Seven in Ten 8-to-12-Year-Olds Still Have 13+ Social Media Accounts as Ireland Tests Age Assurance

Breaking News Ireland Newspaper Report
By 14 min read
Share X Facebook Email

A year after stronger online-safety rules were supposed to make age barriers harder to bypass, 70% of Irish children aged eight to 12 surveyed by CyberSafeKids still had an account on at least one regulated platform whose stated minimum age is 13. The comparable figure before the July 2025 regulatory deadline was 68%, a difference the organisation regards as normal sample variation rather than evidence of meaningful progress.

The finding is important because it shifts the debate from whether platforms publish minimum ages to whether those ages can actually be enforced. CyberSafeKids’ new report, The Year Little Changed, argues that the Digital Services Act and Ireland’s Online Safety Code have yet to produce a measurable reduction in underage access within its survey sample. That does not by itself prove that the legislation has failed: the study is observational rather than a controlled evaluation of regulation, and changes in enforcement, platform systems and children’s behaviour can take time to appear. It does, however, show that one of the most visible outcomes policymakers hoped to influence has barely moved.

The research arrives at a particularly consequential moment for Ireland. The State is simultaneously enforcing an increasingly complex European online-safety regime, developing privacy-preserving age-verification technology and advocating for an EU-level decision on age restrictions for social media. The practical question is no longer simply whether children should be protected online, on which there is broad political agreement, but how a platform can reliably know that a user is a child without creating a new system of intrusive identity surveillance.

70%: the share of surveyed 8-to-12-year-olds with an account on one or more regulated 13+ platforms.

68%: the comparable figure before the 21 July 2025 regulatory deadline, using the same group of platforms.

7,378: children aged 8 to 15 who responded to the 2025–26 CyberSafeKids survey across 74 schools.

26% and 25%: the shares of 8-to-12-year-olds and 12-to-15-year-olds respectively who reported online content or unsolicited contact that bothered them.

The Numbers Have Barely Shifted Since the New Rules Arrived

CyberSafeKids collected 7,378 anonymous survey responses during the 2025–26 academic year from 74 schools in 11 counties across Leinster, Munster and Connacht. More than 6,000 responses came from children aged eight to 12 in primary schools and more than 1,300 from 12-to-15-year-olds in post-primary education. The participating schools included urban, suburban and rural settings as well as DEIS and non-DEIS schools.

The scale of the sample makes the findings significant, but its methodology also matters. It is a school-based survey rather than an official census of every child in Ireland, and the composition of respondents changes somewhat from year to year. CyberSafeKids therefore treats movements of roughly three to four percentage points as potentially attributable to normal variation in the age and gender profile of the sample. That is why the movement from 68% to 70% in account ownership on the same regulated 13+ platforms is described as effectively unchanged rather than as an increase.

YouTube remains particularly prominent among younger children: 63% of the eight-to-12 group reported having an account. Snapchat accounted for 21% and TikTok for 20%. The broader significance is not that every use of these services produces harm, but that large numbers of children below the platforms’ own stated minimum age continue to enter digital environments in which many safety mechanisms depend on the service accurately knowing how old the user is.

What the Latest Survey Found

Measure Age 8–12 Age 12–15
Own a smart device 94% 99%
Account on regulated 13+ platforms 70% 99%
Bothered by online experience 26% 25%
Using generative AI 55% 76%

Source: CyberSafeKids, The Year Little Changed, 2026.

The survey also found that negative experiences remain common. Twenty-six per cent of younger children and 25% of those aged 12 to 15 said something they had seen or experienced online had bothered them. Among affected younger children, Roblox was the most frequently identified environment, while Snapchat was the most frequently named among the older group. Scams or false information, hate, sexual material, threats and other forms of unwanted contact featured in the responses.

One of the sharper movements concerned sexual content among older children. Twenty-four per cent of 12-to-15-year-olds reported accessing sexual content during the year, compared with 10% in the previous report. According to CyberSafeKids, 22% said such material had been pushed to them while 2% said they had sought it out. The figures should not be interpreted as establishing what caused the increase, but they reinforce the distinction between restricting access to a platform and controlling what happens once a young person is inside it.

