Current status: European Commission proposal — not adopted EU law

Design and defaults

Safety by design

The proposal would require child-safe design by default across several service categories, then add a more detailed suite for social networks and video-sharing platforms.

Articles 9–13 do not apply directly and indiscriminately to every service listed in Article 2.

Provider scope

General rule first, detailed rules second

Article 8 supplies the broad entry point. Later Articles name narrower groups or cross-apply selected protections.

Which safety-by-design provisions apply to which providers?
RuleDirect provider scopeImportant qualification
Article 8 general dutySocial networks, video-sharing services, online games, AI companions, general conversational chatbots and app storesNot operating systems. Child-safe defaults may be changed only after compliant age assurance establishes adulthood.
Articles 9–13 detailed suiteSocial networks and video-sharing servicesSelected parts are applied to AI by Article 14 and to games by Article 15.
Article 18 child agencySocial networks, video-sharing services, online games and the two AI categoriesDoes not name app stores or operating systems.
Article 19 reportingSocial networks, video-sharing services, video-gaming platforms and the two AI categoriesNames gaming platforms, not standalone video games.
Article 20 guardian toolsSocial networks, video-sharing services, online games and the two AI categoriesDoes not generally apply to app stores.

Article 8: the general safety-by-design duty

The named providers must ensure a high level of privacy, safety and security for minors whether or not their service can be used with an account. They must apply Chapter III’s requirements by default and may depart from them only after age assurance establishes that the person is an adult.

For AI companions or general conversational chatbots embedded in a social network or video-sharing service, Article 8(3) points to the AI-specific, age-access and general empowerment sections rather than applying every Chapter III section to the embedded AI functionality.

Compulsive or excessive use

Article 9 prohibits social-network and video-sharing providers from designing, organising or operating their services in a way intended—or reasonably foreseeable—to encourage compulsive or excessive use by minors.

The proposal identifies four classes of feature:

  • autoplay and uninterrupted content consumption without effective, regular moments for the child to decide whether to continue;
  • design that undermines stopping, including notifications unrelated to the child’s activity;
  • incentives or rewards for sharing or livestreaming content; and
  • incentives to return at set times or more often, including penalties or lost benefits.

Providers must also introduce effective time limits and interruptions designed to protect school time and core sleep hours.

“Infinite scrolling” is shorthand, not the legal test

The proposal does not simply name and ban one interface pattern. Its operative rule concerns foreseeable encouragement of compulsive or excessive use, including uninterrupted consumption without effective and regular stopping points.

Recommender systems

Article 10 requires covered social-network and video-sharing providers using recommenders to optimise for a high level of child privacy, safety and security. They must:

  • give primary weight to explicit user-stated preferences;
  • disable by default recommendations based on implicit engagement signals from the child’s behaviour;
  • avoid personal data about the child captured outside the service;
  • prevent recommendations that may pose a risk, including through repeated exposure; and
  • use evaluation metrics covering quality, safety and mental-health outcomes rather than exploiting attention or vulnerability.

Children must have prominent tools to change recommender parameters, delete previously identified preferences and choose at least one non-profiled recommendation option. The interface must not entice them back toward profiling.

Safe defaults and unavailable features

Article 11 requires covered social-network and video-sharing providers to turn off geolocation and tracking, microphone and camera access, account recommendations and contact synchronisation, and push notifications by default. Notifications must in any event protect core sleep and school time.

Specified defaults may be changed only where the minor is above 15, has been clearly informed and explicitly consents. Location and tracking must reset off after the session. Features presenting a safety, health or well-being risk must be unavailable to minors, including features that increase social comparison or disproportionately embellish or idealise a child’s image.

Contacts, groups, blocking and visibility

Article 12 would prevent unapproved direct contact, keep minors out of contact recommendations, require explicit agreement before group addition, and provide easy blocking without disclosing the blocker’s identity. Providers must guard against manipulation into accepting contact.

Account information and shared content must be hidden by default from people the child has not accepted and entirely unavailable to users without an account. Personal contact details must not be shared. Children need visibility controls, while other users must be prevented from downloading or screenshotting specified contact, location, account and shared information. Hosting livestreams must be off by default.

Economic transactions and virtual currency

Article 13 applies directly to social networks and video-sharing services. Before a child completes a transaction, the service must clearly identify it as economic and show the official-currency value of purchases made with purchasable virtual currency.

The service must not be designed in a way that can lead to excessive, impulsive or unwanted spending. The Article expressly includes exposing minors to variable reward systems within that prohibition.

This is not a universal direct prohibition for all online games. Game duties arise through Article 15 and Article 17’s code-of-conduct framework, not by automatically applying all of Article 13 to every game.

Agency, reporting and guardian tools

Article 18 requires understandable controls and information, immediate and durable feedback controls for content and prompts, and settings that can be changed temporarily and restored. Article 19 adds accessible child-friendly reporting, priority handling, redress information, authoritative support and risk warnings for its narrower provider group.

Article 20 requires the named providers to offer effective guardian tools for time, settings and reporting, while respecting the child’s privacy, agency and evolving capacities. Children must know when a guardian tool is active. See Parents & guardians.

Monitoring and future updates

Article 22 requires providers in Article 8 that are designated very large online platforms under the DSA to monitor, test and evaluate the effectiveness of their measures as part of the DSA risk assessment.

Article 25 would let the Commission update listed measures in Articles 9, 10, 11, 12, 14, 15 and 18 by delegated act in response to emerging risks. That power concerns specified measures and provider categories; it is not an open-ended power to rewrite every obligation.

For tailored applications, see AI chatbots & companions, online games and app stores. The compliance and enforcement guide explains Article 5 audits, regulators and penalty routes.

Sources and legal references

Primary sources used

EU KIDS Act proposal, COM(2026) 681 final

Articles 8–15, 18–20, 22 and 25.

DSA Guidelines on the protection of minors

Existing guidance and implementation context; not a substitute for the proposal’s operative rules.