Summary. What the twenty-six words do, what they do not, and where the line has moved.


The statute, and the misunderstanding

47 U.S.C. § 230 is frequently described as "the twenty-six words that created the internet," referring to subsection (c)(1):

"No provider or user of an interactive computer service shall be treated as the publisher or speaker of any information provided by another information content provider."

That description is memorable and misleading, because § 230 contains two separate protections that operate independently, and most public argument about the statute confuses them.

Subsection (c)(1) protects a service from being held liable as a publisher for content someone else created. This is the hosting immunity.

Subsection (c)(2) protects a service from liability for restricting access to material it considers objectionable, if the action is taken in good faith:

"No provider or user of an interactive computer service shall be held liable on account of—(A) any action voluntarily taken in good faith to restrict access to or availability of material that the provider or user considers to be obscene, lewd, lascivious, filthy, excessively violent, harassing, or otherwise objectionable, whether or not such material is constitutionally protected."

This is the moderation immunity.

The two are not the same, and the second is used far less than one would expect. Courts frequently resolve moderation claims under (c)(1) rather than (c)(2), reasoning that deciding what to publish — including deciding not to publish — is a traditional publisher function. That has the practical effect of extending (c)(1) to takedown decisions without requiring the good-faith showing that (c)(2) demands.

The historical context explains why both exist. Section 230 was enacted in 1996 in response to a New York decision holding that an online service that moderated content had thereby assumed publisher liability, while a service that moderated nothing had not. The perverse incentive was obvious: to avoid liability, do nothing. Congress reversed it, and the statute's own findings say so — the policy is "to encourage the development of technologies which maximize user control" and "to remove disincentives for the development and utilization of blocking and filtering technologies."

The three elements

Courts apply subsection (c)(1) through a three-part test. The defendant must be:

1. A provider or user of an interactive computer service. This is broad — "any information service, system, or access software provider that provides or enables computer access by multiple users to a computer server." It covers social networks, marketplaces, search engines, hosting providers, app stores, review sites, dating services, message boards, and the comment section of a newspaper. Courts have applied it to individual users who forward content, and to services that most people would not call platforms at all.

2. Treated as the publisher or speaker. The claim must seek to hold the defendant liable for a publishing function — deciding whether to publish, withdraw, postpone, or alter content. This element does the analytical work in the modern cases, because plaintiffs frame claims specifically to avoid it.

3. Information provided by another information content provider. The content must originate with someone else. An "information content provider" is anyone "responsible, in whole or in part, for the creation or development of" the content — and the phrase "in part" is why the next section matters.

The material contribution test

A service loses the protection for content it helped create. But every platform shapes content: it formats posts, ranks them, suggests hashtags, provides templates, and prompts users to write. If any of that counted as "development," the statute would protect nothing.

The controlling framework comes from the Ninth Circuit's en banc decision in Fair Housing Council of San Fernando Valley v. Roommates.Com, LLC, 521 F.3d 1157 (9th Cir. 2008). The site required users to answer questions about sex, sexual orientation, and family status through dropdown menus, then filtered listings by those answers.

The court held that requiring users to provide the discriminatory information, through a structured form the site designed, made the site a content provider as to that information. But it held the site protected as to the free-text "Additional Comments" section, where users wrote whatever they chose.

The test: a service is a content provider if it materially contributes to the alleged unlawfulness of the content. Neutral tools that users employ for unlawful purposes do not strip the protection; tools designed to elicit unlawful content do.

Applications:

Activity Generally protected?
Hosting user posts Yes
Ranking and recommending content Generally yes, though contested
Editing for length, format, or profanity Yes
Removing content Yes
Providing neutral templates and forms Yes
Requiring users to supply unlawful categories of information No
Writing or materially rewriting the content No
Paying a user to create specific content No
Encouraging unlawful content through design Contested

That last row is where the current litigation lives.

The four exceptions

Subsection (e) removes four categories from the statute's reach, and they are doing more work every year.

Federal criminal law. Section 230 does not immunize violations of federal criminal statutes. Prosecutions proceed unaffected.

