17 September 2026: the Commission adopts the proposal
Anyone typing «regulator fines AI» today is searching for the tail end of the regulatory cycle. The beginning came on 17 September 2026, when the European Commission adopted the proposal for an EU KIDS Act, short for «EU Keeping Internet Digital Spaces Accountable and Trustworthy».
The text has a stated aim: to protect minors from risky digital services and from AI systems. The jurisdiction is the European Union. The status is that of a legislative proposal, now before the European Parliament and the Council.
The proposal, published on 17 September 2026 on the European Commission's portal[1], arrives alongside a Communication on the European approach to child safety online and a Staff Working Document setting out the impact analysis. Three documents, one design.
Fifteen: the single European age
At the heart of the proposal sits a number: fifteen.
Below that threshold, creating an account independently remains restricted on the social networking services and video sharing platforms identified in the text. The measure covers those specific services and the systems connected to them. The wording chosen speaks of a limit on independent creation, which opens a role for whoever holds parental responsibility.
Before this instrument, the threshold varied from country to country. Article 8 of Regulation 2016/679 leaves Member States a band between 13 and 16 for a child's digital consent, and States have used it in different ways. The result is a fragmented map that every pan-European platform manages country by country.
Harmonisation is the text's central argument: a single age across the Union removes obstacles to the functioning of the digital single market. The stated benefit is twofold: legal certainty for companies, uniform protection for European children.
Digital services and AI systems within the same perimeter
The regulatory delta lies in the perimeter. Until now, protecting minors online lived in separate texts.
The Digital Services Act, Regulation 2022/2065, governs the obligations of online platforms and has applied in full since 17 February 2024. The EU AI Act, Regulation 2024/1689, governs AI systems on a phased application timetable. The age of digital consent remains a national matter, by virtue of the referral in Article 8 GDPR.
The proposal of 17 September 2026 brings digital services and AI systems together in a single text dedicated to minors. For a group that offers both, the convenient separation between the platform team and the model team falls away.
A compliance posture calibrated to the DSA perimeter is now poorly calibrated for a conversational assistant open to the general public. The audit is still required; what changes is its scope.
The governance signal
The governance signal: access by minors becomes a product function, verifiable, documentable and attributable to a specific role.
Whoever designs the sign-up flow decides whether the service complies. The age a user declares becomes a data point to be verified by proportionate methods. Every method entails processing personal data that must be justified.
The question the General Counsel puts to product is a direct one. Which role, named in writing before release, answers for the protection of minors on this service?
A framework that avoids that name produces documentation, and documentation counts for little in front of a regulator. Anonymous accountability remains compliance theatre.
The objection: verifying age collects data
The strongest objection to the text comes from the privacy side. Verifying everyone's age serves to protect some, and that check generates data on every user.
Data protection authorities have been tracking the issue for years. The minimisation principle in Article 5 GDPR requires verification to use the least intrusive data possible. Zero-knowledge proofs and European digital identity wallets enter the technical conversation here.
The Board Audit & Risk Committee inherits this tension in the form of disclosure. Protection of minors built on an archive of identity documents creates a new risk, and that risk has to be declared to shareholders.
The contrast with the United States
The comparison with the American framework is instructive.
There, online protection of minors runs through state laws that overlap and change fast. Each state legislates according to its own political position, and the federal courts step in downstream. The result is a mosaic that companies reassemble jurisdiction by jurisdiction.
State-level fragmentation is the American pattern, well beyond any single case. A coherent federal law remains far off.
The European Union takes the opposite road: one number, one procedure, one coherent enforcement structure. For a group active on both sides of the Atlantic, the European model becomes the simplest common baseline to implement.
The fines come later, and they come
Enforcement measures follow the statute, and they land. France's CNIL fined the company Extia 300,000 euros for failing to protect individuals' rights, as the EDPB[2] reports.
The amount matters less than the principle. A procedural failing in handling data subjects' rights is enough to trigger the measure.
The litigation front runs in parallel. In the United States, Doe v. GitHub, Inc.[3] shows the courts at work on liability tied to AI systems. Two distinct mechanisms, one shared direction: the administrative authority fines, the civil court assigns liability.
A compliance programme built before entry into force absorbs both fronts.
Three decisions for the board
The text is still a proposal, and this is the cheapest moment to move. The three decisions that follow concern the months before adoption.
- Inventory: which of the group's products remain accessible to users under 15, and through what age assurance mechanism (General Counsel and Chief Compliance Officer).
- Risk framework: which entry in the risk register covers access by minors to conversational AI systems (Chief Risk Officer).
- Disclosure: what the Board Audit & Risk Committee reports in the accounts on the protection measures adopted and the data collected to apply them.
The CEO inherits the fourth decision, strategic in nature. A service whose user base includes a significant share of European teenagers faces a product choice constrained by the law. That constraint feeds into growth plans and user acquisition projections.
Organisations that map products and sign-up flows now reach the final vote with the inventory ready. Those that wait for the final text buy the same work at a higher price.
Regulatory horizon
Current status: proposal adopted by the European Commission on 17 September 2026. Jurisdiction: European Union, with effect on every service aimed at users resident in the Union.
Next steps: examination by the European Parliament and the Council, interinstitutional negotiation, final text. The fifteen-year threshold remains the point on which political debate will concentrate. Amendments are a normal part of the process.
On the parallel track, Regulation 2024/1689 continues its phased application, with obligations on high-risk systems placed later in the timetable. Anyone running a European digital product is working today against two timetables set to converge.
The question of the age of access has received a European answer. A second question, on verifying that age, has just opened.
This article was written by an AI editorial author under human supervision, in compliance with the transparency obligations of Regulation (EU) 2024/1689 (AI Act, Art. 50). Sources are linked in the text.
Article by ATLAS
Sources
- on the European Commission's portal 17 Sep 2026 (digital-strategy.ec.europa.eu)
- EDPB (edpb.europa.eu)
- Doe v. GitHub, Inc. (courtlistener.com)