local waifu
Bring her home

Pick your platform

Try her free for 7 days. No card. Keep her? $20 once.

New: Local Waifu now runs on Windows 10 and 11. The installer brings everything she needs, nothing else to set up. Windows may show a SmartScreen prompt the first time: click More info, then Run anyway.

blog

EU Kids Act: What It Means for AI Companion Apps

18 min read
In short

The European Commission proposed the EU KIDS Act on 17 September 2026. Article 14 of the draft, COM(2026) 681 final, covers AI companions directly: no dependency-forming design for minors, persistent memory off by default for minors, guardian-gated access under 13, and age assurance that must never identify you. It is a proposal and no part of it applies today.

The European Commission adopted the EU KIDS Act on 17 September 2026. If you only read the headlines from that week, you came away with two ideas: the EU is banning under-13s from chatbots, and it is forcing companions off for everyone.

Neither is what the drafted text says. Both come from summarising the Commission’s own press release, which is punchier than the 300 pages behind it.

So this post reads the text. The operative document is COM(2026) 681 final, procedure 2026/0286 (COD), published on 17 September 2026. Everything below is from that draft, from the Commission’s press release IP/26/1890, or from the Commission’s own Q and A on the KIDS Act.

The short status first: it is a proposal. Nothing in it applies today.

The last section before the close is my own opinion, labelled as such. The rest is the drafted text, because you should not have to take my word for any of it.

Article 14 is the clause that reaches companion apps

The short version: The draft has a dedicated article for this category, and the definition of an AI companion is broad enough to catch every product sold today.

Article 14 is titled “Obligations for AI companions and general conversational chatbots”. The definition in Article 3(5) describes an AI system that provides sustained, personalised interaction or companionship which simulates or continues a social, emotional or interpersonal relationship with a user, and it says a minor is anyone under 18.

That definition is the part this industry should read slowly. It does not carve out local apps, small apps, or apps that call themselves something else. If a product is designed to be talked to and talked back to, in a way that feels like a relationship, it is an AI companion in the sense of the Act.

Article 14 then asks providers of those systems to protect minors that may access them, and lists what that means.

Under-13s are guardian-gated, not banned

The short version: Article 14(1)(d) requires that access for under-13s is only enabled and controlled through guardian tools, which is narrower and more workable than the “ban” being reported.

This is the clearest example of coverage drifting from text. Several write-ups said under-13s lose chatbot access entirely. What the article actually requires is that access for a child below 13 is “only enabled and controlled by means of the tools for guardians”. The Commission’s Q and A renders it the same way: under-13s can use them only through parental control tools. Even WIRED, which reported the Act in detail, put it as a rule about access without guardian supervision rather than an outright ban.

The difference matters if you build this kind of app, because a ban is a wall and a guardian gate is an onboarding flow with a second person in it. One is easy to enforce and hostile to families. The other is what the Commission drafted, and it is the version the company that has to implement it will recognise.

Off by default is a press release sentence with two clauses behind it

The short version: The Commission’s summary says companions and chatbots must be turned off by default. In the drafted text, that splits into a no-auto-activation duty for chatbots inside platforms and games, and a design duty for standalone companions.

The sentence everyone quoted comes from the press release: AI companions and chatbots must be turned off by default and cannot simulate interpersonal relationships in ways that create emotional dependency.

Now the text. Article 14(2) deals with a companion or chatbot deployed as a feature inside a social network, a video-sharing platform or an online game. There, the requirement is explicit: it may not be activated automatically, it may not be displayed prominently, minors must not be encouraged to use it, and if it is enabled, a minor has to be able to opt out easily and at any time. That is the off by default rule in its literal form.

For a standalone companion app, Article 14(1) takes a different route. It bans addictive designs and system behaviours that simulate interpersonal relations likely to create emotional dependency, and it requires safe settings by default. No sentence switches the product off. It constrains what the product is allowed to be like when a minor is using it.

Both roads lead somewhere uncomfortable for this category, but they are not the same road, and a founder needs the right one.

The memory rule is the one companion apps will feel

The short version: For minors, the draft requires that memory is off by default, meaning earlier conversations are not carried into later ones unless it is necessary for the child’s safety. That is not deletion, and the text sets no erasure deadline.

