France's Conseil constitutionnel ruled on August 14, 2026 in decision n° 2026-915 DC that the RIPOST law's extension of algorithmic video surveillance (VSA) is largely constitutional. It capped some of the new authorisations at three months. It also warned that widening the experiment and easing automated licence-plate reading could unjustifiably infringe privacy. The law was promulgated on August 18. The ruling is a real constraint, but it covers only the surveillance the state has chosen to legislate. The more serious gap is the facial recognition the state says it has not authorised.
The strongest case for the law
Supporters of algorithmic video surveillance have a serious argument. VSA software does not identify people. It flags events such as an abandoned bag, a crowd surge, or a person entering a restricted zone, and a human operator then decides what to do. The 2023 Olympics law introduced it as an experiment, and RIPOST extends it. According to FNMS's summary of the promulgated text, the experiment now runs to December 31, 2030 and reaches certain buildings and places open to the public exposed to terrorism or serious harm, beyond sporting and cultural events and transport. Officials can reasonably say that a tool which detects incidents without recognising faces is a far lesser intrusion than the biometric systems it replaces.
The Council largely agreed. Its press release records the limit that the authorisation for certain buildings "ne peut excéder trois mois". The Council's summary of the decision repeats the three-month limit. It also says that widening the VSA experiment and easing licence-plate reading could constitute "une atteinte injustifiée au droit au respect de la vie privée". Per FNMS, the three months is renewable, so the cap forces periodic review instead of a long blanket authorisation.
Why the cap is the right kind of rule
This is proportionate regulation. It does not ban a useful public-safety tool. It requires the administration to renew its justification on a short cycle, and the tool has to keep earning its place. Innovation-friendly regulation looks like this: a defined scope, a bounded duration, and a review point. Technology companies can build to a rule like that, and citizens can contest it.
The statute also keeps its exclusion of facial recognition and biometric identification. FNMS reports the Council confirmed that the treatments "excluent toute reconnaissance faciale" and biometric data. Read alone, that is reassuring.
The parallel system the ban does not reach
Read against the reporting from earlier this year, it is not. Disclose reported on March 16, 2026 that facial-recognition matching built by Germany's Cognitec runs on NEO phones issued to French police and gendarmes. The matching works against the TAJ criminal-records file, which holds up to 9 million facial photographs. Police access began on January 24, 2022, and consultations rose from 375,000 in 2019 to nearly 1 million in 2024, roughly 2,500 a day. The same report cites an IGPN (police inspectorate) finding that the TAJ is frequently used on public roads during identity checks. That contradicts the file's purpose, which is criminal investigations by authorised personnel.
La Quadrature du Net states the legal problem plainly: no text governs how facial recognition may be used, by whom, or under what conditions. Interior Minister Laurent Nuñez has called this use unlawful. Yet Disclose's later investigation documents officers doing it in a Paris identity check on May 19, 2026. One gendarme said the difficulty is that access to Reco-TAJ cannot be verified for every officer.
The consequences are concrete. Disclose describes a woman held for 30 days in a deportation centre after a 68% similarity match to another person. On July 6, 2026, a tribunal in Valence annulled proceedings against eight climate activists, citing "disloyal identification methods", which ended in their acquittal. Illegally obtained identification has now collapsed a prosecution. That is a cost to public safety as well as to privacy.
What proportionate policy would do
The Council reviewed the law it was given. It could not review an unwritten practice that the ministry says is prohibited. The result is odd. A camera that detects an abandoned bag is authorised, capped, and reviewable. A phone that names a person on the pavement is neither authorised nor effectively policed.
Three changes follow from the evidence:
- Choose a rule. Either legislate a narrow, judicially supervised facial-recognition regime with purpose limits and accuracy thresholds, or enforce the prohibition in practice. Tolerating a prohibited tool is the worst of both.
- Log every query. If the TAJ face search stays available for investigations, access should be per-officer, auditable and reportable to the CNIL, which resolves the verification gap the gendarme described.
- Publish the numbers. Roughly a million annual queries is public-interest data. The three-month VSA reviews should come with reporting on what was detected and what was done.
A pro-innovation position does not mean minimal rules. It means predictable ones. Vendors, police forces and courts can all operate under a clear line. They cannot operate under a statutory ban that sits beside a mass-deployed, formally forbidden tool. The RIPOST ruling shows France can write proportionate limits when it legislates openly. The next step is to apply the same discipline to what already runs on police phones.