Social media platforms will be prohibited from accessing children under the age of 13 under a new ‘EU Kids Act’ adopted by the EU Commission to enhance the online safety of children in Europe.

The proposal also sets an EU-wide minimum age for minors to open an account of their own at the age of 15. A key element of the Kids Act is to reverse the burden of proof, meaning service providers will have to show that their services are age-appropriate and safe by design.
Under the EU Kids Act, children would only be able to create autonomous accounts on social media services from the age of 15. For children between 13 and under 15, parental control would enable guardians to set up mini accounts that children can access through the guardian’s account. This would allow them to access age-appropriate social media and video-sharing platforms. In addition, services available on the mini accounts must be designed with safeguards, such as limited social contacts and limited screen time up to one hour per day, recognising the role of guardians in supporting the autonomous and safe development of their children online.
While children between 3 and under 13 cannot access social media, they would be able to access specially designed child-friendly video-sharing services through accounts managed by their guardian. The platforms would need to offer parents or guardians an easy-to-use tool to restrict the use of the adult’s device to such child-friendly services, when it is passed on to children, and limit the child’s exposure up to a maximum of one hour per day.
The Act would impose a number of obligations for all online services offering social media services, video sharing, online video games, AI companions and chatbots to users below the age of 18. These include a ban on addictive features and profiling-based recommender feeds dragging minors into ‘rabbit holes’ of harmful content. It also includes prohibiting infinite scroll without stopping points, reward tricks, and push notifications during sleeping hours, as well as unsolicited contact from strangers. In addition, AI companions and chatbots must be turned off by default and cannot simulate interpersonal relationships in ways that create emotional dependency.
Profiles for minors must be private by default, with geolocation, camera and microphone access turned off. Online services must also offer easy ways for minors to block and mute users, effective time-management tools, and safe recommender systems that minors can control, tune and reset.
Online services and app stores will have to use age assurance tools. They can, for example, use the EU age verification app, which does not retain identity documents or biometric data, thereby meeting the highest privacy-preserving safeguards. Member States will be closely involved in setting up this ecosystem.
In addition, providers of social media services and video-sharing platforms will be called to perform age verification when a user opens a new account.
When it comes to existing accounts, providers have to estimate the user’s age based on reasonable proxies (e.g. account creation date, credit card details).
A key element is that the proposal reverses the ‘burden of proof’, making the providers of very large online platforms responsible for proving that their services are ‘safe by design’. This obliges them to submit a compliance plan to the Commission, and to an independent auditor that has to thoroughly assess the new service, feature or functionality. The Commission can request the provider to propose corrective measures if based on the auditor’s report, it considers that the compliance plan contains any shortcoming.
The enforcement framework builds on the structures already in place under the Digital Services Act and the Artificial Intelligence Act, making use of established mechanisms and existing expertise. The proposal introduces expedited enforcement procedures against providers in case of non-compliance with the EU KIDS Act, where the Commission should conclude investigations within 90 days.






