September 2026: IJLT Tech-Law Bulletin
Beyond Parental Consent: Children’s Online Safety and the Responsibility to Design Safer Platforms
On 17 September 2026, the European Commission proposed the EU KIDS Act, combining phased access to social media with obligations governing the design of services used by children. The proposal seeks to prohibit social-media access below thirteen, permit parent-managed limited accounts between thirteen and fifteen, and allow independent accounts from fifteen. It awaits consideration by the European Parliament and the Council. While the age thresholds will attract considerable attention, the more consequential question concerns what platforms must change once a child is allowed in.
The proposal addresses features that encourage excessive use, including infinite scroll, reward mechanisms and notifications during sleeping hours. It also envisages private profiles by default, restrictions on unsolicited contact from strangers, and accessible blocking and muting tools. AI companions and chatbots would face safeguards against designs that encourage emotional dependency. These measures recognise that children’s exposure to harm can arise through ordinary product features, and regulation cannot be limited merely to services that host unlawful content.
Parental consent answers whether a child has permission to use a service, but does not really reflect on conditions of use. A parent may approve an account without understanding how recommendations are generated, why certain notifications appear, or how the service responds to a child’s repeated engagement. Nor can parental supervision readily alter those features. A framework centred on permission therefore risks assigning responsibility to the person with the least control over the product.
This concern connects with the Bulletin’s earlier Meta coverage, titled “New Mexico v Meta: Platform Design, Public Harm and the Limits of Judicial Regulation.” That discussion examined the distinction between responsibility for third-party content and responsibility for a platform’s own design. It also highlighted the limits of seeking structural changes through litigation against one company. This proposal furthers this debate into legislative reform: safety obligations would attach to covered services before families are required to establish that harm has occurred.
The Commission’s explanatory material gives this preventive approach institutional substance. The largest platforms would have to submit compliance plans supported by independent audits before their services come into contact with children under the new regime. Parental tools would complement providers’ obligations. For regulatory purposes, this makes safety a matter that companies must demonstrate through their systems and practices. The practical difficulty will be ensuring that an audit tests the psychological experience and impact of using a service, rather than merely recording the existence of protective settings.
Similar concerns have been raised in India; Vidhi published a report: In Their Best Interests, which a analyses the statutes and subordinate legislations against fourteen digital harms. It concludes that the current framework is a largely reactive and fragmented, with limited attention to children’s evolving capacities and risks embedded in digital environments.
The report finds a stronger legal framework where harm involves a wrongful act by an identifiable actor. But the structure fails to respond to cumulative harms. This helps explain why criminalisation and content removal, although necessary, cannot exhaust the regulatory response. Where risk develops through repeated exposure or several interacting features, identifying an offending post or prosecuting an individual leaves the surrounding system largely untouched. Vidhi accordingly proposes safety by design, proportionate intervention and responsibility differentiated according to each stakeholder’s influence and capacity. It does not recommend importing foreign frameworks wholesale.
India’s data-protection framework already contains preventive elements. Section 9 of the DPDP Act provides for verifiable parental consent, prohibits processing likely to harm children’s well-being, and restricts tracking, behavioural monitoring and targeted advertising directed at children, subject to statutory exceptions. These provisions give children’s interests legal significance beyond consent alone. Their focus on personal-data processing nevertheless leaves a further question: how should the law address harmful design choices across the wider range of services children use?
Age verification introduces its own difficulties. In an earlier FPF–nasscom discussion, Vrinda Bhandari stressed that parental-consent verification must be proportionate and sensitive to risk. She pointed to privacy concerns surrounding identification methods and uneven digital literacy among parents. Verification can itself become a source of vulnerability if it requires unnecessary disclosure of sensitive information. Its success cannot be measured simply by how difficult it makes account creation.
The European approach also raises questions about children’s autonomy. In a 24 September discussion, Sonia Livingstone welcomed the graduated approach while emphasising privacy-preserving age assurance and effective enforcement. Youth representative Tobiáš Bruno Galia questioned the continued reliance on access restrictions, warning that exclusion could deprive young people of valuable communities and opportunities for participation. Safer access must accommodate the fact that children use digital services for friendship, learning and expression, as well as entertainment.
For India, the useful lesson concerns the allocation of responsibility. Parents and schools can support informed use, while platforms control recommendations, defaults and engagement features. Regulatory duties should reflect that distribution of power.
Pacing the Frontier: AI Safety Cooperation and the Competition-Law Limits on Restraining Innovation
On 18 September 2026, four paying subscribers filed a proposed class action against Anthropic, OpenAI, SpaceXAI and Google in the Northern District of California. In Buist v Anthropic, they allege that the companies agreed to slow improvements in competing AI products, violating Section 1 of the Sherman Act. Their claim concerns competition over capability and product quality: subscribers allegedly receive slower improvements for the prices they pay. The complaint advances per se illegality, abbreviated “quick-look” analysis and rule-of-reason liability in the alternative.
