What the Adopted Text Actually Bans

The European Commission adopted the EU Kids Act on September 17, 2026, formally titled EU Keeping Internet Digital Spaces Accountable and Trustworthy, COM(2026) 681 final, under Article 114 of the Treaty on the Functioning of the European Union. The text goes further than the social-media rules that dominated earlier coverage of the proposal: it reaches directly into game design. Games can no longer expose minors to loot boxes or similar products with random or unpredictable outcomes, which the proposal says have well documented associations with gambling-related and compulsive behaviours. Games also cannot expose minors to features that undermine a minor's decision to stop playing, or that reward engagement at regular intervals or penalize failing to log in regularly, the mechanic behind most daily login bonuses.

Age itself has to be verified, not declared. The proposal requires certified solutions independent of the platform, including a free EU age verification app, moving eventually toward the European Digital Identity Wallet using zero-knowledge-proof technology so a platform confirms age without seeing other identity data. Games also face restrictions on link-outs to other services and must ensure any AI chatbot embedded in a game does not activate automatically and can be easily disabled.

Why It Matters: PEGI Is on Probation

Game mechanicStatus under the adopted text
Loot boxes and random-reward systems for minorsBanned outright in the operative legal text
Login-streak bonuses and penalties for missed playBanned as engagement mechanics that undermine a minor's decision to stop
Self-declared age gatesNo longer sufficient; certified, independent age verification required
PEGI's existing rating systemNamed as a candidate enforcement benchmark, conditional on meeting the required protection level

That last line is the one worth watching. Earlier leaked drafts of the act left loot-box treatment ambiguous, mentioning it only in the recitals for games rather than the operative legal text. The adopted version resolves that: the ban is now explicit and operative. But the Commission has also handed the games industry a specific, testable condition. PEGI's classification system and code of conduct are floated as the mechanism that could satisfy the law, provided it delivers the required level of protection. If PEGI's self-regulatory code does not measure up, Brussels writes its own code instead. The industry now has a defined target to hit, and a defined alternative if it misses.

The Compliance Clock

The proposal now enters the EU's ordinary legislative procedure, which requires approval from both the European Parliament and the Council of the EU before it becomes binding law. No timeline for final passage has been set, and amendments are still possible at both stages. That said, the direction of the operative text, an outright ban on loot boxes for minors and a hard requirement for certified age verification, is unlikely to soften rather than harden as the file moves through co-legislators who have consistently pushed for stronger child-protection measures in earlier EU digital files.

What This Means If You Publish or Operate Games in the EU

Three concrete items belong on a compliance checklist now, well before final adoption. First, audit any loot box, gacha, or randomized-reward mechanic reachable by a minor account and have a removal or age-gating plan ready. Second, review daily login-streak and comeback-bonus systems for language that penalizes a break in play, since that mechanic is named directly. Third, start evaluating certified age-verification providers rather than relying on a self-declared birthdate field, since that approach is explicitly ruled insufficient. Studios that treat this as a 2028 problem will be rebuilding under deadline pressure; studios that treat it as a design review due now will not.