The EU KIDS Act would regulate general AI chatbots, not customer-support bots

Ulf Aslak Lai photo Ulf Aslak Lai Published 30 Sep 2026 AI drafted 9 min read
The EU KIDS Act would regulate general AI chatbots, not customer-support bots

Take a support bot that runs on a model such as Claude or GPT, with a system prompt that says "only answer questions about our product, and decline everything else". An engineer deletes that line to make the bot more helpful, and now it writes birthday poems and explains algebra. Under the EU KIDS Act, which the European Commission proposed on 17 September 2026, that one-line change could turn it into a regulated "general conversational chatbot". If minors can reach a chatbot like that, the company offering it would have to give every user child-safe defaults, including no memory between chats and notifications off, until an age check that is not a tick box shows the user is an adult 1. A narrow assistant inside a product sold to businesses, used by staff through their employer's account, is most likely outside on both counts: the chat is narrow, and minors cannot reach it. None of this is law yet: the European Parliament and the national governments still have to agree the text, and it would apply six months after it enters into force. If it follows the roughly two-year path of comparable EU laws, that means around 2029.

What would the KIDS Act require of an AI chatbot?

The child-safe defaults are not a mode for users who say they are children. They are the product every user gets until an age check shows the user is an adult, meaning 18 or over. Article 8(1) lets the company offering the chatbot depart from them only "after they have established that the ... user of the system is an adult, by making use of age assurance" 1.

Article 14 lists what those defaults are for a chatbot:

  • No designs that create emotional dependency. No behaviour that simulates a relationship likely to make a minor dependent, plus time limits and breaks that protect school time and sleep.
  • Safe settings. The chatbot must not use what it learned in a minor's earlier conversations in later ones, unless needed for the minor's safety. In product terms, cross-session memory is off. Location tracking, microphone and camera access, and push notifications are off too, and a minor over 15 may switch those on after being told plainly what changes and agreeing to it.
  • Purchases shown as purchases. A minor must be told, in real time and plainly, when something costs money.
  • Under-13s only through a parent. A child below 13 gets access only through tools a parent or guardian controls.
  • Testing before launch. Evaluate the chatbot for risks to minors' health, safety and well-being before it goes on the market, and put safeguards in place.
  • Monitoring after launch, including responding to serious incidents involving minors. Small and micro companies are exempt from this one (details below).

The proposal adds three more for chatbots: controls and explanations a minor can understand, a way for minors to report harmful content or behaviour, and tools for parents 1. The Commission's own summary of the chatbot part is that chatbots "will no longer be able to act in ways that make children emotionally dependent on them" 2.

Does your legal documentation match what you ship?

Lawcel watches your product changes and flags the moment your terms or privacy policy fall out of sync, then proposes the edits for your team to approve and publish.

Get started

Which chat features count as a "general conversational chatbot"?

The proposal defines a general conversational chatbot as a general-purpose AI system with general conversational functionality "that is capable of providing assistance across multiple domains and tasks". It then excludes "AI systems whose conversational functionality is limited to a specialised service, task or pre-defined set of functions", and lists examples: customer-service, business operation, technical-support, transactional, educational, information-retrieval, industrial and manufacturing uses 1.

"General-purpose AI system" comes from the AI Act: a system "based on a general-purpose AI model" that "has the capability to serve a variety of purposes" 3. In practice, nearly any chat built on a GPT or Claude API starts out in scope. Being built for one job is what takes it out.

Here is how I would read common chat features against that test. These are my readings of a proposal, not settled law.

Chat feature In scope? Why
Support bot, help docs only No Customer service
Search over product docs No Information retrieval
Copilot over a customer's data Likely no Business operation
Booking assistant No Transactional
"Ask AI anything" panel Likely Multiple domains
Coding assistant Unclear One domain, open chat
Companion app Yes AI companion

The last row sits under a different definition. An "AI companion" is any AI system that provides "sustained, personalised interaction or companionship" simulating a social, emotional or interpersonal relationship 1. A narrow system can still be a companion, so the one-job exclusion does not help a character app.

The support bot at the top of this post is the hard case. The definition asks what the system is "capable of", and a prompt line does not remove what the model underneath can do. Users, and teenagers in particular, are good at talking a bot out of its instructions. My reading is that a regulator would look at whether the limit holds in practice, not at whether someone wrote it down: a bot that reliably refuses off-topic requests is limited to a specialised service, and a bot that writes the poem after two tries is not.

Does it apply to a small startup outside the EU?

Yes, and the duties fall on the startup, not on the model company. The proposal uses the AI Act's meaning of "provider": whoever develops a system, or has it developed, and puts it on the market under its own name 3. A startup that wraps a model API in an assistant carrying its own brand is the provider of that assistant, even though another company provides the model underneath (more on the two kinds of provider in the post on fine-tuning and the AI Act).

Size does not help. The Commission writes in the proposal that "small and micro enterprises are not exempted from this Regulation, since they may equally provide harms to minors" 1. Under the EU definition, a small enterprise has fewer than 50 staff and no more than 10 million euros in turnover or balance sheet total 4. A 12-person independent startup with 3 million euros in revenue qualifies, which spares it the post-launch monitoring and nothing else.

Location does not help either. The rules apply to anyone offering these chatbots in the EU "irrespective of where those providers are established or located", and a provider with no EU establishment must appoint a legal representative in the EU in writing 1. A company that already has one for the AI Act can extend that mandate.

Can minors reach your chatbot, and what age check counts?

My reading: a consumer app with open sign-up should assume minors can reach its chatbot, whatever its terms say. An assistant that people reach only through their employer's account is less likely to be in scope, because its users are staff. Employees can still be 16 (apprentices and interns), so if I ran one, I would build the child-safe defaults as settings that can be unlocked anyway. It costs little in a new feature and a lot to retrofit, and it keeps the answer from depending on a customer's HR policy.

