Apple Got Sued for Not Scanning Your iCloud Photos
Tech companies get sued for looking at user data all the time. Getting sued for not looking is newer. Apple is now defending itself against exactly that claim, and the case has dragged the industry’s most stubborn unsolved problem into a courtroom where nobody wanted it.
Worth flagging upfront: this isn’t a story that’s been lighting up Reddit or HN in the last month. Litigation moves in geological time — quiet for years, loud for a week when a ruling drops. So the interesting part here isn’t the discourse. It’s the structure of the trap Apple walked into.
Remember That 2021 Announcement
August 2021. Apple announced it would detect child sexual abuse material (CSAM) in photos uploaded to iCloud. The method was clever: instead of opening files on the server, Apple would compare image hashes against a known CSAM database on the device itself.
Apple pitched it as the best of both worlds. Privacy preserved, children protected. The reception was brutal. Security researchers, civil liberties groups, and cryptographers lined up to tear it apart. Their objection wasn’t about the hashing math. It was that once you build content-scanning infrastructure inside a phone, the scope never stays where you put it.
The question nobody at Apple could answer: when a government shows up and says “great system, now add these hashes to the list,” what exactly does Apple say no with? Apple shelved the plan within weeks and killed it outright in December 2022. Then it went the opposite direction entirely and shipped Advanced Data Protection, its end-to-end encryption option for iCloud.
The Lawsuit
Three years later, the counterattack arrived from the other flank. Survivors of child sexual abuse filed a class action against Apple. The argument is straightforward: Apple had the capability, publicly committed to deploying it, then walked away — and in doing so let iCloud operate as a distribution channel.
Here’s the sharp part. The plaintiffs leaned harder on announcing and abandoning than on never building it at all. The announcement, they argue, was a promise. People relied on it. Legally they wrapped this in product liability and negligence theories, trying to frame iCloud as a defective product.
The numbers explain why the theory has bite. Google files millions of CSAM reports annually with the National Center for Missing and Exploited Children. Meta files more. Apple’s reports sat in the hundreds per year for a long stretch. Given the size of Apple’s user base, that gap isn’t subtle. The plaintiffs offered it as evidence of a simple mechanism: you don’t find what you don’t look for.
Why the Court Sided With Apple
Apple won. But the reasoning wasn’t that Apple behaved well. It was Section 230 of the Communications Decency Act.
Section 230 is the load-bearing wall of American internet law. Online platforms aren’t treated as publishers of third-party content. It’s why YouTube isn’t the defendant when someone uploads a defamatory video.
Apple’s defense sat squarely on it. Files in iCloud are uploaded by users; Apple supplies storage. The decision not to scan, Apple argued, is an editorial judgment about how to handle content. Section 230 explicitly immunizes platforms that voluntarily filter content — and the court held that the inverse choice, declining to filter, sits under the same umbrella.
The product liability claim failed too. Cloud storage is a service, not a manufactured good, and the doctrine doesn’t stretch that far.
The Part Where the Judge Squirms
This is where it gets interesting. There’s a recurring pattern in rulings like this: the court rules for the platform, then leaves a paragraph making clear it isn’t happy about it and doesn’t think this is its call to make.
Follow the logic and you see why. If a court held that Apple should have scanned, it would effectively impose a content-surveillance duty on every cloud provider in the country. That’s not a norm one district judge invents from the bench. Rule the other way, and the status quo — a report count near the floor — becomes legally blessed, and victims lose their remedy.
Neither option is clean. So courts reach for procedural avoidance: dismiss on the clear statutory text, decline to pretend the underlying problem is small. Ball goes to Congress. Congress has been debating Section 230 reform for over a decade without shipping anything.
The Question That Actually Remains
Look at the timeline and the symmetry is almost comic. In 2021 Apple got hammered for planning to scan. In 2025 it got sued for deciding not to. Same company, opposite directions, both times the villain.
And this isn’t an Apple problem. Every end-to-end encrypted service is standing in the same spot — Signal, WhatsApp, Telegram. If the provider can’t read the content by design, it can’t read the illegal content either. That’s not a bug. That’s the entire specification.
There’s still no technical escape hatch. Client-side scanning, homomorphic encryption, trusted execution environments — every proposal runs into the same wall: who controls the surveillance capability once it exists? It’s the exact question the cryptographers put to Apple in 2021, and it remains unanswered.
The Takeaway
Apple won, but the win doesn’t mean Apple was right. It means the law isn’t equipped to answer the question. The case is closed and the problem is exactly where it was.
So where do you land? Accept a blind spot in the surveillance net as the price of your phone not inspecting your photos — or accept the scanning as the price of catching abuse? If that choice feels easy, you probably haven’t sat with the other side’s argument long enough. Five years of deadlock isn’t an accident.
Comments
Loading comments...