A kiosk is a computer nobody is allowed to install anything on. That single property changes the shape of the whole problem, because the web accessibility you are used to quietly assumes the person arrives carrying their own software. On your website, a blind customer brings a screen reader. At a ticket machine, they bring nothing, and whatever the machine does not do for them does not happen.
There is a name for it. Closed functionality is the term W3C uses, and it is defined as a property that prevents users from attaching, installing or using assistive technology. Once you have that word, the rest of the subject organizes itself, because every standard in this area is an attempt to answer the same question. What has to be built into the machine, given that nothing can be added to it.
The short version
Closed functionality means no assistive technology can be attached. WCAG covers the web content shown on a kiosk screen and has nothing to say about the machine. Europe answers the machine with EN 301 549 clause 5.1. The US answers it four different ways depending on what the machine is for.
Closed Functionality Is About Assistive Technology, Not About Being Locked Down
The definition is narrower than the everyday sense of the words, and the narrowness is the useful part. A device is not closed because a shop bolted it to a counter or because the operating system is hidden. It is closed for the exact reason that a person cannot bring their own tools to it.
Two consequences follow, and both change how you scope work.
Closed is a property of a function, not of a machine. W3C's own example is an ebook reader that lets assistive technology reach every control in the reading app and not the text of the book itself. Half open, half closed, one device. A better one for most readers is an operating system that will not load assistive technology until somebody has signed in. The login screen is closed functionality and everything after it is not.
A closed machine is expected to carry its own assistive technology instead. That is what the headphone socket on a cash machine is, and it is why the standards keep talking about speech output. The machine has to be the screen reader, because nothing else can be.
WCAG Does Reach Kiosks, in a Narrower Way Than People Assume
People are surprised to learn kiosks appear in WCAG at all, and they do. The abstract says the guidelines address accessibility of web content on any kind of device, and it names desktops, laptops, kiosks and mobile devices in that list.
Read the sentence carefully though, because it is doing less than it looks. It is about the range of devices web content gets displayed on. So a browser-based ordering screen in a fast food restaurant is web content shown on a kiosk, and WCAG applies to it exactly as written, with no translation needed. That is a genuinely useful fact and it covers a lot of modern terminals.
What the sentence does not do is put the machine in scope. WCAG never mentions non-web software at all, and it has no jurisdiction over a keypad, a card reader or a receipt printer. The document that bridges that gap is WCAG2ICT, which works through the criteria one at a time and says how to read each one on something that is not a web page. It is a W3C Group Note dated December 11, 2025, and a Note is not a standard. It carries no requirements and nobody conforms to it.
The 34 Criteria That Break on a Closed Machine
WCAG2ICT keeps a list, in an appendix, of the success criteria that run into trouble on closed functionality. There are 34 of them, and the framing is careful. It does not say those criteria stop applying. It says alternate provisions might be needed to cover the user needs behind them.
The number needs one caveat before you quote it anywhere, because the entries do not all point the same way. Five of the 34 are on the list only to record that the criterion comes out fine. Parsing is there only to note that WCAG 2.2 removed it. Orientation is covered by the essential exception on a fixed screen. And No Keyboard Trap, Character Key Shortcuts and Focus Visible are each listed with the conclusion that they are satisfied, because a machine whose buttons map straight to functions has no concept of focus, so there is nothing to trap and nothing to outline. So 34 is the number flagged for a decision, not the number that fail.
Four of the entries are worth knowing by name.
- 2.1.1 Keyboard. The criterion assumes a keyboard interface that also accepts alternative input devices. Where a machine has no built-in keyboard and supports no keyboard-like alternative, W3C says it may not be possible to satisfy. A keypad that reaches every function might count as a keyboard.
- 1.4.3 Contrast (Minimum). Where the contrast is set by the hardware and the software author cannot change it, meeting the criterion may be impossible. There is also a testing note every auditor of a physical machine needs. A photograph of a hardware display is not sufficient evidence, because lighting, the camera and the screen itself distort what you measure.
- 1.4.10 Reflow. W3C names kiosks in this entry directly. Some closed software has no scrolling, no zoom and no way to change the size of the viewing area, which is most of what the criterion asks for.
