Courts & Litigation Surveillance & Privacy

Zombie Formalism in Luxembourg

Michael FitzGerald
Thursday, September 17, 2026, 2:00 PM
A CJEU ruling on driving-app data and online pornography quietly guts the EU's Section 230 equivalent—and the court owes Europe an explanation it hasn't given.
Flags of the European Union in front of the EU-commission building "Berlaymont" in Brussels, Belgium (Christian Lue, https://unsplash.com/photos/blue-flag-on-pole-near-building-C241mbgtgys; Unsplash License)

On June 16, 2026, the Court of Justice of the European Union (CJEU) handed down a controversial judgment in Coyote System v. Ministre de l’Intérieur et des Outre-mer (Coyote System), a case that concerned a challenge brought by a French driving assistance app against a provision of the French Road Traffic Code. The decision prohibited the rebroadcasting of user-generated content that might facilitate drivers to evade police checkpoints.

“Controversial” might be an understatement. The CJEU is the highest court of the European Union and though it does not hear appeals from national European courts, and rules instead by clarifying abstract questions of EU law, its judgments have a gravity and weight not dissimilar to a Supreme Court ruling in the United States. Taken on its face, the Coyote System ruling eviscerates Europe’s equivalent of Section 230(c)(1) of the Communications Decency Act (Section 230): the online hosting “safe harbor” contained in Article 14 of the E-Commerce Directive which has protected internet service providers in the EU since 2000, including digital platforms, by providing them with a conditional exemption from liability for illegal content posted by their users.

Platforms are no longer intermediaries at European law. The CJEU’s judgment in Coyote System—read literally—demolishes the EU’s intermediary liability safe harbor, and it does so without explaining why. Early commentary on the ruling, such as that from Robert Spano, former president of the European Court of Human Rights, suggests treating the ruling as an unforced error, subject to correction. This interpretation itself would be an unforced error. Instead, Europe should presume the CJEU means what it says and come to grips with the deeper institutional culture the judgment exemplifies: an anachronistic formalism no longer fit for a democratizing legal order.

Porn and Police Checkpoints

The judgment arose from two joined disputes (Coyote System and Webgroup) referred by the Conseil d’État, France’s highest administrative law court. In the first dispute, a Czech pornography website operator called WebGroup sought the annulment of a French law criminalizing the provision of porn websites without adequate age verification. The second dispute concerned a French company called Coyote System that provides a “driving assistance” app called Coyote which describes itself as a “community app” intended to guide drivers and alert them “in real time about dangers on the road.” Coyote System challenged a decree prohibiting such providers from distributing user content which might allow drivers to evade roadside police checkpoints. The cases reached the CJEU through the “preliminary reference” mechanism whereby national courts seek clarification on the interpretation of EU law. The Conseil d’État submitted six questions on the E-Commerce Directive’s relationship to national law.

Most of these questions produced no real legal novelty. The judgment’s first 82 paragraphs reaffirm established doctrine—namely, the principles of ‘home state control’ and ‘mutual recognition’—with the result that France could not require porn websites generally to install age verification, but could, within reason and within the bounds set by EU law, require an individual service to do so.

Knowledge and Control

The main significance of the ruling came in the final 19 paragraphs in which the Court tackled a question of intermediary liability that arose in the dispute concerning Coyote System. An aspect of that dispute related to a rule in Article 15 of the E-Commerce Directive whereby Member States are prohibited from imposing general obligations on intermediary service providers to monitor for illegal content or activity online. Because the applicability of this rule rests upon the prior characterization of the service in question as an ‘intermediary hosting service’, the dispute required the European Court to re-examine the conditions on which internet services can claim protection under the EU’s exemption from intermediary liability claims.

It was in reconsidering this characterization that the Court held that “where, by means of an algorithm, the operator…determines, in its own interest or that of its service, under what conditions, how and in which order of priority that information is or is not broadcast as part of that service, it exercises control over that information.”

The word “control” had featured in the Court’s prior case law, but it had been fused to the higher bar of the Court’s established ‘knowledge’ standard. Coyote System emphasized their separation and distinctness for the first time: the “two conditions requiring knowledge and control,” the Court held, “should be understood as being alternative to and independent of each other.” Where previously ‘knowledge’ (or, the related notion of ‘awareness’) was required to rescind platform immunity, after Coyote System, an operator that exercises algorithmic ‘control’ over user content—regardless of what it knows—can no longer be deemed an intermediary for European law and cannot avail of protection from liability regarding the illegal user content it carries.

What Would This Mean if it Happened in the U.S.?

