A close look at how the EARN IT Act, which is modeled after FOSTA and was recently reintroduced in Congress, would harm online speech, privacy, and security
This is the latest entry in my lengthy archive of writing, talks, and interviews about the EARN IT Act:
The Center for Internet and SocietyRiana Pfefferkorn
Context & Ripple Effects
The reintroduction returns a Section 230 proposal that would make firms' protections contingent on standards aimed at reducing child exploitation, following a 2020 examination of that trade-off. Earlier amendments did not resolve critics' free-speech objections, according to a subsequent review of the revised bill.
The latest analysis extends the critique from child-safety outcomes to the bill's effects on speech, privacy, and security. It also sits alongside an argument that the PACT Act offered a more workable Section 230 reform path.
First-order effects
Congress is again considering a FOSTA-modeled approach that ties online firms' Section 230 protections to prescribed child-exploitation standards.
Online firms facing that framework would have to weigh compliance measures against the speech, privacy, and security harms identified by critics.
Second-order effects
The bill's return sharpens the policy choice between EARN IT's conditional-liability model and alternative Section 230 reforms such as the PACT Act.
A compliance-centered approach would push platforms' safety, privacy, and security practices into the center of congressional debate rather than treating them as separate issues.
Third-order effects
If Congress continues to pursue Section 230 reform through liability-conditioned standards, platform governance will increasingly be shaped by statutory compliance requirements rather than firms' own moderation policies.
The recurring criticism across EARN IT and related proposals points to a durable tension: interventions framed around online safety can redistribute risk toward speech and privacy protections.
The trend: Section 230 reform is evolving into a contest over whether online-safety policy should impose platform liability incentives despite their consequences for speech, privacy, and security.
🚨 The #EarnItAct's reintroduction in the Senate threatens #freespeech & internet users' crucial protections from strong #encryption. Addressing online child exploitation is essential, but this bill increases risks to the online safety of children+adults. https://cdt.org/...
I wrote up why the reintroduced #EARNITAct is worse than ever. There are links to my many, many previous writings on this topic. There's a run-down of why it's so harmful. There's a table of the ways it doesn't help. https://cyberlaw.stanford.edu/ ...
So @Riana_Crypto has put together a detailed “why EARN IT is terrible” post complete with a handy dandy table, that shows how (1) no matter how you define the problem (2) EARN IT is not the answer... https://cyberlaw.stanford.edu/ ...
Have you heard of the “EARN IT” Act? It would “pave the way for a massive new surveillance system, run by private companies, that would roll back some of the most important privacy and security features in technology used by people around the globe."https://www.eff.org/...
#CyberpunkisNow The US Senate is trying to pass the EARN IT Act again. Senators say the bill will combat online child exploitation; in reality, it'll seriously impact online encryption & may undermine actual efforts to address online child exploitation. https://techdirt.com/... h…
“So it's not even clear what problem these Senators think they're solving (unless the problem is “not enough headlines during an election year about how I'm protecting the children.")" - @mmasnick https://www.techdirt.com/...
“Protecting children online is a laudable and urgent goal. However, the EARN IT Act would do little to protect victims - to the contrary, it risks making it even harder to track down and convict offenders.” https://cyberlaw.stanford.edu/ ...