I have spent this week writing a series arguing that the platforms children use are not doing nearly enough about the people hunting them there. Protecting Our Children is three parts in and its position is not subtle. Design decisions made in Menlo Park and Santa Monica have consequences in bedrooms in Basingstoke, and the industry has been allowed to treat those consequences as somebody else's problem for a very long time.
So it is a slightly awkward week to read a court doing something about it and find myself uneasy.
On 16 June the Grand Chamber of the Court of Justice of the European Union handed down a judgment in two joined cases that, between them, involve a pornography company and a speed-camera app. It has taken a month for the implications to be properly digested, and Christoph Schmon, the Electronic Frontier Foundation's international policy director, has now set out the case for alarm. He is right to be alarmed. I want to explain why, and to be honest about the fact that it cuts across what I have been arguing.
Two cases, one judgment
The first case is French age verification. France requires pornography sites to verify that users are adults. XVideos and XNXX, operated by companies established in the Czech Republic, argued that France could not do this to them — under the country-of-origin principle in the e-Commerce Directive, an online service is regulated by the member state it is established in, not by every member state it can be reached from.
The second case is Coyote, the driver-assistance service that warns motorists about speed traps and roadside checks. France restricts rebroadcasting information about police checks. Coyote, established elsewhere, made the same argument.
The Court took both and answered a much larger question than either company asked.
The half that supports my position
On the first question, France won, with a condition attached.
The Court held that these national rules do fall inside the coordinated field — so country-of-origin applies as the default — but that a member state may derogate from it where the measure is necessary on public policy grounds, targeted at a specific service rather than a whole category, and proportionate. It must first ask the state of establishment to act, and it must notify both that state and the Commission. Miss the notification and the measure is unenforceable against the individuals it was aimed at.
In practice: a member state can now reach across a border and compel age verification, provided it does the paperwork and aims at named services rather than legislating at the sector.
That matters. The single most effective defence the adult industry has run for two decades is jurisdictional. Establish in a permissive state, serve the whole bloc, and treat national law as an inconvenience that applies to someone else. That defence has just become considerably weaker, and I am not going to pretend to be sorry about it. I have written reservations about age gates and I stand by every one of them, but the specific proposition that a company can be structurally unreachable by the laws of the country whose children it is serving was never defensible.
Note the trade, though. The price of enforceability is fragmentation. Twenty-seven states can each derogate, individually, against named services. Comply once, comply everywhere is over.
The half that worries me
The second question is the one that will still be being argued about in five years.
To get the hosting liability exemption — Article 14 of the old e-Commerce Directive, carried into Article 6 of the Digital Services Act in near-identical language — a provider has to be a passive conduit for other people's content. Store it, do not adopt it, take it down when you learn it is unlawful, and you are not liable for it. That exemption is the reason the user-generated internet exists in the shape it does.
The Court has now said that where a provider's algorithm determines, in the provider's own interest, under what conditions, how and in which order of priority information is disseminated, the provider is exercising control over that information, and control is incompatible with being a mere host. It added that it makes no difference that the operator does not intervene by hand. Automation does not launder the decision.
The Court did try to leave room. Simple categorisation and indexing that just makes content findable is not control. But everything above that line is now in question, and the line is not where most engineers would think to draw it.
Schmon's objection is the correct one and it is short. Every hosting provider of any scale has some control over how content is arranged. Facebook, Amazon, Bluesky, a recruitment site, a customer review section. If the mere existence of a ranking function is what decides the analysis, then the exemption does not narrow, it evaporates. The disqualifying active role has always been about the content — adopting it, presenting it as your own, exercising intellectual control over it — not about the plumbing that decides what order things appear in. That distinction is what YouTube and Cyando protected, and it is what this judgment blurs.
There is a legislative point underneath that, and it is the part I find hardest to argue past. Stripping immunity from platforms that optimise content was proposed during the DSA negotiations. It was considered and rejected. The DSA instead treats recommender systems as a normal feature of a modern platform and regulates them through transparency and risk-assessment duties, while leaving hosting liability alone. A court has now delivered, by interpretation, roughly the thing the legislature declined to enact.
The trapdoor
Here is the consequence that has had the least attention and, from where I sit, matters most.
Article 15 of the e-Commerce Directive, and Article 8 of the DSA after it, prohibit general monitoring obligations. No member state may require a platform to proactively scan everything passing through it. That prohibition is the single most important structural protection against mass surveillance in European internet law. It is the reason client-side scanning proposals keep running aground.
