Leaked documents have given the public an early look at the European Commission's plan to overhaul how children access online platforms. The proposal, reportedly dubbed the EU Kids Act, would restrict users under 15 from freely accessing social media, video-sharing platforms, online games, and AI chatbots unless specific safeguards are in place. The measure is expected to be formally unveiled soon, and it marks one of the most significant attempts yet by a major regulatory body to reshape how minors experience the internet.
What the Leaked EU Kids Act Proposes
According to the leaked material, the EU Kids Act would not simply ban children from platforms like TikTok, Instagram, or YouTube outright. Instead, it appears to set a baseline: users under 15 would need parental consent to access many of these services, and platforms would be required to build "safety by design" features specifically for younger users. That could mean stripped-down interfaces, restricted recommendation algorithms, limits on direct messaging from strangers, or reduced exposure to advertising.
What makes this proposal notably broader than previous child-safety efforts is its scope. Rather than focusing narrowly on social media, the leaked framework reportedly extends to AI chatbots and online gaming platforms as well. That reflects how quickly the online landscape has changed. A decade ago, regulators worried mainly about social feeds and messaging apps. Today, children spend significant time interacting with generative AI tools and multiplayer games that collect behavioral data, enable real-time chat with strangers, and use engagement-driven design similar to social platforms.
If finalized, the EU Kids Act would join a growing list of European digital regulations, following in the footsteps of the Digital Services Act and GDPR, both of which already impose obligations on platforms regarding minors' data and content. But this proposal goes further by attempting to draw a hard age line across multiple categories of digital services at once.
The Privacy Trade-Off: Age Verification at Scale
Any law that restricts access based on age requires a way to actually determine how old someone is, and that is where the privacy implications become significant. To enforce restrictions on under-15 users across social media, games, and AI chatbots, platforms operating in the EU would likely need to deploy some form of age verification or age estimation technology at scale.
That could involve document uploads, facial age-estimation scans, or third-party identity verification services woven into sign-up flows across thousands of apps and websites. Each of these approaches introduces new data collection questions: What information is collected during verification? How long is it retained? Who has access to it, and how well is it protected from breaches?
This is not a hypothetical concern. As detailed in a broader look at age verification laws building a global surveillance network, similar mandates in the United States, United Kingdom, and Brazil have raised concerns among privacy researchers about the infrastructure being created in the name of child safety. Centralizing identity checks across major platforms, even with good intentions, creates new data repositories that could become attractive targets or be repurposed beyond their original scope.
The EU's approach, still in leaked draft form, will need to grapple with these same tensions. Regulators will likely face pressure to specify exactly what verification methods are acceptable, how data minimization will be enforced, and whether smaller platforms will face the same compliance burden as major tech companies.
How This Fits a Global Pattern
The leaked EU Kids Act does not exist in isolation. Governments around the world have been moving toward stricter age-based access rules for digital platforms, driven by concerns about mental health, exploitation, and excessive screen time among children. What sets the EU's reported approach apart is its attempt to cover such a wide range of technology types under one framework, rather than passing separate rules for social media, gaming, and AI tools individually.
This breadth is likely intentional. AI chatbots in particular have emerged rapidly as a category regulators previously had little reason to address, and their inclusion here signals that EU policymakers see them as functionally similar to social platforms in terms of engagement design and data collection.
What This Means For You
For parents and guardians in the EU, the eventual passage of the Kids Act could mean new consent workflows, age checks, and restricted features on apps their children already use. For platforms, it means significant engineering and compliance work to build age-appropriate experiences and verification systems that satisfy regulators without alienating adult users through excessive friction.
For everyday users, even those outside the EU, this proposal is worth watching closely. Major platforms often apply regulatory changes globally rather than building separate systems per region, meaning age verification requirements introduced in Europe could eventually shape product design elsewhere. It is also a preview of how governments are increasingly willing to regulate AI chatbots alongside more established platforms, a sign that this technology is now viewed as mainstream enough to warrant the same scrutiny as social media.
Actionable Takeaways
The leaked EU Kids Act is still a draft, and details will likely change before formal introduction. Readers should watch for the official proposal to see how age verification will actually be implemented and what data protections accompany it. Parents can start reviewing privacy settings and parental controls already available on platforms their children use, since many of the safety features under discussion already exist in limited form. And anyone concerned about the broader trend toward mandatory identity checks online should pay attention to how these systems handle data retention and security, since the effectiveness of child-safety legislation will ultimately depend on how responsibly that underlying verification infrastructure is built and protected.




