On 8 September 2026, Coimisiún na Meán opened its first formal investigation under Ireland's Online Safety Code, and the target is X. The regulator is examining whether X's age assurance for adult-only video content (Section 12(10)) is effective, and whether its parental controls meet Section 14(1), (2), (4) and (5). The stakes are substantial: administrative financial sanctions can reach 10% of relevant annual turnover or €20 million, whichever is greater, according to the regulator's announcement.
The strongest case for the regulator
The case for acting is stronger than X's critics on the libertarian side usually admit. The Code is not new or surprising. Coimisiún na Meán adopted it in October 2024, and X was designated as a video-sharing platform service back in December 2023, per the regulator's June 2025 information notice. X then challenged the Code's age-assurance provisions as regulatory overreach, and the High Court dismissed that judicial review on 29 July 2025, as reported by Biometric Update. The rules were lawful, publicly known and, by the time of this investigation, more than a year in force.
The regulator also did not jump straight to an investigation. In June 2025 it issued X a statutory information notice, saying earlier submissions were not sufficient to assess whether children were adequately protected. The September investigation follows what the regulator calls reviews by its platform supervision team. The concerns are specific. Age assurance may rest on self-declaration alone, which the Code does not treat as effective, and parental controls may be hard to find, lack minimum functions, and not be shown to new users at sign-up.
The advocacy case is also serious. Children's Rights Alliance figures told RTÉ that fines "will have to be big" to change behaviour at large companies. A pop-up asking "are you 18?" is not a safeguard, and a regulator that tolerated it would be tolerating theatre.
Where proportionality matters
Granting all that, the way this case is decided will matter more than the fact that it was opened. Three points deserve attention.
First, define "effective" by outcome. The Code rules out self-declaration as a sole measure, which is a sensible floor. But above that floor, the regulator should judge whether adult-only video is in practice unlikely to reach children, not whether a platform bought a particular vendor's product. Age estimation, verification, and cross-platform methods all carry different privacy and accuracy trade-offs. A rule that quietly converges on government-ID checks would put identity documents at the gate of general-purpose speech platforms. That is a real cost for adult users, for anonymous dissidents, and for people without ID.
Second, keep the target narrow. Section 12(10) concerns adult-only video content. It does not license blanket age-gating of a platform where most content is text and links. If enforcement drifts from "adult video must be walled off" to "everything must be age-checked", the burden falls on lawful speech, and on smaller services that cannot absorb compliance costs the way large ones can. Coimisiún na Meán should say explicitly in its eventual decision that the obligation is tied to the content category.
Third, parental controls are the cleaner enforcement case. Findability, a minimum feature set, and prompts at sign-up are objective and cheap to fix. They empower families without restricting anyone's speech. If the regulator wants a fast, defensible finding that improves child safety without collateral cost, this limb of the investigation is where to find it.
The process is the product
The investigation runs under Part 8B of the Broadcasting Act 2009, as amended. It is the regulator's first under the Online Safety Code, following five Digital Services Act investigations opened in the preceding year, according to the regulator. The Irish Times notes that neither report includes a response from X, so the platform's account of its current measures is not yet public.
That gap is a reminder to hold two things together. Regulators are right to expect platforms to protect children, and a platform that ignores a lawful, court-tested code should face consequences. But the penalty ceiling of 10% of turnover is large enough that the reasoning in the final decision will be treated as a template by every other designated platform, and by regulators elsewhere in the EU. A decision that names what evidence shows an age-assurance system works, and that respects data minimisation, would be a useful public good. A decision that simply punishes non-compliance without saying what compliance looks like would push platforms toward the most invasive and over-inclusive option because it is the safest legally.
What to watch
Watch for three things. Whether the regulator publishes its assessment criteria for "effective" age assurance. Whether X responds by adopting privacy-preserving estimation or by restricting adult content for Irish users. And whether any eventual sanction is proportionate to the specific failures found rather than to the headline ceiling. Child protection and an open internet are compatible goals, and this case is the first real chance to show it.