❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

EU Kids Act Won't Keep the Internet Accountable and Trustworthy

21 September 2026 at 12:27

The EU Commission draft law to restrict young people’s access to the internet that it presented last week will come at a high cost: it will put online services behind age gates, expand the use of intrusive age verification, and undermine the privacy of all users. 

The EU Kids Act aims to protect children from risks associated with social media, video games, and AI systems by introducing age-based access rules, safety requirements, and stronger enforcement and oversight measures. It presents itself as building on the Digital Services Act (DSA) and puts into “hard law” some of the safety-by-design measures specified in the non-binding DSA guidelines on minors’ protection. 

The proposal is built around the following elements: social media age “delay”, safety by design, age assurance and parental responsibility, and strong enforcement. Each of these measures are concerning.  

Mandatory Age Gates for Social Media and Video-Sharing Platforms 

Following the advice of an expert panel, the proposal would create a phased access to social media and video-sharing platforms deemed risky—a threshold met simply by relying on personalized recommender systems or offering “uninterrupted content consumption”: no service accounts for children under 13; restricted accounts under tight parental supervision from 13 to 15; and autonomous accounts in a safe-by-design environment from 15 to 18. Full online access is therefore reserved for adults. 

However they’re designed, age gates undermine civil liberties, reduce safety, and create barriers to internet entry, often at the expense of marginalized groups.

If this sounds complex and like a compliance nightmare, that’s because it is. The access delay comes with privacy-intrusive age verification across the board, relying on the EU age verification scheme. For teenagers, this law means significant control in the hands of their parents, who must set up accounts and prove that they are, in fact, parents, adding yet another problematic layer of verification. 

In fairness, the Kids Act’s gradual approach at least appears to be designed with some proportionality considerations, rather than imposing a blanket social media ban. Just last month a French court declared such undifferentiated bans unconstitutional. The EU Kids Act distinguishes between age groups and certain services and follows a risk-based approach. This means, for example, that age verification is not required for existing accounts if the provider can tell with a “high degree of confidence” that the user is above the age threshold—a vaguely specified standard.  

Yet, the law still indiscriminately covers social media and video-sharing, with virtually all mainstream services being covered by the proposal. The broad scope also sits uneasy with the use of age thresholds, which remain a blunt proxy for maturity. What is more, by focusing heavily on safety and harms, the EU Kids Act pays little attention to the privacy and freedom of expression rights of users, as well as the right of children themselves to access information and to participate online. However they’re designed, age gates undermine civil liberties, reduce safety, and create barriers to internet entry, often at the expense of marginalized groups. They also create a powerful infrastructure for control and further entrench the power of big tech. 

The proposal exempts not-for-profit encyclopedias, scientific repositories and educational services, as well as open-source software-developing and-sharing platforms. However, no exceptions are foreseen for small and medium-sized enterprises, which will only foster the dominance of resource-laden tech companies that were already investing in similar measures. And we know that most companies are well-advised to play it safe and use privacy-unfriendly age checks across their platforms. 

Safety by Design Across Covered Services 

The proposal’s second pillar, “safety by design”, casts a wider net. It applies across social media, video-sharing, online games, AI companions, chatbots and even app stores—with varying requirements. Providers must generally make child-safe design the default and can relax from the requirements only if they use age assurance to establish that the user is an adult. 

For example, rules on addictive features such as infinite scrolling, safe account settings, and more choice over recommender systems are to provide a safe internet experience to young people. As regards AI companions and chatbots, the proposal requires companies to design their services to reduce minors’ exposure to emotional dependencies and harmful interactions. Online games are covered as well: they must come with contact protections. The law also makes app stores the gate keeper for age-appropriate access, based on an age-rating system. 

The devil of these measures lies in the details, but all of them raise fundamental rights concerns and some of them seem poorly suited, if at all, to the decentralized architecture of the Fediverse. The requirement for very large online platforms to set up compliance plans before rolling out new services raises additional questions about the risks of transplanting product-safety doctrines of conformity and risk control into speech regulation. Deciding what is “safe” can easily become a question of what content people can access or share.  

Next Steps  

By choosing to regulate all these aspects through the Kids Act, the Commission not only but creates a privacy minefield, it also intermingles the digital fairness agenda with the more fundamental-rights heavy questions of age assurance and access to information. An unfortunate policy choice that will politicize well-intentioned efforts to curb manipulative and addictive design practices (read our position on the DFA). 

