The EU KIDS Act proposal would bar under-15s from risky social media accounts and require certified, zero-knowledge age checks. What it requires, what is open.
Table of contents
The European Commission proposed the EU KIDS Act on 17 September 2026: a regulation barring under-15s from their own accounts on social media with risky design features, enforced by certified, zero-knowledge age verification. It is a proposal, not law. Parliament and Council must still adopt it, and the application date in the text is a placeholder.
- Proposal COM(2026) 681, procedure 2026/0286(COD), would set an EU-wide minimum age of 15 for autonomous accounts on risky social networking and video-sharing services.
- Children aged 13 to under 15 could use guardian-created limited accounts capped at one hour a day.
- For the account age check, platforms would have to rely exclusively on a third-party EU age verification solution certified by a public authority.
- Article 28 would bar any age assurance that identifies, tracks or profiles the user, and require zero-knowledge proofs.
- Platforms would have six months after the date of application to sweep existing accounts and disable those of under-15s.
What does the EU KIDS Act propose?
The EU KIDS Act ("EU Keeping Internet Digital Spaces Accountable and Trustworthy") is a draft regulation under Article 114 of the Treaty on the Functioning of the European Union. It would set a harmonised minimum age for social media accounts, safety-by-design duties for services used by minors, and EU-wide rules on how age is checked.
The Commission adopted the proposal on 17 September 2026 and sent it to the European Parliament and the Council under the ordinary legislative procedure. Its press release describes four pillars: a social media delay, safety by design, privacy-preserving age assurance and effective enforcement.
Article 2 covers online social networking services, video-sharing platforms, app stores, online games, operating systems, AI companions and general conversational chatbots, wherever the provider is established, if the service reaches users in the Union. Not-for-profit encyclopaedias, educational services and public-authority services are exempt.
The age-assurance chapter is the part identity teams should read closely. Article 28(3) reads: "Any age assurance measure shall be zero knowledge proof."
| Item | Detail |
|---|---|
| Instrument | Proposal for a regulation, COM(2026) 681 final |
| Procedure | 2026/0286(COD), ordinary legislative procedure |
| Adopted by the Commission | 17 September 2026 |
| Legal status | Proposed; not adopted, not in force |
| Minimum age, own account | 15 (Article 6(1)) |
| Limited guardian accounts | 13 to under 15, one hour a day maximum (Article 6(2)) |
| Age check for accounts | Certified EU age verification solution only (Article 29(2)) |
| Application | Placeholder: entry into force plus six months (Article 43) |
How would EU KIDS Act age verification work?
The EU KIDS Act would work in three layers. Risk features, not brand names, decide which services must refuse under-15s their own accounts: live streaming, contact with strangers, profiling-based recommendations, suggestions from outside a user's connections, or design that drives uninterrupted use. Those services must use a certified EU solution. Every check must be a zero-knowledge proof.
Under Article 29(2), those providers must rely exclusively on an EU age verification solution using an EU proof of age attestation, supplied by a third party, certified against a new EU Age Verification Scheme and listed by the Commission. Certification comes from a public authority. European Digital Identity Wallets certified under Article 5c of the eIDAS Regulation are deemed certified if they meet the scheme's requirements.
Article 29(4) allows more flexibility for other duties. For safety-by-design defaults under Article 8 and app-store age ratings under Article 16, providers may use alternative age assurance, provided it meets the Article 27 and 28 standards. The Commission will set requirements for these alternatives by delegated act.
Article 28 applies to every method. Age assurance must not identify the user, or locate, track, target, advertise to or profile them. It may process only the data strictly needed to confirm an age threshold, and may not combine that data with anything else. Providers may keep a minimal age signal at account level to avoid repeat checks.
