How the EU Kids Act Can Promote Interoperability for Online Safety
Aahil Sheikh / Sep 23, 2026The author is writing in his personal capacity.

European Commission President Ursula von der Leyen and Executive Vice President Henna Virkkunen speak at a press conference presenting the EU KIDS Act in Strasbourg, France, Sept. 17, 2026. Source: von der Leyen/X.
The proposed Kids Act adds to the European Union’s digital policy toolkit, complementing existing safety and privacy rules for children prescribed under the Digital Services Act (DSA), the GDPR, AI Act, the Digital Markets Act (DMA), and the Audiovisual Media Services Directive (AVMSD). It has received a lot of attention in terms of supervisory fees and the age-tiered social media ban implemented through age verification.
But the proposal’s provisions on interoperability and third-party tools demand a closer look. Section 6 of the draft envisions tools and allows guardians to manage screen time limits, account settings, receive warnings about potential risks and — for Very Large Online Platforms (VLOPs) — use interoperable third-party guardian tools to “further enhance usability and effectiveness.”
While some elements are now ubiquitous in online child safety laws globally, interoperability offers a different approach by giving parents and minors more control over how safety measures work rather than leaving that control entirely to platforms. The proposal’s approach builds on a broader debate over whether third-party tools can make online spaces safer, more private and more responsive to users’ needs.
While not explicitly stated in the text, this thread of the EU Kids Act seems to follow up on a finding from a recent study of the DMA’s interoperability obligation, where survey respondents expressed interest in the use of third-party functionality for privacy, security and content moderation features. The study did examine demand for interoperability and third-party services, although its findings covered a broader range of potential interoperability uses rather than specifically establishing interest in child-safety tools.
Far from a recent interest, interoperability and decentralization have long been considered pathways for healthier and safer online spaces. Separately, the Future of Technology Institute outlined a European framework that calls for a full interoperability mandate, where large online platforms open their proprietary, closed networks to third-party digital wellbeing tools.
As existing safety-by-design and teen safety measures and tools come under scrutiny for being ineffective, interoperability with third-party tools can restore autonomy to guardians and minors to control their own safety, privacy and wellbeing online. In this context, it is worth analyzing the safety gap that interoperability can bridge and how existing concerns can be addressed, all in pursuit of a new approach that situates user choice at the center of online safety.
Existing measures move slowly
As part of the $17.1 billion settlement, Meta has been required to make certain design changes for its teen users, such as parental supervision features, a "school mode" and "night mode" that restrict app usage and notifications at specific times, hiding like counts and disabling certain cosmetic procedure filters for teen accounts, and carrying out age verification to ensure age-appropriate experiences. This is not the first time these changes have been proposed, as they are already a part of the DSA playbook.
These features come under the broader ambit of safety-by-design, which, while well-intentioned, does not currently address one critical gap: the real changes that need to be made rely on platforms with centralized control over features. Legislation and enforcement can mandate changes, and risk assessments can highlight precisely what platforms need to address, but the final call lies with the tech companies themselves. The closed nature of these services prevents any third-party involvement or external entity from doing much besides legislating, enforcing, and awaiting compliance, with fines barely acting as a deterrent for violators.
In the window between legal enforcement and platform compliance, users are vulnerable to online harms, having to rely on imperfect content moderation systems that both overmoderate and undermoderate content in low-resource languages, amidst rising AI-generated harms that disproportionately affect women, children and LGBTQIA+ communities. In essence, users lack significant control over their online experiences, and can benefit from platform-agnostic safety features that are not dependent on companies making jurisdiction-specific changes.
The Meta settlement — contingent on Snap, YouTube and TikTok following suit, and so far limited to the US — opens doors for a new paradigm on online safety. Here, the EU Kids Act can advance this new paradigm through interoperability and middleware, i.e., third-party tools used with existing social networks to modify online experiences. The Act can deliver customizable safety tools in the hands of parents and guardians, providing them with the ability to use their preferred moderation tools, algorithmic feeds, and content filters. The draft proposal acknowledges that these third-party tools aim to complement — not substitute — existing online safety measures, letting governments and tech companies define legal safety standards, while also enabling users to define them for themselves.
Interoperability for online safety in practice
The algorithmic feed is one of the primary avenues where children often encounter online harm without explicitly searching for it, with limited choice over how their social feed is organized. Middleware can provide more granular control over content categories and can be an alternative to organizing social feeds. Blacksky, built on the decentralized AT Protocol, serves as a practical example, as users can fine-tune the visibility of misogynoir, digital blackface, non-consensual intimate imagery, ableism content, and more.
