Europe Has Proposed a New Social Media Rulebook for Children — What the KIDS Act Could Mean for Ireland

Europe's proposed EU KIDS Act would reshape social media for children in Ireland, bringing new age limits and safer platform design requirements.

By Safegram Editorial TeamPublished · 🇮🇪 English
Irish parent and teenage son reviewing a smartphone together at home, illustrating the proposed balance between parental oversight and teenage digital independence.

Europe’s debate about children and social media has moved into a new phase. The European Commission has proposed the EU KIDS Act, a regulation that would combine age-based access rules with a much broader requirement for safer platform design. For Ireland, the important point is not only the proposed age limits. The proposal would also reshape feeds, notifications, stranger contact, parental controls, age verification and AI companions used by minors.

Key takeaways

  • The EU KIDS Act is a legislative proposal, not final law. The European Parliament and Council can change it during negotiations.
  • Under the proposal, children under 13 would not have social-media accounts; ages 13 and 14 could use guardian-managed limited accounts; independent accounts would begin at 15.
  • For 13- and 14-year-olds, the proposal describes always-on parental tools, approved contacts and a daily time limit of no more than one hour.
  • Age checks would have to be more meaningful than self-declared birthdays and should use privacy-preserving methods that verify age without revealing identity to the platform.
  • Services used by minors would face restrictions on infinite scroll, endless autoplay, certain engagement rewards, sleep-disrupting notifications and unsolicited stranger contact.
  • Minor profiles would be private by default, and recommendation systems would need to prioritise safety, quality and mental wellbeing rather than engagement.
  • AI companions and chatbots accessible to minors would face specific restrictions, including default-off behaviour in some contexts and safeguards against designs that encourage emotional dependency.
  • Ireland is already enforcing existing online-safety rules: Coimisiún na Meán opened its first formal Online Safety Code investigation on 8 September 2026 into concerns about potentially ineffective age-assurance and parental-control implementation on X. That investigation is ongoing and is not a finding of breach.

The most important detail: this is a proposal

The headline numbers are likely to attract the most attention: no social-media accounts under 13, parent-supervised access at 13 and 14, and autonomous accounts from 15.

But the legal status matters.

The European Commission adopted the KIDS Act proposal on 17 September 2026. It must now be examined by the European Parliament and the Council. Those institutions can amend the text before any final regulation is adopted.

So parents, schools and platforms should not treat the current proposal as if it were already binding law.

What is useful today is understanding the direction of travel.

The Commission is proposing a model in which age limits and safer design operate together. The core idea is that protecting children online cannot rely only on a date-of-birth box or on parents manually finding every safety setting after an account has already been created.

A three-step age model

The proposal creates a staged approach to social-media access.

Under 13, children would not be able to create social-media accounts. A narrow exception would allow limited access to child-focused video services through a parent’s own account, with personalised feeds and search switched off and a parent-controlled time limit.

At ages 13 and 14, a guardian could create a limited “mini account”. Parental tools would remain active, contacts would require approval and daily use would be capped at no more than one hour.

From age 15, young people could open and manage their own account — but the service would still have to comply with the proposal’s protections for minors.

That distinction is important.

The proposal is not simply saying that a teenager becomes an adult user at 15. It is separating independent account control from the safety obligations platforms would continue to owe to users under 18.

Age verification without turning social media into an id database

One of the hardest questions in age-based online regulation is obvious: how can a platform know a user’s age without collecting more identity data than necessary?

The Commission’s proposal explicitly tries to separate age proof from identity.

Its explanatory materials say platforms should use certified age-verification solutions independent of the platform. The Commission points to the EU age-verification app and, over time, the European Digital Identity Wallet as examples.

The intended principle is that the service learns the age result it needs — for example, whether a user is above or below a threshold — rather than receiving a copy of the person’s passport, identity document or full identity profile.

The Commission also says the approach should use privacy-preserving techniques, including zero-knowledge proof technology, so the verification itself cannot be used to identify, locate, track or profile a person.

Every Member State would have to provide at least one free way to prove age, including for people without a digital identity.

Teenager using a smartphone with an abstract age-verification symbol that confirms age without displaying identity documents.

The Commission proposes privacy-preserving age checks designed to prove an age threshold without handing identity documents to the platform.

Why self-declared birthdays would no longer be enough

For years, many services have effectively relied on a user typing a date of birth.

The KIDS Act proposal would explicitly move away from that model for services within scope.

