EU KIDS Act proposal (Keeping Internet Digital Spaces Accountable and Trustworthy)
Introduced in the first chamber, dated , as of .
An age-appropriate design code rule binding public and private bodies.
- Audit expectation
- periodic
- Who audits it
- Independent third party
- Where the report goes
- Filed with regulator, Published summary
As of .
Where it has got to
The text described here is Proposal for a Regulation, COM(2026) 681 final. That print is COM(2026) 681 final, 2026/0286(COD), published .
Locally, this stage is Legislative proposal published, preparatory phase in Parliament.
The stage above is recorded at oeil.secure.europarl.europa.eu.
The Legislative Observatory lists the stage reached as the preparatory phase in Parliament, with the committee responsible pending a final decision on the referral.
What it requires
- A provider of an online social networking service or video-sharing platform service would have to stop a person below the age of 15 from creating an account or using one, where the service poses a risk to the privacy, safety or security of a minor below that age; the proposal defines that risk by listed features, such as live streaming to an indeterminate audience, contact with people outside a user's existing connections, or a recommender system based on profiling.
- A provider that lets a guardian set up a limited account for a minor above 13 and below 15 would have to keep the tools for guardians always activated, let the guardian set a daily time limit of no more than one hour, and let the guardian pre-approve new contacts and cap the number of contacts.
- Within six months after the Regulation applies, a provider would have to establish whether holders of existing accounts are below 15, and disable the accounts of those established to be below 15 or whose age cannot be established.
- A provider bound by the minimum age would have to verify age exclusively through an EU age verification solution using an EU proof of age attestation, provided by a third party and certified under the EU Age Verification Scheme.
- A provider of an online social networking service, video-sharing platform service, online game, AI companion, general conversational chatbot or software application store would have to ensure a high level of privacy, safety and security of minors and design its service by default to the Chapter III requirements, departing from them only after establishing through age assurance that the user is an adult.
- A provider of a software application store would have to put in place an age-rating system for each application it offers, and would have to stop minors from accessing or buying applications that are inappropriate for their age under that system.
- A provider of an operating system that has obtained a user's age signal would have to enable sharing of that signal with in-scope providers, after obtaining the user's consent, when they need it to comply.
- A provider of an AI companion or general conversational chatbot would have to put in place proportionate and effective measures to protect minors, including enabling access for minors below 13 only through the tools for guardians.
- A provider using age assurance would have to use a solution that does not identify, locate, track or profile the person, and would have to process no more personal data than strictly necessary to assess whether the age threshold is met.
- A provider of an online social networking service or video-sharing platform service that is a designated very large online platform would have to notify the Commission of a compliance plan within four months of its designation, or within 30 days after the Regulation applies if already designated, and have the plan audited by independent auditors at its own expense.
- A provider would have to refrain from any behaviour, contractual, commercial or technical, that undermines compliance, and from using behavioural techniques or interface design to do so.
Who enforces it
Enforcement body
National authorities designated under the Digital Services Act and the AI Act, and the European Commission under its powers in those two Regulations.
What it reaches
Age threshold
15
Covered services
Providers of online social networking services, video-sharing platform services, software application stores, online games, operating systems, AI companions and general conversational chatbots that are accessible to minors.
Obligation class
Access restriction, Age verification, Design code
Verification methods
Digital ID, Third party service
What this law does
The European Commission tabled the proposal on as COM(2026) 681 final, procedure 2026/0286(COD), for a Regulation titled the EU KIDS Act. It would apply to providers of online social networking services, video-sharing platform services, software application stores, online games, operating systems, AI companions and general conversational chatbots that are accessible to minors.
It would not apply to not-for-profit online encyclopaedias, not-for-profit educational and scientific repositories, services designed for primarily educational purposes and operated by educational establishments or organisations or on their behalf, open-source software-developing and sharing platforms unless the platform itself is an AI system in scope, services specifically developed and operated for the sole purpose of scientific research and development, or services designed, developed and operated by public authorities for their exclusive use or on their behalf.
Providers of online social networking services and video-sharing platform services would have to stop a person below the age of 15 from creating an account or using one where the service poses a risk to the privacy, safety or security of a minor below that age.
Providers of online social networking services, video-sharing platform services, online games, AI companions, general conversational chatbots and software application stores would have to design their services by default to a high level of privacy, safety and security of minors, and could depart from the Chapter III requirements only after establishing through age assurance that the user is an adult.
Providers of software application stores would also have to put in place an age-rating system and would not be allowed to let minors access or buy applications that are inappropriate for their age under it. Providers bound by the minimum age would have to rely exclusively on an EU age verification solution using an EU proof of age attestation certified under the EU Age Verification Scheme.
A provider of an operating system that holds a user's age signal would have to enable sharing it, after obtaining the user's consent, with in-scope providers that need it to comply. Supervision and enforcement against providers of social networking services, video-sharing platform services, online games that are video gaming platforms and software application stores would run through Chapter IV of the Digital Services Act.
For AI companions and general conversational chatbots, non-compliance would draw administrative fines under Article 99 of Regulation (EU) 2024/1689 of up to 6 % of the total worldwide annual turnover of the undertaking in the preceding financial year, where the provider acted intentionally or negligently.
Article 43 of the proposal would bring it into force on the twentieth day after publication in the Official Journal and have it apply six months after entry into force, with Article 5 applying from entry into force and Articles 33 and 35 twelve months after entry into force, the intervals being given in square brackets.
When LexLint raises it
When your app profile says your app serves under-18s, operates a social platform or operates an app store.