Protecting children without checking everyone
The EU Kids Act goes after real harm to our children. But to get there, it would require proof of age before anyone opens an account on the largest platforms. But can't we protect children by changing the services instead?
This is an editorial opinion piece. The argument is presented by the author. Sources in notes.
Two citizens' initiatives
A European Citizens' Initiative is the one tool the EU treaties give ordinary people to put a law on the Commission's desk: collect a million verified signatures across at least seven member states, and the Commission must give a formal answer. In June it answered one signed by more than 1.29 million people and validated in 24 member states.1 The initiative, "Stop Destroying Videogames", came from the gamers' campaign Stop Killing Games. It asked that games people have paid for keep working when the publisher switches off its servers. The Commission replied that it "cannot propose a legal obligation to keep video games playable", citing among other things publishers' intellectual property rights, and offered instead to work with the industry on a voluntary code of conduct.2
The same campaigners have since registered a second initiative, "Stop Killing The Internet: No Digital ID & No Age Verification", asking that digital identity and age checks stay "voluntary, privacy-preserving and non-discriminatory".3 In September the Commission proposed the EU Kids Act, which brings online games into scope alongside social networks, video platforms, app stores, operating systems and AI chatbots.4, 5 A hobby has turned into a key EU policy question that every European has reason to ask: what does it cost to make the internet safer for children, and who pays?
The monsters, by name
Safer from what, exactly? "Protecting children online" can mean almost anything, so it helps to be specific. Researchers who study children's online lives sort the risks into four groups, the "4Cs": content, contact, conduct and contract.6
Content is what children see. In the 2026 wave of EU Kids Online, a survey of 28,465 children aged 10 to 16 in 19 countries, 40 percent reported seeing gory or violent images, 39 percent content about ways to become very thin, and 37 percent content about hurting themselves.7 Recommendation systems can turn one search into an endless stream of more of the same; the Commission calls these "rabbit holes".8
Contact is who reaches them: strangers, and in the worst cases adults who groom children for abuse or radicalisation. The Commission's answer is "prohibiting unsolicited contact from strangers".9
Conduct is what other people, often other children, do to them. Three in ten children in the same survey meet hateful messages at least once a month.7
Contract is what the business model does to them. Loot boxes are digital "mystery boxes" bought with real money, whose contents the player sees only after paying.10 Premium in-game currencies blur what things cost, in a market where 84 percent of children aged 11 to 14 play video games regularly.11 Profiling turns a child's behaviour into advertising data.
One monster runs through all four: design built to hold attention. Autoplay, infinite scroll, "streaks" that punish a missed day, and notifications that pull a child back are the Commission's own examples.8 Among the adolescents surveyed for the World Health Organization in Europe, problematic social media use rose from 7 percent in 2018 to 11 percent in 2022.12 The newest arrival is the AI companion, a chatbot built to feel like a friend; the proposal bans designs "likely to create emotional dependency".8 Italy's data protection authority fined the maker of one such app, Replika, €5 million in 2025, finding among other things that it had no age check at all.13
Nearly all of these harms are properties of the service: what it recommends, whom it allows to send messages, how it charges, how it holds attention. Fixing most of them does not require knowing who the user is. Blocking strangers from contacting children is the clearest exception.
What the Act would do
The Kids Act is still a proposal; Parliament and the member states will amend it before it becomes law.4
Its core rule is short. Social networks and video-sharing platforms "shall not allow minors below the age of 15 to create" their own account. Between 13 and 15, a parent or guardian can hold a limited account on the child's behalf.14
To enforce that rule, the platform has to know your age, and ticking a box saying you are old enough will no longer count.15 The proposal routes the check through an EU proof-of-age attestation from a certified provider,16 and every member state must offer at least one free way to get one. The EU digital identity wallet, the phone app every member state must offer its residents under the European digital identity rules, qualifies.17
An attestation is a digitally signed statement, in this case "this person is over 15", issued by a party that has already checked who you are, for example against your national ID. Under the design the Commission published in July 2025, the platform receives a yes or a no and nothing else: no name, no birth date.18 The proposal requires the check to use a zero-knowledge proof, a cryptographic method that proves a statement without revealing the data behind it.19 What the issuer may log about each check is left to later implementing rules.20
Figure 1. Who sees what
| What | Issuer | Platform |
|---|---|---|
| Your name | Knows | Does not learn |
| Your date of birth | Knows | Does not learn |
| Over 15: yes or no | Knows | Learns |
| That you opened an account, and where | Not yet decided | Knows |
knows or learns does not learn open: left to implementing rules
What each party knows after an age check at account creation, as proposed. The zero-knowledge design keeps the platform's share to one answer; what the issuer may record is not yet settled. Simplified; based on the Kids Act proposal, COM(2026) 681, and the Commission's 2025 age-verification blueprint.