Intellectual property. Section 230 has "no effect on any law pertaining to intellectual property." Copyright claims run through the separate safe harbor of 17 U.S.C. § 512, which requires a registered agent, a repeat-infringer policy, and expeditious removal on notice — a materially more demanding regime than § 230. Whether the carve-out extends to state intellectual property claims, notably the right of publicity, has split the circuits, and it is one of the more consequential unresolved questions for platforms.

The Electronic Communications Privacy Act. Section 230 does not limit the application of federal wiretap and stored communications law.

Sex trafficking. The 2018 amendment commonly called FOSTA-SESTA created an exception permitting certain civil claims under 18 U.S.C. § 1595 and state criminal prosecutions relating to sex trafficking. Its practical effect has been debated, but it established the precedent that Congress will carve out categories, and subsequent proposals have followed the same template.

Also outside the statute: claims that do not depend on third-party content at all. A platform's own promises, its own statements, and its own conduct are not protected. Breach of contract based on the platform's terms, a claim that the platform misrepresented its own practices, and a claim based on the platform's own speech all proceed.

What the Supreme Court has and has not decided

Three recent decisions are frequently cited for propositions they do not support.

Twitter, Inc. v. Taamneh, 598 U.S. 471 (2023) was not a § 230 case at all. It asked whether social media companies aided and abetted terrorism under the Anti-Terrorism Act by failing to remove content. The Court held they did not, applying ordinary aiding-and-abetting principles:

"[T]he mere creation of those platforms is not culpable. To be sure, it might be that bad actors like ISIS are able to use platforms like defendants' for illegal — and sometimes terrible — ends. But the same could be said of cell phones, email, or the internet generally."

The Court reasoned that providing generally available services to billions of users, without more, is not substantial assistance to a specific wrong.

Gonzalez v. Google LLC, 598 U.S. 617 (2023) squarely presented whether § 230 protects algorithmic recommendations. The Court declined to decide, issuing a brief per curiam opinion that, in light of Taamneh, the complaint stated little claim for relief regardless of § 230.

This is important and widely misreported. The Supreme Court has never ruled on whether recommendation algorithms fall within § 230. Lower courts have generally held they do, on the theory that recommending is a publishing function, but the question is open at the highest level and is being actively litigated.

Moody v. NetChoice, LLC, 603 U.S. 707 (2024) addressed state laws restricting platforms' ability to moderate. The Court vacated and remanded because the lower courts had not properly analyzed the laws' full scope in facial challenges — but it said a great deal about the merits along the way. Justice Kagan's opinion explained that a platform's curation of a feed is itself expressive activity protected by the First Amendment:

"[T]he editorial judgments influencing the content of those feeds are, contrary to the Fifth Circuit's view, protected expressive activity."

And:

"[A] State may not interfere with private actors' speech to advance its own vision of ideological balance."

The significance: even if Congress narrowed § 230, the First Amendment would independently protect much moderation activity. The two protections are separate and cumulative, and litigants who focus only on the statute miss half the analysis.

Pleading around the statute

Because § 230 defeats claims premised on third-party content, plaintiffs frame claims that are not.

Product design defect. The theory: the platform's design — infinite scroll, autoplay, engagement-optimized ranking, notification patterns — is defectively dangerous, independent of any particular content. Framed carefully, this is a claim about the platform's own conduct.

Courts have split. Some hold the theory is really about content and dismiss; others allow claims to proceed where the alleged defect is genuinely about functionality rather than about what was said. The Ninth Circuit's treatment of a claim that a platform's design facilitated harm, and the Third Circuit's approach treating a recommendation feed as the platform's own expressive product, illustrate the range. This is the most active area of platform litigation.

Negligent design and failure to warn. Similar framing, applied to features affecting minors.

Breach of the platform's own promises. A platform that says it removes certain content and does not may face contract and misrepresentation claims that do not depend on treating it as a publisher.

Its own speech. Statements the platform makes about safety, moderation, or product characteristics are its own content.

