Ursula von der Leyen’s Kids Act formally bans social media for children under 13. But its real target lies deeper: the infinite scroll, recommendation algorithms, and AI companions that underpin an attention economy worth hundreds of billions of dollars.
In August 2026, Meta agreed to pay U.S. states and territories up to $18 billion over ten years. That settlement ended litigation launched in 2023, when attorneys general from dozens of states accused the company of deliberately designing Instagram and Facebook so that teenagers would find it difficult to put down their screens. The company admitted no wrongdoing. It did, however, agree to pay.
A month later, on September 16, European Commission President Ursula von der Leyen took the floor at the European Parliament in Strasbourg for her annual State of the Union address and delivered two short lines that executives at Meta headquarters almost certainly parsed word by word: no social media before age 13, no personal accounts before age 15. The following day, together with European Commission Executive Vice President for Technological Sovereignty, Security and Democracy Henna Virkkunen, she unveiled a draft regulation given the working title Kids Act.
There is a fundamental dividing line between the two events. The American system presented Meta with a bill for the past. Europe is trying to rewrite the machine that generated that bill.
Newsrooms around the world seized on the age ban, and they missed the point. The threshold of 13 is the most decorative part of the proposal. What matters is that Brussels is attempting, for the first time, to prohibit by law the engineering features that constitute the business model of global platforms: infinite scroll, personalized feeds, autoplay, and chatbots designed to act like friends. This is about the product. Content is secondary.
Six Percent of the Entire World: What the Proposal Actually Says
The Kids Act is built around a three-tier system. Children under 13 would be completely barred from social networks, video platforms, online games, chatbots, and AI companions. Teenagers aged 13 and 14 would receive so-called mini-accounts, created through a parent’s account, placed under parental control, equipped with limited functionality and, according to the published details, restricted to one hour per day. From ages 15 to 18, teenagers could create their own accounts, but platforms would be required to provide a safe-by-default architecture.
The list of obligations imposed on platforms is longer and tougher. For all minors, the proposal would prohibit infinite feeds, recommendations based on behavioral profiling, gamified reward mechanisms, and unsolicited contact from strangers. Children’s and teenagers’ accounts would be partially private by default: geolocation concealed, camera and microphone disabled. AI companions and chatbots would be switched off by default for minors, while such systems would also be prohibited from simulating interpersonal relationships in ways designed to create emotional dependence.
Von der Leyen stated the logic in Strasbourg with unusual clarity: age restrictions, she said, do not absolve technology companies of responsibility, and for everyone under 18 platforms will have to follow the principle of safety by design, without toxic or addictive features.
The most radical innovation is buried in the procedure. Companies would be required to submit modernization plans for their platforms to the European Commission. The Commission, together with independent assessors, would review those plans within three months and either approve them or send them back for revision. In effect, the burden of proof is reversed. Previously, regulators had to prove that a platform caused harm. Now the platform would have to prove that it is safe.
The penalty is borrowed from the Digital Services Act, or DSA: up to 6 percent of global annual revenue. For Meta, whose 2025 revenue came in just below $201 billion, the maximum fine would exceed $12 billion. That is comparable to the American settlement, except that it would be payable at once rather than spread over a decade.
The proposal also rests on public opinion, and here the Commission is operating from a strong position. According to an EU-commissioned survey, 92 percent of respondents consider protecting children online to be a priority of European policy. It is difficult to find another issue in Europe today with that degree of consensus. Migration, Ukraine, the Green Deal, and defense spending divide electorates. Children with smartphones unite them.
Why 13? The Number Europe Inherited From Washington in 1998
The age threshold of 13 has nothing to do with developmental psychology. Its origins are legal and commercial.
In October 1998, the U.S. Congress passed the Children’s Online Privacy Protection Act, or COPPA, which took effect in April 2000. The law required parental consent for the collection of personal data from children under 13. Young internet companies made a simple calculation: it was easier to prohibit registration by children under 13 than to build elaborate parental-consent systems. A number originally written into a law governing advertising data thus evolved into a global standard of “digital adulthood,” embedded in the terms of service of Facebook, Instagram, TikTok, and YouTube.
Europe tried to raise the threshold in 2016. Article 8 of the General Data Protection Regulation, or GDPR, set the age of independent consent to data processing at 16, while allowing member states to lower it to 13. The result was a patchwork: Germany and the Netherlands remained at 16, France chose 15, while Belgium and Denmark went down to 13. No uniform European age emerged, and platforms continued operating under the American standard.
