EU KIDS Act: AI Companions Must Be Off by Default, Emotional Dependence in Children Prohibited

The European Commission has proposed the KIDS Act, which would bring AI companions and chatbots alongside social media, video-sharing platforms, and online games under stricter protections for minors. The proposal would require AI companion features to be off by default for minors, ban designs that foster emotional dependence, and shift the burden of proof onto platforms to show their products are safe.

On September 17, 2026, the European Commission officially submitted the KIDS Act proposal to the European Parliament and the Council of the European Union. The full name of the document is the "Keeping Internet Digital Spaces Accountable and Trustworthy" Act, the broadest legislative attempt in EU history to address minors' online safety. The biggest difference from previous regulatory documents is that this proposal, for the first time, places AI companions and chatbots alongside social media, video-sharing platforms, and online games within its regulatory scope—and not merely to restrict minors' access, but to directly constrain the design logic of AI products themselves. Companies that violate the rules face fines of up to 6% of their total global annual revenue.

Four Technical Constraints Facing AI Chatbots

The KIDS Act sets four specific requirements for AI chatbots and AI companion products, each targeting the core operating mechanisms of such products.

First, off by default. AI chatbots and companion features must be off by default for minors and must be actively enabled by parents, rather than allowing users to opt out themselves. This is the exact opposite of the current logic of most products, which are "on by default, with users configuring settings themselves."

Second, prohibition of emotional-dependence designs. The bill explicitly bans design patterns that "simulate interpersonal relationships and may lead to emotional dependence." This strikes directly at the differentiating advantage of AI companion products: deliberately cultivating emotional connection is precisely the core mechanism by which such products retain users and form usage habits.

Third, cross-session memory off by default. According to the FAQ on the EU Digital Strategy website, AI systems "must not, by default, carry a child's previous conversation content into subsequent conversations." Persistent memory is the cornerstone of the AI companion product experience—the accumulated "relationship history" between a user and an AI character is a core competitive advantage of such products—and the bill requires that this feature not be enabled by default for minors.

Fourth, additional restrictions in embedded contexts. When AI chat features are integrated into games or other platforms, they must also meet these conditions: opening the platform must not automatically activate AI chat; AI features must not be proactively promoted to children; and users must have an easy way to turn them off. Children under 13 may access AI chat features only through parental control tools.

Taken together, these four requirements effectively oblige developers to treat a "minors compliance mode" as the first layer of a product's architecture, rather than a filter layer added on after the fact.

A Fundamental Reversal of the Burden of Proof

The most structurally significant change in the KIDS Act is not these specific prohibitions, but the direction of the burden of proof. European Commission President Ursula von der Leyen said in a statement released with the proposal: "Our KIDS Act reverses the burden of proof—it is up to platforms to prove that their designs are safe."

That statement implies an entirely new compliance logic: companies no longer wait for regulators to prove their products are harmful; instead, they must proactively submit proof of safety and compliance before a product reaches the market and establish ongoing post-launch risk monitoring. According to the EU Digital Strategy website, AI companions and chatbots must complete specialized testing for risks to children before launch and continuously monitor for harm afterward.

According to CNET, Megan Jenkins, an analyst at research firm Assembly Research, characterized this mechanism as "the strictest of the bills proposed to date" and said its biggest change lies precisely here: "If tech companies cannot prove their products are safe, they will not be able to provide services to minors." If safety cannot be proven, market access is denied—a logic closer to pharmaceutical approval than to the traditional internet regulatory model of "find a problem, then address it."

For AI companies, this means compliance checks must be moved earlier in the product development process. Technical documentation, risk assessments, and behavioral testing records—materials that in traditional internet products are post hoc response documents—would become prerequisites for market launch under the KIDS Act framework.

