Quick Thoughts on EU Kids Act Leaked Draft

Thoughts on the draft EU law limiting internet access to young people (the "Kids Act"), particularly how it fits with existing EU tech legislation like the Digital Services Act.

Quick Thoughts on EU Kids Act Leaked Draft

Some things which jumped out to me on first read of leaked draft EU Kids Act (document via @netzpolitik - https://netzpolitik.org/2026/eu-kids-act-eu-kommission-will-netz-mit-alterskontrollen-zupflastern/ ]. 

Update: A proposal has now been officially published. Quick Claude check suggests it’s largely unchanged from leak but I haven’t yet done a manual review. https://digital-strategy.ec.europa.eu/en/library/proposal-eu-kids-act-eu-keeping-internet-digital-spaces-accountable-and-trustworthy

Caveat: These are very quick responses to the text, not bigger “will this work”, “is this a good idea”, “what about privacy / civil liberties” etc.

One broader point: Whatever one thinks about protecting young people online, there is already a massive EU digital rulebook (see below). We already have a new Digital Fairness Act coming (which will address similar problems as the DSA, but will be administrated by a different Unit in the EUCOM...). This on top of updates and implementation challenges with existing rules.

Each new Act results in another branching timeline of consultations, working groups, webpages, arguments over competencies... Regulation needs to be able to update, iterate, and learn. But there must be a more pragmatic lever than "make a new Act"? See: https://www.kaizenner.eu/post/2026-09-01-digital-enforcement-gap

Text of the Act:

Summary: 13-15 year olds can create accounts with limits - see later point - plus parental controls. Under 13s can access particular services via a guardian’s account (and there are strong requirements on those services e.g. impact assessment).

Scope of affected services is broad - see below - with no SME exemptions. Some exemptions which I suspect will be litigated a lot (given “exemption” means “I don’t have to verify every EU user”).

This Regulation applies to providers of the following services or systems accessible to minors: (a) online social networking services; (b) video-sharing platform services; (c) software application stores (d) online games; (e) operating systems; (f) AI companions; (g) general conversational chatbots.
This Regulation does not apply to the providers of any of the following: (a) not-for-profit online encyclopaedias; (b) not-for-profit educational and scientific repositories; (c) services and systems that are designed for primarily educational purposes, and operated by educational establishments or organisations, or on their behalf; (d) open-source software-developing and-sharing platforms, unless the platform itself constitutes an AI system in scope of this Regulation or Regulation (EU) 2024/1689; (e) services and systems specifically developed and operated for the sole purpose of scientific research and development; (f) services and systems designed, developed and operated by public authorities and for exclusive use of those public authorities or on their behalf.

Services will have 6 months after Act comes into force to verify existing users.  That will be a big media moment (and probably not positive for the EU, as adults are confronted with it).

On the debate between age verification vs. assurance, it seems verification will be required for Art 6 (is the account under 15) but only assurance for safety by design and app stores.  I find the language slips unhelpfully between the two, tbh. I won’t go into the requirements for the tools to be “EU approved” etc. here but it’s in the Act.  See Art.29 on.

The combination of online services, chatbots, and games means enforcement is a mix of DSA, AI Act, some DMA, and some new provisions - each bit enforced by own existing regulators, plus maybe new ones.  This could get complicated and I expect will end up with more power to EUCOM (but which part of EUCOM?)

For VLOPs and VLOSEs under DSA, the provisions add new parts to existing risk assessment procedures (see e.g. new auditing requirement below).  Will this make child safety a “priority risk” above the other risks, or will other systemic risks be gradually brought in line with child safety?

For the purpose of enabling the Commission to assess the compliance of providers referred to in paragraph 1 with the obligations laid down in Chapters II to V, those providers shall, at their own expense, commission an audit of the compliance plan notified pursuant to paragraph 1 by one or more independent auditors. The independent auditors shall have, or shall retain experts with proven expertise in the following areas relevant for the protection of minors: (a) protection and rights of the child; (b) paediatric medicine and child psychiatry; (c) developmental science; (d) age assurance; (e) the design of online interfaces and recommender systems; (f) data protection and security. Article 37(2) and (3) of Regulation (EU) 2022/2065 shall apply mutatis mutandis to the audits carried out pursuant to this Article and to the independent auditors and any...

Also - see the below in the new text. Is this a response to complaints DSA enforcement is too slow?  90 working days would be a LOT faster than “some years”

Where the Commission initiates proceedings for infringement of this Regulation in accordance with Article 66 of Regulation (EU) 2022/2065 or Article 75a of Regulation (EU) 2024/1689 in view of the possible adoption of decisions pursuant to Articles 73 and 74 of Regulation (EU) 2022/2065 or Articles 75c of Regulation (EU) 2024/1689, the Commission shall endeavour to: (a) communicate its preliminary findings to the provider concerned within [30] working days from the opening of the proceedings pursuant to Article 66 of Regulation (EU) 2022/2065 or Article 75a of Regulation (EU) 2024/1689; (b) adopt a final decision within 90 working days from the opening of proceedings.

The things restricted for 13-15 year olds are the expected: contact with strangers, recommender systems, and infinite scroll, also livestreaming. On the first, I suspect language around “pre-existing contacts” will be hard to enforce. 

On recommender systems, primary weight is to be given to explicit user-stated preferences but implicit signals are by default not to be used. This could prompt a genuinely interesting debate about what these are and when implicit signals are actually bad.

Article 20 - details of parental controls - is foreshadowed a lot but quite slim in the end. Even within parental controls, the Act says screentime can only be set by parents to maximum 1 hour daily.  I imagine this won’t help any “over-reach” narratives.

The objectives apparently include empowerment of young people, but I find that very thin in the Act. Stakeholders to be consulted explicitly says “parents”, but not young people (a “Youth Advisory Group” and “youth representatives” were consulted, but I find their omission in the consultation article revealing).

On my usual question “who gets to be a consulted expert” - Safer Internet Centres are explicitly mentioned as a model.  ECAT mentioned nowhere.

Also, is this the first EU text to steal the US approach of backronyms? Please can it be the last? We don’t need tortured neologisms like “Internet Digital Spaces”.

Proposal for a  REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL  EU KIDS ACT - 'EU Keeping Internet Digital Spaces Accountable and Trustworthy'  {SWD(2026) 681 final}