Three thousand recorded conversations, a hundred and fifty people wiretapped, two thousand names filed away in three databases. Between January 1983 and March 1986, the Élysée’s counterterrorism cell listened to journalists, lawyers, an actress, entire newsrooms. It took a Paris court until November 2005 to rule on it, and the judgment named François Mitterrand as the man who inspired and decided the essential part of it. Seven of his staff were convicted, all with suspended sentences. He was covered by presidential immunity. The French intelligence law of 2015 was written partly in response to that memory, and I keep coming back to it because the real question was never what the state can do. It is who would notice.

The statute was amended for the seventh time on 16 August 2026. Barely anyone covered it.

Version française : La loi renseignement a dix ans, personne ne peut vérifier si elle tient.

Seven layers, ten years

Before 2015, France had no general framework. Fragments of statute, the 1991 law on the secrecy of correspondence, an oversight commission with almost no teeth, and a lot of old unwritten practice. The law of 24 July 2015 created Book VIII of the internal security code and set three things in place: seven exhaustively listed purposes under article L. 811-3, a catalog of authorized techniques, and dual oversight by the CNCTR and a specialized chamber of the Conseil d’État.

Read those seven purposes without the press-release filter and the picture changes. National independence and defense, major foreign policy interests and prevention of foreign interference, major economic and scientific interests, prevention of terrorism, prevention of attacks on the republican form of institutions and of collective violence, organized crime, proliferation. Terrorism is one line out of seven. Senator Claude Malhuret said it during the debates, and it remains the sharpest criticism anyone has made of the text: every justification offered concerned the terrorist threat, while the machinery reaches far past it.

What follows reads as sediment. November 2015 for international communications surveillance, written to patch what the Constitutional Council had just struck down. A constitutional challenge on radio-spectrum surveillance in 2016, the SILT counterterrorism law in October 2017. Then the only genuine external pressure in the whole run: the CJEU’s October 2020 ruling on general data retention, and the Conseil d’État’s answer in French Data Network on 21 April 2021. The legislature responded with the law of 30 July 2021, the pivot text that made the so-called algorithm technique permanent, extended it to URLs, and rebuilt the retention regime. Then the foreign interference law of 25 July 2024, which opened the algorithm to two further purposes on an experimental basis.

The Constitutional Council’s 12 June 2025 ruling on the narcotrafficking law is the most interesting moment in the sequence. Asked to review thirty-eight of sixty-four articles, it upheld thirty-two and struck six, including the one giving first-circle services direct access to tax databases, and the one extending algorithmic URL processing to organized crime. Then it went further than the text put in front of it and deleted the words allowing full internet resource addresses inside article L. 851-3, wording that had been law since 2021. The reasoning is one sentence long and it is a good one: authorizing algorithmic processing generally and indiscriminately across all data transiting operator networks, with no condition attached to the nature of what those URLs reveal, does not balance public order against privacy.

A year later, the legislature came back with the identical tool, better fenced. The military programming update of 16 August 2026 restored URL use, extended the algorithm to organized crime, rewrote the procedure in L. 851-3, and bolted on new guarantees. It also created a prior-declaration regime for anything current and former officers publish, plus a national security alert state. The Constitutional Council upheld it all without reservation on 6 August 2026.

That is the cadence of this file: expand, get censured, come back in six to twelve months with the same capability and tighter drafting. It works, and it never rolls back. One exception: encryption, which I get to at the end.

Five algorithms

Everyone talks about the black boxes. Almost nobody looks at the counter.

The mechanism first, because people misdescribe it constantly. The Prime Minister can require operators and internet service providers to run automated processing on their own networks to detect connections revealing a threat. Those algorithms touch only connection metadata, never content, and must not identify the people behind the data. Anything collected is kept twenty-four hours maximum for processing. De-anonymization happens in a second stage, on a sixty-day clock.

Now the counter. The first algorithm was deployed in October 2017, two years after the vote. Three running at the end of 2018. Still three at the end of 2020, with not a single new authorization even requested that year. One more in 2023 brings the total to five since 2015. And the URL extension opened in 2021 had still not been implemented when the Constitutional Council struck it down four years later.

Five algorithms in a decade. This is not a drift net over national traffic; it is a handful of tuned detectors authorized case by case, and the CNCTR’s own president concedes they can turn out either too narrow or so broad they flood the service with signals. Ten years of public argument built on a capability whose operational value the people overseeing it still openly question.

The volume is somewhere else entirely

If you are looking for bulk collection, it exists, under a separate legal regime nobody argues about. International communications surveillance, framed by the law of 30 November 2015, lets the DGSE run both targeted measures and non-individualized exploitation of connection data. The core safeguard is that communications between identifiers attached to national territory, when this system captures them, must be destroyed instantly.

Physically, France is a chokepoint. A submarine cable interception program covering the landing stations at Marseille, Penmarch and Saint-Valéry-en-Caux was launched in 2008 with a budget in the hundreds of millions of euros, and public accounts describe roughly twenty interception sites mixing satellite stations and fiber landings. Ninety-nine percent of intercontinental telecommunications ride those cables.

