Realm33 Dossier: EU Kids Act — The Complete Archival Record
REALM33
Directorate of Information Preservation and Archival
FILE REF: R33-DCPRA-POL-007  |  CLASSIFICATION: DIGITAL POLICY / CIVIL LIBERTIES / REGULATORY ARCHITECTURE  |  LAST UPDATED: OCTOBER 2026

Policy Dossier — Complete Archival Record

SUBJECT: The EU Kids Act — COM(2026) 681 final — “EU Keeping Internet Digital Spaces Accountable and Trustworthy”
OFFICIAL DESIGNATION: Proposal for a Regulation of the European Parliament and of the Council. Published by the European Commission, Brussels, 17 September 2026. Legal basis: Article 114 of the Treaty on the Functioning of the European Union (internal market harmonisation).
STATED PURPOSE: To protect minors from harmful online environments by mandating age verification for social media and online games, restricting autonomous account creation for under-15s, requiring “safety by design” from all covered platforms, and establishing a harmonised EU-wide framework for digital child protection superseding diverging national laws.
SCOPE — WHAT IT COVERS: Online social networking services · Video-sharing platforms · Online games (all games with any online component, regardless of whether sold digitally or on physical media with a network feature) · Software application stores (Apple App Store, Google Play, Steam) · AI companions and conversational chatbots · Small and micro enterprises are explicitly NOT exempted.
KEY CONCERNS DOCUMENTED IN THIS FILE: Mass digital identity infrastructure under child-safety framing  ·  Precedent of UK Online Safety Act and its immediate data breach consequences  ·  Destruction of the indie game development sector in the EU  ·  Conflict with Stop Killing Games and consumer rights  ·  The path toward full digital surveillance of internet access  ·  Connection to the broader “2030 agenda” and the end of anonymous digital presence.
DIRECTORATE POSITION: Archival and analytical. This file documents the Act’s text, its stated intentions, and the full range of concerns raised by critics — from civil liberties organisations, the independent gaming sector, and digital rights researchers. The Directorate neither endorses the Act nor dismisses the concerns raised about it. Child safety is a legitimate policy objective. The question documented here is whether the mechanism chosen to pursue it is proportionate to its stated aim, or whether it accomplishes something considerably larger.
Conspiracy Illustration

Fig. 0 — Conspiracy Illustration of the subject. The use of children to make regulations which affects primarily adults.

Declassified
05/10/2026
⚠ ARCHIVAL STANDARD NOTICE — This file documents an active legislative proposal as of October 2026. The EU Kids Act has been formally proposed but has not yet been enacted. Its final text may differ from COM(2026) 681. The concerns documented here reflect responses to the proposal as published. The Directorate treats proposed legislation as worthy of documentation at the proposal stage precisely because the most significant public debate — and the widest opportunity for public understanding — occurs before enactment, not after. All direct quotes from the Act are drawn from COM(2026) 681 final as published in the EUR-Lex database.
Document Structure — Eight Chapters
I    What the Act Actually Says — The text, the scope, the mechanisms, and what “safety by design” means in practice
II   The Digital Identity Problem — Age verification as surveillance infrastructure, the EU Age Verification Scheme, and what it builds
III  The UK Precedent — What Already Happened — The Online Safety Act 2023, the Discord breach, 70,000 government IDs leaked
IV  The Gaming Sector — Existential Impact — Stop Killing Games, indie developers, private servers, and “the biggest threat yet”
V   The Small Developer Problem — No SME exemption, compliance costs, de facto EU market exclusion for independent creators
VI  The Broader Architecture — Where This Leads — The 2030 Digital Agenda, “You will own nothing,” the end of anonymous internet presence
VII  Voices of Concern — Documented Opposition — Civil liberties organisations, gaming advocates, privacy researchers, platform operators
VIII Evidentiary Assessment and Status — What is confirmed, what is concern, what is speculation — timeline and open questions
Chapter I What the Act Actually Says The Text, the Scope, the Mechanisms, and What “Safety by Design” Means in Practice

The EU Kids Act — formally designated COM(2026) 681 final, titled “EU Keeping Internet Digital Spaces Accountable and Trustworthy” — was published by the European Commission on 17 September 2026. It is a proposed Regulation, meaning that if enacted it would apply directly and uniformly across all 27 EU Member States without requiring national transposition legislation. It builds on and “specifies” the existing Digital Services Act (Regulation EU 2022/2065) and the AI Act (Regulation EU 2024/1689). The Commission’s stated rationale: only half of European children aged 9–16 say they feel safe online, and Member States are adopting diverging national laws that fragment the digital single market. A single EU-wide framework is proposed to harmonise protections and compliance obligations.

