Section 230: The Shield and Its Limits

The Statute That Outlived Its Own Act

Section 230 was enacted on February 8, 1996 as section 509 of the Telecommunications Act of 1996 — Pub. L. 104–104, title V, §509, 110 Stat. 137. Title V of that Act is the Communications Decency Act, and the CDA's central project was criminal: it made it a federal offense to knowingly transmit indecent material to minors, or to display patently offensive material in a manner available to them.

That project collapsed within eighteen months. In Reno v. American Civil Liberties Union, 521 U.S. 844 (1997), decided June 26, 1997, the Supreme Court held that the CDA's "indecent transmission" provision, 47 U.S.C. §223(a)(1)(B)(ii), and its "patently offensive display" provision, §223(d), abridged the freedom of speech protected by the First Amendment.

We state the relationship precisely, because the loose version is often told and is wrong in a way that matters. Reno did not strike down "most of the CDA" as a counted matter, and it did not pass on Section 230 at all. What it destroyed was the CDA's operative scheme — the criminal prohibitions that were the reason the Act existed. Section 230 had been added by a separate amendment, on a different theory: that the way to keep indecency from children was not to prosecute speech but to remove the legal disincentives that discouraged providers from filtering it themselves. It was never challenged in Reno, and it survived intact.

So the provision that now shields the largest publishers in human history is the surviving remnant of a failed censorship statute — the voluntary carrot that outlived the stick. Congress said as much in the statute's own statement of policy, declaring it the policy of the United States "to remove disincentives for the development and utilization of blocking and filtering technologies that empower parents to restrict their children's access to objectionable or inappropriate online material." Everything that follows should be measured against that purpose.

What Section 230 Actually Says

The operative text is short. It is reproduced here in full, from the Office of the Law Revision Counsel's edition of 47 U.S.C. §230, cross-checked against Cornell's Legal Information Institute.

Subsection (c) is captioned "Protection for 'Good Samaritan' blocking and screening of offensive material." Note the caption. The Good Samaritan is the party who acts.

(1) Treatment of publisher or speaker

No provider or user of an interactive computer service shall be treated as the publisher or speaker of any information provided by another information content provider.

(2) Civil liability

No provider or user of an interactive computer service shall be held liable on account of—

(A) any action voluntarily taken in good faith to restrict access to or availability of material that the provider or user considers to be obscene, lewd, lascivious, filthy, excessively violent, harassing, or otherwise objectionable, whether or not such material is constitutionally protected; or

(B) any action taken to enable or make available to information content providers or others the technical means to restrict access to material described in paragraph (1).

The cross-reference in (c)(2)(B) is a drafting error preserved in the enacted text; the Code's own footnote to that subparagraph reads "So in original. Probably should be 'subparagraph (A).'" We quote it as enacted.

Read the two paragraphs together and the design is plain. Paragraph (c)(2) is the actual immunity, and every word of it is about acting on content: restricting it, screening it, giving others the tools to screen it. It is conditioned on good faith. Paragraph (c)(1) is the narrower companion — a rule about who is deemed to have spoken. Neither paragraph says that a service may select, rank, target, and promote third-party content into an individual's attention and remain a stranger to what it has promoted.

Nor is the shield absolute on its own terms. Subsection (e) preserves federal criminal law, intellectual property law, and the Electronic Communications Privacy Act, and — since 2018 — carves out civil claims and state prosecutions arising from sex trafficking under 18 U.S.C. §1591.

From Good Samaritan to Something Much Larger

The expansion happened fast, and it happened in the courts rather than in Congress.

The foundational case is Zeran v. America Online, Inc., 129 F.3d 327 (4th Cir. 1997), No. 97-1523, decided November 12, 1997 — nine months after Section 230 took effect. Kenneth Zeran was the victim of a hoax: an anonymous user posted advertisements attributing repulsive merchandise to his home phone number, and he was buried in threats. The poster was unknown, so he sued AOL for unreasonable delay in removing the messages after being notified of them.

The Fourth Circuit, in an opinion by Chief Judge Wilkinson, held that Section 230 barred the claim. Two moves did most of the work that has been done since. First, the court read §230(c)(1) to foreclose suits seeking to hold a service liable for its exercise of a publisher's traditional editorial functions. Second, and more consequentially, it rejected the argument that a provider with actual notice of defamatory material could be held liable as a distributor rather than a publisher — the distinction that governs booksellers and newsstands — reasoning that distributor liability is a species of publisher liability and falls within the same bar. The court decided against the backdrop of the earlier decisions Zeran itself invokes — Stratton Oakmont among them — which had penalized providers for moderating at all, and it read Congress to have wanted that penalty removed.

Zeran is a hard case on its facts: the actual wrongdoer was anonymous and AOL was merely slow. But its reasoning has been extended far past the conduct it addressed. A defense against liability for failing to remove another's post became a defense against liability for choosing to promote it. By the time the platforms had recommender systems, they were asserting — and mostly receiving — an immunity covering the algorithm's own output.

The best judicial statement of the objection comes from within the majority coalition. Dissenting in part in Force v. Facebook, Inc., 934 F.3d 53 (2d Cir. 2019), No. 18-397, decided July 31, 2019, Chief Judge Robert A. Katzmann wrote:

I agree with much of the reasoning in the excellent majority opinion, and I join that opinion except for Parts I and II of the Discussion. But I must respectfully part company with the majority on its treatment of Facebook's friend- and content-suggestion algorithms under the Communications Decency Act ("CDA").

