OUT-LAW ANALYSIS

The scope of the proposed KIDS Act

Boy and girl playing games on mobile phone_Digital - SEOSocialEditorial image

It is envisaged that the KIDS Act apply to seven categories of services – including online games. miljko/iStock.


A complex new EU-wide child online safety regime has been envisaged by policymakers, with the European Commission publishing a proposed new KIDS Act earlier this month.

Imagined is a graduated system of age-related access restrictions and parental controls for digital services, each of which will need to be designed with child safety in mind.

The complexity stems from the fact that the proposed new obligations are not uniform. First, different expectations are set with reference to the age of the child – there are overarching rules applicable to services accessible to under-18s and these are supplemented by graduated restrictions and requirements in relation to children aged between 13 and 15 and for under-13s.

On top of that, requirements vary depending on the type of service that is being provided. Social networks, video-sharing platforms, app stores, operating systems, online games and AI companions and chatbots each face different duties from one another.

This complicated web of obligations belies the clear and simple aims of the proposal: to address the risks that children face when using online services, such as exposure to harmful content and dangerous interactions with other users, and to avoid the fragmentation and inconsistencies that would arise should individual EU member states impose new child online safety measures in silos.

Below, we unpick the Commission’s KIDS Act proposal with a view to helping businesses understand how the proposed new regime could impact on the services and systems they provide.

Scope and exemptions – a brief overview

There are seven categories of systems and services that fall within the scope of the proposed KIDS Act. These are:

 

  • online social networking services (social networks);
  • video-sharing platform services;
  • software application stores (app stores);
  • online games;
  • operating systems;
  • AI companions;
  • general conversational chatbots (chatbots)

In each case, only systems or services within one of those seven categories that are “accessible to minors” are in-scope. That is, systems or services accessible to children under the age of 18.

It is proposed that the KIDS Act apply extraterritorially. In the case of social networks, video-sharing platforms, app stores, online games, and operating systems, the scope of the draft regulation is tied, as in the EU Digital Services Act (DSA), to whether the recipient of the service is “established or located in the Union”, not where the service is accessed from. This would require providers of those services to not only adhere to its requirements when an EU-based child engages with their services at home but also when accessing the service from outside of the EU, such as when on holiday. This suggests providers would need to track not only where the user is accessing the service from, but also where they are normally established.

Exemptions are envisaged for some services. An example is not-for-profit online encyclopaedias – a reference expected to cover Wikipedia – and open-source software-developing and sharing platforms, which is expected to encompass platforms such as Github.

Further exemptions outlined include those provided for on educational and scientific research grounds, but the regulation does not provide exemptions with reference to a company’s size – small and micro-enterprises are not excluded from the proposal's scope.

Online platforms and ‘VLOPs’

As explained in a separate Pinsent Masons guide, the DSA imposes a tiered system of regulation on online intermediaries. This includes, for providers of online platforms accessible to minors, some overarching child safety duties – such as a duty to put in place appropriate and proportionate measures to ensure a high level of privacy, safety and security of minors – on their service. With its KIDS Act proposal, the Commission seeks to particularise those requirements – the compliance with which would be deemed to meet the platform providers’ DSA duty.

The DSA sets out qualifying criteria and a process by which online platforms can be designated as ‘very large’ online platforms (VLOPs). VLOPs are a category of online intermediary that face among the strictest obligations under the DSA, beyond those that apply to smaller online platforms. In the context of child online safety, this includes duties to assess risks their service poses to minors and implement appropriate measures to address them, such as age verification and parental control tools.

The KIDS Act proposal envisages expanding the child online safety obligations that VLOPs are already subject to – including by requiring VLOPs to prepare a compliance plan, setting out how they will adhere to the requirements they face under the KIDS Act. Those compliance plans must be subject to independent audit whose summary report must be shared with the European Commission by the provider. The Commission can order VLOPs to take corrective action if they identify shortcomings.

Under the KIDS Act, VLOPs would also face enhanced requirements around age verification, disclosure of information and interoperability of guardian control tools, and around monitoring, testing and evaluation of the measures they implement.

For the purposes of the KIDS Act, three categories of service – social networks, video-sharing platforms and app stores – are all classed as ‘online platforms’. In addition, a video gaming platform – a sub-category of online games – is also considered an online platform.

The classification of these services as online platforms connects those services to the DSA's supervisory and enforcement mechanism. Accordingly, the KIDS Act obligations applicable to these services will not be subject to a separate supervisory and enforcement regime established under the new legislation but will instead be supervised and enforced through the existing framework provided for under the DSA.

Social networks and video-sharing platforms

Social networks and video-sharing platforms are considered sub-categories of online platform for the purposes of the KIDS Act. The providers of those services face very similar – but not identical – obligations under the proposal.

Social networks are defined as platforms that enable end users to connect and communicate with each other, share content and discover other users and content across multiple devices and, in particular, via chats, posts, videos and recommendations. That definition is drawn from the EU Digital Markets Act (DMA).

The definition of video-sharing platforms has its roots in EU audiovisual media service law (AVMS Directive). It broadly covers services that are devoted to providing programmes and/or user-generated videos to the general public for the purposes to inform, entertain or educate. The service must be provided over an electronic communication network. Such a service is only in scope if the provider does not have editorial responsibility over the content but rather determines the organisation of it, including by automatic means or algorithms.