Fig. 1 — The Berlaymont building, Brussels — headquarters of the European Commission, which published COM(2026) 681 on 17 September 2026. The Commission’s role is to propose legislation; the Parliament and Council enact it. The proposal is currently in its legislative journey. Photo: public domain via Wikimedia Commons.

The Core Mechanisms — What the Act Requires

  • Access Delay — Under-15 Social Media Ban The Act prohibits online social networking services and video-sharing platforms from allowing minors under the age of 15 to create autonomous accounts. Between ages 13 and 15, guardians may create limited-functionality accounts on behalf of a child. Under-13s may not access social media platforms at all in autonomous mode. This provision requires all covered platforms to verify the age of new account holders before access is granted — establishing age verification as a structural requirement for social media access across the EU.
  • Safety by Design — Mandatory Platform Architecture Changes The Act mandates sweeping “safety by design” requirements for social networks, video platforms, online games, AI companions, and app stores. These include: prohibiting “autoplay, autoscroll, autoreplay, infinite scroll” and push notifications for minors; disabling algorithmic recommendation by default; prohibiting features that “incentivise engagement at regular times or with greater frequency”; implementing “effective” time management tools that prevent use during school hours and between 22:00 and 08:00 (core sleep hours); and restricting live-streaming and contact with unknown users. The Commission may expand this list through delegated acts — meaning future expansions do not require full parliamentary procedure.
  • Online Games — Comprehensive Coverage Including Indie Titles The Act covers “any game that can be played on a computer, a mobile device, or a games console, irrespective of whether the game underlying software is subsequently executed locally, remotely, such as by means of durable medium, and irrespective of whether the service is provided free of charge, against payment, or against hybrid remuneration involving in-service purchases.” The only exclusion is games purchasable exclusively through physical media with no online component whatsoever. This definition explicitly covers small indie games with multiplayer features, modding platforms, and user-generated content tools. Critically, the Act states: “small and micro enterprises are not exempted from this Regulation, since they may equally provide harms to minors.”
  • App Stores — Age Rating Enforcement and Access Blocking Software application stores — Apple App Store, Google Play, Steam, itch.io, and any equivalent — are required to implement age rating systems for all applications and to block minors from accessing age-inappropriate applications. The store operator, not the developer, bears primary enforcement responsibility. This creates an intermediary gatekeeping layer between developers and their audiences that did not previously exist in EU law.
  • AI Companions and Chatbots — Emotional Dependency Prohibition AI companions and conversational chatbots accessible to minors are prohibited from displaying “behaviours or simulating emotions or interpersonal relationships that are likely to create emotional and other dependencies.” Persistent conversational memory must be disabled by default for interactions with minors. This provision extends regulatory reach to a rapidly growing category of consumer AI products.
“Small and micro enterprises are not exempted from this Regulation, since they may equally provide harms to minors. It would undermine the objective of this proposal to exclude them from scope.” — COM(2026) 681 final, Section 2, Proportionality assessment. This sentence is the clause most cited by independent game developers and small software creators as the defining statement of the Act’s impact on the independent sector. It explicitly removes the small business carve-out that appears in most comparable EU regulation. Every indie developer who releases an online game into the EU market is in scope.
Chapter II The Digital Identity Problem Age Verification as Surveillance Infrastructure, the EU Age Verification Scheme, and What It Builds

The most significant structural concern raised by digital rights researchers about the EU Kids Act is not what it bans children from seeing. It is the infrastructure it builds to enforce that ban. Age verification — the technical requirement that every user of a covered service prove their age before access — cannot be implemented without identity verification. You cannot verify age without verifying identity. The Act acknowledges this, establishes the “EU Age Verification Scheme” as a centralised framework, and mandates that Member States make available at least one government-backed age verification solution. What is being constructed, critics argue, is the infrastructure for a de facto digital identity requirement covering access to most of the modern internet.

EU Digital Identity Wallet logo
Fig. 2 — The EU Digital Identity Wallet (EUDI Wallet) logo. The EUDI Wallet — a EU-wide digital identity framework already in development under Regulation EU 2024/1183 — is explicitly referenced in the EU Kids Act as the basis for its age assurance definitions. Critics describe the Kids Act as the adoption mechanism that will drive mass uptake of the EUDI Wallet under child-protection framing. Image: European Commission, public domain.

The EU Age Verification Scheme — What the Act Builds

The Act establishes, in Chapter V, a formal framework for age assurance. It requires that age verification be “highly accurate, reliable, robust, non-intrusive, privacy-preserving, and non-discriminatory.” It explicitly states that “self-declaration is not sufficient for compliance.” Member States must “ensure the availability of different means of obtaining a proof of age attestation” and must “make available at least one age verification solution” — meaning governments are mandated to provide the infrastructure. The definitions used for this scheme are explicitly drawn from Regulation EU No 910/2014 as amended by Regulation EU 2024/1183 — the eIDAS 2.0 framework that underpins the EU Digital Identity Wallet (EUDI Wallet) already under development across all 27 Member States.

