The EU Kids Act remains a proposal, but the European Commission’s direction is already visible. On September 16, 2026, Ursula von der Leyen announced a plan to restrict social-media access for children under 13, place 13- to 15-year-olds in supervised accounts and impose “safe by design” expectations on services used by minors. The practical centerpiece is age assurance: proving that a user meets a threshold without handing an entire identity file to every website.
A separate leaked draft reportedly goes further, outlining age tiers from 0–3, 3–13, 13–15 and 15–18 and potentially bringing risky online games, video-sharing platforms and AI chatbots or companions into the discussion. Those details remain part of reported draft material, not an enacted legal regime.
What the EU announced on September 16, 2026
The announced social-media plan would restrict access for children under 13. Teenagers aged 13 to 15 would reportedly use parent-created, supervised mini-accounts rather than ordinary personal accounts. Those accounts would have limited features, and a reported outline includes a one-hour-per-day limit.
The policy direction also calls for services used by minors to be safer by design. The reported goals include limiting addictive design features such as infinite scrolling, regulating recommender systems and providing safer account settings. The political argument is that platforms should not rely solely on a child’s ability—or a parent’s constant vigilance—to avoid harmful design choices.
The proposal is not currently an EU law. The announced plan and reported draft describe a future regulatory framework; they do not create an effective restriction for users today.
What the reported draft would add
A leaked draft reportedly describes age verification when a user opens a new account on covered social-media and video-sharing services. It divides users into four age bands:
- 0–3: reportedly barred from social media and risky services.
- 3–13: reportedly eligible for fully parent-controlled accounts on child-friendly services that meet safety standards.
- 13–15: aligned with the announced plan for supervised, limited accounts.
- 15–18: reportedly eligible for autonomous accounts when the online environment is safe by design.
The same draft could extend the framework beyond conventional social networks. Risky online games, AI chatbots and AI companions are among the services reportedly under consideration. The exact thresholds, definitions and access procedures for games and AI services have not been set out as final rules.
That distinction matters for gamers and AI users. A proposal to verify age when opening an account is not the same thing as a confirmed requirement for every game, chatbot or account in the European Union.
How age verification could work
The European Commission’s separate age-verification solution is designed to issue a simple threshold credential—for example, whether someone is over 18—without disclosing unrelated identity information to the service. The system is intended to work with future European Digital Identity Wallets and to adapt to thresholds such as 13+.
The demonstration presents four possible ways to establish age: a national electronic ID, a passport or identity card, a third-party app, or an in-person check. In one example, a user scans a QR code on a cinema website and receives a “yes” or “no” proof of age. The demonstration also describes zero-knowledge proofs, a cryptographic technique intended to prove a fact without revealing the underlying data, and says that document data and photos are not stored in the app.
Whether this Commission solution would be mandatory for compliance with the EU Kids Act has not been determined.
The privacy and enforcement fault lines
A threshold credential could reduce the amount of information a platform receives. A service may need to know only whether the user meets an age requirement, rather than receiving a name, birth date or a copy of an identity document. That is the privacy promise behind the Commission’s design.
The difficult question is how that promise survives real-world deployment. Age checks must be accurate enough to separate children from adults, usable across many services and resistant to circumvention. Parents may also receive significant control over younger users’ accounts, raising a separate question about how much supervision is appropriate as children gain more autonomy.
A deep level of parental access can affect how freely teenagers use a service and can create privacy concerns of its own. The system therefore has two sensitive boundaries to manage: what platforms learn about a user and what parents can see or control.
The community debate has focused on those fault lines. Skeptics have raised concerns about repeated checks, identity-data breaches, loss of online anonymity and circumvention through tools such as VPNs. Other commenters favor a threshold-only system in which a trusted issuer confirms age without revealing a user’s name or identity-document details. Those are competing views about implementation, not provisions of the proposed framework.
What happens next
The European Commission published an age-verification blueprint on July 14, 2025, said a feature-ready solution became available on April 15, 2026, and adopted a recommendation for a common EU-wide approach on April 29, 2026. That recommendation asks Member States to work toward making at least one compliant age-verification solution available in every Member State by the end of 2026.
| Date or period | Event | What it concerns |
| July 14, 2025 | The European Commission published an age-verification blueprint. | Technical groundwork for proving age online |
| April 15, 2026 | The Commission said a feature-ready solution became available. | A customizable age-verification system |
| April 29, 2026 | The Commission adopted a recommendation for a common approach. | National preparation and interoperable age checks |
| September 14, 2026 | A leaked draft was reported. | Age tiers, account checks, games and AI services |
| September 16, 2026 | Ursula von der Leyen announced the social-media policy direction. | Under-13 restrictions, supervised teen accounts and safer design |
| By the end of 2026 | The Commission’s recommendation set a target for national availability. | At least one compliant age-verification solution in each Member State |
| Around 2029 | A legal estimate placed the broader legislative process around this point. | The possible timetable for the wider framework |
The end-of-2026 target concerns the availability of an age-verification solution, not the entry into force of the EU Kids Act. A legal estimate places the wider legislative process around 2029.