EU KIDS Act puts the burden of proof on platforms, not parents

For years, the default assumption in tech regulation has been that harm has to be proven before platforms face consequences. The EU is now trying to change that. The European Commission has adopted the EU KIDS Act, a sweeping proposal that bans children under 13 from social media entirely, sets 15 as the minimum age for independent accounts, and forces platforms to demonstrate their services are safe before users get hurt, not after.

What the law actually does

The age framework works in three tiers. Under-13s cannot access social media at all, though they can use specially designed child-friendly video services through a parent’s account, capped at one hour per day. Children aged 13 to 14 get limited ‘mini accounts’ under parental control, with restricted contacts and the same one-hour daily screen time ceiling. Only at 15 can a minor open a fully autonomous account.

But age limits are only part of the story. The law bans a specific list of design features that researchers have linked to compulsive use and harm. These include:

  • Infinite scroll without stopping points
  • Reward mechanics and engagement tricks
  • Push notifications during sleeping hours
  • Profiling-based recommendation feeds that push minors toward harmful content
  • Unsolicited contact from strangers
  • AI companions and chatbots that simulate emotional relationships or are on by default

Minor profiles must be private by default. Geolocation, camera, and microphone access must be off unless actively switched on. Platforms also have to provide real tools for blocking users and managing screen time, not buried settings menus that nobody finds.

The age verification problem

Age verification is where child safety laws usually fall apart. The EU’s proposal points to an official age verification app that does not store identity documents or biometric data. That’s the right instinct. But ‘does not retain’ is a phrase worth watching closely. Who operates the verification infrastructure, what data passes through it in transit, and who audits compliance are questions the proposal leaves largely to member states to sort out. Getting this wrong could mean trading one privacy risk for another.

Platforms must prove safety, not just claim it

The most significant shift here is structural. Platforms covered by the law must submit compliance plans to the Commission and to independent auditors before new services or features go live. If auditors find problems, the Commission can demand corrective action. Investigations for non-compliance must conclude within 90 days, which is fast by EU standards. Enforcement runs through the existing Digital Services Act and AI Act frameworks, so there’s at least an institutional structure in place.

Still, a 90-day investigation window only matters if regulators actually use it. The DSA has been on the books for years, and enforcement against major platforms has been slow. The KIDS Act’s credibility will depend entirely on whether that pattern changes. The proposal now goes to the European Parliament and Council. Given that 92% of Europeans say stronger child protection online is a top policy priority, political momentum is unlikely to be the bottleneck.