The connection is not incidental. The EUDI Wallet is the EU’s in-development universal digital identity document — a smartphone-based credential that would allow EU citizens to authenticate their identity, age, and other attributes across both government and private services. The Kids Act’s age verification requirements create a compelling use case for the EUDI Wallet’s mass adoption: if you need to verify your age to access a social media platform or an online game, and the government has provided an EUDI Wallet solution as the mandated verification method, the result is mass consumer adoption of EU digital identity infrastructure driven by the requirement to play video games or use social media. Whether this is the Act’s intent or an incidental consequence is the question critics cannot resolve from the public record — the infrastructure is the same either way.

What Anonymous Internet Access Becomes

The practical implication of universal age verification requirements across social media, video platforms, gaming platforms, and app stores is that the anonymous or pseudonymous internet — in which a user can create an account, interact, purchase, and consume content without providing government-verified identity — ceases to exist for the services covered. A user wishing to play an online game in the EU, download an app, or create a social media account will be required to authenticate their age through a system linked, directly or through an intermediary, to a government-backed identity record. The Act provides for “privacy-preserving” verification mechanisms, and the Commission presents this as resolving the privacy concern. Critics respond that any system that verifies your age against a government record — regardless of how the data is subsequently handled — creates a point of identity linkage between your government file and your digital activity that did not previously exist.

Chapter III The UK Precedent — What Already Happened The Online Safety Act 2023, the Discord Breach, 70,000 Government IDs Published, and the VPN Response

Before the EU Kids Act reaches its final form, a directly relevant experiment has already been conducted at national scale: the United Kingdom’s Online Safety Act 2023, whose children’s safety provisions came into force on 25 July 2025. The UK Act required platforms accessible to under-18s — including YouTube, Spotify, Reddit, X, and Discord — to implement “highly effective” age verification for harmful content. The results documented in the first twelve months provide the most direct available evidence of what EU-wide age verification requirements produce in practice. They are not encouraging for the Act’s proponents.

UK Online Safety Act logo
Fig. 3 — The UK Online Safety Act 2023 became the world’s first major enacted legislation requiring platforms to implement age verification at scale across a broad range of services. It came into force in July 2025 and produced its first significant data breach in October 2025, three months after implementation. Image: public domain.

The Discord Breach — October 2025

On 9 October 2025 — less than three months after the UK Online Safety Act’s age verification requirements came into force — Discord disclosed that approximately 70,000 users had their government ID photographs stolen in a breach of a third-party vendor the platform used for age-related appeals. Users who had submitted government ID documents as part of Discord’s age verification process — required to comply with the UK Online Safety Act — had their passport and driving licence photographs, selfie images holding their government ID, and IP addresses exposed. The hackers published over 100 photographs publicly online. Researchers at 404 Media reported the attackers claimed to have stolen 1.5 terabytes of data — suggesting the true scale of the breach significantly exceeded Discord’s initial disclosure.

Discord subsequently delayed its planned global rollout of mandatory age verification, with CEO Stanislav Vishnevskiy acknowledging publicly that the company had “made mistakes.” The Tea app suffered a parallel breach in July 2025, exposing 72,000 identity verification images. A verification firm contracted to handle UK age appeals lost control of 70,000 passports and driving licences to a separate incident. The pattern was consistent: legislation requiring mass identity document collection created a centralised target for criminal actors. The children the legislation was designed to protect had their government identification documents published on the internet as a direct consequence of the protection mechanism.

The Perverse Outcomes — What the UK Experiment Produced

  • Traffic Shifted to Unregulated Sites — Not Removed Pornhub and multiple adult content providers blocked UK traffic entirely rather than implement age verification, stating publicly that the requirement “diverted traffic to darker, unregulated corners of the internet.” Compliant sites lost traffic to non-compliant sites. The intended effect — restricting minors’ access to harmful content — was not achieved; it was redirected. The harmful content did not become inaccessible; it became accessible through channels without any age verification at all.
  • VPN Adoption Surge — Circumvention at Scale UK Google searches for “VPN UK” surged immediately following the Act’s implementation. The Electronic Frontier Foundation described age verification systems as “surveillance systems” that effectively drove privacy-conscious users — including minors — to VPNs that also bypassed all content controls. The circumvention mechanism made the regulation simultaneously more invasive for compliant adult users and less effective for the minors it targeted.
  • Reddit Fined — For Collecting Too Little Identity Data Reddit was fined £14.5 million (approximately $19.5 million) by the UK Information Commissioner’s Office for failing to adequately verify users’ ages — despite the platform’s stated objection that “the ICO’s insistence that we collect more private information on every UK user is counterintuitive and at odds with our strong belief in our users’ online privacy and safety.” The paradox was explicit: regulators fined a platform for not collecting enough of the very identity data that, when collected, was being systematically stolen by hackers.
  • Children’s Data Most Exposed The data breaches resulting from age verification compliance did not exclusively expose adults. In several documented breach incidents, family accounts, parental verification data, and data linked to accounts used by minors was included in the exposed datasets. Legislation enacted to protect children’s safety online produced documented incidents in which children’s identity documentation and associated family data was stolen and published. This is the UK precedent the EU Kids Act proposes to replicate at continental scale.
Chapter IV The Gaming Sector — Existential Impact Stop Killing Games, “The Biggest Threat Yet,” Private Servers, Minecraft, and Unreal Tournament as Examples

