Skip to main content
We have begun the founding chapter. Be among the first
+1 (888) 885-5991|[email protected]

Analysis

A Five Word Clause in the EU's New Child Safety Proposal Decides Whether Any of It Works

On 17 September 2026 the Commission proposed one minimum age for social media across the Union. The provision that decides whether the law works at all sits eleven pages further on, and it is five words long.

By Dinesh Mendhe, Ross Thorpe, Hema Dey and Sofia Martinez

September 21, 2026 · Three parts

Screens down. What the EU KIDS Act asks for, in one picture.

Part one

The proposal

What the EU KIDS Act actually requires, article by article.

The short answer

The EU KIDS Act is a proposed Regulation that would set one minimum age, 15, for opening a social media account anywhere in the European Union. Children of 13 and 14 could have a guardian-controlled account with a one hour daily cap. It would require every service, platform and software a child can reach to be safe by design rather than safe by settings, and extend the same requirements to app stores, operating systems, online games, AI companions and general conversational chatbots. It would also reverse the burden of proof, so the largest platforms must show the Commission that they are safe for children rather than regulators having to prove that they are not.

It is still at proposal stage, so it is not yet law. It goes next to the European Parliament and the Council, so it is nowhere near a finished document, and there will be changes as it is reviewed. The design takes for granted that the technical foundation is already solved, relying entirely on one claim that a platform can verify a child meets the age requirement without learning anything else about them. The Act states this as a requirement. Nothing deployed at scale in Europe today meets it.

This series of articles does two things. First, it sets out, article by article, what the proposal actually obliges. We then examine the five problems standing between that text and a working system and propose an architecture that would close them. We write the second half as people who have argued for verified personhood as a design principle, and who have also argued that a child's right to privacy is not a fee payable for the right to be protected. One of us built the protocol that second half describes.

Overview

We recommend anyone writing or deciding anything about this law should be reading the primary text rather than a summary of it. There are three documents, all dated 17 September 2026.

DocumentReferenceWhat it is
The proposalCOM(2026) 681 final, procedure 2026/0286 (COD)The draft Regulation itself: 99 pages, 43 articles, 9 chapters, and the recitals that will be used to interpret them.
The CommunicationCOM(2026) 680 finalAn EU approach to online child safety. The political framing and the evidence base.
The impact analysisSWD(2026) 681 finalStaff Working Document, 83 pages. Note the title. It is an Analysis of Impacts, not a full Impact Assessment carrying a Regulatory Scrutiny Board opinion.

The full name is an acronym, EU KIDS stands for Keeping Internet Digital Spaces Accountable and Trustworthy. The legal basis is Article 114 of the Treaty on the Functioning of the European Union, the internal market provision, invoked together with Article 114(3), which requires a high level of protection for health and safety. That choice matters, and we return to it.

Who the Act applies to

Article 2 lists seven categories of service and system:

  1. online social networking services,
  2. video-sharing platform services,
  3. software application stores,
  4. online games,
  5. operating systems,
  6. AI companions,
  7. general conversational chatbots.
  8. Regulating only individual apps is not enough, because apps and users can easily bypass the rules. By also holding app stores and device operating systems accountable, the law regulates both how an app is downloaded and how it runs on a device making these child safety rules practical to enforce.

Three definitional points that are important to note, but easy to overlook:

  1. The definitions of online social networking service, video-sharing platform service, software application store and operating system are drawn from the Digital Markets Act, Regulation (EU) 2022/1925, not from the Digital Services Act.
  2. Under the proposed framework, an "AI companion" isn't defined by how a company markets it, but by what it actually does: deliver sustained, personalized interaction that simulates an emotional or social bond. General conversational bots fall into a separate bucket based purely on scope. If a system is built to talk about anything under the sun, it's covered by the rule. If it's designed for a single, narrow task, it gets a pass. That leaves everyday single-purpose tools, customer support bots, checkout helpers, school software, search assistants, and industrial systems safely off the hook.
  3. Article 2(6) provides that compliance with this Regulation is deemed compliance with Article 28(1) of the Digital Services Act for the matters it covers. That single sentence converts the Commission's July 2025 guidelines on the protection of minors, which are not binding, into hard, directly applicable obligations with a certified verification layer attached.

The Regulation applies irrespective of where a provider is established, so long as the service is offered to recipients in the Union or the AI system is placed on the Union market. Article 2(4) sets out the exemptions. They cover not-for-profit online encyclopedias, not-for-profit educational and scientific repositories, services run by or for educational establishments for primarily educational purposes, open-source software development and sharing platforms, pure scientific research and development, and services operated by public authorities for their own exclusive use.

