What the 9th Circuit actually decided

On August 10, 2026, the 9th U.S. Circuit Court of Appeals in San Francisco rejected a bid by Meta, Alphabet's Google, ByteDance's TikTok and Snap to reverse a lower-court ruling and escape more than 3,000 federal lawsuits tied to the multidistrict litigation known as In re: Social Media Adolescent Addiction/Personal Injury Products Liability Litigation. The plaintiffs, including individuals and school districts, allege the companies engineered features such as recommendation algorithms, autoplay, infinite scroll and notification systems to be addictive, and that the design caused mental-health harm to minors.

In a 24-page opinion, Circuit Judge Jacqueline Hong-Ngoc Nguyen wrote that Section 230 of the Communications Decency Act "merely provides a defense to liability, not immunity from suit," and that the court therefore lacked jurisdiction to review the lower court's decision before a final judgment. The companies had tried to use an early appeal to get the design-feature claims dismissed before facing a jury; the panel said that route does not exist for this kind of claim.

The distinction matters because many courts, including earlier 9th Circuit panels, have long read Section 230 as an unusually strong pretrial shield against claims tied to user content. This ruling does not touch that protection for content-moderation claims. It does say that claims about how a platform is designed and engineered, rather than what content it hosts, do not automatically qualify for the immediate, pretrial dismissal that content-based claims have often received.

Why 'a defense, not immunity' changes the calculus

The effect is procedural, and that is exactly why it matters. Until now, platforms facing design-based claims could seek an early appeal arguing Section 230 barred the case entirely, hoping for dismissal before years of discovery or a jury trial. The 9th Circuit's answer is that Section 230 is a defense to be raised and tested at trial like any other defense, not a jurisdictional immunity that lets a company skip the trial altogether.

That pushes more than 3,000 lawsuits toward discovery and, eventually, a jury, where internal company records about why a feature was built a certain way become evidence rather than a hypothetical risk. A related bellwether trial already produced a jury verdict against Meta and YouTube earlier in 2026, with TikTok and Snap settling before a verdict; this ruling removes the main procedural exit that the remaining defendants were trying to take before their own trials reach that stage.

The same week, a second Meta trial was allowed to proceed

On the same day, the 9th Circuit separately denied a request from Meta to postpone a trial, brought by 29 state Attorneys General, over allegations that the company unlawfully collected and used children's data, engineered its platforms to keep minors engaged, and misled the public about the safety of its products. That trial began the same week the ruling came down. Meta had argued the trial should wait until its Section 230 appeal was resolved; the court disagreed, for the same reason it gave in the addiction cases: Section 230 is a defense, not a bar on the case proceeding.

Both rulings sit inside a wider pattern building through 2026. Earlier this month, a New Mexico state court ordered Meta to pay 567 million dollars into a youth-safety fund, on top of an earlier 375 million dollar civil penalty from the same case, plus a five-year decree capping teen usage of Facebook and Instagram. Across multiple courts and legal theories, the direction is the same: judges are treating platform design choices as something a jury or a court-ordered decree can reach, not something a pretrial motion resolves.

What EU and UK operators should actually check now

The ruling is American, decided under an American statute, and it does not bind any EU or UK court. But EU and UK regulators, lawyers and platform operators have watched Section 230 for two decades as the benchmark for how far a "the user did it, not us" defense can stretch, because the EU's Digital Services Act and the UK's Online Safety Act were both built assuming that benchmark would eventually narrow for exactly this kind of claim. This ruling, and the New Mexico decree alongside it, is evidence that the narrowing is now happening in practice, not only in policy debate.

The overlap is specific, not abstract: the features named in this litigation, engagement-optimized notification systems, autoplay defaults and infinite scroll, are the same features the DSA's rules on manipulative design for minors and the Online Safety Act's risk assessments already ask platforms to justify. A company that has only ever treated that overlap as a regulatory-compliance exercise should now treat it as a litigation-exposure exercise too.

The useful first step is not a new policy document. It is an audit of the internal paper trail that already exists: the growth and engagement experiments, A/B tests and product-review notes that explain why a notification cadence, an autoplay default or an infinite-scroll pattern was chosen. Under EU and UK rules, that record is something a regulator can inspect. In US litigation, the same record is something a plaintiff's lawyer can subpoena. Any EU or UK business with a US-facing platform or a US subsidiary should know, now, what that record actually says before someone else asks to see it.