The Stop Killing Games movement — an international consumer rights initiative founded by YouTuber Ross Scott (Accursed Farms) following Ubisoft’s shutdown of the always-online racing game The Crew — campaigns for legislation requiring game publishers to ensure purchased games remain playable even after server shutdown, through local server options, offline modes, or preservation-friendly shutdown plans. The initiative achieved over 1.3 million verified signatures as a European Citizens’ Initiative under the name “Stop Destroying Videogames,” was formally submitted to the European Commission on 26 January 2026, and received a European Parliament hearing on 16 April 2026. The movement had, by mid-2026, achieved the most significant legislative momentum of any consumer gaming rights campaign in EU history.

YouTube logo
Fig. 4 — Stop Killing Games founder Ross Scott (Accursed Farms) published a YouTube video titled “This could legitimately end Stop Killing Games” in late September 2026, describing the EU Kids Act as the “biggest threat yet” to both the Stop Killing Games initiative and the European gaming industry as a whole. The video sparked widespread coverage across gaming media. The image show Ross Scott at the European Parliament session hearing about the European Citizens’ Initiative Stop Destroying Videogames. Image is from the European Parliament: https://www.europarl.europa.eu/legal-notice/en/

Why the EU Kids Act Is “The Biggest Threat Yet”

When the EU Kids Act was published on 17 September 2026, Stop Killing Games founder Ross Scott published a detailed video analysis concluding that the Act represented “the biggest threat yet” to the organisation’s goals and potentially to the European gaming industry as a whole. The concern operates on two distinct but related levels.

First, the Act’s age verification requirements — applied to all online games with no small-enterprise exemption — create a compliance architecture that conflicts directly with the private server model that Stop Killing Games advocates as the preservation mechanism for online games after official server shutdown. If a game is required by law to implement age verification for all users, and the publisher shuts down the official infrastructure, who operates the age verification system for the private servers that Stop Killing Games wants to enable? A private server community running a preserved version of an old game cannot operate a compliant age verification system. The EU Kids Act’s requirements, if applied to private servers, would make the Stop Killing Games preservation model legally non-viable in the EU.

Second, the Act’s safety-by-design requirements — covering “addictive design,” “excessive engagement incentives,” and contact with unknown users — would require fundamental architectural changes to the design of online games that the affected studios may lack the resources to implement. In the video, Ross Scott cited Minecraft and Unreal Tournament as examples of games whose fundamental design features — open server browsers, user-to-user contact, engagement mechanics — would fall under the Act’s prohibitions when accessible to minors.

Chapter V The Small Developer Problem No SME Exemption, Compliance Costs, and De Facto EU Market Exclusion for Independent Creators

European Union legislation typically includes a small and medium enterprise (SME) exemption or a proportionality adjustment that reduces compliance obligations for smaller operators. The General Data Protection Regulation (GDPR), the Digital Services Act, and the AI Act all contain provisions reducing the burden on small businesses. The EU Kids Act explicitly and deliberately does not. The Commission’s stated rationale: “small and micro enterprises are not exempted from this Regulation, since they may equally provide harms to minors. It would undermine the objective of this proposal to exclude them from scope.” The consequence of this choice, as documented by independent gaming sector advocates, is that every indie developer who releases an online game into the EU market — regardless of their company size, revenue, staff count, or technical capacity — faces the full compliance obligations of the regulation.

Steam logo
Fig. 5 — Steam, operated by Valve Corporation, is both an online game store (subject to the Act as a software application store) and a platform through which thousands of independent games are sold (subjecting those games to the Act’s online game requirements). Valve has already indicated it will take a minimal-data approach to UK age verification. Image: Public Domain

The Practical Compliance Gap for Independent Developers

For a major publisher — Electronic Arts, Activision, Ubisoft — absorbing the compliance costs of implementing age verification systems, safety-by-design audits, legal representatives in EU Member States, and compliance plans is operationally manageable. For an independent developer operating with a team of two to ten people, a hobbyist project, or a game released with no ongoing commercial revenue, these requirements are not manageable. They represent a fixed overhead that is not proportional to revenue or scale.