That is the fault line. Not whether a platform must police everything posted to it, but whether the suggestion — the machine's own affirmative act of putting this content in front of this person — is the platform's conduct or someone else's.

The Question the Supreme Court Left Open

The Court took that question and did not answer it. In Gonzalez v. Google LLC, No. 21-1333, 598 U.S. 617 (2023), decided May 18, 2023, the Court had squarely before it whether §230 protects YouTube's recommendations. It wrote instead:

We therefore decline to address the application of §230 to a complaint that appears to state little, if any, plausible claim for relief. Instead, we vacate the judgment below and remand the case for the Ninth Circuit to consider plaintiffs’ complaint in light of our decision in Twitter.

The companion case, Twitter, Inc. v. Taamneh, No. 21-1496, 598 U.S. 471 (2023), also decided May 18, 2023, was resolved on the aiding-and-abetting merits under the Antiterrorism Act, not on Section 230.

No court of last resort has held that Section 230 immunizes algorithmic recommendation. Anyone who tells you the Supreme Court settled this in 2023 has not read the per curiam. The question is open, which is exactly why it is worth arguing.

The Strongest Case for Broad Immunity

We will not caricature the other side. Its argument is real and deserves to be met at full strength.

Consider a woman who runs a message board for a few thousand hobbyists out of her spare room. Under a regime of notice-based liability, every user post is a potential lawsuit against her. She cannot afford counsel, cannot afford discovery, and cannot afford to be wrong once. Her rational response to any complaint — meritorious or not — is to delete first, because litigation costs more than the post is worth. Anyone who dislikes what is said about them thereby acquires a heckler's veto by threat of suit, and new forums stop being founded at all. This is not speculation: it is what the pre-1996 case law was doing, penalizing the providers who moderated and rewarding the ones who did not look.

That is the moderation dilemma, and it is genuine. A service that touches nothing is safe; a service that tries to keep its space decent has, by trying, made itself responsible. Section 230 dissolved the dilemma by making moderation legally free. Whatever else it did, it did that, and the small forums, wikis, review sites, and open-source communities that fill the usable internet exist in the space it cleared. Any reform that ignores them is not serious.

Our Position

We hold that the argument above is a complete defense of §230(c)(2) and no defense at all of what §230(c)(1) has become.

The hobbyist's board hosts. It stores what users write and shows it to whoever asks. The platforms at issue here do something categorically different: they rank, target, and amplify, selecting from millions of candidate items the specific ones calculated to hold a specific person's attention, and they do it because attention is what they sell. That is an editorial act. When a newspaper decides what goes above the fold, we do not ask whether it wrote the wire copy; we ask whether it chose to run it. Recommendation is publishing, not hosting, and Section 230 was never meant to immunize editorial decisions. We develop this distinction at recommender systems.

The remedy we seek is civil liability — the ordinary common-law consequence of causing harm — not censorship and not prior restraint. No one is asking the government to decide what may be said. We are asking that a corporation which chooses to promote illegal content to a person it has profiled answer for that choice in court, as every other publisher does. A chilling effect on illegal content is not a cost of this proposal. It is the point.

Rescinding and Rewriting Are Not the Same Thing

We support either, and we will not pretend they are equivalent.

Rescission repeals §230 outright and returns online services to the common law of publishers, distributors, and hosts. Its virtue is that the common law already distinguishes the newsstand from the newspaper, already conditions distributor liability on notice, and already declines to hold a passive conduit responsible for what passes through it. Courts would sort platforms into those categories case by case, as they have sorted every other medium. Its cost is the moderation dilemma returned in full, plus years of inconsistent circuit law while the categories are rebuilt — and the smallest operators, who can least afford the interval, would bear it first.

Rewriting keeps a shield for hosting and withdraws it from amplification. In practice that means preserving §230(c)(2) substantially as written — so good-faith moderation stays free — while amending §230(c)(1) so that immunity does not extend to content a service affirmatively ranks, targets, or promotes to a user who did not seek it. It is the more surgical instrument and the more likely to pass. Its risk is the risk of all line-drawing: the line between "displaying" and "recommending" will be litigated hard, and a badly drafted line either swallows chronological feeds and search results or lets any ranking system escape by calling itself neutral.

Rewriting is not hypothetical. Section 230 has been amended twice — in 1998, and again on April 11, 2018 by Pub. L. 115–164, which added the sex-trafficking carve-out now at §230(e)(5). Whatever one concludes about that amendment's effects, it settles the structural question: §230 is not a constitutional fixture. It is a statute, and statutes can be edited by the body that wrote them.

Our preference is the rewrite, because it targets the conduct we object to and leaves the hobbyist's board alone. Either is better than the present arrangement, in which the most profitable editorial enterprises ever built are the only publishers in the country who answer to no one.

We also call on platforms to open-source their ranking algorithms voluntarily — not because a court should compel it, but because a person who cannot see why he is being shown what he is being shown cannot choose intelligently about it. That is an argument about transparency, not liability, and we do not conflate them.

This was written with the help of generative AI. Plese verify critical facts.