The EU KIDS Act: what the Commission's proposal asks of the game itself

September 26, 2026

The EU KIDS Act: what the Commission's proposal asks of the game itself

On 17 September 2026 the European Commission published its proposal for the EU KIDS Act, COM(2026) 681 final. KIDS stands for Keeping Internet Digital Spaces Accountable and Trustworthy.

Online games are in scope in their own right: Article 2(1)(d) names them, and Section IV, "Obligations for providers of online games", holds Article 15, addressed to game providers directly. The duties land on the provider of the game, meaning whoever offers it to players in the EU. The app store answers under its own Article 16 separately, and that does not lift the duties off the game provider: shipping through Steam or the App Store does not move them to the store. For most releases the provider is the publisher; a studio building the game under contract most likely is not, though the text does not say so outright (see what the text settles by silence). The Commission's Q&A: "Games must also be safe by design."

Ratings change too, and that change runs past the studio: the proposal puts the mandatory age-rating system on the app store, not on the developer. A publisher reaches PEGI by another road, as a participant in an industry system. PEGI binds no one as a matter of law: recital 39 calls its system and code a benchmark "for the participating companies". What exactly changes about ratings, what Article 16 asks of the store and where that turns into revenue is covered separately, in The EU KIDS Act: age ratings, app stores and PEGI. This piece is about what the proposal asks of the game itself.

Parliament, Council and trilogues lie ahead, and the wording will change. What to do with the build before adoption is already clear.

What the document is and where it stands

What the proposal asks of the game itself

The first duty arrives before Article 15. Article 8(1) names providers of online games among the addressees of the general safety-by-design obligation: ensure a high level of privacy, safety and security of minors, "design those services and systems in accordance with the requirements laid down in this Chapter by default", and derogate from them only "after they have established that the recipient of the service or the user of the system is an adult, by making use of age assurance in accordance with Chapter V". It is the broadest duty a game provider carries in the proposal, but not its only link to age assurance.

The moment the provider switches age assurance on, Article 27 binds it — accuracy, reliability, security, robustness, non-intrusiveness, privacy and data protection, and non-discrimination — and so does Article 28: the solution must not identify, locate, track, target, advertise to or profile the recipient, no more personal data than strictly necessary may be processed, and "any age assurance measure shall be zero knowledge proof". Article 28(4) lets both the software application store under Article 16(4) and the game provider under Article 8(1) store the age signal at account level for the sole purpose of avoiding a repeated check, and it limits that signal to the minimum information necessary for that purpose. Article 29(4) leaves the choice open to both — the game provider under Article 8(1), the software application store under Article 16(2) and 16(3): the providers concerned "may use age assurance solutions other than the EU age verification solutions", where they can demonstrate that those solutions meet the requirements of Articles 27 and 28. And the outcome can be contested: Article 29(5) requires a free internal complaint-handling mechanism against the result of age assurance.

Article 15(1) opens with a general duty: providers of online games shall put in place measures ensuring a high level of privacy, safety and security of minors, including at least these four.

Article 15(2) requires safeguards against the game being used to entice minors to initiate contacts on other services "which may pose a risk to their privacy, safety and security"; 15(3) addresses platforms carrying user-created games. Article 15(4) gives a right to point at a code, and only that: a provider adhering to a code of conduct assessed as adequate by the Commission under Article 17 "may rely upon such adherence to demonstrate compliance with the obligations set out in this Article" — those obligations and no others. The recitals draw the line. Recital 39: "the mere fact of participating in and implementing a given code of conduct should not in itself presume compliance". Recital 40: adherence "may serve as an indication of compliance with the measure-based obligations laid down in this Regulation, but cannot derogate from its prohibitions".

The Article 15 list is not the whole of it. Article 18 is addressed to providers of online games directly: the information, warnings and user-control tools of Chapter III must be easily accessible to every minor and presented so that minors can understand them, and 18(2) requires two mechanisms — control over content with immediate and durable effects, and control over interaction settings that allows temporary changes and an easy return to previous or default settings.

Article 20 names the same addressee and carries seven paragraphs of its own. Six conditions apply to the tools themselves, and they read as a checklist: tailored to the age of the minor with due account of gradual development; easy to use, access and activate for minors and guardians alike; changes only with the same degree of authorisation as the initial activation; effective and not easily circumvented or undermined by the design or operation of the service; no disproportionate restriction of minors' rights; respect for the minor's agency and privacy. Then come telling the minor when a tool is in use, reminding guardians of the tools, built-in mechanisms for time limits, settings management and reporting, and a duty to let guardians and minors report where the tools are not operational or do not function as prescribed (20(6)). The Commission is empowered, but not obliged, to add technical and operational requirements by delegated act (20(7)); the interoperability duty in 20(5) reaches very large online platforms only. Articles 19 and 21 address video gaming platforms and Article 22 very large online platforms: neither lands on an ordinary video game.

