A federal judge in San Jose delivered a ruling this summer that tech policy watchers have been expecting for years, and it landed exactly where Section 230 doctrine says it should. On July 13, 2026, U.S. District Judge Noël Wise dismissed Amy v. Apple, a proposed class action seeking $32.8 billion in compensatory damages on behalf of roughly 2,680 survivors who alleged Apple knowingly let child sexual abuse material recirculate through iCloud. The dismissal was with prejudice — the case cannot be refiled — and Wise's reasoning was blunt: Apple is immune because the claims "seek to treat Apple as a publisher of third-party content," which is precisely what Section 230 of the Communications Decency Act shields platforms from being sued over.
What the Court Actually Said
The plaintiffs argued Apple could have kept using NeuralHash, the on-device hash-matching system it announced in 2021 to flag known CSAM before it reached iCloud, and abandoned in December 2022 after a backlash over surveillance and security risks. Wise didn't dispute that Apple could have kept it. She ruled it doesn't have to. "As the law stands, Apple likewise does not have a duty to go looking for CSAM on its servers via NeuralHash or any other means, no matter how easy it may be for them to do so," she wrote, pointing to 18 U.S.C. § 2258A, the federal statute governing platform reporting duties. That law requires providers to report CSAM they know about to the National Center for Missing & Exploited Children — but subsection (f)(3) explicitly states it does not require providers to "affirmatively search, screen, or scan" for it. Then Wise added the line that matters most for policy: "If lawmakers want to ensure that Apple and other companies address their role in the dissemination of CSAM, they must require it under the law... lawmakers can fix this problem that is contributing to the exploitation of children. This Court cannot."
The Case for a Scanning Mandate — Fairly Stated
Before dismissing the push for a legal duty to scan, it deserves its due. Apple's own gap between stated concern and measured output is stark: the company filed just 267 CyberTipline reports to NCMEC in 2023, compared with roughly 1.47 million from Google and more than 30.6 million from Meta, according to figures cited in West Virginia's parallel lawsuit against Apple, which a federal court sent back to state court on July 7, 2026 over Apple's objection. West Virginia's complaint alleges Apple internally described itself as "the greatest platform for distributing child porn" while shelving the one detection tool it had built. For survivors whose abuse images keep circulating years later, the argument that a trillion-dollar company chose not to deploy technology it already had is not abstract — it's the entire injury. A reasonable person can look at that gap and conclude current law lets companies opt out of responsibility too easily.
Why the Fix Shouldn't Be a Section 230 Carve-Out
But the remedy Congress has actually been debating is broader than closing that specific gap, and that's where the caution belongs. The STOP CSAM Act, reintroduced by Senate Judiciary Chairman Dick Durbin, would let plaintiffs sue platforms that "recklessly" host or facilitate CSAM-adjacent content — a standard vague enough that the Electronic Frontier Foundation warns it would push platforms toward "censor[ing] more and more user content and accounts, with minimal regard as to whether that content is in fact legal," and could deter new platforms from launching at all for fear of litigation exposure. EFF also flags the encryption problem directly: plaintiffs' lawyers would likely argue that offering end-to-end encryption itself "recklessly facilitates" illegal sharing, since encrypted services can't inspect content to catch it. That is not a hypothetical slippery slope — it's the exact mechanism that killed NeuralHash. Apple's 2021 system was abandoned after security researchers and civil liberties groups showed how client-side hash-matching could be repurposed for surveillance far beyond CSAM, in authoritarian contexts especially. A liability regime built to punish companies for not scanning creates the same pressure NeuralHash's critics fought off, just applied with a lawsuit instead of a product announcement.
The Narrower Path Wise Actually Pointed To
Wise's opinion doesn't call for a broad "facilitation" tort. It calls out a specific, fixable gap: there's no statutory duty to detect, only a duty to report what a company already knows. Congress could close that without touching Section 230's core immunity — for instance, by tying detection obligations to objective, narrowly defined circumstances (a company builds and later disables its own known-CSAM matching tool, say) rather than a subjective "recklessness" standard that invites speculative suits against any platform offering encryption. The 2258A reporting regime already carries real teeth — up to $850,000 per missed report for large providers, doubling for repeat violations — which shows Congress can legislate specific, enforceable duties without rewriting the publisher-liability framework that keeps the open internet functional. The dismissal of Amy v. Apple isn't a verdict that Apple did enough. It's a reminder that when courts, survivors, and even judges agree a company should be doing more, the fix has to come from a legislature willing to write a precise rule — not from stretching a 1996 statute to cover a duty it was never written to impose.