Pasta
– Getty Images

Cloudflare filed an appeal against Italian regulators in what it views as an attack on the open internet.

Italy’s communications regulator Autorità per le Garanzie nelle Comunicazioni (AGCOM) hit Cloudflare with a $17 million (€14 million) fine, which may be described as un salasso or exorbitant in English, after Cloudflare refused to register with AGCOM's Piracy Shield antipiracy system. Patrick Nemeroff, Cloudflare’s legal VP in risk, litigation, and employment, and Emily Terrell, associate general counsel director for litigation, explained the move in a blog titled "Standing up for the open internet: why we appealed Italy’s 'Piracy Shield' fine."

The authors labelled Piracy Shield as a “misguided Italian regulatory scheme designed to protect large rightsholder interests at the expense of the broader internet” with what it deemed an unworkable time limit on blocking addresses submitted through the system.

Describing Piracy Shield as a “blunt tool for rightsholders to control what is available on the internet without any traditional legal safeguards,” Cloudflare pointed to its central portal where an unidentified group of Italian media companies can submit websites and IP addresses that must be blocked within 30 minutes by online service providers registered with the system.

Nemeroff and Terrell labelled the Piracy Shield a black box lacking judicial oversight, transparency, due process, and recourse.

“It’s not entirely surprising that Piracy Shield so clearly prioritizes the economic interests of media companies over the rights of Italian internet users,” they Cloudflare team argued. “The system was ‘donated’ to the Italian government by SP Tech, an arm of the law firm that represents several of Piracy Shield’s major direct beneficiaries, including Lega Nazionale Professionisti Serie A (Italy’s major soccer league).”

To use the Italian term, Cloudflare believes this is a case where some mettere le mani in pasta, or putting their hands in their dough when they shouldn't.

'Pugno di ferro'

Problems were claimed to have started almost immediately after Piracy Shield’s rollout, with its pugno di ferro, or iron fist, leading to overblocking of innocent websites due to the shared nature of IP addresses. Outages included Ukrainian government websites for scientific research and schools, online presences of small businesses and NGOs, as well as blocked access to Google Drive for “thousands of Italian students and professionals.”

“We recognize that rightsholders have a legitimate interest in protecting their content. … But those interests cannot override the basic requirements of legal due process or the technical integrity of the global internet and our network,” Cloudflare's team wrote.

Cloudflare cited a University of Twente study that found Piracy Shield routinely blocks legitimate websites for months at a time.

“Even when faced with clear evidence that Piracy Shield has caused significant and repeated overblocking, AGCOM did not change course,” Cloudflare continued. “Rather, it chose to expand Piracy Shield to apply to global DNS providers and VPNs, services which are closely associated with privacy and free expression. AGCOM also started taking increasingly aggressive steps to force global service providers, even ones with no legal or operational presence in Italy, to register with Piracy Shield.”

Cloudflare’s legal leads claim the firm sat down with AGCOM in 2024 to address the supposed faults, only to be ignored. This led to legal action from Cloudflare, challenging AGCOM’s effort to “force” it to join Piracy Shield in the Italian administrative courts while filing a complaint with the European Commission (EC) alongside the Computer & Communications Industry Association (CCIA).

“Our position has been consistent and remains that Piracy Shield is incompatible with European Union law, most notably the Digital Services Act (DSA), which requires that any content restriction be proportionate and subject to strict procedural safeguards," Cloudflare's team wrote.

AGCOM di nascosto?

Cloudflare noted the EC would go on to criticize the lack of oversight inherent in the Piracy Shield framework after hearing the firm’s concerns, before the Italian administrative court issued an encouraging ruling in late December to force AGCOM to share with all of its records that purportedly support Piracy Shield blocking orders with Cloudflare.

AGCOM was also claimed to have offered to make some of its records available for inspection at one of its locations, subject to supervision by AGCOM officials. The offer, made four days before the disclosure deadline, was described as “unreasonably burdensome and contrary to the letter and spirit of the disclosure order,” while raising “real questions” on AGCOM’s attitude to transparency, with Cloudflare suggesting it of fare le cose di nascosto, or doing things in secret.

“While we have not yet received those records, we expect them to shed significant light on Piracy Shield’s operations,” the legal leads explained. “[But] rather than awaiting the outcome of our legal challenges, and less than one week after [the disclosure order], AGCOM moved on December 29, 2025, to issue its fine.

According to the blog, AGCOM miscalculated Cloudflare’s fine by basing it on the firm’s global revenue instead of revenue within the relevant jurisdiction as mandated by Italian law, capped at approximately $161,220. This saw Cloudflare hit with a penalty nearly 100-times higher than the legal limit, it claimed.

“This disproportionate approach sends a chilling message to the global tech community: if you question a flawed regulatory system or defend the rights of your users and the global internet, you risk facing punitive and excessive financial retaliation,” Nemeroff and Terrell argued.

“We will continue to pursue this challenge in the Italian courts and through the European Commission,” they added, framing Cloudflare’s decision as preserving the importance of global connectivity and an internet where “the rules are transparent, the regulators are accountable, and the infrastructure that connects the world remains free, open, and secure.”

This isn't the first European rodeo for San Francisco-based Cloudflare. In November, it was revealed that all sites running on Cloudflare are effectively inaccessible in Spain if a soccer match is being played.

The weekend outages occur due to Spain's top-flight soccer league, La Liga, being allowed to request Spanish ISPs to block any IP addresses it identifies as involved in pirating matches.

Cloudflare attempted to challenge La Liga’s action, claiming it was excessive and resulted in significant collateral damage by restricting access for millions of legitimate users. However, the appeal was dismissed in March of last year, and the blocking remained in effect until the La Liga season concluded in May.