On 17 September 2026, the European Commission presented its proposal for a Regulation known as the EU Kids Act (EU Keeping Internet Digital Spaces Accountable and Trustworthy). The proposal addresses the main outstanding issues concerning the protection of minors online – minimum age requirements for access to social networks, the age for digital consent, responsible service design and age verification – seeking to bring them within a single harmonised framework. If adopted, this Regulation will fundamentally reshape the relationship between minors, digital services and AI systems in the internal market.
A broader scope than expected
The proposal is based on Article 114 TFEU and builds on the framework of the Digital Services Act, specifying and complementing its provisions, while also complementing the AI Act with specific safeguards for minors. Its scope is significantly broader than that of the individual national measures announced to date (including Italian Bill No. 1136) and covers, in particular:
The exclusions are limited to a small number of categories of services (non-profit encyclopaedias and scientific repositories, purely educational services operated by educational institutions, open-source platforms, scientific research services and public administration services). SMEs and micro-enterprises, by contrast, are not granted any substantive exemptions.
The access restriction: a European threshold of 15
Chapter II of the proposal introduces a harmonised age threshold of 15 for the independent creation of accounts with online social networking services and video-sharing platform services, thereby overcoming the national divergences that have dominated the debate in recent months. The framework, however, goes beyond the access restriction itself:
The Italian framework under Bill No. 1136 (based on a threshold of 15 and verification through a digital mini-wallet) is broadly aligned with the European model, but constitutes only a subset of it: if the EU KIDS Act is adopted, Italian legislation will have to be brought into line with it and, for matters covered by the Regulation, replaced by the directly applicable Union framework. Chapter IV lays down detailed rules on the verification of parental responsibility, which is a prerequisite for the creation of accounts for users aged 13 to 15 and for activating the derogations provided for video-sharing platform services specifically designed for minors below the age of 13. In particular, Article 26 requires providers to use, in order of preference, signals from public databases of the Member States, signals already held by the provider as a result of previous interactions with the user and, on a transitional basis – until the delegated act is adopted –, the adult’s self-declaration, which the provider must nevertheless make reasonable efforts to verify. Member States are also required to make available at least one free, privacy-preserving electronic tool enabling a guardian to obtain and present evidence of parental responsibility.
Service design: safety by design becomes hard law
Chapter III turns a substantial part of the content of the Commission’s Guidelines adopted pursuant to Article 28(4) of the DSA into binding requirements. For online social networking services, video-sharing platform services, online games, AI companions and general conversational chatbots, these include, in particular:
These requirements are complemented by tools designed to strengthen the ability of minors and guardians to exercise control over the service (the agency of minors referred to in Article 18). These include child-friendly reporting channels, with priority handling of complaints submitted by minors; tools for controlling content and settings with lasting effects; tools for guardians which VLOPs (Very Large Online Platforms) will have to make interoperable with third-party solutions pursuant to Article 6 of the DMA; and the right to lodge a complaint with the competent authority, including through designated organisations. VLOPs will also be required to periodically monitor the effectiveness of the measures adopted and to adopt sectoral codes of conduct.
Age verification: the EU Age Verification Solution becomes the single reference framework
Chapter V makes mandatory the European age-verification solution anticipated by Recommendation (EU) 2026/1035. For the purposes of complying with the access restrictions, providers will be required to use exclusively the EU Age Verification Solutions and EU proof of age attestations included in the relevant EU lists and compliant with the EU Age Verification Scheme, based on zero-knowledge-proof technology. Self-declaration is expressly excluded.
For the purposes of safety-by-design requirements, other age-assurance solutions may instead be used, provided that they meet the requirements of accuracy, reliability, robustness, security, non-intrusiveness, privacy protection and non-discrimination. Member States are required to ensure, within their territory, the free availability of at least one EU Age Verification Solution and of tools suitable for attesting parental responsibility.
A particularly sensitive issue concerns existing accounts. Providers will have to re-verify the age of existing users through an EU Age Verification Solution, unless they are able to demonstrate, with a high degree of confidence, that the user has already reached the minimum age required to access the service. VLOPs will have to submit to the competent authority a dedicated plan setting out the modalities and timetable for this retrospective verification. This is one of the Regulation’s most significant operational burdens.
