Policy Dossier — Complete Archival Record
Fig. 0 — Conspiracy Illustration of the subject. The use of children to make regulations which affects primarily adults.
05/10/2026
The EU Kids Act — formally designated COM(2026) 681 final, titled “EU Keeping Internet Digital Spaces Accountable and Trustworthy” — was published by the European Commission on 17 September 2026. It is a proposed Regulation, meaning that if enacted it would apply directly and uniformly across all 27 EU Member States without requiring national transposition legislation. It builds on and “specifies” the existing Digital Services Act (Regulation EU 2022/2065) and the AI Act (Regulation EU 2024/1689). The Commission’s stated rationale: only half of European children aged 9–16 say they feel safe online, and Member States are adopting diverging national laws that fragment the digital single market. A single EU-wide framework is proposed to harmonise protections and compliance obligations.
The Core Mechanisms — What the Act Requires
- Access Delay — Under-15 Social Media Ban The Act prohibits online social networking services and video-sharing platforms from allowing minors under the age of 15 to create autonomous accounts. Between ages 13 and 15, guardians may create limited-functionality accounts on behalf of a child. Under-13s may not access social media platforms at all in autonomous mode. This provision requires all covered platforms to verify the age of new account holders before access is granted — establishing age verification as a structural requirement for social media access across the EU.
- Safety by Design — Mandatory Platform Architecture Changes The Act mandates sweeping “safety by design” requirements for social networks, video platforms, online games, AI companions, and app stores. These include: prohibiting “autoplay, autoscroll, autoreplay, infinite scroll” and push notifications for minors; disabling algorithmic recommendation by default; prohibiting features that “incentivise engagement at regular times or with greater frequency”; implementing “effective” time management tools that prevent use during school hours and between 22:00 and 08:00 (core sleep hours); and restricting live-streaming and contact with unknown users. The Commission may expand this list through delegated acts — meaning future expansions do not require full parliamentary procedure.
- Online Games — Comprehensive Coverage Including Indie Titles The Act covers “any game that can be played on a computer, a mobile device, or a games console, irrespective of whether the game underlying software is subsequently executed locally, remotely, such as by means of durable medium, and irrespective of whether the service is provided free of charge, against payment, or against hybrid remuneration involving in-service purchases.” The only exclusion is games purchasable exclusively through physical media with no online component whatsoever. This definition explicitly covers small indie games with multiplayer features, modding platforms, and user-generated content tools. Critically, the Act states: “small and micro enterprises are not exempted from this Regulation, since they may equally provide harms to minors.”
- App Stores — Age Rating Enforcement and Access Blocking Software application stores — Apple App Store, Google Play, Steam, itch.io, and any equivalent — are required to implement age rating systems for all applications and to block minors from accessing age-inappropriate applications. The store operator, not the developer, bears primary enforcement responsibility. This creates an intermediary gatekeeping layer between developers and their audiences that did not previously exist in EU law.
- AI Companions and Chatbots — Emotional Dependency Prohibition AI companions and conversational chatbots accessible to minors are prohibited from displaying “behaviours or simulating emotions or interpersonal relationships that are likely to create emotional and other dependencies.” Persistent conversational memory must be disabled by default for interactions with minors. This provision extends regulatory reach to a rapidly growing category of consumer AI products.
The most significant structural concern raised by digital rights researchers about the EU Kids Act is not what it bans children from seeing. It is the infrastructure it builds to enforce that ban. Age verification — the technical requirement that every user of a covered service prove their age before access — cannot be implemented without identity verification. You cannot verify age without verifying identity. The Act acknowledges this, establishes the “EU Age Verification Scheme” as a centralised framework, and mandates that Member States make available at least one government-backed age verification solution. What is being constructed, critics argue, is the infrastructure for a de facto digital identity requirement covering access to most of the modern internet.
The EU Age Verification Scheme — What the Act Builds
The Act establishes, in Chapter V, a formal framework for age assurance. It requires that age verification be “highly accurate, reliable, robust, non-intrusive, privacy-preserving, and non-discriminatory.” It explicitly states that “self-declaration is not sufficient for compliance.” Member States must “ensure the availability of different means of obtaining a proof of age attestation” and must “make available at least one age verification solution” — meaning governments are mandated to provide the infrastructure. The definitions used for this scheme are explicitly drawn from Regulation EU No 910/2014 as amended by Regulation EU 2024/1183 — the eIDAS 2.0 framework that underpins the EU Digital Identity Wallet (EUDI Wallet) already under development across all 27 Member States.
