Privacy

EU KIDS Act Proposal: Minors’ Implicit-Engagement Feeds Off by Default, Profiling Not Banned Outright

EU KIDS Act proposal, September 17: minors' feeds per the text. Off by default: feeds built on implicit engagement signals, such as time spent viewing and click-through rate. Required: a non-profiling option. Not allowed: personal data from outside the service.

The European Commission adopted its proposal for a Regulation on the protection of minors online on September 17, publishing it as COM(2026) 681 final. Commission President Ursula von der Leyen presented the EU KIDS Act at a press conference in Strasbourg the same day; in the Commission’s press release, she said the act is “reversing the burden of proof”. The 99-page text now goes to the European Parliament and the Council of the EU for negotiation, and it is a proposal: nothing in it takes effect until both bodies agree on a final version.

The Press Release Calls It a Ban. Article 10 Sets a Default.

The Commission’s press release compresses the proposal’s design rules into one line: providers would face “a ban on addictive features and profiling-based recommender feeds dragging minors into ‘rabbit holes’ of harmful content.” Article 10 of the proposal does something narrower, and the recital that explains it uses two standard engagement metrics as its examples.

For minors on social networking and video-sharing services, Article 10(2) would require providers to “disable by default the recommendation of information suggested by the recommender system based on implicit engagement-based signals from minors’ behaviour online”. A recital spells out what counts as an implicit engagement-based signal: data that infers preferences from activity, “such as time spent viewing content and click-through rates.” Recommendations built on signals such as how long a minor spent viewing content, or on click-through rates, would be disabled by default.

The same article would require recommenders to “give priority and primary weight to explicit user-stated preferences”, bar them from relying on “any personal data of minors captured from outside the service”, and require “at least one option of the recommender systems which is not based on profiling”. That non-profiling option is set out in Article 10(3), and the tools offering it “shall not be designed in a manner to entice minors into choosing the option based on profiling,” wording that presupposes a profiling-based option can still be offered alongside it.

What Is the EU KIDS Act?

The EU KIDS Act is the Commission’s September 17 proposal for a Regulation, COM(2026) 681 final, covering social networking and video-sharing services, app stores, online games, operating systems, AI companions and general conversational chatbots. On social networking and video-sharing services that meet any of the text’s risk conditions for users under 15, it would bar accounts for children under 13, allow providers to let guardians set up limited accounts for 13- and 14-year-olds with a daily cap of no more than one hour, and allow accounts of their own from 15. It is not in force: it needs agreement from the European Parliament and the Council, and Article 43 sets the general application date at entry into force plus six months, with the actual date left as a bracketed placeholder in the text.

Press Release vs. Article Text

The Commission’s summaries and the proposal’s articles do not always describe the same mechanism. Three of the four rows below show a gap; in the fourth, the text sets rules for every age assurance solution, not only the Commission’s app.

Topic The Commission’s press release/policy page says The proposal’s text says
Recommender feeds “a ban on addictive features and profiling-based recommender feeds” Art. 10(2): providers must “disable by default” recommendations built on implicit engagement signals; explicit preferences get “priority and primary weight”; a non-profiling option is required under Art. 10(3); profiling-based recommenders remain a listed risk condition under Art. 6
Existing accounts Providers “estimate the user’s age based on reasonable proxies (e.g. account creation date, credit card details)” Art. 32(1): providers “shall rely on an age verification solution”, with a derogation under Art. 32(2) where a provider can show “with a high degree of confidence” that the user has already reached the age threshold
New VLOP features Policy page: very large platforms “will have to submit a compliance plan to the Commission for new services, features or functionalities”; “These will be assessed within 30 days and can only be rolled out after positive opinion by the Commission” Art. 5 does not mention new services or features: a social networking or video-sharing service designated as a very large platform notifies a compliance plan within 4 months of its designation (within 30 days of the date of application if already designated); an independent auditor’s final report follows within two months of receipt of the plan; corrective measures follow if the Commission finds shortcomings; Art. 5(8) states that neither the report nor Commission action “shall constitute a finding of compliance”. No positive-opinion step appears in the published text.
Age assurance data Providers “can, for example, use the EU age verification app, which does not retain identity documents or biometric data” Art. 28(1): age assurance “shall not enable the identification of the recipient nor locate, track, target, advertise to or profile recipients for any purpose”; Art. 28(3): “Any age assurance measure shall be zero knowledge proof.”
See also  Matomo 5.8 Launches AI Chatbot Tracking: Dedicated Reports Separate Bot Traffic from Human Visits