Under Article 29(6), an operating system that holds a compliant age signal must, with the user's consent, share it with in-scope providers that need it.
| Service | Age rule | Permitted age check |
|---|---|---|
| Risky social media and video-sharing | No own account under 15 | Certified EU solution only |
| Same, 13 to under 15 | Guardian-set limited account | Certified EU solution plus guardian check |
| Video-sharing designed for under-13s | Access via guardian's account only | Age declared by guardian |
| Games, chatbots, AI companions | Safety-by-design unless adult confirmed | Certified EU or compliant alternative |
| App stores | Age-rating based access | Certified EU or compliant alternative |
What does the EU KIDS Act mean for your obligations?
The EU KIDS Act would create new duties for in-scope platforms and for the identity vendors that serve them. It would also change how data protection law is enforced against age checks. Most financial services firms are outside its scope, but identity teams that run both KYC and age flows would need to separate the two.
Account gating. In-scope platforms would need to verify age when an account is opened. They would also need to verify that a person setting up a 13 to under 15 account holds parental responsibility (Article 26), using official signals or, until a delegated act lands, a self-declaration checked with reasonable efforts.
Existing accounts. Article 6(4) gives providers six months after the date of application to establish which existing holders are under 15. They must disable those accounts, and any account whose age cannot be established. Article 32(2) lets them use other evidence instead of the certified solution only where they can show a "high degree of confidence" that the holder is old enough.
Very large platforms. Article 5 requires designated very large online platforms to file a compliance plan within 30 days of the date of application, commission an independent audit, and answer any Commission finding of shortcomings with a corrective plan within 30 days, each measure due within 60 days. Article 36 adds an annual supervisory fee of up to 0.03% of worldwide net income.
Identity and age assurance vendors. A vendor that wants to serve the under-15 account check would have to become a certified provider of EU proof of age attestations or of an EU age verification solution. Document scans and selfie matches that reveal identity to the platform would not satisfy Article 28(1).
Data protection. Article 34(6) makes data protection authorities competent for Articles 27 to 29, with fines up to the GDPR Article 83(5) ceiling of 20 million euros or 4% of worldwide annual turnover, whichever is higher. The age rules would run alongside the consent-age rules in GDPR Article 8, not replace them.
KYC teams. Anti-money laundering customer due diligence exists to identify a customer. Article 28 exists to prevent identification. A provider running both would struggle to justify reusing a KYC record as the age signal, because Article 28(2) limits age checks to data strictly necessary and bars combining it with other data.
What is still uncertain about the EU KIDS Act?
The open questions are timing, a certified-supplier market that does not exist yet, the existing-account confidence test, what counts as zero-knowledge, and split supervision. The text settles none of them, and the application date that every other deadline runs from is still a placeholder.
Timing. Article 43 applies the regulation six months after entry into force, but that date is bracketed. Parliament's November 2025 resolution called for a "harmonised European digital age limit of 16" unless parents authorise otherwise, and a harmonised limit of 13 below which no minor can access social media. The age may move in negotiation, but the Commission's guardian tier from 13 already mirrors Parliament's structure.
A market that does not exist yet. The exclusive route for account checks depends on a certification scheme, implementing acts, public accrediting bodies and Commission lists that have not been built. If the proposal applies before certified solutions exist, platforms could not lawfully open accounts for users they cannot check.
Existing-account sweeps. The press release says platforms will estimate existing users' age from "reasonable proxies" such as account creation date or credit card details. Articles 32(1) and 32(2) require the certified solution unless the provider has a high degree of confidence. How regulators read that threshold will decide how many existing accounts need a fresh check.
Zero-knowledge in practice. Article 28(3) requires zero-knowledge proofs but does not define them. The implementing acts will decide whether a signed yes or no token qualifies, or whether cryptographic unlinkability across services is required.
Supervision. Enforcement is split across the Commission, national Digital Services Coordinators, AI Act authorities, games regulators and data protection authorities. Social media providers would be enforced under Chapter IV of the Digital Services Act (Article 34(1)). Chatbot and AI companion providers would face fines of up to 6% of worldwide annual turnover under Article 34(2).
How does the EU KIDS Act compare with the UK and Australia?
