2021-08
On-device detection announced
The operator announced a system to match material against known hashes on the device before upload to its cloud service, together with communication-safety features for child accounts. [1]
apple.com
Deficient
Whether known and novel abuse material is found at all, and across which surfaces of the product.
Hash matching on publicly posted media
No published description of matching applied to material stored in the consumer cloud service.
Hash matching on private messages and attachments
Messaging is end-to-end encrypted with no server-side matching. On-device matching was announced in 2021 and abandoned in 2022. [1] [2]
Classifier detection of previously unseen material
No classifier programme for previously unseen material described.
Detection applied to live and streamed video
Not assessed.
Detection of grooming and solicitation in text
On-device nudity detection warns minors in the messaging app. It is a warning to the child, not a detection signal to the operator. [3]
Participation in industry hash-sharing programmes
Participation not publicly described.
What the operator tells NCMEC, law enforcement and the public, and whether those disclosures can be checked.
Files CyberTipline reports to NCMEC
Files CyberTipline reports at volumes several orders of magnitude below other providers of comparable storage scale. [4]
Publishes child-safety enforcement figures
Transparency reporting does not break out child-safety enforcement.
Report quality sufficient for investigation
Not assessed.
Reporting cadence and timeliness
Not assessed.
What happens after material is found: how fast it comes down, what happens to the account, and whether the decision can be contested.
Time to removal of confirmed material
No figure published.
Account termination on confirmed violation
Terms provide for account termination.
Prevention of re-registration
Hardware and payment identity make re-registration harder than on most assessed platforms, but this is a side effect rather than a stated control.
Preservation of evidence
Preservation on legal request is documented.
Escalation of imminent-harm cases
An emergency request process is published with a stated turnaround.
The design decisions that determine how much abuse is possible in the first place, before any detection is applied.
Protective defaults for minor accounts
Child accounts are a distinct type with restricted defaults enforced at the operating-system level. [3]
Restrictions on adult-initiated contact with minors
Communication limits restrict who can contact a child account. [3]
Age assurance at registration
Family organiser establishes the account age. Standalone accounts remain self-declared.
Recommendation systems assessed for minor-safety harm
App review governs distribution. No published minor-safety assessment of editorial or recommendation surfaces.
Encryption posture and stated mitigations
End-to-end encryption is applied without the compensating detection the operator itself designed and then withdrew. No alternative mitigation has been published. [2]
Published child-safety policy with defined enforcement
Policy is published with stated consequences.
Documented failures, enforcement actions, litigation and investigative reporting bearing on the assessment above.
2021-08
The operator announced a system to match material against known hashes on the device before upload to its cloud service, together with communication-safety features for child accounts. [1]
2022-12
The operator confirmed it would not proceed with the detection system, citing risks of the mechanism being repurposed for wider surveillance. The communication-safety features for child accounts were retained. [2]
2024-12
A civil suit was filed on behalf of survivors alleging that the decision not to deploy the announced system caused continuing harm. [5]
Apple · 2021-08
Apple, reported by WIRED · 2022-12
Apple · 2025
NCMEC · 2025
Illustrative placeholder · 2024-12
If we’ve missed a controversy or there’s newer reporting on Apple, tell us. If you represent Apple, we welcome documentation of safety measures not yet reflected here.
Contact usIf you have encountered CSAM, file a report through one of these channels.