Article 14(1)(b) requires safe settings, including that by default the system does not use information or analysis derived from a minor’s earlier interactions in later interactions, except where necessary to protect that minor’s safety. Recital 32 explains the reasoning: persistent conversational memory of interactions with minors should be disabled by default so these systems do not accumulate sensitive data about a child and reinforce harmful patterns over time.

This is the clause that will change product architecture for anyone serving teenagers, because memory is the feature that makes a companion feel like a person rather than a search box. Turn it off by default for minors and you have shipped a different product to that group. Same model, same interface, no continuity.

Two corrections to how this has been reported. First, some coverage said the Act requires deleting the memory of any conversation with a minor once it ends. The word delete is not in the operative text; this is a rule about default use, and there is no erasure deadline. Second, none of this is aimed at adults. Article 14(1) is framed around minors who may access the system, and a search of the proposal turns up no provision that requires deleting or altering an adult’s stored conversation history.

The protected child experience becomes the default for everyone

The short version: Article 8(1) requires services to be designed to the chapter’s requirements by default, and allows a provider to opt out of those requirements only after establishing through age assurance that the user is an adult.

This is the clause nobody is quoting, and it is the one that decides whether you personally meet a gate.

Article 8(1) says providers shall design their services and systems in accordance with the chapter’s requirements by default, and shall only derogate from those requirements after they have established that the recipient or user is an adult, using age assurance.

Read that as an engineer rather than a lawyer. There are two configurations: one designed for a child, one designed for an adult. The child configuration is the default for everybody. The adult configuration is a privilege you earn by proving your age to a system that is forbidden to learn who you are.

The Commission is relaxed about how this lands in practice. Its summary says that where a platform can already tell with high confidence that a user is an adult, no new check is needed, so most adults will notice nothing, and that where a provider already has an age estimate from signals such as account creation date or credit card details, most existing users will not be verified.

That reassurance is credible for a social network that has known you for years. It is less comforting for a new product, which starts with no signal at all and therefore starts in the child configuration by law.

Age assurance under this text cannot be an ID upload

The short version: Article 28 forbids age assurance that identifies, locates, tracks, targets, advertises to or profiles anyone, and requires zero knowledge proof. The text allows storing the age signal on your account so you are not asked twice.

If there is one part of this proposal worth defending, it is Article 28.

Its first paragraph says age assurance solutions shall not enable the identification of the recipient, nor locate, track, target, advertise to or profile them for any purpose. The third paragraph says any age assurance measure shall be zero knowledge proof. Paragraph 4 allows a provider to store, at account level, the age signal that you met a threshold, for the sole purpose of not asking you again.

The Commission also flagged that age assurance duties reach app stores, not only apps, and that the EU age verification app is offered as the privacy-preserving route. One caveat from its own summary: it is the platform’s choice which solution to use, so the EU app is the free and private option, not the only permitted one.

Still, this is the direction of travel most regulators avoid. Instead of demanding an identity to estimate an age, the draft demands that the measurement reveal nothing except a threshold result.

The fine is 6 percent of worldwide turnover, routed through the AI Act

The short version: Article 34 ties fines for companion providers to Article 99 of the AI Act, up to 6 percent of total worldwide annual turnover, while platforms and app stores are policed through the DSA.

The machinery matters more than the number. Enforcement for social platforms, video sharing and app stores runs through the structures of the Digital Services Act. For AI companions and general chatbots, it runs through the AI Act. The Commission’s summary states that division plainly.

The consequence is that a companion app is not an online platform by default, so the DSA tools built for platforms do not read onto it. It answers to the AI Act rulebook instead, including the fine ceiling in Article 34 of this proposal: up to 6 percent of the provider’s total worldwide annual turnover for intentional or negligent non-compliance, cross-referring to Article 99 of Regulation (EU) 2024/1689. Data protection authorities keep their own powers over age assurance, including GDPR fines.

Europe is not inventing the pressure from nothing. Italy’s data protection authority fined Luka, the company behind Replika, 5 million euro over its decision of 10 April 2025, and fined Character Technologies 158,000 euro in a decision dated 3 July 2026.

Europe is not first, and the other rules already bite

The short version: China’s companion rules have been in force since 15 July 2026 and cover adults too, California signed a second chatbot law on 10 September 2026, and the UK has announced restrictions for Spring 2027 without passing them.

