Europe’s debate over children’s safety online may soon place a new checkpoint in front of some games: prove your age before proceeding. The proposed EU Kids Act, which is due to be presented to the European Parliament on Thursday, could establish age-verification obligations for certain online services, including games considered risky to minors.

That wording matters. The proposal is not a blanket, confirmed demand that every person playing every game submit identification. It remains proposed legislation, and the available details leave major practical questions unanswered: which games would fall under the “risky to minors” description, what verification approaches providers would be permitted or required to use, and whether requirements would apply at account creation, before accessing specific content, or at another point entirely.

Still, its potential scope is significant. Gaming is increasingly tied to persistent accounts, social spaces, voice chat, user-made content, purchases, livestreaming, competitive communities, and cross-platform profiles. An age gate aimed at online risk would therefore not necessarily be limited to the moment someone presses Play. It could affect features around the game just as much as the game itself.

What the EU Kids Act is expected to cover

The EU Kids Act has been under discussion for more than a year and is intended to reduce harm to children online. It is expected to introduce age thresholds for access to a range of digital services, including social-media platforms, artificial-intelligence tools, and certain gaming services.

Reported draft material indicates that social-media services and video-sharing platforms would be required to conduct age verification when someone opens a new account. The same broad policy direction may reach AI chatbots and online games deemed risky for minors. Industrial AI, workplace-oriented AI products, and educational online services are not expected to be included in that proposed reach.

For players, the key phrase is not simply “online games,” but online games that are risky to minors. That distinction suggests regulators may be trying to target categories, mechanics, communication tools, or content rather than treating every connected title as identical. But without a settled definition or final text, it would be premature to assume which storefronts, multiplayer games, or game modes would be affected.

A mature-rated game might seem like an obvious candidate, but age risk can be broader than a content-rating label. Features such as direct messaging, voice communication, livestreaming, unmoderated user-generated material, or interactions with strangers can all complicate the question. Conversely, an online game with limited social functionality could be assessed differently from a broad social platform wearing a game-shaped hat.

Age verification is already arriving in gaming spaces

The proposal lands while game companies and platforms are already experimenting with, or implementing, methods for determining a player’s age. In April, PlayStation began rolling out age-verification checks in Ireland and the United Kingdom for access to selected network functions, including voice chat, messaging, and streaming.

Related coverage includes EU Kids Act Proposal Could Bring Age Checks to Some Online Games.

The available methods can include a facial scan, a mobile number, or identification documents, depending on a user’s country or region. That approach illustrates an important reality of age assurance: one universal global system does not currently exist. Different local rules, available technologies, privacy standards, and payment systems can all influence what players are asked to provide.

Australia offers another recent example with a much narrower verification route. Earlier this month, Steam introduced proof-of-age requirements for access to R18+ games in the country. The system accepts Australian credit cards, which means an adult player without one could encounter a barrier even if their age is not in question.

Valve’s notice to affected Steam users says the company must verify that they are 18 or older under the Age-Restricted Material App Distribution Services Code. It directs users who want to see mature content to add a valid Australian credit card and then update their Mature Content Preferences.

That is an especially clear example of how policy goals and real-world access can collide. A credit card is often treated as a convenient proxy for adulthood, but it is not synonymous with being an adult. Some adults do not own a credit card, avoid them, use another payment method, or cannot obtain a locally issued card. Any future verification framework will have to confront the difference between a system that is simple for providers and one that is workable for all legitimate users.

The privacy problem is part of the game

Child protection advocates have strong reasons to push for better safeguards where minors may encounter harmful material or unsafe interactions. But the verification debate cannot be separated from privacy, data security, and access. Asking a platform to establish a player’s age can mean asking it—or a specialist service working for it—to handle information that users would prefer not to surrender.

Options such as ID checks and facial age estimation provoke different concerns. Government identification can reveal substantially more than a date of birth. Facial systems raise questions about biometric information, accuracy, retention, bias, and whether an estimate could wrongly block an adult or allow a minor through. Phone-number checks may be less intrusive in one respect, yet they still attach account access to a personal identifier.

The stakes became particularly visible after Discord paused plans for a global age-verification rollout following a security incident in which hackers accessed 70,000 images of users’ government IDs. The incident is a reminder that a verification system must be judged not only on whether it can identify an age group, but also on what data it gathers, who retains it, and what happens if those defenses fail.

Players already see versions of this wider tension in other online services. The debate around privacy, encrypted communication, safety tooling, and account identity is not confined to games, as shown by the uncertainty around XChat’s disappearance from the App Store. Gaming platforms may have their own distinct rules and audiences, but they operate in the same increasingly regulated digital environment.

What remains uncertain for players and publishers

At this stage, the EU Kids Act should be read as a developing policy proposal, not as a finalized new sign-in ritual for every European gamer. Its presentation before Parliament is an important step, but it is not the same as passage, implementation, or a complete technical blueprint.

Several details will determine its eventual impact:

  • Which games qualify: The definition of “risky to minors” could decide whether the rules concentrate on mature content, social features, particular business models, or a combination of factors.
  • When checks happen: A requirement at new-account creation is different from a check before a player uses voice chat, enters a mature-content area, watches a stream, or buys a specific product.
  • What proof is accepted: Credit cards, identity documents, phone numbers, facial estimation, and third-party digital-age credentials all have different trade-offs.
  • How data is handled: Rules around collection, storage, sharing, deletion, and security could matter as much to users as the verification step itself.
  • How adult access is protected: Systems will need ways to avoid locking out adults who lack a particular device, payment instrument, document, or national credential.

Publishers and platform holders may also face difficult design choices. A company could potentially apply stricter controls only in territories where rules demand them, but region-specific systems can create confusion for traveling players, expatriates, families sharing devices, and people maintaining long-standing accounts. A broader worldwide solution might be easier to operate in some ways, yet it could impose extra data demands on people outside the relevant jurisdiction.

The United States currently has no federal law requiring online platforms to introduce age-verification checks, although some states have adopted their own measures. That patchwork adds to the challenge for global services. A publisher may need to reconcile European requirements, Australian restrictions on mature material, individual US state laws, existing console policies, and its own community-safety rules—all without turning an ordinary account login into a bureaucratic raid boss.

A policy battle with no easy setting

The central disagreement is not over whether children deserve protection online. It is over which protections work, how much personal information platforms should be allowed to demand, and who bears the consequences when a verification system fails. A weak check can be easily bypassed; an aggressive one can exclude legitimate users or create a lucrative pool of sensitive data.

For gaming, the EU Kids Act proposal is another signal that age assurance is moving from an occasional storefront prompt toward a core platform-policy issue. The eventual rules could influence not only access to specific games, but also the social and media features that surround them. Until the proposal’s language and legislative path become clearer, players should treat any prediction of universal mandatory ID checks as speculation. What is clear is that the next level of the online-safety debate is loading, and games are now firmly on the map.