The age ladder, and the thing the headlines got wrong

The Commission's own factsheet sets out four bands.

AgeWhat the proposal provides
Under 3No access. Article 7(4)(b) sets the floor. Access shall not be enabled for a minor below the age of 3 years. The factsheet puts it more bluntly: no screens.
3 to under 13No social media account. Guardian-mediated access to video-sharing services specifically designed for this age group, through the guardian's own account, capped at one hour per day, with personalization and recommender systems off and not activatable.
13 to under 15A guardian-created account with limited features. Guardian tools always on, contacts pre-approved by the guardian, and a daily cap that shall not exceed one hour.
15 to under 18The minor may create and manage their own account. Safety by design still applies in full until 18.

A great deal of the reporting has described this as a ban on social media for under 13s. However, two corrections are worth making.

First, access below the age of 3 is not permitted at all, which is the first time an EU instrument has drawn a line at the toddler end of the range rather than the teenage end.

Second, under 13 is not a total exclusion from the internet or even from video. It is an exclusion from accounts of one's own, on services designed for adults, with a narrow guardian-mediated channel preserved for services built for children. The distinction between having an account and having access runs through the whole proposal, and it is a more careful piece of drafting than it has been given credit for.

Article 6: the five triggers

Article 6(1) does not say that under 15s may not use social media. It says that providers shall not allow a person below 15 to create or use an account where the service poses a risk to the privacy, safety or security of a minor below that age. It then defines that risk, by listing five features. A service meets the test if it has any one of them.

  1. It lets account holders transmit content in real time to an indeterminate number of other recipients, including live streaming.
  2. It lets account holders contact and interact with recipients outside their pre-existing connections or subscriptions.
  3. It uses a recommender system based on profiling within the meaning of Article 4(4) of the General Data Protection Regulation.
  4. It uses a recommender system that suggests contacts or content that did not come from a pre-existing connection or subscription.
  5. It deploys interface designs or features that enable uninterrupted content consumption, that incentivize interaction, or that send automated notifications designed to prompt the user to start or resume using the service.

Apply that list to any mainstream social product and the answer is not one trigger but four or five. The drafting achieves a general prohibition while remaining, in form, a risk-based rule, which is what Article 114 requires it to be. A service that has none of these five features may lawfully admit under 15s. That is a product design brief, and it is the first time European law has written one this specifically.

It is worth being concrete about what that service looks like, because the Act describes it precisely without ever naming it. No live broadcast to strangers. No contact from anyone the child has not already accepted. No feed assembled from behavior rather than from choice. No suggestions from outside the people they follow. No autoplay, no streaks, no notifications engineered to pull a child back. What remains is a service where a child sees what they asked to see, from people they chose, and leaves when they are finished. The Act does not say whether anyone will build it. It says that anyone who does may lawfully admit children under 15.

The Act does not ban children from social media. It describes, in five clauses, the kind of social media children are allowed to have, and then leaves the industry to decide whether to build it.

Where this leaves us

Four things are settled by the text above. The Union would have one minimum age, 15, for an account of your own, with a guardian-controlled account from 13 and a narrow guardian-mediated channel from 3. The rules reach past social media to app stores, operating systems, games and conversational AI, which is what makes them enforceable. Article 6 does not ban children from social media; it describes, in five clauses, the kind of social media a child may lawfully use. And a service built without those five features may admit them.

What is not settled is whether any of it can be enforced without identifying every child in Europe. That is the subject of part two, which covers safety by design, the enforcement reversal, the deadlines, and the five words in Article 28(3) that decide whether the whole structure stands up.

1 of 3

Dinesh Mendhe is Founder and Chairman of The AI Lab Intelligence Unobscured, Inc. and the inventor and principal author of the Trust Identity Protocol, the architecture part three puts forward. Ross Thorpe is Chief Executive Officer of Rooverse, a human-only social platform built on verified personhood, and Chairman of TopCo Capital. Hema Dey is Founder and Chief Executive Officer of Iffel International Inc. and an Advisor to the AI Trust Council of The AI Lab. Sofia Martinez is Chief Executive Officer of The AI Lab Intelligence Unobscured, Inc. Dinesh Mendhe sits on the AI Trust Council in the Founder Seat, which the Council constitutes as a member holding a declared interest and a defined recusal scope, and Ross Thorpe in an independent capacity. TIP does no age assurance today. Part three proposes an extension to it, and says plainly what is specified and what is built.