The connection is not incidental. The EUDI Wallet is the EU’s in-development universal digital identity document — a smartphone-based credential that would allow EU citizens to authenticate their identity, age, and other attributes across both government and private services. The Kids Act’s age verification requirements create a compelling use case for the EUDI Wallet’s mass adoption: if you need to verify your age to access a social media platform or an online game, and the government has provided an EUDI Wallet solution as the mandated verification method, the result is mass consumer adoption of EU digital identity infrastructure driven by the requirement to play video games or use social media. Whether this is the Act’s intent or an incidental consequence is the question critics cannot resolve from the public record — the infrastructure is the same either way.
What Anonymous Internet Access Becomes
The practical implication of universal age verification requirements across social media, video platforms, gaming platforms, and app stores is that the anonymous or pseudonymous internet — in which a user can create an account, interact, purchase, and consume content without providing government-verified identity — ceases to exist for the services covered. A user wishing to play an online game in the EU, download an app, or create a social media account will be required to authenticate their age through a system linked, directly or through an intermediary, to a government-backed identity record. The Act provides for “privacy-preserving” verification mechanisms, and the Commission presents this as resolving the privacy concern. Critics respond that any system that verifies your age against a government record — regardless of how the data is subsequently handled — creates a point of identity linkage between your government file and your digital activity that did not previously exist.
Before the EU Kids Act reaches its final form, a directly relevant experiment has already been conducted at national scale: the United Kingdom’s Online Safety Act 2023, whose children’s safety provisions came into force on 25 July 2025. The UK Act required platforms accessible to under-18s — including YouTube, Spotify, Reddit, X, and Discord — to implement “highly effective” age verification for harmful content. The results documented in the first twelve months provide the most direct available evidence of what EU-wide age verification requirements produce in practice. They are not encouraging for the Act’s proponents.
The Discord Breach — October 2025
On 9 October 2025 — less than three months after the UK Online Safety Act’s age verification requirements came into force — Discord disclosed that approximately 70,000 users had their government ID photographs stolen in a breach of a third-party vendor the platform used for age-related appeals. Users who had submitted government ID documents as part of Discord’s age verification process — required to comply with the UK Online Safety Act — had their passport and driving licence photographs, selfie images holding their government ID, and IP addresses exposed. The hackers published over 100 photographs publicly online. Researchers at 404 Media reported the attackers claimed to have stolen 1.5 terabytes of data — suggesting the true scale of the breach significantly exceeded Discord’s initial disclosure.
Discord subsequently delayed its planned global rollout of mandatory age verification, with CEO Stanislav Vishnevskiy acknowledging publicly that the company had “made mistakes.” The Tea app suffered a parallel breach in July 2025, exposing 72,000 identity verification images. A verification firm contracted to handle UK age appeals lost control of 70,000 passports and driving licences to a separate incident. The pattern was consistent: legislation requiring mass identity document collection created a centralised target for criminal actors. The children the legislation was designed to protect had their government identification documents published on the internet as a direct consequence of the protection mechanism.
The Perverse Outcomes — What the UK Experiment Produced
- Traffic Shifted to Unregulated Sites — Not Removed Pornhub and multiple adult content providers blocked UK traffic entirely rather than implement age verification, stating publicly that the requirement “diverted traffic to darker, unregulated corners of the internet.” Compliant sites lost traffic to non-compliant sites. The intended effect — restricting minors’ access to harmful content — was not achieved; it was redirected. The harmful content did not become inaccessible; it became accessible through channels without any age verification at all.
- VPN Adoption Surge — Circumvention at Scale UK Google searches for “VPN UK” surged immediately following the Act’s implementation. The Electronic Frontier Foundation described age verification systems as “surveillance systems” that effectively drove privacy-conscious users — including minors — to VPNs that also bypassed all content controls. The circumvention mechanism made the regulation simultaneously more invasive for compliant adult users and less effective for the minors it targeted.
