The European Commission today adopted the EU KIDS Act, a draft Regulation that would bar under-15s from opening their own social media accounts, force platforms to re-check the age of every existing account within six months, and strip implicit engagement signals out of the feeds shown to anyone under 18.

In Short

Brussels has written a new law that would stop children under 13 from having social media accounts at all, let 13 and 14 year olds use accounts their parents set up and control for one hour a day, and let teenagers open their own accounts from 15. It matters because the same text would also rewrite how feeds work for everyone under 18: no autoplay, no streak mechanics, no recommendations built on how long you watched something. If it passes, platforms would have six months from the day the rules apply to find and switch off every account belonging to someone under 15, including accounts that already exist.

What the Commission adopted

Two documents landed in Brussels today. The first, COM(2026) 680 final, is a Communication to the European Parliament and the Council setting out an EU approach to online child safety. The second, COM(2026) 681 final, carrying the interinstitutional file number 2026/0286 (COD), is the legislative proposal itself: the EU KIDS Act, an acronym for EU Keeping Internet Digital Spaces Accountable and Trustworthy. An accompanying Staff Working Document, SWD(2026) 681 final, carries the analysis of impacts.

The proposal rests on Article 114 of the Treaty on the Functioning of the European Union, the internal market legal basis also used for the Digital Services Act and the AI Act. That choice matters procedurally: it puts the file through the ordinary legislative procedure, meaning Parliament and Council both have to agree before anything binds.

Commission President Ursula von der Leyen framed the central mechanism in terms of who has to prove what. According to the Commission press release, the KIDS Act reverses the burden of proof, and "it is for platforms to show they are safe by design."

PPC Land reported on the draft Communication two days ago, when the age brackets had leaked but the operative text had not. The adopted version puts numbers on clauses the draft left blank.

The age staircase, with dates attached

Article 6 prohibits providers of online social networking services and video-sharing platform services from letting anyone under 15 create an autonomous account, where the service poses a risk to minors below that age. The proposal does not leave "risk" to interpretation. A service qualifies if it does any one of five things: permits real-time transmission to an indeterminate audience, permits contact with users outside pre-existing connections, uses a recommender system based on profiling as defined in GDPR Article 4(4), uses a recommender system that surfaces contacts or content not supplied by existing connections, or deploys interface features that enable uninterrupted consumption, incentivise interaction, or send automated prompts to resume use.

Read against any mainstream social platform, that list is close to a description of the product.

Guardians may set up limited accounts for 13 and 14 year olds. Those accounts must keep guardian tools permanently active, cap daily access at no more than one hour, and let the guardian pre-approve contacts and set a ceiling on their number. Article 7 allows a narrower exception below 13: a video-sharing service designed specifically for under-13s may let a guardian admit a child through the guardian's own account, with no account created for the child, all personalisation and recommender features switched off, a published risk assessment, and a one-hour daily cap. That access stops at 13, and cannot be enabled below the age of 3.

The retroactive clause is the one with the clearest commercial edge. Article 6(4) requires providers to establish, within six months of the date the Regulation applies, whether existing account holders are under 15, and to disable the accounts of those found to be under 15 or whose age cannot be established. Article 32 adds that this determination must run through an EU age verification solution, unless the provider can establish with a high degree of confidence that the holder has passed the threshold.

Recommender systems lose the engagement signal

Article 10 is where the proposal reaches furthest into how attention is priced. Providers using recommender systems must design suggestion and optimisation for minors so that the system does not exploit a minor's vulnerability or attention, and must build in evaluation metrics capturing quality, safety and mental-health outcomes.

Four obligations follow. Recommender systems must give priority and primary weight to explicit user-stated preferences. They must disable by default any recommendation driven by implicit engagement-based signals drawn from a minor's behaviour. They must not rely on personal data collected from outside the service. And they must not expose minors to suggested content posing a risk to privacy, safety or security, including where that risk arises from repeated encounter.

Recital 28 defines implicit engagement-based signals in terms any performance team would recognise: signals that infer preference from activity, such as time spent viewing content and click-through rates. The same recital names the rabbit hole effect, the progressive amplification of similar recommendations, and the filter bubble effect, the narrowing of exposure to diverse content, as outcomes to be designed against.

Minors must also be given a prominent tool to reset the recommender by deleting previously identified preferences, plus at least one feed option not based on profiling. That option has to be offered at account creation, must remain reachable from the interface section where content is ranked, and must not be designed to steer minors back toward the profiling-based option. The last clause reads as a direct transplant of dark patterns reasoning from DSA Article 25 into feed architecture.

