Apple Won the CSAM Lawsuit, But the Judge Was Not Pleased: Section 230 and the Privacy Paradox

Apple Won the CSAM Lawsuit, But the Judge Was Not Pleased: Section 230 and the Privacy Paradox

privacyregulationapplecsamsection230

Sources:HN + web research · HN

On July 13, 2026, the U.S. District Court for the Northern District of California handed down a ruling that left many with mixed feelings: Apple won the case and bears no legal liability for child sexual abuse material (CSAM) circulating on iCloud. Judge Noël Wise ruled that the law was on Apple’s side — but she also wrote, in unusually plain language, that the outcome means child victims have become “collateral damage of an ineffective legal landscape.” She all but called on lawmakers: if they want tech companies to act, they must mandate it through legislation.

Apple won the case, but the judge was not pleased. What exactly happened?

Technology & Marketing Law Blog

What Apple Did — and Didn’t Do

The story begins in 2021. That year, Apple grandly announced a system called NeuralHash. The idea: before a user uploads a photo to iCloud, match it locally against a database of known child exploitation material using a digital fingerprinting technique. If a match is found, block the upload and report it.

Sounds reasonable, right? But here’s the catch.

The industry already had a well-established tool — Microsoft’s PhotoDNA, adopted by Google, Facebook, Microsoft, and nearly every major platform. But Apple chose not to use PhotoDNA. Instead, it built NeuralHash from scratch. The in-house system did not perform well — researchers quickly found false positives and ways to bypass it. More critically, privacy advocates attacked the approach, arguing that it essentially built a “backdoor” into every iPhone, one that governments could exploit.

In late 2022, Apple did a complete 180: it scrapped the iCloud CSAM scanning plan entirely and instead introduced end-to-end encryption for iCloud (Advanced Data Protection). This meant that not even Apple itself could read content stored in users’ iCloud accounts.

The move baffled everyone. Child protection advocates saw it as Apple abandoning its responsibility; privacy advocates saw it as the right call. And the lawsuits followed.

The Core of the Case: Knowing About a Problem and Not Fixing It — Is That Illegal?

Two plaintiffs, identified only as Amy and Jessica — whose childhood abuse photos continue to circulate on iCloud — filed a class action on behalf of approximately 2,680 victims, seeking $32.8 billion in damages.

Their lawyers argued: Apple’s own employees acknowledged in iMessage chat logs that they knew iCloud was being used to distribute this illegal content, yet Apple chose not to deploy PhotoDNA or NeuralHash to detect it. The plaintiffs’ position: the technology existed; the problem was Apple’s choice not to act.

That sounds compelling, right? But the court’s response was unexpected.

The legal basis for dismissing the lawsuit is a statute born in the dial-up internet era: Section 230 of the Communications Decency Act.

The core idea of Section 230 is that internet platforms are not liable as “publishers” for content posted by users. Simply put: if someone posts a defamatory comment on Facebook, Facebook is not responsible for that comment — because Facebook is a platform, not a publisher.

But iCloud is “cloud storage,” not “social media.” How did the court’s logic apply?

Judge Wise wrote in her ruling:

“The plaintiffs’ claims essentially demand that Apple, as a publisher, process third-party content. Tools to detect CSAM — whether NeuralHash or PhotoDNA — function to review user-uploaded content. Whether to deploy such a tool is itself a content moderation decision.”

In other words: requiring Apple to scan iCloud content for CSAM is fundamentally asking Apple to act as a “censor” — which is precisely what Section 230 protects against. The law says platforms have no obligation to proactively review user content, so Apple’s failure to do so does not constitute a violation.

The court also noted that even if Apple employees knew iCloud was being misused, Section 230 immunity does not depend on a platform’s “knowledge.”

The Judge’s Dissatisfaction: The Law Protects Apple, But Not Children

If the ruling had stopped there, this might have been just another legal analysis. But Judge Wise’s additional remarks made the case unusual.

