News

The EU KIDS Act Proposes 15 as the Minimum Age for Independent Social Media Accounts

Moca Network
September 18, 2026

The EU KIDS Act is a proposed EU regulation, adopted by the European Commission on 17 September 2026, that would set 15 as the EU-wide minimum age for creating an independent social media account, allow guardian-supervised accounts from 13, and require platforms to gate access with certified age verification rather than self-declared age. Its full name is "EU Keeping Internet Digital Spaces Accountable and Trustworthy". The proposal now goes to the European Parliament and the Council.

The Commission's own explainer notes that most of the law is about how services are built: platforms must show they are safe by design.

Key takeaways

  • The Commission adopted the proposal on 17 September 2026. It would take the form of a regulation, applying directly in every Member State.
  • Under 13: no social media accounts. 13 to under 15: limited accounts set up by a guardian, with parental tools always on and a daily limit of at most one hour. From 15: independent accounts on services that meet the safety requirements.
  • Self-declared age is not enough. Access must be gated by certified age verification, and every Member State must offer at least one free way to prove age.
  • Within six months of the rules applying, platforms must check whether existing account holders are under 15.
  • Fines can reach 6% of total worldwide annual turnover.

What the European Commission proposed

The proposal was published on the Commission's digital strategy site as a legislative proposal for a regulation. It aims to protect minors from risky digital services and artificial intelligence systems, and to replace diverging national rules with one EU-wide age threshold for autonomous account creation on social networking and video-sharing platforms.

The Commission's reasoning, set out in its KIDS Act explainer, is that the internet does not stop at borders, so a single regulation avoids a patchwork of national laws. Several EU countries had been moving on their own minimum ages, a trend we covered in our overview of under-16 social media rules.

Scope goes well beyond social networks. The explainer lists social networking and video-sharing platforms, online games, AI chatbots, AI companions and app stores. The Commission's press release describes the safety obligations as applying to services that offer these functionalities to minors.

The requirements at a glance

AreaWhat the proposal requires
Under 13No social media accounts. Parents may allow limited access to child-specific video services through their own account, with autoplay off and a one-hour daily limit
13 to under 15A guardian can set up a limited account, with parental tools always on, parental approval of contacts and a daily time limit of at most one hour
From 15Independent accounts on services that meet the safety requirements
Age checksSelf-declared age is explicitly not enough; access is gated by certified age verification from solutions independent of the platforms
Verification methodsA free EU age verification app and, in time, the European Digital Identity Wallet; every Member State must offer at least one free way to prove age
Privacy of checks"Zero knowledge proof" technology that cannot identify, locate, track or profile anyone; platforms do not see identity documents
Existing accountsWithin six months of the rules applying, platforms must check whether holders are under 15 and disable accounts of those who are, or whose age cannot be established
Addictive designNo endless autoplay or infinite scrolling, no notifications unrelated to user actions, no streak mechanics or rewards for posting to mass audiences
Contact and defaultsContact from strangers needs prior approval, content visible only to approved contacts, tracking-based personalisation off by default, no livestreaming by default
AI chatbots and companionsMay not simulate human relationships in ways likely to create emotional dependency
App storesMust age-rate every app, including video games, with a published methodology, and stop children accessing or buying apps inappropriate for their age
EnforcementThe Commission supervises the most widely used platforms and AI chatbots (45 million or more monthly EU users); Digital Services Coordinators and national market surveillance authorities cover other services; national authorities supervise video games that are not online platforms
PenaltiesFines of up to 6% of total worldwide annual turnover; for the largest platforms, preliminary findings within 30 days and a final decision within 90 days

Adults are mostly not asked to re-verify. According to the explainer, where a provider already has an age estimate built from multiple signals, such as account creation date or credit card details, most existing adult users face no new verification step.

Existing accounts are in scope. The six-month window for existing users is the operationally heavy part. It mirrors a pattern we described in our piece on retroactive age verification of existing accounts: the backlog, not new sign-ups, is where most of the effort lands.

A constructive step for children's safety online

We welcome the proposal. A single EU threshold gives platforms, parents and children one clear rule instead of several conflicting ones, and the insistence that age checks reveal nothing beyond the answer reflects where privacy-preserving verification has been heading for some time.

Reversing the burden of proof is also sensible. Very large platforms must submit compliance plans checked by independent auditors, at their own expense, which puts responsibility where the knowledge sits.

Like any control, age assurance will need to be continually reviewed and recalibrated as technology and fraud risks evolve. Generative tools make it easier to fake images and documents, and certification gives regulators a lever for that recalibration.

Where verifiable credentials fit

The KIDS Act names its own methods for proving age in the EU: the free EU age verification app, the European Digital Identity Wallet in time, and at least one free national option per Member State. Those stay exactly where the proposal puts them.

AIR Identity, built by Moca Network, is not an integration with the EU Digital Identity Wallet or the EU age verification app, and it is not a substitute for either. The point we would make is a broader one. The principle behind the proposal, attribute-only checks where a platform learns a yes or no answer and nothing else, is not limited to the EU wallet. It applies to many other facts platforms ask about, and to operators working outside the EU or alongside its schemes.