This produces the first paradox of the Kids Act. A ban on children under 13 already formally exists in the platforms’ own rules. The problem is that nobody verifies it. In April 2026, the European Commission preliminarily found Meta in breach of the DSA precisely because of ineffective measures for verifying the ages of users under 13. In other words, Brussels is turning into law a rule the companies themselves wrote and then failed to enforce for decades.
I would call it compulsory honesty. The platforms are finally being told to do what they have promised on the first page of their user agreements since the day they were founded.
Paris Stumbled, Brussels Picked Up the Baton
To understand why the European Commission is acting now, look at Paris.
French President Emmanuel Macron made a ban on social media for children under 15 one of the signature initiatives of the final years of his term. A bill introduced by lawmaker Laure Miller from the pro-presidential bloc passed the National Assembly in January 2026 and was finally adopted by Parliament on July 21. Its path was difficult from the outset. As early as January 8, the Council of State pointed to the absence of a clear definition of a platform or social network and warned of likely incompatibility with EU law. On July 6, 2026, the European Commission sent Paris a detailed opinion: while not challenging the principle of a minimum age itself, Brussels concluded that the law intruded into the harmonized framework created by the DSA. Lawmakers were forced to strip platform obligations from the bill, leaving the prohibition hanging primarily over minors themselves.
On August 14, the Constitutional Council, in Decision No. 2026-911 DC, struck down the law’s key first article. The judges ruled that the ban caused disproportionate harm to freedom of expression and communication. Their reasoning was precise and painful: the prohibition failed to account for a child’s age, family circumstances, or degree of maturity; gave parents no right to lift or soften the restriction in the child’s interests; and could extend to services whose risks to minors’ health had not been established. The Council separately noted that the law failed to define the conditions and limits of age verification and therefore did not provide adequate guarantees for the right to privacy.
That same day, the Élysée Palace announced that Macron had instructed Prime Minister Sébastien Lecornu to prepare a legally durable version of the law and that the president remained fully determined to complete the reform by spring 2027. For France, the setback is doubly painful: in 2023, it had already adopted a law establishing a digital age of consent at 15, but that law never became operational because it ran into the same body of European law.
The French experience explains the architecture of the Kids Act better than any Brussels press release. The Commission’s proposal reads like a correction of Paris’s mistakes. A blanket ban has been replaced with age-based gradation; restrictions imposed on children have been replaced with obligations imposed on platforms. Brussels proposes replacing vague age verification with a European application. Parents, whom the French law effectively left outside the framework, would gain control over the accounts of 13- and 14-year-olds. Every weakness that brought down the French law before the Constitutional Council has been addressed in advance in the European proposal.
This is also where a second, institutional story emerges. According to available information, the European Commission has warned national capitals that if the proposal becomes law, national rules on the subject would have to be repealed and replaced by a single regulation. France, Austria, Denmark, Greece, and Spain had already announced their own restrictions before the Kids Act appeared. Danish Prime Minister Mette Frederiksen advocated a threshold of 15, Spanish Prime Minister Pedro Sánchez called for 16, while the Greek government of Kyriakos Mitsotakis was developing its own parental-control system through a government application. Irish Communications Minister Patrick O’Donovan immediately backed the proposal and said Dublin had already begun consultations with the Commission.
Brussels is effectively taking over a power that national capitals had only just begun to exercise. An EU regulation applies directly and leaves little room for independent national policymaking. For von der Leyen’s Commission, which during her second term has consistently expanded its role in defense, industrial, and digital policy, children’s online safety is an ideal beachhead. No government will readily risk being seen publicly opposing it.
Yet a conflict is already smoldering inside this structure, and few have noticed it. If the final regulation establishes an unconditional ban only for children under 13, Denmark and Spain, which are targeting thresholds of 15 and 16, may be forced to abandon stricter national limits in favor of a more permissive EU-wide standard. In November 2025, a majority in the European Parliament supported an EU-wide minimum age of 16, with access from age 13 permitted with parental consent. The age threshold will become the central bargaining point.
Legally, the proposal’s path is easier than it may appear and harder than the Commission would prefer. A regulation is adopted through the ordinary legislative procedure. Unanimity in the Council of the European Union is unnecessary; a qualified majority is sufficient: 55 percent of member states representing at least 65 percent of the Union’s population. Politically, however, no national capital will want to look like the government that blocked child protection. The overall fate of the regulation is largely predetermined. The bargaining will focus on the details that determine everything: age thresholds, which platforms are covered, when the rules take effect, and how much discretion national governments retain.
