Thoughts 8 min read 1637 words

The EU Sets a Minimum Age for Social Media: What the Kids Act Fixes and What It Leaves Untouched

ES
The EU Sets a Minimum Age for Social Media: What the Kids Act Fixes and What It Leaves Untouched

Yesterday I published an article about AI, minors and age verification prompted by Common Sense Media’s report on Perplexity. The thesis was that the age checkbox is a double failure: fakeable from the outside and useless on the inside, because products collect the data and then do nothing with it.

Today, in her State of the European Union address in Strasbourg, Ursula von der Leyen announced a proposal aimed squarely at that problem. The timing is almost embarrassingly good.

What exactly was proposed

What von der Leyen said boils down to one line of hers:

“No social media under the age of 13. No personal account under the age of 15.”

The tiered structure, as announced:

AgeWhat’s allowed
Under 13Complete ban on social media
13 to 15“Mini accounts” opened and supervised by parents or guardians, with limited features and time caps
15 to 18Full account, but with a safe design obligation on the platform

It comes packaged with the removal of addictive features — infinite scrolling gets an explicit mention — and fines of up to 6% of annual revenue. The fine print arrives tomorrow, Thursday, and according to leaked drafts the scope would also cover video games, video platforms and AI chatbots and companions.

That last part connects directly to yesterday’s piece, and I’ll come back to it.

Von der Leyen anchored the announcement in a specific case: a 14-year-old Belgian girl who died by suicide after being cyberbullied. She quoted her mother: “without these omnipresent networks, my daughter would still be here.” And she framed the whole thing with a statement of intent about Big Tech’s power:

“I am aware that many perceive the power of Big Tech as overwhelming and impossible to roll back. I disagree.”

What this does fix

Let me start with the good, because there is some.

The problem documented in the Perplexity report wasn’t just that a minor can lie about their age. It was that the product does nothing with the data even when it has it. The account was registered as 15 years old, the system knew, and it still offered romantic roleplay, pornographic content and short-selling plans.

This is where the proposal supplies something the industry was missing: an obligation. Until now, differentiating the experience for a minor was a voluntary product decision, and we’ve seen how that goes when each company decides for itself. The safe mode existed inside Perplexity and wasn’t the default.

With fines at 6% of revenue, the internal conversation changes. It stops being “is it worth building two experiences?” and becomes “what does it cost us not to?” A more boring argument, but a far more effective one.

And there’s one detail I think is the most important in the whole package: the reversal of the burden of proof. It falls on the operator to demonstrate compliance, not on the regulator to demonstrate a breach.

This didn’t come out of nowhere. It comes from the report an expert panel on child online safety delivered to von der Leyen back in July, which put it in writing without ambiguity: “when it comes to safety, the burden of proof needs to be on providers, not regulators, parents and children.” That same report recommended restricting access for under-13s until platforms demonstrate they are safe by design.

It’s an important reframing. It moves from “prove this caused harm” to “prove this is safe.” And it’s what turns age verification from a formality into a real obligation.

That AI chatbots and companions fall within scope is, frankly, the part I wasn’t expecting. It lines up exactly with Common Sense’s finding about conversational register: reciprocity, mutuality, permanent availability. Companionship cues in an informational tool, applied to users the system knows are teenagers.

What it doesn’t fix

Now the uncomfortable part, which is the one I find more interesting.

First: the business model remains intact. The sharpest criticism of the announcement came from Simeon de Brouwer, a policy advisor at digital rights group EDRi, and it’s worth reading in full:

The proposal “merely delays young people’s exposure to the risks of online harm instead of addressing the business model and extractive practices which fuel it.” Platforms will “unavoidably target them as soon as they’re a day older than the threshold.”

And he’s right. A kid turning 15 goes straight from full protection to the complete adult product, which is exactly the same engagement-optimised product as before. The safe design obligation for the 15-18 tier is the counterweight, but it’s also the vaguest part of the announcement and the one most dependent on how the fine print gets written.

Second: age verification collides head-on with privacy. This is the structural conflict. To enforce an age limit you need to know everyone’s age, not just the minors’. Which means any adult wanting to open an account has to prove who they are.

