ToolNavs Find Useful AI Tools
Submit Sign in
Back to AI compliance
EU KIDS Act Proposal Adopted: AI Chatbots to Be Off by Default for Minors

EU KIDS Act Proposal Adopted: AI Chatbots to Be Off by Default for Minors

AI compliance Admin 1 views

What happened: Commission adopted the child online-safety proposal on 17 September

On 17 September 2026, the European Commission formally adopted the EU KIDS Act proposal — full name: Keeping Internet Digital Spaces Accountable and Trustworthy Act. It is a directly applicable EU regulation proposal, not a non-binding framework: once passed by the European Parliament and the Council of the EU, it applies across the Union without national transposition.

The proposal hinges on age tiers and “safety by design”: no social media for under-13s; 13- to under-15-year-olds may only use “mini accounts” opened and supervised by parents, with limited features and a one-hour daily cap; personal accounts from 15; mandatory safe design for all under-18 accounts. The sharpest lever is the reversal of the burden of proof: platforms must proactively demonstrate their services are safe for children, not just react after incidents.

The scope is what the AI industry should watch. The proposal defines regulated services as “Social Media+”: beyond social networks, video-sharing platforms, online games, app stores and operating systems, AI companions and general conversational chatbots are explicitly included. In her State of the Union address on 16 September, Ursula von der Leyen said AI chatbots must be switched off by default for minors and must not foster emotional dependence.

Who is affected: also teams registered outside the EU

The proposal applies to all covered services offered in the EU, regardless of where the provider is established — the same extraterritorial logic as the GDPR. Three groups face the most:

First, AI chatbot and AI companion products serving EU users. If your product can be used by minors in the EU, expect three obligations: age tiers, off-by-default, and anti-emotional-dependence design.

Second, app stores and operating systems, because age verification must go through the EU's age-verification solution.

Third, games and video platforms. The “Social Media+” definition is deliberately wider than traditional social media — games with social features are in.

Carve-outs are narrow: educational and not-for-profit services, plus professional or industrial AI tools.

What to do now: treat the negotiation period as a remediation window

The text is still a proposal. Legal analysts estimate that even on a smooth path, it would not apply before 2028. That gives roughly two years of negotiation to work with. Compliance teams can do four things:

First, map the age profile of your users. If the product has real or foreseeable underage users in the EU, start planning age-verification integration now, rather than facing an order to re-check all existing accounts six months before enforcement.

Second, review defaults. Build “off by default for minors” into the product design for AI chatbots, and audit recommendations, notifications and stranger-contact features for patterns that foster emotional dependence.

Third, prepare the safe-design evidence chain. Reversing the burden of proof means platforms must be able to document that their design is safe: keep risk-assessment records, design-decision rationales and testing records with minors from now on.

Fourth, track the age-verification solution. The proposal requires age checks through the EU's age-verification solution, which is officially said not to retain identity documents or biometric data — but the infrastructure is still being built, and the access model may shift during negotiations.

Where the risks are: don't mistake a proposal for a law — and don't ignore the privacy tension

The biggest misconception is treating 17 September as an effective date. This is a Commission proposal; the Parliament and Council will negotiate it at length, and the text can change substantially. Compliance investment should follow the proposal and keep room for redesign — not rebuild products around the strictest reading today.

The second risk is the tension between verification and privacy. Internet-wide age verification means every user must first prove they are an adult — digital-rights groups already warn this lays a de-facto identity layer over the internet, in tension with GDPR's data-minimisation principle. The EU age-verification app is promised not to retain documents or biometrics, but whether that technical promise survives the negotiations is an open question.

The third risk is fines and enforcement. Citing leaked draft versions, media report that violators could face penalties of up to 6% of global turnover and a 90-day fast-track enforcement procedure — not yet officially confirmed line by line, and still negotiable, but the direction is clear: Brussels no longer wants paper compliance.

One more point worth noting: the proposal would prohibit Member States from imposing stricter minimum-age limits than the Act. That means the national underage social-media bans of the past two years — such as the under-15 ban struck down by France's Constitutional Council — would be replaced by a single harmonised framework. For cross-border operators this is good news: one rule instead of a dozen national patchworks — provided the final text is not watered down in negotiations.

Recommended Tools

More