Detailed research note

The EU proposes an age gate—and the machinery behind it

Research checked 2026-09-19. Read the dated findings and sources below.

The Commission's September 17 KIDS Act proposal turns the earlier leaked draft into something we can inspect. This is the Commission's proposed regulation, awaiting the legislative process. Its stated purpose combines child protection with a single European framework. Official publication

The headline is access by age. For covered social and video services, independent accounts would start at 15; guardians could create restricted accounts at 13–14, capped at an hour daily. Younger children would have a narrow, supervised video route. Existing accounts would face checks, with high-confidence exceptions. Commission explanation

Look underneath the age limit. Articles 5 and 36 would require provider-paid audits and supervisory fees; those fees explicitly support the EU Age Verification Scheme. Article 29 would route covered account checks through certified third-party credentials on EU lists. Operating systems would share an already-obtained age signal with consent. Article 28 would require zero-knowledge proof and prohibit identification or tracking through age assurance. Article 8 would make child-protective design the default unless adulthood is established. Privacy protection and compulsory access sorting are being designed together. Proposal, Articles 5, 8 and 28–36

The accompanying Communication extends the picture to AI companions, games and app stores: product-design obligations, regulated recommendations and app age ratings alongside the access rules. Enforcement builds on the DSA and AI Act. This combines public rulemaking with private implementation, assessment and distribution. Commission Communication, sections 2.2–2.4

One revealing detail sits in the impact analysis. An additional rights-and-cost study was commissioned in August, with final publication expected in the fourth quarter. The document also sees wider e-government benefits from expanded digital-identity coverage. It cites earlier 5Rights and WeProtect material. Those are traceable inputs into the evidence base; authorship and influence on particular clauses need their own records. Analysis of impacts, pp. 14, 49 and 75–76

Our reading: the consequential change is a proposed division of labour. Government defines acceptable access and technical requirements; approved verification systems supply credentials; services apply them; auditors assess compliance; industry fees fund supervision. The next investigation should follow who wins those implementation roles and what decisions they can actually make. The specification, certification list, contracts and review procedures are where the institutional outline becomes an operating system.