A Date of Birth Is Not the Same as Knowing Someone’s Age

The central technological weakness identified by the report is straightforward. An undergraduate study at University College Dublin, undertaken in consultation with CyberSafeKids during the academic year, examined account creation on YouTube, TikTok, Snapchat and Instagram and found that the sign-up process continued to rely on users declaring their own age. A child able to enter a false date of birth could therefore present as an older teenager or adult at the point of registration.

This does not mean platforms rely only on a date-of-birth field throughout the lifetime of an account. Services can also use behavioural signals, account activity, content analysis, reports from other users and automated systems to identify people they suspect are younger than claimed. Some platforms have introduced dedicated teen accounts and additional protections, while Meta has said it is expanding AI-assisted age-assurance systems. The important distinction is that these measures can operate after or alongside registration rather than creating an impenetrable age gate at the moment an account is opened.

That distinction has consequences for safety-by-default systems. Privacy settings, restrictions on direct messages, limits on recommendations and other protections designed specifically for children or teenagers work most reliably when a platform correctly classifies the user. A 12-year-old who successfully presents as a 17-year-old may therefore avoid not only a minimum-age barrier but also safeguards intended for younger users.

70% of 8-to-12-year-olds surveyed reported having accounts on one or more regulated platforms with a stated minimum age of 13.

What the Law Actually Requires Is More Complicated Than a 13+ Label

Ireland’s regulatory structure contains several overlapping rules, and they are often conflated in public discussion. A platform’s stated minimum age of 13 is generally a contractual rule set by the service itself. It should not be confused with Ireland’s statutory age of digital consent, which is 16 and applies in particular circumstances when an online service relies on consent as its legal basis for processing a child’s personal data. The Data Protection Commission has explicitly explained that the digital age of consent is not a general prohibition on people under 16 signing up for every online service.

A separate layer comes from the EU Digital Services Act. Article 28 requires online platforms accessible to minors to establish appropriate and proportionate measures ensuring a high level of privacy, safety and security for them. European Commission guidelines published in July 2025 set out how that obligation should be interpreted in practice, including recommendations concerning age assurance, account settings, recommender systems, addictive design and contact risks.

The Commission’s guidelines are particularly clear about simple self-declaration. They conclude that asking users merely to state their age does not provide sufficient robustness and accuracy to qualify as an appropriate age-assurance method where effective age assurance is required. The guidelines do not demand the most intrusive possible identity check in every circumstance; instead they set out a risk-based approach in which the strength of age assurance should correspond to the danger involved.

Ireland’s Online Safety Code adds obligations for video-sharing platform services under Irish jurisdiction. Part B of the Code became fully applicable by 21 July 2025. Among other requirements, services that permit adult-only video content must use effective age assurance so that children cannot normally see pornography or gross or gratuitous violence, and self-declaration alone is expressly insufficient for that purpose.

Three Different Age Rules Often Confused in the Debate

Rule What It Means Status
Platform minimum age Usually 13 on major services Platform rule
Digital age of consent 16 in Ireland for relevant consent-based data processing Existing law
Social-media access limit Possible statutory age restriction Under EU and Irish debate

Source: Data Protection Act 2018, European Commission and Coimisiún na Meán.

The distinction matters because age assurance and an age ban are not the same policy. Age assurance is the mechanism used to establish whether somebody falls above or below a threshold. The threshold itself is a political and legal decision. A country could theoretically require highly reliable age assurance while permitting teenagers to use appropriately designed social media, or it could impose a much higher minimum age but fail to achieve its objective if the verification system were easily circumvented.

Regulators Have Started Testing Whether Platform Measures Are Good Enough

The latest Irish research does not arrive in a regulatory vacuum. In April 2026, the European Commission issued preliminary findings that Meta had failed adequately to address the risk of children under 13 accessing Instagram and Facebook. The Commission specifically identified the ease with which a child could enter a false birth date without an effective control checking whether the declared age was correct.

Those findings are preliminary rather than a final determination of infringement, an important legal distinction. Meta has the opportunity to respond and defend its practices before a final decision is reached. But the case demonstrates that the practical effectiveness of age controls has moved from a theoretical policy debate into formal regulatory enforcement.

