A loophole closes
On July 15, 2026, France's highest administrative court, the Conseil d'État, rejected a challenge brought by Cloudflare against an order from Arcom, France's audiovisual and digital regulator, requiring the company to block French users' access to websites distributing content from EU-sanctioned Russian media entities (decision n° 509579). The ruling matters less for the 19 addresses originally at issue than for what it settles structurally: technical intermediaries that sit below the ISP layer — DNS resolvers, in Cloudflare's case — are now squarely within Arcom's reach, not just the access providers French regulators have targeted since blocking powers were first introduced.
The underlying dispute began on July 9, 2025, when Arcom notified Cloudflare of 19 electronic addresses distributing content from Russian media organizations subject to European Union sanctions, ordering the company to prevent access from France within 72 hours (Solutions Numériques). By February 2026, Arcom's blocking list had grown to 35 sites plus four streaming platforms (Bbox-Mag). Cloudflare declined to comply with the DNS-level order and took the matter to court.
The case for Arcom's position
Arcom's authority here rests on Article 11 of the 2024 SREN law (Loi n° 2024-449 du 21 mai 2024, full text), which lets the regulator notify internet access providers and DNS operators of addresses to block within a set timeframe, in order to give effect to EU sanctions — without first obtaining a judicial order. That is a genuinely defensible design. EU sanctions against Russian propaganda outlets are adopted at the Council level precisely because member states judged that certain state-linked media were functioning as instruments of an information war accompanying the invasion of Ukraine, not as ordinary journalism. If a sanctioned outlet can trivially route around ISP-level blocking simply by having a DNS provider it does not control resolve its domain, the sanction is hollow. Regulators reasonably argue that enforcement has to follow the infrastructure, wherever it sits in the stack, or determined violators will always find the layer nobody is watching.
The Conseil d'État's proportionality reasoning tracks this logic. The court found that Cloudflare already offers geographic filtering and malware/adult-content blocking as standard product features, undercutting the claim that DNS-level compliance would require disruptive re-engineering, and it noted that other DNS operators — including the world's largest — had complied with comparable orders without apparent difficulty (Univers Freebox). The court also rejected Cloudflare's demand for prior written notice to content editors, holding that when addresses correspond to outlets already designated under EU sanctions law, no additional preliminary process is constitutionally required.
Why the ruling still deserves scrutiny
Even granting the sanctions-enforcement rationale, the mechanism built to serve it is broader than the use case that justifies it. The SREN law's administrative-blocking power — no prior judicial authorization, compliance windows as short as 48-72 hours, judicial review only after the fact — was designed for an emergency category (sanctioned propaganda, CSAM) where speed plausibly outweighs due process costs. Extending that same fast, no-court-first mechanism to the infrastructure layer multiplies its reach without multiplying its safeguards. ISPs blocking at the network edge is one thing; a ruling that DNS resolvers, CDNs, and similar technical intermediaries must build compliance functions into their infrastructure sets a precedent regulators elsewhere — including ones with far less independent judicial review than France's — will cite approvingly.
The court's own proportionality test also does some quiet work that should give pause: it upheld the order partly because Cloudflare already had blocking tools built for other purposes (malware, adult content) and partly because competitors had already complied. That reasoning rewards prior compliance infrastructure with more regulatory obligation, and it treats industry acquiescence as evidence of feasibility rather than as its own separate problem — once enough providers comply, refusal becomes legally impossible to sustain, regardless of whether the compliance burden was reasonable in the first place.
There is also a narrower, practical objection: DNS-level blocking is trivially circumvented by switching resolvers or using a VPN, a limitation the ruling itself does not dispute. Bouygues Telecom subscribers, for instance, have had this blocking applied automatically since 2022 with no operational change from this ruling. The Conseil d'État has expanded the legal map of who must comply, without addressing whether the underlying blocking regime meaningfully advances the sanctions objective it is invoked to justify — a mismatch that a proportionality analysis should weigh, not wave past.
The proportionate path
Sanctions enforcement against propaganda outlets tied to an active war is a legitimate state interest, and Arcom's underlying goal is sound. But administrative-blocking powers built for narrow emergencies should not migrate silently to every layer of internet infrastructure just because the previous layer proved incomplete. France's Parliament, not the Conseil d'État case-by-case, is the right venue to decide whether DNS and CDN operators warrant the same expedited, pre-judicial obligations as ISPs — with matching judicial-review guarantees, not an assumption that existing filtering features settle the proportionality question.