archived from the original on 2026-09-21. Retrieved 2026-10-03.
  42. ↑ 42.0 42.1 European Commission (2026-09-16). "2026 State of the Union Address by President von der Leyen". European Commission Press Corner. Retrieved 2026-10-03.
  43. ↑ Directorate-General for Communication (2026-09-17). "EU KIDS Act: helping children navigate a safer online world". European Commission. Archived from the original on 2026-10-01. Retrieved 2026-10-03.
  44. ↑ Council of the European Union (2026-09-25). "Notice of meeting and provisional agenda: Audiovisual and Media Working Party (CM 4255/26)". Council of the European Union. Archived from the original on 2026-10-03. Retrieved 2026-10-03.
  45. ↑ European Commission (2026-09-17). "Proposal for a Regulation of the European Parliament and of the Council EU KIDS Act - 'EU Keeping Internet Digital Spaces Accountable and Trustworthy' (COM(2026) 681 final)". EUR-Lex. Article 42. Archived from the original on 2026-10-03. Retrieved 2026-10-03.
  46. ↑ 46.0 46.1 EDRi (2026-09-30). "The KIDS Act will make the internet less safe". European Digital Rights (EDRi). Archived from the original on 2026-10-03. Retrieved 2026-10-03.
  47. ↑ European Commission (2026-09-22). "The EU approach to age verification". Shaping Europe's digital future. Retrieved 2026-10-03.
  48. ↑ European Commission (2025-10-10). "Commission releases enhanced second version of the age-verification blueprint". Shaping Europe's digital future. Archived from the original on 2026-06-07. Retrieved 2026-10-03.
  49. ↑ European Commission (2026-04-15). "Statement by President von der Leyen with Executive Vice-President Virkkunen on the digital age verification app". European Commission Press Corner. Retrieved 2026-10-03.
  50. ↑ "Going to Production: Implementer Checklist for technical tasks". EU Age Verification Blueprint. Archived from the original on 2026-08-24. Retrieved 2026-10-03.
  51. ↑ "Threat Model". EU Age Verification Blueprint. Archived from the original on 2026-09-25. Retrieved 2026-10-03.
  52. ↑ "av-app-android-wallet-ui/README.md at 4b4fc48a9589a5efeaab06fd2b94ebb8f3cd35a1". GitHub. 2025-07-16. Archived from the original on 2026-10-03. Retrieved 2026-10-03.
  53. ↑ 53.0 53.1 53.2 Arnoud Wokke (2025-07-30). "Gaat de EU echt een Google-account verplichten in app voor 18+-verificatie?". Tweakers (in Nederlands). Archived from the original on 2025-07-30. Retrieved 2026-10-03.
  54. ↑ 54.0 54.1 Eliza Gkritsi; Ellen O'Regan; Émile Marzolf (2026-04-17). "Brussels launched an age checking app. Hackers say it takes 2 minutes to break it". POLITICO Europe. Archived from the original on 2026-10-03. Retrieved 2026-10-03.{{cite web}}: CS1 maint: multiple names: authors list (link)
  55. ↑ Paulina Okunytė (2026-04-16). "EU age verification app can be hacked in 2 minutes, claims security expert". Cybernews. Archived from the original on 2026-08-05. Retrieved 2026-10-03.
  56. ↑ Paulina Okunytė (2026-04-23). "Still broken: EU age verification app faces fresh round of criticism after patch". Cybernews. Archived from the original on 2026-10-03. Retrieved 2026-10-03.
  57. ↑ "Security Improvements from Security Audit (#176)". GitHub. 2026-04-17. Archived from the original on 2026-10-03. Retrieved 2026-10-03.
  58. ↑ "Release 2026.04-2". GitHub. 2026-04-17. Archived from the original on 2026-04-22. Retrieved 2026-10-03.
  59. ↑ "EUDIWALLET-1232 remove basic root-detection logic". GitHub. 2026-04-28. Archived from the original on 2026-10-03. Retrieved 2026-10-03.
  60. ↑ Ernestas Naprys (2026-07-15). "EU's €2 million age verification app bypassed using Chrome extension". Cybernews. Retrieved 2026-10-03.
