Crossing the Rubicon: alternative readings to Section 230 of the Communications Decency Act (CDA) overbroad interpretation

0

On the 24 and 25 of March, two US courts embarked on a path to rewrite the rules governing “Big Tech” with potential cascading effects for the public at large (Rossini C., 2026).

The Santa Fe case has seen the State of New Mexico v. Meta Platforms, Inc. (Meta) arguing over consumer protection before a jury trial. The opening statements of its second phase have been heard on May 4th.

Meanwhile, in Los Angeles County Superior Court (P.F., et al. v. Meta Platforms, Inc., et al. 23SMCV03371), the jury had to deal with a personal injury trial that found Meta and Google (namely, the YouTube video platform) negligent in the design of their platforms, awarding $6 million in punitive and compensatory damages to a single plaintiff.

Jury verdicts: Overview

The jury in the Santa Fe case was instructed to assess whether Meta had misled consumers about the safety of its products under the New Mexico Unfair Practices Act. Relying on that, the state attorney was able to defeat the protection usually afforded to platforms under Section 230 of the Communications Decency Act (CDA) (the so-called “good Samaritan” protection).

The case was preceded by a lengthy investigation on Meta’s platforms to protect children from sexual abuse, online solicitation, and other harms. In the complaint, the attorney general alleged that « the company exposes children to the twin dangers of sexual exploitation and mental health harm ». The jury was presented with conspicuous evidentiary material supposedly showing that Meta’s statements « misled the public about a broader pattern of harm » (Batt M., 2026).

The findings relied on three grounds: deception, recklessness, and unconscionability. Firstly, as the exchange of data for services constitutes commerce and falls under the state’s consumer protection statute, the misrepresentation as to the risks posed by the use of the product amounted to deception. Secondly, despite repeated warnings about harmful content, Meta portrayed its efforts as adequate and reportedly chose to override those warnings for commercial gain. Thirdly, Meta purportedly exploited consumers, mostly minors, who lacked the capacity to protect themselves (Rossini, 2026). As a result of those conducts, the jury ordered Meta to pay the maximum penalty under the law, $5,000 per violation, totalling (only) $375 million in civil penalties for violating New Mexico’s consumer protection laws.

Along with the consumer protection claim, the New Mexico attorney general pursued a public nuisance claim, which is set to be heard in a bench trial scheduled to begin on May 4th, 2026. Such a phase will see the state attorney arguing that social media companies’ design features create an unreasonable interference with a collectively held right, notably the right to public health (Batt M., 2026). Most importantly, he will seek injunctive relief that might require Meta not only to pay additional damages but also to make structural changes to its platforms, such as implementing effective age verification, modifying algorithms, and establishing independent oversight (Hendrix J., 2026).

Meanwhile, in Los Angeles, another jury was called to establish if both Meta and YouTube had been crafting their design features in order to maximise engagement (and therefore profit) at the expense of a young girl’s health, in other words, if the harm was foreseeable and intentional.

The wheel was set in motion by a 20-year-old woman identified as K.G.M., who sued Meta, YouTube, Snap and TikTok, alleging that, by pushing her to compulsive use of the platforms since she was 6 years old through their deliberate design choices like infinite scroll, autoplay video and engagement-based recommendation algorithms, these social media platforms caused her harm. She was reportedly diagnosed with anxiety, depression, body dysmorphia, and suffers from suicidal ideations. (Kerr D., 2025; Rossini C., 2026).

Upon denying the platform’s motions for summary judgment, judge Kuhl ruled that the defendant’s companies had to face trial because of evidence suggesting that specific design features, such as infinite scroll and autoplay, may have caused independent injury regardless of the content viewed (conduct-versus-content legal theory). In other words, the judge acknowledged the substantial difference between features like notification timing and engagement loops, which might not be covered by Section 230 immunity, and features related to third-party content publishing, which Section 230 might protect (Rossini C., 2026; Batt M., 2026).

