What to Know About the EU’s Plans to Restrict Social Media for Under-15s: Dr. Vasilis Ververis Answers Key Questions
On September 17, the European Commission proposed the EU KIDS Act, which would ban social media for children under 13 and allow teenagers to create their own accounts on social media only from the age of 15. For children aged 13 to 15, the officials proposed parental controls that enable guardians to set up mini accounts, which children access through the guardian's account. These mini accounts would come with limited social contacts and screen time of up to one hour per day, the EU Commission states.
Children aged 3 to 13 could not access social media, but they could "access specially designed child-friendly video-sharing services through accounts managed by their guardian," as mentioned on the official website. Platforms would also have to give parents an easy tool to restrict their own device to such services when handing it to a child, with the same one-hour daily limit. Platforms will also have to show that their services are age-appropriate and safe.
Ursula von der Leyen, President of the European Commission, and Henna Virkkunen, Executive Vice President of the European Commission, at the press conference on the EU Kids Act
European Commission
The Commission introduces a "safety-by-design" principle for social media, video-sharing platforms, online games, AI tools and chatbots used by minors. It bans addictive features, such as “recommender feeds based on profiling, infinite scroll without stopping points, reward tricks, push notifications during sleeping hours, and unsolicited contact from strangers”. AI agents and chatbots must not simulate relationships in ways that create emotional dependence.
Online services and app stores must use age-assurance tools, for example, the EU age-verification app. Social media and video-sharing platforms will have to verify a user's age when a new account is opened. For existing accounts, platforms need to estimate a user's age based on reasonable indicators, such as the account creation date or credit card details.
How Does the Commission Justify Its Proposal?
“Around 97% of young people in the EU use the internet daily, and social media is the main source of information for 65% of them,” the European Commission states.
At the same time, while taking into account the EU Charter of Fundamental Rights and children’s rights to freedom of expression and access to information, the European Commission underlines that “while young people are digital natives, their impulse control and understanding of threats is sometimes lacking.” The Commission points to particular platform features designed to keep users engaged, promote violent and rage-bait content, and collect personal data for targeted advertising.
The mechanisms proposed by the EC are intended to reduce the risks of “cyberbullying, privacy breaches, misinformation, harmful or illegal content, sexual exploitation” to children’s physical and mental well-being. According to the Commission, citing a recent Eurobarometer poll, 92% of EU citizens believe that protecting children online should be a high priority.
What Is the Background of the Age-Verification App?
In 2026, the European Commission formally asked all EU Member States to deploy a standardized EU age-verification app by the end of this year, either as a standalone application or as an integration into national or EU digital identity wallets, framing it as a key tool to protect children from harmful online content while preserving user privacy. This initiative is supposed to allow EU users to prove they are old enough, starting with being over 18 years of age, to access adult-restricted online content, such as pornography, gambling, purchasing alcohol, and others.
In a joint statement, Commission President Ursula von der Leyen and executive vice president Henna Virkkunen announced that “our European age verification app is technically ready and soon available for citizens to use” and declared that platforms now have “no more excuses” not to protect children online.
The age verification system allows users to prove they are over 18 without sharing any other personal information and is announced as fully interoperable with future European Digital Identity Wallets. Also referred to as the “mini wallet”, it is a precursor focused on proof of age only and is built on the same technical specifications as the European Digital Identity Wallets that are to be implemented by the end of 2026 in all EU Member States.
Which Member States Are Piloting the App?
According to the Commission, Denmark, France, Greece, Italy, Ireland, Cyprus and Spain have agreed to be the first Member States to pilot the technical solution with a view to publishing customised national age verification apps. These national implementation choices will likely shape whether the system is experienced in practice as genuinely privacy-preserving or as a broader identity-control layer embedded within domestic digital identity infrastructures.
Could These Measures Undermine Children's Rights?
Some civil society organisations have argued that age verification mandates for online services could undermine children’s fundamental rights if they are used primarily as exclusionary tools rather than as part of a broader safety and support strategy.
European Digital Rights (EDRi), drawing on OECD analysis and the UN Committee on the Rights of the Child, stresses that children have rights to participation, expression, information and play in digital environments, and that these rights may only be restricted where “necessary and proportionate”.
EDRi argues that restricting children’s access to online spaces “for their own safety” is an uneven risk mitigation measure when significant room remains to improve safety by reforming platform design, moderation, and support services before resorting to blunt exclusion. It emphasises that children need and deserve online spaces where they can meet others to build relationships, finding comfort and safety, exchange ideas, as well as learn and play. The experts warn that strict age-based restrictions are likely to be widely circumvented by young people, potentially creating new risks while possibly failing to deliver the promised protections.
Does the App Raise Privacy Concerns?
From a privacy perspective, experts at The Internet Engineering Task Force (IETF) warn that mandatory age verification will inevitably erode the anonymity online and access the Internet without being bound to an identification process. This has direct implications for the right to privacy in the digital age, as recognised by the UN Human Rights Council, because these measures will increase the amount of personally identifiable or linkable data collected and processed as a condition of ordinary internet use.
Security-focused critiques argue that while age verification is framed politically as a child safety measure, its practical implementation could lead to normalise an identity check infrastructure across the internet for general purposes. Once a mechanism for identity verification, including age, exists at scale, it rarely remains confined to its original purpose or to the systems built to require it. What concerns technical specialists is that the same infrastructure could become available to whichever actor is best positioned to compel, purchase, or otherwise acquire access, including governments or private entities, who are eager to force individuals to disclose personal information, but are unable to do so now lawfully.
Illustrative photo
Helena Lopes/ Pexels
What Do Academics Say About the Age-Verification App?
While no letter can speak for the entire academic community, but in March 2026, 438 security and privacy scientists from 32 countries published a joint open letter calling for a moratorium on the large-scale deployment of age-assurance systems for online services. The signatories argue that policymakers are moving ahead with mandatory age checks without first establishing, at a scientific level, whether such systems are effective and what their full security and privacy impacts are.
The letter identifies two issues: whether age assurance is in fact efficacious at achieving its stated policy goals, and what harms large-scale deployment might cause to individual and national autonomy, equality, security and privacy. The open letter describes the EU Commission measures as “dangerous and socially unacceptable” for introducing a massive access-control infrastructure without a clear understanding of these implications, and therefore urges to pause until a robust evidence base and technical consensus have been established.
Who Is Developing the App?
The development of the age verification blueprint and its supporting code base is being carried out by the T–Scy consortium, composed of Scytáles AB (Sweden) and T–Systems International GmbH (Germany), under a two-year contract awarded by the Commission in early 2025.
The Commission’s FAQ states that the app will work “with Apple, Google and other app stores to whitelist only official versions of the AV app,” indicating that, in principle, distribution is not limited to the two dominant mobile ecosystems.
However, developer documentation and issue tracking around the reference implementation show that the Android client relies on Google Play Integrity API , and the iOS client on Apple's App Attest, which in practice tightly couples the solution to Google Play and the Apple App Store.
This dependency effectively blocks installation from alternative app stores such as F-Droid, IzzyOnDroid, or other repositories, and excludes many privacy-oriented Android distributions such as GrapheneOS, LineageOS or CalyxOS, unless Member States or third parties produce parallel builds that do not depend on those proprietary integrity services.
Natasha Kondrashova contributed to the blog post