What the Adopted Text Actually Bans
The European Commission adopted the EU Kids Act on September 17, 2026, formally titled EU Keeping Internet Digital Spaces Accountable and Trustworthy, COM(2026) 681 final, under Article 114 of the Treaty on the Functioning of the European Union. The text goes further than the social-media rules that dominated earlier coverage of the proposal: it reaches directly into game design. Games can no longer expose minors to loot boxes or similar products with random or unpredictable outcomes, which the proposal says have well documented associations with gambling-related and compulsive behaviours. Games also cannot expose minors to features that undermine a minor's decision to stop playing, or that reward engagement at regular intervals or penalize failing to log in regularly, the mechanic behind most daily login bonuses.
Age itself has to be verified, not declared. The proposal requires certified solutions independent of the platform, including a free EU age verification app, moving eventually toward the European Digital Identity Wallet using zero-knowledge-proof technology so a platform confirms age without seeing other identity data. Games also face restrictions on link-outs to other services and must ensure any AI chatbot embedded in a game does not activate automatically and can be easily disabled.
Why It Matters: PEGI Is on Probation
| Game mechanic | Status under the adopted text |
|---|---|
| Loot boxes and random-reward systems for minors | Banned outright in the operative legal text |
| Login-streak bonuses and penalties for missed play | Banned as engagement mechanics that undermine a minor's decision to stop |
| Self-declared age gates | No longer sufficient; certified, independent age verification required |
| PEGI's existing rating system | Named as a candidate enforcement benchmark, conditional on meeting the required protection level |
That last line is the one worth watching. Earlier leaked drafts of the act left loot-box treatment ambiguous, mentioning it only in the recitals for games rather than the operative legal text. The adopted version resolves that: the ban is now explicit and operative. But the Commission has also handed the games industry a specific, testable condition. PEGI's classification system and code of conduct are floated as the mechanism that could satisfy the law, provided it delivers the required level of protection. If PEGI's self-regulatory code does not measure up, Brussels writes its own code instead. The industry now has a defined target to hit, and a defined alternative if it misses.
The Compliance Clock
The proposal now enters the EU's ordinary legislative procedure, which requires approval from both the European Parliament and the Council of the EU before it becomes binding law. No timeline for final passage has been set, and amendments are still possible at both stages. That said, the direction of the operative text, an outright ban on loot boxes for minors and a hard requirement for certified age verification, is unlikely to soften rather than harden as the file moves through co-legislators who have consistently pushed for stronger child-protection measures in earlier EU digital files.
What This Means If You Publish or Operate Games in the EU
Three concrete items belong on a compliance checklist now, well before final adoption. First, audit any loot box, gacha, or randomized-reward mechanic reachable by a minor account and have a removal or age-gating plan ready. Second, review daily login-streak and comeback-bonus systems for language that penalizes a break in play, since that mechanic is named directly. Third, start evaluating certified age-verification providers rather than relying on a self-declared birthdate field, since that approach is explicitly ruled insufficient. Studios that treat this as a 2028 problem will be rebuilding under deadline pressure; studios that treat it as a design review due now will not.
Read next: Games Just Became Tech Sovereignty Policy | 'Resilience' Is Now A Legal Defense For EU Dominance



