CaraComp
CaraComp
Forensic-Grade AI Face Recognition for:
Get Started7-day refund guarantee**
privacy

Biometric Research on Biometrics: Ireland Probes X Facial Age Data

biometric research reveals wide range of age assurance gaps on a phone settings screen showing parental controls
Biometric research uncovers subconscious human responses in facial analysis, shown here in a phone displaying hidden parental control settings. Illustration: CaraComp

A regulator in Ireland just asked the question every parent has probably asked at 11pm while staring at their kid's phone: do these "parental controls" actually do anything, or are they just a button that makes everyone feel better? Ireland's media regulator, Coimisiún na Meán, has opened its first-ever investigation under a new online safety law, and it's aimed squarely at X (the platform formerly known as Twitter). The target: whether X's age assurance (the tech and process a platform uses to guess or confirm how old you are) and parental controls are real protections or just window dressing. This is where biometric research and everyday parenting collide, and the answer affects every family with a kid who has a phone. Biometric traits like facial structure are increasingly central to how platforms are expected to prove those checks actually work.

TL;DR: Biometric research and plain old common sense agree on one thing, a regulator in Ireland is now demanding that X prove its age checks and parental controls actually work, instead of just existing as a setting nobody can find.

TL;DR

Biometric research and basic parenting instincts point to the same worry: Ireland's regulator has opened its first formal probe into whether X's age checks and parental controls actually protect kids, or just look like they do.

Here's the part that should make you sit up: Ireland's regulator has said flatly that "any age assurance measure based solely on self-declaration is not sufficient," according to Biometric Update. Translation: if a website just asks "are you 18?" and lets you click yes, that's not a real check. It's a courtesy question, and every 12-year-old on Earth knows exactly which button to click. X has reportedly leaned on things like account creation dates and old "verified" badges as stand-ins for actual age assurance, signals that tell you almost nothing about whether the person scrolling is 14 or 40.

1

formal investigation into whether X's age assurance and parental controls actually work This article is part of a series, start with Social Media Identity Verification Macron Eyes Id Scanning.

Source: Coimisiún na Meán, via Biometric Update

Why biometric research on facial recognition and age checks matters more than a settings menu

Let's back up. Real age assurance usually leans on some combination of things: document checks, third-party verification services, or facial analysis that estimates age from a face scan without storing your actual identity. That's where biometric research comes in, the science of measuring an individual's unique characteristics, whether that's a face, a voice, or how someone types, to answer questions like "is this a live person" or "does this face look like it belongs to a 9-year-old." Facial age estimation is one of the more mature pieces of biometric research out there, and it's a lot harder to fake than typing in a birthday. Facial recognition itself is a related but distinct technology, one built for identity matching rather than age estimation, and the Irish investigation is really asking why X seems to be using neither. It's using account metadata, basically digital breadcrumbs, as a substitute for actually looking at whether a user is a kid.

What does human behavior research say about parental controls and behavioral characteristics?

This is the quieter half of the story, and it matters just as much. Human behavior research on family tech use keeps landing on the same finding: a control setting only works if a parent knows it exists, understands it, and actually uses it consistently. A 2025 evidence review from EuConsent found that parental controls are frequently misunderstood or simply invisible to the people who need them, buried three menus deep, or never surfaced when a new account is created. Behavioral characteristics like how often a family actually opens a settings menu matter more than whether the option technically exists. If your kid signed up for X last year and you've never seen a prompt asking about their age or offering to link a parent account, that's not an accident. That's the design.


The biometric research and biometric recognition behind age assurance, and why X's approach falls short

Ireland's regulator isn't asking X to install face-scanning cameras on every phone (nobody wants that, honestly). It's asking a much more basic question: can you prove your age assurance actually catches kids, or are you just hoping self-reported birthdays are close enough? The Irish Times reported the investigation centers on concerns that children aren't being adequately protected from pornography and violent content on the platform, and that the parental controls X does offer are hard to find and don't come with any minimum standard for what they need to accomplish.