The Commission says age would need to be established through certified age-verification systems. It also proposes checks for existing accounts: within six months of the rules applying, platforms would need to determine whether current users are under 15 and disable accounts where the user is under that threshold or age cannot be established.

For many existing adult accounts, the Commission says additional verification may not be necessary where a provider already has a high-confidence age estimate from multiple signals.

That balance will be closely watched during negotiations because age assurance has to solve two problems at once: enforce meaningful age rules while avoiding unnecessary identity collection.

The feed itself would have to change

The proposal goes much further than account age.

For minors, services would be prohibited from using certain design techniques intended to drive compulsive or excessive use.

The Commission specifically identifies endless autoplay, infinite scrolling without meaningful breaks, certain notifications designed to pull a child back into the service, rewards for posting or streaming to large audiences, and streak mechanics that penalise users for not returning every day.

Services would also need effective time limits and usage breaks designed around sleep and school time.

Recommendation systems would face a different objective for minors. The Commission says feeds should be optimised for safety, quality and mental health rather than engagement.

Content a young person actively chose to follow would come first. Tracking-based personalisation would be off by default, data from outside the service could not be used for this purpose, and platforms would have to avoid recommendation “rabbit holes”.

Children would also need an easy way to reset their feed and at least one feed option without profiling.

Teenager using a calmer social experience with time limits, quiet hours and restricted contacts represented as privacy controls.

The proposal would restrict several engagement and contact features for minors and require safer settings by default.

Private by default, with stranger contact restricted

The proposal also changes the default social graph around a minor.

The Commission says nobody should be able to message a child without pre-approval. Minors should not appear in contact suggestions, should not be added to groups without agreement and should be able to block users anonymously.

Their content would be visible only to accepted contacts, their contact information should not be disclosed, and livestreaming would be disabled by default.

These provisions are significant because they shift online safety away from a model where young users are expected to find the right privacy settings themselves.

Instead, the platform would be expected to begin from the safer state.

AI companions are now part of child-safety policy

The KIDS Act proposal also explicitly covers AI companions and chatbots.

That reflects how quickly children’s digital environments are changing.

Under the Commission’s proposal, AI companions and chatbots accessible to minors could not use designs that simulate human relationships in ways likely to create emotional dependency.

By default, they would not carry a child’s previous conversations into later interactions. They would need child-risk testing before launch and ongoing monitoring afterwards.

For children under 13, access would be through parental-control tools. Where a chatbot is built into another platform or game, it should not switch on automatically, should not be pushed at children and should be easy to disable.

These details could become especially important as AI assistants move from separate apps into social platforms, games, creator tools and everyday communication products.

Parents get tools — but platforms keep the responsibility

The proposal gives parents significant controls.

These include screen-time controls, the ability to see and approve contacts, management of settings and the ability to report harmful content on behalf of a child.

For 13- and 14-year-old accounts, those parental tools would always be active.

But the Commission is explicit that parental tools do not replace platform responsibility.

For the largest online platforms, the proposal would reverse the compliance burden. Rather than waiting for regulators, families or researchers to prove that a product is unsafe, very large platforms would have to produce a detailed compliance plan and have it independently audited before operating under the new regime with children.

The Commission’s Q&A says fines could reach 6% of worldwide annual turnover for breaches.

Irish parents and teenage daughter discussing screen time, privacy and online contacts around a kitchen table.

The proposed rules give parents stronger tools while keeping the legal responsibility for safe design on platforms.

Why this matters in ireland now

Ireland is not starting from zero.

Coimisiún na Meán already operates Ireland’s Online Safety Code for designated video-sharing platforms.

On 8 September 2026, the regulator opened its first formal investigation under that Code into X.

The investigation followed concerns about the possible ineffective implementation of age-assurance measures and parental-control systems. Coimisiún na Meán said the relevant parental controls may be ineffective, may lack minimum requirements, may be difficult to locate and may not be sufficiently brought to users’ attention during sign-up.

The investigation is ongoing.

It is important not to confuse an investigation with a finding. At this stage, Coimisiún na Meán has opened a formal process; it has not concluded that X breached the Code.

The timing nonetheless illustrates why age assurance and parental controls are moving from product-policy discussions into enforceable regulatory questions.

What the proposal could mean for safegram

Safegram’s current teen-safety direction already focuses on age bands, parent-linked teen accounts, restricted adult-to-teen discovery and messaging, content and contact controls, screen-time restrictions, blocking and reporting.