This development arises out of Dario Amodei’s essay, We Must Pace the Frontier. Amodei argues that advancing capabilities could outstrip alignment research, testing and operational safeguards. His proposal combines embedded independent evaluators, coordination among companies in democratic countries, and eventual international cooperation. It contemplates common safety standards and limits on unchecked progress, alongside a narrow antitrust waiver for certain discussions. Amodei distinguishes pacing from halting technological development. His stated objective is to allow safeguards to catch up while preserving AI’s benefits.
The complaint gives those proposals a different legal character. It relies on public endorsements and alleged private discussions to argue that independent rivalry has been replaced by collective restraint. Importantly, it expressly preserves unilateral safety decisions, lawful research and legitimate standard-setting that does not restrict independent competition. The dispute therefore turns partly on what, if anything, the companies committed to do together. Agreement on the importance of safety and an agreement restricting product development are propositions that require separate examination.
Writing in Lawfare, Nicholas Felstead identifies a collective-action difficulty: a company that pauses alone may surrender its lead to a less cautious rival without reducing the overall risk. Effective coordination would require verification, commitments and conditions governing when development stops and resumes. Yet those features can also establish the terms of an agreement restricting competition.
The design of coordination matters within this account. Felstead discusses an evaluation-based scheme proposed by Jide Alaga and Jonas Schuett, under which dangerous capabilities trigger investigation, mitigation and temporary pauses. Voluntary decisions, binding commitments and arrangements involving a common auditor carry different legal risks. Even under the rule of reason, however, courts may resist a justification that competition itself is dangerous. Felstead highlights this difficulty through the US Supreme Court’s rejection of a comparable public-safety defence in National Society of Professional Engineers.
In his interview, the former US antitrust chief Jonathan Kanter takes a more sceptical position, arguing that companies already bear responsibility for safe products. Safety and security should themselves attract innovation, supported by public regulation and accountability. He opposes an antitrust exemption and stresses opportunities for smaller competitors. His position locates the response to unsafe development in obligations governing firms’ conduct, while retaining competitive pressure to improve their products.
Madhavi Singh adds a question about access. Her Project Glasswing analysis concerns a different safety consortium, whose members receive privileged access to advanced capabilities and security information. She warns that exclusion and information exchange can strengthen incumbents or turn consortium practices into barriers to entry. Regulatory scrutiny should examine the necessity of restrictions, the purposes of shared information and the duration of exclusivity. Similarly here, it is important to consider who participates in a safety arrangement and whether its benefits are available to competing developers.
For India, the statutory starting point is unusually direct. Section 3(3)(b) covers agreements among competitors limiting or controlling technical development, investment, production or services. A proven agreement to cap model improvements could therefore attract scrutiny without establishing dominance. Section 2(b) includes informal understandings and action in concert; a signed contract is unnecessary. Nevertheless, the existence and scope of an agreement must be established. Public support for caution does not, by itself, settle that inquiry.
The Indian framework also allows an assessment of benefits. Section 3(3)’s presumption of appreciable adverse effects is rebuttable. Section 19(3) directs attention to consumer benefits, improvements in goods or services, and technical, scientific and economic development, alongside exclusionary effects. The efficiency-enhancing joint-venture proviso removes qualifying arrangements from the subsection’s presumption, rather than providing general immunity from Section 3. The CCI’s COVID-19 advisory expressly recognised these safeguards while limiting its accommodation to necessary and proportionate conduct addressing the crisis. It supplies an analogy for bounded cooperation, rather than an AI-specific exemption.
An AI-safety arrangement could accordingly raise competing interpretations. Joint testing might improve reliability and reduce duplication, supporting an efficiency account. Coordinated release delays might restrict technical development or insulate participants from competitive pressure. Both effects could exist within one arrangement. Applying the statutory factors would require evidence of the particular risk, the benefits of cooperation, its effects on consumers and rivals, and whether narrower measures could achieve comparable protection.
India-focused writing on sustainability agreements explores a related tension. In an ABA article, Naval Satarawala Chopra, Rohan Arora, Raveena Sethia, Shivek Endlaw and Aryan Uppal suggest that existing consumer-interest and efficiency provisions could accommodate beneficial collaboration. They also identify uncertainty and the danger of sheltering collusion behind public objectives. Their proposed responses include guidance, consultation mechanisms and possible statutory reform. This is practitioner analysis of ESG cooperation, whose relevance to AI safety is analogical.
Oorja Newatia’s IndiaCorpLaw contribution places greater emphasis on legislative flexibility. It proposes an additional proviso accommodating agreements that further public-interest objectives pursued by Indian laws, while requiring demonstrable benefits and proportionality. The distinction matters: an expansive interpretation of existing efficiencies and a new statutory exception offer different routes. Neither establishes that a general public-interest defence already protects an AI-development pact.
Other statutory routes remain relevant. Section 32 permits scrutiny of overseas arrangements affecting competition in India. Section 54 empowers the Central Government to notify specified exemptions, including for classes of enterprises where necessary for public interest or state security. Such protection requires governmental action. Meanwhile, the CCI’s AI-study announcement emphasises compliance audits, regulatory coordination and access to infrastructure. It does not authorise coordinated development restraints.
