Age Assurance Is Moving From Policy to Enforcement in Ireland
Ireland's media regulator has launched its first formal investigation under the Online Safety Code, scrutinizing X's age assurance and parental controls.

Article 09 — safegram news
Age Assurance Is Moving From Policy to Enforcement in Ireland
Written by Safegram Editorial Team
Published: 14 September 2026
Age assurance is no longer just a policy debate. Ireland’s media regulator has opened its first formal investigation under the Online Safety Code, while the European Commission is pushing privacy-preserving age verification across the EU. The challenge now is to protect children without turning every user into an identity file.
Key takeaways
- On 8 September 2026, Coimisiún na Meán opened its first formal investigation under Ireland’s Online Safety Code, examining X’s implementation of age assurance and parental controls.
- The regulator says age assurance is required on X to prevent children from seeing pornographic or extreme/gross and gratuitous violent video content.
- The European Commission has urged Member States to make its privacy-preserving EU age-verification solution available by the end of 2026.
- The EU blueprint is designed to let a person prove they meet an age threshold without revealing their exact age, identity or other personal details.
- Enforcement elsewhere is moving in the same direction: the European Commission has issued preliminary DSA findings concerning safeguards for minors on Meta and TikTok and has investigated Snapchat.
- Good age assurance should be proportionate, privacy-preserving and part of a layered safety architecture — not treated as proof that a user will behave safely.
Ireland has entered the enforcement phase
For years, age assurance sat mostly in the realm of policy papers, parental debates and product roadmaps. September 2026 has made the issue much more concrete in Ireland.
On 8 September, Coimisiún na Meán announced the first formal investigation under Ireland’s Online Safety Code. The investigation concerns X and potential ineffective implementation of age-assurance mechanisms. The regulator also raised concerns about parental controls, including whether they are effective, sufficiently visible and brought to users’ attention at sign-up.
This is an investigation, not a finding of wrongdoing. That distinction matters. But the fact that Ireland’s first Online Safety Code investigation focuses on age assurance is itself significant: regulators are increasingly testing whether safeguards work in practice, not merely whether platforms say they have them.

The EU’s emerging model aims to let people prove an age threshold without revealing their exact age or identity.
Why age assurance is different from identity verification
The terms are often blurred together, but they solve different problems.
Identity verification asks, in effect, “Who are you?” Age assurance asks a narrower question: “Are you old enough for this feature, content or interaction?” A well-designed system should collect no more information than is necessary for the risk being addressed.
That is why the EU’s emerging model matters. The European Commission says its age-verification blueprint can allow a person to prove that they are over an age threshold without revealing their exact age, identity or other personal information. The Commission has urged Member States to accelerate rollout and make the solution available by the end of 2026.
Privacy and safety do not have to be opposing goals. In fact, forcing people to expose more identity data than necessary can create a new risk while trying to solve another.
The EU is raising the standard for minors’ accounts
Age assurance is only one layer of a broader European shift.
In April 2026, the European Commission preliminarily found Meta in breach of the Digital Services Act over measures intended to prevent children under 13 from using Instagram and Facebook. The Commission said self-declared birth dates could be falsified without effective controls to verify them.
In July, the Commission issued preliminary findings concerning TikTok, arguing that minors’ account settings did not meet DSA safety standards. Among the concerns was the ability of minors to choose public settings that could expose their content to a global audience and allow content from older minors to be recommended broadly.
Snapchat is also under a formal DSA investigation covering child-safety risks, including age-verification measures and exposure to grooming attempts, criminal recruitment and illegal or age-restricted products.
These cases are at different procedural stages and should not be treated as final judgments where the Commission has described them as preliminary. Together, however, they show the regulatory direction: platforms accessible to children are expected to demonstrate effective protections, not merely publish age limits in their terms.

Effective parental and teen-safety controls need to be understandable, visible and usable at the moment they matter.
Age assurance should not become surveillance
The strongest version of age assurance is not “upload your passport everywhere”.
The design goal should be data minimisation. A service may need to know whether someone is over 13, 16 or 18 without needing their legal name, address or date of birth. Different risks may justify different levels of assurance.
That principle is especially important for social products, where identity, expression, community and privacy intersect. Some adults have legitimate reasons not to publish their real name or face. Teenagers deserve privacy too. Safety architecture should distinguish between what a platform needs to know internally and what other users are entitled to see publicly.
A useful rule is simple: prove the attribute needed for safety, reveal as little else as possible.
What this means for safegram
Safegram’s trust model should be understood in layers rather than as one universal verification switch.
LIVE: Safegram’s current published product information describes identity, seller and business verification through Didit, alongside age estimation used to support age-gating for teen and family-safety features. Safegram also publishes that businesses, creators and sellers must verify before listing, selling, offering services or accepting payments on Safegram Exchange.
LIVE: Circles and Plans provide smaller community and real-world planning contexts with visibility controls. End-to-end encrypted direct messaging and the Family Safety Layer are also described in Safegram’s current public product information.
IMPORTANT LIMIT: Verification is a trust signal, not a guarantee of future behaviour. Age estimation and age assurance can reduce risk but cannot eliminate deception, abuse or harmful conduct. Safegram should continue to describe these systems as safeguards rather than promises of absolute safety.
PLANNED / EVOLVING: As EU age-verification infrastructure matures, Safegram should assess privacy-preserving threshold proofs and interoperability where they improve protection without creating unnecessary identity exposure. No claim is made here that Safegram currently integrates the EU age-verification wallet or blueprint.
That distinction — between what is live and what could sensibly come next — is essential for credibility.