While K.G.M. settled with Snap and TikTok on undisclosed terms (Rossini C., 2026), the case, part of a JCCP (judicial council coordinated proceeding), which is a mechanism used in courts to litigate many cases that involve similar issues together, went to trial for Meta and YouTube (Batt M., 2026). This case too engages product liability, like the Santa Fe case; however, for the Los Angeles claim to prevail, plaintiffs « also have to prove a causal connection between how that product design then impacted individual plaintiffs » (Hendrix J., 2026).

As many authors have pointed out (Rossini C., 2026), there is a clear analogy to tobacco litigation, particularly in relation to the soon-to-be-heard public nuisance trial in New Mexico. By way of background, in the 1990s, states succeeded against tobacco companies by proving they had concealed evidence about the addictive and deadly nature of their products. A master settlement agreement (MSA) between the settling states and a number of manufacturers was entered into by the parties, releasing the participating manufacturers from past and future legal claims for costs incurred by the states for smoking-related illnesses and death and for equitable relief. The release did not include the individual claims of their residents. In exchange, the participating manufacturers agreed not only to make annual payments in perpetuity to the settling states, possibly earmarked for programs to address the harms caused, but also to substantially restrict their advertising, promotion, and marketing of cigarettes.

Why are US verdicts important?

Notwithstanding announcements by the defendant companies about filing appeals against the rulings at stake, the importance of those verdicts in the US lies in the consolidation of an alternative approach, notably platform design, to overcome the protection often afforded to platforms by Section 230.

On the one hand, Section 230(c) (1) ensures that platforms are not treated as the publisher or speaker of content provided by others. On the other hand, Section 230 (c) (2) grants immunity to platforms that, in good faith, restrict access to obscene or harassing content, encouraging moderation without fear of legal liability, and regardless of whether the material is or is not constitutionally protected; or enable or make available to providers of content the technical means to restrict access to material described beforehand.

Section 230 was historically designed to foster (although not in its entirety from the outset, Reno v. Aclu) a “free marketplace of ideas” (John Perry Barlow’s 1996 declaration), relying on the two core protections above. In their recent amicus brief filed in Re: Social media adolescent addiction/personal injury products liability litigation against Meta, TikTok, Snap and Google, the amici plainly explain that Congress enacted Section 230 specifically to prevent the “moderator’s dilemma”, that is, a situation where an internet company’s choice to moderate content would lead to strict liability for all user-generated material. Under this dilemma, an internet company is supposedly left with three choices: proactively monitor and remove all potentially illegal content; forego content moderation entirely, leaving platforms full of harmful content; or stop hosting user-generated content altogether.

The shield provided for by Section 230 functioned so well that it allegedly brought to concentration of enormous power in the hands of a tiny number of corporations (Franks A.M., 2021), so that nowadays the major players in the free speech arena are not only nation-states on the one hand, and speakers, such legacy media, civil-society organizations, and the like on the other, but also privately owned internet-infrastructure companies, including social media companies, and search engines (Balkin J.M., 2018).

In respect of the changed scenario in which Section 230 are to be applied (Weiland M.N., 2022), some scholars, notably Prof. Frank, have emphasised that Section 230(c)(1) immunity for content that intermediaries choose to present or promote should only be granted when three conditions are met: « one, when the content in question is speech, as opposed to conduct; two, when the speech is wholly provided by a third party, as opposed to being solicited or encouraged by the platform itself; and three, when the platform has not exhibited deliberate indifference to harm caused by that speech ».She has further suggested that even a minimal reform, such as the amendment of the definition of “information content provider” in order to include also “solicitation and encouragement of information” could improve upon the status quo(Frank M.A., 2025). Currently, Section 230 defines an information content provider as any person or entity that is responsible, in whole or in part, for the creation or development of information provided through the Internet or any other interactive computer service. Whilst the term interactive computer service means any information service, system, or access software provider that provides or enables computer access by multiple users to a computer server, including specifically a service or system that provides access to the Internet and such systems operated or services offered by libraries or educational institutions. In this context, a recent ruling, Anderson v. TikTok (2024), can be placed. The issue before the court was whether TikTok could claim immunity under Section 230(c)(1) for content that its curated algorithm showed to users (specifically a “Blackout Challenge”). The court has held that recommendation algorithms are not protected by Section 230 because they select and organise videos based on their own decision-making processes rather than passively host content (Frank M.A., 2025). In other words, “curation of speech” should somehow be intended as « both a right and a responsibility » (Frank M.A., 2025).