Though the EU regime does not provide Section 230’s absolute immunity—or use the vocabulary of publisher/speaker—but instead provides a conditional shield against whatever form of liability (excluding injunctions) that an EU Member State might otherwise wish to impose on an intermediary, a brief illustration by analogy to the U.S. context will underline how far the European Court has gone in this ruling. The closest thing to an American Coyote System would have been if the Supreme Court had decided Gonzalez v. Google differently, and had addressed the question of whether Section 230 protects interactive computer services when they make targeted recommendations of third-party content, and answered no. 

But Coyote System’s dismantling of the European equivalent to Section 230 is in a different galaxy even than this hypothetical Gonzalez. In remanding Gonzalez, the Court left the ordinary function of Section 230 undisturbed, and declined to answer the main issue which regarded the narrower question of whether a platform might be held liable for the targeted recommendation itself, as a form of own-content provision, as distinct from being exposed to liability as publisher/speaker in respect of the content of the individual posts to which the recommendations related. Coyote System, by contrast, attacked the exemption’s ordinary function, removing its protection from a broad class of service providers. It would be as if algorithmically-driven platforms were no longer interactive computer services per Section 230.

The Road Not Taken… Again

The Coyote System judgment does not concern the more nuanced question of whether the algorithm itself manifests a form of own-content creation, which should be outside the scope of the relevant statutory immunity which would remain applicable to each individual user post. Though the case could have been read to relate to this narrower question: Indeed, the Court’s own advocate general—a kind of in-house amicus curiae who delivers a non-binding, impartial opinion before the Court rules in important cases—noted that the case could be interpreted more narrowly. He observed that, though users of the Coyote app press icons to report various categories of traffic events, the app’s algorithm removes duplications and disputed reports, providing a managed picture based upon the initial user reports. For the advocate general, the algorithmic management displaces and supersedes, if perhaps a bit tenuously, the intermediary activity inherent in transmitting the initial user reports, placing the service at issue outside of the protection of the EU intermediary liability exemption. The algorithm creates a “new corpus of information in which the information provided by users is no longer identifiable,” according to the advocate general.

Just as it did recently in Russmedia v. X (Russmedia), another Grand Chamber ruling in which the Court controversially limited the EU’s intermediary liability protections, examined in more detail below, the Court ignored the advocate general’s suggestion that the intermediary liability issue could be managed by thus recognizing the particularities of the service, however. The more extreme position, expounded in the Court’s judgment, holds that the use of an algorithmic ordering system means that the service concerned is no longer intermediary. This means that intermediaries that use algorithms are now exposed to potential criminal liability and civil damages claims throughout Europe in respect of any illegal user-generated content hosted through their platforms unless they employ a plain chronological feed—whatever this might look like in today’s platform economy. On the best literal interpretation, the paradigmatic intermediaries—the platforms—are no longer intermediaries at European law, at least as regards the user content they host and distribute. For that content, they are exposed to whatever characterization, as publisher or otherwise, might secure liability in the national context.

This liability exposure is not confined to European companies, and equally affects the foreign services which provide, according to the 2024 European competitiveness report of former President of the European Central Bank Mario Draghi, over 80 percent of Europe’s “digital products, services, infrastructure and intellectual property.” European national courts have long asserted both civil and criminal jurisdiction over harms arising from internet services directed toward Europeans by companies incorporated elsewhere.

The End of Immunity?

Read literally, Coyote System is existential for the existing European intermediary liability framework. In an blog post published soon after the ruling was handed down, Lorna Woods, professor emerita of internet law at the University of Essex, asks whether the case represents “The End of Immunity for Internet Service Providers?” Woods leaves the question open, but Betteridge's law of headlines—that any headline ending in a question mark can be answered by the word “no”—points toward some caveats: first, the immunity still exists on the books, and it is still applicable to protect a whole range of internet services which do not use algorithms to arrange the user content they host, including cloud storage services like Dropbox, email providers, Wikipedia.

Second, there is uncertainty concerning the expiry of the legal provisions at issue: One interpretation, discussed by Woods, would be to treat Coyote System as relevant only to the jurisprudence of the E-Commerce Directive which is currently in the process of being supplanted by the Digital Services Act (DSA) as regards questions of intermediary liability. In this reading, Coyote System should be understood, in Woods’s phrase, as “just a transient discussion, fading away as the [DSA] becomes the relevant law.”