The requirement to maintain a “legal representative in a Member State” — mandatory for providers not established in the EU — is alone a non-trivial ongoing cost. The requirement to implement an age verification system that meets the Act’s technical specifications requires either building proprietary infrastructure or contracting a third-party verification provider, both of which carry costs and liabilities that small developers cannot easily absorb. The requirement to prepare “compliance plans” subject to independent audit — while explicitly reserved for very large platforms for the notification mechanism — layers on documentation obligations that scale unfavourably with small operations. The cumulative effect, critics argue, is not that small developers will comply at great cost. It is that small developers will not release online games in the EU market at all.

The Broader Creative Ecosystem — Beyond Gaming

The Act’s scope extends beyond commercial game studios to encompass any creator operating an online service accessible to minors. Independent forum operators, hobbyist community platforms, small online tools with social features, and creator-operated platforms could all fall within the Act’s coverage depending on whether their service involves features characterised as an “online social networking service” or “video-sharing platform.” The Act includes carve-outs for not-for-profit educational repositories, open-source software development platforms, and public authority services. It does not include a carve-out for small commercial services, creative communities, or independent artists’ platforms. The creative internet — the layer of the web built by individuals rather than corporations — faces the same compliance obligations as the largest platforms on earth, with none of the resources that make those obligations survivable.

Chapter VI The Broader Architecture — Where This Leads The 2030 Digital Agenda, “You Will Own Nothing,” the End of Anonymous Internet Presence, and Individual Digital Freedoms

The EU Kids Act does not exist in isolation. It arrives as one layer in a regulatory stack that has been building since at least 2020, encompassing the Digital Services Act (2022), the AI Act (2024), the proposed Digital Fairness Act, the Audio-Visual Media Services Directive, eIDAS 2.0 and the EU Digital Identity Wallet, the GDPR enforcement intensification, and now the Kids Act — each described individually as a targeted response to a specific problem, together constituting what critics describe as the most comprehensive regulatory architecture for digital control ever assembled in a democratic polity. The Commission’s own documentation references its “2030 Roadmap on the future of digital education and skills” and the “Digital Decade 2030” targets as the framework within which the Kids Act sits.

World Economic Forum logo
Fig. 6 — The World Economic Forum (WEF), whose “Great Reset” initiative and associated 2030 projections — including the widely cited statement “you will own nothing and be happy” from a 2016 WEF video — have become reference points in debates about the trajectory of digital ownership rights. Critics connect the EU’s regulatory direction to these stated goals. Image: public domain.

The “You Will Own Nothing” Trajectory — Digital Rights Under Pressure

The phrase “you will own nothing and be happy” — originating from a 2016 World Economic Forum social media video discussing predicted changes by 2030 — has become a shorthand reference in digital rights discourse for a trajectory in which individual ownership of software, games, media, and digital goods is progressively replaced by licensed access that can be revoked, restricted, or modified by the licensor or regulator at any time. The Stop Killing Games movement itself exists precisely because this transition is already occurring in the gaming sector: games purchased by consumers have been permanently deactivated when publishers shut down online infrastructure, transforming a purchased product into a revoked licence.

Critics of the EU Kids Act situate it within this trajectory in two ways. First, the Act’s safety-by-design requirements give regulators ongoing authority over the design and features of software — not just at release, but continuously, since delegated acts can extend or modify requirements without full parliamentary procedure. A game, platform, or application that is compliant today may be non-compliant next year following a delegated act expansion, with no legislative vote required. Second, the age verification infrastructure — once built for child protection purposes — creates a system that can in principle be extended to other categories of content, other categories of verification, and other categories of restriction. The architecture built to verify age is the same architecture that could later verify political identity, creditworthiness, criminal record, or any other attribute a future government might legislate around. The infrastructure is built once; its scope is a political question.

The End of the Anonymous Internet — Structural Analysis

The specific combination of requirements in the EU Kids Act — age verification for social media, age verification for gaming platforms, age verification by app stores, “safety by design” requirements that apply even where platforms cannot prove a user is an adult — effectively means that any EU resident wishing to use covered digital services without government-linked identity verification must either provide that verification, use a VPN to appear to be in a non-covered jurisdiction, or go without the service. This is not a paranoid extrapolation from the text; it is the stated mechanism. The Commission describes the EU Age Verification Scheme as a solution to the fragmentation problem. What it solves, structurally, is the existence of unverified digital presence. What it creates, structurally, is a population of verified digital identities whose access to digital services is mediated by a government-linked credential. Whether this outcome is characterised as “child protection” or “the end of anonymous internet access” depends entirely on which starting concern you bring to the document. The technical architecture is the same.