What the Act does not do matters as much. There is no daily check, and existing accounts whose holders are already established as adults "with high confidence" are left alone.21 The weight falls on new accounts: every new account, at any age, starts from the assumption that its holder is a child. In the words of European Digital Rights (EDRi), the Brussels-based network of digital rights organisations, services "would have to treat users as children by default unless they prove their age."22 Parents opening a guardian account must also prove they are parents.23
The case for it, at its strongest
The harms are real, and the Act deserves its best defence before any criticism. The Commission's impact assessment rests on an observation about development: childhood and early adolescence are stages in which "cognitive control, emotional regulation and resistance to social pressure remain under development".24 A special panel of more than 60 experts, co-chaired by the child psychiatrist Jörg Fegert and the epidemiologist Maria Melchior, advised the Commission this summer.25 The proposal followed a call for evidence in 2024 and a public consultation in 2025, with several hundred contributions.26 In the Commission's survey work, 92 percent of respondents called stronger protection of children online a top priority.27
Child-rights organisations broadly welcome it. 5Rights, which campaigns for children's rights online, called the proposal "a solid basis", while asking that it apply equally to all platforms.28 Eurochild, the European network of children's rights organisations, wrote that the debate "has moved beyond the polarising choice between a 'ban' and 'no ban'".29
The engineering deserves credit too. The UK lets platforms and their vendors check age with photo ID, facial estimation or credit cards.30 US states such as Utah push the check into the app store, and China builds it into the device.31 Of those models, Europe's yes-or-no proof reveals the least to the service that receives it. If an age gate must exist, this is the one I would choose.
Where the case is thin
Three gaps sit under the obligation. The first is the age itself. The Commission's own expert panel recommended EU-wide restrictions "below age 13".32 The Act sets 15 for an own account. The number appeared first in the President's State of the Union speech the day before the proposal: "No social media under the age of 13. No personal account under the age of 15."33 Neither the proposal nor its impact assessment, as far as the published analyses show, gives a reason for moving from the panel's 13 to 15.34
The second is sequence. In August 2026 the Commission ordered an external study of the impact of age assurance, due in the fourth quarter.35 The obligation to check was proposed before the study of what checking does was finished.
The third is causation. Whether social media harms young people's mental health is a live scientific dispute. In 2019 the UK's four Chief Medical Officers found that the research "does not present evidence of a causal relationship between screen-based activities and mental health problems".36
This does not mean the harm is imaginary. In my view, the evidence supports caution and changes to how services are designed. And basic common sense tells us that we are shaped by what we read, consume, witness and participate in, particularly in the formative years of our youth. However, the evidence does not establish that an identity check at 15 is the remedy.
Sovereignty, pointed inward
nupath.eu, the publication you are reading, uses "sovereignty" in a narrow sense: it means control and jurisdiction over the systems a society depends on. Individual freedom sits deliberately outside that definition. My premise here is that the frame exists to serve something: sovereignty is a means, and the end is a democratic society of free people.
The European digital sovereignty agenda was built to protect from the outside, against dependence on foreign cloud, foreign chips and foreign governments' access to European data. By that outward test, the Kids Act scores well. The credential that proves your age comes from a certified European source; Apple and Google do not issue it, even though their app stores and operating systems must apply the check (see our deep dive It's time to pick up the smartphone).37 In our map of the world's technology blocs, Europe is the region that put the age layer in the state's wallet (Tech blocs, part one).38
That is what raises the inward question. The most sovereign identity layer Europe has built so far is pointed towards the people who live here. Zero-knowledge proofs limit what the platform learns. They do not change the fact that a certified credential becomes a precondition for a new account on large parts of the internet, which leaves out anyone without a suitable phone or ID, and puts a compliance cost on small services that the largest companies absorb easily.39 EDRi's Simeon de Brouwer put the first point in one line: "We are turning smartphones and identity documents into prerequisites for accessing online spaces and exercising fundamental rights."40 Stop Killing Games raises a version of the second point for games, warning that community-run servers could not carry the load; lawyers dispute that reading.41
My prediction is that infrastructure outlives the intentions it was built with: a credential gate built for social media will be cheap to extend to the next category of service, and each extension will always come with a good reason, like children, security or health. The child-abuse file shows how that reason works, with a different instrument: the temporary rule that lets messaging services scan for abuse material voluntarily now runs to 2028, and the permanent regulation, known as chat control, is still being negotiated.42 In both files, the protection of children is the reason given for infrastructure that reaches everyone.
