Young people looking at the mobile phones

The “Brussels Effect” has become shorthand for a familiar story about digital regulation: the European Union regulates first, and the rest of the world follows. We have witnessed this effect most noticeably with the General Data Protection Regulation, the EU’s data privacy law that was similarly adopted in dozens of other countries ranging from Brazil to Thailand. The EU KIDS Act, proposed by the European Commission on 17 September 2026, seems to suggest a new narrative when it comes to platform regulation. With this new proposed law, the European Commission builds upon a predominantly risk-based model under the 2022 Digital Services Act (DSA) and introduces a combination of age-based bans, design obligations, and ex ante compliance controls. China’s long-standing restrictive policies on gaming for minors, Australia’s social-media age restrictions and recent US litigation against Meta provide striking precedents for both components.

The members of the CoCoDa consortium, which includes leading platform governance researchers from the ODI, the University of St. Gallen, and Maastricht University, are closely monitoring the policy changes.

The DSA already contains various protections for minors: It requires platforms to put in place “appropriate and proportionate measures” for minors to ensure a high level of privacy, safety and security. The DSA further prohibits profiling-based advertising where a platform knows with reasonable certainty that a user is a minor. For Very Large Online Platforms (VLOPs), there is an overarching obligation to assess and mitigate systemic risks, expressly including risks affecting minors and physical and mental wellbeing.

Unlike the DSA, Australia took a more drastic measure with its amended Online Safety Act: As of December 2025, leading social media platforms must take “reasonable steps” to prevent Australians under 16 from creating or keeping accounts. This is different from the DSA model. Instead of asking a platform to assess the risks its service creates for children and mitigate them, Australian law elevates access itself as the primary regulatory object – over many other possible, and potentially less extreme design measures under the DSA.

European countries looked closely at how Australia’s experiment is working (or not working, as studies have begun illustrating) and tried to imitate the approach. The French approach has notably been struck down by the French Constitutional Court because it would disproportionately affect children’s rights to freedom of speech and privacy. Kids, after all, also have rights that cannot simply be taken away by an act of parliament and blanket bans.

Yet another approach is being taken in the USA: In August 2026, a bipartisan coalition of US state attorneys general announced a settlement with Meta—still subject to court approval—arising from litigation concerning allegedly addictive and harmful design practices affecting young users. The settlement does not only require Meta to “mitigate risks”. It specifies what Facebook and Instagram must do, specifically: Meta must take steps to verify age, limit under-18s to two hours per day across Facebook and Instagram, restrict access between midnight and 6 a.m., limit notifications during nighttime and school hours, and give children and parents mechanisms to opt out of addictive algorithmic feeds. These are product rules. They regulate age assurance, time, notifications, recommender systems and the architecture of engagement itself.

The proposed KIDS Act brings these two approaches together. On access, the Commission proposes no social-media accounts below 13, then guardian-established and supervised limited accounts at 13 and 14, and from 15 onwards autonomous accounts. Self-declaration of age would no longer suffice: platforms would have to rely on certified age-assurance mechanisms – and potentially lead to ID verification across many different websites on the internet. This looks considerably more like the Australian logic than the original DSA architecture.

On design, the similarities with the Meta settlement are even more striking. The KIDS Act would prohibit addictive features such as infinite scrolling and sleep-hour push notifications; require child-safe recommender systems offering greater control; mandate safer and private defaults; strengthen parental controls and blocking tools; restrict unwanted contact; and prohibit minors from livestreaming. Similar measures have already been mandated by the Commission in its enforcement of the DSA against social media companies, as well as guidelines published specifically on Article 28 DSA. So, why then introduce yet another law to the existing jungle of EU digital regulation? (for an overview by Kai Zenner, see here).

While Australia gets much of the attention in the current press, the more instructive precedent is Beijing. China has restricted minors online for the better part of a decade: 90-minute daily gaming caps in 2019, tightened in 2021 to a single hour on Fridays, weekends and holidays – with duties placed on handset makers, app stores and developers together. It should, however, be noted that these bans have been considered “largely ineffective”. Also on age assurance, China provides important precedent: real-name SIM registration (which are for children tied to their parents), real-name accounts, and since July 2025 a state-issued network ID with dedicated provisions for children. Moreover, whenever software and AI is to be published, it commonly has to be registered with or approved by the Cyberspace Administration of China.

While the KIDS ACT proposal does not go as far as requiring pre-market authorisation of new social media functionalities, the features imposed and tested in other jurisdictions seem this time to travel back to Europe. The Brussels Effect, at least on child safety, has become an import rather than an export. While under the DSA, VLOPs are required to assess risks before deploying critical functionalities likely to affect systemic risks (and this obligation remains subject to auditing and enforcement), under the KIDS Act proposal, VLOPs would have to submit a compliance plan which will be subject to children-specific independent auditing and Commission assessment for approval.This would then continue to be monitored through annual systemic risk management. The Commission describes this as reversing the "burden of proof": providers must demonstrate ex ante that their services comply with the child-safety requirements.

The CoCODa project is funded by the Swiss National Science Foundation.