One Condition Among Five, Not a Blanket Rule

A profiling-based recommender is not barred outright for minors as a class. It is one of the conditions in Article 6(1) that make a social networking or video-sharing service count as posing a risk to someone under 15, which is what triggers the account-age bar in the first place. The published list of conditions runs from (d) to (h): real-time transmission to an indeterminate number of recipients, including live streaming; contact with users outside a user’s pre-existing connections or subscriptions; “a recommender system which is based on profiling as defined in Article 4, point (4), of Regulation (EU) 2016/679” (the GDPR’s definition); a recommender that suggests contacts or information not provided by a user’s pre-existing connections or subscriptions; and features that are intended, or can reasonably be foreseen, to enable uninterrupted content consumption, that incentivise interactions, or that send automated notifications designed to prompt a user to start or resume using the service.

Age tier What the proposal says
Under 13 Per the press release, children between 3 and under 13 “cannot access social media”, but can access “specially designed child-friendly video-sharing services through accounts managed by their guardian”
13 to 14 Art. 6(2): a guardian-set-up account “with limited features”, guardian tools always on, a daily cap “which shall not exceed one hour per day”, and guardian pre-approval of new contacts
15 and up An account of their own, under the general rule in Art. 6(1)

Two Routes to the Same Age Check

For a new account on a service covered by the under-15 account rule, Article 29(2) sets one route: providers “shall rely exclusively on an EU age verification solution using an EU proof of age attestation” certified against the EU Age Verification Scheme. For an account that already exists, Article 32(1) makes age verification the rule for checking whether the holder is under 15, and Article 32(2) lets a provider skip it where it “can establish, with a high degree of confidence, that the recipient of the service has reached the minimum age”. For confidence that a user is an adult, a recital gives “previously legitimately acquired credit card details” as an example of reliable information. The press release describes the same situation as providers estimating age “based on reasonable proxies (e.g. account creation date, credit card details).”

See also  Claude Shared Chats Indexed by Google: Disallow Blocked the Noindex

Platform-side age estimation already runs in at least one consumer product. Our report on the August rollout of ChatGPT for Teens quoted OpenAI’s placement rule: an account moves into the teen product when “our system estimates someone is under 18 or they state their age is between 13 and 17”. Under the proposal, Article 32(4) would require very large platforms in scope to submit a plan on how they intend to comply and, if they intend to rely on the exceptions in Article 32(2) and (3), how they intend to establish that a user has reached the minimum age (the second exception applies where a provider can establish with a high degree of confidence that a user is not a minor).

The recommender rule in Article 10(2)(c) would bar recommenders from relying on “any personal data of minors captured from outside the service”. It is written for recommender systems, not for every system a platform runs.

What Is Not Settled Yet

  • No calendar date exists. Article 43 states the Regulation applies from “[same day as entry into force plus 6 months]”, brackets included. Australia’s exposure draft privacy bill also left every commencement date blank.
  • The Commission’s policy page says very large online platforms “will have to submit a compliance plan to the Commission for new services, features or functionalities”, and adds: “These will be assessed within 30 days and can only be rolled out after positive opinion by the Commission.” Article 5 of the published proposal does not tie the plan to new features and contains no positive-opinion step; its two 30-day deadlines cover notification by already-designated platforms and corrective action plans. The two descriptions do not match.
  • The text sets no numeric pass mark for “a high degree of confidence” on an existing account; its recitals ask very large platforms to back the claim, where relevant, with accuracy, precision and recall for underage recipients, measured on a representative sample of users, without naming a threshold.
  • What the European Parliament and the Council change in the text before it can become law is open, by definition, at the proposal stage.

The proposal PDF is posted on the Commission’s newsroom repository. Rappler’s report from Strasbourg covers the same day’s press conference.