One clarification while I am here, because the confusion comes up every time: the detection probes ANSSI places with operators and hosting providers under article L. 33-14 of the postal and communications code are a completely different animal. Same physical location, opposite purpose: defensive cybersecurity in the sense of the NIS 2 directive and its continent-wide security floor.

A hundred suitcases and a forty-eight-hour clock

The IMSI catcher does not exist in French law. Statutes refer to the device mentioned at 1° of article 226-3 of the criminal code, an article that makes possessing or using such equipment a criminal offense without authorization. Everything else is a carve-out from a crime, which is a rather elegant piece of legal construction once you notice it.

On the intelligence side, two guardrails stand out. Hardware quotas first, genuinely rare in French law: the number of devices that can be simultaneously authorized is capped by decision of the Prime Minister after CNCTR opinion; that cap sits at one hundred, and every unit is entered in a dedicated register kept available to the commission. Then duration. When the device is used to intercept the content of communications rather than just connection data, authorization cannot exceed forty-eight hours, against four months under the ordinary regime.

The judicial regime opened by the law of 3 June 2016 is deliberately narrower: technical connection and location data only, two months renewable twice, inside the organized crime perimeter. The law left out geolocation and interception functions because criminal procedure already has its own regimes for both. The 2025 narcotrafficking law loosened both sides, notably by allowing entry into private premises, at night if needed, without the occupant’s knowledge, excluding lawyers’ offices, press companies, medical practices and judges’ homes.

The underlying flaw has not moved since 2015: the device grabs every handset in range, not just the target. Oversight remains awkward too, with the Défenseur des droits noting in 2017 that IMSI catcher collection is decentralized and done locally, without full traceability, which prevented the CNCTR from exercising the control the law prescribes. Centralizing the output at the GIC has closed part of that gap.

Who actually gets to read it

The principle is a wall. Intelligence is administrative policing and prevention, not evidence-gathering. The GIC classifies and centralizes the data. Access goes to individually designated and cleared officers of the requesting service, to the CNCTR, which holds permanent, complete, direct, and immediate access, and to the specialized chamber of the Conseil d’État. Not the prosecutor, not the investigating judge, not the police. Retention runs from thirty days to four years depending on the data type.

The wall has doors, though. The first is article 40 of the criminal procedure code, and it is openly acknowledged, since L. 811-2 of the security code points straight at it: using an intelligence technique does not remove the duty to inform the prosecutor when you learn of a crime. What travels is information, not the technical product.

The second is the note blanche, and politically it matters most. An unsigned document with no source and no procedure attached, which administrative courts treat with a presumption of truth when it reads as precise and circumstantial, meaning the person targeted has to rebut it with abundant concurring evidence. Good luck with that. Criminal courts have started drawing lines, with the Cour de cassation accepting that a liberty judge can authorize a home search on a note blanche alone but without interpreting or extrapolating from it, and requiring the prefect to produce something else when the person contests it seriously.

The third door is lateral, and it keeps widening. The Constitutional Council did push back in its July 2021 ruling, upholding information sharing between intelligence services while striking the parts of article L. 863-2 that let other administrations feed them. The narcotrafficking law still loosened first-circle to second-circle transmissions, and more importantly opened the reverse flow: prosecutors handling organized crime can now pass services any material of any kind sitting in their case files. Justice feeding intelligence, with separation of powers taking the hit.

How the collected data is guarded

The framework is public; the technical detail is not. The reference text is IGI 1300 in its 9 August 2021 version: any system handling Secret or Très Secret material must be accredited, with approved products, protected zones and cleared staff. Accreditation is not a technical certificate; it is a formal, dated, signed acceptance of residual risk by an authority that carries the consequences.

For the crypto itself, the rule is ANSSI approval, the decision by which the agency recognizes an evaluated product as fit to protect classified information at a stated level and under stated conditions of use. The agency sits by right on every accreditation panel regardless of level. Encryptors themselves are controlled items under instruction 910, inventoried and tracked. Encryption alone is never enough here, since IGI 1300 also imposes physical security and protection against compromising emanations, with ANSSI acting as the national TEMPEST authority.

What you will never learn: the algorithms chosen, the key lengths, the specific products running at the GIC or the DGSE. Classified. Nobody outside the cleared circle can verify any of it, and that is structural rather than accidental.

Quantum arrives after the problem

No, an AI does not break AES. No credible path exists from machine learning to cryptanalysis of a correctly implemented symmetric algorithm. Where it does shift things is everywhere around the crypto: automated vulnerability discovery in implementations, social engineering against cleared personnel, large-scale exploitation of data already out through other means. ANSSI is in fact helping evaluation labs build side-channel analysis skills for post-quantum algorithms, which tells you exactly where the real terrain sits.

Quantum threatens the asymmetric half, so key exchange and signatures, not 256-bit symmetric. No cryptographically relevant quantum computer exists, and ANSSI’s own roadmap puts its arrival somewhere around 2035 to 2040 with an openly acknowledged question mark. The danger is therefore deferred and it is called Harvest Now, Decrypt Later: intercept and store encrypted traffic today, decrypt it later. Diplomatic correspondence or a patent portfolio holds value well past ten years, and a state actor has no reason to wait for the machine before starting the harvest.

