Home

Donate
Analysis

Where Does the KIDS Act Fit in the EU’s Digital Rulebook?

Jessica Galissaire / Sep 24, 2026

(Edwin Remsberg / VWPics via AP Images)

Republish

Last week, the European Commission introduced the EU KIDS ACT, a new legislative proposal aimed at strengthening the protection of children online.

While the initiative had long been anticipated, it remained unclear until the very end what instrument the Commission would use to complement its existing digital rulebook. By opting for a standalone regulation instead of revising existing ones, the EU executive has added another layer to an already dense regulatory landscape.

The Digital Services Act (DSA) already contains extensive obligations to protect minors online, while the forthcoming Digital Fairness Act (DFA) is expected to address many of the problematic design practices targeted by the KIDS ACT.

So, the questions naturally follow: What exactly does the new proposal add? Where do these instruments overlap? And what does this growing regulatory stack mean for enforcement and the EU’s broader approach to online child safety?

The current status quo under the DSA

Under Article 28 of the DSA, which applies since 2024, providers of online platforms accessible to minors — with the exception of micro or small enterprises — must already “put in place appropriate and proportionate measures to ensure a high level of privacy, safety, and security of minors, on their service.”

In July 2025, to give this broad obligation more concrete meaning, the European Commission published more than 60 pages of guidelines detailing measures platforms may take to comply with Article 28. These range from setting minors’ accounts to private by default, to adapting recommender systems to reduce exposure to harmful content or disabling by default features that can contribute to excessive use.

Services designated by the European Commission as Very Large Online Platforms (VLOPs) or Very Large Online Search Engines (VLOSEs), such as Facebook, Instagram, Snapchat, TikTok or Google Search, carry additional obligations.

Under Articles 34 and 35, they must assess and mitigate systemic risks to minors that may arise on their services. For VLOPs and VLOSEs, enforcement is the responsibility of the European Commission, while national Digital Services Coordinators oversee other regulated actors.

The Commission has already used the DSA against several major platforms used by minors in the EU. In April 2026, it preliminarily found Meta in breach for failing to adequately assess and mitigate the risks of under-13s accessing Instagram and Facebook. A few months earlier, it had reached a similar preliminarily finding against TikTok over addictive design features including infinite scroll, autoplay, push notifications and its recommender system.

Four porn platforms were also preliminarily found in breach by the European Commission for failing to protect minors from pornographic content, while formal proceedings were opened against Snapchat concerning its compliance with Article 28 and the protection of minors.

What the KIDS ACT brings to the table

By extending safety-by-design obligations to online games, video-gaming platforms and AI chatbots and companions, the EU KIDS ACT reaches beyond the DSA’s platform framework.

One thing the KIDS ACT adds to this already extensive regulatory landscape is turning some of the safety-by-design measures set out in the Article 28 guidelines into binding, more prescriptive rules.

Chapter III lists specific obligations for online social networking services, video-sharing platform services, online games, AI companions, general conversational chatbots, and software application stores. These obligations apply by default, unless the provider has established, through age assurance, that the user is over 18. They cover addictive design, recommender systems, safe settings, contact and interaction safeguards, economic transactions, age-appropriate access, and tools to support minors’ agency and empower them and their guardians.

Article 9 illustrates the shift: it states that social media and video-sharing platforms must not be designed or operated in ways that are intended or likely to encourage compulsive or excessive use by minors. It identifies a number of designs made to encourage compulsive or excessive use, including autoplay and endless content feeds without meaningful breaks, notifications designed to pull minors back onto a service, rewards for posting or livestreaming, and mechanisms that pressure users to return regularly or risk losing benefits.

Another major addition is the introduction of a three-tier age-based system for access to social media and video-sharing platforms (Chapter II). For social networking and video-sharing services covered by the proposal, children under 13 generally cannot create their own account. A limited exception would allow guardian-controlled access to certain age-appropriate video-sharing services designed for younger children.

Those aged 13 and 14 can access these services only through a limited “mini account” set up and supervised by a parent or guardian, with restrictions on features, contacts and screen time.

From age 15, teenagers can create their own account without parental permission, while still benefiting from the safety-by-design protections until they turn 18. Chapter V sets the conditions for mandatory age-checks, for instance, when providers must use age verification and when other forms of age assurance, such as age estimation, may be used.