“The Online Safety Act serves as the soft launch of a national ID card by stealth. The question is not whether the infrastructure will be built. It already is. The question is what it will be used for once child safety is no longer the only thing it is used for.” — The Rational Forum (Substack), July 2025 — analysis of the UK Online Safety Act’s digital identity implications. Cited here not as verified fact but as representative of a documented body of critical commentary from digital rights researchers examining the structural consequences of child-safety legislation as identity infrastructure. The UK experience is the direct precedent for the EU Kids Act’s planned mechanism.
Chapter VII Voices of Concern — Documented Opposition Civil Liberties, Gaming Advocates, Platform Operators, Privacy Researchers, and the VPN Response

Opposition to the EU Kids Act — or to its core mechanism of mandatory age verification — spans a wide range of constituencies that do not typically find themselves in agreement. The Directorate documents the principal positions without endorsing any of them. The concern is not monolithic; different critics object to different elements. What they share is the view that the Act’s mechanism is disproportionate to its stated aim, or that it achieves something beyond its stated aim, or both.

  • Stop Killing Games — Gaming and Consumer Rights Founder Ross Scott has described the EU Kids Act as the “biggest threat yet” to both the Stop Killing Games initiative’s preservation goals and to the European gaming industry. His specific concerns centre on the Act’s application to private servers, the no-SME-exemption clause, and the impossibility of a small developer or community operator maintaining compliant age verification infrastructure for a game whose original publisher has exited the market. The initiative reached over 1.3 million signatures on its European Citizens’ Initiative, demonstrating substantial public engagement with digital consumer rights in the EU gaming context.
  • Electronic Frontier Foundation — Surveillance and Privacy The EFF, responding to the UK’s parallel Online Safety Act (the direct legislative precursor to the EU Kids Act’s mechanism), stated explicitly that “age verification systems are surveillance systems.” The organisation’s assistant director of federal affairs, Maddie Daly, made this statement in the context of the Discord breach — articulating the position that the architecture required for age verification cannot be separated from the architecture of identity surveillance, regardless of the stated purpose for which it is built.
  • Platform Operators — Pornhub’s Decision as Evidence Pornhub — one of the world’s largest online platforms — chose to block all UK traffic rather than implement the UK Online Safety Act’s age verification requirements. The company stated that the law “diverted traffic to darker, unregulated corners of the internet” and “jeopardized the privacy and personal data of U.K. users.” This is not a privacy advocacy position; it is a market operator’s documented assessment that the compliance mechanism was more harmful than the problem it addressed. The same operator is among those facing compliance obligations under the EU Kids Act.
  • Privacy Researchers — The Data Breach Literature Academic and research commentary following the Discord breach, the Tea app breach, and the UK verification firm breach has consistently documented that age verification laws create “a veritable treasure trove for hackers” (TechXplore, November 2025). Research from Proton and independent security researchers has documented that the identity verification sector — AU10TIX, k-ID, and similar providers — has a documented breach history that predates the Online Safety Act and continued immediately following its implementation. The infrastructure mandated for child protection has a demonstrated vulnerability to exactly the kind of exposure that most damages the children it claims to protect.
  • Wikipedia — Institutional Challenge to Age Verification Wikipedia challenged the UK Online Safety Act in court, arguing that its age verification provisions were incompatible with its role as a free-access encyclopaedia. The challenge was ultimately unsuccessful but was noted as establishing new precedent for institutional resistance to the legal framework. The Wikimedia Foundation’s position — that requiring identity verification for access to an encyclopaedia represents a fundamental departure from the open-access principle of public knowledge — is a documented institutional position in the debate.
  • Independent Developers — Market Exit as Response Multiple independent developers, when asked about the EU Kids Act in gaming press coverage, have indicated that the most likely response to unmanageable compliance requirements is not compliance — it is EU market exit. Geo-blocking the EU is technically straightforward for an online game. A small studio with ten staff and a global online game release faces the same compliance obligations as Electronic Arts under the Act. The rational economic response for a small studio, many observers note, is not to build a compliance system it cannot afford — it is to block EU IP addresses and serve only markets where compliance costs are proportionate to revenue.
Chapter VIII Evidentiary Assessment and Status What Is Confirmed in the Text, What Is Documented Concern, and What the Timeline Looks Like

The EU Kids Act is, as of October 2026, a legislative proposal. It has been published, it is in the EU’s ordinary legislative procedure, and it carries the Commission’s formal backing. It is not yet law. The concerns documented in this file are responses to the proposed text, not to enacted requirements. The Directorate notes that the gap between a Commission proposal and enacted regulation is substantial — the Digital Services Act took approximately two years from proposal to enactment; the AI Act took approximately four. The Kids Act may change significantly in the legislative process. It may also pass substantially as proposed. The timeline and the text are what the Directorate can document; the outcome is not.