A New Regulatory Layer Independent of the AI Act

In its legal architecture, the KIDS Act is independent of the EU AI Act, which officially took effect in 2024. The two frameworks start from different logical premises: the AI Act centers on capability-risk classification, assigning regulatory tiers according to an AI system's use case and degree of potential harm; the KIDS Act centers on protecting a specific user group, regulating design patterns specifically for minors.

This means two sets of compliance obligations may apply simultaneously to the same AI product. A company offering AI companion services would need to assess under the AI Act whether its system falls into the "high-risk" or "transparency obligations" category; under the KIDS Act, it would also need to provide additional proof for minor users that the product contains no emotional-manipulation designs and to ensure default-off status and cross-session memory restrictions. The two compliance paths do not fully overlap in assessment methods and documentation requirements, increasing the complexity for companies.

Divergence from the Australian Model

The KIDS Act is not the world's first legislation to restrict minors' use of digital services. Australia, the United Kingdom, India, and China have all adopted related measures, but the regulatory logic differs fundamentally.

Australia's model has been described as a "blanket ban"—minors under 16 may not use social media—using a hard age cutoff with a relatively simple enforcement logic. The EU proposal's core approach is different: rather than simply cutting off access, it combines tiered age rules with mandatory safety-by-design requirements, requiring products to be "safe by design."

According to CNET, Megan Jenkins said the EU bill "represents a major shift compared with blanket social media bans in countries such as Australia." The logic of the EU proposal is that age restrictions alone only address the access point, while addictive design at the underlying service layer is the root problem. The European Commission website puts it plainly: "Age limits alone will not reach the real root problem: service designs that maximize children's time and attention."

Each path has its costs. The Australian model has clear enforcement boundaries but is relatively easy to circumvent, and its age cutoff is crude. The EU model is more granular but harder to check for compliance—standards such as "emotional-dependence design" involve behavioral psychology assessments, and the bill text has not yet provided operational details on how to define and measure them at a technical level.

How the Impact Reaches Different Parties

The impact of the KIDS Act is not evenly distributed across the entire industry chain.

For large platforms such as Meta, Google's YouTube, and Roblox, the bill requires restructuring account-tier systems, shutting off recommendation algorithms and nighttime push notifications for minors, and adding documentary obligations for large platforms that meet scale thresholds to prove compliance. The bill also requires app stores to check users' ages when they create new accounts, extending platform responsibility into the distribution layer.

For AI companion and chatbot developers, the impact is more structural. Persistent memory and emotional interaction are the core differentiators of such products, and these are precisely what the bill explicitly constrains. Developers need to implement minor identification, default-off settings, and feature downgrading at the product level—not a parameter adjustment, but a requirement for independent account-management infrastructure and parental control interfaces.

For non-EU companies operating in the EU market, the KIDS Act also has extraterritorial effect—any company providing services to minor users within the EU must meet compliance requirements or risk being unable to serve EU minors and even triggering fines of 6% of global revenue.

Legislative Process and Two Signals

The KIDS Act is currently still a proposal. Under the EU legislative procedure, before it becomes law it must undergo review by the European Parliament and negotiations in the Council of the 27 member states. Specific technical requirements, scope of application, and effective timelines remain variable, and the bill's content may be adjusted during negotiations.

From a legislative-signal perspective, the introduction of the KIDS Act establishes the EU's baseline position on AI child protection: replace "prohibiting access" with "safe by design," constrain platforms through evidentiary obligations, and replace fragmented national legislation with unified rules across member states. Even if the final version changes some technical details, the two principled positions—"prohibiting emotional-dependence design" and "AI minors mode off by default"—are likely to remain, because they are the foundation of the entire legislative logic, not bargaining chips to be traded away.

For AI companies, two signals warrant continued tracking: first, whether the European Parliament provides a more operational technical definition of "emotional dependence" during its review, which will determine how predictable the compliance standard is; second, how app stores such as Apple and Google respond to the age-check obligation. If major app stores choose to apply EU standards globally rather than only regionally, the real impact of these rules will extend far beyond the geographic borders of the EU's 27 member states.