Supervision, sanctions and representative actions
The Regulation does not establish a standalone supervisory framework, but builds on the institutional arrangements already established by the DSA and the AI Act, drawing on their competent authorities and procedural mechanisms. The allocation of responsibilities is calibrated to the type of service and designed to prevent overlaps. Supervision is entrusted to the Digital Services Coordinators designated pursuant to Article 49 of the DSA for online social networking services, video-sharing platform services, video gaming platform services and software application stores, and to the market surveillance authorities designated pursuant to Articles 70 and 74 of the AI Act for AI companions and general conversational chatbots. The Commission retains exclusive competence over VLOPs and AI systems falling within its competence, with an expedited enforcement procedure under which the Commission is to communicate preliminary findings to the provider concerned within 30 working days from the opening of proceedings and endeavour to adopt a final decision within 90 working days.
The sanctions regime varies according to the type of addressee:
In addition, Article 36 of the proposal establishes an annual supervisory fee, structured as a top-up to the fee already provided for under Article 43 of the DSA, the principles of which the Commission must also follow when applying the new provision. The entities liable for the fee do not coincide with all entities falling within the scope of the Regulation. The fee is payable only by providers of online social networking services, video-sharing platform services, software application stores, AI companions, general conversational chatbots and video gaming platforms which, having been designated as VLOPs under Article 33 of the DSA or otherwise falling within the Commission’s exclusive competence, are subject to its direct supervision. The amount is fixed annually and shall not exceed 0.03% of the provider’s worldwide annual net income in the preceding financial year. It must be assessed together with the ceiling provided for under the DSA, so that the overall burden remains proportionate to the economic capacity of the individual operator. On the expenditure side, the fee is intended to cover the costs incurred by the Commission in the preceding year for supervisory, monitoring, investigative and enforcement activities, including dedicated human resources, the development of the expertise and capabilities referred to in Article 37 and, in particular, the set-up, maintenance and operation of the EU Age Verification Scheme, including the financing of the deployment of the European age-verification solution across the Union. The methodological details – including cost estimates, the calculation of individual fees, the maximum ceiling and payment arrangements – are deferred to subsequent delegated acts.
As regards litigation, Article 41 is particularly significant. It amends Annex I to Directive (EU) 2020/1828 by adding the Regulation to the list of Union acts whose infringement may give rise to representative actions for the protection of minors. This choice is likely to have significant operational consequences. Over the medium term, a substantial increase in collective litigation in this area may reasonably be expected, with a corresponding expansion of the risk profile for providers.
Compliance plan, independent audit and national strategies
VLOPs designated under Article 33 of the DSA will be required to notify the Commission of a detailed compliance plan, setting out how they intend to comply with the obligations laid down in Chapters II to V of the Regulation, and to submit that plan, at their own expense, to an independent audit conducted by one or more external auditors. The auditors shall have, or shall retain experts with proven expertise in six specific areas relevant for the protection of minors: (i) protection and rights of the child; (ii) paediatric medicine and child psychiatry; (iii) developmental science; (iv) age assurance; (v) the design of online interfaces and recommender systems; and (vi) personal data protection and security. This is the only obligation under the Regulation that, pursuant to Article 5, will apply from the date of its entry into force, by way of derogation from the general deferred application regime.
Chapter VI, by contrast, requires Member States to adopt national strategies to ensure that minors and their guardians have free, confidential and accessible access to dedicated support channels, including for cyberbullying and unwanted contact; adequate information about the risks addressed by the Regulation and the available means of protection; and structured digital-literacy initiatives, drawing on the experience and expertise of the Safer Internet Centres. The strategies must be communicated to the Commission within 12 months of the Regulation’s entry into force.
Entry into force and application
Article 43 establishes a staggered application regime. The Regulation will enter into force on the twentieth day following its publication in the Official Journal of the European Union and will generally become applicable six months later. There are two exceptions. Article 5, concerning the compliance plan and independent audit for VLOPs, will apply from the date of entry into force, while Articles 33, concerning national strategies, and 35, concerning the expedited enforcement procedure, will apply 12 months after entry into force. The Commission will be required to review the Regulation by 31 August 2030, followed by four-yearly reports.