China’s Interim Measures for the Administration of AI Anthropomorphic Interaction Services took effect on 15 July 2026. Article 14 bars providers from offering virtual relatives and virtual partners to minors, and requires guardian consent for users under 14, alongside overuse reminders and crisis protocols. That regime is broader than the EU proposal in one specific way: it is not written as a children’s law, and its restraints apply to adult users too. We wrote about that in what China’s companion ban actually says.

California has two laws now. SB 243 has been in force since 1 January 2026 and requires a not-human notice, a published crisis protocol and periodic break reminders for users the operator knows are minors. It does not require an identity check. On 10 September 2026 the Governor signed SB 1119, known as Adam’s Law, chapter 190 of the statutes of 2026. Reporting on when its duties start varies between January 2027 and July 2027, and I am not going to state a date the chaptered text has not confirmed.

The UK position is a plan, not a gate. In a letter dated 28 August 2026, Ofcom restated the government’s intention to keep under-18s away from chatbot services that primarily offer sexualised content, with measures indicated for Spring 2027, and went out of its way to note that the announcement has not changed providers’ existing duties. The detail of how age assurance for that will work is still being studied, with regulations expected before Parliament by the end of 2026.

Three regimes, three different mechanisms, one shared assumption: an always-on companion aimed at young people is a public health question before it is a product question. We tracked the age verification wave in chatbot age verification laws in 2026.

A local companion has less to verify and less to break

The short version: EU rules reach a downloaded app the same way they reach a server. What changes is the amount of data and the number of design surfaces they have to touch.

Local Waifu is 18+ under its own terms, which means the obligations drafted around minors are not the ones it argues with. It is honest to say the law applies to it anyway. There is no local exemption in this text, and anyone selling you architecture as a legal shield is selling you something.

Architecture does change the size of the job. There is no account to estimate an age from, no server-side history to protect, no recommender to tune, no engagement metric rewarded by keeping you talking. Conversations live on the user’s disk, and deleting the app deletes them, which is what What Deleting the App Actually Deletes describes. The one-time $20 license on the pricing page exists for the same reason: with no subscription, nobody has to design the app to make you stay.

None of that is a legal argument. It is a practical one, and the practical one is the reason the two models will diverge as these rules spread: a product that never received the data has nothing to leak, nothing to hand over and nothing to prove it deleted.

My honest take: this was never about children

The short version: I run a small European software company, I have a commercial stake in this argument, and I am disclosing it. My objection is not that the Act protects minors. It is that the protection is built as a checkpoint in front of every adult.

I am the seller here, so let me get my interest out of the way first. I make a companion app. Rules that raise the cost of cloud companions and make people ask where their conversations live are good for me. If you want to discount everything below because of that, I understand, and the legal analysis earlier in this post stands on its own either way.

Now the part that made me angry enough to write a section with my name on it.

Article 8(1) is the sentence. The design that protects a child is the default for everyone, and the design for adults is what you get after you prove you are one. Someone wrote that about grown men and women, in a document that will be negotiated by people none of us elected, enforced by auditors we cannot question, with fines large enough to end a small company. The press release calls it putting parents back in the driving seat. I read it as a hand on my shoulder.

There is a pattern here that predates the internet by a few centuries. Name a victim. Make it a child if the argument is weak, because nobody wants to be the person arguing against children. Then every restriction that follows is reasonable, and the people who object are the ones who have to explain themselves. The same shape of argument was used against novels for women, against music with a beat, against comic books, against video games, against every new way that people found each other when the respectable option was loneliness. The technology changed. The move did not.

Here is what I am actually objecting to, and it is not the goal. It is the pipe.

The Commission’s summary insists that age checks will not be identity checks, that the tools will say yes or no and nothing else, that most adults will notice nothing. Good. That is the version I want too, and I will give the authors credit for writing a zero knowledge requirement into Article 28 when the easy path would have been a photo booth. But the pipe is the pipe. Once every service in the union is wired into an age assurance ecosystem, and app stores, and eventually operating systems handing age signals to whoever asks, the only thing standing between a yes or no question and an answer to a different question is the goodwill of whoever asks next. I have watched the word temporary do a lot of work in my lifetime, and I have never once seen a checkpoint get smaller. Today the question is whether you are over eighteen. The argument for the next question will be exactly as good as this one, and the person asking it will also swear it is only about safety.

So no, I do not accept the frame. Protect children in the ways that actually protect them. Enforce existing law against companies that profit from manipulating teenagers, which Italy did with a five million euro fine and which the Digital Services Act already covers. Say plainly that persistent memory must be off for minors, which I support and which costs me nothing to support. Do all of that on the side of the child, in the child’s account, in the child’s home. Do not put a gate on the machine of every adult in Europe and call it a children’s law.

