← Platforms

Apple

apple.com

D

Deficient

The operator built and then withdrew an on-device detection system in 2022, and reports to NCMEC at volumes far below comparable cloud storage providers. Product-level protections for minors are among the strongest assessed; detection and reporting are among the weakest.
Domain
apple.com
Category
Devices & cloud
Last review
2026-03-28

Detection & scanning

Whether known and novel abuse material is found at all, and across which surfaces of the product.

D
1.01

Hash matching on publicly posted media

No published description of matching applied to material stored in the consumer cloud service.

Neutral
1.02

Hash matching on private messages and attachments

Messaging is end-to-end encrypted with no server-side matching. On-device matching was announced in 2021 and abandoned in 2022. [1] [2]

Fail
1.03

Classifier detection of previously unseen material

No classifier programme for previously unseen material described.

Fail
1.04

Detection applied to live and streamed video

Not assessed.

Neutral
1.05

Detection of grooming and solicitation in text

On-device nudity detection warns minors in the messaging app. It is a warning to the child, not a detection signal to the operator. [3]

Neutral
1.06

Participation in industry hash-sharing programmes

Participation not publicly described.

Neutral

Reporting & transparency

What the operator tells NCMEC, law enforcement and the public, and whether those disclosures can be checked.

D
2.01

Files CyberTipline reports to NCMEC

Files CyberTipline reports at volumes several orders of magnitude below other providers of comparable storage scale. [4]

Neutral
2.02

Publishes child-safety enforcement figures

Transparency reporting does not break out child-safety enforcement.

Fail
2.03

Report quality sufficient for investigation

Not assessed.

Neutral
2.04

Reporting cadence and timeliness

Not assessed.

Neutral

Response & enforcement

What happens after material is found: how fast it comes down, what happens to the account, and whether the decision can be contested.

C
3.01

Time to removal of confirmed material

No figure published.

Neutral
3.02

Account termination on confirmed violation

Terms provide for account termination.

Pass
3.03

Prevention of re-registration

Hardware and payment identity make re-registration harder than on most assessed platforms, but this is a side effect rather than a stated control.

Neutral
3.04

Preservation of evidence

Preservation on legal request is documented.

Neutral
3.05

Escalation of imminent-harm cases

An emergency request process is published with a stated turnaround.

Pass

Product & policy posture

The design decisions that determine how much abuse is possible in the first place, before any detection is applied.

B
4.01

Protective defaults for minor accounts

Child accounts are a distinct type with restricted defaults enforced at the operating-system level. [3]

Pass
4.02

Restrictions on adult-initiated contact with minors

Communication limits restrict who can contact a child account. [3]

Pass
4.03

Age assurance at registration

Family organiser establishes the account age. Standalone accounts remain self-declared.

Neutral
4.04

Recommendation systems assessed for minor-safety harm

App review governs distribution. No published minor-safety assessment of editorial or recommendation surfaces.

Neutral
4.05

Encryption posture and stated mitigations

End-to-end encryption is applied without the compensating detection the operator itself designed and then withdrew. No alternative mitigation has been published. [2]

Fail
4.06

Published child-safety policy with defined enforcement

Policy is published with stated consequences.

Pass

Record

Documented failures, enforcement actions, litigation and investigative reporting bearing on the assessment above.

2021-08

On-device detection announced

The operator announced a system to match material against known hashes on the device before upload to its cloud service, together with communication-safety features for child accounts. [1]

2022-12

Detection programme withdrawn

The operator confirmed it would not proceed with the detection system, citing risks of the mechanism being repurposed for wider surveillance. The communication-safety features for child accounts were retained. [2]

2024-12

Civil action over withdrawal of detection

A civil suit was filed on behalf of survivors alleging that the decision not to deploy the announced system caused continuing harm. [5]

Sources

  1. [1]
  2. [2]
  3. [3]
  4. [4]
  5. [5]
    Civil complaint

    Illustrative placeholder · 2024-12

Know something we don’t?

If we’ve missed a controversy or there’s newer reporting on Apple, tell us. If you represent Apple, we welcome documentation of safety measures not yet reflected here.

Contact us

Report CSAM

If you have encountered CSAM, file a report through one of these channels.