A Third Strike, a First for Foreign Operators
On July 29, 2026, Italy's communications regulator AGCOM published Delibera n. 171/26/CONS, adopted at its July 7 Council session, ordering Italian internet service providers to block DNS access to Escort Advisor. The site is operated by DonTouch SA, a company registered in Switzerland — outside the EU. AGCOM found DonTouch had ignored a formal notice to implement age verification and gave ISPs two days to disable access.
This is AGCOM's third blocking order under Article 13-bis of the Caivano Decree (Decree-Law 123/2023, converted into Law 159/2023), and the first against an operator based outside the European Union. The first two, issued after AGCOM's March 26, 2026 session, hit giochipremium.com and hentai-ita.net, both run by the Italy-based Onlab. Escort Advisor is a meaningfully harder case: a non-EU company, publishing content AGCOM classifies as pornographic behind an escort-listings format, now subject to an Italian regulator's extraterritorial assertion of authority.
The Legitimate Case for the Rule
The Caivano Decree exists because of a real and specific harm: it followed a highly publicized 2023 gang-rape case involving minors in Caivano, near Naples, that galvanized Italian lawmakers around child-safety gaps online. AGCOM's technical standard for compliance, Delibera n. 96/25/CONS (approved April 2025), is more thoughtfully built than the blunt instruments some jurisdictions have reached for. It requires a "double-anonymity" model — one party verifies age, a separate party delivers content, and neither learns the other's identity — explicitly designed to minimize the personal data collected in the process. AGCOM was not the first regulator to demand age gates; it was one of the more careful ones about not turning age verification into a data-harvesting exercise. That distinction matters, and critics of age-verification mandates should credit it rather than treat every version of the policy as equivalent to document-upload schemes that create honeypots of sensitive data.
Where Enforcement Breaks Down
The mechanics of this specific case show the limits of the model AGCOM is using to enforce it. According to reporting from sbircialanotizia.it, DonTouch redirected its blocked .com domain to escort-advisor.net on July 30 — one day after the block order was published — and as of July 31 AGCOM's order had not been extended to the new domain. DNS blocking targets a hostname, not a service; a company willing to re-register can often stay a step ahead of the specific order in hand. Italy has run this experiment before, against piracy sites, for over a decade, with the same whack-a-mole result: blocking suppresses casual traffic but rarely stops a determined operator, while it does impose a permanent compliance burden on every Italian ISP that must maintain and update blocklists indefinitely.
DonTouch's public defense adds a second layer of friction. The company argued it had already reorganized — moving pornographic images and video into a gated "Premium" area — and separately invoked the EU's Digital Services Act's hosting-provider liability protections, plus the legality of its operations under Swiss law, according to the same reporting. AGCOM rejected both arguments, holding that Article 13-bis applies based on whether content is made accessible to users in Italy, regardless of where the operator is incorporated or hosted. That is a defensible reading of the statute, but it is also a preview of a coordination problem the DSA was partly built to avoid: when a national child-safety rule and the EU's harmonized intermediary-liability framework brush up against each other, and a non-EU company can plausibly claim DSA-adjacent protections while a national regulator asserts territorial reach anyway, the result is legal uncertainty for every foreign platform serving Italian users, not just marginal ones like Escort Advisor.
The Proportionate Path Forward
None of this argues against age verification as a policy — protecting minors from pornographic content is a legitimate state interest, and AGCOM's privacy-preserving technical standard is a genuine improvement over cruder alternatives. But a rule is only as credible as its enforcement, and an order that a target can route around within 24 hours by re-registering a domain is not proportionate to the compliance burden it places on ISPs or the precedent it sets for extraterritorial jurisdiction claims. AGCOM should close the domain-hopping gap with a standing successor-domain mechanism, similar to what some EU member states use for gambling-site blocks, rather than issuing a fresh delibera for every new hostname a non-compliant operator registers. And as AGCOM extends this regime to more non-EU operators, it should coordinate explicitly with the European Commission on how national Caivano-style rules interact with DSA hosting-liability protections — before a patchwork of national assertions, rather than the DSA's intended harmonization, becomes the default operating environment for platforms serving European users.