Pedro Sánchez put it well back in February, announcing Spain’s under-16 ban, with a line that captures the demand neatly: age verification systems need to be “not just check boxes, but real barriers that work.” I agree with the goal. The problem is what it costs to meet it.

The EU has spent a decade building privacy architecture and now needs a tool that pulls in the opposite direction. The technical route on the table — verifiable credentials and zero-knowledge proofs on top of the European digital identity wallet — is sound on paper: you certify you’re over an age without revealing who you are. But the real implementations tested so far haven’t fared well; there are analyses describing verifications broken in a couple of minutes, with the passport or selfie image left unencrypted on the device itself.

Third: this isn’t law, and might never be. All 27 member states have to debate and vote. AP talks about years. Estonia has already openly rejected the idea of a single EU-wide minimum age, arguing for digital literacy instead. And there’s a serious precedent: last month France’s constitutional court struck down a law banning under-15s from social media, ruling it infringed fundamental freedoms. Macron vowed to rework it.

There’s also a fit problem. Brussels arrives late to a movement member states had already started on their own, each with a different age:

CountryMinimum ageStatus
Australia16Being implemented, world’s first
Spain16Announced in February, pending parliament
France15Passed in January, struck down by the court
Denmark15Legislation introduced
EU proposal13 / 15Proposed, not voted

If the EU Kids Act settles on 13 and 15, Spain would have to lower its threshold from 16 or defend why it keeps a stricter one. European harmonisation has the advantage of ending the patchwork, but it means some countries loosening what they had already tightened.

Add the external front. The proposal lands amid tension with Trump and US tech companies. Brando Benifei, the Italian MEP who supports the plan, put it plainly: “to apply this, you need to confront in a very frontal way the interests of platforms and Big Tech who are not happy with this.”

The gap that stays open

There’s an asymmetry that’s been nagging at me since yesterday, and this announcement doesn’t close it.

The EU Kids Act attacks access: who can open an account and at what age. But the Perplexity report documented a failure of behaviour: what the system does once it already knows it’s talking to a minor.

flowchart LR
    A["Age verification"] --> B["Solves: who gets in"]
    A --> C["Doesn't solve: what they get inside"]
    C --> D["Crisis context that doesn't survive one turn"]
    C --> E["Safe mode that exists · isn't the default"]
    C --> F["Minor's data into the same pipeline"]

A 15-year-old with a supervised mini account can still ask a chatbot which household products are poisonous right after disclosing suicidal ideation. That failure — the gravest in the report — isn’t a minimum-age problem. It’s a context-continuity problem inside the product, and no identity verification touches it.

Verifying age is an identity problem. Acting on it is a product problem. Yesterday I wrote that the second one is the expensive one. I still think so, and today’s proposal mostly attacks the first.

What I take from it

I’m glad about the announcement and simultaneously wary of the enthusiasm it’s going to generate.

I’m glad because it breaks something that had been stuck for years: the idea that self-regulation would sort this out. Facebook, Instagram and TikTok already prohibit under-13 accounts in their own terms of service. They have for years. And authorities have spent those same years accusing them of doing nothing to enforce it. The age checkbox didn’t work when industry put it there; it makes sense to test what happens when the law puts it there with a fine behind it.

And it’s worth noting Brussels isn’t sitting on its hands waiting for the age tiers to pass. Back in July it warned Meta, using the digital services rules already in force, that it needs to disable addictive design features like infinite scrolling or face a hefty fine. That route doesn’t need years of votes.

I’m wary because a minimum age is a legible, headline-friendly and politically profitable measure, and none of those qualities make it sufficient. It’s easier to legislate who gets in than to legislate how the product behaves once they’re inside. The first gets announced in a speech; the second requires auditing systems, defining behavioural standards for crisis situations and sustaining technical oversight for years.

The part of the EU Kids Act I genuinely care about isn’t the age. It’s whether the safe design obligation for the 15-18 tier ends up with teeth or stays a statement of principles. That’s where it gets decided whether this changes products or just changes the front door. Tomorrow we see the fine print.