By Elena Georgiou Strouthos
Co-Founder & CTO, Cocoon Creations
For years, signing up for a website or a mobile was simple. Provide an email and a password and you have an account.
Sometimes there was one more question: Date of birth? But it was never an issue, if you were a minor you just typed a different year and you were in. This is going to change.
The European Commission has proposed the EU KIDS Act, introducing new rules for how digital services protect children online.
Under the proposal, children under 13 would not have personal social-media accounts. Those aged 13–14 would have restricted accounts under parental supervision, while independent accounts would start at 15.
But the interesting part isn’t just the age limit. It’s what happens inside the software.
The proposal would require social media, video platforms, online games and AI companions to be safer for minors by design.
That means restrictions on addictive features, profiling-based recommendation feeds, infinite scrolling, reward mechanisms and push notifications during sleeping hours. Profiles for minors would be private by default, with features such as geolocation, camera and microphone access switched off. AI companions and chatbots would also have to meet specific safeguards.
You cannot any longer build the product first and bolt safety onto it later because safety should be part of the product.
The European Union has a solution for this; probably borrowing on an idea the operating systems started implementing a few years back.
If a platform needs to know whether you’re under 15, an obvious solution is to ask for your ID. But why should TikTok, Instagram or an online game need to know your name, ID number, exact date of birth and what you look like?
The EU is proposing privacy-preserving age assurance.
The idea is that a user should be able to prove something about themselves without handing over their entire identity. The platform needs to know: “Is this person 15 or older?” without knowing who the person is.
The proposed European age-verification solution is designed around exactly this principle, without retaining identity documents or biometric data. The verification would happen through national ID applications.
Australia has already introduced restrictions preventing under-16s from having accounts on major social-media platforms.
And in the US, Meta recently reached a landmark multistate settlement following allegations about the impact of Facebook and Instagram on young users. Among the measures agreed are stronger age assurance, daily time limits, nighttime and school-hour restrictions, and changes to features such as endless scrolling.
The details are different, but the direction is remarkably similar:
Cyprus is moving in the same direction.
On 16 September, the Council of Ministers approved an Action Plan proposing 15 as the minimum age for social media and the development of an age-verification mechanism based on the European approach, with integration into Digital Citizen.
So what does all of this mean for businesses building software? Quite a lot.
Because suddenly, a sentence in a regulation becomes a series of technical questions:
These aren’t questions you can leave until after the software is built. They need to be considered when the product is being designed. And that’s an increasingly important part of building software.
You need to understand not just what the software should do, but the rules it needs to operate under. Because when regulation changes the way a digital product must behave, compliance isn’t just a legal problem anymore.
And getting that right at the beginning is considerably easier than trying to retrofit it later.
At Cocoon Creations we help businesses turn complex requirements into software that works — technically, commercially and within the rules it needs to follow.