- Reddit Fined — For Collecting Too Little Identity Data Reddit was fined £14.5 million (approximately $19.5 million) by the UK Information Commissioner’s Office for failing to adequately verify users’ ages — despite the platform’s stated objection that “the ICO’s insistence that we collect more private information on every UK user is counterintuitive and at odds with our strong belief in our users’ online privacy and safety.” The paradox was explicit: regulators fined a platform for not collecting enough of the very identity data that, when collected, was being systematically stolen by hackers.
- Children’s Data Most Exposed The data breaches resulting from age verification compliance did not exclusively expose adults. In several documented breach incidents, family accounts, parental verification data, and data linked to accounts used by minors was included in the exposed datasets. Legislation enacted to protect children’s safety online produced documented incidents in which children’s identity documentation and associated family data was stolen and published. This is the UK precedent the EU Kids Act proposes to replicate at continental scale.
The Stop Killing Games movement — an international consumer rights initiative founded by YouTuber Ross Scott (Accursed Farms) following Ubisoft’s shutdown of the always-online racing game The Crew — campaigns for legislation requiring game publishers to ensure purchased games remain playable even after server shutdown, through local server options, offline modes, or preservation-friendly shutdown plans. The initiative achieved over 1.3 million verified signatures as a European Citizens’ Initiative under the name “Stop Destroying Videogames,” was formally submitted to the European Commission on 26 January 2026, and received a European Parliament hearing on 16 April 2026. The movement had, by mid-2026, achieved the most significant legislative momentum of any consumer gaming rights campaign in EU history.
Why the EU Kids Act Is “The Biggest Threat Yet”
When the EU Kids Act was published on 17 September 2026, Stop Killing Games founder Ross Scott published a detailed video analysis concluding that the Act represented “the biggest threat yet” to the organisation’s goals and potentially to the European gaming industry as a whole. The concern operates on two distinct but related levels.
First, the Act’s age verification requirements — applied to all online games with no small-enterprise exemption — create a compliance architecture that conflicts directly with the private server model that Stop Killing Games advocates as the preservation mechanism for online games after official server shutdown. If a game is required by law to implement age verification for all users, and the publisher shuts down the official infrastructure, who operates the age verification system for the private servers that Stop Killing Games wants to enable? A private server community running a preserved version of an old game cannot operate a compliant age verification system. The EU Kids Act’s requirements, if applied to private servers, would make the Stop Killing Games preservation model legally non-viable in the EU.
Second, the Act’s safety-by-design requirements — covering “addictive design,” “excessive engagement incentives,” and contact with unknown users — would require fundamental architectural changes to the design of online games that the affected studios may lack the resources to implement. In the video, Ross Scott cited Minecraft and Unreal Tournament as examples of games whose fundamental design features — open server browsers, user-to-user contact, engagement mechanics — would fall under the Act’s prohibitions when accessible to minors.
European Union legislation typically includes a small and medium enterprise (SME) exemption or a proportionality adjustment that reduces compliance obligations for smaller operators. The General Data Protection Regulation (GDPR), the Digital Services Act, and the AI Act all contain provisions reducing the burden on small businesses. The EU Kids Act explicitly and deliberately does not. The Commission’s stated rationale: “small and micro enterprises are not exempted from this Regulation, since they may equally provide harms to minors. It would undermine the objective of this proposal to exclude them from scope.” The consequence of this choice, as documented by independent gaming sector advocates, is that every indie developer who releases an online game into the EU market — regardless of their company size, revenue, staff count, or technical capacity — faces the full compliance obligations of the regulation.
The Practical Compliance Gap for Independent Developers
For a major publisher — Electronic Arts, Activision, Ubisoft — absorbing the compliance costs of implementing age verification systems, safety-by-design audits, legal representatives in EU Member States, and compliance plans is operationally manageable. For an independent developer operating with a team of two to ten people, a hobbyist project, or a game released with no ongoing commercial revenue, these requirements are not manageable. They represent a fixed overhead that is not proportional to revenue or scale.