Distribution rather than publication. An argument, largely unsuccessful, that a defendant with notice of specific unlawful content becomes a distributor outside (c)(1).

Anti-discrimination claims where the platform's own tools structure the discrimination, following Roommates.Com.

The First Amendment layer

The constitutional analysis operates independently and often matters more.

Platforms are private actors. The state action doctrine means the First Amendment restrains government, not private companies. A user removed from a platform has no First Amendment claim against the platform. This is the single most common misunderstanding in public discussion of the topic.

Platforms have their own First Amendment rights. Moody confirms that curating a feed is expressive activity. Compelled carriage — requiring a platform to host speech it would exclude — is subject to serious constitutional scrutiny.

Government pressure on platforms raises separate questions. Where officials coerce a private platform into suppressing speech, the platform's action may become attributable to the state. The line between permissible persuasion and impermissible coercion is genuinely difficult and heavily litigated.

Access restrictions on speakers face scrutiny. Packingham v. North Carolina, 582 U.S. 98 (2017) struck down a law barring registered sex offenders from social media, describing such sites as among "the most important places . . . for the exchange of views," and Reno v. American Civil Liberties Union, 521 U.S. 844 (1997) established that online speech receives full First Amendment protection rather than the reduced protection applied to broadcast.

Frequently asked questions

Does § 230 protect a platform from claims by the content's author? Generally yes as to publication decisions, including removal. The frequent exception is a contract claim based on the platform's own terms, which does not treat the platform as a publisher of anyone's content and therefore falls outside the statute.

Are generative AI outputs protected? Almost certainly not, on the most natural reading. Section 230 protects a service from liability for content "provided by another information content provider." Material a service generates itself is its own content. Where a system reproduces or surfaces third-party material, the analysis is closer, and courts have only begun to address it.

Does the statute protect against injunctions as well as damages? Courts have generally held that § 230 bars claims seeking injunctive relief as well as damages, since both would treat the service as a publisher. Some courts have been more receptive to narrow injunctive relief, and the question is not uniformly settled.

Who bears the burden on the exceptions? The plaintiff, in practice. A plaintiff invoking the intellectual property or sex trafficking exception must plead facts bringing the claim within it, and a bare assertion that the claim is "an IP claim" does not survive scrutiny where the substance is a state tort.

Does moderating content cost a platform its immunity? No. That was the misconception § 230 was enacted to correct. Subsection (c)(2) protects good-faith moderation expressly, and courts frequently protect it under (c)(1) as a publishing function.

Does § 230 protect copyright infringement? No. Intellectual property is expressly excepted. Copyright liability runs through 17 U.S.C. § 512, which requires an agent, a repeat-infringer policy, and expeditious removal.

Does it protect a platform's own content? No. Only content provided by another information content provider.

Does it protect recommendation algorithms? Lower courts generally say yes. The Supreme Court declined to decide in Gonzalez, so the question is open.

Can a platform be sued for removing content? It can be sued; it usually wins. Subsection (c)(2) protects good-faith restriction, and courts often apply (c)(1) as well. Contract claims based on the platform's own terms are the exception that sometimes survives.

Does § 230 apply to state law claims? Yes, subject to the exceptions. It preempts inconsistent state law by its terms.

Is § 230 a First Amendment provision? No. It is a statute. The First Amendment operates separately, and after Moody it independently protects much moderation activity.

What about small platforms? Section 230 applies regardless of size. The DMCA safe harbor, by contrast, has procedural requirements that a small service must actually satisfy to benefit.

Three scenarios

The marketplace listing

Threadneedle Market is a peer-to-peer marketplace for handmade goods. A seller lists a children's sleep product that fails to meet safety standards; a child is injured. The family sues Threadneedle for negligence and product liability.

What § 230 protects. Claims premised on the listing — its description, its photographs, its claims about the product — are claims treating Threadneedle as the publisher of the seller's content. Those are barred.

