Intermediary Liability Lost at the Supreme Court. The Deputisation Machinery Didn't.
The Cox v Sony reversal kills the theory that carrying an accused infringer's traffic makes you a co-infringer. It leaves intact the incentives that make disconnecting the customer the cheap move anyway.
An IP address identifies a router, not a person. Most of the modern intermediary liability project in copyright depended on nobody saying that out loud. A jury ordered Cox Communications to pay roughly US$1 billion over the alleged infringement of 10,017 works by its subscribers, on the theory that an access provider which keeps serving a customer after enough infringement notices becomes a co-infringer itself. The US Supreme Court has now reversed the contributory-infringement holding in that case, No. 24-171: contributory liability, the Court held, requires more than knowledge plus continued service. It requires culpable intent, shown through inducement or through a service built for infringement. Carrying traffic, even traffic you have been told is dirty, is not enough.
That is the right result. It is also narrower than intermediaries would like to believe. The doctrine got repaired; the machinery bolted on top of the doctrine is still running, and machinery, unlike doctrine, doesn't wait for a court.
What does Cox v Sony mean for intermediary liability?
Follow the mechanism. The theory the labels ran was elegant in the way bad incentives usually are: send enough allegations about an account, and the provider's continued service converts into material contribution. Notice the substitution. Nobody proved infringement against anybody. The allegation did all the work, and the provider, who never saw the conduct and had no way to verify it, was asked to act as judge and executioner over its own customer or inherit that customer's liability at statutory-damages scale. The Court's answer restores an older distinction: you are liable for encouraging wrongdoing, not for declining to punish it on a stranger's say-so.
But the reversal only changes what happens when a provider calls the bluff. It does not change who holds the cards day to day. US safe-harbour law, under 17 U.S.C. §512(i)(1)(A), still conditions a conduit's protection on maintaining a policy of terminating repeat infringers in appropriate circumstances. Read that slowly: repeat infringers, adjudicated by no court, identified by the same notices the Cox litigation just showed to be structurally unreliable. Notice-and-takedown, the bargain everyone thinks they know, grew a harsher sibling: notice-and-terminate. Takedown removes a file. Termination removes a household.
An IP address is not a person
Here is the part the enforcement model never priced in. The identifier at the centre of every notice resolves to a connection, not a culprit. Behind one address sits a family of five, a café full of strangers, a hall of residence, a hospital's guest network. The remedy on offer is all-or-nothing: disconnect the account or keep it. There is no dial, only a switch. So the punishment lands on everyone behind the address, sized to a wrong that may involve none of them. American constitutional law has already flinched at this shape once: in Packingham v North Carolina, the Supreme Court held that cutting an individual off from the modern public square is a constitutionally suspect remedy even after a criminal conviction. The termination machinery asks private companies to impose it on allegation.
There is a quieter lesson here for anyone selling privacy. Technical anonymity dies by subpoena, not by cryptanalysis. Every link in the chain between a person and their packets, the account signup, the payment record, the address-assignment log, is a discrete legal target, and each can be compelled independently. A privacy promise that rests only on engineering is a promise about the wrong layer. If the doctrine protecting anonymous use stays soft, the architecture doesn't matter.
Who inherits this risk next?
The Cox theory was tried against an ISP because ISPs have deep pockets and fixed addresses, not because the logic stops there. The same structure fits any business that sits between a user and the user's conduct: cloud hosts, CDNs, VPNs, marketplaces, payment rails. The internet is a chain of such intermediaries, and a liability theory that attaches ruinous damages to any single link is not really a copyright rule. It is an infrastructure tax, levied without ever weighing the lawful traffic the same conduits carry.
That is the frame worth applying to platform businesses. The question is not what the law requires today; it is which duties are being pushed down the stack, and at what price.
And the direction of push is not in doubt. Legislatures keep discovering that the conduit is easier to regulate than the conduct: age checks spreading outward from adult content toward ordinary retail categories, recurring attempts to restrict the tools people use to route around those checks, identity obligations drifting from platforms toward access layers. None of that needed the Cox theory to survive, and none of it died with the reversal. Expect the enforcement duties to keep arriving, each one framed as a compliance detail rather than a business-model change.
If you operate anywhere in the chain, the practical work is unglamorous. Decide now what evidence threshold turns an allegation into action, and write it down before the first subpoena arrives, not after. Build appeal paths a human can actually use. Minimise what your systems can be compelled to disclose; that is a design decision, not a policy document, and it is the same discipline that underpins secure agentic systems. Then price the tail risk honestly: a customer worth £40 a month set against litigation priced in millions is exactly the asymmetry that makes over-compliance the default. It is the sort of exposure a technical strategy review should surface alongside the architecture diagrams, because it lives in the same place: the seams between systems.
The Supreme Court did its part. It re-attached liability to intent, where it belongs, and told the enforcement industry that an allegation is not a verdict. But doctrine only sets the ceiling. Incentives set the behaviour. Cox won; the machinery didn't lose.
Questions people ask
Did Cox win its Supreme Court case against Sony Music?
Yes. In No. 24-171 the Supreme Court reversed the contributory-infringement holding in the case that produced a roughly US$1 billion jury verdict, ruling that contributory copyright liability requires culpable intent, shown through inducement or a service tailored to infringement. Knowing a subscriber has been accused and continuing to provide access is not enough on its own.
Does the DMCA force ISPs to disconnect repeat infringers?
Not directly. 17 U.S.C. §512(i)(1)(A) conditions safe-harbour protection on maintaining a policy of terminating repeat infringers in appropriate circumstances, so it works as pressure rather than an order. In practice 'infringer' means 'accused', because no court adjudicates the notices that trigger the label.
What does the Cox ruling mean for VPNs, cloud hosts and other intermediaries?
The damages threat for merely carrying accused traffic is much weaker, but the structural pressure is unchanged: safe harbour still rewards termination, and legislatures continue pushing identity and enforcement duties onto conduits. Intermediaries should set evidence thresholds, appeal paths and data-minimisation policies before they are tested.
Related
- On Ubuntu 26.04 LTS, the coreutils Your Build Depends On Isn't GNU Anymore
- The Sovereignty Premium: Why Sovereign AI Solutions for Enterprise Are Winning on Access, Not Speed
- Trade-Secret Cases Are Won Years Before Anyone Resigns. Ask Faccenda Chicken.
- Security & Trust
Written by an AI editorial persona of Abyshire's proprietary editorial system and reviewed by our team.