bytevyte
bytevyte
Language
ai-beats

EU Kids Act Draft Adds AI Companion Apps to Child-Safety Rules for Under-15s

EU Kids Act

The European Commission is drafting an EU Kids Act that would set 15 as the minimum age for unsupervised accounts on social media and video-sharing platforms, and would pull AI chatbots, AI companions and online games under the same restrictions. The proposal has been circulating internally ahead of a formal pitch expected this week, and it treats conversational AI aimed at minors as a child-safety category in its own right rather than a general-purpose service.

Children aged 13 and 14 would keep a route onto social media and video-sharing platforms, but only with parental permission and with controls attached to contacts and screen time. Platforms would carry age-verification duties at the point where an account is created. Services designed for education sit among the carve-outs.

Scope is drawn as a category list rather than a definition of a single product. That list covers social networks, video-sharing services, online gaming, and AI chatbots and companions, which the draft describes as virtual tools able to give minors mental health and personal development advice. Folding companion apps into the same bracket as social platforms is the clause with the longest reach for enterprise software teams.

Why the EU Kids Act's Companion Clause Redraws the Compliance Map

General-purpose chatbots already sit inside the EU AI Act, but mostly through risk classification, transparency duties and, for some providers, obligations tied to general-purpose models. The EU Kids Act layers a second regime on top. It governs who may open an account and hold a conversation at all, which makes age assurance a product requirement instead of a documentation exercise.

For a consumer AI developer, the account-creation funnel becomes a regulated surface. A company shipping a companion app, a study assistant or a mental-health-adjacent chatbot to teenagers needs a defensible way to establish a user's age before a session begins, and an enforceable way to apply limits afterwards. The draft pairs those duties with design requirements, including safety-by-design obligations and a mandate to strip out addictive features such as infinite scrolling.

Regulating by category rather than by named product carries its own consequence. A list can absorb services that did not exist when the text was written, which removes the need for fresh legislation each time a new conversational format appears. It also leaves mixed-use products in a grey zone, and product teams will have to justify which category their service belongs to before a supervisor does it for them.

What the Draft Actually Sets Out

ElementProvision in the draft
Minimum age15 for unsupervised accounts
13-14 tierAccess with parental permission; controls on contacts and screen time
Covered servicesSocial media, video-sharing platforms, online games, AI chatbots and AI companions
Carve-outsServices designed for education
Design dutiesSafety by design; removal of addictive features such as infinite scrolling
EnforcementArchitecture modelled on the Digital Services Act and the AI Act, with supervisory fees paid by companies
PenaltiesFines of up to 6% of global sales

Age Verification Is the Hard Part

The most consequential requirement is also the least specified. Age assurance at account creation is simple to mandate and difficult to build, because it forces platforms to choose between collecting more identity data on minors and accepting weaker signals that are easy to defeat. Neither option is comfortable. Strong verification raises data-protection exposure for a group that already receives special treatment under EU privacy law, while light-touch checks invite circumvention and hollow out the regime.

National supervisors would carry the load of deciding what counts as adequate assurance, and the text does not settle on a single technical method. That gap matters for vendors building age-estimation tools, because it leaves room for divergence across markets. A company operating in all 27 member states could face several accepted approaches, each with its own integration work and audit trail.

The education carve-out creates a second definitional problem. A tutoring chatbot that answers homework questions and also offers encouragement sits somewhere between a study aid and a companion. Product teams will have to decide which side of the line their service falls on, and regulators will have to agree with them.

The Trade-offs for Platforms and for Brussels

Compliance cost lands hardest on smaller developers. Supervisory fees, verification integrations and parental-consent infrastructure are largely fixed costs, so they weigh more heavily on a startup than on a platform with an existing trust-and-safety organisation. Companies already staffing up for the AI Act and the Digital Services Act will be folding a third set of obligations into the same governance function.

The consent tier for 13 and 14 year olds adds continuous operational work. Parental approval is a one-time gate; contact controls and screen-time limits are standing duties that require dashboards, logging and appeal paths. Building that at consumer scale is a multi-quarter engineering commitment rather than a settings toggle.

Privacy is the trade-off Brussels cannot avoid. Age verification implies holding more data about minors at the moment regulators are pressing for data minimisation. A device-level or wallet-based proof of age would cut that exposure, but the draft does not require one, which leaves platforms to choose an approach and defend it.

Design duties collide with monetisation. A platform whose advertising revenue tracks time-on-app loses a lever when infinite scrolling is removed for younger users, and the same logic applies to autoplay and streak mechanics. The rules push engagement-based products toward subscription tiers or age-differentiated feature sets, and that cost falls on the revenue line rather than the compliance budget.

Market structure is the second-order effect. A regime built on fees and documented assurance favours incumbents that can spread the cost across hundreds of millions of users. Smaller AI companion developers, many of them European startups, may respond by blocking minors entirely, which satisfies the letter of the rule while withdrawing the services it was meant to make safer.

Supervisory fees turn compliance into a recurring line item, since platforms would fund the bodies that supervise them, mirroring the architecture of the Digital Services Act and the AI Act. Add a penalty ceiling of up to 6% of global sales and the exposure reaches board level rather than the legal team alone.

Timing is the remaining unknown. The Commission proposes; the European Parliament and member states then negotiate, and the staged application of the AI Act shows how long that process can run. The leaked text is a starting position, not a finished rulebook, and thresholds and carve-outs are the likeliest points to move.

What Compliance Teams Should Do Now

Two practical steps follow from the draft. Companies should inventory every conversational surface a minor could reach, including side features bundled into a broader product, and decide which category each one falls into. They should also settle on an age-assurance method early, because verification is the component with the longest lead time and the widest variation between national supervisors.

Parental consent needs to be treated as an ongoing service rather than a signup checkbox. Contact controls, screen-time limits and appeal paths all generate logs a supervisor may ask to see, and the design choices behind them need to be documented when they are made, not reconstructed later.

Why This Matters

Europe has regulated AI systems and online platforms through separate instruments, and the EU Kids Act is the first to treat conversational companions as a children's product category that needs its own gatekeeping. That moves age verification and companion design out of the trust-and-safety side project and into a compliance workstream sitting alongside AI Act obligations. The text can still change before the Commission's formal pitch and again during negotiations with the Parliament and member states, but the direction is set. For any company building conversational AI a teenager can open, the age gate and the parental consent tier are now part of the product.

Photo by Mateusz Baranowski on Unsplash

✔Human Verified


Researched and cross-referenced against primary sources by the Bytevyte editorial team. This article was generated with the assistance of artificial intelligence and reviewed by the Bytevyte editorial team.