Other scholars, such as Keller, focus on user empowerment tools as a better alternative to both state-directed content moderation and broad design mandates; so as to fend off potential “terminological slippage” between content moderation and design, where terms like “design,” “systems,” and “risk mitigation” may allegedly mask fundamental content-based restrictions on lawful speech (Keller D., 2025).

Besides alternative readings of Section 230, there are two other reasons why the verdicts are particularly noteworthy, and those aspects could be especially relevant in the light of the current European Union scenario too.

Europe’s take

In the last two decades, the EU’s policy on digital technologies has evolved towards a constitutional approach centred on protecting fundamental rights and democratic values. This shift, often described as “digital constitutionalism” (De Gregorio G., 2022), sets boundaries on the exercise of power, whether by states or private actors, in a networked society. The transition has been marked by the European Declaration on Digital Rights and Principle in 2022, which paved the way for an ambitious legal framework for the governance of digital technologies, anchored in legislative instruments, such as the General Data Protection Regulation (GDPR), Digital Services Act (DSA), Digital Markets Act (DMA), the Data Act, the Data Governance Act (DGA), the Artificial Intelligence Act (AI Act), and the future Digital Fairness Act (DFA). Central to these laws is the idea that fundamental rights must be protected “by design and by default”.

Similarly to Section 230 in US, Article 6 of the DSA, provides hosting services with a conditional shield pursuant to which the providers shall not be held liable for the information stored at the request of a recipient of the service, on condition that the providers do not have actual knowledge of illegal content and, upon obtaining such knowledge or awareness, acts expeditiously to remove or to disable access to that content. Likewise, under Article 7 of the DSA, providers of intermediary services are not deemed ineligible for the above exemptions solely because they, in good faith and in a diligent manner, carry out voluntary own-initiative investigations into illegal content, or take the necessary measures to comply with the requirements of law.

However, in contrast to US reactive and case-specific litigation, the DSA goes further to establish a number of provisions governing content moderation in more detail, in terms of actors, procedures, remedies and balancing exercise; design features; transparency obligations as well as risk assessment duties, beyond dissemination of illegal content and including « any actual or foreseeable negative effects for the exercise of fundamental rights », « civic discourse and electoral processes, and public security », « gender-based violence, the protection of public health and minors and serious negative consequences to the person’s physical and mental well-being ».

Notwithstanding their different legal basis, both US courts and the European Commission (in its investigation of TikTokunder the DSA) reached the conclusion that certain “addictive” design features, such as infinite scroll, autoplay, and recommendation systems, implemented by platforms violate the law. Further to that, on April 29th, the European Commission has preliminarily found Meta’s platforms to be in breach of the DSA for failing to diligently identify, assess, and mitigate the risks of minors under 13 accessing their services.

On the private side, Bits of Freedom, a digital rights organisation, has recently filed a request for enforcement with the Authority on Consumers and Markets in the Netherlands, the designated national digital service coordinator responsible for enforcing the DSA there. The filing focuses on an alleged manipulative design in Snapchat’s notifications. Indeed, according to the DSA (Article 25, specifically), providers must not design online platforms in a deceitful manner that would impair recipients’ ability to make free and informed decisions, for instance, “dark patterns”( see also the recent investigations launched by the   Irish regulator (Coimisiún na Meán) to assess whether Instagram and Facebook are in breach of Articles 27 and 25 of the DSA).

