The Italian Communications Regulatory Authority (AGCOM) has fined Cloudflare €14.2 million for failing to comply with requirements regarding the blocking of pirated content in the public DNS service 1.1.1.1. This fine is the largest enforcement action for non-compliance with Italy's anti-piracy legislation, as the penalty is based on the company's total revenue.
In February 2025, AGCOM issued Cloudflare a directive to cease DNS resolution for domains and IP addresses distributing copyright-infringing content. Cloudflare refused to implement the blocking as outlined in the provided list, deeming it unjustified and disproportionate, noting the technical impossibility of applying filters in the 1.1.1.1 service, which processes 200 billion requests daily, without negatively impacting performance. The 1.1.1.1 service initially stated that it does not perform any filtering, and separate DNS resolvers 1.1.1.2 and 1.1.1.3 are provided only for blocking malicious resources and adult sites.
Following Cloudflare's refusal, AGCOM conducted an investigation, concluding that Cloudflare openly violated existing legal norms in Italy that require DNS providers to block pirated sites. VPN AGCOM found the mentioned reason insufficient and disagreed with the argument that introducing filters would degrade service quality, as Cloudflare is not always a neutral intermediary and is known for its complex traffic management mechanisms. According to AGCOM, Cloudflare possesses the necessary experience and resources to implement the required blocking.
Previously, Cloudflare criticized the "Piracy Shield" initiative, which has been in effect in Italy since 2024, during which both pirated sites and legitimate resources using the same hosting platforms and content delivery networks were often blocked. The dissatisfaction is also related to the lack of transparency in compiling the "Piracy Shield" blocking lists, which include about 65,000 domain names and 14,000 (the key to connect to is specified, and iroh finds the associated host and establishes an encrypted connection using the QUIC protocol). Direct P2P connections are established whenever possible, but if not, it falls back to using relays, which are also employed for host discovery by keys. You can run your own relay or connect to public relays supported by the community..
Source: opennet.ru
