The European Commission’s proposed EU KIDS Act sets 15 as the age at which a young person could open their own social media account. That headline number is the easy part. The harder question, and the one the draft leaves to platforms, is how a service would establish that a user is over or under 15 at the moment of sign-up, and how it would do the same for the accounts that already exist. This piece looks at that enforcement machinery. Everything described here is a Commission proposal that Parliament and the Council have yet to negotiate, and no application date has been set.

What the proposal says

The Commission adopted the proposal on 17 September 2026. Lewis Silkin, the law firm, reads the acronym as Keeping Internet Digital Spaces Accountable and Trustworthy. The Next Web (TNW) and Lewis Silkin describe three tiers. Children under 13 would be barred from social media, with a narrow exception allowing child-friendly video services through a guardian-managed account and a cap of one hour a day. Young people from 13 to under 15 could use a guardian-managed “mini account” with limited contacts and a one-hour daily limit. From 15, a user could hold an autonomous account. TNW gives the youngest bracket as ages 3 to 12; Lewis Silkin itself flags that its “3 to under 13” wording may be a typo, so the lower bound is not reliable.

Beyond the age tiers, the draft applies safety-by-design duties to services used by anyone under 18. According to TNW and Lewis Silkin these include bans on infinite scroll without stopping points, reward mechanics, push notifications during sleeping hours, tracking-based recommendation feeds and unsolicited messages from strangers, plus private-by-default profiles with location, camera and microphone access off. AI chatbots and companions would be off by default for minors and barred from designs that simulate relationships in ways likely to create emotional dependency.

On penalties, the sources split. TNW reports fines of up to 6% of worldwide annual turnover. A Danish-language summary of the Commission’s consultation page, published 5 October by the legal portal Lovguiden, gives the same 6% figure, while Lewis Silkin states no penalty at all. Two sources agree, but both are secondary, and the Commission’s own English-language text was not checked for this article, so the figure is best read as “reported” rather than confirmed.

The reversal of the burden of proof

The Commission’s central design choice is procedural. Ursula von der Leyen, quoted by TNW, described the act as reversing the burden of proof: it falls on platforms to show they are safe by design. In practice that is built from three pieces. Platforms with 45 million or more monthly EU users must submit a compliance plan, and pay for independent audits, according to the Lovguiden summary. TNW adds that the plan goes to the Commission and an independent auditor before a new service or feature launches, and that the Commission can require changes. The Danish summary says the Commission may object to an auditor whose independence is not assured.

The second piece is speed. For services the Commission supervises directly, the Lovguiden summary says an expedited procedure targets preliminary findings within 30 days and a final decision within 90 days. TNW and Lewis Silkin both report the 90-day limit. That compares with the Digital Services Act cases against TikTok and Meta, which PPC Land describes as still at the preliminary stage with potential fines of up to 6% of global turnover. A 90-day clock is a very different instrument from an open-ended investigation, but it is a target for the Commission, and the sources do not say what happens if an audit or a platform’s response runs past it.

The third piece is who enforces. The Commission would supervise the largest platforms and AI chatbots itself, with national authorities handling smaller services and online games that are not platforms, building on the structures of the Digital Services Act and the AI Act (Lewis Silkin, Lovguiden). That reuses existing machinery, which helps with speed, but it also means the new duties land on regulators who are already running large DSA caseloads.

The proxy problem

For new accounts the draft is demanding. The Danish summary says self-declared age is not enough: access must be gated by certified, platform-independent age verification using zero-knowledge proofs, so that a platform learns only whether a user is above or below the threshold. Each member state would have to offer at least one free way to prove age, including for people without a digital ID, and an EU age verification app is planned, with the European Digital Identity Wallet to follow. EU Perspectives reports that Brussels wants member states to roll out the app by the end of 2026. Lewis Silkin says the Commission describes the tool as designed not to retain identity documents or biometric data.