The requirement to maintain a “legal representative in a Member State” — mandatory for providers not established in the EU — is alone a non-trivial ongoing cost. The requirement to implement an age verification system that meets the Act’s technical specifications requires either building proprietary infrastructure or contracting a third-party verification provider, both of which carry costs and liabilities that small developers cannot easily absorb. The requirement to prepare “compliance plans” subject to independent audit — while explicitly reserved for very large platforms for the notification mechanism — layers on documentation obligations that scale unfavourably with small operations. The cumulative effect, critics argue, is not that small developers will comply at great cost. It is that small developers will not release online games in the EU market at all.
The Broader Creative Ecosystem — Beyond Gaming
The Act’s scope extends beyond commercial game studios to encompass any creator operating an online service accessible to minors. Independent forum operators, hobbyist community platforms, small online tools with social features, and creator-operated platforms could all fall within the Act’s coverage depending on whether their service involves features characterised as an “online social networking service” or “video-sharing platform.” The Act includes carve-outs for not-for-profit educational repositories, open-source software development platforms, and public authority services. It does not include a carve-out for small commercial services, creative communities, or independent artists’ platforms. The creative internet — the layer of the web built by individuals rather than corporations — faces the same compliance obligations as the largest platforms on earth, with none of the resources that make those obligations survivable.
The EU Kids Act does not exist in isolation. It arrives as one layer in a regulatory stack that has been building since at least 2020, encompassing the Digital Services Act (2022), the AI Act (2024), the proposed Digital Fairness Act, the Audio-Visual Media Services Directive, eIDAS 2.0 and the EU Digital Identity Wallet, the GDPR enforcement intensification, and now the Kids Act — each described individually as a targeted response to a specific problem, together constituting what critics describe as the most comprehensive regulatory architecture for digital control ever assembled in a democratic polity. The Commission’s own documentation references its “2030 Roadmap on the future of digital education and skills” and the “Digital Decade 2030” targets as the framework within which the Kids Act sits.
The “You Will Own Nothing” Trajectory — Digital Rights Under Pressure
The phrase “you will own nothing and be happy” — originating from a 2016 World Economic Forum social media video discussing predicted changes by 2030 — has become a shorthand reference in digital rights discourse for a trajectory in which individual ownership of software, games, media, and digital goods is progressively replaced by licensed access that can be revoked, restricted, or modified by the licensor or regulator at any time. The Stop Killing Games movement itself exists precisely because this transition is already occurring in the gaming sector: games purchased by consumers have been permanently deactivated when publishers shut down online infrastructure, transforming a purchased product into a revoked licence.
Critics of the EU Kids Act situate it within this trajectory in two ways. First, the Act’s safety-by-design requirements give regulators ongoing authority over the design and features of software — not just at release, but continuously, since delegated acts can extend or modify requirements without full parliamentary procedure. A game, platform, or application that is compliant today may be non-compliant next year following a delegated act expansion, with no legislative vote required. Second, the age verification infrastructure — once built for child protection purposes — creates a system that can in principle be extended to other categories of content, other categories of verification, and other categories of restriction. The architecture built to verify age is the same architecture that could later verify political identity, creditworthiness, criminal record, or any other attribute a future government might legislate around. The infrastructure is built once; its scope is a political question.
The End of the Anonymous Internet — Structural Analysis
The specific combination of requirements in the EU Kids Act — age verification for social media, age verification for gaming platforms, age verification by app stores, “safety by design” requirements that apply even where platforms cannot prove a user is an adult — effectively means that any EU resident wishing to use covered digital services without government-linked identity verification must either provide that verification, use a VPN to appear to be in a non-covered jurisdiction, or go without the service. This is not a paranoid extrapolation from the text; it is the stated mechanism. The Commission describes the EU Age Verification Scheme as a solution to the fragmentation problem. What it solves, structurally, is the existence of unverified digital presence. What it creates, structurally, is a population of verified digital identities whose access to digital services is mediated by a government-linked credential. Whether this outcome is characterised as “child protection” or “the end of anonymous internet access” depends entirely on which starting concern you bring to the document. The technical architecture is the same.
Opposition to the EU Kids Act — or to its core mechanism of mandatory age verification — spans a wide range of constituencies that do not typically find themselves in agreement. The Directorate documents the principal positions without endorsing any of them. The concern is not monolithic; different critics object to different elements. What they share is the view that the Act’s mechanism is disproportionate to its stated aim, or that it achieves something beyond its stated aim, or both.