The Australian Lesson: Five Million Accounts Removed and Not a Single Fine
Von der Leyen explicitly said the Commission had studied Australia’s experience. There was plenty to study.
Canberra passed its social-media minimum-age law in November 2024. Since December 10, 2025, ten platforms, including Facebook, Instagram, Threads, TikTok, Snapchat, YouTube, X, Reddit, Twitch, and Kick, have been required to take reasonable steps to prevent Australians under 16 from holding accounts. The maximum penalty for systemic violations is 49.5 million Australian dollars. Children and parents themselves face no liability.
The first figures looked triumphant. In January 2026, eSafety Commissioner Julie Inman Grant said platforms had blocked access to approximately 4.7 million accounts belonging to children under 16 during the first half of December. The government later cited more than 5 million blocked accounts. Differences between the estimates stem from methodology, but the scale is clear.
The problem lies elsewhere. The Australian regulator’s own report showed that before the ban, nearly 86 percent of surveyed children used at least one prohibited platform; three months after the ban took effect, the figure was still above 81 percent. The share of teenagers using social media every day fell from about 60 percent to 58 percent. Five million closed accounts translated into a five-percentage-point decline in overall reach. Teenagers opened new accounts, lied about their age, used older people’s accounts, and installed VPNs.
Canberra’s response is revealing. In June 2026, Anthony Albanese’s government announced plans to double the maximum fine to 99 million Australian dollars and expand the regulator’s powers. Communications Minister Anika Wells said platforms were relying on tactics straight out of the Big Tech playbook and doing the minimum necessary to claim compliance. The regulator is investigating possible violations by Facebook, Instagram, Snapchat, TikTok, and YouTube. Reddit is complying with the law while simultaneously challenging it in the High Court. In September, Wells acknowledged that many minors remained on prohibited platforms and that not a single company had yet been fined.
The lesson Brussels appears to have drawn is straightforward. Restricting access is the weakest element of any such policy because teenagers are more inventive than age-verification algorithms. Regulating design is more durable: you cannot circumvent the absence of infinite scroll with a VPN if infinite scroll has been removed from the product. That is why the European Commission chose a lower age threshold than Australia and shifted the full weight of its proposal toward platform obligations for teenagers aged 13 to 18. Canberra built a fence. Brussels is trying to rebuild the house itself.
Britain is taking a third path. The Online Safety Act 2023 required websites carrying adult content to begin verifying users’ ages on July 25, 2025, after which, according to VPN providers themselves, registrations from Britain multiplied. London has already adopted framework legislation for a ban modeled on Australia’s approach and says it intends to introduce it from spring 2027, with the first rules due before the end of this year.
The Chatbot That Pretends to Be a Friend Too Well
The most innovative and perhaps most difficult provision of the Kids Act to enforce concerns artificial intelligence.
In February 2024, 14-year-old Sewell Setzer died by suicide in Florida. His mother sued Character.AI, alleging that her son had spent months engaged in emotionally dependent conversations with a chatbot persona. In August 2025, the parents of 16-year-old Californian Adam Raine filed a lawsuit against OpenAI, linking their son’s death to his conversations with ChatGPT. After a wave of lawsuits and public pressure, Character.AI shut down open-ended chats for users under 18 at the end of 2025. It is precisely this type of case that the European prohibition on simulations of relationships capable of creating emotional dependence is intended to address.
Europe’s Artificial Intelligence Act has, since February 2025, already prohibited systems that exploit vulnerabilities associated with a person’s age in order to materially distort that person’s behavior. The Kids Act goes further, addressing a problem the AI Act largely bypassed: a companion may manipulate no one in the legal sense and still become a substitute for real human relationships in a teenager’s life.
The commercial logic is the same as with the feed. Companion applications make money from engagement: the longer and more emotional the conversation, the greater the likelihood of a paid subscription. To prohibit a chatbot from encouraging attachment is to prohibit precisely the behavior for which users are paying. Legally defining where a friendly interface ends and the simulation of a relationship begins will be extraordinarily difficult. I suspect this provision will generate some of the longest debates in the Council and the European Parliament and will ultimately become one of the most vaguely worded sections of the final text.
Age Verification: Vaccine Against Harm or Surveillance Virus
The core argument made by opponents of such restrictions is simple. To prove that you are older than 13 or 15, you will have to show someone an identity document. Age verification for children inevitably becomes age verification for everyone.
