On 17 September 2026 the European Commission presented the proposal for a regulation entitled EU Keeping Internet Digital Spaces Accountable and Trustworthy, abbreviated as the EU KIDS Act (European Commission). It is an initiative that addresses the presence of minors online through a dedicated set of rules, rather than through the application of rules designed for all users.
The text is a proposal and will now have to be examined by the European Parliament and the Council, with the timescales and amendments that this entails. Some of the choices it contains, however, are already relevant today for those who design digital services, because they indicate a direction that is unlikely to be reversed.
Access by age bracket: a gradual model
The central mechanism of the proposal is the articulation of access by age bracket, in place of the single threshold that characterises the current rules.
Below the age of thirteen no access to social media is envisaged. Access to child-friendly video-sharing platforms remains permitted, through an account managed by a parent.
From thirteen to fifteen the proposal introduces the “mini account”, managed by a parent or by the holder of parental responsibility, with limited features and a time restriction of one hour per day.
From the age of fifteen the minor may hold their own account.
The underlying logic is that of progressive autonomy: not a single moment at which the minor moves from total exclusion to full digital capacity, but a sequence of steps in which their faculties expand progressively. It is the approach that we have already seen emerging in the Italian debate and on which we commented when discussing the protection of minors online and the development of skills.
Service design as the object of the rule
The second part of the proposal does not concern access requirements, but the design of the service. The safety by design obligations include limits on infinite scroll, reward tricks and push notifications during sleeping hours; the prohibition of unsolicited contact from strangers; the setting of minors’ profiles as private by default; and the availability of easy ways to block and mute other users.
This is the point that marks the greatest distance from the past. Rules on the protection of minors have traditionally governed content, that is, what the minor may see. Here the object is the mechanism, the way in which the service captures and retains attention, regardless of the content conveyed. A stream of content that is lawful in itself, if designed to have no end and to reactivate itself with notifications during the night, falls within the scope of the rule.
Conversational systems turned off by default
The proposal expressly applies to online games and to conversational and companion artificial intelligence systems as well. For the latter the rule is twofold: they must be turned off by default in minors’ accounts, and they may not operate in ways that create emotional dependency in children.
A European legislative text thus qualifies emotional dependency on a conversational system as a risk to be regulated preventively, rather than as a side effect to be reported. The provision sits alongside the prohibition, already contained in Article 5 of the AI Act, of practices that exploit age-related vulnerabilities, and constitutes an operational specification of it: not a ban on placing on the market, but a configuration obligation. We addressed the liability of providers for the behaviour of conversational systems aimed at minors when commenting on the United States case involving Meta.
Age verification and the problem it brings with it
The proposal requires online services and app stores to use age verification tools, and expressly requires verification when a new account is opened on social media and video-sharing platforms. The technical reference is to the EU age verification app, which according to the Commission does not retain identity documents or biometric data.
The clarification is not a marginal one. Verifying everyone’s age in order to protect some means introducing a generalised identity check at the entrance to services that are today accessible in a substantially anonymous form, with a cost in terms of privacy that falls on every user, adults included. The selective disclosure solution, in which the system attests that an age threshold has been passed without transmitting the underlying data or retaining the document, is the only one that makes the measure proportionate. Whether it actually holds will depend on implementation, not on the text of the regulation, and on it will depend the effectiveness of the entire framework.
The reversal of the burden of proof
The structurally most significant element of the proposal is, however, another one, and it often goes unnoticed because it does not concern minors directly. The burden of proof shifts from regulators to platforms: providers of Very Large Online Platforms will have to show that their services are safe for children.
Until now the model has been the opposite. The authority had to identify the harm, reconstruct its link with a feature of the service and prove it, with investigation times that regularly exceed the useful life of the contested feature. If the proposal is approved in these terms, it will be the provider that has to document the safety of its service in advance, following a logic analogous to that which European law has adopted for decades for medical devices, toys and food, where nobody asks the authority to prove that a product is dangerous before it can be withdrawn.
The proposal builds on Article 28 of the Digital Services Act, which already requires appropriate measures to ensure a high level of safety for minors, and transforms that general principle into specific and verifiable obligations. The preparatory work is that of the panel of experts set up on the initiative of the President of the Commission.
Critical aspects
Three points deserve critical attention.
The first concerns the misalignment with the existing framework. Article 8 of the General Data Protection Regulation sets the age of consent for information society services at sixteen, allowing Member States to lower it to thirteen; Italy has chosen fourteen. Law No 132 of 23 September 2025, in Article 4, adopted the same threshold of fourteen for access to artificial intelligence technologies. The European proposal introduces two further thresholds, thirteen and fifteen, on a different axis, that of access to the service rather than that of the lawfulness of processing. For the same fourteen-year-old in Italy there will therefore coexist a consent to data processing that they may give on their own and a social media account that will have to be managed by a parent. Such coexistence is technically possible, but it requires a regulatory coordination that is currently lacking.
The second concerns the effectiveness of parental management. The “mini account” presupposes a parent who configures, supervises and understands. It is a measure that works well in families that already exercise that control and that risks not working at all where the minor is the only member of the household familiar with digital tools, that is to say, in the most exposed contexts. A safeguard that rests on the digital capacity of the adult amplifies inequalities instead of reducing them, unless it is accompanied by an investment in literacy which the text, by its nature, cannot contain.
The third concerns the one hour per day limit. It is a quantitative threshold applied to a qualitatively heterogeneous experience: an hour spent on a shared school project and an hour of passive scrolling receive the same treatment. The choice has the merit of verifiability, and is probably the only one that is workable in a legal rule, but it risks shifting use towards services not covered rather than reducing it, and consolidating the idea that the problem is duration rather than structure, which is instead what the proposal itself asserts elsewhere when it speaks of design. We dwelt on the European data on screen time and the wellbeing of minors in a previous contribution.
Conclusions
The EU KIDS Act is a proposal, and the text that emerges from the negotiations will differ from the one presented. Two elements, however, already have value today for those who design or operate digital services accessible to minors. The first is that safety by design is no longer a principle to be stated in privacy notices but a characteristic of the product that will have to be documented. The second is that the burden of demonstrating it is shifting onto those who offer the service. Those who are already able today to describe how their service limits the features that retain minors’ attention, which settings are set by default and why, will find themselves in a position of advantage; those who are not will have to reconstruct it retrospectively on a framework designed for opposite purposes.
Author: Valentina Grazia Sapuppo