- 3.3.8 Accessible Authentication. A machine designed for shared public use can block the things people normally lean on, such as pasting a password from a manager. There is also a carve-out worth knowing, which is that regulated banking or security authentication requirements may be judged to take legal precedence over this criterion.
Europe Answers the Machine With Clause 5.1
EN 301 549 has a whole clause for this, and it is the most complete answer any standards body has published. Clause 5.1 covers closed functionality, and its operative rule is short. Where a function is closed, it has to be operable without the user attaching, connecting or installing assistive technology.
Then comes the sentence that makes the rule workable. Personal headsets and personal induction loops are not classed as assistive technology for this purpose. So the headphone socket is a legitimate answer rather than a dodge, and a machine can meet the rule by speaking to somebody through their own earphones.
Underneath that sits real detail. Where visual information is needed to use a function that is closed to screen readers, the machine has to provide at least one non-visual way to use it. Sixteen further requirements cover how that speech behaves. Volume control, private listening, masked entry spoken rather than beeped, spoken error messages, and what happens to a printed receipt. Separate clauses handle text enlargement, operation without a keyboard, and access without speech for somebody who cannot talk to it.
Two clauses next door land on the same machines. Clause 8 is the hardware standard, carrying reach ranges, tactile keys and force limits, and it names kiosks by name. And a short rule on biometrics says a machine must not rely on one biological characteristic as its only way to identify somebody, which is what makes fingerprint-only entry a failure.
The Accessibility Act Makes a Terminal a Product
The European Accessibility Act regulates self-service terminals as products, which is a different legal category from the services most readers of this site are worrying about. The list is specific. Payment terminals, and then cash machines, ticketing machines, check-in machines and interactive self-service terminals providing information, where those serve something the Act already covers. Terminals built into vehicles, aircraft, ships and rolling stock are carved out.
The date to know is that the Act applies to products placed on the market after June 28, 2025. And then there is the provision almost nobody has read, which is the one that decides whether the machine in your lobby has to change.
Member States may allow a self-service terminal that was lawfully in use before June 28, 2025 to carry on until the end of its economically useful life, capped at 20 years from when it entered use. Three qualifiers keep that fact honest. It is a national choice rather than an automatic European grace period, so the answer depends on your country's transposition. The clock runs from when the machine went into service, not from 2025, so a terminal installed in 2015 has ten years left rather than twenty. And it has to have been in lawful use already.
There is a shorter, broader transitional period alongside it. Service providers may keep using products they were lawfully using before the deadline until June 28, 2030, and service contracts agreed before June 28, 2025 can run to expiry, though no longer than five years from that date.
Norway Sends Machines Somewhere Else Entirely
Norway is worth a paragraph on its own, because one regulation carries three different technical routes and the machine route touches WCAG nowhere.
The Norwegian regulation covers web solutions and machines. Private web solutions go to WCAG. Public web solutions go to EN 301 549. Machines, meaning anything a person operates alone to buy something or get a service done, go to a list of ten card system, ergonomics and walk-up-and-use standards instead. Keypads, tactile identifiers on cards, coding for users with special requirements, ease of operation for walk-up products. WCAG is not among them, and that machine route was re-enacted as recently as 2021, so it is a current choice rather than a leftover.
In the United States, the Kind of Machine Decides the Rule
There is no single American kiosk rule. There are four answers, and which one you get depends on what the machine does and who operates it.
| Machine | What applies | How specific it is |
|---|---|---|
| Cash machines and fare machines | Section 707 of the 2010 ADA Standards for Accessible Design | Very. Speech output, operable parts, reach ranges, all enforceable |
| Other interactive transaction machines | Nothing in Section 707. Its advisory says so outright | None. The general duty still applies, the technical standard does not |
| Automated airport kiosks | 14 CFR 382.57, under the Air Carrier Access Act | Very. A quarter of machines in each location, to a written specification, by December 12, 2022 |
| Health and human service kiosks | 45 CFR 84.83, under Section 504 | A duty not to discriminate, and no technical standard at all |
| State and local government kiosks | General Title II obligations. The 2024 web rule leaves them out on purpose | None. Covered, unspecified |
Two rows deserve unpacking, because they are the extremes.
