The Commission's child safety proposal

On 16 September, the European Commission unveiled the KIDS Act—an initiative framed as a response to mounting concerns about young people's safety in digital spaces. The acronym stands for 'Keeping Internet Digital Spaces Accountable and Trustworthy.' This announcement came during the Commission President's annual address to the European Parliament, where she outlined intentions to shield young people from platforms that undermine their childhood and ability to concentrate. The timing reflects broader European debate on youth protection, including proposals for social media bans in several member states. Youth organisations had previously called for substantive reform rather than exclusionary measures, issuing their demands in April.

Rather than fundamentally restructuring how platforms operate, the proposal largely determines who may access services built on problematic design patterns. It attempts to make certain features safer for a specific age group rather than eliminating the harmful practices themselves. This approach leaves the underlying business models—which expose all users to risk—largely untouched while establishing complex safety standards that may entrench the dominance of large technology companies.

The age-based framework and its limitations

The KIDS Act would prohibit social media accounts for those under 15, though this threshold can be lowered to 13 with parental consent. For users aged 15 to 18, the proposal mandates protections against exploitative tracking, intrusive default settings, and artificial intelligence companions designed to foster emotional attachment, among other risky design elements.

A fundamental flaw emerges when examining who receives these protections. The safeguards apply exclusively to the 15-18 age group, implying that manipulative design and unfair personalisation cease to cause harm upon reaching adulthood. In reality, all people remain susceptible to strategic interface design and algorithmic manipulation regardless of age. The skills required to navigate every default setting, understand recommendation systems, or resist deliberately timed notifications exceed what individual users can reasonably manage. Safety must be embedded into platforms themselves rather than dependent on user sophistication.

Many provisions in the KIDS Act target harms unrelated to childhood specifically. These same issues were intended to be addressed through the forthcoming Digital Fairness Act, which the Commission indicated would tackle addictive design across all consumer segments. By reframing these practices primarily as child-safety concerns, the Commission risks weakening the ambition of future regulations. The net effect could be that protections for the broader population—including children themselves—become weaker than they might otherwise have been.

Age verification and exclusion from digital participation

The KIDS Act's core logic treats children's online presence as inherently problematic rather than examining the conditions that create genuine harm. This contradicts the UN Convention on the Rights of the Child, which guarantees young people—including those under 15—fundamental rights to participate in society, access information, communicate, play and develop identity both online and offline. Age-based restrictions undermine these protections.

Implementation would require services to treat all users as children unless they demonstrate their age, fundamentally altering the internet's open character. This creates a two-tier system excluding not only young people but also adults unable or unwilling to complete age verification—a category encompassing vulnerable populations including elderly people, those experiencing homelessness, and migrants. The proposal neglects the broader fundamental rights implications for the entire affected population, extending far beyond privacy and data protection concerns.

The Commission presented this proposal despite serious warnings about building unprecedented surveillance and exclusion infrastructure, and without conducting an appropriate impact assessment. Alternative regulatory approaches exist that are more direct and proportionate: enforcing current legal obligations, strengthening protections for all users through the Digital Fairness Act, and requiring platforms to eliminate the harmful design and business practices underlying their models.

Circumvention and unintended consequences

The age-based framework creates practical problems rather than solving underlying harms. While guardians may override the 15-year threshold for children at least 13, doing so requires their own account, proof of age, proof of guardianship, detailed oversight of the child's contacts, and enforcement of mandatory daily time limits ranging from zero to 60 minutes. This cumbersome system invites circumvention.

Young people will likely find ways to access unprotected versions of services, bypassing the restricted, heavily monitored guardian-controlled variant. Some guardians may lack capacity to complete all required steps; others may use monitoring tools in ways that enable excessive surveillance or facilitate abuse. This risk is particularly acute for vulnerable youth relying on online spaces to access information or communities unavailable through family channels—including LGBTQIA+ young people and those seeking sexual or reproductive health information. These groups face heightened incentive to circumvent restrictions.

Adults will also seek workarounds. A parent providing a phone to a child for convenience may simply hand them an age-verified device instead. Compliance itself poses barriers, particularly for smaller services and open-source projects. The burden could consolidate Big Tech's dominance over alternatives offering data minimisation, non-addictive design, interoperability, or free and open software models. The simplest compliance strategy may be labelling services as '18+,' effectively sidestepping the rules entirely.

The likely outcome: widespread age verification infrastructure, exclusion of young people from important digital spaces, further Big Tech consolidation, and structural harms remaining unaddressed for those 18 and older.

A missed opportunity for systemic reform

The KIDS Act reflects a broader pattern in EU policy: while promoting deregulation through 'simplification' and investing heavily in artificial intelligence deployment, the Commission responds to digital harms by imposing restrictions on users rather than companies. The proposal asks who should be permitted to access services rather than what companies should be allowed to build and optimise for.

Genuine ambition on children's digital safety should not be measured by the age threshold announced but by whether platforms become safe enough for young people and everyone else to participate meaningfully. Pushing young people out of digital spaces does not make them safer—it simply makes them absent.