France's media regulator Arcom announced on July 30, 2026 its largest single enforcement action yet against pornographic websites: proceedings against 31 additional sites for failing to deploy age verification required under the 2024 "SREN" law, bringing the cumulative total to 66 sites targeted since the campaign began in February 2025 (macg.co). The scale is real, but so is the pattern the action reveals: France's enforcement machine is working exactly as designed, and minors are routing around it exactly as fast.
A Two-Tier Legal Arsenal
Arcom's power here comes from Law No. 2024-449 of May 21, 2024, "visant à sécuriser et à réguler l'espace numérique" (legifrance.gouv.fr), which the Senate fast-tracked under an accelerated procedure in 2023 (senat.fr). Article 10 requires pornographic sites to block access to minors under a technical standard Arcom published in October 2024; Article 10-1 backs that mandate with teeth — if a site's operator can't be identified or won't comply, Arcom can order French ISPs to block it and search engines to delist it within 48 hours.
The July 30 action splits the 31 sites into three enforcement tracks, and the split is the interesting part. Thirteen sites of unidentifiable origin, with no age-verification system at all, got the 48-hour blocking order directly. Thirteen more, hosted elsewhere in the EU, are being pursued through Digital Services Act cooperation with Arcom's counterpart regulators — French blocking power alone doesn't reach a server in Cyprus or the Netherlands, so Arcom leans on its status as France's DSA Digital Services Coordinator to request cross-border action instead. The remaining five, based in France or outside the EU, received formal observation letters giving them 15 days to explain the absence of verification before a blocking notice follows (macg.co).
The Case Arcom Can Actually Make
It's worth taking the strongest version of the government's case seriously, because there is one. Médiamétrie Netratings data cited by Arcom shows minors' time spent on measured adult sites fell by roughly a third since the enforcement campaign started in early 2025 (journaldugeek.com). That's not nothing. A regulator that forces the largest, most-trafficked platforms to either verify age or exit the market — Aylo pulled Pornhub out of France entirely in June 2025 rather than comply, citing the privacy risk of centralizing government ID checks — has genuinely raised the floor of casual, no-friction access for a 13-year-old with a browser and no VPN. Proportionate child-safety regulation doesn't require solving the problem perfectly; reducing frictionless exposure at scale is a legitimate policy win, and France is one of the only European states willing to spend the political and diplomatic capital of a two-law enforcement architecture to get there.
Why the Model Still Doesn't Close
But the same July 30 announcement that produces the 66-site headline also documents the strategy's structural ceiling. Arcom is now three tiers deep into a whack-a-mole cycle: block the big platforms, watch traffic redistribute to smaller ones, then chase the smaller ones with a slower, letter-first process precisely because they're harder to identify and less worth an EU regulator's cooperation bandwidth. A 15-year-old blocked by DNS-level filtering circumvents it with a free VPN in seconds — a limitation French commentators covering this same announcement flagged directly. The 48-hour blocking window is fast on paper; it is not fast relative to how quickly traffic finds the next unindexed site.
This is where proportionality analysis should bite. Site-by-site blocking imposes real compliance costs on legitimate EU-hosted operators and pushes consumption toward the sites least willing to identify themselves or hold any data responsibly — the opposite of the privacy-protective outcome age-verification advocates want. Aylo's stated objection, that verification should sit at the device or OS layer rather than requiring every individual site to collect identity signals, is not just an industry excuse: centralizing age assurance at fewer, better-audited chokepoints (app stores, OS-level parental controls) would plausibly cut circumvention and reduce the number of entities handling sensitive verification data, compared to forcing dozens of individual sites — many offshore, unaccountable, and now 66 deep — to each build or buy their own check.
Arcom's enforcement posture isn't unreasonable on its own terms, and treating a genuine one-third drop in measured minor engagement as meaningless would be its own kind of strawman. But a policy that requires an ever-expanding blocklist, cross-border DSA diplomacy, and 15-day letters to keep pace with traffic migration is not converging on a solution — it's running to stay in place. The proportionate fix looks less like site number 67 and more like moving verification up the stack, where it has to happen once instead of sixty-six times.