It speaks volume that the Kids Act has not gone through a full impact assessment process, which would typically require a systemic check of alternative policy options and stakeholder consultations. Looking forward, we call on the EU lawmakers to pull the teeth of the most harmful suggestions and to make sure that the new measures don’t erode the fundamental rights of all users. 

New EU Court of Justice Ruling on Platform Liability Could Cause Collateral Damage to Freedom of Expression

Intermediary liability laws around the world recognize that social media platforms, search engines, and other online service providers have become an integral part of our lives: they shape how we access information, communicate with others and participate in public debate, and foster innovation online. These laws generally shield platforms, to varying degrees, from legal liability for user content: the responsibility for unlawful speech should rest primarily with the speaker, not with those who merely host it.  

These liability protections are not a gift for platforms. They exist so that platforms are not encouraged to proactively monitor and filter what we say online, or to remove even lawful speech simply to avoid legal risk. 

This is why a recent judgment by the EU Court of Justice, Coyote System (Joined Cases C-188/24 and C-190/24), is concerning: it could deprive online platforms of liability protection because of how they organize and disseminate user content. The consequences for freedom of expression could be significant. 

Liability Protections in the EU 

The European Union has long embraced a system of limited liability for online service providers. Under the e-Commerce Directive and now the Digital Services Act (DSA), platforms benefit from liability exemptions for user content. To discourage censorship, they also cannot be required to generally monitor user content or actively search for illegal activity. But that liability protection comes with qualifications: Platforms lose this benefit if they play an "active role" such that they have knowledge of, or control over, user-provided information (Recital 42 ECD, Recital 18 DSA, and case law, for example para. 113 in L’Oréal v eBay). For hosting services, providers must remove or disable content they know to be illegal. The DSA has introduced extensive due diligence obligations for platforms but left these foundational immunities intact. The message is clear: platforms bear responsibility for proper systems and processes, but generally not for users' speech. 

Coyote System, however, could undermine this balance. Confronted with a case about restrictions on navigation systems that transmit information to drivers about roadside checks, the Court formulated a general test for when an intermediary ceases to be a "neutral" host and therefore loses the hosting liability exemption. In essence, the Court held that where an intermediary's algorithm goes beyond merely categorizing and indexing user information to determine, "under what conditions, how and in which order of priority" (para. 122) information is disseminated, the intermediary "controls" that information and is deprived of protection under the e-Commerce Directive. 

Let's be clear: the case is not about a service that ranked or recommended user-generated content in the way social media platforms do. It is about the collection and real-time relay of user alerts about roadside checks. However, the Court's reasoning is not confined to navigation services. Recommendation algorithms determine how and in what order user content is disseminated across virtually every major online platform. Should such platforms now cease to qualify as neutral intermediaries and lose the protection of the hosting liability exemption? The answer should be no. 

The Meaning of Control 

Control has never been understood this broadly. Nor should it be. Every hosting service provider, think of Facebook, Amazon or Bluesky, will have some control over users’ content. If that ability alone ruled the analysis, the liability exemption would become largely meaningless. Instead, the disqualifying “active role” must relate to the actual content itself, not merely the technical means by which that content is organised or disseminated. 

The Court’s own case law reinforces this conclusion: In YouTube and Cyando, it examined a platform that categorises, ranks and recommends user content through algorithms, yet still proceeded on the basis that it could generally benefit from the hosting liability exemption. To be sure, the Court was mainly addressing specific knowledge of illegal content rather than the separate category of control. Even so, the underlying premise is clear: those features do not, by themselves, place a platform outside of protection. Advocate General therefore explained that what matters is the provider's "intellectual control of that content" (para 152). The relevant question is who controls the information itself, makes it their own, not who determines how it appears. 

That is precisely where Coyote System breaks new ground and offers a dangerous change of emphasis. By equating algorithmic organisation with content control, the ruling risks excluding social networks and other platforms from the liability exemption and encouraging proactive monitoring of what users say online and removal of lawful content. 