The EU KIDS Act would set a lower account age than Australia, and the UK sets none. The EU proposal would also have the strictest rule of the three on how age is checked, and it is the only one that would require zero-knowledge proofs by law.
Australia's Online Safety Amendment (Social Media Minimum Age) Act 2024 requires age-restricted platforms to take reasonable steps to stop under-16s having accounts, under section 63D. Section 63DB stops platforms from requiring government ID or an accredited Digital ID service unless an alternative is offered. The EU proposal goes the other way: the only lawful route for accounts is a certified, state-backed attestation.
The UK Online Safety Act 2023 requires age verification or estimation that is "highly effective" where section 12 demands it, but leaves the method to providers under Ofcom codes. Penalties reach the greater of £18 million or 10% of qualifying worldwide revenue under Schedule 13. One consequence: facial age estimation, which the UK regime permits, would not on its own qualify for the certified-only EU account check.
| Regime | Status | Age line | Method rule | Maximum penalty |
|---|---|---|---|---|
| EU KIDS Act | Proposed | 15, guardian accounts from 13 | Certified EU solution, zero-knowledge | DSA Chapter IV for social media (Art 34(1)); 6% for chatbots (Art 34(2)); GDPR Art 83(5) via DPAs |
| UK Online Safety Act | In force | Under 18 (children) for the most harmful content | "Highly effective", method open | Greater of £18m or 10% of revenue |
| Australia SMMA Act | In force | Under 16 | Reasonable steps; ID cannot be the only option | Civil penalty of 30,000 penalty units (s63D) |
The explanatory memorandum notes that Italy, France, Norway, Greece, Austria, Poland and Belgium notified national age-limit drafts in 2025 and 2026. That patchwork is the Commission's main argument for a single regulation.
How should compliance teams respond?
Teams should prepare now for the parts least likely to change in negotiation: data minimisation, the ban on identifying users during age checks, and independent certification. The age threshold and the dates may move, but data minimisation already binds you under GDPR Article 5(1)(c), so work on it pays off whatever the final text says.
First, map every service against the Article 6 risk features, not against a product label. Second, inventory what your current age check collects. If it stores documents, selfies or dates of birth, list them now. Third, separate age assurance from any KYC or fraud data store, in design and in contracts.
Fourth, ask vendors whether they intend to seek certification under the scheme, and on what timeline. Fifth, model the existing-account sweep: how many accounts could you place above 15 with high confidence today, and how many would need a check? Finally, track Parliament's first-reading position and the implementing acts, because they will settle the details. Our earlier coverage of the EU age verification trusted list and the UK Online Safety Act sets out the groundwork.
Zyphe's age verification lets a user verified once prove they are over an age limit as a yes or no zero-knowledge proof, disclosing no date of birth and no document. The first check uses an NFC chip read to ICAO 9303 and eIDAS standards, two-step liveness and no image upload, with a customer-held key and no central identity store. No provider can hold certification under the proposed scheme until it exists. To see it working, book a demo.
The bottom line
The EU KIDS Act is still a proposal, but its age-assurance design is unusually specific: certified third-party attestations, no identification, no profiling and zero-knowledge proofs written into the legal text. For platforms, the costly part of the EU KIDS Act is the existing-account sweep. For identity vendors, it is certification. For KYC teams, it is a reminder that proving an age and proving an identity would become separate legal jobs that should not share data.
Cited sources
- European Commission, Proposal for a Regulation on the EU KIDS Act, COM(2026) 681 final, 17 September 2026
- European Commission, press release IP/26/1890, EU KIDS Act, 17 September 2026
- European Parliament, resolution of 26 November 2025 on the protection of minors online, TA-10-2025-0299
- UK Online Safety Act 2023, section 12
- UK Online Safety Act 2023, Schedule 13 paragraph 4, maximum penalties
- Australia, Online Safety Amendment (Social Media Minimum Age) Act 2024
- Regulation (EU) 2016/679, General Data Protection Regulation, Articles 8 and 83
Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.