The EU KIDS Act: What you need to know (for now)

22nd September 2026

On 17 September 2026, the European Commission published its proposal for the EU KIDS Act ("EU Keeping Internet Digital Spaces Accountable and Trustworthy"), a new Regulation designed to create a single, harmonised EU framework for the protection of minors online. It is a proposal for a Regulation of the European Parliament and of the Council, COM(2026) 681 final, based on Article 114 TFEU (internal market harmonisation).

Why It Exists

The Commission’s concern is regulatory fragmentation: several Member States have already notified or are developing national laws restricting minors’ access to digital services, with divergent scope, age thresholds and restrictions, risking a fragmented single market, legal uncertainty and uneven protection.

The proposal is expressly designed to sit alongside and use frameworks set out under the Digital Services Act (Regulation (EU) 2022/2065), particularly Article 28 on the protection of minors, and to complement the AI Act (Regulation (EU) 2024/1689) for AI companions and chatbots.

 

Who Is In Scope

The Regulation applies to providers of online social networking services, video-sharing platform services, software application stores, online games, operating systems, AI companions and general conversational chatbots that are accessible to minors, regardless of the provider’s place of establishment where EU-based recipients are targeted. Small and micro enterprises are not exempted.

Narrow carve-outs exist for not-for-profit encyclopaedias and educational or scientific repositories, purely educational services, open-source platforms (unless they are in-scope AI systems), scientific research services, and public-authority systems.

 

Headline Obligations

 

  • Minimum age for social media and video-sharing accounts

Providers of social networking and video-sharing services with certain risk-triggering features (real-time broadcast, contact with non-connections, profiling-based recommender systems, engagement-maximising design) must not let anyone under 15 create or use an autonomous account. A guardian may set up a limited-functionality account for a 13–15 year-old, subject to conditions including a one-hour daily time cap and guardian pre-approval of contacts. Existing accounts must be assessed within six months of the Regulation applying, and accounts of confirmed or unverifiable under-15s must be disabled.

  • Safety by design

Providers must not design services to encourage compulsive or excessive use (autoplay, non-activity notifications, engagement-frequency rewards) and must build in time-management and interruption tools protecting school time and core sleep hours. High-privacy default settings are mandated (geolocation, microphone or camera access, contact recommendations and push notifications off by default). AI companions and general conversational chatbots face bespoke rules, including bans on features fostering emotional dependency, disabled persistent memory by default, and mandatory pre-market testing and post-market monitoring.

  • Age assurance

For the age-15 threshold, providers must rely exclusively on an “EU age verification solution” using an EU proof of age attestation certified under a new EU Age Verification Scheme, interoperable with the EU Digital Identity Wallet. For general safety-by-design purposes, other compliant age assurance methods may be used. Self-declaration alone is expressly insufficient, and all age assurance must meet accuracy, reliability, security, non-intrusiveness, privacy and non-discrimination criteria, built on data minimisation and zero-knowledge-proof principles.

 

Impact on Video Games

Online games, defined broadly to cover both individual video games and video gaming platforms, are a distinct and significant category of in-scope service under the proposal, separate from social media and video-sharing services, subject to a bespoke set of rules it sets out in Article 15. The definition is deliberately wide: it captures any game playable on a computer, mobile device or console, whether executed locally or remotely, and whether monetised through upfront payment, free access or in-app purchases. Only games accessible exclusively through physical media with no online component fall outside scope. Where a game also functions as a video-sharing platform, it is treated as an online game for these purposes.

The Commission’s recitals acknowledge that games bring real benefits to minors, including entertainment, social connection across age groups and geographies through multiplayer functionality, and support for learning in areas such as coordination, cooperation, science, mathematics and languages, and for minors with disabilities in particular. At the same time, the proposal treats both individual video games and video gaming platforms as carrying diverse risks that justify tailored intervention, distinct from the generic DSA duty of care already owed by video gaming platforms as online platforms.

  • Risks the proposal targets

The recitals identify particular vulnerabilities in online games: unsolicited contact and communication features (voice and text chat, friend requests) that can expose minors to grooming or harassment; exposure to content unsuitable for a minor’s age, including through user-generated content within a game; and design features such as reward loops, variable rewards, loot mechanics and time-pressured prompts, which can foster compulsive, excessive or addictive play patterns. In-game monetisation is treated as a related but distinct risk, given the difficulty minors and guardians can have in understanding the real monetary value of virtual currencies and the resemblance of certain reward mechanisms to gambling.

