Sep 21, 2026 · 8 min read
EU KIDS Act Would Force Age Checks on Every Account
The European Commission published the EU Keeping Internet Digital Spaces Accountable and Trustworthy proposal on 17 September 2026. It bars under 13s from social media, sets 15 as the age at which a minor can open their own account, and requires social media and video sharing services to verify age whenever anyone opens a new one.
The number everyone repeated on 17 September was 15 — the age at which a European teenager could run a social media account without a parent holding the keys. But the number that reshapes the internet is not an age at all. It is the word every. Under the EU KIDS Act proposal, social media services and video sharing platforms "will be required to verify age when a new account is opened" — not the age of every child, the age of every user. A rule written to keep 12 year olds off Instagram lands on all 450 million people in the Union.
Key Takeaways
- The European Commission published the EU KIDS Act — EU Keeping Internet Digital Spaces Accountable and Trustworthy — on 17 September 2026.
- Under 13s would be barred from social media entirely, 13 and 14 year olds would get a parent managed mini account capped at one hour per day, and from 15 a minor could open their own.
- The proposal covers social media, video sharing platforms, online games, app stores, and AI companions and chatbots.
- The EU KIDS Act is not law: it "will now be examined by the European Parliament and the Council, who will negotiate and decide on the final text before it becomes law."
- Because the verification duty attaches at account creation rather than to minors specifically, every adult in the EU would also have to prove an age to open an account.
What Is the EU KIDS Act?
The EU KIDS Act is a European Commission legislative proposal, published on 17 September 2026, that would set EU wide minimum ages for social media accounts and require covered online services to establish how old their users are. The acronym unpacks to EU Keeping Internet Digital Spaces Accountable and Trustworthy, which is the sort of name that gets written after the initials.
Scope is the striking part. The Commission describes it as covering "online services used by minors, including social media, video-sharing platforms, online games, and AI companions and chatbots." Chatbots in the same sentence as Instagram is new. Child safety law drafted before 2025 did not contemplate a conversational AI as something a 12 year old forms an attachment to.
Beyond the age gate, the proposal attacks engagement mechanics directly, "limiting features that can encourage excessive use, such as infinite scroll, reward tricks and push notifications during sleeping hours," and requires "ensuring profiles for minors are private by default." The burden of proof moves too: "Now, service providers will have to show that their services are age-appropriate and safe by design."
Which Ages Get Which Account?
The proposal sorts European minors into three brackets, and the middle one is the genuinely novel design. Per the Commission's own summary:
- Under 13: "children will not be able to access social media services." A flat bar, not a parental consent option.
- 13 and 14: a "mini account managed by a parent or guardian, with limited features and a time restriction of 1 hour per day."
- 15 and over: "children will be able to open and manage their own social media account."
One hour per day, enforced in code, for two years of a teenager's life is a harder line than anything in the Digital Services Act as it stands. It also answers what Brussels found when it looked at the incumbents: preliminary DSA findings against Meta turned on age assurance that amounted to asking users to type a birthday, covered in our piece on Brussels telling Meta its age check is a birthday field. A self declared birthday cannot support a one hour daily cap.
Is the EU KIDS Act Law Yet?
No. The EU KIDS Act is a Commission proposal at the very start of the ordinary legislative procedure, and the Commission states plainly that it "will now be examined by the European Parliament and the Council, who will negotiate and decide on the final text before it becomes law." Nothing in it binds a platform today.
One naming point worth nailing down, because the search results will confuse it: this is not the American bill of a similar name. The US KIDS Act is separate legislation with separate consequences, which we covered in how the KIDS Act could end anonymous whistleblowing. Two continents, two bills, one acronym, no relation.
Why Does Age Verification Cost Everyone Privacy?
Because you cannot prove someone is over 15 without first learning something about who they are. That claim has to be sourced from somewhere: a government document, a face scan, a payment card, a behavioural inference. Every one of those routes moves identity data into a place it was not before.
This is not a hypothetical raised after the fact. A joint statement from 63 organisations, academics and experts spanning privacy, encryption, child safety, sex workers' rights and consumer rights landed alongside the proposal, arguing that current age verification systems often fail to protect children while undermining privacy and creating a false sense of security. European Digital Rights calls it a short sighted measure that excludes a large portion of the population beyond children and is easily circumvented anyway — the same argument that ran through the letter from 400 scientists calling age verification mass surveillance.
There is a quieter structural cost too. Age checks push verification down the stack toward the device and operating system, the cheapest place to answer the question once for every app. Both Apple's age assurance changes in the UK and Illinois HB 5511's device level ID checks show that gravity at work, and the EU KIDS Act naming app stores and operating systems among covered services pulls Europe the same way.
Does the EU Age Verification App Fix This?
Partly, and it is a real engineering effort rather than a fig leaf. The Commission points services at its own tool, noting they "can for example use the EU age verification app, which does not retain identity documents or biometric data." That app is a mini wallet: a white label reference design built on the EU Digital Identity Wallet technical specifications, which Member States are invited to fork into national apps.
The mechanism beats uploading a passport to a social network. A trust anchor, typically a state issued ID, provisions a batch of single use credentials. You hand a fresh one to each age gated service, so as EDRi puts it, "these services cannot collaborate" to correlate your visits.
EDRi's technical critique of the EU age verification tool is where the caveats live, and they are specific rather than rhetorical. Batch issuance "does not make tracking impossible." Credentials still carry "salts, hashes, public keys, signatures and timestamps" unique to you or to the credential, and "linkability could still be achieved based on the app's back-end transaction handling, the network-level interactions, or on the correlation of the issuance/presentation flow." The specification merely hinders unlinkability, because "the system does not require the parties involved to use the strongest privacy-preserving technologies available."
Then there is fragmentation, which is arithmetic rather than cryptography. A reference design each Member State reimplements produces what EDRi calls "27 shades of age-verification apps, one for each Member State, with different designs, technologies and privacy protections." Twenty seven implementations is twenty seven chances to get unlinkability wrong, and the weakest one sets the real floor.
What This Means If You Are Not a Teenager
Most coverage has reported the EU KIDS Act as a rule about children. Read the obligation as drafted and it is a rule about accounts. Verification triggers "when a new account is opened," and no service knows in advance whether the person opening one is 12 or 40, so it must check everyone. A children's safety statute ends up regulating the entire adult online population of the Union.
Age assurance at account creation applies to app stores and operating systems as well as platforms, so the identity layer being built here sits underneath your mail account, your banking apps and your messaging. It is a general purpose identity check justified by social media harms, and once it exists, extending it to other services is a one line amendment rather than a new system.
For compliance teams, the honest read is that the exposure the IAPP puts at up to 6% of global annual revenue will push platforms to over verify rather than under verify. Nobody gets fined for collecting too much assurance, and that asymmetry, not the letter of the text, will determine how invasive the implementations are.
What to Watch Next
Two things will tell you where this lands long before the final vote. First, whether Parliament writes a hard data minimisation floor into the verification article or leaves a list of adjectives as the standard — adjectives do not constrain an implementation the way a prohibition does. Second, whether the 27 national mini wallets converge on one certified stack or diverge; divergence is the default outcome and the worse one. The age brackets are the other live variable, and the one hour daily cap on 13 and 14 year olds is the provision most likely to be traded away.
The Commission's digital strategy portal is where text updates will appear as the file moves through Parliament and Council.
Child safety online is a real problem and a birthday text field was never a serious answer to it. But the answer Brussels has chosen is paid for in identity data, by everyone, permanently. That bill should be argued over now, while the text is still a proposal.