Apple wins iCloud CSAM scan liability case under Section 230

Original: Apple defeats liability for not scanning iCloud for CSAM

Why This Matters

The ruling reaffirms Section 230's broad scope for cloud platforms, but a Ninth Circuit reversal could reshape CSAM liability standards industry-wide.

A U.S. federal court dismissed a lawsuit (Amy v. Apple) alleging Apple failed to scan iCloud for CSAM. The court ruled Apple is protected under Section 230, as plaintiffs' claims treat Apple as a publisher of third-party content. The case is now positioned for Ninth Circuit appeal.

In Amy v. Apple, a federal court dismissed the third amended complaint filed by CSAM victims who alleged Apple's failure to implement known CSAM detection tools—such as PhotoDNA—constituted a design defect. Apple had previously developed its own alternative called NeuralHash, but abandoned it and instead implemented end-to-end encryption for iCloud files, drawing criticism from governments and victim advocates.

The court ruled that Section 230 immunity applies because plaintiffs' claims fundamentally treat Apple as a publisher or speaker of third-party content. The court cited Doe 1 v. Meta and Grindr precedents, noting that 'the duties Plaintiffs seek to invoke spring from the defendant's status as publisher,' and that design decisions related to facilitating others' communications fall within Section 230 protections. Critically, the court affirmed that Apple's internal knowledge of iCloud's potential misuse does not strip it of immunity under current law.

The court also rejected plaintiffs' attempts to invoke exceptions established in Doe v. X. Notably, the presiding judge expressed clear displeasure with the outcome despite ruling in Apple's favor. The dismissal sets up a Ninth Circuit appeal, where the outcome remains uncertain.

Source

blog.ericgoldman.org — Read original →