Economist Daron Acemoglu argued in August that removing algorithmic ranking would leave Facebook functional while ending TikTok's model. Article 10 does not remove ranking. It removes the input that makes ranking cheap.

Safety by design, itemised

Article 9 prohibits designing services in a manner intended, or reasonably foreseeable, to encourage compulsive or excessive use by minors, then lists four features deemed to do so: automatic play and uninterrupted consumption without effective interruption moments, notifications not triggered by the minor's own activity, rewards for sharing or broadcasting content to indeterminate audiences, and mechanics that penalise a failure to return at regular intervals. Time-management measures must protect school time and core sleep hours.

Article 11 sets default-off requirements for geolocation and other tracking, microphone and camera access, account recommendations and contact synchronisation, and push notifications. Defaults may only be changed where the minor is above 15, was clearly informed, and explicitly consented. Features that increase social comparison or that disproportionately embellish or idealise a minor's image must not be available to minors at all.

Article 12 sets contact rules: no unapproved direct contact, no inclusion of minors in contact recommendations, no group additions without explicit agreement, anonymous blocking, no downloads or screenshots of a minor's content by others, no disclosure of contact details, and livestreaming disabled by default.

Article 13 covers commercial transactions. Purchases must be labelled as economic transactions in real time, virtual-currency purchases must display the value in the national currency of the minor's residence, and services must not be designed to produce excessive, impulsive or unwanted spending. Variable reward systems are named specifically. Recital 31 lists the commercial mechanics under examination: advertisements, product placements, virtual currencies, influencer marketing, sponsorship and AI-enhanced nudging.

AI companions and chatbots sit inside scope

The proposal covers seven categories of provider: online social networking services, video-sharing platform services, software application stores, online games, operating systems, AI companions, and general conversational chatbots. Article 3 defines an AI companion as a system providing sustained, personalised interaction simulating a social, emotional or interpersonal relationship, and a general conversational chatbot as a general-purpose system with broad conversational functionality. Specialised customer-service, transactional, educational and industrial applications are carved out.

Article 14 applies the addictive-design, safe-settings and transaction-transparency rules to those systems, then adds four requirements. Systems must avoid behaviours simulating interpersonal relations likely to create emotional dependencies. Persistent conversational memory of a minor's prior interactions must be off by default. Under-13 access must run through guardian tools. And providers must run state-of-the-art evaluation and testing before placing the system on the market, plus post-market monitoring afterwards, with micro and small enterprises exempt from the monitoring duty.

Where a chatbot is embedded inside a social platform, video service or game, it must not activate automatically, must not be displayed prominently, must not be pushed at minors, and must be easy to switch off.

Exemptions run to six categories: not-for-profit online encyclopaedias, not-for-profit educational and scientific repositories, services operated by or for educational establishments, open-source development platforms, research-only systems, and services built for public authorities. Small and micro enterprises are not exempt.

Age verification narrows to a single rail

Article 29(2) is the provision with the most direct supply-chain consequence. For the purpose of the access delay, providers must rely exclusively on an EU age verification solution using an EU proof of age attestation, supplied by a third party, certified against the EU Age Verification Scheme and listed by the Commission. European Digital Identity Wallets certified under Article 5c of Regulation 910/2014, the eIDAS framework, count as certified.

That is a closed list for one purpose and an open one for another. For safety-by-design obligations and app store checks, Article 29(4) permits alternative age assurance methods, including age estimation, provided they meet the accuracy, reliability, robustness, non-intrusiveness, privacy and non-discrimination criteria in Articles 27 and 28.

Article 28 sets the data boundary. Age assurance solutions must not enable identification, nor locate, track, target, advertise to or profile recipients for any purpose. Providers must not process more personal data than strictly necessary, must not combine it with data from other services they operate or from third-party services, and every measure must be zero knowledge proof. A narrow derogation lets providers store an age signal at account level solely to avoid repeated checks.

Article 31 obliges Member States to make at least one certified EU age verification solution available free of charge, and at least one free electronic means for a guardian to attest parental responsibility. Article 29(6) requires operating systems holding a compliant age signal to share it, with user consent, to providers that need it.

The Commission has been assembling this infrastructure for over a year without binding anyone to it. The April 2026 recommendation urging member states to deploy verification apps by 31 December 2026 carries no penalty for missing the date. Article 29(2) would convert that optional tooling into the only permitted route for the access delay. Supply-side fragility is already visible: Yoti pulled its digital ID app from Spanish app stores on 10 September 2026 after a fine, leaving one fewer private option in a market where the public replacement is undeployed.

Reddit has already run the experiment on the demand side, disabling advertising personalisation for EU accounts aged 13 to 15 when its checks began on 24 June 2026.

