STOP CSAM Act
What it does
The bill opens providers to civil suits over child sexual abuse material on their services, with a recklessness standard for liability. It also builds a Report and Remove regime: a notified provider has 48 hours to take material down, and refusals go to a new Child Online Protection Board of three FTC attorneys that can order every copy removed and fine the provider up to $200,000. The removal power reaches beyond CSAM to other content relating to the person. A service that cannot scan messages because they are end-to-end encrypted can be painted as reckless by design. Introduced by Senators Hawley and Durbin in May 2025, it cleared the Judiciary Committee in June and has been waiting for floor time since.
Why it matters
This is the EARN IT playbook with a different cover: nobody has to ban encryption if hosting it becomes an uninsurable legal risk. Committee approval means it is one floor vote from moving, and bills like this get attached to must-pass packages in the year-end crush.
Our take
Encryption does not know what it is protecting. That is the point of it. A law that punishes providers for not knowing what their users say is a law against encryption, whoever it claims to target. EARN IT went dormant; this is the same idea, better dressed, one committee further along.
Cosponsors (26)
Richard Durbin (D-IL), Amy Klobuchar (D-MN), Chuck Grassley (R-IA), Mark Kelly (D-AZ), Katie Britt (R-AL), Ashley Moody (R-FL)
Committee
Judiciary Committee
Timeline
- May 21, 2025Introduced
- May 21, 2025Referred to committee
- June 12, 2025Reported by committee
Related bills
Our coverage: all encryption stories · Status checked July 20, 2026