That outcome would have terrible consequences for freedom of expression in the EU. It’s also difficult to reconcile with the structure of the DSA, which certainly does not treat recommendation algorithms as incompatible with intermediary immunity. On the contrary, it accepts them as a defining feature of modern platforms, regulates them extensively through dedicated due diligence obligations, and still leaves the hosting liability regime untouched (it even integrated the YouTube ruling in its preamble!).  

This was no accident: During the DSA negotiations, proposals to deprive platforms of the hosting liability exemption if they optimize, classify, organize or otherwise promote online content were rejected, following successful advocacy by EFF and allies. Would the Court have decided this case differently under the DSA? Probably not. It’s more plausible that the EU judges were influenced by the specific nature of the service, which could explain why the judgment says remarkably, and sadly, little about why intermediary liability exists in the first place and the fundamental rights it serves. Coyote System did not merely transmit user reports but aggregated them into what the Advocate General described as a new "information layer," a distinction omitted by the Court. 

Chipping Away at Intermediary Liability Protections 

The danger is that the Court's broad language on algorithmic curation reaches well beyond that narrow category and, unintentionally or not, chips away at one of the most important safeguards for freedom of expression online.  

Unfortunately, Coyote System does not stand alone. It is the latest in a line of judgments that have gradually narrowed intermediary liability protections. Recently, in Russmedia, the Court privileged preventive content control in the name of data protection, paying little regard to the possibility of reconciling both regimes and the privacy costs of increased monitoring of user content. And in AGCOM, concerning Google's liability for YouTube videos uploaded by creators participating in its Partner Programme, the Court appears to leap from eligibility reviews to specific knowledge of illegal content. 

There is a political risk too. While the top court’s reasoning will be applied by national courts and further refined over time, the European Commission has shown little hesitation in incorporating landmark rulings into legislation. Just recently, in its digital omnibus proposal, it selectively restated part of a recent Court of Justice judgment to justify narrowing privacy rights of users. 

If these trends continue, freedom of expression online will become collateral damage in the EU. 

Getting Digital Fairness Right: EFF's Recommendations for the EU's Digital Fairness Act

Digital Fairness in the EU

The next few years will be decisive for EU digital policymaking. With major laws like the Digital Services Act, the Digital Markets Act, and the AI Act now in place, the EU is entering an enforcement era that will show whether these rules are rights-respecting or drift toward overreach and corporate control. With the proposed EU’s Digital Fairness Act (DFA), the Commission is now turning to increasingly visible risks for users, such as dark patterns and exploitative personalization. Its “Digital Fairness Fitness Check” makes clear that existing consumer rules need updating to reflect how digital markets operate today.

But not all proposed solutions point in the right direction. Regulators are already flirting with measures that rely on expanded surveillance, such as age verification mandates—surface-level fixes that risk undermining fundamental rights while offering little more than a false sense of protection.

For EFF, digital fairness means addressing the root causes of harm, not requiring platforms to exert more control over their users. It means safeguarding privacy, freedom of expression, and the rights of users and developers.

If the DFA is to make a real difference, it must tackle structural imbalances. Lawmakers should focus on two interlocking principles. First, prioritize privacy. Reforms should address harms driven by surveillance-based business models, alongside deceptive design practices that impair informed choices. Second, strengthen user sovereignty, which is also a necessary precondition for European digital sovereignty more broadly. Strengthening user sovereignty means taking measures that address user lock-in, coercive contract terms, and manipulative defaults that limit users’ ability to freely choose how they use digital products and services.

Together, these principles would support the EU’s objectives of consistent consumer protection, fair markets, and a more coherent legal framework. If implemented properly, the EU could address power imbalances and build trust in Europe’s digital economy.

Ban Dark Patterns

Dark patterns are practices that impair users’ ability to make informed and autonomous decisions. Many companies deploy these tactics through interface design to steer choices and influence behavior. Their impact goes beyond poor consumer decisions. Dark patterns push users to share personal data they would not otherwise disclose and undermine autonomy by making alternatives harder to access.

The DFA should address this by clearly prohibiting misleading interfaces that distort user choice in commercial contexts. While the Digital Services Act introduced a definition, it only partially bans such practices and leaves gaps across existing consumer law rules. The DFA should close these gaps by, at the very least, introducing explicit prohibitions and clearer enforcement rules, without resorting to design mandates.

