A close look at the EARN IT Act, which is modeled after FOSTA and was recently reintroduced in Congress, and why it risks exacerbating the online CSAM problem
This is the latest entry in my lengthy archive of writing, talks, and interviews about the EARN IT Act:
The Center for Internet and SocietyRiana Pfefferkorn
Context & Ripple Effects
The bill returns after earlier revisions that critics said still threatened online speech, and after it was framed as making platforms earn Section 230 protections by meeting anti-exploitation standards. Its FOSTA-based model places it in the same policy debate as tying liability protections to mandated platform practices.
Related coverage contrasts EARN IT with the PACT Act’s alternative approach to Section 230 reform, while the Senate Judiciary Committee’s subsequent advance shows the proposal moving beyond renewed introduction into an active congressional vehicle.
First-order effects
Congress’s reintroduction renews pressure on online services that rely on Section 230 protections, particularly where compliance standards implicate CSAM detection, user privacy, and service security.
FOSTA becomes the operative precedent in the debate: advocates and critics are again judging EARN IT by whether its liability-focused model reduces exploitation without worsening the problem it targets.
Second-order effects
The proposal sharpens the choice for lawmakers between EARN IT’s standards-linked liability approach and the PACT Act-style reform discussed in related coverage, forcing a more explicit contest over how Section 230 should be changed.
Platforms facing potential exposure have incentives to favor more restrictive content and access controls, extending the speech and privacy concerns raised in the related analysis beyond CSAM-specific enforcement.
Third-order effects
If Congress continues to pursue Section 230 reform through eligibility conditions, platform liability protection becomes increasingly contingent on federally preferred moderation and safety practices rather than a baseline legal shield.
The policy dispute is converging on whether online-safety regulation should use FOSTA-like liability leverage or narrower procedural reforms, with consequences for how services balance abuse prevention, privacy, and lawful speech.
The trend: EARN IT is one data point in a broader shift toward using Section 230 eligibility and liability exposure as levers for online-safety regulation.
🚨 The #EarnItAct's reintroduction in the Senate threatens #freespeech & internet users' crucial protections from strong #encryption. Addressing online child exploitation is essential, but this bill increases risks to the online safety of children+adults. https://cdt.org/...
I wrote up why the reintroduced #EARNITAct is worse than ever. There are links to my many, many previous writings on this topic. There's a run-down of why it's so harmful. There's a table of the ways it doesn't help. https://cyberlaw.stanford.edu/ ...
So @Riana_Crypto has put together a detailed “why EARN IT is terrible” post complete with a handy dandy table, that shows how (1) no matter how you define the problem (2) EARN IT is not the answer... https://cyberlaw.stanford.edu/ ...
Have you heard of the “EARN IT” Act? It would “pave the way for a massive new surveillance system, run by private companies, that would roll back some of the most important privacy and security features in technology used by people around the globe."https://www.eff.org/...
#CyberpunkisNow The US Senate is trying to pass the EARN IT Act again. Senators say the bill will combat online child exploitation; in reality, it'll seriously impact online encryption & may undermine actual efforts to address online child exploitation. https://techdirt.com/... h…
“So it's not even clear what problem these Senators think they're solving (unless the problem is “not enough headlines during an election year about how I'm protecting the children.")" - @mmasnick https://www.techdirt.com/...
“Protecting children online is a laudable and urgent goal. However, the EARN IT Act would do little to protect victims - to the contrary, it risks making it even harder to track down and convict offenders.” https://cyberlaw.stanford.edu/ ...