In 26 words, a 1996 federal law changed the internet permanently — and most people who argue about it have never read it.
Section 230 of the Communications Decency Act says platforms are not legally responsible for content their users post. That single idea is why YouTube exists at its current scale, why Facebook reached two billion users without a legal team reviewing every post, and why a hotel can’t sue Yelp because a guest left a scathing review.
This guide explains exactly what Section 230 does, who it protects, where its limits are, and why both sides of the political aisle want to reform it — for completely opposite reasons.
What Is Section 230 and Why Does It Exist?
Section 230 is a U.S. federal statute that shields internet platforms from civil liability for content created by third parties. Without it, every social media post, product review, or comment thread could expose a platform to a defamation lawsuit — making user-generated content economically unworkable at any scale.
To understand why it was written, you need to go back to two contradictory court decisions that left the early internet in legal chaos.
The Legal Problem That Created Section 230
In Cubby, Inc. v. CompuServe (1991), a federal court ruled that CompuServe — because it did not moderate content in its online forums — was not liable for defamatory statements users posted there. The logic tracked: a platform acting like a newsstand or library, simply distributing content without editorial control, shouldn’t bear the same legal exposure as a publisher who curates every word.
Four years later, Stratton Oakmont v. Prodigy Services (1995) reached the opposite conclusion. Prodigy did moderate some content on its message boards — and the court ruled that moderation made Prodigy a “publisher,” liable for everything users posted. The penalty for trying to clean up harmful content was more legal exposure, not less.
Congress grasped the problem immediately. If platforms that moderated faced greater liability than those that did nothing, the incentive was obvious: do nothing. Senators Ron Wyden and Chris Cox drafted Section 230 in 1996 to break this trap. The goal was straightforward — let platforms moderate without becoming legally responsible for everything their users say.
The 26 Words That Built the Modern Internet
The core protection lives in subsection (c)(1):
“No provider or user of an interactive computer service shall be treated as the publisher or speaker of any information provided by another information content provider.”
Technology journalist Jeff Kosseff called this sentence “the 26 words that created the internet” in his 2019 book of the same name. That phrase has since become shorthand for how much weight one legal sentence can carry. It established that the person who posts content is legally responsible for it — not the platform that hosts it.
How Does Section 230 Protection Actually Work?
Section 230 provides two separate legal protections: one for hosting content users create, and one for moderating or removing it. Both matter — and conflating them produces most of the confusion in public debate.
Protection One: The Hosting Shield (c)(1)
The first shield is the more famous one. When a user posts defamatory content, a platform is not treated as the legal “publisher” of that post under civil law. The person who wrote it carries the liability. The platform that hosted it does not.
This is why Reddit isn’t sued every time a user spreads a false claim in a subreddit. It’s why Airbnb isn’t liable for every fraudulent host listing. The content creator remains legally accountable; the platform is treated more like a telephone company than a newspaper.
Protection Two: The Moderation Shield (c)(2)
The second shield covers what happens when platforms make editorial decisions. Section 230(c)(2) states that no platform shall be held liable for any good-faith action taken to restrict access to content it considers “obscene, lewd, lascivious, filthy, excessively violent, harassing, or otherwise objectionable.”
This is the section that most political commentary gets wrong. A platform can remove a post, label a tweet as disputed, suspend an account, or filter content algorithmically — without losing its protection under (c)(1). Section 230 was deliberately designed to encourage moderation. The law doesn’t require neutrality; it rewards active content governance.
What Section 230 Does NOT Cover
Section 230 is not a blanket shield, and it was never designed to be. Here is where it ends:
| Area | Protected by 230? | Key Detail |
|---|---|---|
| Federal criminal law | ❌ No | Full criminal prosecution still applies |
| Sex trafficking content | ❌ No | FOSTA-SESTA (2018) removed this immunity |
| Copyright infringement | ❌ No | The DMCA handles this separately |
| Content platforms create themselves | ❌ No | Only third-party content is covered |
| Electronic privacy violations | ❌ No | Not included in the statute |
| State criminal prosecution | ❌ No | No protection against state criminal law |
| AI-generated content (disputed) | ⚠️ Contested | Courts have not yet settled this question |
This table contains the single most important correction in the Section 230 debate. The law has real, enforceable limits — and Congress has demonstrated it can remove those protections when it chooses to, as it did in 2018.
Who Does Section 230 Cover — With Real-World Examples
Section 230 applies to any “interactive computer service” — any platform that hosts content created by multiple users. The scope is broader than most people assume, and includes companies you use every day without realizing they depend on this law.
The High-Profile Cases
Social media platforms are the obvious examples: Facebook, YouTube, X (formerly Twitter), TikTok, Instagram, and Reddit all rely on Section 230 daily. When a Facebook user posts false information about a local business, the business can sue the user — not Facebook. Without that protection, Facebook would need to legally pre-screen hundreds of millions of posts per day. No content moderation system could operate under that legal structure.
