left-caret

Client Alerts

Europe Aims to Limit Minors’ Access to Social Media: The EU KIDS Act, Danish Draft Bill and Lessons Learned From the Australian Example

September 28, 2026

By Natalie Rae Coulton and Harry Martin

On 17 September 2026, the European Commission announced its proposal to implement a harmonised framework aimed at protecting children across the EU from some of the nefarious risks associated with social media, video-sharing platforms, online games and AI systems. The proposal, captured in the “EU KIDS Act — EU Keeping Internet Digital Spaces Accountable and Trustworthy” (the EU KIDS Act) runs to approximately 99 pages and centres around four primary pillars designed to protect minors from risky digital services and AI systems, uphold the digital single market and maintain a coherent regulatory frameworks and enforcement structure for the protection of minors online.

The announcement of this proposal from the European Commission coincides with a similar announcement from the Danish government, which submitted for public consultation a draft bill of legislation that was aimed at introducing a minimum age of 15 for access to certain social media services earlier this month. It also comes almost a year after the Australian government introduced a blanket ban on social media for minors under 16 years old.

So, the question becomes, will this proposal achieve its aim? And have the Danish and EU proposals factored in the lessons learned from the Australian approach?

In this article we will briefly step through the EU’s proposal and briefly touch on the Danish draft bill before drawing a comparison to the Australian legislation, all with the aim of understanding how these new legislative developments may impact use, access and the availability of digital content to minors across Europe.

I. EU Kids Act Approach – The Four Pillars

The EU KIDS Act has adopted a four-pillar approach to address what is seen as a gap in the existing EU legislation surrounding internet and social media usage by minors.

Pillar One – Tiered Age Restrictions

The first pillar of the proposal seeks to introduce a “tiered” system that would allow the gradual introduction of social media to minors. Children under the age of 13 would be entirely prohibited from making and holding any social media accounts. The proposal would allow, however, for children under 13 years old to access “specifically designed, child-friendly video-sharing services” through a guardian’s account. Relevant platforms would be required to offer a simple tool to easily restrict a device and limit usage of the service to one hour per day.

Children aged 13 and 14 would be granted access via “mini accounts” to age-appropriate social media and video-sharing platforms set up and managed by a guardian. This tool is also intended to include capped usage of one hour per day.

Children aged 15 to 17 would be granted authority to open “autonomous” social media accounts without the need for a guardian to supervise the account or the child’s usage of that account. Platforms will remain subject to specific design requirements for users under the age of 18. Specifically, these requirements focus on anti-addictive design (e.g., no infinite scroll, autoplay or engagement-penalising features), restrictions on recommender systems and profiling, default privacy and device settings (camera, microphone, geolocation off), contact safeguards against strangers and protections against exploitative economic transactions.

These requirements originate primarily from the EU KIDS Act itself, which will implement many of the recommendations the European Commission had already issued under Article 28 of the Digital Services Act (DSA) in its July 2025 guidelines on the protection of minors. The DSA provides the existing baseline obligation requiring platforms accessible to minors to ensure a high level of privacy and safety and prohibits profiling-based advertising to known minors. The EU AI Act supplements this by classifying certain AI use-cases affecting children as high-risk, requiring dedicated risk management and transparency safeguards. The GDPR (notably Article 8 on children's consent and the data minimization principle) underpins the entire framework as the foundational data protection layer.

Pillar Two – Safety by Design

The Act imposes strict “safety by design” requirements on providers of online social networking services, video-sharing platform services and AI companions, general conversational chatbots and online games. These safety by design obligations are intended to apply in various layers, with some generally applicable requirements, as well as others that are more targeted to particular services. One key proposal would see online social networking services and video-sharing platform services subject to additional prohibitions on designing, organising or operating their platforms in a manner intended to encourage compulsive or excessive use of the service by minors.

This obligation is aimed at specifically limiting features aimed at keeping users under the age of 18 “continuously engaged”, and targets some of the key underlying design features prominent in these platforms, including infinite scrolling, endless autoplay, certain push notifications, and reward mechanisms. Additional features such as default safety settings and preventing undesired contact from strangers must also be implemented into the platforms.

Specific obligations to be placed on AI companions and general conversational chatbots relate to ensuring that these systems are designed so minors are not exposed to features likely to create emotional dependencies. The prevention of harmful interactions and carrying out testing and post-market monitoring are also likely to be among the new obligations placed on these platforms and programs. Additionally, minors will need to be given the opportunity to opt out of these AI companions and conversational chatbots where they are deployed as part of an online social networking service, a video-sharing platform service or an online game, and they must not be automatically activated.

App stores will also need to implement an age rating system and ensure minors are prevented from accessing software applications that are not age-appropriate. Platforms that are designated as a “Very Large Online Platform (VLOP)” under the EU Digital Services Act will also have additional monitoring obligations under the proposed safety by design provisions.

