Europe Wants Real Social-Media Age Limits. That Means Finding a Way to Prove Your Age

Illustration of an EU social-media age-verification screen showing age thresholds under the proposed KIDS Act.

Europe wants to stop children under 13 from having social-media accounts and prevent teenagers from opening independent accounts until they turn 15.

Making that rule actually work creates a harder problem.

Platforms have to know how old their users are.

The European Commission formally proposed its EU KIDS Act on Thursday, setting out an EU-wide system intended to replace the largely ineffective age declarations currently used across much of the internet.

Under-13s would not be permitted to have social-media accounts. Children aged 13 and 14 could use limited accounts created and supervised by a parent or guardian, while independent accounts would become available from 15.

The legislation goes considerably further than age limits. Services used by children would face restrictions on addictive design, profiling-based feeds and unsolicited contact, while AI companions and chatbots would have to meet specific child-safety requirements. The largest platforms would also have to demonstrate that their services are safe by design rather than waiting for regulators to establish harm afterwards.

Companies that fail to comply could ultimately face fines reaching 6% of worldwide annual turnover.

The proposal still has to be negotiated with EU member states and the European Parliament, meaning its final provisions could change before becoming law.

But one practical problem will survive almost any version of the legislation.

A social-media age limit means little if platforms cannot tell a 12-year-old from a 16-year-old.

Current systems often rely on users entering their own date of birth. A child encountering a box asking whether they are 13 can simply provide a different birthday.

The KIDS Act is intended to replace that honour system with age assurance robust enough to enforce the rules. Self-declared age would no longer be sufficient, existing accounts would have to be checked and platforms would need certified mechanisms for establishing whether users meet the relevant threshold.

That is where child protection meets privacy.

Establishing somebody’s age requires information about them. The more reliable the check becomes, the greater the risk that age verification turns into identity verification.

A platform could potentially ask for an identity document. Other systems can rely on independent digital credentials or techniques that establish whether somebody is above or below an age threshold without revealing their identity to the service itself.

Those approaches carry very different privacy risks.

A system that tells a platform only that a user is “over 15” reveals much less than handing the platform a passport containing a name, photograph, nationality and date of birth.

The Commission says its approach is designed around that distinction. Platforms would not themselves check identity documents. Certified independent tools, including a planned EU age-verification app and eventually the European Digital Identity Wallet, would instead provide confirmation that a user falls above or below the relevant threshold.

The proposal requires zero-knowledge proof technology intended to prevent those checks from identifying, locating, tracking or profiling the user. Member states would also have to provide at least one free method of proving age, including for people without a digital identity.

Technology industry groups remain sceptical. CCIA Europe argues that collecting age information and credentials at population scale could create new privacy and cybersecurity risks, particularly where systems also need to establish relationships between children and parents or guardians.

That criticism does not remove the enforcement problem.

If Europe genuinely intends to prevent under-13s from creating social-media accounts, some mechanism has to distinguish them from older users. Asking platforms to enforce an age restriction while denying them any reliable method of establishing age would reproduce the system the legislation is intended to replace.

The difficult question is therefore not whether age should be checked, but how much information the check needs to reveal.

That matters because age assurance will not affect only children.

To identify users who are under 13 or under 15, services need some method of establishing that everybody else is older. The Commission says most adults should not face a new check where a platform can already determine with high confidence that they are adults, but users whose age cannot be established may have to prove it.

Europe is effectively trying to create an internet on which a service can know that somebody is old enough without necessarily knowing who that person is.

If that works, meaningful age restrictions could become considerably more enforceable without requiring websites to accumulate copies of passports or build detailed identity profiles of their users.

If it does not, governments may face an uncomfortable choice between weak age restrictions and increasingly intrusive verification.

The KIDS Act attempts to avoid that choice by treating privacy-preserving age assurance as part of the child-safety system rather than as an exception to it.

There is another significant change in where the Commission wants responsibility to sit.

The proposal is not simply telling parents to manage children’s internet use more carefully. It would place obligations directly on the companies designing the services children use.

Infinite scrolling, algorithmic profiling, AI companions and other features would no longer be treated simply as neutral products that parents are expected to supervise. Platforms would have to demonstrate that services reaching children are designed appropriately for them.

Parents would still control the limited accounts available to 13- and 14-year-olds. But parental controls would sit alongside platform responsibility rather than replacing it.

That represents a broader shift in European internet regulation: from asking whether harmful content can be removed after the event towards asking whether products used by children should have been designed differently in the first place.

The legislation now faces negotiations in Brussels, where its age thresholds, technical requirements and enforcement mechanisms can still change.

The central implementation problem will remain.

Europe can write 13 into the law.

Making 13 mean something online requires a system capable of distinguishing the child from the adult.

The success of the KIDS Act may therefore depend on whether Europe can answer a deceptively difficult question:

Can the internet reliably learn how old you are without having to learn exactly who you are?

Sources

Share this story