02.10.2026
Legal Alert | Proposal for a Regulation "EU Kids Act"
On 17 September 2026, the European Commission adopted the proposal for the “EU Kids Act” Regulation, which aims to strengthen the protection of minors across the digital environment. The proposal sets out rules on children’s and young people’s access to social media, safety and privacy by design, age verification and verification of parental responsibility, parental controls and data protection, as well as national support measures and a framework for supervision, enforcement and sanctions coordinated with the DSA, the AI Act and the GDPR. The document now proceeds to the European Parliament and the Council of the European Union as the legislative process continues.
On 17 September 2026, the European Commission adopted the proposal for the “EU Kids Act” Regulation. Through this initiative, the European Union aims to strengthen the protection of minors across the digital environment, ensuring their wellbeing, safety, privacy and freedom of expression considering the risks inherent in the use of social media.
The “EU Kids Act” prohibits children under the age of 13 from accessing social media platforms and sets the minimum age for creating an account at 15.
The main measures that the European Union intends to introduce are outlined below:
1. Delaying the creation and use of accounts by minors
- Prohibition on the creation and use of accounts by children under 15 years of age: wherever a social media or video-sharing service poses a risk to a child’s privacy, protection or safety, the creation and use of an account is prohibited. The risk is assessed based on the platform’s features, in particular live streaming options, contact with strangers and the encouragement of uninterrupted content consumption (see Article 6(1));
- Restrictions for children aged between 13 and 15: in these cases, the creation and use of accounts is subject to strict conditions, including the account being set up by a parent or guardian, the permanent activation of parental controls, a maximum usage limit of one hour per day, pre-approval of new contacts, a limit on the number of contacts, and prior verification of parental responsibility and that the child is at least 13 years old (see Article 6(2));
- Obligation for platforms to verify the age of existing account holders: platforms are obliged to verify accounts and to deactivate those belonging to children under 15 or whose age cannot be properly verified (see Article 6(4));
- Parental control on platforms for children under 13 years of age: where content is specifically designed for children under 13, access must be strictly controlled by parents, subject to the cumulative fulfilment of the following conditions: i) the account must not have been created or directly assigned to the child; ii) mandatory use of the tools provided to parents or guardians (see Article 20 of the proposal under consideration); iii) express authorisation from the service provider, subject to parental approval; iv) publication of an impact assessment on the risks to this age group; and v) a public definition of inappropriate content, with recommendations, personalisation and search functions blocked and disabled by default, unless the child’s best interests are demonstrated for that purpose (see Article 7(1)).
2. Safety by design
- Design of safe applications: a general design obligation is imposed to ensure a high level of protection and safety for minors, applicable to social media, video platforms, online games, companion Artificial Intelligence (AI), general-purpose chatbots and app stores (see Article 8(1));
- Prohibition of addictive features: addictive features include, amongst others, the automatic playback of content, the sending of notifications unrelated to the child’s activity, and the provision of incentives for frequent interaction under threat of losing benefits (see Article 9(1) and (2));
- Privacy-focused recommendation systems: platforms must use recommendation systems that ensure a high level of privacy and security, give priority to the user’s explicit preferences, do not collect the child’s personal data outside the service, and have recommendations based on implicit behavioural signals disabled by default (see Article 10(1) and (2));
- Default privacy settings: measures must be adopted to ensure settings that provide a high level of protection for minors, notably the disabling, by default, of geolocation, the microphone, the camera and automatic notifications (see Article 11(1));
- Transparency in financial transactions: service providers must inform minors, in a clear, comprehensible and real-time manner, whenever a financial transaction takes place; furthermore, the introduction of features likely to lead to excessive spending is prohibited (see Article 13(1) and (2));
- Protection against emotional dependence on AI: providers of companion AI and chatbots are required to adopt specific measures to prevent emotional dependence amongst young people (see Article 14(1));
- Control and reporting: platforms must include features enabling minors to control content and report suspicious activity (see Article 18(1) and (2), and Article 19(1));
- Use of platforms by parents or guardians: effective, accessible, user-friendly tools must be implemented which are proportionate and respect the privacy and autonomy of minors, and which can be used by parents or guardians to monitor minors’ use of the platforms (see Article 20).
3. Age verification and verification of parental responsibility
- Methods for verifying parental responsibility: to create restricted accounts or age-appropriate experiences, service providers may use online databases or public interfaces made available by Member States, the service’s usage history, or a self-declaration by the responsible adult (see Article 26(1)(a), (b) and (c));
- Age verification: the age verification solutions implemented by platforms must ensure a high level of accuracy, reliability, security, robustness, privacy, non-intrusiveness, data protection and non-discrimination (see Article 27);
- Strict data protection: age verification solutions must not identify, track, target or profile the user, and providers must process only the data strictly necessary to verify the age threshold. The measures must also be based on advanced technology and rely on zero-knowledge proofs (see Article 27(1) and (3)).
4. National support measures for minors
- Duty of Member States to provide support: Member States must support the protection of minors by implementing national strategies that ensure free, confidential and easy access to support services in the event of harm suffered, and that promote appropriate information on digital literacy (see Article 33).
5. Supervision, enforcement and sanctions
- Need to coordinate measures with the Digital Services Act (Regulation (EU) 2022/2065 – DSA) and the Artificial Intelligence Act (Regulation (EU) 2024/1689 – AI Act):
i) For the purposes of supervising and enforcing the obligations imposed by the Regulation on service providers covered by the legislation, Member States shall designate one or more competent authorities responsible for the application of the Regulation (see Article 34(1));
ii) For the purposes of supervising and enforcing the obligations imposed on providers of AI-powered chatbots and conversational robots, failure to comply with those obligations shall result in the imposition of fines not exceeding 6% of the provider’s current global turnover, where it is found that the provider has acted intentionally or negligently (see Article 34(2));
iii) Member States must ensure that the national bodies responsible for enforcing compliance with the DSA, as well as the authorities responsible for the AI Act, are empowered to enforce the “EU Kids Act”, thereby ensuring the necessary regulatory consistency (see Article 34(3));
iv) The supervisory and enforcement powers conferred on the Commission under Chapter IV, Section 4, of the DSA and Articles 75a to 75d and 99 of the AI Act are extended to the supervision of compliance with the “EU Kids Act” by the same economic operators (see Article 34(4));
v) Where obligations involving the processing of personal data are concerned, the monitoring and imposition of sanctions fall within the remit of the data protection authorities, in accordance with Articles 51 and 84 of Regulation (EU) 2016/679 (GDPR) (see Article 34(6));
vi) In the case of large online platforms (with an average monthly number of active service recipients in the Union of 45 million or more, in accordance with Article 33 of the DSA) or an AI system subject to Commission supervision under the AI Act, where there is a suspicion of a breach of the rules of the “EU Kids Act”, the Commission will adopt an accelerated procedure: it will notify the operator of its preliminary findings within 30 working days and issue a final decision no later than 90 working days after the proceedings are initiated (see Article 35).
Following the European Commission’s adoption of the proposed Regulation, the document now proceeds to the European Parliament and the Council of the European Union, as the legislative process continues.
The Morais Leitão’s Technology team will continue to closely monitor legislative and regulatory developments applicable to the artificial intelligence sector, and remains fully available to answer any further questions.