- Stop Killing Games — Gaming and Consumer Rights Founder Ross Scott has described the EU Kids Act as the “biggest threat yet” to both the Stop Killing Games initiative’s preservation goals and to the European gaming industry. His specific concerns centre on the Act’s application to private servers, the no-SME-exemption clause, and the impossibility of a small developer or community operator maintaining compliant age verification infrastructure for a game whose original publisher has exited the market. The initiative reached over 1.3 million signatures on its European Citizens’ Initiative, demonstrating substantial public engagement with digital consumer rights in the EU gaming context.
- Electronic Frontier Foundation — Surveillance and Privacy The EFF, responding to the UK’s parallel Online Safety Act (the direct legislative precursor to the EU Kids Act’s mechanism), stated explicitly that “age verification systems are surveillance systems.” The organisation’s assistant director of federal affairs, Maddie Daly, made this statement in the context of the Discord breach — articulating the position that the architecture required for age verification cannot be separated from the architecture of identity surveillance, regardless of the stated purpose for which it is built.
- Platform Operators — Pornhub’s Decision as Evidence Pornhub — one of the world’s largest online platforms — chose to block all UK traffic rather than implement the UK Online Safety Act’s age verification requirements. The company stated that the law “diverted traffic to darker, unregulated corners of the internet” and “jeopardized the privacy and personal data of U.K. users.” This is not a privacy advocacy position; it is a market operator’s documented assessment that the compliance mechanism was more harmful than the problem it addressed. The same operator is among those facing compliance obligations under the EU Kids Act.
- Privacy Researchers — The Data Breach Literature Academic and research commentary following the Discord breach, the Tea app breach, and the UK verification firm breach has consistently documented that age verification laws create “a veritable treasure trove for hackers” (TechXplore, November 2025). Research from Proton and independent security researchers has documented that the identity verification sector — AU10TIX, k-ID, and similar providers — has a documented breach history that predates the Online Safety Act and continued immediately following its implementation. The infrastructure mandated for child protection has a demonstrated vulnerability to exactly the kind of exposure that most damages the children it claims to protect.
- Wikipedia — Institutional Challenge to Age Verification Wikipedia challenged the UK Online Safety Act in court, arguing that its age verification provisions were incompatible with its role as a free-access encyclopaedia. The challenge was ultimately unsuccessful but was noted as establishing new precedent for institutional resistance to the legal framework. The Wikimedia Foundation’s position — that requiring identity verification for access to an encyclopaedia represents a fundamental departure from the open-access principle of public knowledge — is a documented institutional position in the debate.
- Independent Developers — Market Exit as Response Multiple independent developers, when asked about the EU Kids Act in gaming press coverage, have indicated that the most likely response to unmanageable compliance requirements is not compliance — it is EU market exit. Geo-blocking the EU is technically straightforward for an online game. A small studio with ten staff and a global online game release faces the same compliance obligations as Electronic Arts under the Act. The rational economic response for a small studio, many observers note, is not to build a compliance system it cannot afford — it is to block EU IP addresses and serve only markets where compliance costs are proportionate to revenue.
The EU Kids Act is, as of October 2026, a legislative proposal. It has been published, it is in the EU’s ordinary legislative procedure, and it carries the Commission’s formal backing. It is not yet law. The concerns documented in this file are responses to the proposed text, not to enacted requirements. The Directorate notes that the gap between a Commission proposal and enacted regulation is substantial — the Digital Services Act took approximately two years from proposal to enactment; the AI Act took approximately four. The Kids Act may change significantly in the legislative process. It may also pass substantially as proposed. The timeline and the text are what the Directorate can document; the outcome is not.
Evidentiary Status — October 2026
Archival Status and Classification
The EU Kids Act is assessed by this Directorate as one of the most consequential pieces of proposed digital regulation in European history — not primarily because of what it restricts children from seeing, but because of the infrastructure it mandates to implement those restrictions. The child-safety objective is genuine and the harms it addresses are real: the Commission’s documentation of online risks to minors is substantive and well-evidenced. The question that this file documents — and that the Directorate does not resolve — is whether the mechanism chosen to address those harms is proportionate, or whether it is a regulatory architecture whose effects on the adult internet, the independent creative sector, digital anonymity, and the trajectory toward universal digital identity documentation are incidental consequences of good intentions, or something more deliberately considered.
