AGCOM, Italy's communications regulator, ordered internet service providers to DNS-block Escort Advisor on July 7, 2026, giving ISPs two days to disable access for Italian users. The site is operated by DonTouch SA, a Switzerland-based company outside the EU's jurisdiction, which the regulator says failed to deploy an age-verification system after a formal warning. AGCOM's own press release counts this as the third enforcement action under Article 13-bis of the Caivano Decree — the September 2023 law, converted into Law 159/2023 after last year's youth-violence scandal in the Naples suburb that gave the decree its name.
What the Law Actually Requires
Article 13-bis bars minors from pornographic content and orders operators — Italian or foreign — to verify users' age before granting access. AGCOM spent 2025 building the technical machinery: Deliberation 96/25/CONS, published October 31, 2025, set out a "double anonymity" model in which a certified third-party verifier confirms a user is over 18 without learning which site they're visiting, while the site itself never learns the user's identity. The obligation took effect November 12, 2025 for Italian and non-EU operators, and February 1, 2026 for EU-based ones. Non-compliant operators get a 20-day warning; after that, AGCOM can order "every useful measure for blocking the site" until compliance is restored.
The enforcement record so far is short but instructive. AGCOM's first action, adopted March 18, 2026, blocked two Italian-registered sites — giochipremium.com and hentai-ita.net, both run by Onlab S.R.L.S. — after routine monitoring caught them ignoring the deadline. Escort Advisor is the first target based entirely outside the EU, and notably the company disputed the characterization: it told Italian press it had already "completely reorganized" the platform, walling off explicit content behind a restricted adult section while preserving its core function as an escort-review and listings service. AGCOM blocked it anyway.
The Case For the Law
The strongest version of AGCOM's position is straightforward: a 2023 law passed with near-unanimous political support after a real child-safety scandal, built genuine technical safeguards against the obvious privacy failure mode of naive age verification, and is now enforcing it evenhandedly against Italian and foreign operators alike. The double-anonymity design is a meaningfully better answer to the "who's watching the verifier" problem than the crude government-ID uploads some other jurisdictions have tried. And DNS blocking is, in a narrow sense, the only enforcement lever Italy has against a Swiss company with no assets or presence to fine — a point AGCOM can fairly make in its own defense.
Where This Gets Harder to Defend
But DNS blocking is also a crude instrument, and the record so far illustrates why. It is trivially circumvented — Italian regulators themselves acknowledge that using a VPN to route around the block isn't prohibited, only advertising VPNs as a workaround is. That means the practical effect of a block falls almost entirely on casual users while doing little to the technically motivated ones, including, awkwardly, motivated minors. It's also blunt in scope: Escort Advisor's dispute over how much of its site actually needed gating is a real question that a blocking order, unlike a graduated fine, has no room to weigh — it's binary, whole-domain, and immediate.
The EFF's recent critique of age-verification technology generally is worth taking seriously here, even for a system as carefully designed as AGCOM's: any age-assurance layer, however anonymized, adds friction, a point of failure, and a new category of infrastructure that could be repurposed for broader access control later. Italy's model minimizes the privacy exposure better than most, but it doesn't eliminate the structural risk that a blocking power built for pornography sites migrates to a wider set of "harmful content" categories once the DNS-blocking muscle exists.
The DSA Backdrop
It's worth being precise about what this is and isn't. This is a national Italian enforcement action under domestic law, not a DSA case. The EU's parallel track — the European Commission's Article 28 DSA guidelines on protecting minors, published July 14, 2025 — is explicitly non-binding, a "reference point" for regulators rather than an enforceable standard, and it applies only to platforms, not to the narrower category of dedicated pornography sites the Caivano Decree targets. Italy is not waiting for Brussels to harmonize an approach; it built its own regime, and other member states with weaker technical capacity may simply copy the blocking playbook without the double-anonymity safeguards that make AGCOM's version defensible. That's the real risk of this precedent: not that Italy got the balance badly wrong, but that cruder imitators elsewhere will.
AGCOM should keep publishing its enforcement rationale as transparently as it did with Escort Advisor's press dispute, and Brussels should treat Italy's double-anonymity model, not blanket blocking, as the export-worthy part of this framework.