The topic is an old one, but in 2026 it has two new fronts: a proposed European regulation on protecting minors online, which dedicates an article to games, and new PEGI classification criteria that take in-game purchases and return mechanics into account. Here is what the texts actually say, and what is still only a proposal.
The European proposal: where it stands
On September 17, 2026 the European Commission presented proposal COM(2026) 681 on protecting minors online. It is not yet law: it needs the approval of the European Parliament and the Council. The text provides that the regulation enters into force on the twentieth day after publication in the Official Journal of the European Union and applies six months after entry into force.
Article 15: obligations for online games
Article 15 asks online game providers to put in place measures for a high level of privacy, safety and security for minors. At least:
- no encouragement of compulsive or excessive use by minors, applying the rules on addictive design (article 9), including those against mechanics that reward playing at regular times or more often, even through penalties or loss of benefits for failing to do so;
- minors' settings at a high level of privacy and security by default (article 11);
- contacts between minors and other users subject to safety safeguards (article 12);
- mandatory tools for parents or guardians (article 20), and for minors under 13 access to online games enabled and controlled only through these tools.
Two further provisions apply: providers must put safeguards in place to prevent the game from being used to entice minors into contacts on other services that may pose a risk, and platforms that let users create and publish video games must have the necessary measures so that those games also comply.
The tools for guardians
Article 20 describes what the control tools must be like: tailored to the minor's age, easy to use and activate, changeable only with the same level of authorisation required to activate them, effective and not easy to circumvent, not disproportionately restricting minors' rights and respectful of their agency and privacy. They must include measures for time-limited access, settings management and a way to report content or behaviour considered harmful. The minor must be informed when a tool is in use.
App stores
Article 16 covers software application stores. They must:
- have an age-rating system for each application offered;
- not allow minors to access or purchase applications that are not appropriate for their age under that system;
- assess the user's age, including through the tools for guardians, and for minors under 13 allow access only through those tools;
- make publicly available, in clear terms, the methodology, criteria and sources used for the rating;
- allow the EU age verification solution.
Codes of conduct
Article 17 tasks the Commission with encouraging codes of conduct at EU level, with the involvement of stores, developers, age classification systems, organisations representing minors and authorities. They must define common criteria for assessing age-appropriateness of content, in particular violent, sexual, gambling and self-harm content, and for in-app purchases, contact risks and addictive design features. For online games they must set out measures to give effect to the obligations of article 15, also building on existing European classification frameworks, including their criteria on interactive features and monetisation practices. Providers adhering to a code assessed as adequate by the Commission can rely on it to demonstrate compliance.
Who enforces it
For online games that are video games, article 34 provides that each Member State designates a competent authority to supervise and enforce article 15. Penalties are set by Member States; exclusive competence lies with the authority of the State where the provider's main establishment is located. For video gaming platforms, the supervision and penalty rules of the Digital Services Act apply instead.
What changes with PEGI
PEGI, the European age rating system, has added new interactive risk categories since June 2026. Under the new criteria:
| Element | Rating |
|---|---|
| Time-limited or quantity-limited offers (in-game purchases) | PEGI 12 |
| Blockchain or NFT mechanics | PEGI 18 |
| Paid random items (loot boxes) | PEGI 16 by default, in some cases PEGI 18 |
| Incentives to return (daily quests, login streaks) | at least PEGI 7 |
| Penalties for not returning to play | at least PEGI 12 |
| Entirely unrestricted online communication | PEGI 18 |
These features can therefore automatically raise a game's age rating.
What parents can do now
Until the proposal becomes law, the tools that already exist remain:
- read the PEGI rating and descriptors before buying, keeping the new criteria on purchases and communication in mind;
- use parental controls on consoles, PCs and stores: limits on time, spending and chat;
- turn off or limit in-game purchases and protect payments with a password;
- talk with your children about who they can contact online and what to do if someone keeps insisting.
For those who develop or publish games and apps
If you publish online games or apps that also reach minors, it is worth checking three things today: how purchases and daily-return rewards are presented, which settings are on by default for underage users and how communication between players works. The proposal is still under discussion and the final text may change, but the requests on these points are already clear.
Read also: October 2026 releases.
This article is informational: for the binding text, the final regulation prevails once adopted.
