Most of the companies the European Union argues with about children online do not answer to Brussels first. They answer to Dublin. Meta, TikTok, X, Google, LinkedIn, Pinterest, Tumblr, Reddit — the platforms whose age-assurance choices set the terms for hundreds of millions of European users — keep their EU headquarters in Ireland, and that single fact of corporate geography hands a mid-sized national regulator a job vastly out of proportion to its size. Under the audiovisual country-of-origin principle, the rules that bind a video-sharing platform are the rules of the member state where it is established. For a large slice of the internet, that state is Ireland, and the rulebook is Coimisiún na Meán’s Online Safety Code.
Here is the part operators keep missing. Ireland has spent 2026 talking about a government wallet and a pan-European “digital age of majority” — future-tense infrastructure, still in beta, that no platform has agreed to use. Meanwhile the Online Safety Code’s age-assurance obligation has been enforceable since July 2025. The country that hosts the platforms has a live rule and a hypothetical tool, and the gap between the two is exactly where a compliance team gets caught: waiting for the wallet, past the deadline for the Code.
Why Dublin is the centre of gravity
Country of origin is not a detail; it is the load-bearing beam of European platform regulation. The Audiovisual Media Services Directive, which the Online Safety Code transposes into Irish law, assigns jurisdiction over a video-sharing platform service to the member state in which it is established — not to each country where its users happen to live. A platform established in Ireland is regulated for its European conduct by an Irish regulator, and a French or German user who wants that platform to check ages is, in the first instance, relying on an Irish enforcement decision. We walked through the cross-border mechanics of this in the CJEU country-of-origin ruling piece; the short version is that where a company plants its EU flag determines whose age-assurance standard it lives under.
This is distinct from the Digital Services Act, and it is worth keeping the two straight because they are often blurred. Under the DSA, the systemic-risk obligations of the very large platforms — the ones with the July 2025 minors-protection guidelines and the age-verification blueprint attached — are enforced by the European Commission directly. Everything below that tier, and the audiovisual-specific duties on video-sharing platforms, runs through the national regulator: in Ireland, Coimisiún na Meán, which also serves as the country’s Digital Services Coordinator. The result is that a Dublin-headquartered platform sits under two overlapping regimes at once, and the one most people forget — the audiovisual one, with its own concrete age-assurance text — is the one with a deadline that has already passed.
The Online Safety Code is the binding rule, and it is already live
Strip away the strategy documents and the wallet announcements and one instrument does the actual legal work today. The Online Safety Code applied its age-assurance obligations to designated video-sharing platform services established in Ireland from 21 July 2025. The Code does not ask nicely. It requires platforms that carry pornography or gratuitous violence to prevent children from encountering that content, and it is explicit that age assurance based on user self-declaration will not be treated as effective. A checkbox that says “I am 18” is not a control the Irish regulator recognises.
That last point is the one that should reorganise a roadmap. Self-declaration failing is not an Irish idiosyncrasy — it is the same conclusion the UK’s regulator reached, the same one behind the ICO’s action against Reddit that we covered in the self-declaration write-up. The Code demands “effective” age assurance, which in practice means age estimation or verification that can withstand scrutiny, applied before a user reaches restricted content, and demonstrable to a regulator after the fact. If your Irish-established service still gates adult content behind a date-of-birth field, you are not waiting for a future obligation. You are non-compliant with a current one.
It is true that Ireland’s regime is, on paper, softer than the strictest European models. Its rules for standalone pornography sites are less prescriptive than France’s double-blind referential or the UK’s “highly effective age assurance” bar under Ofcom’s Online Safety Act enforcement, and a 2025 policy paper by Cuan, the state agency on domestic and sexual violence, has pushed the government to tighten them, pointing to France as the model. Aylo — the operator behind many of the world’s largest adult sites — even keeps a billing subsidiary in Dublin. But “softer than France” is a trap if you read it as “optional.” The Code’s effectiveness standard binds general video-sharing platforms now, and the direction of travel, with Cuan pushing and the AVMSD under review, is toward more, not less.
The wallet is a maybe, not a plan
The reason Ireland looks quieter than France or the UK is that its government has placed a different bet. Rather than mandate site-by-site checks, Dublin is building — and hoping to lean on — a national Government Digital Wallet, aligned with the EU Digital Identity (EUDI) framework. The pitch is elegant: a citizen holds a wallet containing a digital birth certificate, driving licence and Public Services Card data, and proves “over 16” or “over 18” to a platform without handing over the underlying documents. That is the same architecture the EU Age Verification Blueprint describes and the same wallet direction we covered in the EUDI age-verification piece.
The problem is the distance between the pitch and the reality. The wallet is in beta with a public consultation still running; its public rollout is scheduled for later in 2026; and the government’s own messaging contradicts itself on whether it will ever be compulsory. The Minister for Communications, Patrick O’Donovan, has suggested the wallet should be mandatory for social-media age checks. The Irish Times reports the wallet will not be compulsory for any service and that its main purpose is simplifying access to government services. Both cannot be true. And the decisive fact, as of the pilot: not one of the social networks based in Ireland has agreed to participate in a wallet-based age-verification trial.