Providers of both social networks and video-sharing platforms face a raft of requirements, including general duties around safety by design, rules on addictive design, and requirements around their use of ‘recommender systems’ – another concept borrowed from the DSA that refers to systems that generate personalised recommendations for users. They also face an overarching obligation to ensure certain features – such as geolocation tracking and access to microphone and camera – are disabled by default for all children, with only heavily conditioned scope given to the providers to change those settings in the case of children aged over 15.

The providers also face bespoke requirements – for example, they are generally prohibited from enabling children under the age of 15 to set up their own accounts or to otherwise access their service if their service poses a risk to the privacy, safety or security of such children. The KIDS Act proposal specifies when the service will be considered to pose such a risk, with relevant factors including the degree of interactivity the service provides between users and the extent to which features of the service enable uninterrupted content consumption or incentivise interactions.

Where such a risk is present, enabling under 15s to access the service is prohibited, unless this is done via “limited features” accounts set up by the child’s guardian and a range of tools and controls are enabled for that guardian. Again, the KIDS Act proposal sets out more detail around those requirements.

For video-sharing platforms distinctly, an exception is provided for children under the age of 13. Where a video-sharing platform service is specifically designed for such young children, the provider may enable a guardian to allow a child below 13 limited access to the service via the guardian's own account, with no separate account created for or attributed to the child. Other restrictions include the turning off of personalisation and recommender features and tools enabling guardians to control the child’s access.

App stores

An app store is defined as a type of online intermediation service, which is focused on software applications as the intermediated product or service. That definition is drawn from the DMA.

App store providers face fewer bespoke obligations than providers of social networks and video-sharing platforms, despite falling under the umbrella of online platform.

Whilst they too would be expected to adhere to general duties around safety by design, the remainder of their proposed duties centre around establishing and operating an age-rating system, to ensure children can only download the apps that are age-appropriate for them. This reflects an additional layer of protective measures that supplement the service-level obligations facing the in-scope app providers.

Online games

The concept of ‘online games’ is defined under the proposed new KIDS Act as either a video game or video gaming platform, with the latter referring to an online platform that involves interaction with a user interface or input device to generate visual feedback from a display device in a simulated environment [for play or entertainment purposes].

The definitions are extremely broad. It is conceivable that it encompasses not only some of the most contemporary games that enable users to see one another on screen and exchange messages but also games that have a much more classic online multiplayer mode. Industry body Video Games Europe, reacting to the KIDS Act proposal, recently cautioned against “sweeping age assurance measures applicable to every game and player in Europe”.

Like with most of the other categories of in-scope services, providers of online games are subject to the general obligation on safety by design. They also face bespoke requirements to put in place measures to ensure a high level of privacy, safety and security of minors – with those rules drawing on aspects of other parts of the KIDS Act, such as rules around addictive design, default settings and tools for guardians.

Online games providers must take further steps to ensure their games are not used to entice minors to initiate contact on other services that could pose a risk to their privacy, safety and security. 

Under the proposal, standalone economic transaction requirements that apply to social networks and video-sharing platforms would not apply to online games. Instead, game-related codes of conduct are expected to address monetisation practices.

Operating systems

An operating system is defined, for KIDS Act purposes, as a system software that controls the basic functions of the hardware or software and enables software applications to run on it. That definition is drawn from the DMA.

Operating systems are not subject to the general obligation on safety by design that the other six categories of in-scope services face under the KIDS Act proposal, nor are bespoke rules envisaged for their providers. However, providers of operating systems are seen as playing an important intermediary role in enabling age-appropriate access to other in-scope services.

The sole obligation which seems intended to be imposed on operating system providers is that if they have received an age signal, they enable the user to share the signal with other in-scope services.

Like all the other in-scope providers, providers of operating systems would also face obligations aimed at preventing circumvention of the KIDS Act requirements.

It is not clear whether open-source operating systems will be impacted.

AI companions and chatbots

The KIDS Act proposal reflects a desire to extend existing EU regulation of AI systems and models, under the AI Act, deeper into the child online safety sphere. AI companions and chatbots are targeted by the proposal.

An ‘AI companion’ is broadly defined as an AI system that provides sustained, personalised interaction or companionship which simulates or facilitates a social, emotional or interpersonal relationship with a user.

A ‘general conversational chatbot’ is a general-purpose AI system with general conversational functionalities for direct interaction with users that is capable of providing assistance across multiple domains and tasks. AI systems whose conversational functionality is limited to a specialised service, task or pre-defined set of functions, including specialised customer service, business operation, technical support, transactional, educational, information-retrieval, industrial or manufacturing AI applications, are expressly excluded from the scope of that definition.

Some comparisons can be drawn with the UK’s plans to impose a minimum age requirement of 18 for AI tools that either operate as a “romantic companion” or have “similar intimate functionalities”. While the detail of what the UK is proposing has not yet been published, it appears that the KIDS Act proposal would apply to a wider number of AI systems.

The KIDS Act proposal envisages providers of AI companions and chatbots adhering to the general safety by design obligations and separate rules around addictive design and default settings, among others. Providers would be expected to design their systems so minors are not exposed to features that are likely to create emotional dependencies and to undertake testing and monitoring to identify and mitigate harms to their safety, health, fundamental rights and well-being and development.

Specific rules also apply to AI companions or chatbots that are embedded within other online services, like social networks, video-sharing platforms, or online games. Those rules require providers of those services to ensure that AI companions and chatbots are not automatically activated and that children are not encouraged to use them. Where those AI systems are enabled, providers must ensure children can easily opt out from using them.

We are processing your request. \n Thank you for your patience. An error occurred. This could be due to inactivity on the page - please try again.