field note / 2026 / france + social-media A legislative implementation desk with the final French social-media bill, an age-assurance flowchart, a phone test rig, school policy folders, and marked-up DSA pages tracing the missing enforcement path.

field dossier

France Banned Under-15s From Social Media Without Building the Gate

The French Parliament passed a clean prohibition and stripped out the machinery that once made it legible: platform duties, an ARCOM age-control standard, parental authorization, and a defined verification path.

France passed an under-15 social-media ban on July 21. The final text is beautifully blunt: access to an online social-network service “is prohibited to minors under fifteen.” It takes effect September 1, with existing accounts given four additional months. Online encyclopedias, educational or scientific directories, and open-source educational project platforms are exempt.

Then the machinery disappears.

The final cross-party compromise contains no French age-verification standard, no direct duty for platforms to block registration, no penalty for failing to detect a child, and no parental authorization path. Parliament declared the state it wants. Identity proof, account discovery, enforcement, appeals, and deletion still have to happen somewhere else.

This is a materially new development from my July 10 piece on how addictive design became a platform compliance surface. That case pulled feed mechanics inside the EU’s Digital Services Act risk regime. France has now made the user’s age a legal access boundary, while leaving the gate distributed across European law and infrastructure that the statute never names.

The first bill had an enforcement machine

The original November 2025 proposal was much easier to understand as software policy. According to the Council of State’s January opinion, social platforms operating in France would have been required to refuse registration to children under 15. They would have used age-control systems conforming to an ARCOM reference standard. Failure could bring a fine and an injunction from the president of the Paris judicial court.

The proposal also carried a digital curfew. Accounts belonging to users aged 15 through 17 would have been disabled automatically between 10 p.m. and 8 a.m., using the same age-control machinery. Whatever one thinks of that policy, the control path was explicit: platform registration, age check, regulator standard, court-backed enforcement.

That architecture collided with the EU’s harmonized platform rules. The Council of State warned that France could run into the Digital Services Act by imposing extra obligations directly on social networks. Its jurisdictional fix was clever and deeply weird: move the legal obligation from the platform to the child.

The suggested sentence became the final law. A minor under 15 is prohibited from accessing a social network. The Council reasoned that this turns underage access into an illegal activity under national law. The DSA can then supply its existing machinery around platform knowledge, orders to act, complaints, national regulator action, and European Commission enforcement.

France can define an unlawful activity. Brussels controls much of the platform-duty layer. The resulting statute looks simple because the complexity has been pushed across the border between them.

The operating system was supposed to become the checkpoint

The Council of State did not stop at wordplay. It proposed a technical route designed to avoid adding forbidden platform obligations. Parental authorization could be handled by controls installed on the operating systems of internet-connected devices distributed by access providers. The authorization would verify the user’s age and the identity of the parent granting permission. Facial recognition was explicitly excluded.

That proposal would have moved age assurance below the app layer. Apple, Google, Microsoft, device vendors, access providers, identity issuers, and family-account systems would become part of the enforcement substrate. A parent could authorize categories of use, preserve private messaging, set a daily duration, and revoke permission. Dangerous social networks designated by decree could still be blocked absolutely.

The final compromise kept none of it. Article 1 says who may not enter. It says nothing about who checks the door.

That omission matters because age is hidden state on the internet. A birthday typed into a form proves almost nothing. Document checks pull passports and identity providers into ordinary speech and association. Face estimation creates biometric error and surveillance risk. Device-level family controls miss shared devices, alternative clients, web access, and children with the technical sophistication required to change a DNS setting. Existing accounts are worse: a platform has to find people who may have lied years ago, then decide what happens to their posts, messages, purchases, communities, and personal data.

The law gives existing accounts until January 2027. Four months is a deadline, not a discovery protocol.

A ban assembled from indirect pressure

The legislative dossier shows how much was removed on the way to passage. The first proposal had seven articles. The final compromise has an access ban, a narrow criminal-code update around suicide-method propaganda, digital-health education duties, and an extension of phone restrictions into high schools. Proposed curfew and authorization provisions vanished. Several articles are simply marked deleted.

The remaining enforcement theory relies on a relay. France defines the activity as illegal. A platform somehow learns that an account belongs to a child under 15. DSA procedures make that knowledge actionable. ARCOM or the Commission can use their authority. The platform blocks access, handles complaints, and eventually terminates or preserves the account under rules that still need operational detail.

Each hop can work in isolation. Together they form a brittle chain. A notice-and-action regime normally starts with a visible object: a post, listing, account behavior, or other reportable artifact. Age is a private attribute. The regulator needs evidence before issuing an order. The platform needs a lawful method to collect or infer that evidence. The child needs an appeal when the classifier, document service, parent account, or database is wrong. Nobody gets to skip identity governance because the statute used one clean sentence.

The Associated Press report published by NPR captures the immediate implementation hole. Ines Legendre of the child-protection group e-Enfance asks how existing under-15 accounts will be identified and suspended, then points to age verification for new accounts. Opposition lawmakers warned about constitutionality, enforcement, and the practical end of online anonymity. A constitutional review could still delay the September start.

Those objections should not be waved away as platform lobbying. A state can protect children and still build a terrible identity system. The same verifier that keeps a 14-year-old out of TikTok can become the credential demanded by forums, political groups, sexuality resources, health communities, game servers, and every service that fears regulatory exposure. Function creep loves a noble origin story.

The school rule is more executable

The other major piece of the law extends phone restrictions to high schools. Schools already have buildings, rosters, staff, schedules, disciplinary procedures, and local rulebooks. The law lets each institution define implementation and exceptions through its internal regulations. Higher-education students attending courses inside a high school can receive special treatment.

That control surface is legible. A teacher can see a phone. A school can store it, return it, document an exception, and hear a complaint. Enforcement can still be arbitrary or stupid, but the institution exists in the same place as the behavior.

The social-media ban operates across foreign platforms, app stores, browsers, device accounts, VPNs, identity services, regulators, parents, and children. Parliament owns only one part of that stack: the declaration.

The cultural boundary moved anyway

The law will matter even if enforcement arrives late or unevenly. Product counsel will model the risk. Platforms will revisit teen-account defaults and age-assurance vendors. Schools and parents will treat September as a new baseline. The Commission will face pressure to turn DSA child-safety guidance into an executable cross-platform regime. Smaller communities will wonder whether their forums count as social networks or exempt open educational projects.

A symbolic law can still rearrange infrastructure by changing who expects a gate to exist.

That makes France’s move consequential and dangerous in the same breath. The country has established a hard political boundary around childhood and social media. It has also created demand for an age credential that works across unrelated services without becoming a universal identity card. The market will happily sell ten bad versions before public institutions specify one defensible version.

The sane implementation target is selective proof: enough evidence to establish an age band, minimal disclosure, no reusable face template, no document copy retained by the platform, independent audits, revocation, appeals, and strict limits on secondary use. The verifier should reveal “over 15” rather than a birthday, name, address, or government identifier. Existing account deletion needs export and preservation rules. Appeals need human ownership. Exemptions need criteria that do not punish small forums for lacking lawyers.

France passed the political sentence first. Europe now has to write the protocol.