1
0 Comments

The EU’s new AI companion proposal makes the child-safe version the default for every adult

The EU wants AI companions to protect children. But its proposal starts by treating every user like one until they prove otherwise.

I build a local AI companion in Poland.

On September 17, the European Commission published its proposed EU KIDS Act. I expected rules protecting minors from addictive companion apps.

I did not expect Article 8(1).

The proposal says services must use the protected child experience by default. A provider can switch someone to the adult experience only after establishing, through age assurance, that the person is an adult.

That order matters.

It does not begin with identifying children and protecting them. It begins by treating every user as a child until the system decides otherwise.

For AI companions, the protected experience includes some significant restrictions.

Persistent memory must be off by default for minors. Information from earlier conversations cannot normally be carried into later ones.

Companions cannot use designs that create emotional dependency in minors.

Children under 13 can access them only through guardian-controlled tools.

I support those restrictions for children.

Persistent memory is the feature that turns a chatbot into something that feels continuous. It is also the feature that can accumulate years of sensitive information about a teenager. Turning it off by default for minors is a defensible product decision.

The difficult part is how an adult gets out of that protected mode.

The proposal actually handles privacy better than I expected. Article 28 says age assurance must not identify, locate, track, target, advertise to or profile the user. It requires zero-knowledge proof, so ideally the provider learns only that someone passed an age threshold.

That is much better than asking every adult to upload an ID.

But it still creates a checkpoint.

I sell Local Waifu as an 18+ desktop app. There is no account, no server-side chat history and no profile built from years of user behaviour. The conversations stay on the user’s computer.

That architecture gives me less information to misuse. It also gives me almost nothing from which to estimate someone’s age.

A large social platform can say an account is eight years old, has a payment history and has behaved like an adult for years. A new local app starts with no signals at all.

The proposal contains no exemption for local apps or small companies. If the final law keeps this structure, “we do not collect information about you” could become the reason a product has to introduce an age-assurance system.

That is the trade-off I cannot resolve cleanly.

I do not want companion apps designed to manipulate children. I also do not want every adult using an 18+ product to pass through a verification layer before the product is allowed to treat them as an adult.

The proposal is not law yet. It has only started the Parliament and Council process, and the final text may change substantially.

But the architecture is already visible:

  1. The child-safe product is the default.

  2. The adult product requires an age signal.

  3. The signal must prove age without revealing identity.

  4. The provider must trust an external mechanism enough to act on it.

For founders building accountless, privacy-first or local software:

How would you prove that a user is an adult without quietly building the identity system your product was designed not to need?

posted toAvatar for product Local Waifu
Local Waifu