The forthcoming Kids Act represents an addition to the EU's expanding rulebook on digital matters, working alongside protections already established through the Digital Services Act, GDPR, AI Act, Digital Markets Act and Audiovisual Media Services Directive. While much discussion has centred on supervisory fees and age-tiered social media restrictions with age verification mechanisms, the legislation's provisions regarding interoperability and third-party tools warrant closer examination.
Section 6 of the draft text contemplates tools that permit guardians to establish screen time restrictions, adjust account configurations, receive alerts about emerging dangers and—specifically for Very Large Online Platforms—deploy interoperable third-party guardian tools designed to "further enhance usability and effectiveness." This approach diverges from certain elements now standard across child safety legislation globally by distributing control over safety mechanisms to parents and minors rather than concentrating it entirely within platform hands.
The proposal appears to draw inspiration from research into the Digital Markets Act's interoperability requirements, where survey participants indicated enthusiasm for third-party capabilities addressing privacy, security and content moderation. Though the study examined broader interoperability demand rather than focusing specifically on child-safety applications, it documented receptiveness to such tools. Interoperability and decentralization have historically been viewed as potential foundations for healthier digital environments, with the Future of Technology Institute previously proposing a European framework mandating that large platforms unlock their proprietary networks to third-party digital wellbeing applications.
Existing measures move slowly
Meta's $17.1 billion settlement has obligated the company to implement specific design modifications for teenage users, including parental oversight capabilities, a "school mode" and "night mode" limiting app access and notifications during designated periods, concealing engagement metrics and restricting certain cosmetic filters on teen profiles, plus age verification to enforce age-appropriate content. These modifications are not novel proposals—they already feature in the DSA's established toolkit.
Safety-by-design frameworks, despite their constructive intent, leave a significant gap unaddressed: meaningful improvements depend on platforms maintaining centralised authority over functionality. While legislation and enforcement can compel changes and risk assessments can pinpoint necessary modifications, ultimate decisions rest with technology firms themselves. The proprietary structure of these platforms restricts third-party participation, leaving external actors limited to legislative and enforcement roles while awaiting corporate compliance, with financial penalties functioning as weak deterrents.
During the interval separating legal mandates from actual platform implementation, young users face exposure to harms, depending on flawed content moderation systems that simultaneously over-filter and under-filter material in languages with fewer resources, alongside mounting AI-generated threats disproportionately harming women, children and LGBTQIA+ populations. Users fundamentally lack substantial agency over their digital experiences and could benefit from platform-independent safety mechanisms not contingent on companies making jurisdiction-specific adjustments.
The Meta settlement—contingent on comparable action from Snap, YouTube and TikTok, and presently confined to the United States—creates space for reimagining online safety. The Kids Act can advance this direction through interoperability and middleware—third-party applications that integrate with existing social networks to reshape user experiences. This mechanism would equip parents and guardians with customizable safety instruments, enabling selection of preferred moderation approaches, feed algorithms and content screening. The draft acknowledges that third-party tools are meant to enhance—not replace—existing safety frameworks, permitting authorities and platforms to establish legal safety benchmarks while enabling individuals to establish their own.
Algorithmic feeds represent a primary channel through which children encounter harmful material without active searching, with minimal input into feed organisation. Middleware enables more detailed control over content categories as an alternative to platform-determined feeds. Bluesky, constructed on the decentralised AT Protocol, demonstrates this practically, permitting users to adjust visibility of misogynoir, digital blackface, non-consensual intimate imagery, ableism content and comparable material.
The Kids Act presently frames middleware within a supervisory context, where guardians monitor a child's online duration and activities. Extending Bluesky's model to child protection, organisations could theoretically convert their policy guidance into functional middleware applications. Entities such as Common Sense Media might construct their own moderation and recommendation systems aligned with their media ratings frameworks. Similarly, 5Rights could engineer algorithmic recommenders reflecting its research on age-suitable design principles.
The draft recognises that guardians may lack constant availability to configure third-party tools for child protection, addressing longstanding criticism that parental controls prove ineffective at preventing compulsive use while demanding substantial parental time and capability. Governments, platforms and civil society should jointly champion substitute feeds and moderation options. The DMA's browser choice education provisions can model how such guidance materials should be constructed.
Data portability—enabling users to transfer information and have it processed by alternative services—underpins interoperability and middleware functionality. Following Cambridge Analytica, institutions have grown cautious about permitting third-party applications to access platform information, complicating data-sharing mechanics. In vertical interoperability scenarios, for instance, did other users authorise third-party tools to process their data? These questions intensify given that numerous jurisdictions lack enforceable data protection legislation, amid inconsistent international data-sharing frameworks.
Consent mechanisms linking social networks, users, middleware applications and developers will establish interoperability's credibility, demanding collaborative standard-setting among governments, developers and civil society regarding trust, consent and privacy. Data protection audits already feature in frameworks including the GDPR and India's DPDP Act. Their limitations can be refined to accommodate middleware and data portability, with regulatory sandboxes offering another avenue—controlled spaces where authorities test emerging capabilities against simulated privacy conditions to verify compliance and governance adequacy, with findings informing compatibility assessments for data portability and middleware within child protection contexts.
Platforms achieved dominance partly through controlling both content selection and oversight. Displacing them requires middleware creators to engineer recommendation and safety systems surpassing platform equivalents while maintaining comparable user-friendliness—a challenging proposition when middleware typically originates from independent developers with constrained budgets. Child safety organisations could build their own applications, yet compliance expenditures may exceed smaller developers' capacity, and expansion to serve billions presents resource obstacles for limited teams.
A 2024 Georgetown University and Foundation for American Innovation paper addresses sustainability through for-profit models (subscriptions, micropayments) or nonprofit structures (grants, donations). The Centre for Democracy and Technology Europe recently proposed financial backing for trusted flaggers in its DSA response, a framework adaptable to middleware developers. Open Future's proposed EU Sovereign Tech Fund, supporting initiatives like Eurosky, could establish a funding template for middleware creators to achieve platform-scale operations.
The Kids Act will undergo refinement in coming months, presenting an opportunity to embed interoperability as a central element in safety discourse, signalling regulatory evolution in safety-by-design thinking. Third-party applications can reconcile the UN Convention on the Rights of the Child's guarantee of information access with proportionate protection in ways social media bans have faced criticism for neglecting. Yet interoperable mechanisms risk excluding marginalised youth from LGBTQIA+ and ethnic minority backgrounds from connecting with peers, while stringent oversight could obstruct access to reproductive health resources youth frequently seek online. The draft appropriately emphasises that minors' information and privacy entitlements remain vital, necessitating that these rights remain uncompromised.
Enabling platforms to interoperate with third-party applications for bespoke safety filters, recommendation systems, screen management and similar functions introduces additional user complexity, yet this very complexity can strengthen user self-protection when conventional approaches falter. Transitioning toward interoperable safety-by-design redistributes authority to users, stimulates competition centred on safety rather than engagement, and resurrects the openness and decentralisation principles that characterised the internet's origins.



