Apple、Amy v. Apple 事件で iCloud の CSAM スキャンを行わなかったことに対する責任を免除される
Apple Defeats Liability for Not Scanning iCloud for CSAM in Amy v. Apple
Court Rules Section 230 Protects Apple's Decision Not to Scan iCloud
In the case of Amy v. Apple Inc., a US court dismissed a third amended complaint alleging that Apple's failure to implement industry-standard CSAM (Child Sexual Abuse Material) detection in iCloud storage constituted a design defect. The court ruled that Apple is entitled to complete immunity under Section 230 of the Communications Decency Act, as the plaintiffs' claims essentially sought to treat Apple as a publisher or speaker of third-party content.
Section 230 Immunity and the "Publisher" Role
The court determined that Section 230 applies because the plaintiffs' injuries resulted from the actions of third parties using iCloud to share CSAM. The court highlighted several key legal points:
- Publisher Status: The plaintiffs argued that Apple should have used available technology to prevent the distribution of CSAM. The court found that the duties the plaintiffs sought to invoke "spring from the defendant's status as publisher," and therefore, immunity applies.
- Irrelevance of Knowledge: Even if Apple was aware that its tools were likely to be used to distribute child pornography—a point the court noted was confirmed by internal Apple text messages—under current law, Apple remains immune regardless of that general knowledge.
- Design Decisions vs. Content Moderation: Citing Doe v. Grindr, the court stated that Section 230 bars claims arising from design decisions when those claims relate to Apple's role in facilitating the communication and content of others. Specifically, the court noted that any tool used to detect CSAM must necessarily review the content, making the decision to deploy such a tool a choice related to content moderation.
Rejection of Legal Workarounds
The court explicitly rejected several attempts by the plaintiffs to bypass Section 230 immunity:
- Reporting Infrastructure: The court distinguished this case from Doe v. Twitter, noting that while Twitter could fix reporting infrastructure without monitoring content, Apple cannot implement CSAM safeguards without actively monitoring and reporting images via tools like NeuralHash or PhotoDNA.
- Content Creation: The Lemmon v. Snap workaround failed because Apple did not create the harmful content (unlike a Snapchat filter).
- Content Modification: The Roommates.com workaround failed because Apple did not modify or augment the CSAM on its servers.
The Tension Between Privacy, Encryption, and Child Safety
While Apple won the legal battle, Judge Wise expressed significant unease regarding the implications of the ruling. She noted that while no law currently obligates companies to proactively scan for CSAM, the current legal framework leaves victims of child abuse as "collateral damage" of privacy protections.
The Role of End-to-End Encryption (E2EE)
Apple's shift toward end-to-end encryption for iCloud files was a pivotal move. The court's opinion mentioned encryption briefly, but technical experts and legal analysts argue that E2EE is the critical attribute: forcing a company to scan for CSAM in an encrypted environment would require breaking E2EE for all users. This would potentially expose private data to criminal actors and government weaponization.
Judicial Perspective on Legislative Action
Judge Wise concluded that if lawmakers want to ensure companies address the dissemination of CSAM, they must mandate it by law, as voluntary efforts have proven inadequate. She stated:
"If lawmakers expected that companies would take steps to prevent their products from being used for storing and distributing child pornography based on something short of a legal imperative, this case, like many others before it, demonstrates the inadequacy of that approach."
Community Insights and Technical Counterpoints
Discussion among technical observers highlights several critical perspectives on the trade‑offs involved in this case:
The "Physics" of Encryption
Some contributors argue that there is no "middle ground" for encryption. If a system is designed to be truly end‑to‑end encrypted, the service provider cannot see the content. To implement scanning, the provider must be party to the communication, effectively destroying the privacy guarantee for all users.
Client‑Side vs. Server‑Side Scanning
There is a debate regarding Apple's previous attempts to implement on‑device (client‑side) scanning. While some argue this is marginally better than server‑side scanning, others contend that both paths lead to "privacy rot" and create vulnerabilities that can be exploited by governments to monitor other types of speech.
Critique of Law Enforcement Priorities
Some observers suggest that the focus on scanning platforms for CSAM—which occurs after the abuse has taken place—is a misplaced priority compared to the proactive prevention of Child Sexual Abuse (CSA) and the prosecution of the actual perpetrators through traditional law enforcement methods rather than mass surveillance of cloud storage.
要約
米国の裁判所は、Apple が iCloud ストレージで児童性的虐待資料(CSAM)をスキャンしないという決定について、Section 230 が免責を提供すると判断し、訴訟を棄却しました。これにより、プライバシーと暗号化を優先し、積極的なコンテンツモデレーションよりも法的保護が優先されることが再確認されました。
タイトル
Apple、Amy v. Apple 事件で iCloud の CSAM スキャンを行わなかったことに対する責任を免除される