Regulate the machine, not the person
There is a better tool, and the Act already contains part of it. The features that the panel worried about are design choices: endless feeds, autoplay, notifications at night, recommendation systems tuned to keep a child scrolling. The panel asked for them to be switched off by default, and is reported to have said that "the burden of proof needs to be on providers, not regulators, parents and children."43 The Act adds safety-by-design duties of its own.44
None of this is a new idea. "Make safe products" is the foundation modern European consumer protection is built on. Food law lets regulators act when "the possibility of harmful effects on health is identified but scientific uncertainty persists".45 Toys must be safe before they reach the shelf, and a toy with small parts carries the warning "Not suitable for children under 36 months".46 Nobody checks a parent's ID at the toy shop. The General Product Safety Regulation, which has applied since December 2024, asks makers to weigh the risk for "vulnerable consumers such as children".47 Even the AI Act was built on the same product-safety machinery: a high-risk system must meet its requirements before it is placed on the market.48 Games already carry the European PEGI age labels, used in more than 35 countries since 2003.49 Why should online games and platforms be the one product category where safety is delivered by checking the customer instead of the product?
The analogy has a limit, and it points the same way. Europe does check age where a product is harmful by nature: tobacco sold at a distance must pass an age check at the moment of sale,50 and in June the EU's Court of Justice confirmed that member states can require age checks on foreign pornography sites.51 That gives a principled line. A feature that works like gambling, such as a paid loot box, can be treated like gambling: Belgium's gaming regulator ruled in 2018 that paid loot boxes fall under its gambling law, even if enforcement has since proved hard.52 Everything else should be made safe, like a toy, and labelled for age, as games already are. A label informs parents without identifying anyone.
This is not a case for leaving the market to sort itself out, as some would prefer. It is a case for regulating, but aiming at the product instead of the person using it. Nor is this a case for raising children in cotton wool. A safe playground still has climbing frames; it just has no rusty nails. Children learn to cope by meeting real challenges, and an age gate does not teach that, it postpones the encounter.
Design duties have a weakness, and it should be named: a default that applies only to minors still needs to know who is a minor. The way out is to make the safe setting the default for everyone. Profiling-based feeds, autoplay and night-time notifications start switched off, and any adult who wants them switches them on. The European Parliament asked for exactly this in 2023, a "right not to be disturbed" with attention-seeking features off by design,53 and the Digital Fairness Act, the consumer-protection package expected before the end of the year, is meant to address addictive design for all users.54 Where a specific feature carries a specific risk, a narrow age check at that point can be argued for, as with gambling. A credential at the front door for every new account is a different thing. Moritz Katzner, who directs European affairs for the second citizens' initiative, put it as an image: "If a town hall has problems, you address the problems inside it. You do not close the town hall or demand identity papers from everybody at the entrance."55
Default-safe design is not free. It cuts into business models built on engagement and in-game spending, and I expect the companies that depend on them to resist design duties harder than an age gate, which leaves their products unchanged for everyone who passes it.
Default-safe design constrains the companies whose features are suspected of causing the harm, protects a 14-year-old and a 40-year-old at once, and asks nobody for papers. It needs the same evidence test, but if it proves unnecessary, users have lost nothing. EDRi put the alternative with some edge: under an age gate, it is "as if these services, practices and functionalities will magically cease to be harmful on someone's 18th birthday."56 They don't. The World Health Organization has recognised gaming disorder as a condition since 2022,57 and we all know stories about adults who end up spending excessive time and money on digital services; some of us have watched adults lose their grip on life through excessive online gaming.
The strongest version of the gamers' case is not about servers. It is in their second initiative, which asks that digital identity stay "voluntary, privacy-preserving, decentralised and usable without forcing citizens into one state-backed or Big-Tech-mediated wallet", and that no one be required to identify themselves to reach lawful content "unless strictly necessary, proportionate, and provided by law".3 The Kids Act already meets part of that demand: its proof of age is built to reveal nothing else. The open questions are the two words it does not yet settle: voluntary, and decentralised.
