Key takeaways
- The EU Kids Act proposal (September 17, 2026) would phase social media access by age (no accounts under 13, supervised mini-accounts at 13-15, autonomous accounts at 15+), mandate age verification, and impose safety-by-design duties across social media, games, app stores, and AI chatbots.
- It is not law and may not apply before 2028, but the architecture decisions it forces get locked in now, while vendors are chosen.
- Canada’s Bill C-34 is heading the same direction with its proposed under-16 age gate. Treat the EU text as an early draft of your own homework: prove age without keeping identity, and ship safe defaults first.
On September 17, 2026, the European Commission published its proposed EU Kids Act. The EFF’s analysis calls it what it is: the largest attempt yet to make age verification a precondition for ordinary internet use. If your product reaches minors, this is your compliance future, and it is not a foreign story for Canadians.
What the Commission proposed
Phased access. No accounts under 13; supervised mini-accounts with parental control and limited features from 13 to 15 (reported outlines include a one-hour daily cap); autonomous accounts in a safe-by-design environment from 15.
Mandatory age verification through an EU age verification solution built on EU digital identity rules. The Commission says the app retains no identity documents or biometrics. The EFF flags the catch: providers that can tell with a “high degree of confidence” that a user is above the threshold need no re-verification. That vague standard is the battleground.
Safety by design. Social media, video platforms, online games, AI companions and chatbots, app stores: child-safe by default with limits on infinite scroll and reward tricks, no push notifications during sleeping hours, no unsolicited contact from strangers, private profiles by default. AI chatbots would be off by default and barred from fostering emotional dependence.
Not law yet. Parliament and Council must negotiate; Wilson Sonsini’s Data Advisor says the Act is unlikely to apply before 2028. Exemptions cover non-profit encyclopedias, scientific repositories, educational services, and open-source platforms, but not small businesses. The EFF notes the proposal skipped a full impact assessment.
The trend is law-like even before the text is law
| Jurisdiction | Age rule | Status |
|---|---|---|
| Australia | Under-16 social media ban (Online Safety Amendment Act 2024) | In force since late 2025 |
| France | Under-15 social media ban | Struck down before taking effect (August 2026); revised proposal underway |
| United Kingdom | Announced under-16 ban | Announced June 2026, intended early 2027; legislation not yet introduced |
| EU | Phased: no accounts under 13, supervised 13-15, autonomous 15+ | Proposal; negotiation ahead; unlikely before 2028 |
| Canada | Proposed under-16 age gate plus a Digital Safety Commission (Bill C-34) | Proposal |
France’s ban died on proportionality: blanket age bans lose in court, while risk-based, least-intrusive designs survive. Brussels and Ottawa are both moving toward the latter.
Why this is Canada’s homework too
The Brussels effect is doing what it always does. Michael Geist’s analysis this week notes Canada is negotiating a Digital Trade Agreement with the EU whose directives say the deal should “neither negotiate nor affect the EU’s personal data protection rules.” European law becomes the standard; Canada finds room around it. The EU AI Act already reaches Canadian providers whose systems are used in Europe. The Kids Act applies the same export to children’s safety, and Canadian companies serving EU users will comply with it whatever Parliament does.
Canada is building its own gate anyway. Bill C-34 carries a proposed under-16 age verification duty, a Digital Safety Commission, and 24-hour CSAM/NCII duties. I wrote in April about the paradox: prove you are 16, then destroy the verification data so the gate never becomes a registry. The EU version is bigger but structurally identical.
Architecture locks in before legislation does. Where age signals are collected, stored, kept, and seen is decided when vendors are selected. A proposal with a two-year runway is the best compliance gift you will get. Use it.
What privacy teams should do now
Map every place you collect age or identity signals. Sign-up, parental consent, ad targeting, support desk. Campaigners’ readings of the proposal say platforms would have to check all existing accounts, with accounts whose age cannot be established at risk. Know your backlog before anyone audits it.
Separate proof of age from proof of identity. Build age assurance that returns an attribute (“over 16”) and retains nothing else. Hold every vendor to that term, and verify it technically, not on a slide deck.
Ship safe defaults now. Private-by-default profiles, no stranger contact, recommender choice, notification quiet hours: defensible today under PIPEDA’s safeguards and Law 25’s privacy-by-default, whatever Ottawa or Brussels enact.
Document proportionality reasoning. France’s ban failed that test. Keep the record: the risk assessment, why an age gate is the least intrusive effective measure, the alternatives you rejected. This is the file the regulator will ask for.
Actionable takeaway: Pick one product surface where you serve EU users, or minors in Canada, and draw a one-page age-assurance data-flow map: what age signal you collect, where it is stored, how long it is kept, who can see it. Any “we’re not sure” is the first gap the EU Kids Act will ask about.