What does this mean for enforcement?

Interestingly, the new proposal does not create a new enforcement mechanism from scratch. Instead, it largely plugs into the existing structures established under the DSA and AI Act.

Social media, video-sharing and gaming platforms, as well as app stores, would be supervised through the DSA’s enforcement framework (Article 34(1)), while AI companions and general conversational chatbots would fall under the AI Act’s supervisory system (Article 34(2)).

Existing national authorities — and, where relevant, the European Commission and AI Office — would therefore see their current investigatory and enforcement powers extended to KIDS ACT obligations. Data protection authorities would remain responsible for the processing of personal data under the relevant provisions, while Member States would designate competent authorities for video games that fall outside the DSA framework, i.e. those that are not gaming platforms.

This approach avoids creating an entirely new layer of institutions, but it makes coordination more important, as the same product or design feature may now fall under the DSA, the KIDS ACT, the AI Act and, potentially, consumer protection law. The Commission explicitly acknowledges this in Article 34(7) of the KIDS ACT, calling for the Commission, Member States and relevant national authorities to “work in close cooperation and coordination.”

Brussels also heard the criticism that enforcement of the DSA is not going fast enough and seems to be determined to act upon it. Article 35 of the KIDS ACT introduces an expedited procedure for infringement proceedings launched by the Commission under the DSA and AI Act.

If the new proposal were adopted as is, the Commission would have 30 days to communicate preliminary findings, and 90 days to reach a final decision. As a comparison, it took nearly two years to obtain preliminary findings in the above-mentioned TikTok case, and a final decision is yet to be delivered.

Stepping on the DFA’s toes?

While the relationship between the KIDS ACT, DSA and AI Act is set out relatively clearly, the division of labor with the upcoming DFA remains less certain. In a May 2026 communication on ending child poverty, the Commission stated that the DFA would contribute to protecting children online by addressing “from a consumer protection perspective, unfair commercial practices, including dark patterns, unfair influencer marketing, and addictive design features that encourage excessive screen time and spending.”

Since then, however, the Commission’s framing of the division of labor between the two initiatives appears to have shifted, leaving addictive design, at least for minors and the services covered by the new proposal, extensively regulated by the KIDS ACT.

As a confirmation of this evolution, the communication accompanying the KIDS ACT describes the DFA as updating horizontal consumer protection rules against harmful commercial practices online, including “manipulative business-to-consumer digital practices, unfair pricing techniques, problematic influencer marketing and issues with digital contracts and subscriptions”, but does not mention addictive designs per se.

This does not make the DFA redundant. A horizontal consumer protection instrument can address online harms — including addictive designs — that affect everyone, not just children. This may create further overlap with the KIDS ACT, requiring closer coordination between consumer protection authorities and those overseeing the DSA, KIDS ACT, AI Act and GDPR, among others.

With the DFA proposal expected in the coming weeks, however, the two files are likely to move through the legislative process in parallel, giving the co-legislators an opportunity to align them from the outset.

What this means for the EU’s approach to online child safety

The KIDS ACT points to two broader shifts in the EU’s approach to online child safety.

First, it moves beyond platform governance towards more direct regulation of product design. The focus is increasingly not only on whether companies properly assess and mitigate harms, but on whether certain features should exist at all, or under what conditions they may be offered to children.

Second, it adds to an increasingly layered regulatory stack. The EU is addressing the same online experience through platform regulation, child-specific design requirements, AI regulation and consumer law. That may strengthen protection, but it will also make coherence between instruments — and coordination between enforcers — a central test of the EU’s approach to online child safety.

Support Tech Policy Press
If you've found our work helpful, consider supporting us.

Authors

Jessica Galissaire
Jessica Galissaire is a Senior Policy Researcher in the Interface’s Strengthening the Digital Public Sphere and Platform Regulation program. Her research focuses on the protection of minors in digital environments.

Topics

Related

Perspective
How the EU Kids Act Can Promote Interoperability for Online SafetySeptember 23, 2026
News
What Von der Leyen’s State of the Union Means for Europe’s Tech AmbitionsSeptember 16, 2026
Analysis
Tracking Efforts To Restrict Or Ban Teens from Social Media Across the GlobeFebruary 23, 2026