Safegram also separates verification from public identity. The intended model is that a user can be verified for safety and accountability without necessarily displaying their legal identity publicly.

However, the KIDS Act proposal uses a more specific age structure than Safegram’s current 13+ model.

If the proposal became law in substantially its current form and Safegram fell within scope, Safegram would need to review whether its age bands, guardian controls, time limits and account-creation rules matched the final legal requirements.

That review would also need to cover AI.

Any Safegram AI assistant or AI-powered interaction accessible to minors would need to be assessed against the final rules on default settings, memory, emotional-dependency design, parental controls and risk monitoring.

Safegram should not claim compliance with a law that is still under negotiation.

Its public product claims should continue to distinguish clearly between features that are live, features in testing or beta, and planned controls. Recent Safegram product status has treated core teen protections as implemented, while some more advanced recommendation-safety and AI-related protections have remained in implementation or planning and should not be presented as live without production verification.

The bigger change: safety becomes a design requirement

The most consequential part of the KIDS Act may not ultimately be the age of 13 or 15.

It may be the principle underneath the proposal.

For years, online child safety has often been treated as a collection of optional settings: turn off recommendations, make the profile private, disable messages, set a screen-time reminder, block a stranger.

The KIDS Act would move toward a different model.

For minors, the safer state becomes the default state.

The platform would have to justify its design rather than requiring the child or parent to discover every protection manually.

Whether the final law retains every detail of the Commission’s proposal will now depend on negotiations between the European Parliament and Council.

But the policy direction is increasingly clear: age assurance, privacy, parental control, recommendation systems, messaging architecture and AI companions are being treated as parts of the same child-safety system.

For Irish families, that means the future conversation is likely to be broader than “What age should children join social media?”

The harder question is becoming: once they are allowed in, what kind of social media should they be allowed into?

Frequently asked questions

Is the EU KIDS Act already law?

No. The European Commission adopted a legislative proposal on 17 September 2026. The European Parliament and Council must now negotiate the text before any final regulation is adopted.

What age would children be allowed to use social media?

Under the current proposal, children under 13 would not have social-media accounts. Ages 13 and 14 could use guardian-managed limited accounts. Independent account management would begin at 15.

Would 13- and 14-year-olds have a time limit?

The Commission’s current proposal describes a daily limit of no more than one hour for guardian-managed accounts for ages 13 and 14.

Would platforms need to see a child’s passport or identity card?

The proposal aims to avoid that. The Commission says certified age-verification tools should verify the required age threshold without platforms receiving identity documents or learning the person’s identity.

Would infinite scroll be banned for everyone?

No. The proposal’s restrictions discussed here apply to services and experiences used by minors. The final legal text may also change during negotiations.

Would AI chatbots be covered?

Yes. The proposal includes AI companions and chatbots accessible to minors and sets rules intended to reduce emotional dependency, automatic activation and other child-safety risks.

What is happening in Ireland already?

Coimisiún na Meán opened its first formal investigation under Ireland’s Online Safety Code on 8 September 2026 into concerns about potentially ineffective age assurance and parental controls on X. It is an investigation, not a finding of breach.

How does this relate to Safegram?

Safegram’s teen-safety model already includes age-based protections, guardian-linked controls and restrictions on adult-to-teen contact. If the KIDS Act becomes law, Safegram would need to assess its final obligations against the adopted text and verify the production status of each relevant safety feature before claiming compliance.

Source references

European Commission — “EU KIDS Act: helping children navigate a safer online world”, 17 September 2026.

https://commission.europa.eu/news-and-media/news/eu-kids-act-helping-children-navigate-safer-online-world-2026-09-17_en

European Commission / Shaping Europe’s Digital Future — “The KIDS Act explained”, updated 17 September 2026.

https://digital-strategy.ec.europa.eu/en/faqs/kids-act-explained

European Commission / Shaping Europe’s Digital Future — “Proposal for EU KIDS Act — EU Keeping Internet Digital Spaces Accountable and Trustworthy”, 17 September 2026.

https://digital-strategy.ec.europa.eu/en/library/proposal-eu-kids-act-eu-keeping-internet-digital-spaces-accountable-and-trustworthy

Coimisiún na Meán — “Investigation commenced into X under Online Safety Code”, 8 September 2026.

https://www.cnam.ie/investigation-commenced-into-x-under-online-safety-code/

More from Safegram

Try Safegram

Privacy-first social and a verified marketplace, built in Dublin.