EU KIDS Act is the central development. The EU KIDS Act proposal published on September 17 would create a tiered access model for minors using social media and other interactive online services. The European Commission says children under 13 should not access covered social-media services, ages 13 and 14 should use parent-opened introductory accounts with strict limits, and users aged 15 or older may open personal accounts.
EU KIDS Act: what changed
| Proposal date | September 17, 2026 | European Commission |
|---|---|---|
| Under 13 | No access to covered social-media services | European Commission; AP |
| Ages 13–14 | Parent-opened introductory accounts with limits | European Commission; Le Monde |
| Age 15+ | Personal accounts permitted under the proposed tiered model | European Commission |
| Status | Commission proposal; not yet a final binding rule | European Commission; AP |
The proposal reaches beyond familiar social feeds. Commission material and independent reporting identify video-sharing platforms, AI chatbots and online games among the product categories affected by the wider child-protection framework. That breadth matters because a single child may move between public posts, private AI conversations, livestreams and game chat without leaving one device.
The central mechanism is age assurance at account creation. A platform cannot apply a tiered rule without estimating or verifying whether a user is below 13, between 13 and 14, or at least 15. The proposal points toward the EU age-verification tool or comparable public-authority solutions, but the final technical and legal standards will determine how much personal data users must disclose.
For children aged 13 and 14, the introductory-account model is not simply an ordinary account opened by a parent. Reporting on the proposal describes restricted contacts, strict time limits and parental involvement. Product teams would therefore need a distinct default configuration rather than a consent checkbox layered onto the standard adult experience.
The proposal should not be described as law already in force. It is a Commission initiative that must move through the EU legislative process, where the European Parliament and member states can amend the text. National constitutional rules, existing digital-safety laws and the Digital Services Act will also shape how any final obligations are enforced.
The age thresholds are only the visible part of the compliance problem. Platforms must decide which features are disabled by default, how a child moves from one age tier to the next, what parents can see, and how an appeal works when the system estimates age incorrectly. A false positive can lock out an adult; a false negative can expose a child to features the rule was designed to restrict.
Privacy is the first design tension. Collecting identity documents from every user could create a new repository of sensitive data, while weak self-declaration would be easy to evade. A credible system needs data minimisation, separation between the age signal and the underlying identity, short retention periods and independent security testing.
AI chatbots introduce a separate challenge because risk does not depend only on account access. Memory, recommendation, emotional attachment and private conversation can shape a minor's experience over time. Compliance teams should map which chatbot functions retain history, personalise responses, initiate contact or recommend content, rather than treating a chatbot as a static search box.
Online games and video platforms also mix several services. A game can include voice chat, direct messages, payments and algorithmic discovery. A video app can combine viewing, comments, live broadcasts and creator messaging. Regulators will need to clarify whether one age determination travels across these functions and which restrictions apply to each surface.
Enforcement responsibilities also need a clear chain. App stores, operating systems and network providers may supply age signals, but the service deciding whether to admit a user still controls the experience. Final rules should prevent companies from passing responsibility around while leaving families to resolve conflicting estimates and inaccessible appeals.
Interoperability could reduce repeated identity checks. If a trusted wallet supplies only an age-band credential, each service would not need a fresh document copy. Yet shared credentials create concentration risk, so revocation, recovery and breach notification must be tested before the system is treated as infrastructure.
Parents need understandable controls rather than a dense compliance dashboard. The design should state which contacts, recommendations, purchases and chat functions are available, how time limits operate, and when settings change automatically. A parent cannot give meaningful approval when product consequences are hidden behind general consent language.
Researchers and auditors will need access to aggregate results without exposing children. Platforms should publish error rates by age band, appeal outcomes and evidence of whether restricted accounts receive fewer harmful recommendations. Independent evaluation is especially important when the provider that profits from engagement also measures its own safety performance.
For platforms operating in India, the proposal has no direct domestic legal force, but it can still affect global product architecture. Companies often build common age-assurance and youth-safety systems across regions, then configure thresholds locally. Indian policymakers and child-safety groups will watch whether the EU model reduces harm without normalising excessive identity collection.
The Commission will also need measurable outcomes. Account numbers, blocked sign-ups and parental approvals show whether a control ran, but not whether it improved safety. Useful evaluation should track exposure to harmful content, unwanted contact, evasion rates, appeals, false age estimates and the security of the verification process.
Smaller services will face a different burden from the largest platforms. A proportional model should preserve the same safety outcome without forcing every developer to build identity infrastructure from scratch. Shared standards, audited vendors and clear liability boundaries could make the rules workable without handing a new advantage to companies that already hold vast amounts of user data. That balance belongs in the final legislative scrutiny, not in private platform guidance.
The proposal's differentiated structure is more precise than a single headline age ban, but precision on paper does not guarantee safe implementation. The final EU KIDS Act will be judged by whether it gives children age-appropriate experiences while preventing the age-checking system itself from becoming a new privacy and security risk.
Related Lapaas Voice coverage
Read our coverage of Cohere encrypted inference and NVIDIA CUDA-Q logical quantum codesign for adjacent context.
Frequently asked questions
What is EU KIDS Act?
The proposal bars social-media access below 13 and allows tightly controlled introductory accounts for ages 13 and 14.
What changed?
At 15, minors may open personal accounts, while the proposal also covers video-sharing platforms, AI chatbots and online games.
What should readers or organisations do next?
Age assurance, privacy, enforcement and national-law interaction remain decisive implementation questions.
Sources
Get the day’s top stories in your inbox
One concise email. No spam, unsubscribe anytime.