Tackle Commercial Surveillance

At the core of digital unfairness lies the pervasive collection and use of personal data. Surveillance and profiling drive many of the harms regulators are trying to address, from dark patterns to exploitative personalization. The DFA should tackle these incentives directly by reducing reliance on surveillance-based business models. These practices are fundamentally incompatible with privacy and fairness, and they distort digital markets by rewarding data exploitation rather than quality of service. At a minimum, the DFA should address unfair profiling and surveillance advertising by strengthening privacy rights and banning pay-for-privacy schemes. Users should not have to trade their data or pay extra to avoid being tracked. Accordingly, the DFA should support the recognition of automated privacy signals by web browsers and mobile operating systems, which give users a better way to reject tracking and exercise their rights. Practices that override such signals through banners or interface design should be considered unfair.

Addressing surveillance and profiling also protects children, since many online harms are tied to the collection and exploitation of their data. Systems that serve ads or curate content often rely on intrusive profiling practices, raising concerns about privacy and fairness, particularly when applied to minors. Rather than turning to invasive age verification, the focus should be on limiting data use by default.

Strengthen User Sovereignty

There is a major gap in how EU law addresses user autonomy in digital markets: many digital products and services still restrict what people can do with what they pay for through opaque or one-sided licensing terms, technical protection measures, and remote controls. These mechanisms increasingly limit lawful use, modification, or access after purchase, allowing providers to revoke access, disable functionalities, or degrade performance over time. In practice, this turns ownership into a conditional rental.

Consumers must be able to use and resell digital goods without hidden limitations and with clear licensing terms. Too often, technical and contractual lock-ins, including remote lockouts and unilateral restrictions on functionality, erode that control. Recent legal reforms show that progress is possible. Rules such as those under the Digital Markets Act have begun to curb technical and contractual barriers and promote user choice. However, many restrictions persist.

The DFA must address these practices by targeting unfair post-sale restrictions and strengthening users’ ability to control and switch services. This means setting clear limits on unfair terms and misleading practices, alongside robust transparency on how digital services function over time. It should also strengthen interoperability and support user control, allowing people to access third-party applications and to let trusted applications act on their behalf, reducing lock-in and expanding meaningful choice in how users interact with digital services.

EU Parliament Blocks Mass-Scanning of Our Chats—What's Next?

The EU’s so-called Chat Control plan, which would mandate mass scanning and other encryption breaking measures, has had some good news lately. The most controversial idea, the forced requirement to scan encrypted messages, was given up by EU member states. And now, another win for privacy: the EU Parliament has dealt a real blow to voluntary mass-scanning of chats by voting to not prolong an interim derogation from e-Privacy rules in the EU. These rules allowed service providers, temporarily, to scan private communication.  

But no one should celebrate just yet. We said there is more to it, and voluntary scanning is a key part. Unlike in the U.S., where there is no comprehensive federal privacy law, the general and indiscriminate scanning of people’s messages is not legal in the EU without a specific legal basis. The e-Privacy derogation law, which gave (limited) cover for such activities, has now expired. Does that mean mass scanning will stop overnight?  

Not really. 

Companies have continued similar scanning practices during past gaps. Google, Meta, Microsoft, and Snap have already signaled in a joint statement to “continue to take voluntary action on our relevant Interpersonal Communication Services.” Whether this indicates continued scanning of our private communication is not entirely clear, but what is clear is that such activity would now risk breaching EU law. Then again, lack of compliance with EU data protection and privacy rules is nothing new for big tech in Europe. 

Most importantly, the “Chat Control” proposal for mandatory detection of child abuse material (CSAM) is still alive and being negotiated. It has shifted the focus toward so-called risk mitigation measures, such as problematic age verification and voluntary activities. If platforms are expected to adopt these as part of their compliance, they risk no longer being truly voluntary. While mass scanning may be gone on paper, some broader concerns remain.  

So, where does this leave us? The immediate priority is to make sure the expired exception for mass scanning is not revived. At the same time, lawmakers need to pull the teeth from the currently negotiated Chat Control proposal by narrowing risk mitigation measures. This means ensuring that age verification does not become a default requirement and “voluntary activities” are not turned into an expectation to scan our communications.   

As we said before, this is a zombie proposal. It keeps coming back and must not be allowed to return through the back door. 

❌
❌