The Ruling
On July 13, 2026, U.S. District Judge Noël Wise dismissed Amy v. Apple Inc. (No. 24-cv-08832-NW, N.D. Cal.) with prejudice, ending a proposed class action that sought $32.8 billion on behalf of roughly 2,680 survivors of child sexual abuse material. The plaintiffs, proceeding as "Amy" and "Jessica," alleged that Apple's decision to abandon its planned iCloud CSAM-detection tool let images of their abuse keep circulating on Apple's servers. Judge Wise found every theory the plaintiffs offered — product liability, negligence, intentional infliction of emotional distress — ultimately required treating Apple as the publisher of what third parties uploaded. Section 230 of the Communications Decency Act forecloses exactly that. As she put it, "a claim that obliges the defendant to monitor third-party content to avoid liability also treats the defendant as a publisher." Declining to run a scanning tool, in other words, is itself a content-moderation choice, and Section 230 protects moderation choices — including the choice to do less of it.
The Steelman: Advocates Have a Real Point
Before siding with the outcome, it's worth taking the plaintiffs' case seriously. Apple is not a neutral bystander here. In 2021 it announced NeuralHash, a system that would have matched iCloud Photos uploads against known CSAM hash databases and reported matches to the National Center for Missing & Exploited Children (NCMEC). Apple shelved it in December 2022 after security researchers warned the same infrastructure could be repurposed for surveillance. The practical result: Apple submitted just 267 CyberTipline reports to NCMEC in 2023, versus roughly 1.47 million from Google and 30.6 million from Meta — a gap plaintiffs' counsel and child-safety groups have pointed to for years. Judge Wise herself did not pretend the law produces a good outcome. She wrote that current law "prioritizes privacy... but the law should not ignore how those who create, view, and distribute child pornography leverage privacy protections," and added pointedly: "If lawmakers want to ensure that Apple and other companies address their role in the dissemination of CSAM, they must require it under the law." That is a judge on record saying the status quo under-deters a real harm — not a judge finding the plaintiffs invented one.
Why Section 230 Still Got This Right
The steelman is real, but it argues for a legislative fix, not a judicial one — and that distinction is the whole point of Section 230. The statute, enacted in 1996 as part of the Telecommunications Act, says a platform "shall not be treated as the publisher or speaker of any information provided by another information content provider." Courts have consistently read that to bar not just liability for hosting content, but liability for how much or how little a platform screens it — because turning under-moderation into a lawsuit trigger would force every platform into either maximal, error-prone scanning of private data or maximal legal exposure. If a court can impose $32.8 billion in liability for choosing not to deploy one specific detection tool, the next suit demands liability for not deploying a different one, or not scanning fast enough, or not scanning encrypted backups — with a jury, not an engineer or a legislature, setting the standard each time through 20/20 hindsight. That is a genuinely bad way to regulate a technical, adversarial, constantly-evolving problem like CSAM detection, which is precisely why Congress — not the N.D. Cal. docket — built a mechanism (a federal criminal carve-out already exists in Section 230 for CSAM) and left the rest to legislation.
Congress Already Has the Tool — and Hasn't Used It
That legislative mechanism has a name: the EARN IT Act, which would strip Section 230's civil immunity for CSAM claims and has been introduced, and stalled, in three consecutive Congresses since 2020 — largely because groups including the Center for Democracy & Technology and the Electronic Frontier Foundation warned it would pressure platforms to weaken or abandon end-to-end encryption to avoid liability, trading one harm for another. That fight over encryption is real, unresolved, and exactly what a court cannot referee case-by-case. A single N.D. Cal. judge dismissing one class action cannot set a scanning standard that applies to every cloud provider, weigh it against Fourth Amendment and privacy interests, or decide how false-positive rates should be regulated. Legislation can do all three, with hearings, technical testimony, and a vote — which is why Judge Wise's ruling reads less like a defense of Apple's product choices and more like a pointed referral to Capitol Hill.
The Takeaway
Section 230 is functioning as designed here: it keeps a court from freelancing a national CSAM-detection mandate through tort law, while leaving the mandate itself entirely available to Congress. Apple's low CyberTipline numbers relative to Meta and Google are a legitimate policy problem — but the fix is a specific, debated, encryption-aware statute, not a $32.8 billion damages verdict decided by a jury with no visibility into hash-matching false-positive rates or backdoor risk. Plaintiffs' counsel has said they are weighing an appeal and "other potential legal claims"; the more consequential venue for this fight was never the Ninth Circuit — it's the Senate Judiciary Committee, which has let EARN IT die three times without ever forcing the encryption trade-off into the open.