Chatbot publishers may have to rethink how their tools interact with minors. Presented by the European Commission on 17 September 2026, the proposal for a regulation EU KIDS Act, COM(2026) 681, provides for disabling by default the use of memory of previous conversations and preventing emotional dependency mechanisms. It adds to age rules on certain social networks a set of obligations specific to AI companions and general-purpose conversational assistants.

These provisions are not in force. The proposal must be examined by the European Parliament and the Council under the ordinary legislative procedure. Its scope, obligations and timetable may still evolve during negotiations.

From general-purpose assistants to AI companions

The text targets two categories. An AI companion is defined by the personalised and lasting interaction it offers, simulating or facilitating a social, emotional or interpersonal relationship. A general-purpose conversational chatbot is a general-purpose system capable of helping the user in several areas and tasks.

Article 3 excludes from this second definition systems whose conversation is limited to a specialised service or a predefined set of functions, such as customer service, technical support or certain educational and industrial applications. A banking assistance tool limited to these functions would therefore not fall into the category of general-purpose chatbots. However, this exclusion does not make it possible to rule out a system that would otherwise meet the definition of an AI companion.

Providers would be concerned as soon as they place on the market or put into service in the Union a system falling within this scope and accessible to minors, regardless of their country of establishment. Micro and small enterprises would not benefit from a general exemption.

Conversational memory limited by default

Article 14 provides for measures against behaviours simulating relationships likely to create emotional dependency. It also extends to chatbots certain protections against compulsive uses, as well as requirements for protective settings and transparency of commercial transactions.

The provision on memory would have a direct effect on personalisation: by default, the system could not use, in a subsequent exchange, information or analyses from a minor's previous interactions, except where necessary for their safety. Recital 32 links this measure to the risk of accumulation of sensitive data and reinforcement of harmful behaviours. This is a restriction on reuse in conversation, which should not be confused with a general obligation to immediately erase all history.

Access for under-13s to the targeted companions and chatbots should be activated and controlled by tools intended for holders of parental authority. This regime specific to AI systems differs from the account opening restrictions provided for certain social networks and video services.

Before commercialisation or putting into service, providers would have to assess and test risks to the health, safety, fundamental rights and development of minors, then put in place the corresponding protections. Post-launch monitoring would also be required to identify emerging risks and deal with serious incidents. Micro and small enterprises would be exempt from this last obligation of Article 14, without being exempted from prior testing or other safeguards.

Protection of minors would become the common setting

The operational scope of the project also lies in its Article 8. Protective settings should be applied by default. The provider could only derogate from them after establishing that the user is an adult, by means of an age assurance device compliant with the text. Protection would therefore not rely solely on profiles that the publisher already knows belong to children.

Articles 27 to 29 govern in particular the reliability of solutions and data minimisation. A simple age declaration would not suffice. Article 32, however, provides for a derogation where the provider can establish with a high degree of confidence that the user is not a minor. Implementation will have to reconcile this exception with the general requirements of verification and privacy protection.

Different obligations depending on chatbot integration

The Commission's presentation insists on the deactivation by default of chatbots. The legal text reserves this rule for companions and assistants integrated into a social network, a video platform or an online game. They should not activate automatically or be highlighted in the interface; minors should be able to easily stop using them. A standalone assistant would not be subject to this particular provision of Article 14, paragraph 2.

The distinction also applies to audit. Article 5 provides for a compliance plan and its examination by independent auditors, at the provider's expense, for social networks and video platforms designated as very large platforms under the Digital Services Act (DSA). The obligations relating to their integrated chatbots would be included in this examination.

Article 14, for its part, imposes prior assessments and protections on providers of assistants. It does not create a general procedure for administrative authorisation before launch or a mandatory external audit for each standalone chatbot. Adherence to a code of conduct deemed adequate by the Commission could serve to demonstrate compliance with the obligations of this article.

Sanctions of up to 6% of turnover

Article 34 links the supervision of companions and chatbots to the control structures of the European AI regulation. A breach committed intentionally or through negligence could result in a fine of up to 6% of the company's total worldwide annual turnover for the preceding financial year. The project does not set an alternative ceiling in euros for this provision.

The distribution of control would follow the European and national competences provided for by the AI Act. The documents accompanying the proposal envisage in particular European supervision of assistants built on a general-purpose model from the same provider, as well as certain systems integrated into very large platforms. The others would fall to the competent national authorities.

In procedures falling to the Commission, Article 35 sets an objective of communicating preliminary findings within 30 working days and a final decision within 90 working days. These are deadlines that the authority should endeavour to meet, not automatic guarantees of closure.

Recognised costs, a timetable to be stabilised

The analysis document accompanying the proposal recognises the additional burdens for publishers: assessments, protective devices, product adaptations and monitoring. They could weigh more heavily on small businesses and constrain certain business models based on engagement. The Commission does not provide a specific costing for all chatbot providers.

The European project comes amid a regulatory debate already underway elsewhere. The Constitutional Council censured on 14 August the general French ban on social networks for under-15s, in particular with regard to the risks specific to each service, the role of parents and privacy guarantees. The European project distinguishes these parameters, without this prejudging its legal assessment. In California, the governor signed Adam's Law on 10 September, which provides according to its press release for independent child safety audits for companion chatbots.

In the European version consulted on 18 September, Article 43 envisages entry into force twenty days after publication in the Official Journal, then general application six months later. It provides for separate deadlines for the compliance plan and certain control measures. These deadlines are still in square brackets. The financial statement mentions, for chatbots, compliance twelve months after entry into application, which does not match this reading of the mechanism. The effective timetable will depend on the text adopted at the end of negotiations.

Our articles will then appear first in Google Top Stories.