EU KIDS Act flips proof burden: what platforms must do

EU KIDS Act flips proof burden: what platforms must do

On September 17, 2026, the European Commission adopted a proposal for the EU KIDS Act, a children’s online safety package that would ban social platforms from accessing users under 13 and set a 15+ minimum for minors to open their own accounts. The move also reverses the burden of proof, requiring companies to demonstrate their services are age‑appropriate and safe by design, according to the Commission’s announcement on its Digital Strategy portal.

What the EU KIDS Act proposes

The proposal, formally titled “EU Keeping Internet Digital Spaces Accountable and Trustworthy,” targets two problems the Commission says remain unresolved: very young users on social platforms and weak, inconsistent protections for teens. Under the plan described by the Commission, services:

  • Must prevent access by children under 13.
  • May only allow minors to open their own accounts from age 15, creating an EU‑wide baseline.
  • Must prove their products are age‑appropriate and safe by design, a shift that places the evidentiary load on providers rather than regulators or families.

That last point is the hinge. The EU KIDS Act doesn’t just add more rules; it changes who must show the rules are being met. In practice, that means design documentation, risk tests, and measurable outcomes are no longer “nice to have.” They become the artifact set a platform will need on hand when auditors or national authorities ask to see it.

How the children’s online safety law reshapes product work

Reversing the burden of proof will push platforms to turn diffuse safety goals into testable controls. Expect standard playbooks across product, trust & safety, and security:

  • Age assurance: Providers will need workable age verification or estimation flows at signup and re‑authentication. This spans document checks, telco‑based tokens, or on‑device estimation methods, each with privacy trade‑offs.
  • Safety‑by‑design evidence: Teams will be expected to produce design reviews, harms taxonomies by age cohort, UI copy tests, and rollout metrics that show real‑world effect. “We turned off a feature for teens” won’t suffice without impact data.
  • Algorithmic controls: Feed ranking, recommendations, and connections will need modes that align to minors’ needs. That means stricter defaults, fewer dark patterns, and explainable switches parents can understand.
  • Vendor scrutiny: Identity, content moderation, and analytics vendors will face the same proof burden. Contracts will be rewritten to require audit‑ready logs and model cards tuned to youth risks.

For global companies, the EU KIDS Act could become the high bar that redesigns the baseline experience everywhere. Running two materially different account systems for 13–14 year‑olds versus 15–17 year‑olds is expensive; harmonizing up to EU standards may prove cheaper than maintaining parallel logic.

Where this sits beside the DSA and GDPR

The Commission’s proposal slots into a dense policy stack. The Digital Services Act already bans targeted advertising to minors and forces very large platforms to assess and mitigate systemic risks to children. The General Data Protection Regulation sets the age of consent for information society services at up to 16, with Member States allowed to lower it to 13 (Article 8). By proposing an EU‑wide minimum age of 15 to open an account, the KIDS Act would reduce today’s country‑by‑country patchwork for platforms, though consent for data processing and eligibility to open an account aren’t the same legal question.

Compared with other jurisdictions, the bar looks higher. The United States’ COPPA focuses on children under 13 and centers on parental consent and data collection limits. The UK’s Age Appropriate Design Code pushes privacy‑by‑default for under‑18s, but it doesn’t introduce an EU‑style 15+ account baseline. If the EU KIDS Act advances into law, it creates a distinct compliance template that blends eligibility, proof, and design obligations.

The practical upshot: DSA risk assessments identify the problem space; GDPR governs lawful processing and transparency; the EU KIDS Act, as described by the Commission, would force platforms to prove their design choices actually work for minors, and to keep that proof handy.

Why the proof burden matters for costs and timelines

Moving from “comply” to “show your work” changes budgets. Verification flows will need fallback paths, exception handling, and clear redress processes. Trust & safety teams will need researchers who can run pre‑launch tests with teen cohorts and then validate outcomes in production. Legal will push for attestations and internal audits before each major feature ships to minors.

That costs money. It also creates repeatable artifacts: test plans, hazard logs, consent flows by age band, and rollback criteria. Over time those artifacts could become a de facto certification kit that investors, partners, and app stores expect to see. The KIDS Act’s approach encourages that ecosystem, because the burden of proof is only satisfied with evidence a third party can read and understand.

What to watch on timing, enforcement, and tech choices

The Commission’s September 17, 2026 proposal is the starting gun, not the finish line. It must pass the European Parliament and Council, so details can shift in trilogues. But the direction is set: the EU favors an enforceable, evidence‑first model for youth safety. Platforms that wait for final text to scope engineering will be behind.

Three decisions to make now:

  • Pick a primary age‑assurance path and a privacy‑preserving backup. Map failure rates and false positives, then publish the trade‑offs.
  • Rewrite product requirement docs for minor‑facing features to include testable risk mitigations, success metrics, and retention limits.
  • Align DSA risk assessments, GDPR records of processing, and KIDS Act evidence into one set of living documents to cut audit friction.

There are open debates the law won’t settle alone: which age‑assurance tools protect privacy best; how to treat children who borrow devices; how to prevent design workarounds that push teens to less safe corners of the internet. Those are implementation choices. They will define whether the EU KIDS Act improves outcomes for young users, or just thickens paperwork.

The Commission has set a clear expectation: if a service wants children or teens on the platform, it needs proof that the experience is built for them. That is the core change the EU KIDS Act would bring. Companies that build the evidence now will find compliance less painful later, and they may ship a better product for families in the process. For more on this, see bloomberg.com and nytimes.com.