Back to Blog
Data Protection

Off by Default Under 15: The EU KIDS Act Moves the Burden of Proving Age Onto You

Origami TeamData Protection
8 min read
Off by Default Under 15: The EU KIDS Act Moves the Burden of Proving Age Onto You
Like what we publish? Pin Origami as a preferred source on Google.Add as a preferred source on Google

Off by Default Under 15: The EU KIDS Act Moves the Burden of Proving Age Onto You

On 17 September 2026 the European Commission adopted its proposal for the EU KIDS Act. The short version: any digital service a minor in the EU might use — a social network, a video platform, a game, an app store, or an AI chatbot — has to demonstrate that it is safe by design rather than wait for a complaint. Under 13, no independent account at all. Between 13 and 14, a supervised mini account under parental controls. Independent accounts start at 15. AI chatbots and AI companions are switched off by default for minors. Non-compliance carries fines of up to 6% of total worldwide annual turnover.

The proposal is not law yet — it still has to be negotiated with the European Parliament and the member states. But the direction of regulation is now clear enough to affect technical decisions you are making in your product today.

What actually changed in the rule

Earlier rules asked one question: did you take the harmful content down after it was reported? The KIDS Act flips it and asks instead: did you design the service so that someone too young to use it never got in? The Commission's own framing is that the proposal reverses the burden of proof and puts it on the service provider.

The scope is wider than most people assume. This is not only about the large social platforms. It covers games, app stores, and video-sharing services with proven risky features, and it explicitly covers AI chatbots and AI companions. Put differently: if your product has an assistant that talks to the user, you are in scope even if you are not a social media company.

The clause that matters to anyone who added an AI assistant

This is the most important part for any business that bolted a chatbot onto its store or app over the last two years. The proposal requires that AI companions must not simulate human relationships in ways likely to create emotional dependency. In practice that translates into different default behaviour: conversations do not carry memory forward between sessions by default, and access for under-13s runs only through parental controls.

It also adds an obligation that has nothing to do with the interface: chatbots must be tested for child-safety risks before launch and monitored after it. Anyone running an AI assistant without a reviewable conversation log and without a way to measure how it behaves will find they cannot prove anything when asked.

Age assurance does not mean collecting ID photos

The most common misunderstanding is that age verification means collecting identity documents from users — which is the worst thing you can do to your own database. The Commission's text goes the other way: verification runs through certified solutions that are independent of the platforms, including a free EU age verification app and the European Digital Identity Wallet, and uses zero-knowledge proof technology so the platform receives a yes-or-no answer about an age threshold without learning who the user is or where they are.

That design is worth copying well outside Europe. The general principle: take the answer you need, not the data that produces it. If your decision is allow or deny, you need one boolean — not a record holding a date of birth and an ID number that becomes your security liability forever.

There is an operational detail many will miss: existing accounts. The proposal requires providers to disable existing underage accounts within six months of the rules taking effect. So the work is not confined to a new sign-up screen; it reaches into your current user base and what you actually know about it.

Design patterns that used to count as growth smarts and are now violations

A large part of the proposal is not about content at all but about interface mechanics built to stretch the session. For minors, the banned list includes:

  • Endless autoplay and infinite scrolling with no real break.
  • Notifications designed to pull the user back that are unrelated to anything they actually did.
  • Rewards for posting to mass audiences.
  • Streak mechanics that penalise a user for missing a day.
  • Tracking-based recommender feeds, messages from strangers, and public-by-default profiles.

The point for non-social products: those same patterns live inside plenty of loyalty apps, stores, and education apps. If part of your growth model rests on a daily streak and evening notifications, understand that this model is under rising regulatory pressure — and not only in Europe.

Does this reach you as a Saudi business

In three clear cases. First, if you have users inside the EU: European rules follow the user, not the company's headquarters, and a Saudi game or education app published globally on both stores qualifies. Second, if you are a supplier to a European entity, where the obligation reaches you through the contract and the audit requirements. Third, and the one that bites most often in practice: the two app stores translate rules like these into publishing conditions. What starts as European regulation usually ends up as a clause in App Store and Google Play review that applies to everyone.

Locally, Saudi Arabia's Personal Data Protection Law already addresses the data of people who lack full legal capacity, requires guardian consent in those cases, and binds you to data minimisation. The difference is that the European proposal adds a product-design layer on top of the data-protection layer. The good news is that preparing for one is very nearly preparing for the other.

What your technical team should do this quarter

You do not need a large compliance programme right now — four steps that fit into weeks will do:

  • Know your ages. Does your system even know which users might be minors? Most products cannot answer that, and it is the first gap.
  • Separate minor settings from adult settings in code. Make it a switchable flag in the permissions layer, not a condition scattered across the UI.
  • Fix the defaults. AI assistant off, profile private, no messages from strangers, no night-time notifications. Changing a default is far cheaper than rebuilding a feature later.
  • Document the testing. If you run a chatbot, keep a safety-test record for every release. The document itself is your evidence.

The rule we build by at Origami is simple: a design that does not know its user's age cannot protect them, and cannot protect you either. Everything above is implementable in any properly built product without a rewrite.

Sources

#Data Protection#EU KIDS Act#Age Verification#App Design

Frequently asked questions

Our app is Saudi and our users are in the Kingdom — does the EU law apply to us?+

Not directly, as long as you have no users inside the EU, because the rules follow the user's location rather than the company's headquarters. Watch two things, though: if your app is published globally on the App Store or Google Play you may have European users without realising it, and both stores tend to convert rules like these into publishing conditions that apply to everyone.

Does age verification mean asking users for ID photos?+

No — the opposite is intended. The European proposal relies on certified solutions independent of the platform, including the EU age verification app and the Digital Identity Wallet, using zero-knowledge proofs that return a yes or no on an age threshold without revealing identity. Collecting ID images increases your security liability with no regulatory benefit.

We have a chatbot in our store — what has to change?+

Three things: it must be off by default for users below the age threshold, it must not be designed to create emotional attachment or simulate a human relationship, and you need a pre-launch safety test record plus post-launch monitoring. In practice that means an age flag in the permissions layer and a reviewable conversation log.

When does the law take effect?+

It has not taken effect yet. What happened on 17 September 2026 was the Commission adopting the proposal, which still has to be negotiated and approved with the European Parliament and the member states. The text points to a six-month window to disable existing underage accounts once the rules apply, so the practical runway is shorter than it looks.

Follow Origami in Google

Pin Origami as a preferred source and our articles will surface first for you in Google Search and Top Stories.

Add as a preferred source on Google

Related articles

Have a project in mind?

We build custom systems, apps and websites for your business. Tell us your idea and we will give you a straight answer on it.

One session. Twenty minutes. No commitments.