The Less Obvious Cases
In my research tracking Section 230 litigation, the breadth of companies that depend on this statute is consistently underreported:
- Yelp and Google Reviews — A restaurant cannot sue Yelp for hosting a one-star review calling the food contaminated, even if the claim is disputed. The reviewer is liable; Yelp is not.
- Wikipedia — When a Wikipedia editor adds false biographical information, the Wikimedia Foundation generally cannot be held civilly liable for the content. The editor who contributed it can be.
- Dating apps — If a user creates a deceptive profile on Hinge or Bumble, the app isn’t liable for the fraud. The user is.
- Email providers — Gmail hosts billions of user-written messages daily without legal exposure for their content.
- Amazon Marketplace — Third-party sellers list their products on Amazon’s platform. Courts have wrestled with how Section 230 applies to product liability claims against Amazon itself — this is an actively evolving area of case law.
- Online job boards — Platforms like Indeed or LinkedIn that host user-submitted job postings are generally protected from defamation claims if an employer misrepresents a position.
The Case That Nearly Changed Everything: Gonzalez v. Google (2023)
In 2023, the Supreme Court considered Gonzalez v. Google — the most significant Section 230 case to reach that court. The family of an ISIS terrorist attack victim argued that YouTube’s recommendation algorithm, by actively surfacing ISIS recruitment videos, went beyond passive hosting into active editorial curation. If true, Google would lose its Section 230 protection for those recommendations.
The court declined to answer that question directly, deciding the case on narrower grounds under a different statute. But the underlying tension — when does algorithmic amplification become editorial responsibility? — remains legally unresolved. This is the next major frontier in Section 230 litigation, and it will almost certainly return to the Supreme Court.
Why Is Section 230 So Controversial — and What Would Reform Actually Do?
Section 230 is unusual in American politics: both Republicans and Democrats want to change it, but for completely opposite reasons. That divergence reveals more about political frustration with Big Tech than it does about the law itself.
The Conservative Critique
Many Republican lawmakers argue that platforms use Section 230’s immunity as cover to suppress conservative speech. The claim: if Facebook or X removes certain political content, it is functioning as an editor — making active judgments about what speech is acceptable. A company acting as an editor, the argument goes, should carry editorial liability.
In 2021, Florida passed SB 7072 and Texas passed HB 20 — laws that attempted to prohibit large platforms from removing political content. Both were challenged as violations of the First Amendment. In Moody v. NetChoice (2024), the Supreme Court sent both laws back to lower courts for further analysis, declining to resolve the core constitutional question. The debate remains legally open.
The Progressive Critique
Many Democratic lawmakers take the opposite position. They argue that Section 230 allows platforms to profit from harmful content — misinformation, harassment, health disinformation, radicalization pipelines — without bearing any responsibility for its real-world effects. Senator Mark Warner, among others, has called Section 230’s current form “a get out of jail free card for Big Tech.”
The push from this side targets knowing amplification of harmful content, arguing that when a platform’s algorithm actively promotes dangerous material, the platform has moved beyond passive hosting into something more like complicity.
FOSTA-SESTA: What Happens When Congress Acts
In 2018, Congress passed FOSTA-SESTA — the first major carve-out from Section 230. The law removed immunity for content related to sex trafficking and prostitution. The stated goal was to shut down platforms used to facilitate human trafficking.
Research published after the law took effect told a more complicated story. Studies by Vanderbilt Law’s Danielle Citron and others found that platforms used by adult sex workers for screening and safety — not traffickers — shut down en masse. Many sex workers reported moving to less visible and more dangerous venues as a result. The case became a cautionary example of how Section 230 reform can produce serious unintended consequences.
What Full Repeal Would Actually Mean
If Section 230 were eliminated tomorrow, platforms would face two realistic choices: hyper-aggressive moderation (removing anything carrying legal risk, far exceeding current practices) or abandoning user-generated content models entirely.
Neither outcome serves free expression. More significantly, the legal costs of defending content-related lawsuits would fall entirely on platforms — and small platforms and startups cannot afford the legal infrastructure that Facebook or Google can. Eliminating Section 230 would likely concentrate power in fewer hands, not fewer.
5 Common Myths About Section 230 — Corrected
Years of political combat have generated more misinformation about Section 230 than almost any other active policy debate. Here are the five claims most in need of correction.
Myth 1: “Section 230 protects platforms that censor conservative speech.”
Section 230 does not require neutrality as a condition of immunity. It never has. Platforms were constitutionally permitted to moderate content before Section 230 existed — they are private companies, and the First Amendment restricts government censorship, not editorial choices made by private entities. Section 230 didn’t create that right; it added civil liability protection for how platforms exercise it.
Myth 2: “Section 230 means platforms can host anything without consequence.”
False. Federal criminal law applies in full. Copyright law applies under the DMCA. State criminal statutes apply. The EARN IT Act, if passed, would add child safety compliance requirements. Congress removed sex trafficking immunity in 2018. The idea that Section 230 creates lawless zones on the internet is not supported by the statute’s text.