The UK precedent answers one question clearly: mandatory age verification for online services does not protect children’s data. It concentrates it into a smaller number of high-value targets and makes it accessible to criminal actors through the very infrastructure designed to protect it. Whether the EU can implement the same mechanism at continental scale with materially better security outcomes is an empirical question that will be answered only after enactment. The Directorate notes that the question has already been answered once, at smaller scale, in a direction that should concern legislators. Whether it does is a matter of public record that this file will continue to document.
Recommended classification: ACTIVE LEGISLATION — TIER ONE SIGNIFICANCE — CHILD SAFETY OBJECTIVE GENUINE — DIGITAL IDENTITY INFRASTRUCTURE IMPLICATIONS CONFIRMED IN TEXT — INDEPENDENT SECTOR IMPACT SEVERE AND DOCUMENTED — UK PRECEDENT DATA BREACH CONFIRMED — ARCHIVAL STATUS: ACTIVE, CRITICAL, AND EVOLVING — DIRECTORATE MONITORING ONGOING
Source References
- EU Kids Act — Full Proposal Text: COM(2026) 681 final — eur-lex.europa.eu
- Stop Killing Games — Video Response to EU Kids Act: Ross Scott (Accursed Farms) — “This could legitimately end Stop Killing Games” — youtube.com
- Notebookcheck — Stop Killing Games EU Kids Act Warning (October 2026): notebookcheck.net
- Stop Killing Games / Stop Destroying Videogames — European Citizens’ Initiative (1.3M signatures, January 2026): citizens-initiative.europa.eu
- TechCrunch — Discord Data Breach, October 2025: techcrunch.com
- NBC News — 70,000 Government ID Photos Exposed in Discord Breach: nbcnews.com
- The Register — Discord 70,000 Photo IDs Compromised: theregister.com
- PinkNews — Discord Delays Age Verification After Breach (February 2026): thepinknews.com
- Proton — Is Age Verification Safe?: proton.me
- Courthouse News — Reddit £14.5M UK Fine (2026): courthousenews.com
- TechXplore — Online Age Checking Creates Treasure Trove for Hackers (November 2025): techxplore.com
- The Rational Forum — UK Online Safety Act as Digital ID Infrastructure (Substack, 2025): rationals.substack.com
- IBANET — UK Online Safety Act Implementation Analysis: ibanet.org
- EU Digital Identity Wallet Framework — Regulation EU 2024/1183 (eIDAS 2.0): eur-lex.europa.eu
- Wikipedia — EU Kids Act (disambiguation): en.wikipedia.org
- PC Gamer — Online Safety Act coverage hub: pcgamer.com/tag/online-safety-act
- GamingOnLinux — Discord ID breach coverage (October 2025): gamingonlinux.com
Last updated: October 2026. Compiled by the Directorate of Information Preservation and Archival, Realm33.org. The Directorate’s observation: legislation framed around protecting the most vulnerable members of society has historically faced the least scrutiny and the most difficulty producing effective opposition. The question is not whether children deserve protection online — they do. The question is whether the specific mechanism proposed achieves that goal, or whether it achieves something else at children’s expense, in their name. The UK precedent suggests the latter. The Directorate files this document as an ongoing record and will update it as the legislative process progresses.
The EU Kids Act is a proposal. It has not been enacted. The legislative process that decides its fate runs through the European Parliament — an institution whose members answer to voters. The European Citizens’ Initiative is the formal democratic mechanism through which EU citizens can place a topic directly before the Commission: one million verified signatures across a sufficient number of Member States carries legal weight. A petition against the EU Kids Act is currently open. If you live in the European Union and believe that child protection online should not come at the cost of digital identity surveillance, the destruction of the independent creative sector, and the end of anonymous internet access — this is the mechanism available to you. It is free. It takes less than two minutes. It is real.
⚠ This initiative is hosted on the official European Commission ECI platform (eci.ec.europa.eu). Realm33 is not affiliated with the initiative organisers. The Directorate documents this initiative as a matter of public record and presents it here as the primary democratic instrument available to EU citizens who wish to formally oppose the proposal. Non-EU residents cannot sign but can share.









