Ursula von der Leyen called it reversing the burden of proof. “It is for platforms to show they are safe by design,” she told the European Parliament on September 16, unveiling the EU KIDS Act, the most sweeping child-online-safety law any Western democracy has attempted. No social media under 13. No independent account until 15. Thirteen and fourteen-year-olds get “mini accounts” tethered permanently to a parent’s own login. Every platform, every app store, every game must now verify a user’s age before granting access, using a government-built app rolling out across 450 million people in 27countries.
Framed as child protection, it undeniably is that, in part. But strip away the press conference, and what’s being built is something with a much longer half-life than any single child’s adolescence: a continent-wide infrastructure for verifying, categorizing, and tracking who is allowed to be online, and at what age, permanently.
What the Law Actually Does
The mechanics are real and specific. Under the KIDS Act, any child under 13 is barred from social media outright. Ages 13 and 14 get accounts that exist only as extensions of a parent’s, with restricted features and screen-time limits baked in. Only at 15 does a teenager get to open an account of their own. Enforcement runs through the Digital Services Act’s existing penalty structure, fines of up to 6% of a company’s global revenue, with investigations fast-tracked to conclude within 90 days.
The tool making all of this enforceable is the EU’s own age-verification app, already piloting in Cyprus, Denmark, France, Greece, Ireland, Italy, and Spain, with EU-wide rollout expected by the end of 2026. To its credit, the Commission built real privacy engineering into it: a user proves their age once to a vetted national issuer, a bank, post office, or digital ID authority, and the app then tells a platform only “yes” or “no.” No document, no birthdate, no identity is handed to the website itself. Each proof is single-use, preventing a platform from tracking a user across sites.
Why That Detail Doesn’t End the Argument
Here is where the reassurance stops holding. The privacy-preserving math only protects you at the platform level. It says nothing about the issuer level, the government-vetted authority that verified you in the first place, and now holds a permanent record that you exist, your age, and that you sought access to a monitored space. That record sits inside infrastructure the EU is simultaneously building for an entirely separate purpose: the European Digital Identity Wallet, mandated under the eIDAS 2.0 regulation, requiring every member state to hand every citizen a government-issued digital ID app by the end of 2026, linking driving licenses, diplomas, bank accounts, and now, age verification, into one interoperable credential.
European Digital Rights, the continent’s own leading digital-rights watchdog, isn’t reassured. In a formal analysis this year, EDRi flagged that implementation is quietly pushing mandatory biometric facial-data processing nowhere authorized in the original law, and is narrowing the wallet’s privacy-preserving pseudonym features until “over-identification of users” becomes the default. A separate peer-reviewed privacy audit published in ScienceDirect this year found the wallet’s architecture, even under its own reference framework, creates real risks of linkability and identifiability across services. In plain terms: the system that verifies a 14-year-old’s age today is the same rail being laid for verifying every adult’s identity tomorrow, and the people building it are already on record admitting the safeguards aren’t holding.
Lines the Government Shouldn’t Cross
There is a real question buried under the child-safety branding, and it deserves to be asked without apology: why does keeping a 13-year-old off Instagram require building a national identity-verification apparatus that outlives that child’s adolescence by decades? A government’s legitimate role is to prosecute platforms that harm children and to support parents, not to become the entity a citizen must check in with, at any age, to prove who they are before speaking. Privacy is not a benefit governments extend when convenient. It is the default condition a free person is owed, and it does not evaporate because the stated justification is a sympathetic one.
Protecting children and building a surveillance rail are not the same project, even when they share an app icon. Europe would do well to ask which one it just approved.