In October 2025, the same organisation had obtained favourable findings from the Amsterdam Court, upheld by the Court of Appeal, in relation to another matter, specifically, Meta’s violation of Article 38 of the DSA. As a result of that, since the beginning of 2026, most Facebook and Instagram users in the Netherlands have been able to choose between two feeds: one of them compiled by Meta, based on the profile created about the user; the other is a feed with posts from the accounts the user follows in chronological order. However, the positive effect of this victory might be in the long-term, the unrestrained participation in public debate.

The weight of the obligation set out in Article 38 of the DSA had been also reiterated, together with Articles 39 and 40, in the November 2025 judgment of the EU General Court on the case Amazon EU Sàrl v European Commission (T-367/23). In particular, the court emphasised that Article 38 not only strengthens consumer rights, a core protection under the EU Charter of Fundamental Rights, by allowing users to choose the information to which they are exposed, but also prevents systemic risk in relation to the exercise of fundamental rights. According to the court, systemic risks, as spelt out in Article 34 § 1 of the DSA, are identified as such for their reach, i.e. their large-scale effects, potentially affecting a significant portion of society, rather than risks within a specific technical system, and regardless of whether only recipients of a single Member State were to be exposed to those risks.

“Bellwether”

It clearly follows from the above that the key values of the two US verdicts are: evidence and precedent.

In terms of evidence, the US trials brought to public knowledge internal data, metrics, and experimental evidence that could support rigorous outcome-oriented design-based regulation. Meta’s Internal Researchcompiled and annotated by the Tech and Society Lab at NYU Stern, shows what Meta ostensibly knew: « that employees compared the platform to slot machines and drugs; that 85 percent of clinicians surveyed by Meta said social media can be addictive; that its own research showed teens were unhappy with the time they spent on its apps; and that when users were randomly assigned to stop using Facebook and Instagram, their depression, anxiety, and loneliness improved. »(Rosenblat, M.O. 2026). Such internal documents cannot now be easily ignored in the conversation around platforms’ safety and accountability. All the more so, given K.G.M. trial shares legal teams and an evidence pool, including internal Meta documents, with a federal multidistrict litigation (MDL) concerning similar claims related to social media addiction, which is scheduled to proceed in Northern California courts in June (Batt, M. 2026), and considering that in Europe, early risk assessments remained largely descriptive (Isola C., 2026).

In terms of accountability, the two verdicts are symptomatic of a broader trend towards engaging the platform liability through product liability and design regulation. In the US, for instance, Knight-Georgetown Institute (KGI) is advancing collaboration between researchers, legal scholars, and litigators pursuing cases against online platforms, not only to inform litigation and strengthen platform accountability but also to instruct policy, advance future scholarship, and ultimately change technology design.

In a way, the verdicts help steer the conversation from what content appears on the platforms to why and how it is delivered (Rosenblat, M.O. 2026).

Conclusion

Despite conflicting views, Section 230(c) of the CDA remains a challenging provision that, according to some scholars, in order to preserve its core function, needs adjustment to the current state of the art.

However, the present US cases have shown both that a workaround is not only possible but also timely under certain circumstances. Above all, those cases have explained, substantiated, and linked to the law the practical impact and implications of platforms’ model and conduct, making it possible for the courts to assess it concretely.

While EU courts may take courage and set their own precedent on addictive design, considering, for instance, TikTok’s preliminary findings, refine risk assessment concrete significance, and acknowledge the relevance of data access and scrutiny; the US may start to think whether to rely solely on after-the-fact remedy or, on the basis of the knowledge accumulated as of today, even if not completely univocal, push for legislative changes to regulate by design and prevent harm before it occurs.

Given the complexity of the challenges at stake and the systemic response required, what remains to be seen is whether the path embarked by the two US courts will lead to adjustment of the current legislative framework, taking also advantage from existing and future complementary measures (for instance data and privacy protections, competition rules, and fundamental rights) or, similarly to other industry, will push so far as to rewrite the standards expected from “Big Tech” «before rolling out a product out to billions of people» (Potel-Saville M., 2026).

Share this article!

About Author

Lyda Mastrantonio

Leave A Reply