One detail is easy to lose: only Article 11(1) is carried into games. Article 11(2), which lets the provider change those defaults for a minor above 15 who was clearly and unambiguously informed and explicitly consented, is not on the Article 15 list. The permission a social network has to weaken those settings is absent for a game altogether.

Games already released: there is no transitional rule. Article 32 does not pass the game provider by — its paragraph 3 derogates from Article 8(1) and relieves providers falling within that Article, where online games are named expressly, and providers of software application stores, of assessing the recipient's age where they can establish with a high degree of confidence that the recipient is not a minor. Nothing in the text postpones the duties themselves for a game already shipped.

Waiting for the final text costs more than starting now. The four points of Article 15 — compulsive use, default settings, contacts and guardian tools — are build and backend changes that fit an ordinary development cycle: the guardian tools can be built on the conditions Article 20 already sets, and the technical and operational requirements are ones the Commission may or may not add later. A team that works through the list calmly meets the adopted regulation with a finished product; one that waits does the same work against a deadline.
— Futura Digital's assessment

Monetisation and loot boxes: where they sit in the text

Article 13 covers economic transactions: before one happens the minor is told clearly and in real time that it is an economic transaction; purchases in in-game currency bought with money show the equivalent in the official currency of the member state where the player habitually resides; and the service may not be designed, organised or operated in a way that can lead to excessive, impulsive or unwanted spending, which expressly includes not exposing minors to variable reward systems.

Article 13 is addressed to social networking and video-sharing providers and is not on the Article 15 list. The intention to give games the same protection sits in recital 40, and the route there runs through the codes of conduct of Article 17(2)(f), which name monetisation practices outright.

Monetisation has an industry road as well, and it is already marked out: the PEGI criteria on paid random items, timer-backed offers and pressure to play have applied since June 2026 in their own right, independently of the proposal, and are set out in the piece on ratings, app stores and PEGI. This scale is live today, and Article 17(2)(f) tells codes of conduct to build, where appropriate, on existing pan-European age classification frameworks, including their criteria on interactive functionalities and monetisation practices. Which means a paid mechanic in a game carries two independent addresses at once: the Article 15 list and the code of conduct to come on one side, the PEGI category on the other. Run a review of loot box and randomised reward mechanics against both.

That draws the boundary with the Digital Fairness Act, a separate initiative still unpublished: the Commission work programme for 2026 announces it as "a legislative initiative for the fourth quarter of 2026", and the European Parliament's Legislative Train Schedule carries the same indicative date under the status "announced". The KIDS Act has its own ban on variable reward systems, so "loot boxes belong entirely to the other act" is wrong. The line runs by addressee and by mechanism, and the wider frame for shipping a game into the EU is our publishing and gamedev legal support.

What to do now

STEP 1 — Establish your role under Article 2

Video game or video gaming platform: that choice decides who supervises you and on what scale you are fined.

STEP 2 — Walk the four points of Article 15(1) through your build

Defaults, notifications and return-to-play mechanics, contacts, the guardian tools of Article 20, with under-13 access closed except through those tools. Most of it is settings and interface work; the guardian tools and under-13 access reach into the account system itself, and the technical and operational requirements for those tools are not written yet: the Commission is empowered to lay them down in delegated acts, but is not obliged to.

STEP 3 — Sort out your AI features under Article 14

A bot embedded in a game falls under Article 14(2): no automatic activation, no prominent display, no nudging minors towards it, an easy opt-out at any time. Whether an LLM-driven story NPC also counts as an "AI companion" or a "general conversational chatbot" under Article 3(5)(c) and (d) decides whether Article 14(1) reaches it. That paragraph bars design features that simulate interpersonal relations and are likely to create emotional dependencies, and it requires risk testing before release and post-market monitoring afterwards, including detecting and responding to serious incidents involving minors. The monitoring falls away "unless the system is provided by a micro or small enterprise within the meaning of Recommendation 2003/361/EC" — for an indie studio or a small publisher that carve-out applies more often than not. Independently of the KIDS Act, Article 5 of the AI Act has since 2 February 2025 prohibited AI systems exploiting age-related vulnerabilities with the objective or effect of materially distorting behaviour so as to cause, or be reasonably likely to cause, significant harm. Fines run up to EUR 35 million or, for an undertaking, up to 7% of total worldwide annual turnover, whichever is higher.

The steps after these no longer fix the build; they reconcile it with the shopfront. The store's methodology becomes public under Article 16(5), and the consequence under 16(2) is direct: the store closes access and purchase for minors by category. How to re-score the category and line the build up with the store listing is in the piece on ratings, app stores and PEGI. Checking the whole perimeter of duties at once is what a regulatory compliance audit is for.