She wrote:

“Currently, no law prevents any company — including Apple — from using available technology to identify and report child sexual abuse material. But at the same time, no law requires companies to do so.

“These children are collateral damage of our ineffective legal landscape. They deserve better.”

The subtext is clear: the judge believes that, from a moral standpoint, Apple should do something; but from a legal standpoint, she cannot compel Apple to do anything. She wants Congress to legislate, not the courts to fill the gap.

This is a classic “legislative vacuum” dilemma: technology moves faster than law. Section 230, drafted in 1996, never foresaw cloud storage services used by billions of people.

Eric Goldman - Technology & Marketing Law Blog

Eric Goldman’s blog analysis is the primary source for this article.

The Villain’s Perspective: Privacy vs. Child Protection

The most vexing aspect of this case is that there is no simple “good versus evil” narrative.

Those who support scanning argue:

Child sexual abuse material involves criminal activity — the tools already exist (PhotoDNA is widely validated), and Apple has hundreds of billions in cash reserves. It is fully capable of deploying them. Not scanning is complicity. Every photo in circulation is a renewed trauma for the victim. Regulators in the UK and Australia have publicly criticized Apple’s approach.

Those who oppose scanning argue:

Once you allow Apple to scan iCloud content, you have created an exception to end-to-end encryption. Today it is used to find CSAM; tomorrow it could be used to find political dissidents, medical records, or private photos. History has shown — from PRISM to governments’ ongoing assault on encryption — that any mandatory scanning mechanism will eventually be abused. And systems like NeuralHash have false positive rates that could flag innocent users’ private photos.

This author’s view: both sides have valid points, but the fundamental question is about the distribution of power.

Engineering Judgment: Being Able to Do Something Doesn’t Mean You Should

From a purely technical standpoint, deploying PhotoDNA or an improved NeuralHash on iCloud is entirely feasible. Microsoft’s PhotoDNA has been running for over a decade, processing billions of images daily with an extremely low false-positive rate.

But here’s the problem: once any scanning mechanism is deployed on cloud storage, end-to-end encryption is effectively dead. Scanning must happen before encryption or after decryption, which means Apple must hold the decryption keys — meaning it has access to every user’s private files.

Apple’s 2022 choice — abandon scanning, embrace end-to-end encryption — was honest from a security engineering perspective. It acknowledged that you cannot give users real privacy while also peeking at their cloud content.

Apple’s technology is not the issue. The laws of physics prevent simultaneously having end-to-end encryption and server-side content scanning.

What Happens Next?

The plaintiffs’ lawyers have already signaled an appeal to the Ninth Circuit. But the more consequential development may be on the legislative front: Congress has been debating Section 230 reform for years, but the issue has become so politicized that progress has been glacial.

Meanwhile, the West Virginia Attorney General has filed a separate lawsuit against Apple — the first state-level government action targeting iCloud’s role in CSAM distribution.

This case may ultimately reach the Supreme Court. And until then, the victims’ photographs continue to circulate on iCloud.

Reflection

This lawsuit reveals an uncomfortable truth: our legal system was not designed for a world where “platform” and “infrastructure” are the same thing. iCloud is both a personal archive and a content distribution channel. When you impose a scanning obligation on it, you simultaneously undermine its function as a private archive.

Judge Wise was right: this is a problem for legislators, not courts. But whether legislators have the political will to balance child protection with privacy is another question entirely.

Technology was never the hard part. The hard part is deciding how much of one right we are willing to sacrifice to protect another.


Reference links:

  • Eric Goldman’s blog: Apple’s legal victory and Section 230 analysis
  • HN discussion (item?id=48992870): Polarized debate in the tech community
  • 9to5Mac coverage: Case facts and litigation timeline
  • Reuters coverage: Ruling outcome and plaintiffs’ appeal plans
  • Microsoft PhotoDNA: Hashing and matching technical overview
  • EFF: Technical ethics of end-to-end encryption and CSAM scanning
  • Wikipedia: iCloud Advanced Data Protection timeline