  • Article 15 obligations

Providers of online games must ensure a high level of privacy, safety and security for minors by design and by default. In practice this requires, at a minimum: (i) restricting or disabling features that facilitate unsolicited contact with minors from persons who are not existing connections; (ii) applying the same restrictions on compulsive or excessive use, and the same high-privacy default settings, that apply to social media and video-sharing services under the general safety-by-design regime; (iii) implementing safeguards to prevent the game being used to entice minors into initiating contact with individuals on other services, including third-party messaging or social platforms, where that follow-on contact may expose the minor to additional risks not addressed within the game itself; and (iv) giving guardians tools to oversee and manage a minor’s use of the game, including guardian-controlled access and settings for users under 13.

  • User-generated and platform-hosted games

Where a video gaming platform allows recipients of the service to create and publish their own games, the platform provider must put in place the necessary software and organisational measures to enable those user-created games to comply with the same Article 15 obligations, rather than treating user-generated content as outside its own compliance perimeter. This places an affirmative design and governance burden on platforms with creator ecosystems (for example platforms supporting user-built game modes or experiences), not just on the studios that publish games directly.

  • Monetisation and virtual currency

Minors are entitled to the same protections around economic transactions in online games as apply on social media and video-sharing services. Providers must give harmonised, easily understandable information on the real monetary value of virtual currencies and items before a minor can make a purchase, and must not deploy variable reward mechanisms (for example randomised loot boxes or similar chance-based reward features) in a manner that resembles gambling or is designed to encourage compulsive spending. Providers must also offer regular, transparent reporting to guardians on a minor’s in-game spending.

  • Codes of conduct and co-regulation

The proposal favours a co-regulatory approach for this sector. The Commission may facilitate and assess a code of conduct on age rating and safety design for online games, which industry may develop building on existing pan-European self-regulatory frameworks such as PEGI. Demonstrated adherence to an approved code can be used as a factor showing compliance with the safety-by-design and age-appropriate design obligations, but it does not substitute for the underlying statutory duties, which remain independently enforceable.

  • Supervision and enforcement

Online games follow a different enforcement path from the other in-scope services. Rather than falling under the Commission’s centralised, exclusive competence (which is reserved for very large online platforms and in-scope AI systems), compliance by providers of online games is supervised by the Digital Services Coordinator or other competent authority of the Member State where the provider has its main establishment, applying the DSA’s existing cooperation and mutual assistance mechanisms. Games nonetheless remain subject to the wider DSA supervisory architecture, so a games business already engaging with its Digital Services Coordinator on DSA compliance should expect the same authority to pick up EU KIDS Act obligations.

 

Enforcement and Timing

Enforcement piggybacks on existing DSA and AI Act structures: the Commission has exclusive competence over very large online platforms and relevant AI systems, with an expedited procedure targeting preliminary findings within 30 days and a final decision within 90 days. Non-compliance by AI companion or chatbot providers can attract fines of up to 6% of worldwide annual turnover.

As drafted, the Regulation would apply six months after entry into force, with the compliance-plan obligation (Article 5) applying immediately and the national support-strategy and expedited-enforcement provisions applying after 12 months.

 

What This Means in Practice Now

This is a proposal, not adopted law. It will go through the ordinary legislative procedure (Parliament and Council), so scope, age thresholds and timelines may shift. It follows the July 2026 recommendations of the Commission’s Special Panel on Child Safety Online and reflects strong political momentum, including the Jutland Declaration and European Parliament and Council conclusions calling for harmonised digital age limits and age assurance rules.

Tech, platform, gaming and AI-companion providers could start now on the following:

  • map which services trigger the Article 6 risk criteria for the 15-year account threshold, including whether recommender systems rely on profiling;
  • for games and gaming platforms specifically, assess open-chat, contact and in-game monetisation features against the Article 15 obligations, and consider whether an existing or forthcoming age-rating code of conduct (including PEGI-based frameworks) can be leveraged to help demonstrate compliance;
  • assess what age assurance infrastructure will be needed, particularly readiness to integrate with the EU Age Verification Scheme and EU Digital Identity Wallet;
  • review guardian-tool and parental-control functionality against the Article 20 requirements; and
  • track the legislative file (2026/0286 (COD)) for amendments as it moves through trilogue negotiations between the European Parliament, the Council of the European Union, and the European Commission.

Please contact our videogames team if you would like to discuss or receive advice on any specific aspect of the proposal.