The VLOP compliance gate

Article 5 creates a pre-clearance mechanism for the largest services. Providers of social networking and video-sharing services designated as a very large online platform under DSA Article 33, the 45 million monthly active user threshold, must notify the Commission of a compliance plan describing in detail how they meet Chapters II to V. Newly designated platforms have four months from designation. Platforms already designated have 30 days from the date the Regulation applies.

The plan must then be audited, at the provider's expense, by independent auditors holding or retaining expertise across six fields: child protection and rights, paediatric medicine and child psychiatry, developmental science, age assurance, interface and recommender system design, and data protection and security. Auditors send a draft to the provider, which has 15 days to comment, and issue a final report to the Commission and provider within two months of receiving the plan. Providers must publish a non-confidential summary.

Where the Commission decides the plan contains shortcomings, the provider has 30 days to submit a corrective action plan, with each measure carrying an implementation period of no more than 60 days. Article 5(8) is explicit that neither the auditor's report nor Commission inaction constitutes a finding of compliance.

Article 22 folds ongoing monitoring of these measures into the systemic risk assessment VLOPs already run under DSA Article 34.

Fines, fees and a faster clock

Enforcement borrows wholesale rather than building new machinery. Article 34 applies Chapter IV of the DSA to platforms, app stores and video gaming platforms, and Chapter IX of the AI Act to AI companions and general conversational chatbots. For the AI systems, administrative fines are capped at 6% of total worldwide annual turnover in the preceding financial year where the provider acted intentionally or negligently. Data protection authorities retain competence over the processing involved in age assurance, with GDPR Article 83(5) fine levels available.

Article 35 compresses the timetable. Where the Commission opens proceedings against a VLOP or an AI system under its exclusive supervision, it must endeavour to communicate preliminary findings within 30 working days and adopt a final decision within 90 working days. The bracketed 30 in the article text signals a figure still open for negotiation, and the explanatory memorandum and the Commission FAQ both describe the periods as calendar days rather than working days.

The comparison point is the existing caseload. The Commission opened its Meta investigation on 16 May 2024 and issued preliminary findings on addictive design on 10 July 2026, more than two years later. Its findings against TikTok over infinite scroll, autoplay, push notifications and recommender systems came on 6 February 2026, and the preliminary findings on Meta's under-13 age assurance on 29 April 2026. Article 35 would replace that cadence with months.

Article 36 creates an annual supervisory fee charged per service on designated platforms and on providers of AI companions, chatbots and video gaming platforms under Commission supervision, capped at 0.03% of worldwide annual net income in the preceding financial year. The fee is meant to fund the Commission's supervisory staff, the operation of the EU Age Verification Scheme, and enforcement.

What the impact analysis says about cost

The Staff Working Document treats age assurance as the largest incremental cost line, then argues it down. The Australian government estimated 80 hours of staff time per social media service to implement age assurance, EUR 0.39 per check, and roughly EUR 33 million to cover 21 million Australians holding four accounts each. The UK Online Safety Act impact assessment assumed 12 hours of developer time for a backend integration and a ten-year total between EUR 21 million and EUR 107 million to cover 27 million users per year. Ofcom's 2026 findings put median per-check costs at around EUR 0.07, with some large providers between EUR 0 and EUR 0.08.

For small and medium services integrating third-party solutions, the Commission's external study expects costs in the hundreds to low thousands of euros, while noting the evidence base remains limited. Australian projections have weekly operational staff time falling from ten hours to two after the first year.

Games face a different calculation. Around 80% of EU video game companies are small or micro enterprises, and industry told the Commission that off-by-default requirements could affect existing monetisation models. The Staff Working Document counters that only a quarter of online game users in the EU are minors, so restricting features for that group need not move overall revenue substantially.

Vendor-side claims of half-day integrations appear in the document flagged as unverified by the Commission's own study.

Why this matters for the marketing industry

Three consequences follow for anyone buying, selling or measuring European inventory.

The first is audience size. Under-15s were never a directly monetisable audience in the EU, because DSA Article 28(2) already prohibits profiling-based advertising to recipients a platform knows with reasonable certainty are minors, and the European Data Protection Board set out the interaction with data protection law in Guidelines 3/2025. What changes is reach and signal. A six-month sweep that disables accounts whose age cannot be established removes users from measured audiences, and removes their behaviour from the engagement data feeding ranking for everyone.

The second is signal quality. Article 10 does not restrict targeting. It restricts optimisation. Disabling implicit engagement-based signals by default for every user under 18, and cutting off external data in recommender systems for that group, degrades the ranking inputs on the organic side of the same surfaces where paid inventory sits. Where a platform cannot establish adult status, Article 8 requires it to apply the minor defaults anyway.