Those concerns are not groundless. In October 2025, Discord acknowledged a breach involving a third-party contractor handling user support requests. According to the company, images of identity documents belonging to roughly 70,000 people who had uploaded them for age verification may have been compromised. In August, France’s Constitutional Council specifically cited privacy risks arising from an age-verification system whose limits had not been defined in law.
The European Commission’s answer is its own infrastructure. In summer 2025, Brussels unveiled a prototype European age-verification application and launched a pilot program in five countries: Denmark, France, Greece, Italy, and Spain. The application is supposed to confirm a single piece of information to the platform, such as whether the user is older than 13, without transmitting a name, address, date of birth, or document number. Eventually, the function is intended to be integrated into the European Digital Identity Wallet, which EU countries are required under the eIDAS 2.0 regulation to offer their citizens by the end of 2026.
Technically, the model appears sensible. Politically, it creates a precedent whose consequences extend far beyond child protection. A government-backed digital identifier used to access social networks is an instrument that today’s Commission may deploy to protect children, while tomorrow’s government in some member state may want to use it for something else. Digital-rights advocates in Brussels raise another objection: in their view, the proposal merely postpones a teenager’s encounter with harmful platform mechanics without changing the underlying business model, and companies will begin targeting the user the day after that person turns 18.
I consider that criticism only partly fair. The Kids Act does not prohibit the advertising model as such. Personalized advertising to minors based on profiling has already been prohibited under the DSA since 2024, and Brussels is not revisiting that issue. But banning infinite feeds and profiling-based recommendations for everyone under 18 attacks the mechanics of habit formation, and a habit established at age 14 is worth more to a platform than any single advertisement impression.
Washington Will Not Let This Pass Quietly
The list of companies affected by the Kids Act is almost entirely American: Meta, Google and YouTube, OpenAI, Snap, Roblox, and Discord. The only major exception is China’s TikTok. The proposal therefore inevitably lands in the middle of the transatlantic conflict over digital regulation.
Since the first months of Donald Trump’s second term, his administration has attacked the DSA as an instrument for censoring American companies. In December 2025, after the first DSA fine in history, a €120 million penalty against Elon Musk’s X, the State Department imposed visa restrictions on former European Commissioner Thierry Breton, one of the law’s architects, and several European activists. EU digital rules became a recurring issue in trade negotiations: Washington pressed for weaker enforcement, while Brussels insisted that the DSA was not a bargaining chip.
Against that backdrop, the Kids Act is a tactically brilliant move. It is easy for American politicians to characterize action against disinformation as censorship. That argument becomes far harder when the issue is protecting 12-year-olds from infinite scroll, particularly when dozens of U.S. states themselves reached an $18 billion settlement with Meta and Republican lawmakers in Utah and Texas have adopted their own age-verification laws. Von der Leyen has chosen terrain on which the U.S. administration cannot assume its familiar role as the defender of free speech without risking the appearance that it is defending corporations against parents.
The chronology of recent months shows that Brussels has been preparing this ground methodically. On February 6, 2026, the Commission preliminarily found TikTok’s addictive design in violation of the DSA. For the first time, the law was applied to platform architecture rather than illegal content. On April 29 came preliminary findings against Meta over age verification for children under 13. In May, Temu was fined €200 million. On July 10, the Commission preliminarily found the design of Instagram and Facebook to be addictive. Henna Virkkunen said at the time that protecting Europeans’ physical and mental health must be a priority for social-media platforms and that the DSA provides a clear legal basis for holding companies accountable for addictive design. Meta responded that it disagreed with findings that failed to take into account significant steps the company had taken to protect teenagers, and pointed to teen accounts with nighttime protections and parental controls allowing screen time to be limited to 15 minutes a day.
The Kids Act codifies what the Commission is already pursuing case by case through the DSA. The difference is scale: instead of years-long investigations into individual companies, uniform rules for everyone; instead of preliminary findings, mandatory advance review.
Who Wins and Who Pays
The principal beneficiary of the proposal is the European Commission itself. It gains new powers, direct oversight of platform design, and an issue on which it is almost impossible to lose publicly. Von der Leyen, whose second term has coincided with declining support for mainstream parties across the continent, needs initiatives that voters understand immediately. A parent whose 12-year-old daughter falls asleep with a phone in her hand understands the Kids Act instantly.
