Italy Italy AGCOM platform regulation DSA

TAR Lazio's Cloudflare Ruling Lets Italy Regulate the Global Internet From Rome

An Italian court upheld a €14M fine on Cloudflare and ruled AGCOM can order blocks against DNS providers 'wherever resident,' regardless of EU one-stop-shop rules.

Cloudflare v. AGCOM, by the Numbers People of Internet Research · Italy €14.2M Fine upheld by TAR Lazio About 1% of Cloudflare's global re… 15,000+ Network resources ordered blocked Domains and IPs Cloudflare was ord… 30 minutes Piracy Shield blocking deadline Maximum time providers get to disa… ~€140K Fine if capped at Italian revenue What Cloudflare says the penalty s… peopleofinternet.com
Cloudflare v. AGCOM, by the Numbers People of Internet Research · Italy €14.2M Fine upheld by TAR Lazio 15,000+ Network resources ordered blocked 30 minutes Piracy Shield blocking deadline ~€140K Fine if capped at Italian revenue peopleofinternet.com

Key Takeaways

A Fine, and a Jurisdictional Claim, Both Confirmed

On July 17, 2026, the Lazio Regional Administrative Court (TAR Lazio) issued sentenza n. 13201/2026, rejecting Cloudflare's appeals and upholding AGCOM's €14 million fine for non-compliance with Italy's Piracy Shield blocking system (Digital-News.it; ANSA). The ruling did two things at once: it confirmed the penalty amount, and it endorsed AGCOM's claim to jurisdiction over foreign infrastructure providers "wherever resident and wherever located." That second part is the one that should worry anyone who relies on global internet infrastructure headquartered outside Italy.

What AGCOM Actually Found

The fine traces back to a February 2025 AGCOM order (delibera n. 49/25/CONS) requiring Cloudflare to disable DNS resolution and reroute traffic away from more than 15,000 network resources flagged as distributing pirated live sports broadcasts through Piracy Shield, Italy's automated blocking platform created under Law 93/2023 (Gazzetta Ufficiale). AGCOM determined Cloudflare simply didn't comply, and on December 29, 2025 imposed a penalty of roughly 1% of Cloudflare's global revenue — about €14.2 million — under a statute capping fines at 2% (AGCOM press release). The regulator justified going after global rather than Italian-market revenue by pointing to Cloudflare's scale: it said the company's infrastructure was linked to roughly 70% of the pirate sites targeted under the regime (TorrentFreak).

There's a real case for that framing. Piracy Shield exists because live sports piracy is a genuine, fast-moving harm to rightsholders — a pirated stream that isn't blocked within the 30-minute window Italian law demands is worthless as an enforcement tool, since the match is already over. Regulators are also right that a company with Cloudflare's technical sophistication and global reach can't credibly claim it lacks the capacity to build targeted blocking tools; if the penalty were capped at Italian-only revenue (roughly €140,000, on Cloudflare's own math), it would be a rounding error for a company of Cloudflare's size and would function as a licensing fee for defiance rather than a deterrent.

Where the Ruling Overreaches

But proportionality and jurisdiction are separate questions, and TAR Lazio's answer to the second one is the more consequential holding. Cloudflare argued that under the EU's Digital Services Act, oversight of its DNS resolver service belonged to Portugal's regulator (Anacom), where Cloudflare's EU establishment sits — the DSA's whole architecture is built around a country-of-origin "one-stop shop" so platforms face one lead regulator, not 27. TAR Lazio rejected that outright, holding that what matters is where the infringement's effects land, not where the company is domiciled, and that Italy's anti-piracy statute independently empowers AGCOM to act against "service providers involved, including VPN and DNS suppliers, wherever resident and wherever located" (Digital-News.it).

That's a broad claim for a national regulator to make about extraterritorial reach over infrastructure that serves the entire internet, not just Italian users. Cloudflare's 1.1.1.1 is a public DNS resolver used globally; filtering it at the DNS layer for Italian piracy targets risks blocking or degrading resolution for users far outside Italy who happen to route through the same anycast network. The European Commission itself flagged concerns about Piracy Shield's lack of judicial oversight and due process in a June 2025 letter, and a University of Twente study cited by Cloudflare found the system "routinely blocks legitimate websites for months at a time" (Cloudflare). None of that is addressed by insisting AGCOM's writ runs everywhere a DNS query might resolve.

The DSA Coordination Problem

This ruling arrives alongside a wider EU pattern of national regulators and courts stretching platform-liability doctrine in ways that create collateral damage for lawful expression and services, a dynamic the EFF has separately warned about following a July 2026 CJEU ruling on platform liability (EFF). If every member state can claim jurisdiction over infrastructure providers based purely on where harm is felt, the DSA's one-stop-shop model — designed precisely to prevent 27 overlapping national enforcement regimes — becomes optional. That's a worse outcome for smaller providers who can't absorb multi-jurisdiction compliance costs the way Cloudflare can, and it undermines the predictability the DSA was supposed to deliver to the whole EU digital single market.

What Comes Next

This is a first-instance ruling; Cloudflare has said it will appeal to the Council of State, Italy's highest administrative court (ANSA). CEO Matthew Prince has threatened to pull cybersecurity support for Italian venues during the upcoming Winter Olympics and scale back Italian investment if the fine stands (TorrentFreak) — a threat that reads as leverage but underscores the real stakes for Italian users if infrastructure providers start treating Italian jurisdiction as too costly to serve. The Council of State should uphold the penalty as a proportionate response to demonstrated non-compliance, while narrowing the jurisdictional holding to avoid inviting every EU member state to relitigate the DSA's coordination framework one national court ruling at a time.

Sources & Citations

  1. AGCOM press release on Cloudflare fine
  2. Law 93/2023, Gazzetta Ufficiale
  3. ANSA: TAR confirms AGCOM maxi-fine on Cloudflare
  4. Digital-News.it: TAR Lazio confirms AGCOM sanction
  5. TorrentFreak: Italy fines Cloudflare €14M
  6. Cloudflare: Standing up for the open internet
  7. EFF: New CJEU ruling on platform liability