What § 230 does not protect. Claims premised on Threadneedle's own conduct. If Threadneedle took possession of the goods, handled fulfillment, set the price, or held itself out as the seller, product liability may attach under state law doctrines that treat certain intermediaries as sellers — an analysis that has nothing to do with publishing. State courts have divided on when a marketplace is a "seller," and the answer turns on control over the transaction rather than on control over the content.

The design question. If Threadneedle's listing form required sellers to select from categories that themselves obscured safety information, Roommates.Com is in play.

What Threadneedle should have done. Verified safety certifications for regulated categories at onboarding; maintained a recall-monitoring process; and structured its role in fulfillment deliberately, understanding that operational control is what creates seller liability.

The removed account

Bellamy Argosy operates a channel with 400,000 subscribers on a video platform. The platform removes it for violating a policy on medical misinformation. Bellamy sues for breach of contract, tortious interference, and violation of a state law prohibiting platforms from removing content based on viewpoint.

Section 230(c)(1) and (c)(2) protect the removal decision itself. Bellamy's tort claims fail.

The contract claim is different. If the platform's terms promise a specific process — notice, an explanation, an appeal — and the platform did not follow it, the claim is about the platform's own promise, not about publishing. These claims survive dismissal with some regularity and fail later on the merits, usually because platform terms reserve broad discretion. Platforms that write specific procedural commitments into their terms create the exposure themselves.

The state statute runs into Moody. A law restricting a platform's editorial judgment about what to carry faces serious First Amendment problems independent of § 230, because curating a feed is expressive activity.

Practical lesson for platforms: promise a process you actually run, or reserve discretion clearly. The middle ground — aspirational commitments the operations team cannot meet at scale — is where the claims come from.

The harassment campaign

An anonymous user organizes a sustained harassment campaign against Dr. Ottoline Vasquez-Braun across a social platform. She reports it repeatedly over four months. The platform removes some posts and not others. She sues the platform.

Claims about the posts are barred. Failing to remove third-party content is the paradigm § 230 case, and notice does not change the analysis in most circuits — the "distributor liability" argument has been rejected repeatedly.

Claims that might survive. If the platform promised in its terms to act on reports within a stated time and did not, a contract theory exists. If the platform's own safety representations were false, a misrepresentation theory exists. If the platform's design — for example, a feature that surfaced the harassing account's content to her repeatedly — is framed as a defect independent of the content, a design claim may survive dismissal in some courts.

What actually helps her more than litigation: identifying the anonymous user. A pre-suit subpoena or a John Doe action seeking identifying information from the platform proceeds under ordinary discovery rules, and § 230 does not shield the user. Platforms respond to properly issued subpoenas, and the underlying claims against the individual are unaffected by the statute.

Running a platform so the protection holds

Section 230 is broad, and platforms still lose cases. Most losses trace to the platform's own conduct rather than to a gap in the statute.

Write terms you can actually follow. The most common self-inflicted wound. Terms promising a specific review timeline, a specific appeal process, or a specific standard create contract exposure that § 230 does not touch. Either build the process and run it, or reserve discretion in terms that say so.

Keep the platform's own speech separate. Editorial content, safety claims, and marketing statements are the platform's own content and are unprotected. A safety page describing what the platform does is a representation, and it should be accurate.

Be careful with structured inputs. Dropdowns, required fields, and templates that elicit categories of unlawful information are the Roommates.Com problem. Free-text fields are safe; forms that require users to supply the offending category are not. Review intake design with this in mind, particularly in housing, employment, lending, and insurance contexts where anti-discrimination law is specific.

Do not co-author. Editing for length and format is protected. Rewriting substance, adding claims, or paying users to say particular things is not.

Maintain the DMCA infrastructure separately. The intellectual property carve-out means copyright runs through 17 U.S.C. § 512. That requires a designated agent registered with the Copyright Office, a published notice procedure, expeditious removal, a counter-notice process, and — the requirement most often missed — a repeat infringer policy that is actually implemented. A platform with a policy on paper and no termination practice loses the safe harbor.

