Client Alerts
EU KIDS Act and Other Global Developments Reshape Minors’ Access to Social Media
October 01, 2026
By Alex Morganand Natalie Rae Coulton
On 17 September 2026, the European Commission announced its proposal for a Regulation titled the “EU Keeping Internet Digital Spaces Accountable and Trustworthy” (the EU KIDS Act), which seeks to harmonise the protection of minors online. It would cover social networking services, video-sharing platforms, online games, app stores, operating systems, AI companions and general conversational chatbots (Article 2(1)). The proposal would centre on four pillars — tiered age restrictions, “safety by design”, age assurance, and burden of proof and enforcement — and three objectives: protecting minors from risky digital services and AI systems; upholding the digital single market; and maintaining a coherent regulatory and enforcement structure for the protection of minors online. Certain not-for-profit, educational, research and public authority services would be exempt, but the Regulation would apply to small and micro enterprises (SMEs).
The proposed Regulation is still subject to approval by the European Parliament and the Council, and adoption is unlikely before 2028.
The announcement of the proposed Regulation coincides with a related announcement from the Danish Government, which earlier this month published a draft bill for public consultation that would introduce a minimum age of 15 for access to certain social media services. Denmark’s consultation runs from 7 September to 5 October 2026 and, if passed, the bill would enter into force on 1 July 2027.
The Commission’s proposal comes almost a year after the Australian Government introduced a ban on under-16s holding accounts on age-restricted social media platforms and follows the UK Government’s announcement in June this year of an under-16s social media ban set to begin in spring 2027.
This article briefly considers the new EU proposal, the recent Danish proposal and UK announcement, as well as the implementation of the social media ban in Australia. It concludes with practical steps for businesses likely to be affected by the proposed EU KIDS Act.
I. EU KIDS Act Approach – The Four Pillars
The EU KIDS Act would address perceived gaps in the existing legal framework for the protection of minors accessing social media and other internet platforms through four pillars: tiered age restrictions, “safety by design”, age assurance, and burden of proof and enforcement.
Pillar One – Tiered Age Restrictions
The first pillar would establish tiered age restrictions. Children under 13 would generally be prohibited from creating or holding accounts on relevant social networking and video-sharing services. Services with specified risky features would be required to ensure minors below 15 are not able to create an autonomous account (Article 6(1)). A video-sharing service designed for under-13s could nevertheless provide limited access through a guardian-controlled account, with a tool limiting use to one hour per day (Article 7).
For children aged 13 to 15, guardians could create limited accounts subject to a maximum of one hour’s daily use, pre-approved contacts and guardian tools that would remain available (Article 6(2)). These arrangements would operate within the parental responsibility framework (Article 26) and alongside the consent rules in GDPR Article 8 (Article 6(5)).
From age 15, minors would be able to create autonomous accounts on covered services, subject to safety-by-design duties and age assurance (summarised in the sections below). Providers would also need to check existing accounts within six months of application of the Regulation where necessary (Articles 6(4) and 32). The proposal also seeks to address anti-circumvention (Article 4).
The EU KIDS Act would go beyond Article 28 of the DSA (online protection of minors), which is a general duty supported by nonbinding July 2025 Guidelines issued by the European Commission. It would convert those guidelines into “hard law” (Article 1), with compliance satisfying Article 28(1) DSA only for covered matters (Article 2(6)). It would add a harmonised minimum age (Article 6), express feature prohibitions (Article 9(2)), certified account access age verification (Article 29(2)), broader coverage (Article 2(1)), compliance plans and audits (Article 5), and expedited enforcement (Article 35).
Overlapping Regulatory Regimes
Under the proposed EU KIDS Act, Article 28 of the DSA, DSA Chapter IV enforcement for covered platforms (Article 34(1)) and VLOP risk assessments would remain relevant (Article 22). GDPR Article 8 would also operate in parallel (Article 6(5)), while Article 28 would govern data protection in age assurance. The EU KIDS Act proposal further specifies that data protection authorities (DPAs) could impose GDPR-level fines (Article 34(6)) for any data protection failures associated with implementing the requirements under the EU KIDS Act. The EU AI Act would also be complemented, not displaced: AI companions and chatbots would be regulated through both frameworks, with fines up to 6% of worldwide turnover for noncompliance (Article 34(2)). The resulting overlap would require an integrated compliance programme and cooperation under Article 34(7).
