Yesterday I closed my article on von der Leyen’s announcement with a line that was half question, half bet:
“The part of the EU Kids Act I genuinely care about isn’t the age. It’s whether the safe design obligation for the 15-18 tier ends up with teeth or stays a statement of principles.”
Today the Commission presented the text in Strasbourg, von der Leyen alongside Henna Virkkunen. The fine print is here.
And the answer is yes, it has teeth. Rather more than I expected.
What’s in the text
Yesterday’s announcement was about ages. Today’s text is about design, and that’s where it gets interesting:
| Obligation | What it means |
|---|---|
| Ban on addictive features | Infinite scrolling, artificial notifications and certain reward mechanics, named explicitly |
| Recommenders beyond engagement | Algorithms can’t rely solely on interaction signals, and must avoid rabbit-hole effects |
| Safe defaults | Private accounts, risky settings blocked, clear warnings |
| Contact protection | Strangers can’t initiate direct contact; adding someone to a group requires explicit permission |
| Prior authorisation | Very large platforms need a positive opinion from the Commission before rolling out new features, with a 30-day review |
| Supervisory fee | Platforms pay for the oversight they’re subject to |
The age structure gets refined too: nothing under 3, child-friendly supervised services from 3 to 13, introductory accounts from 13 to 15 with time caps and limited contact lists, and from 15 an autonomous account provided the environment meets safety standards.
That last clause didn’t exist yesterday and does today. It isn’t “at 15 you’re a digital adult.” It’s “at 15 you’re in, if the place complies.”
Where I got it wrong yesterday
Yesterday I took Simeon de Brouwer’s (EDRi) criticism at face value without qualifying it: that the proposal “merely delays young people’s exposure to the risks of online harm instead of addressing the business model and extractive practices which fuel it.”
With the text in front of me, that criticism holds up less well. A recommender that can’t optimise purely for interaction signals is, precisely, touching the business model. This isn’t a minor detail: infinite scroll and the algorithm that maximises screen time aren’t decorations on the product, they are the product. Banning them by law for minors goes considerably further than delaying exposure.
The core of his argument still stands — the day you turn 15 there’s a jump, and the platforms are waiting on the other side — but the jump is smaller than it looked, because the environment you jump into carries obligations too.
What actually caught my attention
There’s one piece in the text getting little coverage that strikes me as the most important of all: prior authorisation.
A very large platform cannot roll out a new feature affecting minors until the Commission issues a positive opinion, with a 30-day review window.
This isn’t tougher regulation. It’s regulation of a different nature:
flowchart LR
A["Classic model"] --> B["You ship the feature"]
B --> C["It causes harm"]
C --> D["Investigation · fine years later"]
E["EU Kids Act model"] --> F["You submit the feature"]
F --> G["30-day review"]
G --> H["Only then you ship"]The classic model of European digital regulation is punitive: you ship, and if you cause harm, the fine arrives years later. That has an obvious problem when the harm lands on a minor and is irreversible. A 6% fine gives nothing back to the family of the Belgian girl von der Leyen cited yesterday.
Prior authorisation reverses the order: first you show, then you ship. It’s what we already do with medicines and aviation, and the underlying question the EU Kids Act raises is whether software aimed at minors belongs in that category of things reviewed beforehand.
It will be, by some distance, the most fought-over part of the text. Not without reason: it’s also what slows the product cycle most, and where the lobbying pressure will concentrate during negotiations.
The problem that remains unsolved
And here’s the part that ties back to the first article in this series, the one about the Perplexity report.
This entire architecture rests on one piece: knowing the user’s age. And that piece still doesn’t work.
The text requires verification at account creation via an EU-wide tool or equivalent public systems meeting standards of accuracy, privacy and non-discrimination. On paper it’s the right route. In practice there are two data points worth keeping in view:
- The zero-knowledge proof based solution was bypassed by researchers in under two minutes.
- Australia, the world leader on this, is running a 70% failure rate on its verification.
These aren’t implementation details. They’re the foundation. If verification fails, everything else — the mini accounts, the tiers, the age-differentiated safe design — rests on data that isn’t reliable.
And this is where the Perplexity report I wrote about on Monday stays uncomfortable, because it documented the other end of the same problem: even when the system knew with certainty it was talking to a 15-year-old, it didn’t change its behaviour. Crisis context didn’t survive from one turn to the next. The safe mode existed and wasn’t the default.
The EU Kids Act now requires that safe mode to be the default. That’s real progress. But the obligation triggers when the system knows it’s talking to a minor, and knowing that remains the weak link.
What I take from these three days
Three articles in a row on the same thread, so let me close it.
On Monday I wrote that the age checkbox was a double failure: fakeable from the outside and useless on the inside. Of those two halves, the EU Kids Act attacks mostly the second — the one I’d written off. It forces the product to behave differently when it knows there’s a minor in front of it, bans the engagement features by name, and introduces prior review. That’s considerably more than I expected from an announcement that started out looking like a minimum age with a headline.
The first half, verification, is as open as it was on Monday. And it looks like the genuinely hard problem, because you don’t solve it by legislating: you solve it with cryptography that doesn’t yet survive a researcher with two spare minutes.
Then there’s the process, which is no small thing. This is a proposal, it has to pass Council and Parliament, and the French precedent — an equivalent law struck down by its constitutional court — is a reminder that the path isn’t straight. But the conceptual framework is on the table, and it’s better than I anticipated on Tuesday.
What I take away is the change of question. We spent years arguing about what content a minor can see. Today’s text argues about how the thing they use should be built. That’s a much better question.




