Back to blog

Europe Just Changed Its AI Rules. What It Means for the Toy in Your Child's Bedroom

If you bought a talking toy this year, or are thinking about it, you have probably read a headline about Europe regulating artificial intelligence and assumed the matter was settled. It is not settled, and the reason is a set of dates that almost nobody outside compliance departments has looked at properly.

Two things happened in the space of eight months. On 12 December 2025 the European Union published a brand new Toy Safety Regulation, replacing a directive that had governed the shelves since 2009. Then on 2 August 2026, enforcement of the EU Artificial Intelligence Act began for a first set of obligations. Between those two texts, a connected toy sold in Europe is now covered by more law than at any point in the category's short history. What follows is what is actually in force today, what is still years away, and the handful of things a parent can verify without waiting for a regulator.

Europe's rulebook for connected toys, date by dateWhat is already enforceable, and what is still years away12 Dec 2025Toy Safety Regulation 2025/2509 published in the OfficialJournal2 Aug 2026AI Act enforcement begins: transparency duties, bannedpractices, general-purpose AI rulesIN FORCE2 Dec 2026Deadline for AI systems already on sale to meetcontent-marking duties2 Dec 2027Rules for stand-alone high-risk AI systems (Annex III) apply2 Aug 2028Rules for high-risk AI built into regulated products,including toys, apply1 Aug 2030Old Toy Safety Directive repealed: only Regulation 2025/2509appliesSource: EU AI Act Service Desk, Regulation (EU) 2025/2509, European Commission
Two European texts, one calendar. The column that matters to a parent buying a toy in 2026 is the left one, and it is the shortest.

What actually changed on 2 August 2026?

Enforcement powers arrived, not new rules for toys. From that date the AI Office and national authorities can enforce three things: the ban on prohibited AI practices, the transparency requirements for certain AI systems, and the rules for general-purpose AI models. The European Commission's own AI Act Service Desk spells out the sequence.

The transparency obligations matter most for anyone selling a voice product. In plain terms, a person interacting with an AI system has to be able to know they are interacting with one, and synthetic content has to be marked as machine generated. Systems already on the market before 2 August 2026 have until 2 December 2026 to comply with the marking and detection duties under Article 50(2). Two prohibitions with nothing to do with toys, covering non-consensual intimate imagery and child sexual abuse material, also start applying on 2 December 2026.

What did not happen on 2 August 2026 is the part parents assume happened. There is still no European rule saying a conversational toy must be tested for how it talks to a five-year-old.

Is a teddy bear in a child's bedroom a high-risk AI system?

Under the AI Act, a toy with an AI safety component sits in the high-risk category, and those rules do not apply yet. High-risk AI embedded into already-regulated products, the family that includes toys, applies from 2 August 2028. Stand-alone high-risk systems listed in Annex III come earlier, on 2 December 2027.

That gap of two years is deliberate rather than accidental. The Commission's enforcement framework staggers obligations so that harmonised standards and notified bodies exist before manufacturers are judged against them. The practical consequence for a family shopping in 2026 is simple and worth saying out loud: the toy on the shelf has been assessed for choking hazards and chemical migration, and not for what it will say at bedtime.

What does the new Toy Safety Regulation add?

Regulation (EU) 2025/2509 is the first European toy law to name mental health and artificial intelligence in the same breath as small parts and flammability. Manufacturers must carry out a safety assessment that addresses the health risks of digitally connected toys, and that assessment has to take mental health into account. Toys using AI must also comply with the AI Act, including its cybersecurity, data protection and privacy requirements.

The rest of the text is a serious tightening of the chemical rules. Intentionally added PFAS are banned. Ten bisphenols are banned. Endocrine disruptors, respiratory sensitisers and category 1A skin sensitisers join the existing prohibitions. Restrictions that previously applied only to toys for children under three, covering substances such as formaldehyde, phenol and flame retardants, now apply to toys for every age, as SGS set out in its analysis of the published text. Allergenic fragrances drop from a 100 mg/kg tolerance to 10 mg/kg.

The catch is the calendar. The old Directive 2009/48/EC is repealed on 1 August 2030. Until then, most of what you are buying is certified against the old framework. A brand can comply early, and some will, but nothing forces the issue for another four years.

What is a Digital Product Passport, and when will parents see one?

A Digital Product Passport is a QR code on the toy or its packaging that opens the product's full compliance file. It replaces the paper declaration of conformity, must be readable in the relevant EU languages, and stays available for ten years. Eurofins summarises the requirement as one passport per toy model, uploaded to an EU digital registry that does not exist yet.

