Skip to main content

EU KIDS Act Would Make AI Chatbots Prove Child Safety Before Launch

4 min read

The proposed EU KIDS Act would make AI chatbots prove child safety before launch, add continuous monitoring and expose violations to turnover-based fines.

EU KIDS Act Would Make AI Chatbots Prove Child Safety Before Launch

The European Commission has proposed a KIDS Act that would put AI companions and chatbots behind a child-safety gate: providers would need to demonstrate compliance before placing them on the EU market, then keep monitoring risks and incidents after launch. The proposal is consequential, but it is not yet law.

The Commission adopted the proposal on September 17, 2026. The European Parliament and Council must now negotiate the text, so requirements, dates and enforcement details can still change. Any account that describes these rules as already in force skips the most important legal fact.

The proposal reaches beyond social media

The EU KIDS Act AI chatbots provisions matter because the Commission explicitly includes AI companions and chatbots in a package commonly discussed as a social-media measure. The policy logic is that a conversational product can create a sustained relationship with a child, even when it does not look like a traditional feed.

Covered areaProposed controlPractical question
Social mediaNo access below age 13How will age be estimated without collecting excessive identity data?
Ages 13 to 14Guardian-controlled accessWhat counts as verified and revocable consent?
Age 15 and aboveAutonomous accessHow will services handle age transitions?
AI companions and chatbotsCompliance shown before market entryWhat evidence will satisfy the safety assessment?
Post-launch operationRisk and incident monitoringWhich incidents trigger reporting or product suspension?
Requirements are summarized from the Commission proposal and explainer. The implementation questions are MustHave.ai analysis.

Pre-launch proof changes the product cycle

For an AI company, the key change is timing. A safety review would not be something added after public complaints. Providers would need evidence before market entry. That could move child-safety testing into model selection, product design, red-team exercises, data governance and launch approval.

  • Test whether the system recognizes that a user may be a minor without asking for unnecessary sensitive data.
  • Evaluate manipulation, dependency, sexual content, self-harm advice and attempts to move a conversation off-platform.
  • Document how the assistant changes behavior when guardian controls or youth settings apply.
  • Verify that safety policies survive long conversations, role play and memory features.
  • Define the evidence and sign-off required before each model or policy update ships.

This is a broader standard than checking whether an individual answer contains a prohibited phrase. A companion can create risk through tone, persistence, emotional framing and repeated interaction. Our analysis of model behavior incidents and reporting explains why process and intermediate actions need evaluation alongside final answers.

Continuous monitoring is the harder requirement

A provider can prepare a polished launch test. Continuous monitoring asks whether the product remains safe as users discover new prompts, the model changes, retrieval sources shift and memory accumulates. The Commission says covered providers would need a mechanism for risks and incidents, but the public material does not yet define a universal dashboard or benchmark.

A credible monitoring program should separate raw reports from confirmed incidents, record the model and policy version involved, preserve privacy, measure the time to containment and track whether a corrective action creates new failure modes. It should also make escalation possible when the provider cannot determine a child’s immediate safety.

The proposed fine is large, but the denominator matters

The Commission proposes maximum fines of up to 6% of total worldwide annual turnover. Turnover is revenue, not profit, and a maximum is not an automatic penalty. The actual amount would depend on the final law, the violation and enforcement decisions.

The global-turnover basis is designed to keep the penalty meaningful for large platforms. Smaller providers should not assume that size removes their duties, but proportionality and the final enforcement framework will matter.

Age assurance could create a second privacy risk

Restricting access requires some way to distinguish age groups. The danger is solving one problem by collecting identity documents, facial estimates or behavioral signals that create another sensitive dataset. The best implementation would minimize data, disclose the method, allow challenges and avoid turning age assurance into general identity tracking.

Parents and schools should also distinguish access controls from content accuracy. A system can verify age correctly and still give a harmful answer. Conversely, a safe assistant should not be assumed to have perfect age detection. These are separate controls.

What AI chatbot providers should prepare now

  1. Map where minors can encounter the product, including embedded assistants and third-party integrations.
  2. Create a child-safety risk register covering content, persuasion, dependency, privacy and off-platform contact.
  3. Version model, policy, memory and retrieval changes so incidents can be reproduced.
  4. Build guardian controls that are understandable and revocable.
  5. Define pre-launch evidence and an independent review path.
  6. Plan monitoring metrics before the proposal becomes a deadline.

Teams building assistants may also want to compare the permission questions in our Firefox Smart Window review. Browser context and youth protection are different domains, but both depend on visible, limited and revocable data access.

The practical verdict

The KIDS Act proposal treats an AI chatbot as a relationship product, not merely a text box. Its strongest idea is the combination of evidence before launch and monitoring afterward. The unresolved work is substantial: lawmakers still need to define the final obligations, while providers need safety evidence that measures more than blocked words or successful age checks.

Primary sources

Checked September 17, 2026. This article describes a European Commission proposal, not enacted law. Legal requirements may change during negotiation.

Leave a comment

Your email address will not be published. Required fields are marked *