Address the state IP question deliberately. Whether the carve-out reaches state right-of-publicity claims is unsettled and circuit-dependent. Platforms hosting user images and voices should assume exposure and build a notice-and-removal process for publicity complaints even though no statute requires one.

Build a subpoena response process. Requests for user identifying information arrive constantly. A documented process — validate the legal basis, notify the user where permitted, respond within the required period, log everything — protects the platform and the users.

Document moderation decisions. Not for § 230, which rarely requires it, but for contract claims, for regulatory inquiries, and for the transparency reporting that several jurisdictions now require.

Watch the design claims. The most significant current exposure is not about content at all. It concerns features: engagement optimization, notification patterns, autoplay, recommendation systems directed at minors, and age assurance. These claims are pleaded as product defect precisely to avoid § 230, and they survive dismissal often enough to matter. Product decisions in these areas are legal decisions and should be reviewed as such.

The regulatory layer beyond Section 230

Section 230 addresses liability for third-party content. It does not address the growing body of affirmative obligations.

Transparency and reporting. Several jurisdictions require platforms to publish moderation statistics, explain enforcement decisions, and provide appeal mechanisms. These are obligations to disclose, not liability for content, and § 230 does not preempt them — though Moody signals that requirements compelling or restricting editorial judgment face First Amendment scrutiny.

Minors and design. Age-appropriate design requirements, default privacy settings for minors, restrictions on profiling, and limits on engagement-maximizing features aimed at children. 15 U.S.C. § 6501 and the rule at 16 C.F.R. Part 312 govern services directed to children under thirteen, with verifiable parental consent requirements and data minimization obligations.

Illegal content obligations. Notice-and-action requirements, trusted flagger systems, and risk assessment duties in some jurisdictions, particularly for very large services.

Consumer protection. 15 U.S.C. § 45 reaches unfair and deceptive practices, and platform representations about safety, moderation, and data practices are squarely within it. This is the most active federal enforcement vector against platforms and is entirely unaffected by § 230.

Marketplace-specific rules. Seller verification, disclosure requirements, and recall obligations for online marketplaces, which operate on the platform's own conduct rather than on the listing's content.

The practical point: a compliance program built around § 230 addresses only defensive liability. The affirmative obligations — transparency, minors' safety, notice-and-action, seller verification, and accurate representations — are where the enforcement activity is, and none of them is answered by the statute.

Litigating a Section 230 defense

The defense is usually raised early and often resolves the case, but it fails when asserted mechanically.

Raise it on the pleadings. Section 230 is an affirmative defense that courts routinely decide on a motion to dismiss where the complaint's own allegations establish the elements. The advantage is enormous: no discovery, no expense, no exposure of internal moderation practice. Waiting to raise it at summary judgment forfeits most of that value.

Establish the three elements from the complaint itself. The service is an interactive computer service; the claim treats the defendant as a publisher; the content came from another information content provider. Where the complaint alleges facts establishing all three — and complaints frequently do — the motion is straightforward.

Anticipate the recharacterization. Sophisticated plaintiffs plead around the statute deliberately, and the response must engage what they actually pleaded. Ask: does this claim require the fact-finder to determine that the defendant should have published, unpublished, or altered content? If yes, § 230 applies regardless of the label on the count. If the claim genuinely rests on the defendant's own conduct — a promise made, a statement issued, a feature built — the statute does not answer it, and a motion insisting otherwise loses credibility.

Do not overclaim. A brief asserting that § 230 bars every count, including the contract count based on the platform's own terms, invites the court to distrust the argument on the counts where it is correct. Concede what must be conceded and win the rest.

Watch the record. Where a plaintiff alleges the platform materially contributed to the content, the motion may require the court to look at the platform's actual interface. Screenshots attached to the complaint, or subject to judicial notice, can resolve it. Where the interface is genuinely contested, the issue may survive to discovery, which is the outcome to avoid.

Preserve the alternative grounds. Section 230 is a defense to liability, not a substitute for the merits. Brief the substantive deficiencies too — failure to state a claim, absence of duty, absence of causation — because a court reluctant to reach a broad statutory holding may prefer to dismiss on narrower grounds, and because the defense may be unavailable on appeal.