The EU Kids Act currently envisions middleware in a supervisory context, where guardians can oversee the child’s time spent online and how that time is spent. Extending Blacksky’s example to child safety, it is hypothetically possible for organizations in this space to translate their policy recommendations into concrete middleware tools. For instance, actors such as Common Sense Media can potentially develop their own content moderation and algorithmic recommendations, aligned with their existing media ratings. Similarly, 5Rights could develop algorithmic recommenders based on its work on age-appropriate design codes.
The draft proposal acknowledges that parents and guardians may not always be available and present to set-up third-party tools for their child’s safety, and this aligns with criticism of parental controls on grounds of not being helpful to curb compulsive social media use, while being dependent on parents’ time and capacity to enable said controls. Here, governments, technology companies, and civil society organizations should collectively promote alternative feeds and moderation tools. The DMA’s screen choice provisions to educate users on alternative browsers can serve as the basis for how these tutorials are developed.
Addressing data protection and privacy risks
Data portability, i.e., the ability for users to transfer their data and have it read by different services, is essential for interoperability and middleware. After the Cambridge Analytica case, companies and governments have been skeptical about letting third-party applications access platform data, complicating how data sharing is operationalized. For instance, in the case of vertical interoperability (using middleware as an add-on to existing services), did other users consent to their data being read by third-party tools? Such questions are further complicated by the fact that many countries lack an actionable data privacy law, in the backdrop of fragmented global approaches to data-sharing.
How consent materializes between social networks, users, middleware tools and developers will determine the trustworthiness of interoperability as a whole, and addressing these questions requires governments, tech developers, and civil society groups to co-develop modern standards around trust, consent, and privacy. Conducting data protection audits is already contemplated under laws such as the EU’s GDPR and India's DPDP Act.
Their shortcomings can be addressed and adapted to accommodate middleware tools and data portability. Another potential solution is regulatory sandboxes: controlled environments where regulators subject new features to simulated real-life privacy frameworks to assess whether the former effectively complies and if the latter is capable of governing emerging technologies. Their learnings can be used to evaluate how compatible data portability and middleware tools are with specific child data protection frameworks and any other emerging privacy risks.
Funding middleware safety tools and developers
Platforms emerged as the dominant model of social networking partly because they controlled both content curation and moderation. To disrupt them, middleware developers would have to create recommendation engines and safety tools that qualitatively exceed those of established platforms with equivalent seamlessness. This could prove difficult, as middleware is often developed by independent developers with limited funding. Child safety advocates could develop their own tools, but privacy and safety compliance costs may not be achievable for smaller developers, and scaling for potentially billions of users will be difficult for teams with limited resources.
A 2024 paper from Georgetown University and the Foundation for American Innovation addresses this, suggesting sustainable business models through for-profit (subscriptions, micropayments) or nonprofit (grants, donations) structures. Similarly, the Centre for Democracy and Technology Europe recently published its response to the DSA's draft Trusted Flaggers' guidelines, suggesting financial support to trusted flaggers. A similar model can be adapted for middleware developers, where Open Future's proposed EU Sovereign Tech Fund for initiatives such as Eurosky can lay the blueprint for funding middleware developers to match the scale of large digital services.
The long road towards a different approach
The EU Kids Act will evolve in the coming months, and it has the opportunity to make interoperability provisions a mainstay in online safety discussions, signaling an evolution in how regulators perceive safety-by-design. Third-party tools can balance the UNCRC’s right of children to access information and proportional safety in a way that social media bans have been criticized for failing to do. However, interoperable tools can still act as a barrier for marginalized children from LGBTQIA+ and ethnic minority communities to socialize with others like them, and strict supervisory tools can control access to important reproductive health information that youth often engage with through online spaces. The draft EU Kids Act rightfully acknowledges that the minor’s right to information and privacy is important, and it is crucial that this right is not diluted in any form.
Opening up platforms to be interoperable with third-party tools for custom safety filters, recommendation algorithms, screen limit controls, etc. comes with an additional layer of complexity for parents and minors, but this very complexity can empower users to protect themselves when existing measures fail. A move towards interoperable safety-by-design restores control to users, promotes greater competition that prioritizes safety rather than profit, and re-institutes the values of openness and decentralization that once defined the internet.
Authors