TikTok is also facing scrutiny. In July, the European Commission issued separate preliminary findings concerning the safety settings of accounts belonging to minors, including the ability of minors to make accounts public and the potential for content from older teenagers to be distributed more broadly through recommendation systems. Snapchat has meanwhile been subject to formal EU proceedings examining child-protection issues including grooming risks and access to age-restricted products.

For Ireland, enforcement is especially significant because many of the world’s largest technology companies have their European headquarters or principal EU establishments in the State. Coimisiún na Meán acts as Ireland’s Digital Services Coordinator and also supervises compliance with the Online Safety Code. Serious infringements can expose companies to substantial financial sanctions, although investigations involving complex platform systems can take considerable time and are subject to procedural and legal safeguards.

Stronger Verification Creates a Second Problem: Privacy

If asking for a date of birth is too weak, the obvious alternative is to demand stronger evidence. But that creates another risk. Requiring millions of people to upload passports, identity cards or facial images to every platform they visit would potentially expose more personal information than is necessary simply to establish that someone is above a particular age.

The European approach is increasingly focused on separating proof of age from proof of identity. The Commission’s age-verification blueprint is designed to allow a person to demonstrate that they meet an age threshold without revealing their name, exact date of birth or other unnecessary personal information to the website or app. The proof can originate from a trusted source such as an electronic identity, passport or identity card while the online service receives only an anonymous confirmation that the relevant threshold has been met.

The technical blueprint was first released in July 2025 and had reached a feature-ready stage by April 2026. The Commission has encouraged Member States to make privacy-preserving age-verification tools available by the end of 2026, either through standalone applications or eventually through European Digital Identity Wallets. Ireland has separately committed to work on age verification through its Government Digital Wallet.

This architecture could resolve part of the apparent conflict between child safety and adult privacy, but it does not eliminate every difficulty. Any system must work for people without conventional identity documents or compatible devices, minimise discrimination and false classification, resist circumvention and prevent age credentials from becoming a mechanism for tracking users across the internet. A verification tool that is highly accurate but excludes significant groups of legitimate users would create a different regulatory problem.

The Debate Is Moving Beyond Whether Under-13s Should Be There

Ireland’s policy debate has advanced further than enforcing the minimum ages already written into platform terms. The Government’s 2026 Digital and AI Strategy commits the State to working with other EU members on age restrictions for social media, with particular attention to children under 16. The Government has said it prefers a harmonised European approach, while retaining the option of domestic action if EU agreement cannot be reached.

The European debate is not yet settled on the same threshold. A special panel advising European Commission President Ursula von der Leyen reported in July 2026 that social media and other digital services should face a harmonised EU-wide access restriction for children under 13 until providers can demonstrate that their services are safe by design. It proposed supervised and age-appropriate use for younger children in limited circumstances and an increasingly autonomous but protected environment for adolescents from 13 onwards. The panel also left open the possibility of individual Member States adopting stricter precautionary restrictions for older adolescents.

Those recommendations are not EU law. The Commission has said it will use the panel’s work to inform future proposals, meaning the political negotiations over the threshold, parental consent, exemptions and enforcement remain ahead. Ireland’s presidency of the Council of the European Union gives the State an unusually influential coordinating role in those discussions during the second half of 2026.

A Ban Cannot Work Better Than the System That Determines Age

The new CyberSafeKids findings expose the central weakness in any future statutory age limit. Raising a minimum age from 13 to 16 would be a substantial legal change, but it would achieve little if a 12-year-old could still type a different birth year into a registration box. In that sense, the current experience with 13+ accounts is a practical test of the infrastructure that any stronger restriction would eventually depend upon.

There is also a second limitation to an access-only approach. A successful age gate can reduce the number of younger children entering a service, but it does not make the service safe for teenagers who are legally permitted to use it. The survey’s figures on unwanted contact, scams, misinformation and sexual material therefore point towards a broader regulatory agenda involving recommender systems, default privacy, direct messaging, addictive features, advertising, reporting mechanisms and rapid responses to harmful behaviour.

That is increasingly reflected in EU enforcement. Regulatory attention has expanded from what platforms say in their terms and conditions to how their systems actually behave: whether an account is private by default, who can contact a minor, what algorithms recommend, how easily age controls can be bypassed and whether design features encourage excessive use. The regulatory objective is moving from simply publishing safety policies towards demonstrating measurable safety outcomes.