Consider fee exposure. Some state anti-SLAPP statutes reach claims arising from protected speech activity and provide fee-shifting. Where a claim against a platform arises from moderation or publication decisions, an anti-SLAPP motion may offer both dismissal and fees, and it should be evaluated alongside the § 230 motion.

Remember what is not protected. Federal criminal enforcement, intellectual property claims, ECPA claims, and the sex trafficking exception all proceed. A defense strategy premised entirely on § 230 leaves those unaddressed.

Where reform proposals would bite

Section 230 has been the subject of more legislative proposals than almost any other technology statute. Practitioners should understand the categories, because each would change platform operations differently.

Conditioning immunity on conduct. Proposals that make the protection available only to platforms meeting stated obligations — transparency reporting, appeal processes, defined moderation standards, or an absence of "algorithmic amplification." The practical effect would be to convert a threshold defense into a fact question about compliance, which would move the analysis from the pleadings to summary judgment and change the economics of every platform case.

Carving out categories. Following the FOSTA template, removing specified subject matter from the statute's reach — civil rights violations, child safety, terrorism, harassment, or drug sales. Categorical carve-outs are the most legislatively achievable form of reform and the one most likely to appear.

Distinguishing hosting from amplification. Proposals that protect passive hosting but not algorithmic recommendation. This would answer the question the Supreme Court declined to reach in Gonzalez v. Google LLC, 598 U.S. 617 (2023). It would also require courts to distinguish ranking from hosting, which is difficult given that every feed involves ordering choices.

Size thresholds. Applying obligations only to services above a user or revenue threshold, on the theory that a small forum should not bear the compliance burden of a global network.

Sunset provisions. Proposals to repeal the statute on a date certain, forcing a negotiation over a replacement.

What would survive repeal. This is the point most often missed in the debate. Repealing § 230 would not make platforms liable for everything. Traditional publisher liability requires fault, and the underlying torts have their own elements — defamation requires falsity and fault, negligence requires duty and causation. More importantly, Moody v. NetChoice, LLC, 603 U.S. 707 (2024) confirms that curating a feed is protected expressive activity, so the First Amendment would independently constrain much of what a repeal is imagined to accomplish. What repeal would reliably produce is a great deal more litigation, and a strong incentive for platforms to over-remove.

Advising clients through the uncertainty. Build the operational practices that would survive any of these proposals: accurate representations, a moderation process that matches the published terms, transparency data the platform can produce, working notice-and-action mechanisms, and deliberate design review for features affecting minors. Every reform proposal on the table would find that platform better prepared than one whose compliance program consists of citing the statute.

Section 230 outside the United States

American platform operators frequently assume the domestic framework travels. It does not, and the differences are structural rather than marginal.

No equivalent exists elsewhere. No other major jurisdiction has adopted a provision as broad as § 230. The common international model is conditional immunity: a hosting provider is protected while it lacks knowledge of unlawful content, and loses protection if it fails to act expeditiously once notified. That is closer to the American copyright regime under 17 U.S.C. § 512 than to § 230, and it means notice matters everywhere else in a way it does not here.

Notice-and-action is the norm. Where a platform receives a substantiated notice of illegal content, obligations attach: assess, act, inform the notifier, inform the affected user, and provide a route to challenge the decision. Several jurisdictions add statements-of-reasons requirements, internal complaint mechanisms, and out-of-court dispute settlement.

Risk assessment duties for large services. Obligations to assess systemic risks — illegal content, effects on fundamental rights, civic discourse, and minors' well-being — and to adopt mitigation measures, subject to independent audit. These are affirmative program obligations with no American analogue.

Trusted flaggers and priority handling. Designated entities whose notices receive expedited treatment.

Advertising and recommender transparency. Requirements to explain why a user sees particular content and to offer non-profiling alternatives.