Pillar Two – ‘Safety by Design’
The second pillar of the EU KIDS Act would impose “safety by design” requirements on social networking services, video-sharing platforms, AI companions, general conversational chatbots and online games (Article 8). A key proposal would subject social networking services and video-sharing platforms to additional prohibitions on “addictive designs” (Article 9(2)).
This obligation would target features that are “intended, or can reasonably be foreseen, to encourage compulsive or excessive use of online social networking services and video-sharing platform services by minors” (Article 9(1)). Such features include infinite scrolling, endless autoplay, non-activity notifications and engagement incentives. Time limits would need to be implemented to protect school time and core sleep hours (Article 9(3)). Recommender systems would be required to turn off engagement signals by default and offer a non-profiling option (Article 10), and defaults would need to be set to protect geolocation, microphone, camera and contacts from strangers (Articles 11 and 12).
Providers of AI companions and general conversational chatbots would be required to put in place proportionate and effective measures to ensure a high level of protection of the health, safety, fundamental rights, and well-being and development of minors who may access their AI system (Article 14). Such measures include safeguards against emotional dependency and harmful interactions, memory off by default, pre-market testing and post-market monitoring (Article 14(1)). Where deployed within a social networking service, video-sharing platform or online game, these systems must not be automatically activated and minors must have an opt-out (Article 14(2)).
App stores would need age-rating systems and must prevent access to age-inappropriate applications (Article 16). Online games would face tailored safeguards (Article 15), providers would need to protect against impulsive spending and variable reward systems (Article 13), and VLOPs would need to include these measures in DSA Article 34 risk assessments (Article 22).
Pillar Three – Age Assurance
Where the proposal would require providers to implement age assurance, solutions would need to be accurate, reliable, robust, secure, nonintrusive, privacy-preserving and nondiscriminatory (Article 27). Self-declaration would not be sufficient under this framework (Article 27).
For account access, providers would need certified EU age verification solutions subject to privacy safeguards and account access requirements (Articles 28 and 29(2)). Such solutions should not lead to additional processing of personal data enabling the determination of the identity or tracking of the adult or minor concerned. Alternatives could be used for safety-by-design obligations and app stores if they met those safeguards (Article 29(4)), and operating systems could share an age signal with consent (Article 29(6)).
Member States would need to make available at least one free, privacy-preserving EU age verification solution and a means of obtaining a proof-of-age attestation (Article 31).
Pillar Four – Burden of Proof and Enforcement Mechanisms
Providers would need to positively demonstrate compliance with the relevant provisions of the EU KIDS Act. VLOP social networking and video-sharing providers would need to notify a compliance plan to the Commission within four months of designation, or within 30 days for existing VLOPs, and commission an independent audit at their expense (Article 5). The Commission could require a corrective action plan for shortcomings.
Enforcement would build on DSA Chapter IV (Article 34(1)), while AI companions and chatbots would be subject to the EU AI Act framework, with fines up to 6% of worldwide turnover (Article 34(2)). DPAs could impose GDPR-level fines (Article 34(6)); national authorities could not contradict Commission decisions (Article 34(7)); and the supervisory fee would be capped at 0.03% of worldwide net income (Article 36). The proposed EU KIDS Act anticipates the Commission endeavouring to issue preliminary findings within 30 working days and a final decision within 90 working days (Article 35) - timelines called “unprecedented” in the Commission’s financial statement. Minors and guardians could complain and mandate not-for-profit bodies to take action (Article 21), while qualified entities could bring representative actions under the Representative Actions Directive (Article 41).
II. Incoming Danish Legislation – National Minimum Age for Social Media Services
Separately, the Danish Government is consulting on a draft bill that would introduce a minimum age of 15 for access to certain social media services. The consultation runs from 7 September to 5 October 2026 and, if passed, the bill would enter into force on 1 July 2027.
The Danish proposal would apply only to DSA-designated VLOP social media platforms, with those providers responsible for effective age assurance. It would not cover the EU KIDS Act’s broader framework for games, AI, app stores or operating systems.