Who gets heard
Over the months the Kids Act took shape, 1.29 million validated signatures for game preservation were answered with a voluntary code of conduct.2 The two cases differ, but they sit awkwardly together: when citizens ask the Commission to bind the game companies, they get a voluntary code; when the Commission wants every new user to prove their age, it proposes a law. A requirement that reaches citizens deserves at least the caution shown to one that would bind companies. Parliament will now decide much of this, and it may push further rather than back: in November 2025 it called for a default digital age limit of 16.58
The price of a safer internet
In my view, Europe's sovereignty project was never meant as independence for its own sake. The democratic society is what is being protected; sovereignty is the means to protect it. A continent that becomes independent of foreign platforms while building an identity check into the everyday use of its own internet would, by that measure, have failed on its own terms.
At times it seems that policy circles work on the assumption that the only way to affect something is to tighten control, even when that carries an echo of virtue signalling ("at least we are doing something").
The conditions I would accept: wait for the age-assurance study the Commission has already ordered before making the check an obligation; enforce default-safe design first and measure what it achieves; keep age checks for specific, named risks and voluntary everywhere else; add a sunset clause and a review with the power to end the regime, in addition to the review the proposal already plans;59 and build nothing that cannot be switched off once its reason is gone. Even that is risky: temporary solutions tend to become permanent out of sheer convenience. And in the current European political climate, it is easy to tighten laws and much harder to loosen them.
Notes
- European Commission replies to 'Stop Destroying Videogames' initiative (European Citizens' Initiative, 16 Jun 2026)
- Commission replies to the European Citizens' Initiative 'Stop Destroying Videogames' (European Commission, IP/26/1369, 16 Jun 2026)
- Commission concludes eligibility checks for two European citizens' initiatives (European Citizens' Initiative, 22 Jul 2026)
- Proposal for a Regulation on keeping internet digital spaces accountable and trustworthy (EU KIDS Act), COM(2026) 681 (European Commission, 17 Sep 2026)
- The scope of the proposed KIDS Act (Pinsent Masons, Sep 2026)
- What are online risks? (CO:RE, 8 Dec 2022), based on Sonia Livingstone and Mariya Stoilova, The 4Cs: Classifying Online Risk to Children (CO:RE, 2021)
- EU Kids Online 2026: comparative findings (EU Kids Online, LSE, 2026)
- Kids Act explained (European Commission, updated 2 Oct 2026)
- EU Kids Act: helping children navigate a safer online world (European Commission, 17 Sep 2026)
- Insert Coin: How the gaming industry exploits consumers using loot boxes (Norwegian Consumer Council, 2022)
- Game Over: a legal assessment of premium in-game currencies (BEUC, 12 Sep 2024)
- Teens, screens and mental health (WHO Regional Office for Europe, 25 Sep 2024)
- AI: the Italian Supervisory Authority fines company behind chatbot Replika (European Data Protection Board, 2025)
- Proposal for a Regulation on keeping internet digital spaces accountable and trustworthy (EU KIDS Act), COM(2026) 681, Art. 6 (European Commission, 17 Sep 2026)
- Proposal for a Regulation on keeping internet digital spaces accountable and trustworthy (EU KIDS Act), COM(2026) 681, Art. 27 (European Commission, 17 Sep 2026)
- Proposal for a Regulation on keeping internet digital spaces accountable and trustworthy (EU KIDS Act), COM(2026) 681, Art. 29(2) (European Commission, 17 Sep 2026); EU KIDS Act: age assurance (Bratby Law, Sep 2026)
- Proposal for a Regulation on keeping internet digital spaces accountable and trustworthy (EU KIDS Act), COM(2026) 681, Art. 31 (European Commission, 17 Sep 2026)
- Commission makes available age-verification blueprint (European Commission, 14 Jul 2025)
- Proposal for a Regulation on keeping internet digital spaces accountable and trustworthy (EU KIDS Act), COM(2026) 681, Art. 28(3) (European Commission, 17 Sep 2026); EU KIDS Act: age assurance (Bratby Law, Sep 2026)
- Proposal for a Regulation on keeping internet digital spaces accountable and trustworthy (EU KIDS Act), COM(2026) 681, Art. 28 (European Commission, 17 Sep 2026)
