Product1 publisher3 min readPublished
The EU's draft Kids Act makes adults prove their age to switch off child-safe defaults
EU Commission's draft Kids Act bars social media accounts for under-13s and locks the unrestricted version of covered apps behind an age check. Techdirt argues platforms will play it safe and check everyone, so adults carry the privacy cost too.
The Product Desk · Product desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- The draft moves some safety-by-design measures from the Digital Services Act's non-binding guidelines on protecting minors into hard law.
- A social media or video-sharing platform counts as risky if it relies on personalized recommendations or offers uninterrupted content consumption.
- Users aged 13 to 15 would get restricted accounts under tight parental supervision, and those aged 15 to 18 autonomous accounts in a safe-by-design environment.
- The safety-by-design rules also reach online games, AI companions, chatbots and app stores, with requirements that vary by service.
- Not-for-profit encyclopedias, scientific repositories, educational services and open-source software platforms are exempt from the proposal.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- decision A game, chatbot or app store that skips age assurance has to serve every user the child-safe default, so offering adults the full product means paying for verification.
- exposure Adults become the main audience for age checks because the check is what unlocks the unrestricted product, and Techdirt expects companies to check every user to stay safe.
- cost With no carve-out for small and medium-sized companies, a small studio builds the same verification and parent-proof flows as a large platform. Techdirt says that favours incumbents already investing in them.
- constraint Until the "high degree of confidence" test is defined, teams cannot know whether their existing age signals spare current users from being verified again.
A parent opens a video app to set up a 14-year-old's account. Before the child gets anywhere, the parent is asked to prove that they are, in fact, the parent [7]. The teenager sits behind age verification as well, which the draft applies across the board through the EU's age verification scheme [6]. Techdirt, which opposes the draft, wrote: "If this sounds complex and like a compliance nightmare, that's because it is." [22]
The Commission presents the act as a continuation of the Digital Services Act [3]. The draft changes who a product team has to check. Techdirt argues the "risky" threshold covers virtually all mainstream social and video services [10]. It does give the draft some credit for proportionality, since the tiers stop short of a blanket ban, and it notes that a French court declared such undifferentiated bans unconstitutional last month [18][9].
Under this draft, the check guards the adult version of the product. Providers must generally make child-safe design the default, and they can relax it only after age assurance establishes that the user is an adult [15]. The defaults include rules on addictive features such as infinite scrolling [16]. So the adult who wants last year's product is the one asked for proof. Techdirt expects companies to check everyone: "most companies are well-advised to play it safe and use privacy-unfriendly age checks across their platforms," it wrote [13].
Under a headline saying the act won't keep the internet accountable [23], Techdirt makes its case on privacy and concentration. Age gates, it argues, create an infrastructure for control and entrench big tech's power [20]. It lists strong enforcement as one of the draft's four pillars without describing what that enforcement involves [21].
The first question for an operator is whether the service meets the risky threshold [4]. If it does, the age check is required. What is left to decide is how little the check collects, and whether current age signals clear the "high degree of confidence" bar that spares existing accounts [8]. If the service falls only under safety by design, as a game, chatbot or app store might [14], the second question is whether adult retention depends on the features the child-safe default removes. Test that with retention and usage depth among adults, with infinite scroll on and off, and ignore time-in-app.
For that second group, I'd recommend this: if adults stay without those features, give everyone the child-safe default and ask nobody for proof. A provider that runs no age assurance simply keeps the default for all users [1]. The cost is that adults lose features some of them chose, and every age group gets the same product. If adult retention does fall, the team is building age assurance and taking on the privacy cost Techdirt says the act imposes on all users [17].
What to watch
- A definition of the "high degree of confidence" test would settle how many existing accounts escape fresh age checks.
- Whether an exemption for small and medium-sized companies is added as the draft moves forward.
- Whether the age assurance needed to relax safety-by-design defaults must run through the EU age verification scheme used for the social media tiers.