  61. ↑ 61.0 61.1 61.2 61.3 61.4 61.5 Falk Steiner (2026-09-16). "Mindestalter für Social Media: Lob und Kritik für den von-der-Leyen-Plan". heise online (in Deutsch). Archived from the original on 2026-10-03. Retrieved 2026-10-03.
  62. ↑ Eurochild (2026-09-17). "State of the Union Address 2026: Where are children's rights?". Eurochild. Retrieved 2026-10-03.
  63. ↑ EU Affairs Team (2026-09-17). "New EU KIDS Act can "put paid to the tech exploitation of children" but must apply equally to all platforms". 5Rights Foundation. Archived from the original on 2026-09-26. Retrieved 2026-10-03.
  64. ↑ Missing Children Europe (2026-09-17). "MCE welcomes the European Commission's announcement of the EU KIDS Act". Missing Children Europe. Retrieved 2026-10-03.
  65. ↑ 65.0 65.1 Socialists and Democrats (2026-09-17). "EU Kids Act: we must show that Europe's democracy, not Big Tech, set our digital agenda". Socialists and Democrats. Retrieved 2026-10-03.
  66. ↑ 66.0 66.1 Suzanne Smalley (2026-09-17). "European Commission set to push social media restrictions, safety requirements into law". The Record from Recorded Future News. Archived from the original on 2026-09-24. Retrieved 2026-10-03.
  67. ↑ 67.0 67.1 67.2 Sebastian Meineck (2026-09-16). "EU Kids Act: EU-Kommission will Netz mit Alterskontrollen zupflastern". netzpolitik.org (in Deutsch). Retrieved 2026-10-03.
  68. ↑ epicenter.works (2026-09-22). "Zwei Fronten, ein Irrweg. Warum digitaler Ausweiszwang niemanden schützt". epicenter.works (in Deutsch). Retrieved 2026-10-03.
  69. ↑ Alex LaCasse (2026-09-17). "European Commission unveils EU KIDS Act". IAPP. Retrieved 2026-10-03.
  70. ↑ Greens/EFA (2026-09-17). "EU KIDS Act must tackle addictive design for everyone". Greens/EFA. Retrieved 2026-10-03.
  71. ↑ Foo Yun Chee; Yves Herman (2026-09-17). "EU Commission proposes under-13s social media ban". Reuters. Retrieved 2026-10-03.{{cite web}}: CS1 maint: multiple names: authors list (link)
  72. ↑ 72.0 72.1 Computer & Communications Industry Association (2026-09-17). "EU Online Age Checks Make Privacy Trade-Offs Unavoidable, CCIA Europe Warns". CCIA. Retrieved 2026-10-03.
  73. ↑ 73.0 73.1 Video Games Europe (2026-09-17). "Video Games Europe statement on the EU KIDS Act announcement". Video Games Europe. Archived from the original on 2026-10-03. Retrieved 2026-10-03.
  74. ↑ Bitkom (2026-09-16). "Bitkom zum EU Kids Act". Bitkom (in Deutsch). Retrieved 2026-10-03.
  75. ↑ DOT Europe (2026-09-14). "European digital associations call for a coherent framework for child safety online ahead of the SOTEU". DOT Europe. Archived from the original on 2026-10-03. Retrieved 2026-10-03.
  76. ↑ Stop Killing Games (2026-09-30). "This could legitimately end Stop Killing Games". YouTube. Retrieved 2026-10-03.
  77. ↑ Marius Müller (2026-10-01). ""Biggest threat yet": New EU rules could severely restrict online gaming". Notebookcheck. Archived from the original on 2026-10-01. Retrieved 2026-10-03.
  78. ↑ Open Rights Group (2026-06-16). "Stop Killing the Internet: New global movement launches". Open Rights Group. Archived from the original on 2026-09-23. Retrieved 2026-10-03.
  79. ↑ European Commission. "Stop Killing The Internet: No Digital ID & No Age Verification (ECI(2026)000011)". European Citizens' Initiative register. Retrieved 2026-10-03.