Europe Is About To Regulate AI Chatbots As Children’s Products. Hassan Taher on What That Reclassification Does.

0

The European Commission is unveiling the EU Kids Act this week, previewed in President von der Leyen’s State of the Union address. Draft text leaked over the weekend of September 13, and the coverage focused, predictably, on the age thresholds.

They are worth stating precisely. Under 3: barred entirely from social media and high-risk services. Ages 3 to 13: child-friendly services only, with adult supervision. Ages 13 to 15: restricted access to social media and video platforms, with parental controls. Ages 15 to 18: access without parental consent, but safety-by-design obligations still apply.

The provision that will matter more, and that received a fraction of the attention, is the scope clause. The Act covers social media, video-sharing platforms, online games, and AI-powered chatbots — specifically described in the draft as “virtual tools that can give mental health and personal development advice to minors.”

That phrasing is doing an enormous amount of work.

 

The Reclassification, Not the Ban

Regulating a general-purpose AI assistant as a children’s product means something quite different from regulating a social network as one.

A social platform has an identifiable service, a defined feed, and a discrete set of features a regulator can require or prohibit. The Act’s safety-by-design provisions read accordingly: disable infinite scrolling, disable artificial notifications, disable engagement-based reward mechanics, keep recommender algorithms out of rabbit holes, default minors’ accounts to private.

An AI assistant has none of those surfaces. There is no feed to reorder, no infinite scroll to disable, no notification cadence to throttle. What it has is a conversation, and the harm the drafters are pointing at is not addictive design — it is the substance of what the system says when a fourteen-year-old asks it something about their mental health.

The phrase “virtual tools that can give mental health and personal development advice” is not describing a product category. It is describing a capability that every general-purpose assistant possesses, cannot be architected out of, and did not have to be deliberately built. A model trained on the internet will answer a question about anxiety. That is not a feature anyone shipped. It is what the model is.

“This is the reclassification that the industry has been dreading and largely pretending would not arrive,” says Hassan Taher, an AI analyst and author who advises organizations on enterprise AI strategy. “Everyone has been arguing about whether AI is a product or a platform. The Commission has answered a narrower and more awkward question: when a minor uses it, is it a service or an advisor? If the answer is advisor, then an entire body of law about duty of care, competence, and supervision comes into contact with a system that has none of those properties and cannot acquire them by patching.”

 

Why the Enforcement Design Is the Real Story

Two provisions in the leaked draft should get more attention than the age brackets.

The first is the burden of proof. Tech companies must demonstrate compliance rather than regulators demonstrating violation. That inverts the posture of most platform enforcement to date, and it changes what a company must build before shipping rather than after being investigated.

The second is more consequential: platforms designated as systemic risks under existing Digital Services Act rules will require Commission authorization before rolling out features that affect children. Prior authorization. Not notification, not a risk assessment filed afterward — permission in advance.

That mechanism has a direct and recent application. ChatGPT was designated a Very Large Online Search Engine under the DSA on August 31, placing it in the regime’s top enforcement tier — a designation that arrived alongside the same market-structure questions Hassan Taher has traced in what public markets will ask of AI labs. Combine that designation with the Kids Act’s prior-authorization clause and the implication is concrete: a designated AI assistant may need Commission sign-off before shipping features that touch minors, in a product category where features ship continuously and the distinction between a feature and a model update is not always meaningful.

“The compliance question nobody has answered is what counts as a feature when the product is a model,” Taher observes. “If a lab retrains and the new checkpoint is better at emotional conversation, has it shipped a feature affecting children? By any functional reading, yes. By any process reading, there is nothing to file. European regulators are going to have to build a definition, and whatever they build will apply to a release cadence measured in weeks against an authorization process measured in months. That mismatch is where this gets genuinely difficult, and it is not a mismatch anyone can engineer away.”

 

The Age Verification Problem Nobody Has Solved

Every provision in the Act depends on knowing a user’s age. That dependency has defeated every prior attempt at this.

The available methods are all bad in different directions. Self-declaration does not work. Document verification excludes the large share of teenagers without government ID and creates a database of minors’ identity documents — a target with an obvious risk profile. Facial age estimation is biometric processing under GDPR and carries accuracy disparities across demographic groups that will not survive contact with European equality law. Parental attestation collapses in households where the parent is the path of least resistance.

The EU’s own digital identity wallet is the intended answer, and it is genuinely more promising than the alternatives because it can attest to an age bracket without disclosing an identity. It is also not fully deployed, not universally adopted, and not available to every user who will be covered on day one.

Meta’s $17 billion settlement in California in August turned substantially on age verification and engagement mechanics — obligations that arrived through litigation rather than legislation. Regulation reaching this category through the courts before it reaches it through statute is a pattern Taher has examined in the context of the Great American AI Act and the fight over who sets the rules. The Kids Act attempts the same objective through statute, and inherits the same unsolved dependency. The United Kingdom is moving on a parallel track toward under-16 restrictions with its own chatbot provisions.

 

What Companies Should Do Now

This is a draft. It will change in trilogue, and the timeline to application will be measured in years. That is not a reason to wait, for three reasons.

Determine whether you are in scope, and assume the answer is yes. The draft language reaches any tool that can give mental health or personal development advice to minors. That is not limited to consumer chatbots. An education product, a customer service assistant, a fitness or wellness app with a conversational layer — all of them can produce that output on request. Scope here is defined by capability, not by intent or marketing.

Find out how many of your users are minors. Most companies deploying conversational AI do not know, have not measured, and will discover the number is higher than assumed. It is not possible to plan for this regime without that figure.

Watch the definitional fight, not the age brackets. The brackets will get the headlines and will probably survive roughly intact. What will determine the actual cost of compliance is how “feature affecting children” is defined, how the prior-authorization process is operationalized, and whether model updates fall inside it. Those fights happen in technical working groups, and they are where the outcome is decided.

 

The Broader Point

The quote in the draft that will be read aloud in the State of the Union is that “parents, not algorithms, should raise Europe’s children.”

It is good rhetoric and it points at something real, but it understates what has changed. The concern with social media was that an algorithm decided what a child saw. The concern with conversational AI is that a system talks to a child, one to one, patiently, at three in the morning, about whatever the child raises — and does so without training, without duty of care, without escalation paths, and without any of the professional apparatus society built around the people who previously did that job.

“Every prior generation of this debate was about exposure — what content reaches a child,” Taher says. “This one is about relationship, and that is a category the existing regulatory vocabulary does not really have a word for. Europe is going to spend the next three years inventing one. Whether the Kids Act is the right instrument is genuinely arguable. That the question needed asking is not.”

 

→ See what else we’re tracking at our site.


There is no ads to display, Please add some