An "18+ only" clause in your terms is unlikely to count as proof that minors cannot reach you. The proposal does not define "accessible to minors", but for online platforms EU regulators already treat an 18+ clause as a promise to verify ages 5. That is Spain's data protection authority summarising the Commission's July 2025 guidelines on protecting minors.

On what counts as an age check, the proposal is explicit. It defines age assurance as methods to "determine, estimate or verify" a person's age, "excluding self-declaration" 1. A birth-date field at sign-up would not let a provider switch the child-safe defaults off for anyone.

When would this apply, and what are the fines?

The proposal now goes to the European Parliament and the Council (the ministers of the EU's national governments), which negotiate the final text 2. Freshfields, a law firm, estimates that comparable EU laws have taken about two years to get through that process. Once it enters into force, most of it would apply six months later, and the text can change on the way, including the definitions 1.

Enforcement for chatbots would run through the national regulators that already enforce the AI Act, with fines of up to 6% of worldwide annual turnover where the provider acted intentionally or negligently 1.

What should you do if you ship an AI chat feature?

If you build or run a product with an AI chat feature that minors could use, the KIDS Act asks nothing of you yet. If it passes in this shape, a general chatbot that minors can reach will need the child-safe defaults six months after the law enters into force, with fines of up to 6% of turnover behind them. Three decisions are easier to make now, while the feature is small, plus one duty from a different law:

  • Decide whether your chat is narrow or general, and make it true. If it should be narrow, test that it refuses off-topic requests, and treat a pull request that widens the system prompt as a scope change to review.
  • Decide whether minors can reach it. Check whether sign-up is open to the public or only through an employer's account, and whether your age rule in the terms is checked by anything.
  • Build the child-safe defaults as settings you can unlock per user. Cross-session memory, microphone, location and notifications start off, and switch on without a rewrite once an age check (not a tick box) shows a user is an adult.
  • Separately, tell users they are talking to an AI. That is an AI Act duty that already applies; see the Article 50 post.

If your chat is general and open to the public, add the rest of the list above to the roadmap: a report button, parental tools and a written pre-launch test for risks to minors.

FAQ

No. The Commission proposed it on 17 September 2026. The European Parliament and the Council now negotiate the final text, and most of it would apply six months after it enters into force.
Not under the proposal. The definition of a general conversational chatbot excludes chat limited to a specialised service, including customer-service and technical-support uses.
No. The proposal says small and micro enterprises are not exempted. They are spared only the post-market monitoring duty.
No. The proposal defines age assurance as estimation or verification and excludes self-declaration, so a birth-date field or an "I am 18" box would not unlock adult settings.
For AI chatbots and companions, up to 6% of worldwide annual turnover, enforced through the AI Act's market-surveillance system, where the provider acted intentionally or negligently.

References

  1. European Commission, Proposal for a Regulation on keeping internet digital spaces accountable and trustworthy for minors (EU KIDS Act), COM(2026) 681 final, 17 September 2026 - accessed 30 Sep 2026
  2. European Commission, EU KIDS Act: helping children navigate a safer online world (17 September 2026) - accessed 30 Sep 2026
  3. Regulation (EU) 2024/1689 (AI Act), Article 3: Definitions - accessed 30 Sep 2026
  4. European Commission, SME definition (Recommendation 2003/361/EC) - accessed 30 Sep 2026
  5. AEPD and CNMC, Decoding Article 28 DSA: age assurance and service design on online platforms (24 March 2026) - accessed 30 Sep 2026

About the author

Ulf Aslak Lai

Ulf Aslak Lai

Co-founder, Chief Technology Officer

Ulf is Co-founder and CTO at Lawcel. He leads engineering architecture for connectors, analysis pipelines, and the safeguards needed when automation touches regulated customer content.

  • Platform architecture
  • Data governance
  • ML/AI systems
AI Act

Fine-tuning rarely makes you a model's provider under the AI Act. The threshold is a third of the base model's compute.

The AI Act has two provider roles, and a fine-tune almost never moves the second one to you. Shipping an AI feature under your own name makes you the provider of that AI system. The provider of the model underneath is normally the lab that trained it, and the Commission's indicative criterion for whether your fine-tune changes that is compute greater than a third of what it took to train the base model.

AI Act

Article 50 applies on 2 August 2026, and your model vendor cannot carry it for you

Article 50 of the EU AI Act applies from 2 August 2026. The delay you read about in June covered high-risk uses such as hiring and credit scoring, not this. If your product has an AI feature that ships under your own name, the law treats you as its provider even though the model belongs to your vendor, so telling users about it and marking what it generates are your duties. You may use whatever marking your vendor builds, but the Commission's guidelines say that demonstrating compliance stays with you.

AI Act

Most SaaS AI features are not high-risk under the AI Act. Hiring and credit tools need a check.

Most SaaS features are not high-risk under the EU AI Act. Two things make a system high-risk: it is, or is built into, a product covered by EU product-safety law, or it sits in one of the eight areas in Annex III, such as hiring, education or credit scoring. If yours is, Article 6(3) can still take it out, but you then owe a written assessment and an EU database entry.

AI Act

The AI Act's AI literacy duty still applies to companies whose staff use ChatGPT

Article 4 of the EU AI Act still requires companies whose staff use AI tools such as ChatGPT to build their AI literacy, if the company is in the EU or the work reaches the EU. In practice: list the AI tools in use, tell each group what can go wrong with them, and keep a dated record. No certificate is needed, and no level has to be guaranteed.