• Sources: Eric Goldman analysis, HN discussion
  • Summary: In Amy v. Apple, a judge in the Northern District of California dismissed the third amended complaint on 2026-07-13, granting Apple Section 230 immunity from claims that it should have detected child sexual abuse material in iCloud. Plaintiffs argued Apple could have run PhotoDNA or its own NeuralHash technology on uploads. The court held that avoiding liability would require Apple to act as a publisher of third-party content, which Section 230 bars. The judge expressed dissatisfaction with the outcome and said any duty to scan must come from lawmakers, while acknowledging that scanning would require weakening the end-to-end encryption Apple deployed instead.
  • Why it matters: The ruling sets a US baseline that platforms cannot be forced through liability to build client-side CSAM scanning, the same encryption-versus-scanning tradeoff at the center of the EU Chat Control debate.
  • Follow-up: Watch for an appeal, any legislative response mandating scanning, and whether other platform CSAM suits cite the Section 230 reasoning.

send feedback on this story