"Any age assurance measure based solely on self-declaration is not sufficient." Coimisiún na Meán, as reported by Biometric Update

This is a big deal financially, too. Under Ireland's Online Safety Code, a platform found non-compliant can be fined up to €20 million or 10 percent of its yearly revenue, whichever is bigger. That's not a slap on the wrist. That's a number designed to make a company's finance department actually pay attention, instead of quietly shrugging off a compliance letter. For the first time, "we offer parental controls" isn't a defense on its own. A company has to show the controls do what they claim, and that's a much higher bar than most platforms have ever been asked to clear.

Performance, testing, and the data gap in age assurance

Good biometric systems get judged on performance the same way a car gets judged on crash tests: you don't just trust the sticker, you run it through testing and see what actually happens. Academic research evaluating age verification across major platforms (a paper hosted by SCITEPRESS) found systemic gaps in how these systems perform in practice, not just in theory. That's the whole issue with X's setup, according to the regulator: there's no visible testing, no independent analysis of whether the age assurance measures actually flag underage users, and no data showing how many kids slip through. Without performance data, "parental controls" is just a phrase on a settings page. Previously in this series: Social Media Identity Verification Macron Eyes Id Scanning P.

Why Parental Controls Backed by Real Biometric Research Matter

  • Self-declaration isn't protectiona birthday typed into a form proves nothing about who's actually behind the screen
  • 📊 Buried settings are a design choicecontrols that new users never see aren't oversights, they're friction built to lower usage
  • 🔮 Fines change incentivesa possible €20 million penalty pushes platforms to test their systems instead of just marketing them
  • 🧠 Parents can't audit aloneregulators exist because expecting every household to reverse-engineer an app's safety design isn't realistic

Trusted by Investigators Worldwide
Run Forensic-Grade Comparisons in Seconds
Detailed facial comparison reports. Results in seconds.
Get Started
7-day refund guarantee**

Facial analysis, eye tracking, and other biometric modalities platforms could actually use

So what does "doing it right" even look like? Biometric research covers a genuinely wide range of tools that go way beyond a face scan, drawing on many different biometric modalities depending on what question a platform is trying to answer. There's facial age estimation, which studies facial expression and bone structure patterns to guess an age range without ever storing an actual photo. There's eye tracking, a method more commonly used in emotional and cognitive studies, where researchers watch how someone's eye moves across a screen, it's mostly used in market research and behavior research labs right now, not age checks, but it shows how deep this field goes. Some labs even study EEG, which measures brain activity, for research into how people respond to content, though that's more of a lab tool than something you'd expect baked into a social app tomorrow. The point isn't that X needs an EEG headset. It's that credible age assurance is a whole field of applied science, with actual testing standards, and X's current approach, old account dates and self-reported birthdays, doesn't touch it.

Weak age assurance (self-declaration)Biometric research based age assuranceStatus
User types in any birthday, no verificationFacial analysis estimates age range from real facial characteristicsNot deployed by X
No testing or performance data publishedSystems get testing against known age groups, with accuracy reportedData gap flagged
Parental controls buried, not surfaced at sign-upProtections built into onboarding, tied to verified account signalsUnder investigation
No audit trail of who was flagged as underageData collection creates a record regulators can actually reviewMissing entirely

One CaraComp-style thought for the road: this isn't really about whether you trust X specifically. It's about the exact question this kind of technology exists to answer, is the account, the photo, the profile actually what it claims to be? If you're a parent, here's one useful thing to actually check tonight, no audit degree required: open your kid's account settings and see if a parental control option is visible within two taps of the main menu. If you have to dig, that's your answer about how seriously that platform treats it.

