Technology · Digital regulation
EU proposes 13-plus age floor for unsupervised social media use
Commission president Ursula von der Leyen backs expert panel recommendation for phased access, with under-13s restricted to time-limited, supervised use only.
The European Commission will move to legislate a minimum age of 13 for unsupervised access to social media platforms, President Ursula von der Leyen announced on Monday, adopting the central recommendation of an expert panel she convened last year. Children under 13 would be restricted to "time-limited" access under parental or caregiver supervision, part of a phased approach that would gradually introduce young people to different online services as they age.
The announcement, made in Brussels alongside the panel's final report, marks the most concrete step yet in a campaign von der Leyen has made a signature priority of her second term. "It is very clear that we need age-appropriate restrictions to platforms," she said. "This is not about whether children can access social media. It is about whether and when social media can access our children."
What the expert panel recommends
The panel's report, published Monday, sets out a developmental framework rather than a single cut-off. It advises no screen exposure for children below three, followed by a gradual, supervised introduction to digital technologies until the age of 13. Only from 13 onwards would young people gain full, unsupervised access to social media platforms. The Commission said it would translate these recommendations into "phased and gradual access for different age ranges," suggesting a tiered regulatory model rather than a binary gate.
Von der Leyen stressed that parents and caregivers should retain control over the precise age at which a child moves between tiers. "Children should only be exposed to social media under the supervision of parents, of caregivers, teachers, and time-limited," she said. The Commission also intends to examine whether similar age gates should apply to other online services, gaming platforms, messaging apps, video-sharing sites, and will begin work on a methodology to determine which platforms pose the greatest risk to minors.
Existing legal baseline and enforcement gap
In practice, most major platforms already set 13 as their minimum sign-up age. That figure derives from the EU's General Data Protection Regulation (GDPR), which establishes 16 as the default age for valid consent to data processing but allows member states to lower it to 13. Every EU capital has done so. The rule, however, rests on self-declaration: a child ticks a box asserting they are over 13, and the platform accepts it. No reliable age-verification mechanism is mandated, and enforcement by national data-protection authorities has been sporadic.
The Digital Services Act (DSA), which became fully applicable in February 2024, goes further by requiring very large online platforms to assess and mitigate systemic risks to minors, including addictive design and algorithmic amplification of harmful content. But the DSA stops short of prescribing a verified age gate. The Commission's new push aims to close that gap by moving from self-certification to a system where age is established before a child encounters the service.
Political momentum from capitals and abroad
Von der Leyen's initiative does not arrive in a vacuum. Greece, Denmark and France have all publicly advocated stricter age limits at EU level. France, in particular, has been vocal: President Emmanuel Macron backed a report in 2024 recommending a ban on social media for under-15s and a prohibition on smartphones in schools up to age 15. Outside the bloc, Australia passed legislation in November 2024 banning social media accounts for under-16s, with fines of up to 50 million Australian dollars for non-compliant platforms. Indonesia and Malaysia have signalled similar intentions.
This international convergence gives the Commission political cover. When the world's largest platforms face a patchwork of national age-verification laws, Australia at 16, France potentially at 15, the EU at 13, a harmonised European standard becomes a regulatory necessity for the companies themselves. The Commission is aware that fragmentation raises compliance costs and creates loopholes; a single EU framework, if credible, could become the de facto global baseline.
The age-verification problem
The central technical challenge remains age verification. The panel's report acknowledges that no foolproof method exists. Options range from device-level signals and app-store attestation to third-party identity providers and biometric estimation. Each carries trade-offs: privacy intrusion, exclusion of children without formal ID, susceptibility to fraud, and the risk of creating centralised databases of minors' identities. The Commission has said it will not mandate a specific technology but will set outcome-based requirements, platforms must demonstrate they have taken proportionate measures to keep under-age users off the service.
Industry groups have warned that heavy-handed verification could push teenagers toward unregulated corners of the internet or encourage the use of VPNs and fake credentials. Civil-society organisations, conversely, argue that anything short of independent, audited verification will reproduce the status quo. The Commission's eventual legislative text will have to navigate this tension, likely by establishing a certification scheme for age-assurance providers under the oversight of the European Digital Identity framework.
Scope beyond social media
Von der Leyen's remark that the Commission will "consider age restrictions for other online services too" signals a broader regulatory ambition. Gaming platforms with social features, livestreaming services, and messaging apps used by children, WhatsApp, Discord, Telegram, fall into a grey zone. The DSA already treats some of these as very large online platforms subject to risk assessments, but age gating has not been explicitly required. The panel's developmental logic, no screens under three, gradual introduction until 13, implies a continuum of protection that extends well beyond TikTok, Instagram and Snapchat.
Defining "harmful to minors" will be contentious. The Commission plans to develop a methodology, but the criteria, addictive design, exposure to self-harm content, sexual exploitation risk, commercial profiling, are already contested in DSA risk-assessment audits. A formal classification could trigger additional obligations: default privacy settings, algorithmic transparency, parental dashboards, and bans on targeted advertising to children. The UK's Age Appropriate Design Code, in force since 2021, offers a precedent: 15 standards that online services must meet when likely to be accessed by children.
Legislative path and timeline
The Commission will now draft a legislative proposal, likely a regulation to ensure direct applicability across the 27 member states, which must pass the European Parliament and the Council of the EU. Given the political salience, the file could move quickly. The Parliament's Committee on the Internal Market and Consumer Protection (IMCO) and the Committee on Civil Liberties, Justice and Home Affairs (LIBE) will share competence. Member states with existing national laws (France, Greece) will push for their standards to be reflected; others may resist what they see as overreach into family life.
A key date is the next European Parliament plenary in September, where von der Leyen's State of the Union address may set a target for adoption before the end of 2026. The Commission's own work programme for 2025, 2026 listed a "Child Online Protection" initiative for Q3 2025; Monday's announcement suggests the timetable has accelerated. If a regulation is adopted in 2026, platforms would likely receive a 12-to-18-month implementation period, pushing effective compliance into 2028.
Sources
People mentioned
Organisations
European Commission