Age assurance is one layer; safer defaults, contact controls, reporting, moderation and digital literacy still matter.
A better model: layered, proportionate safety
Age assurance works best when combined with other controls.
For younger users, that can include restrictive discovery and messaging defaults, age-appropriate privacy settings, limits on adult-to-teen contact, understandable reporting tools, safer recommendation settings and family-support features that do not expose private conversation content.
For commerce, the risk changes. Identity or business verification becomes more important because money, services and contractual expectations are involved. A platform can therefore ask more of a seller than of someone who simply wants to read or participate in a community.
For adult-only material, stronger age thresholds may be justified. The key is proportionality: the assurance level should reflect the harm being prevented.
What parents should look for
Parents do not need to become identity-technology specialists. They can ask straightforward questions about the services their children use.
Does the platform rely only on a date of birth typed by the user? What happens if the system believes someone is underage? Are teen accounts private by default? Can unknown adults discover or message younger users? Are parental controls easy to find? Does the platform explain what information an age check uses and what it retains?
The answer should not be hidden in a forty-page policy.
Good safety design makes the important controls understandable at the moment they matter.
What platforms should learn from ireland’s first investigation
The lesson is not that one particular age technology has won. It is that implementation now matters.
A policy saying “13+” or “18+” is not, by itself, an age-assurance system. A parental control that users cannot find is not necessarily an effective control. A verification process that collects excessive personal information can undermine privacy even if its safety objective is legitimate.
The emerging standard is more demanding: identify the risk, choose a proportionate safeguard, minimise data, make controls usable, test whether they work and be prepared to demonstrate that effectiveness to regulators.
That is a healthier direction for the internet.
The goal should not be to know everything about every user. It should be to know enough, at the right moment, to make predictable harms harder — while preserving as much privacy and freedom as possible.
Frequently asked questions
What happened in Ireland on 8 September 2026?
Coimisiún na Meán opened its first formal investigation under Ireland’s Online Safety Code. It is examining X’s implementation of age assurance and parental controls. An investigation is not a final finding of breach.
What is age assurance?
Age assurance is the broader set of methods used to establish or estimate whether a person falls within an age range or meets an age threshold. It can include self-declaration, age estimation and stronger age-verification methods depending on risk.
Is age assurance the same as identity verification?
No. Identity verification establishes who a person is. Age assurance may only need to establish that a person is above or below a threshold. Privacy-preserving systems can separate those questions.
What is the EU age-verification solution?
The European Commission has developed a blueprint intended to let users prove they meet an age threshold without disclosing their exact age, identity or other personal information. The Commission has urged Member States to make the solution available by the end of 2026.
Why are regulators focusing on minors now?
The Digital Services Act and national online-safety frameworks place significant obligations on platforms accessible to minors. Recent European enforcement actions and investigations have focused on whether age restrictions, account defaults and child-safety systems work effectively.
Does Safegram verify every ordinary user?
Safegram’s published model distinguishes ordinary participation from higher-risk activity. Its current verification information says businesses, creators and sellers must verify before transacting, while age estimation supports teen and family-safety gating. Verification should be described as a risk-reduction signal, not a guarantee.
Does Safegram use the EU age-verification app today?
This article makes no such claim. EU interoperability and privacy-preserving threshold proofs are described as an area Safegram should assess as the European infrastructure matures.
Can age assurance make a platform completely safe?
No. It can reduce specific risks, but safety also depends on privacy defaults, contact controls, moderation, reporting, recommendation design, family support, commerce safeguards and user education.
Branding rule
Use only the exact official transparent Safegram logo asset stored in the Safegram News root when branding genuinely helps. Do not recreate, redraw, approximate or place a substitute Safegram logo in any editorial image.
Sources
- https://www.cnam.ie/investigation-commenced-into-x-under-online-safety-code/
- https://digital-strategy.ec.europa.eu/en/news/commission-urges-member-states-rollout-eu-age-verification-app
- https://digital-strategy.ec.europa.eu/en/news/commission-preliminarily-finds-meta-breach-digital-services-act-failing-prevent-minors-under-13
- https://digital-strategy.ec.europa.eu/en/news/commission-preliminary-finds-tiktok-breach-digital-services-act-failing-ensure-safe-accounts-minors
- https://digital-strategy.ec.europa.eu/en/news/commission-investigates-snapchats-compliance-child-protection-rules-under-digital-services-act
- https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-protection-minors
- https://safegram.com/
- https://safegram.com/verification-partner
More from Safegram
Try Safegram
Privacy-first social and a verified marketplace, built in Dublin.