A compliance obligation you can satisfy today does not become optional because a better tool might arrive next year. Even in the best case — a shipped wallet, broad adoption, platform buy-in — a national wallet solves for one signal in one country. It does not cover the tourist, the migrant, the new arrival without a Public Services Card, or the returning user on a device the wallet has never seen. Any platform planning to make an Irish government app the load-bearing element of its age gate is designing a control with a single point of failure and a coverage hole the size of everyone who is not an Irish resident with the app installed.
Why Ireland is deferring to Brussels — and what that timeline actually means
Ireland’s caution is deliberate, and reading the government’s own words clarifies it. The National Digital & AI Strategy, published 18 February 2026, declined to introduce a national age ban and stated that a “digital age of majority” should ideally be defined at EU level to avoid fragmentation — while reserving the right to act domestically “if necessary.” It committed to resourcing Coimisiún na Meán, backed the digital wallet as future age-verification infrastructure, and framed online safety as a standing priority rather than a one-off measure.
The lever Ireland intends to pull is its Presidency of the Council of the European Union in the second half of 2026. The Taoiseach, Micheál Martin, has said that by the end of the presidency people can expect “far greater protection for children online,” with age verification “a key factor”, and Dublin is using the window to push a common European age-of-majority position and to steer the review of the AVMSD, whose public consultation ran into May 2026. There is also political impatience underneath the diplomacy: senior figures have signalled Ireland might legislate age limits even without EU agreement if consensus stalls.
For an operator, the honest read of this timeline is that it does not relieve you of anything. A pan-EU digital age of majority, if it lands, is a multi-year negotiation. The AVMSD review is a consultation, not a rule. The wallet is a beta. The only item on the Irish calendar that is already in force and already carries enforcement risk is the Online Safety Code, and it is the one that gets the least attention precisely because it is not new or dramatic. The strategic noise is future-tense; the obligation is present-tense.
What this means for platforms established in Ireland
Three practical conclusions fall out of the country-of-origin position.
First, if Ireland is your point of EU establishment, the home regulator’s standard is your baseline whether or not you serve Irish users heavily. You are not choosing the lightest European regime by incorporating in Dublin; you are choosing Coimisiún na Meán as the authority that judges your age gate, and its Code already rejects self-declaration and demands effectiveness. This is the same logic that made a single national regulator’s ruling reverberate across borders in the DSA Article 28 enforcement against Meta.
Second, build for the obligation, not the announcement. The obligation is effective age assurance now; the announcement is a wallet later. A gate that depends on a government app that no platform has agreed to use, and that may never be compulsory, is not a plan — it is a press release. Ship a control that works today and can consume a wallet attestation the day one actually exists, rather than one that is inert until then.
Third, an Irish-established platform is, by definition, a cross-border platform. Its users are all over Europe, which means its age-assurance layer has to work for a French teenager, a German adult, and a returning user on an unfamiliar device — not just an Irish resident with a Public Services Card. The France and UK regimes it is tempting to treat as “someone else’s problem” are, in practice, the standards its own users will expect it to meet, because those users are governed at home by exactly those rules even while the platform is governed in Dublin.
What Xident does here, and what it does not
We built Xident for this shape of problem: a European regulatory map where the binding rule, the enforcing regulator, and the user’s home country are three different things at once, and where the “solution” a government is promising is still in beta. The answer is not to wire your compliance to any single national app. It is to run a layer that satisfies the effectiveness standard today and stays ready for the wallet future without depending on it.
Xident runs two operations and keeps them deliberately distinct. A Check is the cheap, fast path — a browser-based age signal, a liveness pass, a returning-user lookup — and it is what most of the Online Safety Code’s general obligation actually needs: a defensible age decision that beats self-declaration without demanding a document from every visitor. A Verification is the heavy path, a document read and face match, roughly ten times the cost of a Check and reserved for the narrow set of cases that genuinely need to establish identity rather than an age band. Each returns a structured decision with an audit trail, so that when Coimisiún na Meán — or any other home regulator — asks you to demonstrate the gate was working during a window under review, you can, without having built a surveillance log to do it.
That last distinction is the one that matters for a country betting on a privacy-preserving wallet. The point of the EUDI direction is to prove age without accumulating a record of who proved what, where. A vendor that satisfies the Code by collecting and retaining document scans on every user has met the letter of “effective” while manufacturing exactly the risk the wallet architecture exists to avoid — the pairing of identity with intent we described in double anonymity or compliance theater and in age verification without surveillance. Xident’s posture is to collect as little as the check requires, discard the source material once the decision resolves, and bind returning users to a reusable, cryptographically held credential so re-proving is a lookup, not a fresh upload. When Ireland’s wallet does ship, a relying-party integration is an additional signal to consume — not a rebuild — because the underlying architecture was already designed to accept an attestation and check a signature rather than warehouse an identity.
If you are weighing whether to wait for the wallet or the pan-EU age of majority before doing anything, the build-versus-buy math is worth running, but the timing question answers itself. The Online Safety Code is enforceable now, the home regulator has already ruled out the cheapest control, and the tool the government is pointing at is a beta with no takers. The clock in Ireland is the Code, not the wallet — and it started in July 2025.