Read the judgment carefully and that prohibition is not a free-standing right belonging to anyone who operates online. It attaches to services that qualify for the intermediary regime. Commentators have drawn the obvious inference: a provider that exercises algorithmic control is not a hosting service, and a provider that is not a hosting service cannot invoke the protection against being made to monitor everything.
So the safe harbour has a trapdoor in it. Fall out of the exemption and you do not simply land in ordinary liability. You land somewhere with no floor, in a category where a member state may in principle require you to scan the lot.
I want to be fair about the uncertainty here. This is an inference from the judgment's structure rather than something the Court spelled out, other analysts think the DSA's own architecture pulls the other way, and national courts will spend years working out where the line actually sits. It may well be read down. But nobody should be relaxed about a doctrine whose logical endpoint is that the more sophisticated your product, the fewer surveillance protections your users have.
What a rational platform does next
This is the bit that turns a legal question into a security question, which is the only reason I am qualified to write about it at all.
Ask what a general counsel does on Monday morning with a memo that says your ranking algorithm may have cost you the hosting defence. Nobody responds to that by moderating more thoughtfully. Three things happen instead.
Content gets removed on suspicion rather than on assessment, because the cost of a wrong takedown is a complaint and the cost of a wrong retention is now liability. Over-removal is not a side effect of this design, it is the rational response to it.
Scanning infrastructure gets built, because if the protection against general monitoring is uncertain, the prudent move is to be able to demonstrate that you were already looking. Once that capability exists it does not stay confined to the harm that justified it.
And identity infrastructure gets built, because liability at the content layer creates pressure to know who your users are. That is the same pressure the age-assurance debate creates, arriving from a different direction. I have made the point before and it has not improved with age: every one of these architectures ends in somebody holding a very large, very concentrated store of who-is-who, and those stores get breached. Not hypothetically. Routinely.
None of those three outcomes protects a single child. All three cost something real.
The honest scorecard
I am not going to pretend the judgment is simply wrong, because parts of it are the correction I have been asking for.
A service that deliberately tunes amplification to push people towards harm and then hides behind a claim of neutrality is not a passive host in any meaningful sense, and the law was starting to look silly pretending otherwise. The Court is right that automation is a choice, not an absence of one. Somebody built that model, chose that objective function, and knew what it optimised for. "The algorithm did it" has been an unearned defence for years.
And the ruling explicitly preserves specific, circumscribed obligations, targeted at defined categories of harm. That is precisely the design I argued for at the end of the teen internet series: regulate functions rather than brands, and target the mechanism rather than the sector.
The problem is not the direction. It is the width. A test that catches deliberate amplification of child abuse material also catches a marketplace sorting by relevance and a forum showing newest first, and there is nothing in the wording to stop it. Wide rules aimed at bad actors reliably land hardest on the people with the least legal budget. The Com will not notice this ruling. A ten-person British company running a community forum will.
If you run something with user content in it
The practical position, because a number of people reading this sit on boards that are more exposed than they think.
If your service accepts content from users and orders it in any way beyond plain chronology or plain categorisation, the assumption that you are covered by the hosting defence in the EU is no longer safe. That includes review sections, marketplaces, job boards, community forums and support communities, not just the obvious social platforms.
Document how your ranking works, why it was built that way and whose interest it serves. That last question is the one the Court's test actually turns on, and it is the one nobody currently has an answer to in writing.
If you serve both EU and UK users, you now need two analyses of one piece of engineering. The UK sits outside the DSA and outside this judgment, and the Online Safety Act builds its duties on a different foundation. Divergence has stopped being theoretical.
And stop assuming the state of establishment settles the question. On age verification and anything else a member state can bring within public policy, it does not.
Where I land
Both things are true and I am not going to resolve them artificially.
The platforms have had it too easy for too long, children are being harmed on their services at scale, and a liability regime that never bites was never going to change that. I wrote three articles about it this week and I meant them.
And the way you get an accountability regime that works is with a scalpel — specific duties, specific harms, specific mechanisms, tested against how a general counsel will actually behave. What the Court has reached for looks more like a lever, and the thing on the other end of it is the legal basis for scanning everyone.
Schmon is right that this needs reading down, narrowly and quickly, by the national courts that will apply it. I would add only that anyone who spent this month cheering the judgment because it finally makes Big Tech liable should sit with the second half of it for a while. Liability and surveillance are not opposites. They have a habit of arriving in the same delivery.