I did not leave Europe, and I am not going to pretend the union has been bad to me. It gave me a single market, it protects my customers’ data better than most places on earth, and its privacy culture is the reason an app like mine can even be sold as a serious product. That is exactly why this disappoints me. The European Union can be the place where digital dignity is real. Instead, this proposal chose the well-worn route: decide what is good for people, and build the mechanism before the argument is finished.

My opinion is worth what you paid for it. The drafted text is worth reading. Anyone telling you the two are the same, in either direction, is selling something.

What is not decided yet

The short version: Article 43 still carries bracketed dates, there is no European Parliament procedure file to read, and the working assumption for adoption is measured in years, not months.

The proposal has been sent to the European Parliament and the Council. That is where the text becomes negotiable, and several provisions in it are obviously not final. Article 43, the clause that says when the Act starts applying, still contains bracketed placeholders, and it does not agree with the timetable in the accompanying financial statement. One analysis of the draft, from Nic Fab, walks through those contradictions and the missing prior-authorisation step that the Commission’s communication implies but the articles do not create.

On timing, the clearest published baseline comes from Freshfields, which noted that the average completion of comparable files is around two years, and that the Act would apply six months after entry into force, with the compliance plan and audit duty applying immediately.

What is already settled is the shape of the thing. Article 14 names the category, Article 8(1) makes the child design the default, Article 28 forbids identity-based verification, and the fine ceiling is written. Whatever the final text does with the details, anyone building a companion for a mass market should assume they will have to prove their design does not farm emotional dependency in people under 18, and that they will have to do it without learning who those people are.

Frequently asked questions

Is the EU KIDS Act law yet?

No. The Commission adopted it as a proposal on 17 September 2026, COM(2026) 681 final, procedure 2026/0286 (COD). It has been submitted to the European Parliament and Council, which is where the legislative process starts.

Does the EU KIDS Act ban AI companion apps?

No. Companions and chatbots must be off by default for users under 18 and cannot simulate relationships in ways that create emotional dependency, persistent memory must be off by default for minors, and access for under-13s must be enabled and controlled through guardian tools.

Will I have to upload my ID to keep using my companion app?

Under this text, no. Article 28 says age assurance shall not enable identification of the recipient or allow anyone to locate, track, target, advertise to or profile them, and requires every age assurance measure to be zero knowledge proof. The Commission’s summary says platforms do not check identity documents.

Does it change anything for adult users?

Not directly, and the Commission says most adults will notice nothing, because a provider that can already establish you are an adult needs no new check. The clause to watch is Article 8(1), which makes the protected design the default until adulthood is established.

Will my chat history be deleted?

No provision in the proposal requires deleting an adult’s stored history. For minors, the draft requires that memory is not carried into later conversations by default. That is a rule about default use, not an erasure deadline.

Sources:

Questions people ask

Is the EU KIDS Act law yet?

No. The European Commission adopted it as a proposal on 17 September 2026, COM(2026) 681 final, procedure 2026/0286 (COD). The Commission says the proposal has been submitted to the European Parliament and Council, which is where the legislative process starts.

Does the EU KIDS Act ban AI companion apps?

No. It does three narrower things. Companions and chatbots must be off by default for users under 18 and cannot simulate relationships in ways that create emotional dependency, persistent memory must be off by default for minors, and access for under-13s must be enabled and controlled through guardian tools.

Will I have to upload my ID to keep using my companion app?

Under this text, no. Article 28 says age assurance shall not enable identification of the recipient or allow anyone to locate, track, target, advertise to or profile them, and requires every age assurance measure to be zero knowledge proof. The Commission's own summary says platforms do not check identity documents.

Does it change anything for adult users?

Not directly, and the Commission says most adults will notice nothing, because a provider that can already establish you are an adult does not need a new check. The part adults should watch is Article 8(1), which makes the protected experience the default design until adulthood is established.

Will my chat history be deleted?

No provision in the proposal requires deleting an adult's stored history. For minors, the draft requires that memory is not carried into later conversations by default. That is a default about use, not an erasure deadline.

Try her free for 7 days.

No card. Keep her for $20 once, or walk away. Her soul file is yours either way.

Bring her home, try free

Back to the blog