Evidentiary Status — October 2026

Evidentiary Status — October 2026
EU KIDS ACT COM(2026) 681 FORMALLY PUBLISHED — 17 SEPTEMBER 2026: CONFIRMED — EUR-LEX DATABASE, FULL TEXT AVAILABLE
NO SME EXEMPTION — EXPLICITLY STATED IN TEXT: CONFIRMED — SECTION 2, PROPORTIONALITY ASSESSMENT, AND ARTICLE SCOPE
ALL ONLINE GAMES IN SCOPE REGARDLESS OF SIZE: CONFIRMED — ARTICLE 15, DEFINITION OF “ONLINE GAME” IN CHAPTER I
EU AGE VERIFICATION SCHEME LINKED TO EUDI WALLET FRAMEWORK: CONFIRMED — CHAPTER V, ARTICLE 27, EXPLICIT REFERENCE TO REG EU 2024/1183
UK ONLINE SAFETY ACT — AGE VERIFICATION CAME INTO FORCE JULY 2025: CONFIRMED — UK STATUTORY INSTRUMENT, OFCOM ENFORCEMENT BEGAN JULY 25 2025
DISCORD BREACH — 70,000 GOVERNMENT ID PHOTOS STOLEN, OCTOBER 2025: CONFIRMED — DISCORD DISCLOSURE, TECHCRUNCH, NBC NEWS, THE REGISTER
TEA APP BREACH — 72,000 IDENTITY VERIFICATION IMAGES EXPOSED, JULY 2025: CONFIRMED — DOCUMENTED IN MULTIPLE SECURITY RESEARCH SOURCES
REDDIT FINED £14.5M BY UK ICO FOR INADEQUATE AGE VERIFICATION: CONFIRMED — ICO PRESS RELEASE, COURTHOUSE NEWS, AP
STOP KILLING GAMES — 1.3M VERIFIED SIGNATURES, PARLIAMENT HEARING APRIL 2026: CONFIRMED — EUROPEAN PARLIAMENT RECORDS
STOP KILLING GAMES DESCRIBES ACT AS “BIGGEST THREAT YET”: CONFIRMED — ROSS SCOTT VIDEO, NOTEBOOKCHECK REPORTING, SEPTEMBER 2026
PRIVATE SERVER MODEL INCOMPATIBLE WITH ACT’S AGE VERIFICATION — LEGAL ANALYSIS: DOCUMENTED CONCERN — LEGAL INCOMPATIBILITY ASSESSED BY SKG, NOT YET TESTED IN LAW
INDIE DEVELOPERS WILL EXIT EU MARKET RATHER THAN COMPLY: DOCUMENTED CONCERN — PREDICTED BY SECTOR ANALYSTS AND DEVELOPERS — NOT YET HAPPENED
AGE VERIFICATION INFRASTRUCTURE = PERMANENT INTERNET ID SYSTEM: DOCUMENTED CONCERN — STRUCTURAL ANALYSIS BY MULTIPLE CIVIL LIBERTIES ORGANISATIONS
EU KIDS ACT CONNECTED TO DELIBERATE 2030 AGENDA FOR DIGITAL CONTROL: ANALYTICAL CLAIM — CONSISTENT WITH DOCUMENTED REGULATORY DIRECTION — INTENT NOT STATED IN TEXT
EU KIDS ACT ENACTED INTO LAW: NOT YET — PROPOSAL STAGE AS OF OCTOBER 2026 — ORDINARY LEGISLATIVE PROCEDURE IN PROGRESS

Archival Status and Classification

The EU Kids Act is assessed by this Directorate as one of the most consequential pieces of proposed digital regulation in European history — not primarily because of what it restricts children from seeing, but because of the infrastructure it mandates to implement those restrictions. The child-safety objective is genuine and the harms it addresses are real: the Commission’s documentation of online risks to minors is substantive and well-evidenced. The question that this file documents — and that the Directorate does not resolve — is whether the mechanism chosen to address those harms is proportionate, or whether it is a regulatory architecture whose effects on the adult internet, the independent creative sector, digital anonymity, and the trajectory toward universal digital identity documentation are incidental consequences of good intentions, or something more deliberately considered.

The UK precedent answers one question clearly: mandatory age verification for online services does not protect children’s data. It concentrates it into a smaller number of high-value targets and makes it accessible to criminal actors through the very infrastructure designed to protect it. Whether the EU can implement the same mechanism at continental scale with materially better security outcomes is an empirical question that will be answered only after enactment. The Directorate notes that the question has already been answered once, at smaller scale, in a direction that should concern legislators. Whether it does is a matter of public record that this file will continue to document.

