This case involves Apple’s handling of user-uploaded files hosted in private iCloud storage. Instead of adopting PhotoDNA to scan hosted files for CSAM, Apple created its own proprietary alternative, NeuralHash:https://apple.fandom.com/wiki/NeuralHash, which apparently wasn’t as good. So Apple U-turned on its efforts to scan for CSAM in its cloud storage and encrypts iCloud files.

Apple’s manuevers confused the public and seemed like an embarrassing unforced error for Apple. It also ensured pressure from governments and plaintiffs, including CSAM victims, who preferred Apple’s more interventionist approaches, which Apple had voluntarily demonstrated it was willing to do.

This lawsuit represents a full-scale attack on Apple and Section 230. “Plaintiffs allege that Apple’s failure to implement any known CSAM detection is a design defect because Apple can safely implement readily available features to prevent the spread of known CSAM but has continuously failed to do so.” Prior blog post:https://blog.ericgoldman.org/archives/2026/01/a-massive-roundup-of-section-230-decisions.htm. The court dismisses the third amended complaint, which tees this case up for the Ninth Circuit, where (as usual) anything could happen.

Apple erhielt gesetzliche Immunität, weil iCloud-Material zu sexuellem Missbrauch von Kindern nicht gescannt wurde

:https://blog.ericgoldman.org/wp-content/uploads/2026/02/IMG_2022.jpgThe court reiterates that Section 230 applies to the plaintiffs’ claims:

First, Plaintiffs’ claims treat Apple as a publisher or speaker of the CSAM content that animates Plaintiffs’ injuries. Fundamentally, Plaintiffs contend that Apple has elected to permit users to disseminate and share third-party CSAM content when it could have—and, in their view, should have—used readily available technology to prevent the distribution of child pornography depicting the Plaintiffs in this putative class. The duties Plaintiffs seek to invoke “spring[ ] from the defendant’s status as publisher,” and consequently, “immunity applies.” Second, immunity also applies because “the means to avoid liability requires [Apple] to act as a publisher.” As a result, Apple is entitled to complete immunity under § 230.

Citing Doe 1 v. Meta:https://blog.ericgoldman.org/archives/2026/05/ninth-circuit-panel-goes-out-of-its-way-to-question-section-230-doe-v-meta.htm, the court says:

Plaintiffs’ injuries are the direct result of the actions of third parties who used iCloud to share CSAM, a use Apple neither explicitly condones nor prevents (even assuming—as alleged in the TAC—that Apple was aware of the use of iCloud for this purpose)….though Plaintiffs allege that Apple knew that its tools were likely to be used to distribute child pornography (as confirmed by the internal Apple text messages at the center of this case), under the current state of the law, Apple is still entitled to immunity under § 230—irrespective of that general knowledge….

Plaintiffs cannot avoid the fact that a tool that detects CSAM must review CSAM to make such a determination. And while Apple could have taken steps to do so—as its competitors have done by using PhotoDNA—Grindr:https://blog.ericgoldman.org/archives/2025/02/ninth-circuit-says-section-230-preempts-defective-design-claims-doe-v-grindr.htm confirms that § 230 bars claims arising from the design decisions Apple could have taken where those claims relate to Apple’s role facilitating the communication and content of others

(A reminder that the defendant’s scienter is irrelevant to Section 230).

The plaintiffs tried to fit into the new Section 230 exceptions created in Doe v. Twitter:https://blog.ericgoldman.org/archives/2025/08/the-ninth-circuit-finds-two-new-ways-to-undermine-section-230-doe-v-twitter.htm, but the court rebuffs the move:

This case does not concern or even discuss Apple’s content reporting systems; it concerns Apple’s “failure to implement industry-standard safeguards” against the dissemination of CSAM. Though reporting systems and CSAM safeguards may both be described as “defects,” the latter requires the Court to treat Apple as a publisher. Twitter “could fulfill its purported duty to cure reporting infrastructure deficiencies without monitoring, removing, or in any way engaging with third-party content”; Apple cannot fulfill a duty to institute CSAM safeguards without deploying a tool like NeuralHash or PhotoDNA. Both NeuralHash and PhotoDNA were built to monitor and report violative images uploaded to company servers. Yet just the decision regarding whether to deploy either tool is a choice related to content moderation.

Also, Apple didn’t fail to satisfy any duty to report items to NCMEC if it never identified CSAM in the first place.

The Lemmon v. Snap:https://blog.ericgoldman.org/archives/2021/05/the-ninth-circuits-confusing-ruling-over-snapchats-speed-filter-lemmon-v-snap.htm workaround fails: “all of Plaintiffs’ claims here are inexorably linked to third-party content; Plaintiffs do not allege that Apple created content like a Snapchat filter that caused them harm.” The Roommates.com:https://blog.ericgoldman.org/archives/2008/04/roommatescom_de_1.htm workaround also fails: “Plaintiffs do not allege that Apple modified or augmented the CSAM on its servers in any way.”

The case reaches its inevitable denouement of a win for Apple. However, Judge Wise remains troubled about its implications. She expresses her uneasiness in stronger-than-normal terms:

This Order does not turn on whether Apple’s decisions contributed to Plaintiffs’ injuries. All Plaintiffs’ claims are founded on Apple serving as a publisher of third-party content. It is that role as “publisher” that is dispositive on the issue of immunity. This does not mean that the existence of images and videos of the putative class members being sexually abused—content that they allege is regularly stored and disseminated on iCloud—has not caused Plaintiffs real and lasting harm…

Judge Wise isn’t well-situated to compare the relative strengths and limitations of the full range of potential anti-CSAM options, but a leading tool has always been and remains the government’s efforts to find and prosecute the creators, disseminators, and downloaders of CSAM. (Do you recall the federal government’s choices that leave children more vulnerable:https://www.theguardian.com/us-news/2026/jan/24/justice-department-cuts-child-sex-trafficking?) Making sure the government is doing what it can should be the #1 priority.

Case Citation : Amy v. Apple Inc.:http://business.cch.com/plsd/AmyvApple7-13-26071426.pdf, 2026 WL 2031817 (N.D. Cal. July 13, 2026). The complaint:https://cdn.arstechnica.net/wp-content/uploads/2024/12/Amy-et.-al.-v.-Apple-Case-24-cv-08832-Doc-1-Complaint-12-07-2024.pdf.