There is one detail in the regulation with real teeth. Customs authorities may release a toy into the European market only after checking that the data carrier and the commodity code match the registry entry. That turns a compliance document into a border control, which is a meaningfully different level of pressure from a PDF filed in a drawer.

In one line: the strongest European rules on connected toys are real, signed and dated, and most of them start applying somewhere between 2028 and 2030.

Who actually enforces all of this?

Three different sets of authorities, which is precisely the problem. Market surveillance bodies police toy safety. Data protection authorities police the GDPR. New AI Act authorities police the AI Act. Legal scholars writing in MediaLaws describe the Toy Safety Regulation as a gateway into the AI Act, the Cyber Resilience Act and the GDPR, with overlapping but uncoordinated mandates.

Add the General Product Safety Regulation, in force since December 2024, which brings obligations for online marketplaces, accident reporting and consumer remedies, and you have four regimes touching the same plush toy. The law firm Mayer Brown noted in its client briefing that moving from a directive to a regulation at least removes the national transposition differences that used to fragment the single market. That helps. It does not tell a parent in Lyon which office to call when a toy says something it should not have said.

Does any of this mean AI toys are now safe?

No, and the honest reading of the evidence points the other way. In December 2025 the U.S. PIRG Education Fund published testing of several conversational toys in which products gave children genuinely unsafe answers, including where to find matches and knives in a house. Those toys were on sale and legally compliant with the toy rules that existed at the time. Compliance and safety are not the same word.

We make one of these products, so treat what follows accordingly. The failures documented in that report were design decisions rather than mysteries: an unfiltered general model, no age adaptation, no topic boundaries a parent could set. Those choices are avoidable today, without any regulator forcing the issue. The bill now moving through the US Senate and the UNICEF comparison of national approaches are both attempts to make them unavoidable, and both are still proposals.

What can a parent check today, without waiting for 2030?

Ask for four things in writing, from any brand, before you pay. None of them requires a regulator, and a brand that cannot answer quickly has told you something.

What to ask What applies today What arrives later
Is there a camera? Nothing in EU law bans one in a toy Connected-toy safety assessment, 2030
Are conversations stored, and for how long? GDPR, enforceable now AI Act data governance duties, 2028
Is the child told they are talking to a machine? AI Act transparency, enforceable since 2 August 2026 Marking deadline for older products, 2 December 2026
Can a parent restrict topics and hours? No legal requirement anywhere Still no legal requirement
Which certifications are listed? CE, EN71, RED under the 2009 directive Regulation 2025/2509 and Digital Product Passport, 2030

Compiled from the AI Act implementation timeline and Regulation (EU) 2025/2509, August 2026. Dates are those published by the European Commission and may be amended.

The fourth row is the uncomfortable one. Parental control over topics, hours and tone is the single feature that most reliably separates a designed toy from a chatbot in a costume, and no European rule requires it in 2026 or in 2030. It exists only where a manufacturer chose to build it. In our case it sits in the Ted&Co parent app, which is also required for setup, and the full list of certifications behind Ted is on our security page so you can check it against the questions above rather than against our marketing.

Frequently asked questions

Are AI toys legal in Europe right now?

Yes. Connected and conversational toys are legal in the European Union, provided they meet existing toy safety requirements such as CE marking and the GDPR. No European rule currently bans them or requires a specific assessment of what they say to children.

When does the EU AI Act apply to toys?

The rules for high-risk AI embedded in regulated products, which is the category covering toys, apply from 2 August 2028. Transparency obligations, meaning a user must be able to know they are dealing with an AI system, have been enforceable since 2 August 2026.

What is changing for toys in 2030?

On 1 August 2030 the 2009 Toy Safety Directive is repealed and Regulation (EU) 2025/2509 applies alone. From that point every toy sold in the EU needs a Digital Product Passport accessible by QR code, and connected toys need a safety assessment that includes mental health risks.

Does the new regulation ban cameras or microphones in toys?

No. The regulation requires manufacturers to assess the risks of digitally connected toys, including risks to mental health, but it does not prohibit specific hardware. Whether a toy has a camera remains a design choice by the maker, which is why it is worth asking directly.

How can I check whether a toy is properly certified?

Today, look for CE marking and ask the seller which EN 71 parts and radio equipment standards the product was tested against. From 2030, a QR code on the packaging will open the Digital Product Passport with that information verified against an EU registry.

Sources