EU Proposes New Kids’ Tech Rules, Plus 4 Stories
Two days ago, I left the EU child-safety story out of the Daily Brief because what we had was a leaked draft. Today the European Commission published the actual proposal.
That changes the story.
The EU KIDS Act would change much more than minimum ages
The European Commission formally adopted its proposed EU KIDS Act Thursday, and the age rules are the part that will get most of the headlines. Children under 13 would not be allowed to have social-media accounts. Thirteen- and 14-year-olds could use limited accounts created and supervised by a parent or guardian. At 15, teenagers could open their own accounts.
But calling this a social-media age-limit bill undersells it. The proposal also puts safety-by-design requirements on social networks, video platforms, online games, app stores, AI chatbots and AI companions used by children. For the 13-to-14 group, parental controls would stay on, contacts would require approval and daily use could be capped at no more than an hour. Services would have to remove or disable things such as addictive engagement tricks, unwanted contact from strangers and spending traps for minors.
The more interesting change, I think, is who has to prove what. Instead of expecting a parent to discover every dangerous setting and shut it off, the provider would have to show that its service is age-appropriate and safe by design. Very large platforms would have to submit compliance plans and pay for independent audits before putting children into the new regime. AI companions and chatbots would face their own pre-market compliance and ongoing risk-monitoring requirements.
Then there is age verification, because there is always an awkward second half to this conversation. The Commission says platforms would not receive a person’s ID or identity. Certified age-verification systems, including an EU app, would answer the narrower question of whether somebody is above or below the required age using privacy-preserving technology. That’s a much better design than handing a passport to every social network on Earth. It also deserves scrutiny in the real implementation, because age gates can protect children and become identity infrastructure at the same time.
The proposal still has to be negotiated with EU member states and the European Parliament. It is not law today, and nobody needs to delete an account this morning. But the direction is hard to miss. California enacted a broad package of child-tech rules last week, Australia is working on its own approach, and now the EU is proposing rules that reach beyond social media into games and AI.
The rules around technology matter too
Platforms, privacy, speech, competition, surveillance, copyright, and regulation increasingly determine what technology companies can build and what the rest of us have to live with. Browse more Raymond Tec News for practical coverage of technology policy and digital rights.
Cisco says an ISE zero-day is already being exploited
Cisco disclosed CVE-2026-76460 Wednesday afternoon, gave it a perfect 10.0 CVSS score and says attackers are already exploiting it.
The affected product is Cisco Identity Services Engine, or ISE, including ISE-PIC. ISE is part of the machinery organizations use to decide who and what is allowed onto a network. So an authentication-bypass vulnerability in the system responsible for network access is, technically speaking, a lousy place to have an authentication-bypass vulnerability.
An unauthenticated remote attacker can send a crafted request to an affected API endpoint and bypass the web management interface’s authentication. Cisco says successful exploitation can ultimately give the attacker command execution as root. The flaw affects vulnerable ISE deployments regardless of configuration, and Cisco says there is no workaround that actually fixes it.
The first fixed releases are ISE 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4. Version 3.0 has already reached the end of software maintenance.
And this is not a patch-it-and-go-home problem. Cisco says administrators should review access logs on every node for suspicious usernames, but it also warns that an attacker with root access can remove or hide evidence. Cisco recommends checking firewall and network logs outside the ISE appliance as well. If malicious activity is suspected, its guidance is to re-image affected nodes and restore configuration as needed.
That distinction matters. Installing the update closes the vulnerability going forward. It does not establish that nobody used it yesterday.
Technical discovery & auditing
The public page doesn’t tell you much about the machinery behind it. Raymond Tec audits inherited and long-running projects to uncover the plugins, integrations, data, dependencies, and old decisions that determine what the next change will really involve.
Google keeps its ad-tech business, but the walls have to open
A federal judge has now unsealed the remedy in the Justice Department’s ad-tech antitrust case against Google. Google does not have to sell its AdX advertising exchange, which is the breakup the government wanted. It does, however, have to make some fairly substantial changes to how its advertising machinery works with competitors.
Google must build and support integrations between AdX, its DFP publisher ad server, the open-source Prebid system and competing publisher ad servers. AdX will have to submit real-time bids into other ad servers. Publishers will be able to access and export their own data from Google’s DFP and AdX products, making it easier to move to another provider. Google’s AdWords system also cannot preferentially bid into Google-owned ad-tech tools simply because Google owns both sides of the transaction.
There will also be an antitrust compliance monitor and technical committee watching this for six years.
If you run a local business and spend a few hundred dollars a month on Google Ads, there is no new button for you to click today. The more immediate effect is on publishers and the companies building the machinery behind online advertising. But that machinery ultimately determines how much competition exists between the businesses selling ad space, the companies buying it and the middlemen taking a cut from both sides.
Google says it plans to appeal the underlying liability ruling. So this isn’t the last chapter. Still, “Google keeps the business but has to let competitors into more of the plumbing” is a much more accurate description than either “Google won” or “Google’s ad monopoly was broken up.”
Pixel owners have a targeted zero-day to patch
Google’s September Pixel update fixes CVE-2026-58704, a high-severity privilege-escalation flaw in the phone’s cellular modem. Google says there are indications the vulnerability may be under limited, targeted exploitation.
Limited and targeted are useful words here. Google is not saying every Pixel owner is under attack, and this is not evidence of some mass compromise of Android phones. It is, however, a real exploited vulnerability with a fix available.
The flaw can allow an attacker with access through an adjacent network and basic privileges on the device to escalate those privileges without requiring the victim to tap a link or open a file. Google says supported Pixels should be on the September 5, 2026 security patch level or later.
On a Pixel, go to Settings, Security & privacy, System & updates, then Security update. Install the update and restart the phone. This is one of the rare security stories where the practical advice really can fit in one sentence.
Technology is rarely just about the technology
Some of the most important technology stories aren’t product launches at all. They’re about health, privacy, education, law, accessibility, work, and what happens when technology reaches ordinary people. Browse more Raymond Tec News for the stories worth understanding without the hype.
Windows Server 2022 is leaving mainstream support, not security support
Finally, a lifecycle reminder before somebody turns this into a “Windows Server 2022 dies next month” headline.
Microsoft says Windows Server 2022 reaches the end of mainstream support on October 13. The October security update will be its last update while in the mainstream-support phase.
It then moves into extended support. Microsoft says monthly security updates continue at no additional cost through October 14, 2031.
That doesn’t mean businesses should ignore the date. Mainstream support ending is a good reason to review server roles, application compatibility, hardware age and the eventual migration path. If you’re still deploying brand-new Server 2022 systems without thinking about the next five years, this is also a useful calendar reminder.
But there is no security cliff on October 14. A properly updated Server 2022 installation does not suddenly become abandoned software because Microsoft changed the label on the support phase.
Planning is warranted. Panic purchasing is not.
Still in a reading mood? The Raymond Tec News archive covers security, AI, small-business technology, policy, and the places technology collides with ordinary life — without requiring a computer-science degree to get through it.
Sources / Further Reading
- European Commission — EU KIDS Act press release
- European Commission — The KIDS Act explained
- Reuters — EU Commission proposes under-13s social media ban
- Cisco — CVE-2026-76460 advisory
- U.S. Department of Justice — Google ad-tech remedies
- Reuters — Google ad-tech remedy decision
- Google — Pixel Update Bulletin, September 2026
- Microsoft — Windows Server 2022 support notice
