Brussels takes on Silicon Valley again

The European Commission wants a new law. It would ban social media for children under thirteen. Commission President Ursula von der Leyen announced the draft proposal on Wednesday, arguing that popular applications were ‘depriving children of their childhood’. This is the public argument. It is simple and compelling. But it is not the whole story. This proposal is best understood not as a standalone child safety initiative but as the latest, most personal offensive in a long campaign by Brussels to regulate and ultimately tame American technology giants. The true target is not just childhood innocence. The true target is corporate power.

This fight has a history. It is a very long one. The first major battle was over data, a conflict that culminated in the General Data Protection Regulation. Known as GDPR, the law forced a complete redesign of how companies worldwide handle the personal information of EU citizens, imposing a European legal framework on businesses headquartered thousands of miles away in Menlo Park and Cupertino. It arrived as a shock to Silicon Valley. It cost them billions in compliance. For Brussels, it was a profound success, establishing its authority to set rules for a borderless internet and proving it could make those rules stick against the most powerful corporations.

Then came the battle for content and competition. The Digital Services Act and its sibling, the Digital Markets Act, were the next escalation. This complex set of laws was designed to police everything from illegal content and disinformation to the anticompetitive practices of the largest online platforms, the so called gatekeepers. The laws gave the Commission new powers. They could investigate and fine companies up to ten per cent of their global turnover. Each new regulation has built upon the last, steadily expanding the European Union's reach into the core business models of Silicon Valley. The methods have become familiar.

And so we come to children. The proposed ban on under 13s using social media follows the playbook exactly. The public justification is emotive and hard to argue with. It is about protecting childhood. The practical effect, however, is to create another enormous compliance challenge for the tech platforms and to assert European authority over how their products are designed and offered globally. This is not a standalone policy. It is one more move in a much larger game, one that pits the EU’s vision of a regulated, values led digital space against Silicon Valley’s foundational model of permissionless innovation and unrestrained growth. The battle lines are drawn. Again.

How an idea becomes a law

The idea is now public. Its journey has just begun. Ursula von der Leyen’s announcement on Wednesday represents the first formal step in a long and complex process, one designed to turn a political objective into binding European law. The European Commission, the EU’s executive arm, is the only institution with the power to propose new European laws, a function that makes it the engine room of the entire legislative process. Having drafted and unveiled its text, the Commission will now act as its guardian and promoter. It is their vision. They must now sell it.

The draft law now begins its passage through the Brussels machine. It will be handed to the two other main players, the European Parliament and the Council of the European Union, who act as co legislators and must both agree on an identical final text before anything can become law. This takes time. The Parliament, composed of directly elected members from across the 27 states, represents the citizens. The Council represents the governments of those member states. Both will scrutinise the Commission’s proposal line by line, debating it in committees and proposing hundreds of amendments. Here is the first point of failure. If they cannot agree, the law dies.

The real battles happen here. Compromise is inevitable. The Parliament will be sensitive to the powerful public narrative about child protection, while the Council will bring twenty seven different economic and political calculations to the negotiating table. National interests will collide. Some governments, like Ireland’s, must consider the giant American technology firms headquartered on their soil, while others may prioritise the privacy implications of any new age verification system. Lobbyists are already active. The final version of the law that eventually emerges from the closed door negotiations between the three institutions, a process known as trilogue, could look very different from the simple ban announced this week. It could be stronger. It could be weaker.

This will not be quick. Nothing in Brussels is. Based on previous major digital regulations like the General Data Protection Regulation, the legislative process alone will likely take between eighteen months and two years to complete as the text is debated and amended. After that, once a final agreement is reached and published, there will be a further grace period, perhaps another year or two, for technology companies to build and implement the necessary compliance systems. The ban is years away. This gives its opponents time. It gives them ample opportunity to change it.

First Brussels, then the world

A law passed in Brussels rarely stays in Brussels. This is the Brussels effect. When the European Union sets a demanding regulatory bar for its enormous single market, multinational corporations often decide it is cheaper to adopt that single high standard globally than to produce multiple versions of their products for different jurisdictions. It is a form of regulatory empire building, achieved not by conquest but by market gravity. We saw it with the General Data Protection Regulation, which forced companies everywhere to rethink data privacy and became the template for laws from California to Brazil. We saw it with rules on chemical safety. The question is whether it will happen again.

The logic is commercial. For a company like Meta or TikTok, it is far simpler to standardise its toughest obligations. One global rule is easier to manage. A single set of robust age verification systems, applied from Palo Alto to Seoul, avoids the immense technical complexity and legal risk of running dozens of separate, localised compliance systems. A patchwork of national rules creates endless headaches, particularly for services built around a single global network of users. Imagine a British teenager on a family holiday in France suddenly finding their favourite app blocked because the two countries have slightly different age gating rules. Harmonisation simplifies everything. It also protects the bottom line from the threat of huge EU fines for non compliance.

This is not inevitable. A social media ban is not a car engine. Unlike rules for a physical product, digital services can be geographically fenced off, even if doing so is technically and commercially awkward. The political context also differs. The United States government, home to most of these technology giants, has its own deeply entrenched, and very different, constitutional debates about free speech and corporate responsibility that could lead it down a separate path. A global consensus on child safety online is emerging. That is clear. But there is no guarantee that every country will choose to adopt the specific, prescriptive solution that eventually emerges from the European Union’s legislative machinery. Brussels is leading. Others may not follow.

