Apple Defeats Liability for Not Scanning iCloud for CSAM

speckx2 pts0 comments

Apple Defeats Liability for Not Scanning iCloud for CSAM, But the Judge Was Not Pleased-Amy v. Apple - Technology & Marketing Law Blog

Technology & Marketing Law Blog

Menu<br>Biography

Academic Materials

Writing

Presentations

Resources

Courses

Advertising & Marketing Law

Contract Law

Copyright Law

Internet Law

IP Survey

Legal Ethics

Contact

Blogs

Tertium Quid Blog

Eric Goldman’s Personal Blog

About the Blogger

Browse: Home<br>" 2026<br>" July<br>" Apple Defeats Liability for Not Scanning iCloud for CSAM, But the Judge Was Not Pleased–Amy v. Apple

Apple Defeats Liability for Not Scanning iCloud for CSAM, But the Judge Was Not Pleased–Amy v. Apple

July 20, 2026 &middot; by Eric Goldman &middot; in Content Regulation, Derivative Liability, Privacy/Security

This case involves Apple’s handling of user-uploaded files hosted in private iCloud storage. Instead of adopting PhotoDNA to scan hosted files for CSAM, Apple created its own proprietary alternative, NeuralHash, which apparently wasn’t as good. So Apple U-turned on its efforts to scan for CSAM in its cloud storage. Instead, Apple implemented end-to-end encryption for iCloud files.

Apple’s manuevers confused the public and seemed like an embarrassing unforced error for Apple. It also ensured pressure from governments and plaintiffs, including CSAM victims, who preferred Apple’s more interventionist approaches, which Apple had voluntarily demonstrated it was willing to do.

This lawsuit represents a full-scale attack on Apple and Section 230. “Plaintiffs allege that Apple’s failure to implement any known CSAM detection is a design defect because Apple can safely implement readily available features to prevent the spread of known CSAM but has continuously failed to do so.” Prior blog post. The court dismisses the third amended complaint, which tees this case up for the Ninth Circuit, where (as usual) anything could happen.

The court reiterates that Section 230 applies to the plaintiffs’ claims:

First, Plaintiffs’ claims treat Apple as a publisher or speaker of the CSAM content that animates Plaintiffs’ injuries. Fundamentally, Plaintiffs contend that Apple has elected to permit users to disseminate and share third-party CSAM content when it could have—and, in their view, should have—used readily available technology to prevent the distribution of child pornography depicting the Plaintiffs in this putative class. The duties Plaintiffs seek to invoke “spring[ ] from the defendant’s status as publisher,” and consequently, “immunity applies.” Second, immunity also applies because “the means to avoid liability requires [Apple] to act as a publisher.” As a result, Apple is entitled to complete immunity under § 230.

Citing Doe 1 v. Meta, the court says:

Plaintiffs’ injuries are the direct result of the actions of third parties who used iCloud to share CSAM, a use Apple neither explicitly condones nor prevents (even assuming—as alleged in the TAC—that Apple was aware of the use of iCloud for this purpose)….though Plaintiffs allege that Apple knew that its tools were likely to be used to distribute child pornography (as confirmed by the internal Apple text messages at the center of this case), under the current state of the law, Apple is still entitled to immunity under § 230—irrespective of that general knowledge….

Plaintiffs cannot avoid the fact that a tool that detects CSAM must review CSAM to make such a determination. And while Apple could have taken steps to do so—as its competitors have done by using PhotoDNA—Grindr confirms that § 230 bars claims arising from the design decisions Apple could have taken where those claims relate to Apple’s role facilitating the communication and content of others

(A reminder that the defendant’s scienter is irrelevant to Section 230).

The plaintiffs tried to fit into the new Section 230 exceptions created in Doe v. Twitter, but the court rebuffs the move:

This case does not concern or even discuss Apple’s content reporting systems; it concerns Apple’s “failure to implement industry-standard safeguards” against the dissemination of CSAM. Though reporting systems and CSAM safeguards may both be described as “defects,” the latter requires the Court to treat Apple as a publisher. Twitter “could fulfill its purported duty to cure reporting infrastructure deficiencies without monitoring, removing, or in any way engaging with third-party content”; Apple cannot fulfill a duty to institute CSAM safeguards without deploying a tool like NeuralHash or PhotoDNA. Both NeuralHash and PhotoDNA were built to monitor and report violative images uploaded to company servers. Yet just the decision regarding whether to deploy either tool is a choice related to content moderation.

Also, Apple didn’t fail to satisfy any duty to report items to NCMEC if it never identified CSAM in the first place.

The Lemmon v. Snap workaround fails: “all of Plaintiffs’ claims here are inexorably linked to third-party content; Plaintiffs do not...

apple csam plaintiffs icloud content liability

Related Articles