The Danish bill would resemble Australia’s age-based approach (described below) more closely than the EU KIDS Act: it would set a minimum age of 15 for VLOP social media services without the EU proposal’s guardian tier or under-13 exception. Whether this approach will change as the EU KIDS Act makes its way through the European Parliament is yet to be seen; however, it is expected that this bill will come into effect before the EU KIDS Act and so may operate as at least a medium-term solution, depending on how both laws evolve as they progress through their respective legislative processes.
III. Australia’s Online Safety Act and Ban on Social Media Accounts for Under-16s
Almost a full year before the Commission’s announcement of the EU KIDS Act, Australia introduced a ban on under-16s holding accounts on age-restricted social media platforms. Unlike the EU’s proposed tiered approach, the Australian Online Safety Act 2021 takes a more binary approach by prohibiting under-16s from holding such accounts.
Australian law places responsibility on platforms. Platforms may estimate age but may not require government identification, and the Australian eSafety Commissioner monitors platforms’ compliance.
Reports on Australia’s ban vary: According to a statement from the Australian Government in January 2026, more than 4.7 million accounts were removed because they belonged to under-16s;[1] however, the results of a survey conducted in March 2026 suggested that 70% of children with pre-ban accounts found it “easy” to circumvent the ban.[2]
In March 2026, Australia’s eSafety Commissioner reported no discernible drop in reports of online harm, including cyberbullying and image-based abuse, among under-16s following implementation of the under-16 account ban.[3]
The Australian experience, therefore, illustrates the practical difficulties (and seemingly mixed impact) of blanket age-based restrictions.
IV. UK’s Proposed Social Media Ban for Under-16s
The UK’s Online Safety Act 2023 is in force, and Ofcom’s Protection of Children Codes have applied since 25 July 2025. Age assurance obligations already apply to the riskiest services, and Ofcom has the power to impose fines up to 10% of qualifying worldwide revenue or £18 million. The Online Safety Act, however, sets no social media minimum age.
In June 2026, the UK Government announced an under-16 social media ban set to commence in spring 2027, following a consultation with more than 116,000 responses and support from nine in 10 parents.[4] Regulations are expected to be laid by the end of 2026. Livestreaming and stranger contact across wider services, including gaming, would also be restricted; those features would be off by default for 16- and 17-year-olds, with a midnight to 6:00 a.m. curfew, and “romantic companion” AI chatbots would have a minimum age limit of 18.
While the UK feature restrictions resemble the EU safety-by-design duties to an extent, unlike the EU proposal, the UK ban would use a single under-16 threshold with no guardian tier.
V. Status of the EU KIDS Act and Next Steps
The proposed EU KIDS Act remains subject to approval by the European Parliament and the Council, with adoption unlikely to occur before 2028. If adopted, the Regulation would apply six months after entry into force. The compliance plan and independent audit requirements would apply immediately (Article 5), while national measures to prepare and support minors and the expedited procedure would apply after 12 months (Articles 33 and 35), with the timing governed by that provision (Article 43).
VI. Practical Next Steps for Affected Businesses
Below are some practical steps to consider if your business is likely to be affected by the proposed EU KIDS Act Regulation.
- Map services and features against the proposed scope and risky-feature triggers (Articles 2(1) and 6(1)).
- Gap-analyse child safety controls against the DSA’s child safety requirements (Article 28) and the July 2025 Guidelines from the European Commission.
- Plan age verification for new and existing accounts, including privacy and account access safeguards (Articles 28 and 29(2)) and existing account reviews (Article 32).
- Audit addictive design features, recommender systems and defaults (Articles 9, 10 and 11), and review AI-companion features (Article 14).
- VLOPs should prepare the Article 5 plan and audit, align EU and UK programmes, and allocate regulatory responsibility.
- Monitor EU, Danish and UK legislative developments.
We at Paul Hastings have significant experience assisting businesses in dealing with current and prospective legislative frameworks. If you or your team wish to learn more or discuss any of the topics covered in this article, please contact alexmorgan@paulhastings.com or nataliecoulton@paulhastings.com.
Contributors


Practice Areas
Compliance & Regulatory Counseling
Privacy & Cybersecurity Solutions Group
For More Information