Pillar Three – Age Assurance

Where providers within the scope of the EU KIDS Act are required to implement age assurance solutions, those solutions will need to have a high level of accuracy, reliability, robustness, non-intrusiveness, privacy and non-discrimination. Specific rules about data protection in age assurance are also covered in the proposal.

Importantly, self-declaration will not be sufficient. 

Virtual services and application stores must use strict age assurance tools to verify the age of users. The proposal includes a “privacy-preserving” verification that simply monitors if a user meets the age threshold without retaining any user documents or personal data. Existing accounts may automatically be checked via credit card details or account creation dates to establish user age.

Additionally, the proposal would see specific provisions made to ensure Member States take necessary steps to ensure the availability of different means of obtaining a proof of age attestation, verifying the minimum age and making available at least one age verification solution. 

Pillar Four – Burden of Proof and Enforcement Mechanisms

Regulators will no longer be required to prove harm under the proposed new legislation; rather, large online platforms must proactively prove that the services they provide are “safe by design” and meet the requirements imposed under the EU KIDS Act. These providers must submit compliance plans to the European Commission, or other independent auditor, who will be empowered to request that corrective measures be implemented when required.

The enforcement mechanisms included in the proposed EU KIDS Act build on those in the Digital Services Act and the EU AI Act.

II. Incoming Danish Legislation – National Minimum Age for Social Media Services

Separately, the Danish government is moving forward with its proposals to introduce a national minimum age of 15 to access specific social media services, a legal requirement that is intended to operate independently of any EU legislation. Formal introduction of the bill is expected in the early stages of 2027 with entry into force anticipated on 1 July 2027.

The proposal does not apply to all social media platforms but aims to restrict very large social media platforms that are designated as a VLOP under the EU Digital Services Act. The onus will be on the platforms to create effective age-assurance mechanisms to protect the interests of minors.

This draft bill more closely resembles previous legislation implemented in Australia, rather than the proposed EU KIDS Act. However, the Danish proposal does not go as far as the Australian legislation in blanket banning all social media.

As the Danish proposal would likely come into effect ahead of the EU KIDS Act it could be a first look at how some of the social media restrictions on minors could work within the EU.

III. Australia’s Online Safety Act and Blanket Ban on Social Media for Under 16s

In December 2025, Australia introduced the world’s first blanket ban on social media for minors. Unlike the tiered approach proposed in the EU KIDS Act, the Australian legislation acts as a total ban on children under 16 having access to and accounts on age-restricted social media platforms.

Under the Australian laws, the onus is placed on the platforms, not on the children or parents, to ensure compliance. The platforms are allowed to use technology to obtain age estimations but are restricted from requiring users to submit government identification in order to complete age-assurance checks. Enforcement of the Australian laws is carried out by the Australian eSafety Commissioner who actively and continuously monitors compliance.

Reports on the overall results and impact of the Australian blanket ban appear to vary significantly, with some hailing it a success and others casting doubt over its efficacy. Over 4.7 million accounts were removed from platforms on the basis that those accounts belonged to Australian users under 16 years old, yet it is estimated that roughly 70% of Australian teens who had social media accounts before the ban have subsequently found workarounds to counteract the ban.

The eSafety Commission has reported no discernible drop in reports of online harm, such as cyberbullying and image-based abuse, from under-16s following the implementation of the legislative ban on social media accounts. Thus, while Apple’s Tim Cook has reportedly touted the Australian social media ban as “world-leading”, the data does not necessarily show that the legislation has been successful implemented as intended.

When considering whether the EU has tried to learn from the Australian experience, we can see some stark differences. Not only is there a fundamental difference in approach (a blanket ban in Australia, which arguably has not worked, versus a tiered approach in the EU), but the breadth of technology affected is also markedly different (social media accounts only in Australia, compared to the EU’s much broader scope, which includes chatbots, app stores and gaming).

It does, therefore, seem that some lessons have been learnt from nearly 12 months of experience with the Australian approach. The EU KIDS Act seems to be attempting to address the root of the issue by requiring platforms to fundamentally redesign the services they offer with the safety of minors at the centre of their design, rather than simply prohibiting minors from accessing addictive platforms until a later age.

Whether the EU’s measures will be any more effective than a blanket ban is yet to be seen. One unavoidable hurdle that all legislation aimed at protecting the safety of minors online faces is the challenge of implementing effective age verification at scale without infringing users’ rights to privacy.

IV. Status of the EU KIDS Act and Next Steps

The proposed EU KIDS Act is still subject to approval from the European Parliament and Council with adoption unlikely to occur prior to 2028. It is also expected that there will be a grace period following adoption, during which affected services will be required to put in place measures to ensure they are fully compliant with the new requirements.

Should you wish to learn more about the EU KIDS Act, the Danish proposal for a national minimum age for social media services or the Australian social media ban, please reach out to nataliecoulton@paulhastings.com.