The Court in Coyote System failed to illuminate the finding’s relation to the DSA as it takes precedence to govern intermediary liability disputes. But the idea of splitting the DSA off from the Directive case law seems highly unusual to anyone familiar with the territory because it will require interpretations which do not make sense. The DSA explicitly underlines in Recital 16 that, owing to the legislator’s satisfaction with the conditional liability exemption system, the ‘framework should be preserved’ and clarified ‘having regard to the case-law of the Court of Justice’. Indeed, until now, as Woods puts it, “it has been assumed given the similarity in the text, that the case law on Article 14 is relevant for understanding Article 6 DSA”.

The Court’s finding in Coyote System will require it to do one of two things, neither of them without complication. Either it can limit damage by splitting the DSA off, treating Coyote System as relevant only to the expiring Directive, and somehow explain away its deviation from the legislator’s intention that the DSA regime, according to its text and the analysis of one of its principal architects, was intended to “preserve and clarify” its directive jurisprudence. This would result in the peculiar situation that the evolving DSA jurisprudence would seek to preserve the pre-Russmedia case law on the Directive while deviating from the post-Russmedia Directive case law.

Otherwise, it can follow through on its present course, treating Coyote System as applicable in the DSA context. But to force this to make sense, it will need to give an interpretation faithful to the letter, not the spirit, of DSA Recital 22, in which the legislator underlined that recommending content is ‘not a sufficient ground’ to establish immunity-removing knowledge. The ‘control’ criterion, elaborated in Coyote System, comes from a different source—Recital 18—which carries over the knowledge/control phrasing from the case law on Recital 42 of the Directive. The CJEU would need to insist, though the legislator’s intention to protect algorithmically-driven services from liability is crystal clear, that it is significant that the legislator only specified the ‘knowledge’ and not the ‘control’ criterion, in its carveout of algorithmic processes in Recital 22. This is a stretch because the strict delineation of these standards was, as Woods observes, ‘not laboured in previous judgments’. The legislators would have had little reason to think that ‘control’ needed separate protection from a distinction the Court had never enforced.

Platforms’ Presumption that the Court Means What It Says

To explain why this article has repeatedly implied that there might be some other option than taking the Court “literally” at its word: Judge Robert Spano posted a more circumspect evaluation through his social channels in the week following the judgment. Spano, who is a subject-matter specialist in intermediary liability and a former President of the European Court of Human Rights (ECtHR, the separate European human rights court), argues that “the better reading” is that Coyote System’s precedential value should be minimized by interpretation as “fact-specific.”

Spano’s approach, though, is founded less in doctrinal method than in a realism derived from his own experience as a European high court judge. Spano writes that, “having been an international judge for years’, he has seen the two European Courts often ‘embark on a certain trajectory…without realising the full context and potential unsatisfactory consequences of a literal reading of their finding. Then, course correction takes place in future cases!” Spano is nodding toward Delfi v. Estonia, a widely criticized ECtHR ruling which, he has argued in speeches and articles, was quietly corrected by fact-specific minimization in later cases.

In a piece published in the weeks after the CJEU’s last controversial assault on the intermediary liability immunity—the case of Russmedia, mentioned previously, which was handed down in December 2025 and which seemed paradigm-shifting until Coyote System eclipsed it—I argued “it will be tempting” for Europeans lawyers “to hope that this controversial ruling will not affect the safe harbour’s functioning far beyond the facts of the immediate case. Scholars of EU law, judges, legislators, NGOs, and think tanks, are likely to favour interpretations” which invoke broader values to minimize the precedent while the platforms, which are largely American companies, will favor more literal, risk-averse interpretations. In April, Daphne Keller observed this split already taking shape and enumerated a variety of problems associated with attempting to interpret Russmedia as fact-specific. A fundamental difficulty with this European interpretative strategy merits emphasis: the authorities empowered to apply and enforce the law created in Luxembourg, the platforms and the Member State courts, may not share the deontological universe—the system of values and incentives—of a Judge Spano.

Regardless of whether Spano convinces a Europeanized audience that the “correct reading” of Coyote System is what he says, member state courts may wish to apply Coyote System to achieve goals diametrically opposite to Spano’s. And most importantly, beyond these lower courts, there is the legal consciousness of the platforms which feel themselves potentially addressed by the reasoning in cases like Coyote System and Russmedia. These platforms’ interpretation will be conditioned by a set of values and objectives very different from Spano’s, and their likely response should be treated as of primary importance because it is the platforms, not the courts, which determine the majority of online speech disputes. The actual conditions of free expression and privacy online will be shaped less by what the ruling says than by what the platforms fear it says, and by the moderation strategies they employ to manage that fear. If the platforms believe Luxembourg’s holding, via the Member State courts, exposes them to legal risk, then the consequence of Russmedia and Coyote System will play out at scale, online, in a largely invisible way, regardless of what opinion leaders in European law believe the ‘correct’ reading should be.

