In brief: The European Commission proposes common age tiers for social networks and video platforms, plus safe defaults for more digital services. Beyond banning accounts below 13, certified age assurance and pre-launch checks would become an access layer for platforms and AI chatbots. Parliament and the Council must still negotiate the draft.
Three age tiers and a wider scope
Children under 13 would have no social-media accounts. Thirteen- and fourteen-year-olds could use only guardian-created “mini accounts”, limited to one hour daily and approved contacts. Independent accounts would be possible from 15, while safe-by-design duties continue until 18. These account rules target social networks and video services with demonstrated risky features.
The product duties reach further, covering online games, app stores, operating systems, AI chatbots and companions. For minors, the proposal bans infinite scrolling without real breaks, manipulative notifications, broadcasting rewards and punitive streaks. Profiles would default to private and tracking-based personalisation to off. Unapproved contact would be blocked. Embedded chatbots could not start automatically; systems capable of encouraging emotional dependency would require pre-launch testing and later monitoring.
A self-declared birth date would no longer suffice. Certified solutions independent of platforms would confirm only whether an age threshold is met. The Commission requires zero-knowledge technology intended to prevent identification, location, tracking or profiling. A free EU app and later the European Digital Identity Wallet are planned; each Member State would provide at least one free route. Existing accounts would need checking within six months of the rules applying.
Pandorex Analysis
The headline “social-media ban below 13” understates the operational change. The proposal creates a trust layer for age assurance, parental responsibility and platform access. Separating identity checks from platforms is a meaningful privacy safeguard, but certification, key management, recovery and guardian-child links become security-critical. Whether the promised yes-or-no signal works without extra data trails depends on standards and implementation not yet proven in practice.
Platforms with at least 45 million monthly active EU users would submit independently audited compliance plans for new services or features; the Commission describes a 30-day assessment. Penalties could reach six per cent of worldwide annual turnover. Enforcement would use Digital Services Act and AI Act structures. These duties are not yet law: Parliament and the Council can change the age tiers, scope and procedures.