The third is compliance sequencing. The Article 5 gate means the largest platforms cannot ship a new feature to a European audience containing minors without a plan on the Commission's desk and an auditor's signature behind it. Product roadmaps acquire a regulatory dependency that agencies and advertisers planning against launch dates will inherit.

The Commission also confirms the wider package. A Digital Fairness Act is coming, covering manipulative business-to-consumer practices, unfair pricing, influencer marketing and digital subscriptions, alongside a revision of the Consumer Protection Cooperation Regulation and of the Audiovisual Media Services Directive, the last of which will clarify how EU audiovisual rules apply to influencers as content providers. IAB Europe and allied trade bodies objected to the scope of the Digital Fairness Act consultation in July 2025, arguing existing frameworks already cover the ground.

Loose threads in the text

The published proposal carries several internal inconsistencies worth noting. Article 6(1) lists its qualifying conditions from (d) to (h) with no (a), (b) or (c). Article 7(5) cross-refers to Article 5(2) for the creation of limited accounts, a provision that sits at Article 6(2). Article 8(1) similarly refers to accounts under Article 5(3) and Article 6(3). Article 36(1) points to Article 33 for Commission competence where Article 34 carries it. Delegated-act references alternate between Articles 39 and 40 in ways the two articles do not support. The explanatory memorandum dates a President's Youth Advisory Group meeting to December 2026, a date that has not yet occurred.

The scope of the under-13 restriction is also described differently across the package. The press release says the proposal prohibits social media platforms from accessing children under 13. The FAQ and Article 7 allow guardian-mediated access to child-designed video platforms below that age. The Communication states that children from birth to under 3 should not have access to any screen, framed as guidance to parents rather than an obligation on providers, while Article 7(4)(b) makes the under-3 exclusion binding on the provider.

What happens next

The Regulation would enter into force 20 days after publication in the Official Journal and apply six months later. Article 5 would apply from entry into force, and Articles 33 and 35 twelve months after. The Commission must review the application of the Regulation and report to Parliament and Council by 31 August 2030, assessing the effectiveness of Articles 6 and 7 and the impact on freedom of expression.

Before any of that, the file needs Parliament and Council. The European Parliament's November 2025 report called for a harmonised digital age limit of 16 for social media, video-sharing platforms and AI companions, with a floor of 13 below which no access is possible. The Commission has proposed 15. The gap between those two numbers is the first negotiation.

National law is the other constraint. France's Constitutional Council struck down its own under-15 social media ban on 14 August 2026, eighteen days before it was to take effect, a ruling the Communication cites among the developments demonstrating the legal complexity of the question. Seventeen Member States have draft legislation in preparation or under negotiation, with age limits between 13 and 16.

The Communication closes on the political framing the whole package is built around, quoting the line that Europe believes children should be raised by their parents, not by algorithms.

Timeline

Summary

Who. The European Commission, with President Ursula von der Leyen presenting the package. In scope are providers of online social networking services, video-sharing platform services, software application stores, online games, operating systems, AI companions and general conversational chatbots, wherever established, where they serve users in the Union. Enforcement sits with the Commission for designated platforms and Commission-supervised AI systems, and with national Digital Services Coordinators, market surveillance authorities and data protection authorities for the rest.

What. A proposed Regulation, the EU KIDS Act, setting 15 as the minimum age for autonomous social media accounts, 13 as the floor for guardian-controlled limited accounts capped at one hour a day, and safety-by-design obligations covering addictive features, recommender systems, default settings, contact, economic transactions, AI chatbots, games and app stores. Age verification for the access delay must run exclusively through a certified EU age verification solution. Existing accounts must be checked within six months and disabled where the holder is under 15 or unverifiable. Designated platforms must file an audited compliance plan. Fines reach 6% of worldwide annual turnover, with an annual supervisory fee capped at 0.03% of worldwide net income.

When. Adopted today, 17 September 2026. Entry into force 20 days after publication in the Official Journal, application six months later, with Article 5 applying from entry into force and Articles 33 and 35 twelve months after. Commission review due by 31 August 2030.

Where. All 27 EU Member States, applying to providers irrespective of place of establishment where they offer services to recipients located in the Union.

Why. According to the Commission, existing rules do not specify a minimum age, do not ban problematic features outright, and lack legal certainty on age verification and design responsibility, while 17 Member States prepare divergent national laws that risk fragmenting the single market. The Commission cites 2026 Eurobarometer findings that teenagers spend an average of 4.5 hours online on school days and 6.1 hours at weekends, that nine in ten adolescents encountered harmful content in the preceding three months, and that only 48% of children aged 9 to 16 report feeling safe online.