A few days ago Euractiv got hold of a document that wasn’t supposed to leave the Commission offices yet. I was landing in Paris for a media education seminar with experts from man countries, and it came just on time. The watermark is all over it, and so is the label “sensitive until adoption”. It’s the draft Communication that comes with the EU KIDS Act, the Commission’s new plan to protect children online. The document is HERE.
Let me be clear from the start: what I’m commenting on here is not the official text. It’s a leaked draft, and even the date on the first page is still “XXX”. Ursula Von der Leyen and Henna Virkkunen are presenting the Act today in Strasbourg, so details may change. And even the official text will only be a proposal. It still has to be negotiated with national governments and MEPs, which in EU time means a couple of years, at best. Still, the direction is clear enough to start talking about it.
Contents
The draft introduces a category called “Social Media+”: social media, video-sharing platforms, online games with risky design and, interestingly, AI chatbots and companions. The core is a graduated system of access:
- Under 3: nothing at all.
- 3 to 12: only parent-controlled accounts on certified “child-friendly” services.
- 13 and 14: “introductory” accounts set up by parents, with limited features, peer-only contacts, a daily screen-time cap and a guardian app to monitor everything.
- 15 and up: you can open your own account, on a platform that must be safe by design.
On top of this come the design rules. No infinite scrolling, no artificial notifications, recommender systems you can actually control, private-by-default settings, and no strangers in your DMs. Age verification becomes mandatory at signup, using the EU age verification tool… which is still a work in process, to be very generous about it. Anyway very large platforms will need the Commission’s green light before rolling out new features.
There’s also a chapter I read twice, for professional reasons: an Education package with AI literacy, teacher training, guidance through the Safer Internet Centres, and Erasmus+ support for offline spaces like youth clubs, sports, arts and libraries.
The good news
We should always give credit where it’s due, so let’s also do it here. The document says, quite literally, that we need to limit the access of tech companies to our children, not the other way around. It puts the primary responsibility on platforms, not on kids and families. This is important, this is a first, and this will have an impact.
It goes after design itself: the slot-machine mechanics that keep us all scrolling. For years many of us working in media education have been saying that the problem is the architecture, not the kid. Seeing this in an official EU document, even a leaked one, feels like a small victory.
And now the problems
Here’s the thing, though: bans on their own have never worked. Not with comics in the 50s, not with drugs in the 70s, not with video games in the 80s and 90s, not with anything teenagers were told they couldn’t touch. What a ban usually does is move the behaviour somewhere less visible, less regulated, and harder for adults to reach. And meanwhile the banned item becomes the object of desire of every teenager.
We don’t need to guess, because we have a live experiment. Australia went further than the EU plans to, with a flat ban up to 16 and no parental exceptions. It took effect on December 10, 2025. The results so far are not encouraging:
- Most kids are still there. A study by eSafety, Australia’s own internet regulator, found that more than eight in ten under-16s are still using social media, and most of them as frequently as before the ban.
- The evidence of an effect is thin. A peer-reviewed evaluation in the BMJ found insufficient evidence of a sharp drop in use, and documented substantial circumvention: fake profiles, fake ages declarations, etc.
- The workarounds are creative. Teenagers talked about using a parent’s face ID, printed face masks to fool facial recognition, and VPNs. In Italy we are kinda expert about bending the rules, so we say: “you make the rule, I find the trick”.
- Many accounts were never touched. Most kids who kept using restricted platforms didn’t even need a workaround, because the platforms never identified and removed their accounts.
- Some moved elsewhere. About 16% opened accounts on platforms that weren’t covered by the restrictions. This is exactly the displacement effect mentioned above.
- The government’s answer is to push harder. Over five million accounts have been blocked, yet the government still says platforms are falling short, and it plans to double the fines on Big Tech. Good luck with that.
So, a stricter and simpler rule than the European one, in a single country, with a regulator actively enforcing it, and it still leaks like a sieve.

Now imagine the EU version. It isn’t a simple yes/no switch but a system of tiers, guardian apps, contact limits and screen-time caps, across 27 countries with different languages, legal systems and levels of digital infrastructure. It also assumes that parents have the skills, the time and the will to configure and monitor all of this. In my experience with families and educators, that’s a very optimistic assumption. The draft itself says it wants to avoid “unduly shifting responsibility” to guardians, and then hands them an app.
Then there’s the legal side. The draft admits the complexity, and it cites the French case, where the Constitutional Council struck down the under-15 ban 18 days before it was due to start. There’s also age verification: existing accounts will only get “proportionate checks”, which sounds reasonable on privacy grounds and also sounds like the exact loophole Australia is struggling with. And the age verification system is still, as I mentioned, a work in progress with much road in front of them.
And there’s a point that EDRi made very well. If a design is harmful at 13, it doesn’t become safe on someone’s 15th or 18th birthday. Even von der Leyen admitted that addictive design is harming everyone. So why is the headline an age limit, and not the design rules for all of us?
What could be improved
The safe-by-design part is the real deal. If it survives negotiations with the lobbies intact (and that is a big IF), it could change the environment for everyone, not only for 14-year-olds. The age limit, on the other hand, is the part that makes headlines and will probably be the hardest to enforce.
What never works on its own is the forbidden approach. What works, slowly and without headlines, is education. Kids who understand how a system works, why that notification pops up at 11pm, and what a platform does with their data. Parents and teachers who are supported instead of just burdened. Youth workers and non-formal education spaces, online and offline, where young people can practise critical thinking with adults who are actually there and possibly are competent about these topics.
The draft mentions all of this, in section 3. But it has no figures and no dates, and it sits after 6 pages of rules.
I really hope that order doesn’t reflect the priorities.