AIR Identity works from two sides. Trusted issuers, such as banks, fintechs, platforms and licensed KYC partners, issue reusable, user-held credentials from checks they have already run: residency, passed KYC, account tenure, membership tier or being a unique person. Businesses then request proof of just the fact they need and receive a yes or no answer through a zero-knowledge proof, with the user's consent and minimal data custody. We explain the underlying mechanism in our guide to zero-knowledge proofs for KYC and GDPR.

RequirementWhat stays with existing controlsWhat a credential layer can add
Certified age verification for EU usersThe certified methods named in the proposal (EU app, EU wallet in time, national free options)Nothing that replaces them; the age check stays within the EU framework
Guardian-supervised accounts from 13Parental tools, contact approval and time limits built by the platformNo change to guardian controls, which remain the platform's responsibility
Checks on existing accountsAge signals and certified verification as the proposal describesFor facts outside the age rule, such as residency or account tenure, a reusable credential can answer without collecting new documents
Safety by design and stranger contactPlatform design, moderation and default settingsWhere a service limits features to a known group, such as members of a club or holders of a professional licence, a credential can confirm that attribute alone
Services and markets outside the EU schemeLocal rules and existing KYC or document checksReusable credentials from issuers that have already run a check, for operators serving several markets

For platforms, the practical benefit sits on the acquisition side. A service that needs to confirm a fact before onboarding someone can reach users who already hold the credentials it requires, paying only when a verification comes back, instead of paying to acquire sign-ups that later fail a check. None of this makes any KIDS Act requirement unnecessary. Each operator remains responsible for meeting its own obligations under the regulation.

What happens next

The proposal now goes to the European Parliament and the Council for examination and adoption. The press release calls for swift passage. Until both institutions agree a final text, the thresholds and deadlines described here may change.

Our read

The KIDS Act is a welcome proposal. It sets a clear age rule and keeps identity documents away from platforms. The detail that matters most for verification teams is the combination of certified checks with zero-knowledge proofs: the regulator is asking for an answer, not a file. We expect that approach to spread well beyond age.

Frequently asked questions

What is the EU KIDS Act?

The EU KIDS Act (EU Keeping Internet Digital Spaces Accountable and Trustworthy) is a proposed regulation adopted by the European Commission on 17 September 2026. It would set 15 as the minimum age for an independent social media account, allow supervised accounts from 13, and allow fines of up to 6% of worldwide annual turnover.

What is the minimum age for social media in the EU under the KIDS Act?

Under the proposal, children under 13 cannot have social media accounts. From 13 to under 15, a guardian can set up a limited account with parental tools always on and a daily limit of at most one hour. From 15, users can hold independent accounts on services that meet the safety requirements.

How will age verification work under the EU KIDS Act?

Self-declared age is not enough. Access must be gated by certified age verification from solutions independent of the platforms, such as a free EU age verification app and, in time, the European Digital Identity Wallet. Every Member State must offer at least one free method.

What happens to existing social media accounts under the KIDS Act?

Within six months of the rules applying, platforms must check whether existing account holders are under 15 and disable the accounts of those who are, or whose age cannot be established.

When will the EU KIDS Act apply?

It is not yet law. The Commission adopted the proposal on 17 September 2026 and it now goes to the European Parliament and the Council for examination and adoption. The application date and deadlines will depend on the final text agreed by both institutions.

Want to onboard users who can prove the facts you need, with minimal data custody? See how AIR Identity works, or partner with us to grow your business.

Sources

Partner with AIR

AIR is one integration suite for identity, money and loyalty. AIR Identity lets trusted issuers issue verifiable credentials and businesses verify them, so acquisition starts with users who already qualify, with minimal data custody. AIR Money embeds compliant global financial infrastructure, opening new markets without building new rails. AIR Loyalty gives brands a programmable, stable-value points engine that keeps users coming back.

Partner with us to grow your business.

AIR is built by Moca Network, the identity network of Animoca Brands.

Stay updated on AIR launches
Product updates, partner launches, and research across digital identity, fintech, and loyalty. Unsubscribe anytime.
By subscribing, you agree to our Privacy Policy and consent to receive updates.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
In this article
Blog

Read more articles

Lorem ipsum dolor sit amet, consectetur adipiscing elit.
View all
News
Three Turkish Regulators Now Put the NFC Chip at the Centre of Remote Onboarding
MASAK, the CMB and the CBRT now anchor remote onboarding in Türkiye to NFC chip reading, and open it to foreign nationals holding ICAO 9303 passports.
News
US Regulators Confirm Banks Can Accept Mobile Driver's Licences When Opening Accounts
FinCEN and four US banking agencies say a government-issued mobile driver's licence can serve as documentary ID under the CIP Rule. What the 2026 FAQs require.
News
South Korea's Amended Privacy Law Lets the Regulator Fine Serious Breaches up to 10% of Total Revenue
South Korea's amended privacy law took effect on 11 September 2026: fines up to 10% of total revenue, CEO accountability and 72-hour notice of possible leaks.