Existing accounts are treated differently, and this is where the sources diverge. TNW says providers estimate ages from signals such as the account creation date or credit card information, then must check within six months of the rules taking effect whether account holders are under 15. Lewis Silkin phrases the same duty as estimating age using “reasonable proxies.” PPC Land, summarising the earlier draft, says existing accounts would get proportionate checks rather than blanket re-verification, with examples such as accounts opened years ago and accounts linked to a card held by the account owner. The Lovguiden summary is the starkest: within six months of the rules applying, platforms must check account holders and disable accounts of users under 15 or whose age cannot be established. Whether an account whose age is merely “unproven” is disabled, or simply re-checked, is therefore unresolved across the sources.

The reasoning below is DrafterDaily’s analysis, not a finding from the documents. Take the account creation date first. Most large platforms already set 13 as their minimum age in their terms of service. If every holder had told the truth at sign-up, any account opened more than two years before the rules apply would belong to someone who is now at least 15, and the signal would be strong. But the people the rule is aimed at are precisely those who did not tell the truth. A ten-year-old who entered a false birth year in 2025 looks like a 13-year-old at creation and will look like a 15-year-old by 2027. The date proxy inherits the error of the original self-declaration and cannot detect it.

A credit card is weaker in a different way. A card held by the account owner suggests adulthood only where card issuers restrict cards to adults. In some markets teenagers hold debit or prepaid cards, and a card attached to an app store account is often a parent’s. A card signal can therefore produce both errors: it can clear a minor who uses a parent’s payment details, and it says nothing about the large share of adults who never attach a card to a social account. The draft calls for “proportionate” checks, but none of the sources reviewed defines what proportionate means or what error rate would be tolerated.

The scale of the problem is easy to illustrate with arithmetic. A platform at the 45 million monthly-user threshold that misclassified just 1% of its accounts would be wrong about 450,000 accounts. That is an illustration, not a forecast, since the draft sets no accuracy standard. It does show why the burden-of-proof reversal matters: under the old model a regulator had to demonstrate a platform’s failure, whereas under this one the platform has to document why its estimate was reasonable.

What will shape the final text

The proposal has to pass the Parliament and the Council under the ordinary legislative procedure, and Lewis Silkin quotes the Commission as saying it is essential that the legislation is adopted swiftly. Lovguiden reports that a public feedback period opened on 5 October and runs until 26 November 2026, after which the Commission summarises the responses for the two institutions. Even the sources’ description of the sequence differs slightly, which is a reminder that the procedure is still being worked out.

The politics are not settled. TNW reports that Parliament previously called for a minimum age of 16, that Estonia opposes age-based bans altogether, and that before the proposal 13 capitals backed the expert panel’s recommendation while 15 capitals, including France, wanted a higher age limit. Industry and privacy voices raise a different objection. EU Perspectives quotes CCIA Europe, an industry group, arguing that if platforms must tell minors from adults then adults must also prove their age, and that age data becomes a target for cybercriminals. S&D member Alex Agius Saliba is reported as supporting limits on addictive features while insisting that age verification be privacy-preserving, and the Greens’ Kim van Sparrentak warned that design must change for the rules to bite. 5Rights Foundation’s Leanda Barrington-Leach welcomed the burden-of-proof reversal.

There is also a UK comparison. Lewis Silkin says the UK’s Online Safety Act already requires regulated services to protect children, with Ofcom’s codes calling for highly effective age assurance, and that the UK government plans a ban for under-16s with implementation expected from spring 2027. The EU model is more graduated, with a 15-year threshold and guardian-managed accounts in between, whereas the UK approach, as described, uses a single higher age. The two regimes could leave a platform operating in both with different cut-offs for the same teenager.

What the evidence does not establish

Several things cannot be said from the sources reviewed. The penalty level rests on two secondary reports and one silence. The treatment of existing accounts differs between summaries, so the six-month obligation could mean estimation, re-verification or disablement. No source states an application date, a required accuracy level for age estimation, or what counts as a proportionate check. The Commission’s consultation page was read only through a Danish-language summary. And a proposal of this kind usually changes between adoption and the final text, as the split between Parliament’s preference for 16 and the proposal’s 15 already shows.

For platforms and the people who advise them, the practical point is narrower than the headline. The age threshold will probably be argued over for months. The more durable question is evidentiary: what a platform will have to keep on file to show that its estimate of an old account’s age was reasonable. That is the part of the proposal where the proxy signals discussed above will either hold up or fail.