Hence the French timeline, the most aggressive in Europe. On 16 June 2026 at France Quantum, ANSSI put two dates on the record: 2027 for the end of certifications for products without post-quantum cryptography, 2030 for administrations and companies to buy quantum-safe only. The chosen method is hybridization, a post-quantum algorithm paired with a proven classical one, and that caution is earned since several post-quantum candidates have fallen to classical attacks in recent years. It is the same logic tested at full scale when the Eurosystem ran post-quantum signatures through TARGET2, and the same reasoning behind Google putting post-quantum crypto in the Pixel 11’s boot ROM. All of it sits inside the wider push I covered in France’s race to keep its quantum startups sovereign.

For the intelligence data itself, the harvest scenario barely applies: systems not exposed to the internet, protected premises, TEMPEST, short retention. The exposure is in transit traffic and long-lived archives. Historically, what falls is almost never the algorithm. It is the implementation, the key management, or the cleared human.

What would actually need to change

Back to 1983 for a second, because what makes that case instructive is not that a president abused the system. It is the mechanics. The court noted that the head of state’s decisions had been relayed without the slightest reluctance or reservation by every one of his governments. The safety catch did not fail. It was never engaged.

Today’s framework makes a repeat harder. Negative CNCTR opinions have always been followed by the Prime Minister, again in 2024, and the commission can take the matter to the Conseil d’État when they are not. Members of parliament, judges, lawyers and journalists get a reinforced regime. The 2015 law protects officers who report illegality. But the weak points are few and specific: purpose 5° is elastic enough to sweep in a protest movement without anyone lying, the entourage mechanism lets you monitor someone without ever targeting them, the person concerned is never notified and therefore cannot mount a defense, and exchanges with foreign services remain, in the CNCTR’s own 2025 words, an unresolved legal question.

The fixes that would repair something real are known, and none of them is free. Make the CNCTR opinion binding in law, since it already is in practice, which removes no capability and converts a convention into a guarantee. Put the most intrusive techniques before a criminal judge, since they produce identical effects to their judicial equivalents, which already require a magistrate. Narrow purpose 5° so it targets violence rather than dissent. Notify the person afterward when surveillance closes with nothing found; the measure most aligned with Strasbourg case law and the one services fight hardest, because without it there is no litigation, therefore no case law, therefore no self-correction. Put a legal frame around exchanges with foreign partners, the oldest workaround in the business. And formalize the note blanche, because a document carrying a presumption of truth while drafted under no formal guarantee whatsoever is the ideal instrument for a political operation.

One technical measure outweighs the rest: append-only tamper-evident logging, out of reach of the system administrator. Timestamp every query and sign it onto a medium nobody can rewrite. It cuts no operational capability, protects no trafficker, slows no investigation.

Encryption is the one place where the expansion logic reversed. The amendment forcing backdoors into messaging apps was voted down on the floor; the Senate hit back with article 16 bis of the Resilience bill barring anyone from requiring providers to deliberately weaken their own security, and that bill has been stuck for months over this single article while France runs late on its NIS 2 transposition. Fifteen thousand French entities are waiting while the executive and parliament fight over one clause. I understand the operational argument coming from the services: somewhere between sixty and eighty percent of communications now flow through encrypted apps, and classical interception is going dark. But the technical solution they’re asking for doesn’t exist. You cannot build a flaw that only opens for the right people.

I am leaving the EU’s CSAR regulation and the message-scanning fight out of this one. It deserves its own post and its own chaotic timeline.

The paradox is that the French framework is decent on paper, and the European Court of Human Rights said as much in late 2024 when it validated the balance of the statute and the CNCTR’s role. But the ten-year trajectory only points one way. Purposes widen, detection industrializes, inter-service transfers get easier, and 2025 was the first year the annual request count crossed 100,000. Every brick taken alone is defensible. The stack mechanically enlarges the surface for misuse, whoever ends up doing it and whatever their politics. Tamper-evident logging is the one item on that list I treat as non-negotiable, because the cost of not having it is already documented: twenty years for the story to surface, and suspended sentences at the end.

Sources

  • Law no. 2015-912 of 24 July 2015 on intelligence, Légifrance
  • Law no. 2025-532 of 13 June 2025 on narcotrafficking, Légifrance
  • Constitutional Council, decision no. 2025-885 DC of 12 June 2025
  • Law no. 2026-791 of 16 August 2026 updating military programming, Légifrance
  • Constitutional Council, decision no. 2026-907 DC of 6 August 2026
  • Conseil d’État, opinion of 26 March 2026 on the military programming update bill
  • CNIL, deliberation no. 2026-010 of 5 February 2026
  • CNCTR, 2025 activity report and its published overview of controlled intelligence techniques
  • IGI no. 1300 of 9 August 2021 on the protection of national defense secrecy, SGDSN
  • ANSSI, post-quantum cryptography and protection of classified information, cyber.gouv.fr
  • Paris criminal court, judgment of 9 November 2005, Élysée wiretapping case