The ruling
On July 17, 2026, the Fourth Section of Italy's Regional Administrative Court for Lazio (TAR Lazio) issued judgment no. 13201/2026, rejecting in full Cloudflare's challenge to AGCOM's blocking order (delibera n. 49/25/CONS) and the roughly €14.2 million sanction that followed it (ordinanza-ingiunzione n. 333/25/CONS, notified January 8, 2026). The fine — about 1% of Cloudflare's global revenue — punished the company's refusal to block more than 15,000 domains and IP addresses flagged through Piracy Shield, Italy's automated blocking platform for live sports broadcasts. AGCOM says Piracy Shield, operational since February 1, 2024, has disabled more than 65,000 FQDNs and roughly 14,000 IP addresses to date (AGCOM press release).
Cloudflare's core defense was jurisdictional. Because its EU legal representative under the Digital Services Act is established in Portugal, the company argued Portugal's regulator, Anacom, held exclusive competence to police its compliance — the DSA's country-of-origin coordination model, set out in Articles 13 and 56. TAR Lazio rejected that argument outright. The court distinguished DSA-coordinated supervision of procedural obligations, where country-of-origin applies, from the underlying power to order content blocking, which it held Article 2(3) of Italy's 2023 anti-piracy law (Law no. 93/2023) grants AGCOM directly against providers "wherever resident and wherever located." Blocking authority, the court reasoned, isn't a DSA creature at all — the DSA declines to harmonize member states' content-blocking powers — so the DSA's jurisdictional map doesn't govern it. What controls is where the infringement's effects land: Italian users, Italian rightsholders, Italian market harm (Studio Previti legal analysis).
The case for AGCOM
Steelmanned, this isn't a regulator grasping for power it lacks. Live sports piracy is a genuinely hard enforcement problem: a blocking order issued after a match has ended is worthless, and infringing streams are increasingly fronted by CDN and DNS infrastructure sitting several layers removed from the actual pirate site. If an EU compliance address in Lisbon were enough to shield a company's Italy-facing infrastructure decisions from Italian enforcement, routing legal representation through whichever member state runs the lightest oversight would become a standard strategy for platforms adjacent to piracy, not just for pirates themselves. Studio Previti's review of the ruling notes the court found Piracy Shield processed over 119,000 blocking requests with a 0.0059% error rate — evidence, in the judges' view, that the feared overblocking never materialized at scale. A regulator that can only chase storefronts and never the infrastructure layer underneath them is playing permanent catch-up.
Why the ruling still worries platform lawyers
"Piracy Shield has fundamental flaws with respect to European Union law" — Cloudflare, responding to the ruling (TorrentFreak)
None of that resolves the harder problem TAR Lazio's effects-based test creates: if legal establishment doesn't matter and only downstream effect does, every one of the EU's 27 national regulators can plausibly claim jurisdiction over any infrastructure provider whose network is reachable from its territory — which, for a global CDN or DNS resolver, is every regulator, everywhere. That is precisely the fragmentation the DSA's one-home-regulator model was designed to prevent. If Italy can bypass country-of-origin coordination for blocking orders specifically, Germany, France, or Poland can build the same carve-out into their own anti-piracy regimes, each with its own thresholds and its own multi-million-euro penalty schedule. Cloudflare's separate objection sharpens the stakes: the company says AGCOM calculated the fine against its global revenue rather than the 2%-of-Italian-revenue cap it reads into the statute — inflating the penalty roughly 100-fold from its own estimate of about €140,000 (Cloudflare blog). A jurisdictional theory broad enough to reach any provider anywhere pairs naturally with a fine calculated against that provider's entire worldwide balance sheet, not its footprint in the regulating country.
What's next
This is a first-instance decision. Cloudflare has said it will appeal to the Consiglio di Stato, Italy's top administrative court, calling the ruling "deeply disappointing" and reiterating that Piracy Shield lacks the procedural safeguards the DSA requires for content restrictions. Until that appeal resolves, Italy has established at trial-court level that a member state can order blocking against infrastructure providers with no Italian establishment and enforce that order with fines sized to global, not local, revenue. Live-sports piracy is real and largely unsympathetic, and AGCOM's speed-of-blocking rationale is legitimate. But a jurisdictional theory this expansive, if it survives appeal and gets copied elsewhere, trades a genuine enforcement gain for a much larger structural cost: a DSA landscape where global infrastructure providers face 27 potential blocking regimes instead of one coordinated one. Proportionate regulation should scale enforcement to the harm; a rule letting any member state fine any provider on worldwide revenue for infrastructure decisions made outside its borders does not obviously clear that bar.