On August 14, 2026, France's Conseil constitutionnel struck down Article 1 of the law barring under-15s from social media. In Decision No. 2026-911 DC, it censured that article, which had been due to take effect in January 2027, according to the EFF's account of the ruling. The decision is a constitutional reset, and it also clarifies who should police minors' safety online: a national regulator applying a harmonised European framework, not a blanket national prohibition.
The strongest case for the ban
The case for the law deserves a fair statement. Parents and legislators saw platforms designed to maximise engagement, and they saw evidence from a parliamentary inquiry into TikTok's effects on minors. Voluntary measures and incremental duties looked slow against those harms. A clear age line, they argued, is easy to explain and hard to game through corporate design choices. The Council itself accepted the premise: it treated child welfare and the prevention of harm as valid constitutional objectives, according to its press release on the decision.
Why the Council still struck it down
The Council's objection was to the means. On freedom of expression, it recalled that this liberty is a condition of democracy and that restrictions must be necessary, adapted and proportionate. The blanket prohibition applied across services without regard to their risk profile. As the EFF summarises the decision, it did not distinguish between service types or account for a minor's age, maturity or family situation.
The second holding may matter more for the wider policy debate. A ban is only enforceable if every user, adults included, proves their age. The Council found that the legislature had not set conditions and limits for age verification, and so had left no safeguards for the right to private life protected by Article 2 of the 1789 Declaration. The Council's press release frames the flaw as a missing legal framework, not a ban on age assurance in every form. That distinction matters for anyone reading the ruling as the end of age checks in France.
The DSA problem the Council did not need to reach
There was a second vulnerability. According to The Conversation's analysis, the Digital Services Act operates under maximum harmonisation, so a member state cannot add obligations for platforms within its scope. The same analysis reports that the European Commission delivered a detailed opinion on July 6, 2026, finding that the French law encroached on the DSA's coordinated framework. The Council's ruling rested on constitutional grounds, so it did not have to resolve that conflict. A redrafted law would still have to.
What ARCOM and the DSA already provide
France is not starting from zero. ARCOM is France's Digital Services Coordinator, designated under the 2024 SREN Act, and it works with national and European authorities on DSA implementation. It has enforcement experience in the hardest case, age verification for pornographic sites. It adopted technical guidelines for age verification in October 2024 after the data protection authority, CNIL, issued a favourable opinion on the standard on September 26, 2024. That sequence, with a regulator setting minimum technical requirements after privacy review, is the type of safeguard the Council found missing from the ban.
At EU level, the Commission's Article 28 guidelines on the protection of minors, published on July 14, 2025, ask platforms to use age assurance methods that are accurate, reliable, robust, non-intrusive and non-discriminatory. They distinguish age verification, for adult content, from age estimation for other identified risks. They also call for privacy-by-design defaults, such as private accounts for minors. Following the guidelines is voluntary and does not guarantee compliance, but they will inform how the Commission assesses Article 28(1).
A proportionate way forward
The policy lesson is that risk should be regulated where it arises. The Conversation's analysis suggests neutralising toxic functionalities for all users and modulating access by age, in line with the Commission's security-by-design approach, and it argues that a European-coordinated response is needed to make platforms comply. The EFF reports that President Macron has asked Prime Minister Lecornu to redraft legally robust legislation.
From a pro-innovation, pro-speech standpoint, three principles should guide that redraft:
- Target features, not services. Recommendation loops, autoplay and contact-from-strangers defaults are where harm concentrates. Collaborative and educational services were never the problem, yet the ban's breadth could have reached them.
- Put safeguards in statute. Any age assurance must come with purpose limitation, data minimisation and a role for CNIL. Requiring adults to prove their age to read or post online is a privacy cost that the Council has now said needs explicit limits.
- Work within the DSA. National rules that conflict with a maximum-harmonisation regime invite the Commission's objections and legal uncertainty for smaller European services that cannot absorb fragmented compliance costs.
There is a real risk that this is read as a licence for inaction. It is not. The Council endorsed the objective and rejected a blunt instrument. ARCOM has a track record of enforcing age rules through consultation and technical standards, and the DSA gives it and the Commission tools against platform design that harms minors. Enforcement capacity, not prohibition, is what will determine whether children are safer in January 2027.
What to watch
Watch whether the redraft is rooted in DSA-compatible duties on platform design, and whether it places age assurance under a statutory privacy framework with CNIL involvement. The alternative, a second sweeping ban with slightly narrower wording, would likely repeat the constitutional and EU-law problems within a year.