Myth 3: “Big Tech wrote Section 230 to protect themselves.”
Section 230 passed in 1996. Google was founded in 1998. Facebook launched in 2004. YouTube launched in 2005. The senators who wrote the law were responding to two early-internet court rulings that threatened to punish responsible moderation. The companies currently benefiting from it weren’t part of the original conversation.
Myth 4: “Removing Section 230 will reduce online harm.”
There is no evidence base for this claim. A 2020 analysis by Berin Szóka and Corbin Barthold at TechFreedom concluded that removing Section 230 would most likely drive harmful content toward less-moderated, less-visible corners of the internet rather than eliminate it. The practical effect would be to punish platforms attempting responsible governance.
Myth 5: “Europe’s approach is better — they hold platforms accountable.”
The EU’s Digital Services Act (DSA), which took full effect in 2024, does impose more transparency requirements and due-process obligations on large platforms. But it does not eliminate civil liability protection for third-party content — it creates a tiered responsibility model that is closer to reforming Section 230 than abolishing it. The U.S. and European approaches differ in regulatory architecture, not in their fundamental protection of platforms from user-content liability.
Section 230 FAQ
What does Section 230 actually say, in plain English?
Section 230(c)(1) states that no internet platform shall be treated as the publisher of content created by its users. In practice: if a user posts something defamatory, the user can be sued — the platform that hosted it generally cannot be. The protection applies to civil claims, not criminal law.
Does Section 230 apply outside the United States?
Section 230 is a U.S. federal statute. It governs cases in U.S. courts. Other countries have developed their own frameworks — the EU’s Digital Services Act, Australia’s Online Safety Act, the UK’s Online Safety Act — but none of them are Section 230. Foreign courts have sometimes tried to hold U.S. platforms liable under their own national laws.
Can a platform lose its Section 230 protection?
Yes. A platform loses protection when it creates or materially develops content itself (rather than hosting third-party content), when federal or state criminal law applies, or when Congress explicitly removes the immunity — as it did for sex trafficking under FOSTA-SESTA. Courts also examine whether algorithmic curation crosses from hosting into active content development.
Why is Section 230 called “the 26 words that created the internet”?
Journalist Jeff Kosseff popularized this description in his 2019 book of the same title. The 26 words come from subsection (c)(1) of the statute. The phrase captures how a single legal sentence enabled the entire user-generated content economy — from social media to product reviews to open-source collaboration tools.
Is Section 230 being repealed in 2026?
As of mid-2026, Section 230 remains intact as federal law. Multiple reform proposals have been introduced in Congress, including the EARN IT Act and various platform accountability bills, but none have passed. The Supreme Court has preferred narrow rulings in recent platform cases rather than broad reinterpretation of the statute.
Does Section 230 apply to AI-generated content?
This is the most actively contested legal question in 2026. When a generative AI model produces harmful output in response to user input, it is unclear whether the deploying platform qualifies as a “third-party information content provider” — or whether the AI’s output constitutes platform-created content, which would strip away Section 230 protection. No court has definitively settled this.
What is the difference between Section 230 and the First Amendment?
The First Amendment prohibits government from restricting free speech. Section 230 is a statutory protection for private companies against certain civil lawsuits. A platform can remove your post without violating the First Amendment — it is a private actor making an editorial choice, not a government censor. Section 230 protects that editorial choice from civil liability claims.
What was the EARN IT Act?
The Eliminating Abusive and Rampant Neglect of Interactive Technologies (EARN IT) Act is legislation that would require platforms to “earn” their Section 230 immunity by complying with best practices for detecting and reporting child sexual abuse material. Critics argue it is written to effectively mandate encryption backdoors — because compliance with some “best practices” would require platforms to scan encrypted communications. It has been introduced in multiple congressional sessions without passing.
Conclusion
Section 230 is a short law — under 500 words in its entirety — with consequences that now touch every part of the internet.
It enabled platforms to host billions of user-created posts without absorbing unlimited legal exposure. It simultaneously allowed those platforms to moderate content without being punished for doing so. Both functions are essential, and removing either one would change the internet in ways that neither political party has fully modeled.
The genuine policy questions are real: Section 230 doesn’t neatly address algorithmic amplification, AI-generated content, or the concentrated power of a small number of global platforms. Those gaps deserve serious reform conversations.
What it is not is a loophole permitting platforms to host anything without consequences. Federal criminal law applies. Copyright law applies. The people who create harmful content are still legally responsible for it. Section 230 was written to protect the hosting infrastructure — not to immunize the bad actors using it.
Your next step: Read the full statute — it takes under five minutes. Then read the Supreme Court’s opinions in Gonzalez v. Google (2023) and Moody v. NetChoice (2024). The actual legal terrain is more nuanced than any political talking point on either side of this debate.
Never stop learning—our skill-building posts are designed for growth.
