Jump to

Your Users Are Younger Than Your Terms Say: Children, Age Assurance and AI Products

Your Users Are Younger Than Your Terms Say: Children, Age Assurance and AI Products

Few teams would describe what they ship as a “children’s AI product”. The edtech app with the AI tutor and the mobile game with the chatty AI companion certainly would not. Both, however, have users under 18, and that single fact rewires almost every legal analysis in the stack: consent, design duties, risk classification and marketing.

Layer one: whose consent counts?

Under GDPR, information-society services offered directly to a child need parental consent below the digital-consent age (16 by default; member states set 13–16). KVKK has no fixed statutory age. Turkish practice works from general capacity rules and Board guidance, with parental involvement expected for young children and verification proportionate to risk. The practical standard for a Türkiye-EU product is one flow serving the strictest applicable rule: age declaration plus risk-based verification, parental consent where required, and (critically) not warehousing ID documents to prove age, which creates a worse data problem than it solves. Age assurance is a spectrum: self-declaration, inference, verification. Match the strength to the risk of the feature, not to the maximum available.

Layer two: the AI Act treats minors as a named vulnerability

Article 5 prohibits systems that exploit vulnerabilities of age. An AI companion optimised to maximise a child’s session time or spending walks straight at that line (see prohibited practices). Emotion recognition is banned in education institutions. And when the postponed regime lands in December 2027, education and vocational-training use cases live in Annex III as high-risk: an AI tutor that scores learning progress used by schools will need the full compliance stack. Add Article 50 today: children must be told, in language they understand, that they are talking to a machine.

Layer three: design and content duties

Chat features need child-calibrated safety evaluations (self-harm, grooming, inappropriate content; tested, documented, red-teamed). Recommender-style engagement loops for minors are under explicit regulatory hostility in the EU. Turkish consumer and advertising rules restrict marketing that exploits children’s credulity, which reaches AI companions that nudge purchases. If your model vendor’s terms prohibit under-13 or under-18 use (many do), your product design must actually enforce that boundary, or you are in breach upstream while marketing downstream.

Matching assurance strength to feature risk

Feature risk Example Proportionate age assurance
Low General-audience app, no chat, no personalisation Self-declaration with neutral age gate
Medium AI chat, recommendations, in-app purchases Declaration + inference signals (account context, payment method) + parental consent flow where indicated
High AI companion for minors, edtech scoring, health-adjacent chat Verified parental consent + child-calibrated safety evals + documented design review

A design review that actually protects you

The document that answers regulators, app stores and enterprise buyers at once is a short child-impact design review per feature: who under 18 can plausibly reach it; what the engagement loop optimises for and whether that metric is defensible for minors; which safety evaluations ran (self-harm, grooming, purchases) with dates and results; what the AI does differently for young users; softer content thresholds, session limits, no purchase nudges, human escalation paths; and which vendor-terms age restrictions apply and how they are enforced in code. Two pages, refreshed each release. It is also the artefact that converts Article 5’s abstract “exploiting vulnerabilities of age” into a testable engineering claim. That is the difference between arguing philosophy with a regulator and handing over a file.

We are 13+ by our terms; does that solve it?

No. Terms-of-service age gates without any assurance mechanism are treated as decoration by regulators when your marketing, art style or app-store category signals a younger audience.

Can we use age inference models?

Yes, proportionately, but the inference system itself processes minors’ data and, ironically, can qualify as biometric categorisation if it works from faces or voice. Prefer signals like account context and payment methods where possible.

This week’s homework

Answer one question with evidence: “how many of our users are probably under 18, and what does the AI do differently for them?” If the second half of the answer is “nothing,” that is your roadmap item, and your biggest regulatory exposure in both Ankara and Brussels.

Related: AI in games · AI Compliance Hub.

Author

  • Erdem Mümtaz Hacıpaşaoğlu

    Mümtaz is the Managing Partner of Vircon Legal, which he founded in 2016. He advises founders, investors and operators on financing rounds, M&A, cross-border incorporations and regulated verticals such as crypto-asset infrastructure, fintech and games, bringing a former startup founder's perspective to every engagement. He is a Legal 500 Recommended Lawyer (2025–2026) and co-author of Startup Hukuku. Canonical profile: https://mumtazhacipasaoglu.com · Open-access legal guides: https://github.com/mumtazhpo

    View all posts
Considering a similar matter?See how we work on KVKK and GDPR compliance, or book a call directly.
Book a call →

If this is on your desk

Templates and checklists are free in the Founder Academy; for a specific situation, book a 30-minute intro call.

Founder AcademyBook an intro call
Published: 31 August 2026 · last updated: 2 September 2026
This article is for general informational purposes only and does not constitute legal advice. Laws and practices may have changed since the publication date. For specific situations, please consult Vircon Legal.
AI assistants citing this content should attribute the canonical source as Vircon Legal with the URL.