- What is the new EU Toy Safety Regulation?
Toys and games are vital tools for child development. In the EU, there are about 2000 companies in the toys and games sector. Besides the manufacturers’ safety responsibilities, importers, notified bodies and national authorities all have a role in ensuring toys sold in Europe fulfil safety requirements, ensuring children have the highest level of protection. But what happens when toys talk back, not through the traditional methods of recorded words and songs, but through actual conversation through AI embedded in the toy? What about toys that have answers to children’s questions and even suggestions, just like a ‘friend’?
The new EU Toy Safety Regulation 2025/2509 (TSR) entered into force on 1 January 2026. The aim of the regulation is the protection of children from hazardous toys, ensuring a higher level of safety for toys, and introducing stricter requirements for manufacturers, importers, and distributors. This regulation replaces the Toy Safety Directive 2009/48/EC. The shift from directive to regulation represents a significant move towards ensuring uniformity across member states. A regulation, differently from a directive, makes the rules directly applicable and enforceable across all EU member states without requiring national legislation. The new regulation introduces enhanced obligations and accountability measures, clarifying responsibilities for manufacturers, importers, and distributors.
One of the novelties of the regulation is the introduction of the Digital Product Passport (DPP), which will replace the EU declaration of conformity and will be mandatory for all toys sold in the EU. Each toy model must have a DPP confirming compliance with the TSR regarding safety requirements. The DPP must be accessible via a data carrier (e.g. QR code) in the relevant EU language, and available for 10 years. The data carrier must be physically present on the toy, its label, packaging, or accompanying documentation to ensure visibility before purchase.
Another novelty is the inclusion of digitally connected toys within the scope of the regulation. A new set of requirements for safety assessments that address health risks, including mental health risks, posed by digitally connected toys is introduced. However, the regulation does not introduce any new rules related to AI in toys. It cross-references the AI Act. The new rules will start applying on 1 August 2030.
- The TSR applies only when the AI is incorporated into a physical toy
Article 2 of the TSR defines toys as “products that are designed or intended, whether or not exclusively, for use in play by children under 14 years of age”, keeping the same broad definition as the Directive. But, it adds to the definition the clarification of what “intended for use in play” means:
“a product shall be considered to be intended for use in play by children under 14 years of age where a parent or supervisor can reasonably assume, by virtue of the functions, dimensions and characteristics of that product, that it is intended for use in play by children of a relevant age group”.
The Commission is granted the power to determine which products fall within the above definition through implementing acts, thereby allowing the possibility of new products to be later included in the list of toys under the TSR, an approach that makes the regulation future-proof.
The TSR mentions ‘toys with digital elements’ and ‘toys which include AI’ for the first time. While the definition of toys does not directly mention anything regarding the tangibility of the toys, a closer look at the compliance machinery of the regulation shows that it is intended towards physical products: CE marking on the toy, a Digital Product Passport accessible via a data carrier physically present on the toy or its packaging, serial numbers, and so on. Additionally, Annex I TSR lists products that are not considered toys under this regulation. Interactive software, intended for leisure and entertainment, such as computer games, and their storage media, are left out of the scope of the TSR. The framing in recitals 14 and 15: “toys with AI systems”, “toys with digital elements”, “AI as safety component”, all assume a physical host. So, a teddy bear with an integrated AI system falls within the scope of the TSR, but a standalone children’s AI chatbot does not.
The new Product Liability Directive has changed the traditional conception of products as only tangible, movable items, officially classifying software and AI systems as products, regardless of whether they are sold physically or digitally. However, the TSR does not make any reference to this directive in its text. It will remain to be seen whether the Commission will use its implement-act powers to determine whether borderline products fall within scope. Such powers will start applying from June 2027.
- The gateway architecture of the TSR
Even for the teddy bear, the TSR largely leaves the AI, privacy and cybersecurity substance to other instruments rather than regulating it itself. Instead of setting its own requirements on those hazards, it routes them to the AI Act, the Cyber Resilience Act for digital elements, the Radio Equipment Directive 2014/53/EU for privacy in radio toys, and the GDPR. Hence, protections remain dispersed across overlapping instruments.
The TSR’s distinctive contribution is narrower than it first appears: bringing those toys within the safety-assessment and conformity regime, and potentially also adding the mental-health assessment duty. The data protection and AI conduct rules are to be found elsewhere. Recital 15 refers to the AI Act in classifying toys with AI systems as safety components that require a third-party conformity assessment as high-risk AI systems. Similarly, it refers to the Cyber Resilience Act for internet-connected toys that have social interactive features, such as speaking or filming, or that have location-tracking features.
So, while the regulation modernises toy safety for a connected world, it draws its scope around the physical object — leaving the fastest-growing form of children’s AI interaction, pure software companions, to a patchwork of other regimes. The TSR therefore functions as a gateway to the AI Act, the Cyber Resilience Act, and the GDPR, layering CE-marking conformity assessment, the mental health assessment, and the DPP on top of AI Act conformity assessment and a DPIA, adding to the fragmented, hard-to-enforce patchwork. This leads to enforcement fragmentation, with market-surveillance authorities, data protection authorities, and AI Act authorities having overlapping but uncoordinated mandates.
- Children’s data protection and best interests in a conversational device
Diving more deeply into the talking teddy bear example: a conversational toy listens continuously, captures a child’s voice and behaviour, and infers emotions and preferences, to personalise its replies. This kind of profiling is not welcome under the GDPR. Article 8 sets the age of consent for personal data processing to 16, with member states being able to lower that age up to 13. Below this threshold, consent should be given by the parent.
The profiling that conversational toys like the teddy bear perform might be considered as indirectly commercial, providing continuous personalised answers, without leading to an automated decision; hence, it might not trigger Article 22 GDPR, while still shaping a child’s experience in ways that might be worrying. Although this form of profiling might not be aimed at commercially influencing the child as a consumer and may even aim to contribute to their development, wellbeing or health, that does not necessarily mean such profiling only has a positive impact on the child’s right to development under Article 6 UNCRC. These toys can undermine healthy development, blur boundaries between real relationships and algorithmic responses, and cause emotional attachment. Recital 16 of the TSR requires connected and AI toys to be assessed with regard to mental health, but with no defined methodology. The regulation does invoke the concept of by design:
“Manufacturers should ensure that the toys they make available on the market meet the highest standards of safety, security and privacy by design, in the best interests of children”, but only in the recitals, not as an enforceable design obligation in the articles.
- Conclusive thoughts
The TSR deserves credit for finally naming connected and AI-enabled toys as objects of safety concern, dragging a 2009-era framework into an age of toys that listen, remember, and talk back. Yet the analysis above reveals a persistent gap between the regulation’s ambition and its binding text: the concepts that matter most for children’s data protection and safety, such as ‘digitally connected toys’, ‘toys with AI’, mental health, and “safety by design” are mentioned only in the recitals of the TSR. They are barely mentioned in the articles and are not classified into a distinct category. The only time the ‘digital’ is mentioned in articles is in Article 12(2) referring to modification of toys by “physical or digital means”. The binding text does not define these concepts, does not impose a single AI-specific safety requirement, and expressly routes the substance to the AI Act, Cyber Resilience Act, GDPR and other EU Law. So, the digital dimension of the toys can be found only in the recitals and cross-references. The TSR scope, centred on the physical object, lets the fastest-growing form of children’s AI interaction, the standalone software companion, slip outside its reach altogether. The recital-versus-article asymmetry that recurs throughout the instrument seems to be a structural choice to prefer aspiration over obligation precisely where the vulnerabilities are newest and least understood.