Back to blog

EU Toy Safety Rules and AI Toys: What Applies, and When

Corrected and updated on 11 September 2026. An earlier version of this article stated that Regulation (EU) 2025/2509 became fully applicable on 1 August 2026. That was wrong. The European Commission confirms the regulation entered into force on 1 January 2026 and applies from 1 August 2030. The article has been rewritten around the correct dates.

Europe rewrote its toy safety rulebook, and connected toys are inside it for the first time. If your child owns or is about to receive a talking teddy bear, a smart speaker or a chatbot toy, the useful question is not what the new regulation says. It is when any of it actually takes effect, because the answer is further away than most coverage suggests.

When do the EU's new toy safety rules actually apply?

They entered into force on 1 January 2026 and apply from 1 August 2030. The European Commission states both dates plainly in its announcement that stronger toy safety rules enter into force, published on 23 December 2025. Entry into force starts the clock for manufacturers and administrations. Application is the date the obligations can be enforced against a product on a shelf.

A handful of administrative provisions, covering notifying bodies and market surveillance cooperation, apply from January 2026. Everything a parent would recognise as a safety requirement waits until 2030. Until then, the previous Toy Safety Directive remains the operative text, alongside the general product safety and radio equipment rules that already applied. The full text is on EUR-Lex as Regulation (EU) 2025/2509 on the safety of toys.

So the honest summary is a four year gap. The rules exist, they are published, and they do not yet constrain anyone selling a toy this Christmas.

What does the regulation change for connected toys?

Three things, once it applies. Internet connected toys acquire explicit cybersecurity obligations, which means a pairing flaw of the kind that got the My Friend Cayla doll banned in 2017 becomes a breach of product law rather than only a privacy scandal. The safety assessment a manufacturer has to run before selling is widened beyond physical and chemical hazards. And the scope covers every toy placed on the EU market for children under fourteen, connected ones included.

The chemical provisions are the part the Commission leads with, and they are genuinely significant: substances are banned as soon as they are identified as hazardous, including PFAS, bisphenols and endocrine disruptors. That has nothing to do with software, but it is worth knowing it is the centre of gravity of this text. The digital elements are an addition to a chemicals reform, not the reason the reform happened.

What is the digital product passport, and what will it do for parents?

It replaces the paper declaration of conformity with a file you can open from your phone. Every toy placed on the EU market will have to carry a data carrier, typically a QR code on the packaging, linking to safety and compliance information in the relevant language. Customs authorities will be able to check the same passport on imports and on toys sold online.

For a parent this is the single most useful change in the regulation, because it converts a marketing claim into a document. Today, when a brand lists certifications, you have to ask it to produce the underlying paperwork and hope it answers. From 2030, you scan the box. The passport has to remain available for ten years.

The catch is the same as above. Any certification claim made between now and 2030 is still a voluntary claim, and the only way to test one is to ask for the evidence in writing. Our piece on our AI toy safety guide sets out what a serious answer to that request looks like.

Does the AI Act cover AI toys in the meantime?

Partly, and the timing there has also moved. The AI Act applies in stages, and the classification of AI embedded in products such as toys as high risk arrives later than the Act's headline dates, which is why a toy on sale today is not automatically subject to a high risk conformity assessment. Treat any claim that a toy is already AI Act certified with the same scepticism you would apply to any other unverifiable label.

What does already apply, fully and today, is the GDPR. It governs every recording of a child's voice, sets who may consent, and gives parents enforceable rights of access and erasure. We have written a full guide to what the GDPR lets a parent demand from a connected toy maker, which is the text to lean on while the toy specific rules phase in.

What should parents check before buying a connected toy today?

Four checks tell you more than any label will for the next four years, because none of them depends on a regulator having got there first.

  • Camera or no camera? A microphone only toy has a much smaller data footprint than one with a camera, and no regulation is needed to verify which you are holding.
  • Subscription or one off purchase? A recurring fee creates a commercial interest in keeping a child engaged for longer.
  • Which certifications are actually listed, by name? Ask for the list, not the word compliant, and ask who issued each one.
  • Can you set topics, tone and limits from a parent app? Verifiable in the app, not promised in marketing copy.

Two related pieces go further on the wider picture: what Oregon and Washington passed on AI toys, and the case researchers make for safety labels on AI toys.

Ted, our interactive plush toy for children aged 3 to 12, was built around those four questions: no camera, a microphone and speaker only, a one off purchase at 129 euros with no subscription, and parent controls for language, topics, limits and tone in the Ted&Co app. Language switching is manual and stays in the parent's app. The certification list, including CE, RED and GDPR and COPPA alignment, is published on our security page, and we would rather you asked us for the evidence than took the list on trust.

Frequently asked questions

When does Regulation (EU) 2025/2509 apply?

It entered into force on 1 January 2026 and applies from 1 August 2030. A small set of administrative provisions on notifying bodies and market surveillance applies from January 2026. Until August 2030, the previous Toy Safety Directive remains the operative text for the safety requirements a parent would recognise.

Does the new regulation ban AI toys?

No. It brings connected toys into scope, adds cybersecurity obligations and requires a digital product passport, but it does not prohibit toys with conversational features. The bulk of the reform concerns hazardous chemicals rather than software.

Can toys sold before 2030 still be sold legally?

Yes. A toy that complies with the rules in force when it is placed on the market can be sold. This is the normal transitional pattern for EU product law, and it is why the application date matters more than the entry into force date.

Which EU rules already protect my child today?

The GDPR, in full. It treats a child's voice as personal data, requires parental consent for children below fifteen in France, and gives parents a right to access and delete what a company holds, with a one month deadline to answer. Product safety and radio equipment rules also already apply.

Does an AI toy need a camera to work?

No. Voice only toys use a microphone and a speaker, which removes images of a child and a home from the data collected entirely. If a product does have a camera, ask what triggers recording, where the images go, how long they are kept, and how to switch it off.

Sources

Dates and legal status verified against the official texts on 11 September 2026.