The impact on platforms will be uneven. TikTok and Snapchat are likely to suffer most because their audiences are younger than Facebook’s and their businesses depend more directly on recommendation feeds. Roblox, a large share of whose audience consists of children under 13, falls within the proposal through its treatment of online games. For startups developing AI companions, Europe risks becoming effectively closed to underage users.
Meta’s position is considerably more ambiguous. Facebook has been aging alongside its users for years, and European teenagers are now a secondary market for the service. Instagram is another matter. Meta also has its own strategic interest in this fight. In the United States, the company has spent the past two years promoting the idea that age verification should be handled not by individual applications but by the app stores operated by Apple and Google. In 2025, Utah became the first state to pass a law placing that obligation on app stores. If the European regulation allocates verification responsibilities in favor of operating systems, Meta will shift part of the cost onto two competitors. The battle over who exactly must verify age will become one of Brussels’s most important behind-the-scenes lobbying fronts.
European providers of digital-identity technology and national operators of digital wallets also stand to gain, since the regulation would guarantee them mass demand. Strangely enough, parents may be among the losers. A mini-account for a 13- or 14-year-old requires a parent’s account, configuration, monitoring, and daily responsibility. Europe is transferring a bureaucratic burden to families for which most families are unprepared.
For the post-Soviet space, the story has an unexpected dimension. Russia, which designated Meta an extremist organization back in 2022, regulates social networks through access: it blocks platforms and promotes state-backed messengers. Europe regulates through product architecture. The first model serves control over information; the second serves control over the business model. For countries in the South Caucasus and Central Asia, the European choice may prove more consequential than the Russian one. The experience of the GDPR shows that global platforms often roll out Brussels-born settings worldwide because maintaining two versions of the same product costs more. A teenager in Baku or Tashkent could therefore end up with a safer feed without a single decision being taken by his or her own parliament.
Forecast: The Ban Will Take Effect After Today’s Eight-Year-Olds Have Already Grown Past It
Now to what comes next. I am framing my estimates so that they can eventually be tested.
The Council of the European Union will not reach a common position on the Kids Act before autumn 2027. Copenhagen, Madrid, Athens, and Paris will seek the right to preserve national thresholds of 15 and 16, forcing the Commission to look for a compromise, most likely by allowing member states to raise the age of a full ban above 13.
Trilogue negotiations among the Council, the European Parliament, and the Commission will not conclude before the first half of 2028. Drawing on its 2025 resolution, the European Parliament will seek to raise the age threshold and expand the list of prohibited mechanisms, potentially including push notifications during nighttime hours.
With a transition period that will almost certainly last 12 to 24 months, real enforcement of the regulation is unlikely to begin before 2029 or 2030. By then, today’s eight-year-old Europeans will already have crossed the very threshold of 13 around which the proposal is built.
The DSA will hit the platforms sooner than the Kids Act. I expect the Commission to adopt a final infringement decision against Meta over addictive design by the end of the first half of 2027, with a fine exceeding €1 billion. Such an outcome would amount to a de facto early launch of the Kids Act long before the regulation itself takes effect.
France will adopt a revised version of its law by spring 2027, as the Élysée Palace has promised. But if the Kids Act preserves the principle of full harmonization, that French law will prove temporary and will eventually be displaced by the European regulation several years after its adoption.
One question remains for which I have no answer. What happens if, five years after the Kids Act takes effect, European statistics look much like Australia’s: millions of deleted accounts and almost no change in the proportion of teenagers using social media? Will Brussels admit that the ban is ineffective, or will it tighten verification to the point where accessing the internet without a government-issued digital identifier becomes impossible?
The Feed That Has an End
In Menlo Park, Meta’s lawyers are now doing the math: $18 billion for U.S. states, up to $12 billion in potential DSA penalties, not to mention the cost of redesigning products for 27 countries. In Canberra, Anika Wells is explaining why a law the government celebrated in January had still produced not a single fine by September. In Paris, Sébastien Lecornu is rewriting a law the Constitutional Council found disproportionate.
Brussels is making a bet no one else has made. It starts from the premise that teenagers cannot be kept away from social media, but social media can be kept from becoming infinite. In essence, the Kids Act demands the most unthinkable thing imaginable from the attention economy: a final post in the feed, after which nothing else loads.
If the regulation survives long enough to be enforced, a 14-year-old European may, for the first time, reach a blank screen on Instagram or TikTok telling them that there is nothing more for today. Whether they will then put down the phone is something no one knows, including Ursula von der Leyen. But for the first time in twenty years, that decision would be theirs rather than the algorithm that was paid to keep them awake.