France's Parliament spent months building what was billed as Europe's toughest child-safety law: a blanket ban on social media access for anyone under 15. On July 21, 2026, the Senate passed the compromise text 243 votes to 2, with 100 abstentions, and the National Assembly concurred the same day. Three weeks later, on August 14, the Conseil constitutionnel threw out the law's central provision. Decision n° 2026-911 DC didn't quibble over drafting details — it found the ban structurally incompatible with the French Constitution's guarantee of freedom of expression and communication, and with the right to privacy under Article 2 of the 1789 Declaration of the Rights of Man.
The case for the ban was not frivolous
Before dismissing this as legislative overreach, it's worth taking seriously why 243 senators voted for it. The bill's sponsors, working from Arcom data showing French 12-to-17-year-olds spend roughly 1 hour 21 minutes a day on TikTok alone, argued that recommendation algorithms optimized for engagement are structurally likely to surface anxiety-inducing and extreme content to a population with underdeveloped impulse control. The stated goals — curbing cyberbullying, screen addiction, and algorithmically amplified harmful content — describe real, documented harms, not moral panic. Age-based restrictions are a normal regulatory tool: France already bars alcohol sales and restricts driving licenses by age without triggering constitutional crises. A legislature responding to parental anxiety about algorithmic platforms is doing exactly what representative government is supposed to do.
Where the law broke down
The Council's objection wasn't to age-based regulation in principle — it was to how sweepingly and bluntly this one was built. Three failures did the law in.
First, scope. Paragraph 12 of the decision notes that the exemptions carved out for platforms like online encyclopedias and educational projects did not extend to "services collaboratifs de partage de contenus" or online games with collaborative features — meaning a ban aimed at Instagram, TikTok, and Snapchat also swept in collaboration tools and multiplayer games that had never been shown to pose the risks the law was designed to address. A law that cannot distinguish a group chat inside an educational game from an algorithmic content feed is not calibrated to the harm it claims to target.
Second, parental discretion. Paragraph 15 found that "ni les dispositions contestées ni aucune autre disposition" gave parents any legal mechanism to lift the prohibition when they judged access to be in their child's interest. The law didn't just override a 14-year-old's judgment — it overrode their parents' too, categorically, with no case-by-case path for families who concluded supervised access served their child better than a blanket cutoff. Paragraph 18 ties this together: the restriction on expression was, in the Council's words, not "adaptée, nécessaire et proportionnée" — not tailored, necessary, or proportionate — because it applied uniformly regardless of a minor's age, maturity, or family circumstances.
Third, and most consequential for the wider European debate: age verification itself. Paragraphs 20-21 hold that requiring every user — including adults — to prove their age before accessing a platform is a privacy-implicating measure that Parliament failed to pair with adequate legal safeguards. This is the part of the ruling that should worry regulators well beyond France. The UK's Online Safety Act, the EU's forthcoming age-verification guidance under the Digital Services Act, and similar U.S. state laws all lean on some form of mandatory age-checking as the enforcement backbone of youth-protection rules. France's top court has now said, in effect, that verification-by-default is not a neutral technical add-on — it's a privacy-rights question that needs its own constitutional justification, not a rider on a content ban.
The proportionate path was available and ignored
The frustrating part is that a narrower version of this law was plainly available. A statute that (a) defined the targeted risk categories with precision — algorithmic recommendation feeds, not collaboration tools generally — (b) preserved a parental-override mechanism, and (c) built privacy-preserving age-assurance (device-level attestation, zero-knowledge age tokens) rather than blanket identity verification would likely have survived review. Regulators in Australia and several U.S. states are already experimenting with exactly these more targeted architectures. France's Parliament instead reached for the broadest instrument available and got the outcome that broad instruments aimed at speech usually get from a constitutional court: a comprehensive strike-down that resets the clock to zero rather than a narrowing amendment.
What happens now
The political appetite for a sequel hasn't disappeared — French media report Emmanuel Macron has directed Prime Minister Sébastien Lecornu to draft a version that accounts for the Council's reasoning and for the EU's own age-verification framework, positioning this as unfinished business rather than a dead issue. That is the right instinct, and the ruling actually hands Paris a design brief: narrow the scope to services with documented algorithmic risk, restore parental discretion, and separate age-assurance from mandatory identity disclosure. A law built to that spec would do more to protect the minors regulators are worried about than the one just struck down — because it would survive.
For the rest of Europe watching Brussels debate DSA-linked age-verification guidance, the lesson isn't that child-safety regulation is constitutionally impossible. It's that a court will not wave through prohibition-sized restrictions on speech just because the stated purpose is protecting children, and it will treat mandatory age verification as a privacy question in its own right, deserving its own proportionality analysis — not a rounding error attached to a ban.