EU Kids Act proposed 17 September 2026: safe-by-design rules for AI chatbots and companions affect professional services
On 17 September 2026, the European Commission published its proposal for the EU Kids Act — a standalone regulation that would fundamentally reshape how digital services, including AI chatbots and AI companions, are designed, deployed, and governed when children may interact with them. For profession
EU Kids Act Proposed: What Safe-by-Design Rules for AI Chatbots Mean for Professional Services
On 17 September 2026, the European Commission published its proposal for the EU Kids Act — a standalone regulation that would fundamentally reshape how digital services, including AI chatbots and AI companions, are designed, deployed, and governed when children may interact with them. For professional services firms operating AI-powered tools, the proposal deserves careful attention, even if your primary clients are adults.
What the EU Kids Act Proposes
The EU Kids Act is a dedicated regulation, separate from the EU AI Act and the Digital Services Act, focused entirely on strengthening online protections for users under 18. Its scope is broad: social media platforms, video-sharing services, online games, and AI services — explicitly including AI companions and general conversational AI chatbots — all fall within its reach.
The proposal introduces two headline obligations. First, mandatory parental oversight mechanisms for younger users, particularly those under 15, following a Reuters report on 15 September 2026 indicating the Commission was weighing an outright ban for that age group on social media, video platforms, AI chatbots, and online games. Second, and more structurally significant, safe-by-design obligations — meaning services must be built from the ground up with child protection embedded, rather than applying safeguards retrospectively.
The proposal is not yet law. It must pass through the European Parliament and Council before entering force. However, given the EU's track record of advancing digital regulation at pace, and the political consensus around child online safety, professional services firms would be unwise to treat this as a distant concern.
Why Professional Services Firms Are in Scope
The instinctive reaction in professional services is to assume this legislation applies to consumer-facing tech companies — social media giants, gaming studios, entertainment platforms. That assumption is worth scrutinising.
Consider how AI tools are now embedded in professional services workflows. AI chatbots are used for client-facing communications, onboarding portals, HR consultancy platforms, and marketing agency client dashboards. If any of those services are accessible to users under 18 — whether because a client's employee is a minor, because a platform is accessed by young family members on shared devices, or because a service is not age-restricted by design — the EU Kids Act's obligations may apply.
Accountancy firms with client portals, HR consultancies offering self-service tools, solicitors deploying AI-assisted document review interfaces accessible to clients, and marketing agencies running AI chatbot integrations for client websites all need to assess whether their AI services could foreseeably be accessed by minors.
Safe-by-design is not a tick-box exercise. It requires organisations to assess risk at the design stage, build in protections before launch, and document that process. Retrofitting compliance after deployment is significantly more costly and carries greater regulatory risk.
The Global Dimension
The EU Kids Act, like the GDPR before it, is structured to apply based on where users are located, not where a business is incorporated. Any professional services firm offering AI-enabled services to users in the EU — regardless of whether the firm is based in the UK, the US, Canada, the Middle East, or Asia-Pacific — will need to assess its obligations under the regulation if it enters force as proposed.
This extraterritorial logic is now standard in EU digital regulation, and the Kids Act proposal follows the same pattern. A Toronto-based HR consultancy offering an AI-powered employee wellbeing chatbot to EU-based corporate clients, or a Dubai marketing agency running AI chat integrations for EU retail clients, cannot assume geographic distance provides regulatory insulation.
For UK firms specifically, the post-Brexit position means the EU Kids Act will not apply automatically in Great Britain, but firms with EU clients or EU-based users will still need to comply. The UK is also developing its own child safety obligations under the Online Safety Act framework, and the regulatory direction of travel — safe-by-design, age-appropriate experiences, parental controls — is consistent on both sides of the Channel.
What Safe-by-Design Means in Practice
Safe-by-design, as articulated in the EU Kids Act proposal, shifts the compliance burden upstream. Rather than relying on users to opt out of harmful features or apply their own safeguards, providers are required to ensure their services are appropriate and safe for children by default.
For AI chatbots and AI companions specifically, this is likely to mean:
Age verification and access controls. Services will need credible mechanisms to identify and restrict under-18 users, and more stringent controls for those under 15. Relying on users self-declaring their age is unlikely to satisfy the regulation.
Parental oversight tools. For services accessible to minors, providers must offer meaningful parental oversight mechanisms — not simply a terms-of-service acknowledgement, but functional controls that allow parents or guardians to monitor and manage access.
Design-stage risk assessments. Safe-by-design requires documented evidence that child protection was considered before a service launched, not applied as a patch after a complaint. This has significant implications for procurement and vendor management: if your firm is deploying a third-party AI chatbot, you need to understand whether that vendor has conducted the required assessments.
Data minimisation and content restrictions. AI services used by or accessible to minors will face stricter limits on data collection and restrictions on content generation, personalisation, and behavioural profiling.
Immediate Steps for Professional Services Firms
The EU Kids Act is in proposal stage, but the time to act is now. Regulatory proposals of this nature typically provide limited implementation windows once adopted, and the compliance groundwork — mapping AI tools, assessing user demographics, reviewing vendor contracts — takes time.
Firms should begin by auditing every AI-powered service or tool they operate or deploy on behalf of clients to determine whether minors could foreseeably access it. That audit should inform a risk assessment, which in turn should guide design decisions, vendor requirements, and internal policy.
Legal, compliance, and technology teams need to be working together on this. The EU Kids Act sits at the intersection of AI governance, data protection, product liability, and platform regulation — no single function owns it.
Firms advising clients in regulated sectors — financial services, healthcare, education — should also consider how their clients' obligations under the EU Kids Act may affect the advice and services they are expected to deliver.
Act Before the Obligation Arrives
The EU Kids Act proposal represents the next wave of AI and platform regulation in Europe. It is detailed, broad in scope, and backed by strong political momentum. Professional services firms that wait for final adoption before considering their position will find themselves under time pressure, with less opportunity to influence procurement decisions, vendor relationships, and service design.
Ops Intel helps professional services firms understand their AI compliance obligations and build practical, proportionate frameworks for managing them — across the EU AI Act, GDPR, and emerging regulations including the EU Kids Act.
If you would like to understand how the EU Kids Act proposal may affect your firm, visit opsintel.io to find out how we can help.
Follow us in Google
See Ops Intel first when AI rules change
One click tells Google you want our compliance briefings near the top of your results — and marks us as a preferred source inside Google's AI answers. It applies to your Google account only, and you can undo it any time.
What to do about it
The news is what changed. A framework is what you do about it.
Ops Intel writes AI compliance frameworks for small and medium businesses worldwide. Before you spend anything, read a real one — the whole pack, produced by the same system that will write yours.