Europe’s New KIDS Act Puts Safe by Design at the Centre of Children’s Online Lives
The EU KIDS Act proposal emphasizes "safe by design" for children's online services, including age-appropriate social media and AI.
Key takeaways
- The European Commission proposed the EU KIDS Act on 17 September 2026; it is a proposal, not yet final EU law.
- The proposal would prevent children under 13 from holding social-media accounts and set 15 as the EU-wide age for opening an account independently, with a gradual approach in between.
- Service providers would have to demonstrate that services used by children are age-appropriate and safe by design.
- The framework reaches beyond conventional social media, including certain online games and AI chatbots/companions.
- Ireland is already enforcing its Online Safety Code: Coimisiún na Meán opened its first formal investigation under the Code on 8 September 2026, examining X’s age-assurance and parental-control implementation.
A significant change in the European online-safety debate
For years, much of the child-online-safety debate focused on parental settings, content moderation and whether individual platforms were doing enough after harm occurred. The KIDS Act proposal points toward a more structural model: services that children use would be expected to show that safety has been considered in the design of the product itself.
According to the European Commission, the proposal rests on a gradual age approach, safety by design, privacy-preserving age assurance and stronger enforcement. The Commission says children under 13 should not have social-media accounts, while 15 would become the common age at which a minor could open an account independently. The precise obligations and final wording can still change as the proposal moves through the EU legislative process.
Why “safe by design” matters
Safety by design changes where responsibility begins. Instead of relying mainly on a child to recognise danger, a parent to find a buried control, or a regulator to intervene after a problem becomes visible, the product is expected to reduce foreseeable risks from the outset. That can affect default settings, contact permissions, recommendation systems, notifications, age assurance, parental controls and the way potentially harmful features are presented.
Ireland is already moving from rules to enforcement
The European proposal arrives as Ireland’s own online-safety regime enters a more active enforcement phase. On 8 September 2026, Coimisiún na Meán commenced its first formal investigation under Ireland’s Online Safety Code, concerning X. The regulator said its concerns relate to the potential ineffective implementation of age-assurance mechanisms and to parental controls.
The investigation does not itself establish a breach. It is a formal regulatory process examining compliance. That distinction matters: credible online-safety reporting should separate an investigation from a finding.
Age assurance without turning the internet into an identity checkpoint
Age assurance is one of the hardest parts of the debate because two legitimate objectives can collide: protecting minors and protecting everyone’s privacy. The emerging European approach is not simply to collect more identity data. The Commission explicitly describes privacy-preserving age assurance as a pillar of its approach.
Good implementation therefore matters as much as the headline rule. Systems should seek the minimum information necessary, secure it appropriately and avoid turning age checks into unnecessary profiling. Regulators and technology providers will have to demonstrate that child protection and data minimisation can work together.
The rules are expanding beyond social media
One of the most important features of the KIDS Act proposal is its breadth. Commission material describes a framework aimed at risky digital services and AI systems. Published analyses identify coverage extending to social media, video-sharing platforms, online games, AI chatbots and AI companions, with some obligations also touching app stores and operating systems.
That reflects how children’s digital lives actually work. A young person may move between messaging, video, gaming, creator content and conversational AI in a single afternoon. A safety framework focused on only one category can leave large gaps.
Where Safegram fits — and what is live versus planned
Safegram’s product direction is built around verified participation, privacy and safer communities. Live Safegram functionality includes end-to-end encrypted chat, verification layers for users and businesses, the Safegram Exchange, creator/business functionality and safety-oriented account controls.
Safegram’s teen and family safety architecture is designed around stronger separation between teen and adult discovery/messaging, age-aware access and family safety notifications without giving family members access to private message content. Individual elements can evolve as implementation, testing and regulatory requirements develop.
Other Safegram concepts and roadmap items should not be confused with current regulatory requirements or described as universally live unless confirmed in the production app. Safegram’s objective is to keep adapting its safety model as European rules, technical standards and user expectations develop.
What families and platforms should watch next
The KIDS Act is now a legislative proposal. The European Parliament and the Council will consider it, and the final law may differ from the Commission text. Families should therefore be cautious about headlines describing every proposed measure as already legally binding.
For platforms, however, the broader direction is already visible. The Digital Services Act, Ireland’s Online Safety Code and the proposed KIDS Act all point toward stronger accountability for design choices that affect minors.
Frequently asked questions
Is the EU KIDS Act already law?
No. The European Commission adopted its proposal on 17 September 2026. It must go through the EU legislative process before becoming final law, and its provisions may change.
Would social media be banned for everyone under 15?
The Commission proposal describes a gradual approach: children under 13 would not have social-media accounts, while 15 would be the EU-wide age for opening an account independently. The detailed framework includes an intermediate, more supervised approach for younger teenagers.
What does “safe by design” mean?
It means considering foreseeable safety risks when designing the service and its defaults, rather than relying only on users to protect themselves after launch.
Does the proposal cover AI chatbots?
Yes. Commission material says the proposal addresses risky digital services and AI systems, and published analyses identify AI chatbots and AI companions among covered categories.
What is happening in Ireland now?
Coimisiún na Meán is enforcing Ireland’s Online Safety Framework. On 8 September 2026 it opened its first formal investigation under the Online Safety Code, examining X’s implementation of age assurance and parental controls. An investigation is not a finding of breach.
Does safer age assurance have to mean uploading an ID everywhere?
Not necessarily. The Commission identifies privacy-preserving age assurance as a core principle. The practical methods and standards will be important to watch as the proposal develops.
Source references
- European Commission, Shaping Europe’s Digital Future — “EU KIDS Act to restrict social media platforms’ access to children in the EU”, 17 September 2026 (updated 22 September 2026).
- European Commission — Proposal for EU KIDS Act, “EU Keeping Internet Digital Spaces Accountable and Trustworthy”, 17 September 2026.
- Coimisiún na Meán — “Investigation commenced into X under Online Safety Code”, 8 September 2026.
- Coimisiún na Meán — Online Safety Framework materials.
- European Commission — G7 common principles for protecting minors online, 29 May 2026.
More from Safegram
Try Safegram
Privacy-first social and a verified marketplace, built in Dublin.