Different defamation baselines. Several jurisdictions place the burden on the publisher to prove truth, and some permit orders requiring removal with extraterritorial effect. A platform operating globally faces takedown demands premised on standards that would fail entirely in a United States court.

Practical consequences for a platform with international users:

  1. Build notice-and-action for real. A process that exists only for copyright will not satisfy general illegal-content obligations.
  2. Log everything. Transparency reporting obligations require data that cannot be reconstructed later.
  3. Decide the geographic scope of removals deliberately. Global removal in response to a national order is a policy choice with consequences; so is geo-blocking.
  4. Watch the conflict. An order to remove lawful speech from one jurisdiction may conflict with obligations or expectations elsewhere. Platforms need a decision framework, not an ad hoc response.
  5. Do not describe § 230 to non-United States regulators as a defense. It is not one, and asserting it damages credibility.

The user's side: suing the person who actually did it

Section 230 protects the platform. It does nothing for the person who posted the content, and counsel advising a client harmed online should start there rather than at the platform.

Identify the speaker. Where the poster is anonymous, the route is a pre-suit discovery mechanism or a John Doe complaint followed by a subpoena to the platform for identifying information. Platforms respond to properly issued subpoenas, and § 230 is not an obstacle — it is a defense to the platform's own liability, not a shield against discovery.

Expect a notice period. Many platforms notify the account holder before producing identifying information, which gives the poster an opportunity to move to quash. Several jurisdictions apply a heightened standard before unmasking an anonymous speaker, typically requiring the plaintiff to make a prima facie showing on the merits and to demonstrate that the information is necessary. Build the underlying claim before seeking the identity.

Preserve first. Send a preservation letter to the platform immediately. Content disappears — deleted by the poster, removed by moderation, or aged out of retention — and the record you need may exist for weeks rather than years.

Capture everything. Screenshots with URLs and timestamps, archived copies, and where possible the post's unique identifier. Authentication becomes an issue later, so document who captured what and when.

Use the platform's own processes. Reporting mechanisms for harassment, impersonation, and privacy violations resolve most situations faster than litigation and cost nothing. Where content violates the platform's terms, the terms are the remedy.

Consider the non-platform defendants. An employer whose employee posted from a work account, a company that paid for the content, or a coordinated group may all be reachable. Section 230 protects the intermediary, not the participants.

Be realistic about the anonymous poster. Many are judgment-proof, and identification is sometimes impossible where the account was created with false information over an anonymizing service. Where that is the outcome, the platform's reporting process and search delisting may be the only practical remedies, and saying so early is better advice than an expensive unmasking effort that fails.

A note on what the statute is for

Arguments about § 230 usually proceed as though the choice is between protecting platforms and protecting users. That framing obscures what the provision actually allocates.

Before 1996, the operative rule made moderation legally dangerous. A service that reviewed content and removed some of it had, courts reasoned, exercised editorial control and become a publisher; a service that reviewed nothing had not. The rule created an incentive to abandon moderation entirely, and Congress reversed it because the alternative was worse for users, not better.

That history explains a feature of the statute that critics and defenders both tend to underplay: § 230 is what makes aggressive moderation legally safe. A platform that removes harassment, fraud, and abuse at scale — making millions of judgment calls, getting many of them wrong — can do so without each error becoming a lawsuit. Narrowing the provision would not obviously produce more careful moderation; the more predictable result is either less moderation, to avoid the appearance of editorial control, or far more removal, to avoid hosting anything contestable.

None of which resolves the harder question, which is whether a rule designed for message boards fits services that rank, recommend, and optimize at a scale nobody contemplated in 1996. The design-defect litigation is an attempt to reach that question without going through Congress, and the outcome will shape platform product decisions more than any amendment likely to pass.

For counsel, the practical posture is unchanged by the debate. Advise clients to build the operational practices that hold up regardless: terms that match the process actually run, representations that are accurate, notice mechanisms that work, deliberate design review for features affecting minors, and records sufficient to demonstrate all of it. A platform that has done those things is defended by the statute where it applies and is defensible where it does not.

Related documents