EU Kids Act: Proposed Age-Based Restrictions on Minors’ Social Media Use
On 16 September 2026, European Commission President Ursula von der Leyen outlined the main direction of the EU Kids Act in her State of the Union address, proposing age-based restrictions on minors’ use of social media and placing responsibility on platforms to demonstrate that their services are safe for children. The Commission scheduled the legislative proposal for 17 September.
This legislative initiative addresses service access, account permissions, time limits and platform safety by design. This article examines the main arrangements using the Commission’s public statements and the draft proposal disclosed by Euractiv (COM(2026) 681/3). The document, referred to below as “the draft”, is still marked “SENSITIVE — UNTIL ADOPTION”. It is neither the Commission’s formally published version nor legislation in force; individual provisions remain subject to change.
Article 2 of the draft would cover social networks, video-sharing platforms, app stores, online games, operating systems, AI companions and general conversational chatbots accessible to minors, with different obligations depending on the service type.
1. Age-Based Arrangements for Minors’ Social Media Use
Von der Leyen called for protection appropriate to different stages of childhood. The arrangements announced in her speech fall into three tiers:
| Age group | Proposed arrangements announced in the speech |
|---|---|
| Under 13 | No access to social media |
| 13 to under 15 | Access only through restricted “mini accounts” set up and supervised by a parent or guardian, with limited functions and no more than one hour of use per day |
| 15 to under 18 | Platforms must implement safety by design and provide protection appropriate to this age group |
The draft further distinguishes when account restrictions would apply. Article 6 targets social networking and video-sharing services with specified risk features. It would prohibit users under 15 from creating personal accounts or accessing services through accounts created for or assigned to them. Relevant features include livestreaming to an indeterminate audience, interaction with users outside existing contacts or subscriptions, profiling-based recommendations, and designs that promote continuous content consumption or repeated service use. Whether account restrictions apply therefore depends on the functions a service actually provides.
For restricted accounts used by children aged 13 to under 15, Article 6 requires parental tools to remain active at all times. Parents would set a daily limit of no more than one hour and be able to approve new contacts in advance and limit their number. Platforms would also need to verify that the person opening the account holds parental responsibility for the minor and that the user is at least 13. Parental supervision would therefore need to operate continuously through account permissions and interaction features.
Article 7 provides a limited access exception for video-sharing services specifically designed for children under 13. Where the conditions are met, children could access the service through their guardian’s own account; no separate account could be created for or assigned to the child. The service would also need to publish a child impact assessment, restrict age-inappropriate content and adjust its features. Personalisation, recommendations and content search would be disabled in principle, and could be enabled only where an assessment demonstrates that they serve the child’s best interests without compromising privacy or safety. This exception would not allow every social service to admit younger children simply on the basis of parental consent.
Turning 15 would not end the requirements to protect minors. After users reach the age for an independent account, platforms would still need to address risks arising from service design. Account access and protection after entry would require separate implementation.
2. Platform Safety by Design and the Responsibility to Demonstrate Safety
In her speech, von der Leyen identified addictive features, mechanisms that lead children towards more extreme content, and the use of girls’ photographs to generate sexualised images as risks requiring action. She proposed reversing the burden of proof and requiring platforms to demonstrate that their services are safe. The draft addresses these issues through product settings, service-specific requirements and compliance review procedures.
(1) Safety Settings for Social Networks and Video-Sharing Services
Articles 11 and 12 would require platforms to disable geolocation and other tracking functions, microphone and camera access, account recommendations, contact-list synchronisation and push notifications by default for minors. They would also restrict unsolicited direct contact and additions to groups. The visibility of minors’ account profiles and shared content would be limited. These arrangements would embed protection in everyday permissions, contacts and information display.
Article 28 of the existing Digital Services Act (DSA) already requires online platforms subject to that provision and accessible to minors to take appropriate and proportionate protective measures. The Commission’s guidelines on the protection of minors, published in July 2025, also recommend private accounts by default, adjustments to recommender systems, and disabling features that may encourage excessive use by default. The new draft would put some specific design requirements into a regulation. Platforms should compare their existing measures with the proposed provisions.
(2) Specific Requirements for AI Companions and General Conversational Chatbots
Article 14 would require AI providers to avoid designs and system behaviour that simulate interpersonal relationships in ways that create emotional dependency in minors. For system memory, information or analysis derived from a minor’s previous interactions would, in principle, not be used in subsequent interactions by default, except where necessary to protect the minor’s safety or implement safety settings. The article also requires the assessment and testing of risks arising from interactions with minors, and corresponding safeguards, before a system is placed on the market or put into service.
Where an AI companion or chatbot is embedded in a social network, video-sharing platform or online game, the article would also prohibit automatic activation or prominent display in the interface, prohibit encouraging minors to use it, and require an easy option to opt out at any time. AI safeguards would therefore extend to interaction patterns, memory functions and the design of product entry points.
The definition of a “general conversational chatbot” in Article 3 excludes AI whose conversational functionality is limited to specific services, tasks or predefined functions, such as specialised customer service and technical support systems. Businesses should first check the product definitions; the mere presence of a chat function does not establish applicability.
(3) Compliance Plans and Independent Audits for Very Large Platforms
Article 5 would require providers of social networking and video-sharing services designated as very large online platforms under the DSA to submit compliance plans to the Commission and commission independent audits at their own expense. Where an audit identifies shortcomings and the Commission issues the corresponding decision, providers would need to propose corrective measures, with implementation verified by the auditor.
The article also specifies that neither an audit report nor the Commission’s action or inaction regarding a compliance plan would automatically constitute a finding of compliance. This establishes a specific procedure for explaining and demonstrating protective measures, but its scope is limited. It should not be read as requiring every service to undergo the same audit.
3. Preparatory Work and Developments to Monitor
At this stage, businesses can map the relevant provisions by product type. Social networks and video-sharing platforms should focus on the risk features that trigger account restrictions, parental permissions and exceptions for children’s access. AI products should examine relationship simulation, the use of historical interaction information, pre-launch testing and opt-out mechanisms. Online games, app stores and operating systems are also within the draft’s scope and should assess their respective requirements.
Age assessment mechanisms need to be designed together with account and feature restrictions. Articles 27 to 29 address general age-assurance standards, data protection and specific solutions. For account access covered by Article 6, Article 29 proposes certified third-party age-verification solutions that comply with the EU framework. Article 28 also limits the amount of data processed to establish whether an age threshold is met and its subsequent use. Age verification and data minimisation need to be implemented together; this should not simply become a requirement for every user to upload identity documents to a platform.
The Commission’s formal proposal should be used to check for changes to the scope, age thresholds and exceptions, safety design and demonstration procedures. Businesses should also continue to track implementation deadlines and accompanying rules. These materials can support a product gap assessment, but the disclosed version should not be treated as a final remediation checklist at this stage.
References
The Commission’s official video and English transcript of the 2026 State of the Union address: https://audiovisual.ec.europa.eu/en/media/video/I-294512; the EU Kids Act draft proposal disclosed by Euractiv (COM(2026) 681/3, not the formally published version): https://www.euractiv.com/content/uploads/sites/2/2026/09/EURACTIV-KIDSACT.pdf; the Commission’s summary of its main initiatives for 2026: https://commission.europa.eu/strategy-and-policy/state-union/main-initiatives-2026_en; the official DSA text: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022R2065; the Commission’s guidelines on the protection of minors and key recommendations: https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-protection-minors; the guidelines as published in the Official Journal of the European Union: https://eur-lex.europa.eu/eli/C/2025/5519/oj/eng.