Preparing for the EU KIDS Act: an agenda for businesses
The legislative process is only just beginning and the final text may depart, even significantly, from the proposal currently under consideration. The policy trajectory reflected in the proposal, however, is sufficiently clear to enable businesses to start shaping their product-design choices now. The codification of safety by design into binding law, the central role of the EU Age Verification Solution as a common verification infrastructure, the emergence of verification of parental responsibility as an autonomous mechanism and the opening of the door to representative actions constitute structural elements of the proposed framework that are unlikely to disappear from the legislative debate. From an operational perspective, the relevant question is therefore not so much which measures will have to be implemented once the Regulation enters into force, but rather which design choices should already be made for services intended to operate within that regulatory environment.
The first area for action concerns product design. Many solutions still treated as commercial trade-offs – recommendation systems based on behavioural signals enabled by default, persistent conversational memory for AI companions, push notifications without protected time windows, livestreaming accessible to minors, aesthetic filters and social-comparison metrics – are likely to become, under the European framework, binding design constraints. Downstream adaptation of architectures that were not originally designed in accordance with the regulatory framework will generally entail significantly higher costs than incorporating those requirements ex ante as design parameters. From this perspective, the proposal –although not yet in force – can already usefully be read as a technical specification against which products currently on the roadmap should be assessed.
The second area concerns age verification as an infrastructure layer, distinct from product functionalities. The emergence of the EU Age Verification Solution as the common infrastructure for the purposes of access restrictions, as well as the central technical reference point for safety-by-design requirements, calls for age-assurance components to be treated according to a modular model, decoupled from the remainder of the application stack. Providers that currently rely on proprietary age-assurance solutions, or that structurally integrate self-declaration into the onboarding funnel, should already consider appropriate exit clauses and interoperability requirements enabling those solutions to be replaced by the European infrastructure as soon as it becomes available. This is accompanied by a separate area of significant operational complexity: the re-verification of age for existing accounts. Planning for this process – including user communications and the management of cases in which re-verification is unsuccessful – should begin now, given that the period between entry into force and full application of the Regulation leaves little room for late implementation.
The third area concerns the contractual chain and internal governance. Compliance under the proposal cannot be handled solely by the legal function. It involves, jointly, the product function – responsible for supporting safety-by-design requirements and contributing to the compliance plan –; the risk function, which must map the new exposures; the network of third-party providers – for age assurance, recommendation systems, interoperable tools for guardians under Article 6 of the DMA, and independent auditing – whose contractual arrangements will need to be renegotiated or reviewed from a compliance-by-design perspective; and, finally, the data function, with regard to Articles 27-29 of the Regulation and the GDPR framework. For VLOPs, the compliance plan and related independent audit under Article 5, which will apply immediately upon entry into force, presuppose an internal ownership structure that, at present, has not yet been fully defined in a number of groups.
The fourth area concerns the risk profile, understood in a broad sense. The combined effect of sanctions of up to 6% of the worldwide annual turnover, the Commission’s expedited enforcement procedure and the inclusion of the Regulation in Annex I to Directive (EU) 2020/1828 creates a dual exposure. On the one hand, there is administrative and sanctioning exposure, in continuity with the frameworks already established by the DSA and the AI Act. On the other, there is exposure to collective litigation, for which the digital sector does not yet have an established body of European case law but which, following this legislative development, may emerge relatively quickly. This makes it appropriate to incorporate the issue into regulatory and reputational risk assessments already at this stage, with particular attention to disclosures to the market by listed issuers.
Ultimately, uncertainty surrounding the legislative process is not, in itself, sufficient reason to defer preparations for compliance. The overlap between the EU KIDS Act, the DSA, the AI Act, the GDPR and national rules already in force or at an advanced stage of development – first and foremost Bill No. 1136 – makes early compliance, from an implementation perspective, substantially indistinguishable from compliance with obligations that are already in force. Many of the requirements that the Regulation would make binding are already grounded, wholly or in part, in instruments currently applicable. Adopting a compliance-by-design approach now therefore serves not only to prepare for the future regulatory framework, but also to bring greater systemic coherence to a regulatory landscape that, despite its fragmentation, is progressively converging towards a unified model of accountability for providers of digital services accessible to minors.