There is another reason that it feels like wishful thinking to explain away Coyote System as a mistake produced by a court struggling to understand the consequences of its own jurisprudence. What may have been true for the ECtHR in 2015 is not true for the CJEU in 2026. When the ECtHR received the Delfi complaint in 2009, it was the first time that it was required to consider an issue of online intermediary liability. By contrast, when Coyote System reached Luxembourg, the Court could read it against more than fifteen years of its own intermediary liability jurisprudence, stretching back to Promusicae, Google France, and L'Oréal v eBay. Furthermore, it received Coyote System while it was already deliberating over Russmedia. The Court had five months to consider Coyote System in light of the scholarly and practitioners’ prompt responses to Russmedia. Intermediary liability lawyers were overwhelmingly critical, as in Keller’s instructive two-part article, and Erik Tuchtfeld’s lucid blog post. These opinions dropped even while privacy-focused lawyers and advocates against online harm were more positive or placatory, as in an article by the Co-Chair of the Brussels Privacy Hub, Sophie Stalla-Bourdillon, and an Assistant Professor at KU Leuven, Aleksandra Kuczerawy.

Whatever the court is doing, it is doing it in full knowledge of its own case law and of how the legal and scholarly community responds to its rulings. It is changing the legal discipline in a way that is purposeful and consistent rather than merely making mistakes without realizing the context or likely ramifications of its holdings. The Court signaled its intentions in Russmedia. Six months later, given the opportunity to backtrack, it doubled down.

If anyone remains unconvinced that the court must be presumed to mean what it says, they should consider finally that the court’s own AG opinion produced well-reasoned evaluations of the stakes at issue in both Russmedia and Coyote System and recommended legal solutions which would have left the core of the safe harbor’s applicability intact in either case. In both judgments, the Court largely ignored the granular and function-based distinctions which the AG insisted were relevant, preferring instead to produce broad precedents which radically denude the relevant provisions of their force.

That the Court was clearly aware of what it was doing is the reality with which we have to make our interpretation of Coyote System congruent.

Mouths that Pronounce

And why did the court rule this way? And where will it go from here? The honest answer is that we don’t know. And this is the deeper problem Coyote System exemplifies: a problem which goes far beyond internet policy and presents a challenge for the rule of law in Europe. The CJEU has a problematic tendency to assert rather than analyze or argue for its legal interpretation. Even when establishing new doctrines or transforming old ones, the CJEU seems to believe itself empowered to do so without offering any explanation to the people of Europe. This tendency toward opacity descends from a French civil law tradition in which the judge was styled a mere functionary or, to quote Montesquieu, “no more than the mouth that pronounces the words of the law” and who, historically, could not officially even admit to interpreting law at all: six of the Court's seven original judges came from jurisdictions in this tradition, and the court still speaks in a single voice, in French, without dissents. The US comparatist, John P. Dawson, in his magisterial work The Oracles of the Law, once wrote of the obscure style of the French apex court of cassation, which would later provide a model for the EU court: ‘behind the cascades of whereas clauses one can still see stalking the ghostly magistrates of the [Ancien Régime’s] Parlements, majestic in their moldy red robes’. One can still see something like this ghostly apparition in the opacity of the CJEU’s rulings in cases like Russmedia and Coyote System. Though the EU court has changed since its early days, its tradition is still deeply embedded in a French foundation and culture: it emerges from time to time, as a kind of ‘zombie formalism’, to borrow a phrase from art criticism. In 2001, the preeminent European constitutional theorist Joseph Weiler appealed to the CJEU to “abandon the cryptic, Cartesian style which still characterises many of its decisions and move to the more discursive, analytic, and conversational style associated with the common law world.”

Weiler’s appeal must be reinvigorated, not because of some aesthetic attraction to a particular type of language, but because the critique at its core is fundamentally political, and it may prove existential for the EU in the coming decades. We have come a long way since the era in which the European Court could rule, as Eric Stein wrote in 1981, “blessed with benign neglect by the powers that be and the mass media.” Today, Europe is watching. A court that dismantles carefully designed legislation, enacted through the political process, without acknowledging it is doing anything unusual, without explaining the scope of its judgment, and without giving reasons the public can evaluate, displays an almost Napoleonic arbitrariness. Such a display of institutional unconcern becomes a weapon in the hands of the forces that would prefer the EU legal order torn apart.


Michael FitzGerald is a researcher at the European University Institute's department of law.
}

Subscribe to Lawfare