Inside Apple's impossible war on child exploitation, as the company scrapped its on-device CSAM scanning system and key team members behind the initiative left
often tens of millions—of tips on child sexual abuse material to law enforcement each year to help keep kids safe. Apple, the outlier, last year flagged 234. (Before that: 160.) @iblametom and I investigated why:https://www.forbes.com/... Thomas Brewster / @iblametom : Some big questions remain: 1. Apple still scans outgoing https://icloud.com/ emails for CSAM. Why, when it doesn't scan other iCloud data? 2. Why do trust and safety staff report to a longtime sales exec? 3. How much investment is Apple putting into child safety staff? Thomas Brewster / @iblametom : NEW - In the 2 years since Apple announced then canned CSAM scanning tech, it lost senior folks working on child safety, angered police, but gained plenty of fans and a heavier focus on privacy. Inside Apple's Impossible War On Child Exploitation: https://www.forbes.com/...
Context & Ripple Effects
Apple’s withdrawal follows a contentious rollout in which critics said its child-safety effort was developed without sufficient outside input; the company later removed references to the scanning plan from its child-safety page.
The decision arrives as advocates renew pressure for iCloud detection, while Apple has argued broader scanning could create a slippery slope of unintended consequences. The remaining email-scanning practice makes the boundary of its enforcement policy a central issue.
First-order effects
- Apple has abandoned its proposed on-device CSAM-scanning system, while the team associated with the initiative has lost key members.
- Apple’s continued scanning of outgoing iCloud.com email, but not other iCloud data, leaves a narrower and more visibly differentiated enforcement approach for users, advocates, and law enforcement.
Second-order effects
- Child-safety advocates and police are likely to focus pressure on Apple’s gap between email scanning and the absence of broader iCloud scanning; that pressure was already visible in a child-advocacy campaign targeting iCloud.
- The episode raises the operational cost of deploying safety controls that touch private user data: product, trust-and-safety, and communications decisions become inseparable from public confidence.
Third-order effects
- If this pattern persists, consumer platforms may increasingly separate limited server-side abuse detection from device-level scanning, treating the latter as a much higher trust and governance threshold.
- The longer-term contest is not simply whether platforms act on CSAM, but which technical enforcement surfaces can retain legitimacy with privacy advocates, child-safety groups, and authorities at once.
The trend: Child-safety enforcement is becoming a test of whether platforms can expand detection without undermining the privacy commitments that differentiate their services.