Why the EU Kids Act Threatens Privacy and Internet Access for Everyone
- The EU Commission presented a draft law known as the EU Kids Act to restrict young people’s access to the internet.
- The legislative proposal aims to protect children from risks associated with social media, video games, and AI systems through age-based access rules and stronger oversight.
- Following recommendations from an expert panel, the EU Kids Act introduces a phased access scheme for social media and video-sharing platforms that rely on personalized recommender systems or...
The EU Commission presented a draft law known as the EU Kids Act to restrict young people’s access to the internet. It is designed to restrict young people’s internet access by placing online services behind mandatory age gates, expanding intrusive age verification, and enforcing safety-by-design standards.
Brussels Targets Big Tech With Hard-Law Digital Restriction
The legislative proposal aims to protect children from risks associated with social media, video games, and AI systems through age-based access rules and stronger oversight. It builds upon the non-binding guidelines of the Digital Services Act by turning them into hard law.
Phased Access Scheme and Parental Controls
Following recommendations from an expert panel, the EU Kids Act introduces a phased access scheme for social media and video-sharing platforms that rely on personalized recommender systems or uninterrupted content consumption.
Under this proposal, children under 13 cannot hold service accounts. Users aged 13 to 15 are restricted to accounts under tight parental supervision, and teenagers aged 15 to 18 receive autonomous accounts within a safe-by-design environment. Full online access remains restricted exclusively to adults.
The Mechanics of Privacy-Intrusive Age Verification
This access delay requires privacy-intrusive age verification across the board, utilizing the broader EU age verification scheme. For teenagers, the law places significant control in the hands of parents, who must set up accounts and prove their parental status.
Age verification is not required for existing accounts if providers can determine user age above the threshold with a high degree of confidence.
Enforcing Safety-by-Design Across Platforms and AI
The second major pillar of the proposal applies safety-by-design requirements across social media, video-sharing platforms, online games, AI companions, chatbots, and app stores.
Providers must establish child-safe design as the default setting, addressing addictive features such as infinite scrolling and recommender systems. For AI companions and chatbots, companies must design services to minimize emotional dependencies and harmful interactions among minors. Meanwhile, online games must incorporate contact protections and app stores must act as gatekeepers for age-appropriate access.
Fundamental Rights and Market Dominance Risks
Despite its protective intent, the regulatory framework raises fundamental rights concerns, particularly regarding user privacy, freedom of expression, and children’s rights to access information online.

The legislation exempts not-for-profit encyclopedias, scientific repositories, educational services, and open-source software projects, but provides no carve-outs for small and medium-sized enterprises. This lack of exemptions for smaller entities threatens to cement the market dominance of resource-laden technology companies and encourages widespread adoption of privacy-unfriendly age checks.