- Proposal for a Regulation on keeping internet digital spaces accountable and trustworthy (EU KIDS Act), COM(2026) 681, Art. 32 (European Commission, 17 Sep 2026)
- The KIDS Act will make the internet less safe (EDRi, 30 Sep 2026)
- The KIDS Act will make the internet less safe (EDRi, 30 Sep 2026)
- Impact assessment accompanying the EU KIDS Act, SWD(2026) 681 (European Commission, 17 Sep 2026)
- Impact assessment accompanying the EU KIDS Act, SWD(2026) 681 (European Commission, 17 Sep 2026); Proposal for a Regulation on keeping internet digital spaces accountable and trustworthy (EU KIDS Act), COM(2026) 681, recital 2 (European Commission, 17 Sep 2026)
- Impact assessment accompanying the EU KIDS Act, SWD(2026) 681 (European Commission, 17 Sep 2026)
- Impact assessment accompanying the EU KIDS Act, SWD(2026) 681 (European Commission, 17 Sep 2026)
- New EU Kids Act can put paid to the tech exploitation of children, but must apply equally to all platforms (5Rights Foundation, 17 Sep 2026)
- State of the Union address 2026: where are children's rights? (Eurochild, 17 Sep 2026)
- Age checks to protect children online (Ofcom, 2025)
- App Store Accountability Act (Utah Legislature, in force 7 May 2025); Guidelines for the construction of minor mode on the mobile internet (Cyberspace Administration of China, 15 Nov 2024)
- Impact assessment accompanying the EU KIDS Act, SWD(2026) 681 (European Commission, 17 Sep 2026)
- 2026 State of the Union address (European Commission, 16 Sep 2026)
- European Commission proposes EU KIDS Act (Davis Wright Tremaine, Sep 2026)
- Impact assessment accompanying the EU KIDS Act, SWD(2026) 681 (European Commission, 17 Sep 2026)
- Screen-based activities and children and young people's mental health and psychosocial wellbeing: a systematic map of reviews (UK Chief Medical Officers, 7 Feb 2019)
- Proposal for a Regulation on keeping internet digital spaces accountable and trustworthy (EU KIDS Act), COM(2026) 681, Arts. 16, 29 and 31 (European Commission, 17 Sep 2026); The scope of the proposed KIDS Act (Pinsent Masons, Sep 2026)
- Tech blocs, part one (nupath.eu, 24 Sep 2026)
- EU Kids Act won't keep the internet accountable and trustworthy (EFF, Christoph Schmon, 21 Sep 2026)
- The EU wants to protect children online. What about everyone else? (Euronews, 24 Sep 2026)
- Stop Killing Games on the EU Kids Act (Stop Killing Games, Mastodon, 20 Sep 2026); Advocacy group Stop Killing Games sounds alarm on EU Kids Act (Kotaku, 1 Oct 2026); Biggest threat yet: new EU rules could severely restrict online gaming (Notebookcheck, 1 Oct 2026)
- Fighting child sexual abuse online: interim measure protecting children now reinstated (Council of the EU, 23 Jul 2026); Chat control tracker (Brussels Record, 4 Oct 2026)
- Europe wants platforms to prove they are safe for children (Tech Policy Press, Jul 2026)
- The EU KIDS Act: Europe moves online child safety beyond social media bans (Freshfields, Sep 2026)
- General Food Law, Regulation (EC) No 178/2002, Art. 7 (2002)
- Toy Safety Directive 2009/48/EC, Annex V (2009)
- General Product Safety Regulation (EU) 2023/988 (2023, applies from 13 Dec 2024)
- AI Act, Regulation (EU) 2024/1689, recital 46 (2024)
- The PEGI organisation (PEGI)
- Tobacco Products Directive 2014/40/EU (2014, Art. 18)
- EU court clarifies age verification rules for pornographic websites (Digital Watch, June 2026), on case C-188/24
- Belgium's gambling commission rules against loot boxes (European Gaming, 26 Apr 2018); What are loot boxes? (Belgian Gaming Commission); Breaking Ban: Belgium's ineffective gambling law regulation of video game loot boxes (Collabra: Psychology, 2023)
- Resolution on addictive design of online services and consumer protection in the EU single market (European Parliament, 12 Dec 2023)
- Digital Fairness Act (European Parliament Legislative Train)
- One million signatures sought to stop mandatory online ID and age checks (EU Perspectives, Joana Soares, 7 Sep 2026)
- The KIDS Act will make the internet less safe (EDRi, 30 Sep 2026)
- Gaming disorder: frequently asked questions (World Health Organization)
- Resolution on the protection of minors online (European Parliament, 26 Nov 2025)
- Proposal for a Regulation on keeping internet digital spaces accountable and trustworthy (EU KIDS Act), COM(2026) 681, Art. 41 (European Commission, 17 Sep 2026)
Subscribe to our newsletter to get the latest updates and news