What the Conseil d'État Decided
On 15 July 2026, France's Conseil d'État — the country's highest administrative court — dismissed Cloudflare's challenge to a blocking order issued by ARCOM, France's audiovisual and digital regulator (case no. 509579). The dispute began on 9 July 2025, when ARCOM notified Cloudflare that 19 web addresses distributing content from Russian media entities under EU sanctions had to be made inaccessible from France within 72 hours. Cloudflare refused to comply on its own terms and instead sued, arguing the order was inadequately reasoned, violated its freedom to conduct business and freedom of expression under the EU Charter of Fundamental Rights, and was incompatible with the Digital Services Act (Regulation (EU) 2022/2065). It also asked the court to refer the DSA-compatibility question to the Court of Justice of the EU (CJEU) before ruling. The Conseil d'État rejected every argument, and refused the referral, finding no "serious interpretive difficulty" that Luxembourg needed to resolve.
The Legal Basis: Sanctions, Not Ordinary Content Moderation
This is not a generic hate-speech or disinformation case. The underlying obligation traces back to the EU's direct ban on RT and Sputnik broadcasting, imposed by Council Regulation (EU) 2022/350 on 1 March 2022 under the bloc's Russia sanctions regime (itself grounded in TFEU Article 215). That regulation prohibits not just broadcasting sanctioned Russian outlets but "enabling, facilitating, or otherwise contributing to" their distribution — a standard broad enough to reach infrastructure providers, not just publishers. ARCOM's order to Cloudflare sits downstream of that EU-level prohibition; France is not inventing a new censorship power so much as operationalizing one the EU already legislated in 2022.
Steelmanning ARCOM's Position
There is a real case for what ARCOM did here. EU sanctions on state propaganda outlets are only as effective as their enforcement, and the open, redundant architecture of DNS makes single-point-of-failure blocking trivial to route around: block an ISP's resolver and a sanctioned domain remains one 8.8.8.8 or 1.1.1.1 change away from being fully reachable. If a state cannot reach public DNS resolvers, ISP-level blocking becomes theater — a compliance gesture that does nothing to actually restrict access. The Conseil d'État's finding that Cloudflare already has, and uses elsewhere, geography-based access controls undercuts the claim that compliance was technically infeasible; this was a company with the tools declining to use them, not a company being asked to rebuild its network.
Where the Ruling Overreaches
The more consequential part of the decision is not the sanctions holding — it's the DSA question the court chose not to ask. Cloudflare's argument was that the DSA, as a maximum-harmonization regulation for the EU's digital single market, sets the ceiling as well as the floor for how member states can compel intermediary services to act on content, and that a national regulator ordering a DNS resolver — several technical layers removed from hosting — to block content stretches past what Article 9 of the DSA ("orders to act against illegal content") contemplates. That is a genuinely unsettled question of EU law, precisely the kind the CJEU's preliminary-reference procedure under TFEU Article 267 exists to resolve, so that the DSA means the same thing in Paris, Warsaw, and Dublin. By declining to refer it, the Conseil d'État didn't just decide this case — it left 27 member states free to keep drawing their own lines around infrastructure-layer blocking until some other national court, or the European Commission, forces the issue.
The Precedent Problem
Sanctions enforcement is the easiest case a regulator could bring: the underlying prohibition is EU law, the targets are entities the bloc has already formally designated, and the compliance window (72 hours) was short but not absurd. But the mechanism validated here — a national regulator compelling a recursive DNS resolver, with no prior notice to the content's publisher, to block named addresses — is fully general. Nothing in the court's proportionality reasoning is specific to Russian sanctions; the same logic extends to copyright (French courts have already ordered DNS-level blocking against Google, Cloudflare, and Cisco in piracy disputes), and there's no structural reason it stops at defamation, terrorism content, or whatever the next politically salient category turns out to be. Infrastructure providers make efficient enforcement chokepoints precisely because so few of them exist relative to the sites they resolve — which is exactly why compelling them without a harmonized, EU-wide standard for when that's proportionate is worth worrying about, even when today's application is defensible.
The Bottom Line
We think ARCOM's order was a proportionate response to a real evasion risk, and the Conseil d'État reached the right result on the narrow sanctions question. But a national court expanding blocking obligations onto infrastructure-layer providers, and then declining the one mechanism that would pin down EU-wide limits on that power, is the part of this ruling that should outlast the news cycle. The DSA was supposed to replace a patchwork of national content rules with one framework; refusing referrals like this one is how the patchwork comes back one national ruling at a time.