The KIDS Act will make the internet less safe
On 16 September, the European Commission presented the KIDS ACT, its plan for making online experiences safer for young people. Far from being a move to lead the EU towards better digital environments, this move is a missed opportunity to address the root cause of why online platforms are harmful to children – and everyone else. This blog analyse the proposal’s shortcomings.
European Commission announced the KIDS ACT
During her annual address to the European Parliament, the President of the European Commission announced her intention to protect young people from platforms and services that deprive children of their childhood and of their focus. The next day, the Commission published the KIDS ACT (an acronym for ‘Keeping Internet Digital Spaces Accountable and Trustworthy’). This announcement arrives after a period of much debate around protecting young people online, and even announcements of social media bans from countries across Europe. As a response to this discussion, on April 22, youth organisations across Europe came together to demand real change, instead of exclusions and bans, from EU lawmakers.
The Commission had the opportunity to change the rules of the dangerous game that makes people unsafe online. Instead, it’s mostly restricting who gets to play. Not only is the KIDS ACT a terrible proposal, it’s also a missed opportunity for the European Commission to lead the EU towards a safer digital environment for children and everyone else. The proposal instead determines who is allowed to use services built upon harmful design choices, and clumsily tries to make some of these choices safe for a narrow age bracket, rather than addressing why they can be harmful in the first place. In doing so, it leaves largely untouched the business models that put us all at risk, and sets complex standards for safety which will cement Big Tech dominance. Let’s unpack the proposal.
The problem with focusing on age
The KIDS ACT mostly delays young people’s exposure to online harms. On the one hand, it would ban social media accounts for those under 15*. On the other hand, it would require companies to apply certain protections to minors’ accounts against pervasive exploitative tracking, intrusive default settings, and AI companions designed to create emotional dependencies, among other risky features.
What is striking is that these protections apply only to people aged 15*-18. It’s as if these services, practices and functionalities will magically cease to be harmful on someone’s 18th birthday. We all remain vulnerable to manipulative design and unfair personalisation even as adults: not even the most digitally literate person can examine every single default setting, decode every recommendation system, or resist every strategically timed prompt designed to get us to keep clicking. Fairness must be built into the environment itself, not left to the skills of the people using it. Many of the measures proposed in the KIDS ACT address harms that are not specific to childhood and were therefore meant to be tackled through the forthcoming Digital Fairness Act (DFA), which the Commission said will address addictive design for all consumers. The risk is that by treating these practices primarily as child-safety problems, the Commission is lowering the ambition of the rules still to come. Under the appearance of acting on online harms, the KIDS ACT may rob us of stronger protections for ALL of us, including children.
A blanket ban treats everyone’s online presence as illegitimate until proven otherwise
The underlying logic of the KIDS ACT is that, while some risks can be mitigated for people aged 15-18, those under 15* years old should be banned from social media altogether. This blanket age-based exclusion treats children’s online presence as the problem, rather than following young people’s own call to examine the conditions under which digital services expose them to harm. Under the UN Convention on the Rights of the Child, young people — including those under 15 — have the fundamental right, online and offline, to participate in society, access information, communicate with others, play, and develop their identities. Age-gates undermine these rights.
They would also fundamentally change the open nature of the internet: services would have to treat users as children by default unless they prove their age. The Commission’s approach would create a two-tier internet in which children but also adults who cannot or do not wish to pass an age check are excluded from spaces that have become important for education, socialisation, access to information and participation in public life. People who are unable to verify their ages could include many already vulnerable groups – the elderly, the unhoused, migrants. By focusing on risks, the KIDS Act neglects the impact on the fundamental rights of those affected (the entire population) — which go far beyond the rights to privacy and to data protection. Despite serious warnings about the consequences of building an unprecedented infrastructure of surveillance and exclusion, the EU Commission presented the proposal without an appropriate impact assessment.
As the French age-gating failure has shown, measures designed to protect children must be necessary, proportionate, effective and compatible with their rights. The EU has other, more direct and proportionate regulatory choices available: enforcing existing duties, strengthening protection for everyone through the upcoming DFA, and requiring platforms to change the harmful design and business practices which are at the center of the harmful business model. EDRi members are taking the matter into their own hands, going to court and launching class-action lawsuits over addiction-inducing DSA breaches rather than relying on lethargic public authorities. Age-gating cannot be a technological shortcut for a problem rooted in platform design and business incentives.
Why wouldn’t people systematically circumvent it?
The age-based approach creates a new set of problems instead of addressing harms that affect individuals, groups and society as a whole. The proposal gives guardians some (welcome) flexibility to override the 15-year threshold, where a child is at least 13. But guardians would need their own account on the platform, and would have to provide not only their own proof of age but also their proof of guardianship over the child. They would then have to oversee the child’s online experience in detail, pre-approve contacts, and set the mandatory daily time limit between 0 and 60 minutes.
Young people will find ways to bypass this stripped-down, patronising, parent-controlled and heavily monitored version of service and gain access to an unprotected ‘adult’ version instead. Some guardians may not be willing or able to complete all the required steps; others may use the controls in ways that enable excessive surveillance or perpetuate abuse. This is particularly serious for young people who rely on online spaces to access information or communities they cannot safely access through their families, including those who are LGBTQIA+ or who seek sexual or reproductive-health information. These vulnerable young people will therefore be even more likely to circumvent the restrictions. If young people are to grow into autonomous and resilient human beings, they need to build trust, competence and independence: to recognise risky situations, set boundaries and seek help. Draconian rules will not teach those skills. They may simply encourage people to find someone – anyone – to age-verify on their behalf.
Adults, too, may seek workarounds. A parent who gives a child a phone because they lack the time and energy to entertain them may simply give them an age-verified phone instead.
Who else will want to bypass these rules? Companies. Compliance is likely to be complex and demanding, particularly for smaller services and open-source projects. This burden could cement the dominance of Big Tech over the few alternatives we have: services which do not harvest personal data, do not rely on addictive systems, are interoperable, or operate as open and free software. And because the measures apply only to minors only, the simplest workaround may be to label a service ’18+’ and call it a day.
The KIDS Act’s legacy would then be grim: widespread age verification, the exclusion of young people from important online spaces, further consolidation of Big Tech’s power, and structural harms left largely intact for everyone who is (or appears to be) 18 and over.
The proposal also lands in a wider political context. Even as the Commission promotes deregulation under the banner of ‘simplification’ and invests heavily in developing and deploying AI across the EU, it is responding to the harms of digital technologies by placing new responsibilities and restrictions on people. The KIDS Act follows the same pattern: instead of asking what companies should be allowed to build and optimise for, it asks who should be allowed through the door.
The EU should be ambitious about children’s digital safety, but ambition should not be measured by how high an age threshold Europe can announce. It should be measured by whether platforms are made safe enough for children – and everyone else – to participate, rather than considering young people safe because they’ve been pushed out of spaces.
* A threshold which can be lowered to 13 where a supportive and available guardian agrees.