Recommended classification: ACTIVE LEGISLATION — TIER ONE SIGNIFICANCE — CHILD SAFETY OBJECTIVE GENUINE — DIGITAL IDENTITY INFRASTRUCTURE IMPLICATIONS CONFIRMED IN TEXT — INDEPENDENT SECTOR IMPACT SEVERE AND DOCUMENTED — UK PRECEDENT DATA BREACH CONFIRMED — ARCHIVAL STATUS: ACTIVE, CRITICAL, AND EVOLVING — DIRECTORATE MONITORING ONGOING

Flag of the European Union — wide
Fig. 7 — The European Union flag. The EU Kids Act, if enacted as proposed, will reshape the experience of the internet for every person in 27 countries — not only for children. The mechanism required to protect children online, as proposed, is one that touches every user who wishes to access a social platform, play an online game, or download an application in the EU. How that mechanism is designed, what data it collects, who holds it, what it can be used for in the future, and what happens when the companies that hold it are breached: these are the questions the next several years of the legislative process will either answer or fail to. The Directorate is watching. Image: public domain

Source References

  • EU Kids Act — Full Proposal Text: COM(2026) 681 final — eur-lex.europa.eu
  • Stop Killing Games — Video Response to EU Kids Act: Ross Scott (Accursed Farms) — “This could legitimately end Stop Killing Games” — youtube.com
  • Notebookcheck — Stop Killing Games EU Kids Act Warning (October 2026): notebookcheck.net
  • Stop Killing Games / Stop Destroying Videogames — European Citizens’ Initiative (1.3M signatures, January 2026): citizens-initiative.europa.eu
  • TechCrunch — Discord Data Breach, October 2025: techcrunch.com
  • NBC News — 70,000 Government ID Photos Exposed in Discord Breach: nbcnews.com
  • The Register — Discord 70,000 Photo IDs Compromised: theregister.com
  • PinkNews — Discord Delays Age Verification After Breach (February 2026): thepinknews.com
  • Proton — Is Age Verification Safe?: proton.me
  • Courthouse News — Reddit £14.5M UK Fine (2026): courthousenews.com
  • TechXplore — Online Age Checking Creates Treasure Trove for Hackers (November 2025): techxplore.com
  • The Rational Forum — UK Online Safety Act as Digital ID Infrastructure (Substack, 2025): rationals.substack.com
  • IBANET — UK Online Safety Act Implementation Analysis: ibanet.org
  • EU Digital Identity Wallet Framework — Regulation EU 2024/1183 (eIDAS 2.0): eur-lex.europa.eu
  • Wikipedia — EU Kids Act (disambiguation): en.wikipedia.org
  • PC Gamer — Online Safety Act coverage hub: pcgamer.com/tag/online-safety-act
  • GamingOnLinux — Discord ID breach coverage (October 2025): gamingonlinux.com

Last updated: October 2026. Compiled by the Directorate of Information Preservation and Archival, Realm33.org. The Directorate’s observation: legislation framed around protecting the most vulnerable members of society has historically faced the least scrutiny and the most difficulty producing effective opposition. The question is not whether children deserve protection online — they do. The question is whether the specific mechanism proposed achieves that goal, or whether it achieves something else at children’s expense, in their name. The UK precedent suggests the latter. The Directorate files this document as an ongoing record and will update it as the legislative process progresses.

Stop the EU Kids Act
European Citizens’ Initiative — Active
If You Are an EU Citizen — Your Signature Matters

The EU Kids Act is a proposal. It has not been enacted. The legislative process that decides its fate runs through the European Parliament — an institution whose members answer to voters. The European Citizens’ Initiative is the formal democratic mechanism through which EU citizens can place a topic directly before the Commission: one million verified signatures across a sufficient number of Member States carries legal weight. A petition against the EU Kids Act is currently open. If you live in the European Union and believe that child protection online should not come at the cost of digital identity surveillance, the destruction of the independent creative sector, and the end of anonymous internet access — this is the mechanism available to you. It is free. It takes less than two minutes. It is real.

Initiative Details TITLE: Stop The EU Kids Act — Protect the Open Internet
PLATFORM: European Citizens’ Initiative (ECI) — Official EU Commission Platform
ELIGIBILITY: EU citizens only — valid national ID or eID required for verification
DEADLINE: Check the initiative page for current signature deadline
LEGAL EFFECT: 1,000,000 verified signatures triggers mandatory Commission response

⚠ This initiative is hosted on the official European Commission ECI platform (eci.ec.europa.eu). Realm33 is not affiliated with the initiative organisers. The Directorate documents this initiative as a matter of public record and presents it here as the primary democratic instrument available to EU citizens who wish to formally oppose the proposal. Non-EU residents cannot sign but can share.

Leave a Comment

Your email address will not be published. Required fields are marked *