Children’s Access Is Also Shaped by What Happens Outside the Platforms

The report contains another finding that complicates a purely technological solution. Smartphone ownership among eight-to-12-year-olds differs sharply between schools serving different socioeconomic communities. Among children surveyed in DEIS primary schools, 62% owned a fully functional smartphone, compared with 29% in non-DEIS schools. Overall smart-device ownership was much closer, at 96% and 94% respectively, because tablets, games consoles and other devices remain widespread.

CyberSafeKids associates the fall in smartphone ownership in some non-DEIS communities with collective parent initiatives encouraging families to delay giving children smartphones. In the non-DEIS sample, smartphone ownership fell from 43% to 29% over two years, whereas the DEIS figure moved only from 65% to 62%. The organisation cautions that relying on parent-led collective action alone risks producing unequal protection where communities have different resources, levels of participation or competing family pressures.

This is one reason regulation, family decisions and education cannot easily substitute for one another. Parents can delay a smartphone but cannot redesign an algorithm. Regulators can impose safety duties but cannot supervise every child’s use. Schools can teach digital literacy but cannot determine whether an account-opening system accepts a false date of birth. Effective protection depends on those layers working together rather than shifting responsibility from one to another.

AI Is Making the Regulatory Timing Problem More Urgent

The 2026 report also identifies a rapidly expanding area that did not dominate the debate when today’s social-media framework was designed. Fifty-five per cent of surveyed primary-school children and 76% of the 12-to-15 group reported using generative AI. Half of the younger group and 45% of the older group said nobody had talked to them about AI.

Generative AI is not the same regulatory problem as conventional social media, but the overlap is growing as chatbots, companions, image-generation systems, recommendation engines and social platforms become increasingly integrated. The concern for policymakers is that regulation built in response to one generation of online services may again be overtaken by the technology children actually use. CyberSafeKids argues that this is already happening with gaming environments and AI services that may not sit within precisely the same regulatory categories as the best-known social networks.

The Next Year Will Test Enforcement Rather Than Intentions

There is now considerably more law, regulatory capacity and political attention surrounding children’s online safety than there was only a few years ago. Ireland has a binding Online Safety Code, the EU has the Digital Services Act, detailed child-protection guidelines have been published, formal investigations are under way and a technically viable privacy-preserving age-verification system is being prepared for broader deployment. The policy architecture is therefore no longer at the starting line.

What remains uncertain is whether those mechanisms will materially change children’s experience. The most useful measures over the coming year will not be the number of new announcements but observable outcomes: whether fewer under-13s can create ordinary accounts on 13+ services, whether platforms correctly identify young users who misstate their age, whether harmful material reaches them less frequently and whether stronger age checks can operate without requiring unnecessary disclosure of identity.

The disagreement over whether Europe’s eventual social-media threshold should be 13, 16 or something in between will continue. But the latest Irish figures reveal a more immediate problem beneath that argument. Before governments can confidently decide which age should open the digital door, regulators and platforms first have to demonstrate that the door can actually distinguish who is standing in front of it.

Sources

CyberSafeKids — The Year Little Changed: Children’s Digital Lives in Ireland, 2025–26

Coimisiún na Meán — Online Safety Code

Coimisiún na Meán — Online Safety Code Application and Implementation Deadlines

European Commission — Guidelines on the Protection of Minors under the Digital Services Act

European Commission — EU Approach to Age Verification

European Commission — Special Panel on Child Safety Online

Government of Ireland — Digital Ireland: Empower Online Safety

Irish Statute Book — Data Protection Act 2018, Section 31

European Commission — Preliminary DSA Findings Concerning Under-13 Access to Facebook and Instagram

European Commission — Preliminary DSA Findings on TikTok Accounts for Minors

Source & Transparency

This article is published by Ireland Newspaper for editorial and informational purposes.

Published: 2 September 2026 · Updated: 2 September 2026

Newsroom Ireland Newspaper

Editorial Desk · Ireland Newspaper

Ireland Newspaper editorial team prepares daily news coverage for readers in Ireland and abroad.

Related posts

Leave the first comment