What analysis of X's age assurance and biometrics means for the next platform investigated

Ireland picked X first, but this is bigger than one company. Every major platform runs some version of the same self-declaration system X is now being investigated over. The analysis Ireland's regulator is doing here, digging into whether age assurance measures actually function rather than just checking a box, is a template. Expect other regulators, especially across the EU, to run the same playbook: demand proof of performance, not just a settings page. Analysis of this kind takes time (regulators aren't fast, that's just true), but the direction is clear. Platforms will need to show their age assurance and parental controls hold up under real testing, not marketing copy, and any credible answer will lean on biometrics as evidence rather than a settings page nobody reads.

Key Takeaway

Biometric research gives platforms real tools, facial analysis, testing standards, and data collection methods, to prove age assurance actually works, but a regulator now has to force the issue because self-declaration alone was never real protection, it was one flimsy checkbox.

Here's the thing nobody says out loud enough: parental controls that nobody can find aren't a safety feature, they're a legal alibi. A setting that exists but isn't surfaced lets a company say "the tool was available" while knowing full well most families never saw it. Ireland just made that alibi a lot more expensive to hide behind, and every parent quietly checking their kid's app settings tonight already knew the real test wasn't whether the button existed. It was whether anyone was ever supposed to find it.

biometric research and biometrics: Frequently Asked Questions

What is biometric research and how does it relate to age assurance?

Biometric research is the study of an individual's unique characteristics, like facial structure, voice, or eye movement, to identify or estimate things about a person. In age assurance, it usually means facial analysis that estimates whether someone looks old enough to use a platform, without needing a birth certificate. It's more reliable than self-declaration because it doesn't depend on a user telling the truth about their age. Up next: Social Media Identity Verification Macron Eyes Id Scanning P.

Does biometrics require collecting my biometric information permanently?

Not necessarily. Good biometric systems built for age assurance are usually designed to estimate an age range in the moment and then delete the facial data, rather than storing it forever. Biometrics research generally pushes toward this "collect less, delete faster" approach, and privacy rules in places like the EU reinforce it. The concern with platforms like X isn't that they're collecting too much biometric information, it's that they're barely collecting anything meaningful at all.

Why do researchers use eye tracking in human behavior research instead of just surveys?

Eye tracking uncovers subconscious human responses that people can't accurately self-report, like where attention actually goes on a screen versus where someone claims they looked. It's used heavily in market research and behavior research because it quantifies user responses in a way surveys can't. This same idea, that real biometric measurement beats a person's self-reported answer, is exactly why age assurance built on "just ask them" fails.

Can facial analysis really tell if someone's skin appears too smooth to be an adult, or is that a myth?

It's not a myth, but it's also not the whole story. Facial analysis tools do look at texture and structure cues, including whether skin appears too smooth, has less defined bone structure, or shows other patterns common in younger faces, drawing on the same kind of biometric samples used in broader facial research. But these systems only provide an estimated age range, not a precise number, and they work best combined with other signals rather than as a single deciding factor, judged individuals based on multiple cues at once rather than one alone.

Is EEG used in real testing for online safety systems?

Not typically, no. EEG (a way of measuring brain activity through sensors on the scalp) is mostly a lab tool used in academic behavior research and systems biology support studies to understand emotional and cognitive responses, not something built into everyday apps for age checks. It's mentioned in biometric research circles because it's part of the same broader field, but platforms like X are nowhere near using anything that advanced.

Why does information security research matter for parental control settings?

Information security research is needed here because parental control data, like a child's estimated age or account restrictions, has to be stored and transmitted safely, or the "protection" becomes a new risk. If a platform collects data to verify a child's age but secures it poorly, that creates a fresh target for hackers using stolen biometric technology or credentials alike. This is part of why regulators want to see analysis, not just claims, before trusting that a parental control feature, backed by real biometric technologies and modern biometric sensors where relevant, is actually safe. Sound provides biostatistics context too, helping regulators judge whether a system's error rates are honestly reported rather than glossed over.

Ready for forensic-grade facial comparison?

Full forensic reports with detailed similarity scoring. Results in seconds.

Run My First Search