The airline rule is the most concrete kiosk mandate in US law. Carriers must ensure at least a quarter of the automated kiosks they own, lease or control in each location at a qualifying airport meet a design specification written into the regulation, and that deadline passed in December 2022. There is an anti-gaming clause too. Where the kiosks in a location do more than one thing, the accessible ones have to do everything the inaccessible ones do. And the specification opens with a familiar line, which is that the machine must be operable without the user attaching assistive technology, except for personal headsets and audio loops. Two regulators on two continents reached the same carve-out independently.
The health services rule is the opposite. The regulation says no qualified individual with a disability shall be excluded from a program provided through kiosks, and stops there. The very next section gives web content and mobile apps WCAG 2.1 Level AA with dated deadlines. Same subpart, one paragraph apart, and one of them names a standard while the other names an outcome. If you run clinic check-in machines, you have a real obligation and nothing telling you what compliance looks like, which is a good argument for using EN 301 549 clause 5.1 as your specification whether or not anybody asked you to.
One more thing worth knowing about the Title II web rule. Commenters asked the Department of Justice to extend it to closed systems including kiosks, printers and point of sale devices, and it declined, saying it wanted to give certainty on web content and mobile apps. It also said, in the same passage, that those closed systems may still need to be made accessible under the existing Title II regulation. Left out of the technical standard is not the same as left out. A footnote in that same rule defines closed functionality by pointing at the W3C Note, which is a US regulator borrowing a definition from a document that sets no requirements of its own.
South Korea Wrote a Kiosk Duty Into Its Discrimination Act
Korea went furthest fastest on this, and it did it without writing a kiosk standard. It put the duty straight into its disability discrimination act, where kiosks are called unmanned information terminals. The amendment passed in July 2021 and the duty took effect in January 2023, though nothing actually bit that year, because the enforcement decree that carries the schedule was not made until March 2023.
The schedule then ran by sector and by size. Public bodies, schools, hospitals, transport and financial institutions from January 28, 2024. Welfare and cultural bodies and businesses with 100 or more workers from July 28, 2024. Tourism businesses and businesses under 100 workers from January 28, 2025. Machines already installed before an operator's own date got until January 28, 2026. Our page on the Korean rules carries the rest of that regime.
The most interesting part arrived late, in November 2025, and it is worth copying. Korea carved out premises under 50 square meters, businesses with fewer than ten regular employees, and machines with a screen under 28 centimeters across. What it did not do is exempt them. Those operators have to offer an alternative instead, either a device or software the customer's own assistive technology can work with, or a member of staff and a call bell to summon one. A carve-out that swaps a technical duty for a human one is a rare thing in accessibility law, and it is a far better answer than the exemptions most regulators reach for.
What to Do If You Own One
Four steps, and the first one is the one people skip.
- Work out which parts are actually closed. A modern terminal is often a browser inside a case. If the screen is web content, that part is ordinary WCAG work and your existing team can do it. Only the parts nothing can attach to need the other treatment.
- Use clause 5.1 as your specification even outside Europe. It is the most detailed published answer to the closed functionality problem, it is free to read, and no US rule contradicts it. Where a regulator gives you a duty and no standard, this is the gap to fill it with.
- Ask the manufacturer for a conformance report before you buy. Machines are replaced on ten and twenty year cycles, so the decision you make at procurement is the one you live with. Our page on what a conformance report cannot tell you covers what to ask for alongside it.
- Check the speech mode can be switched on without sight. This is the commonest real failure and it is nearly always found by trying rather than reading. A speech mode you can only enable from a menu you cannot see is not a speech mode.
One honest limit
We audit websites, web applications and documents. We do not test hardware kiosks, and we would rather say so than take the work and improvise. What we can do is test the web content running on a terminal screen, which on a lot of modern machines is most of the interface. If you need the machine itself assessed against clause 5.1 or the hardware clauses, ask us and we will point you at somebody who does it properly.