A narrow ruling, not a rejection of the idea
On August 14, 2026, France's Conseil constitutionnel issued Decision n° 2026-911 DC, striking down Article 1 of a law that would have barred anyone under 15 from social media platforms, with a conditional carve-out for 13-to-15-year-olds who had explicit parental consent. The press release is unambiguous about why: the provisions "disproportionately infringe upon the freedom of expression and communication" and "fail to provide the legal safeguards necessary to ensure the right to respect for private life." Crucially, the Council examined only Article 1 — the rest of the law, and the underlying policy goal, remain untouched. President Macron has already tasked Prime Minister Sébastien Lecornu with drafting a revised, "legally robust" version before spring 2027, according to reporting on the Élysée's response.
This matters because it is not a defeat for the idea of protecting minors online. It is a textbook proportionality ruling, and a fairly instructive one for every government now drafting similar rules.
The steelman: there is a real problem here
The case for restricting under-15 access to social platforms is not frivolous. Youth mental health researchers have documented associations between heavy social media use and adolescent anxiety and sleep disruption; platforms' own recommender systems are optimized for engagement, not wellbeing; and parents genuinely lack tools to verify what their children are exposed to. France's National Assembly passed this bill on those grounds, and Australia moved first with its own under-16 restriction, which took effect in December 2025. A legislature acting on that evidence is not acting irrationally, and the Council did not say otherwise — it said the specific instrument chosen went further than necessary.
Why the court drew the line where it did
The decision's reasoning, laid out in paragraphs 11 through 18 of the full text, turns on two distinct defects. First, the ban applied uniformly to "numerous online services... whose risks for minors' health and safety... are not established," with no mechanism for a parent to authorize access based on "the minor's age, maturity, or family situation." A blanket rule that cannot distinguish a moderated messaging app from an algorithmic feed, the Council held, is not a proportionate response to a risk that varies enormously by service design.
Second — and this is the part every other regulator drafting age-verification rules should read closely — the law required every user, including adults, to prove their age before accessing a platform, but never specified how that verification would work, what data it would collect, or how that data would be protected. The Council found this left "no legal guarantees" for privacy rights that the law itself put at risk. In other words: you cannot mandate identity-adjacent verification for an entire national user base and leave the privacy architecture to be worked out later by the platforms.
That second finding tracks what France's own data protection authority had already been saying. CNIL's guidance on age verification concludes that no current verification method satisfies all three of reliability, full population coverage, and privacy protection at once — and warns that identity-linked verification schemes create a new privacy risk by binding a person's identity to their browsing activity. CNIL has been piloting zero-knowledge-proof approaches that could confirm someone is over or under an age threshold without revealing who they are, precisely because it does not trust identity-based verification to stay contained.
Australia is the live experiment, and the early data is not encouraging
France was set to become the first EU country to follow Australia's under-16 ban, which took effect in December 2025. The results so far are a caution against assuming a ban plus a verification mandate straightforwardly works. Tech Policy Press reports that more than 4.7 million accounts assessed as belonging to under-16s were removed, deactivated, or restricted as of mid-January 2026 — a large enforcement number — but that compliance gaps persisted because platforms had not deployed verification checks against existing accounts, and some users regained access simply by re-declaring their age. Parental surveys cited in the same reporting found roughly 70% of parents said their children still held a Facebook, Instagram, Snapchat, or TikTok account, and the regulator reported no clear decline in cyberbullying or image-based-abuse complaints from under-16 users since the ban took effect. The headline enforcement statistic and the on-the-ground outcome are not the same thing.
The proportionate path forward
None of this means age-appropriate design rules are pointless — the EU's Digital Services Act already requires platforms accessible to minors to assess and mitigate risks to them, without a blanket access ban or a national identity-verification mandate. A revised French law that differentiates by service risk, preserves a parental-discretion channel, and builds age assurance on CNIL's minimization principles — third-party verification, no biometric or identity retention, proportionate to the actual risk of the service — would likely survive the same constitutional test that just failed. The Council has effectively handed the government a checklist. Whether the spring 2027 version follows it, or reaches again for a blunter instrument now that account-removal numbers photograph well, is the real story to watch.