September’s dispute thus brings several unresolved questions together: whether an agreement exists, what it restricts, whose interests it protects, and which institution should assess the claimed benefits. The commentators differ on each of these questions. Indian law offers grounds for scrutinising restraints and considering efficiencies, while the wider debate concerns how far those provisions can accommodate risks extending beyond the immediate market.
India’s Amended E-Commerce Rules: What Changes on 1 January 2027
On 9 September 2026, the Department of Consumer Affairs notified the Consumer Protection (E-Commerce) (Amendment) Rules, 2026, amending the 2020 Rules framed under the Consumer Protection Act, 2019. They take effect on 1 January 2027. The amendments are broad, touching search, pricing, seller identity, grievances, and data use. The Rules apply broadly to e-commerce entities, covering both marketplace and inventory models, as well as e-commerce retail activities and unfair trade practices across e-commerce models. They also extend to entities established outside India where they systematically offer goods or services to consumers in India
The key changes include ranking, search and sponsored listings, and seller product information, which expand Rules 3, 4 and 5 of the earlier Rules. The definition of “ranking” in Rule 3(1)(j) now covers the prominence given to sellers as well as goods and services irrespective of the technological means used to present or organise them. This brings algorithmic and AI-driven systems within scope. Under amended Rule 5(3)(f), marketplaces must set out the main ranking parameters in descending order of significance, with their relative importance, in plain language. Platforms need not disclose the algorithm itself. This gives sellers and consumers a baseline against which to question how visibility is allocated, but a parameter list is only as informative as it is specific, and it does not by itself stop a platform from weighting its own interests. New Rule 5(6) addresses part of this concern by restricting how marketplaces use the consumer information they collect. It bars use of that information to sell goods, directly or indirectly through any related or unrelated seller, that carry a brand or name common with the marketplace. It also bars using it to promote any seller as associated with the marketplace without the consumer’s express and affirmative consent. The rule regulates the data inputs behind private-label promotion, not the ranking outcomes themselves.
New Rule 4(13) states that the reduced price must be shown alongside the “prior price”, defined as the lowest price of the item during the 30 days before the announcement. This aims to stop discounts being measured against inflated reference prices. Under Rule 4(14), the seller’s name must appear on the invoice in the same font size as the platform’s. Marketplaces are also barred, under new Rule 5(7), from collecting bundled fees for unrelated services, except loyalty and membership programmes. Both provisions address consumer confusion about who they are dealing with and what they are paying for, which matters for post-purchase remedies and for pinning responsibility on the right party.
Particularly, the amendments made with respect to Dark Patterns and Grievance with respect to the National Consumer Helpline bring the E-Commerce trade within mandatory direct statutory regulations. First, in relation to Dark Patterns, new Rule 4(15) requires every e-commerce entity to comply with the Guidelines for Prevention and Regulation of Dark Patterns, 2023. Each must conduct a yearly self-audit and prominently display a compliance certificate. This converts the CCPA’s 2025 advisory, which asked platforms to self-audit, into a binding duty. Two further provisions apply to all e-commerce entities. A new clause in Rule 4(11) prohibits misleading users by manipulating search results or indexes in response to their queries. Further, Rule 4(12) requires sponsored listings to be distinctly identified through clear and prominent disclosures. Together, these separate paid visibility from organic results, but they depend on someone being able to detect a violation in an interface that changes constantly.
The major problem which arises with such self-audits is that there is no audit standard with respect to dark patterns. Neither the 2026 rules nor the 2023 guidelines prescribe any methodology, auditor independence, sampling, or disclosure of findings. Commentaries on the Rules already flag that certificates need consistent standards and regulatory scrutiny to be more than formal compliance. An annual audit also captures a single point in time, whereas interfaces are redesigned and A/B tested continuously, so a certificate may overstate what it can actually assure.
Second, with respect to grievances, Rule 4(2) requires fuller contact and entity disclosures, including grievance officer details. Under Rule 4(5), grievances must be acknowledged within 48 hours and redressed within one month, and the complainant must receive a copy of the complaint as recorded. Participation in the National Consumer Helpline convergence process, previously a best-efforts matter under Rule 4(7), is now mandatory. This is a welcome move since it gives consumers a single, government-monitored channel that tracks complaints against platforms across sellers and sectors, so unresolved grievances become visible to regulators and can be escalated, instead of ending at a platform’s own grievance officer.
Conclusion
Taken together, the amendments move e-commerce regulation from general principles of fairness towards mandatory rules on how platforms are built and operated. These transform voluntary compliance into enforceable duties with identifiable standards. Platforms have until 1 January 2027 to rebuild price-history systems, seller onboarding, disclosures and audit processes. The effect of the Rules will depend on two things: whether the CCPA issues audit standards and guidance, and whether early enforcement shows the new duties will be tested. Without them, the risk is a compliance ritual of certificates and disclosures that leaves platform conduct unchanged.