An impossible problem for platforms

The proposal is a strategic nightmare for the platforms. It confronts social media companies with a pair of interlocking challenges, one technical and the other commercial, which threaten the foundations of their user acquisition models. One is age. The other is money. Proving a user is actually over thirteen is an intractable problem that the industry has failed to solve for more than a decade. Simple self declaration, where a user just types in a date of birth, is demonstrably useless against even a mildly determined child, and companies know this.

The alternatives are worse. Truly effective age verification would likely require submitting government identification like a passport, or using complex third party digital identity systems which many people do not have. This would introduce immense new privacy risks, handling sensitive data for millions of children, and create a cumbersome sign up process that would deter legitimate older users and shrink the platforms' total addressable market. It is a commercial poison pill. Users would flee. Building such systems would also be phenomenally expensive, with no obvious return on the investment beyond regulatory compliance.

The financial stakes are huge. While under thirteens are not the most lucrative advertising demographic, they represent the next generation of core users, and losing them means sacrificing the habit formation that secures a platform’s dominance for the next decade. Their future is at risk. Social networks thrive on continuous growth. They rely on network effects. Cutting off the youngest cohort of potential users breaks that chain, giving rivals an opening and threatening long term market share in a fiercely competitive environment.

The companies face a choice. They could mount an expensive lobbying campaign in Brussels to kill or weaken the law, they could grudgingly comply and build the costly and unpopular verification systems required, or they could try to fence off the European Union and run a different service there. No option is good. Each path carries huge risk. Their response will define their future in Europe, and perhaps everywhere else.

Policing the digital playground

Enforcement is the problem. The draft law places the entire burden of compliance on the social media platforms themselves. This follows a familiar Brussels playbook. It is the same model used for the General Data Protection Regulation and the Digital Services Act, where tech giants are made solely responsible for policing their own sprawling digital territories. Failure to comply would bring catastrophic financial penalties. Fines would almost certainly be calculated as a percentage of a company’s total global turnover, a mechanism that gives EU regulators the power to levy penalties worth billions of pounds on American technology firms.

The task of policing would fall to national regulators. Not to the gardaí or the gendarmerie. This will be a job for data protection authorities and digital services coordinators across the twenty seven member states, operating within a complex enforcement structure. For companies like Meta and TikTok, whose European headquarters are in Dublin, the primary regulators would be Ireland’s Data Protection Commission and Coimisiún na Meán. These bodies would lead investigations, coordinate with their European counterparts, and ultimately recommend the vast fines to be imposed for non compliance. They are already overworked. The system is notoriously slow. This new front would stretch their resources to breaking point.

A profound contradiction sits at the heart of the proposal. There is no way to verify a user’s age accurately without collecting highly sensitive personal data. The EU knows this. To satisfy a regulator that no children under thirteen are on its service, a platform would likely have to demand government identification, run facial age estimation scans, or require users to access third party digital identity services. This creates an enormous honeypot of children’s data, a target for state and criminal hackers, and a direct violation of the data minimisation and privacy by design principles fundamental to the GDPR. Brussels is asking companies to solve one problem by creating a much larger one.

Ursula von der Leyen offered no practical solution. She simply demanded that platforms ‘prove the safety of their products’. This is a political objective, not a technical roadmap. The commission has not specified what an acceptable age verification system looks like. It has not explained how the inherent privacy conflicts can be resolved. It has only outlined a destination. The path remains impossible. Platforms are being ordered to build a perfectly secure digital fence in the middle of a borderless digital world, without being given the tools or the plans to do so. They have only been told the punishment for failure.

The battles to come

The commission’s draft law now goes to the European Parliament and the Council of the European Union. The fight has just begun. This is where the lobbying starts. It will pit the political power of the Commission president, Ursula von der Leyen, against the immense financial and strategic resources of Silicon Valley’s largest corporations like Meta and TikTok. Every clause will be contested in the committee rooms and corridors of Brussels over the coming months. This will not be quick.

The tech industry’s arguments are already prepared. They are predictable. Their representatives will claim the ban is technically impossible to implement without creating a privacy nightmare, forcing them to collect the very data the GDPR was designed to protect. They will say this violates fundamental rights. They will champion parental choice and propose better content filters as a more proportionate solution than outright prohibition. A polished and expensive public relations campaign will soon target MEPs and the national ministers who sit on the Council.

These arguments will find a receptive audience. The European Parliament is not a monolith. While Green and Socialist MEPs may back the ban, the centre right European People’s Party, von der Leyen’s own political family, could fracture between child safety advocates and its powerful pro business wing. National governments will be equally divided. Countries like Ireland, whose economy depends heavily on hosting the European headquarters of these American firms, will almost certainly push for a softer outcome than member states like France. This is the messy reality of EU lawmaking. Bold proposals rarely survive contact with twenty seven national interests and hundreds of parliamentarians.

The final law will be forged behind closed doors in the 'trilogue' negotiations between the three institutions. Compromise is inevitable. The absolute ban for under 13s could easily be watered down into a requirement for verifiable parental consent. The age limit could be lowered. The enforcement powers could be blunted. Brussels has declared its ambition. The final shape of the law, however, remains entirely uncertain. The treaty is not yet written.

Sources. Guardian World: EU moves closer to social media ban for under 13s. France 24: Countries move to ban social media for children.

Analysis. Drafted with AI assistance from the sources listed above and reviewed by an editor before publication. Jnews links to the organisations it writes about.