Thirteen Strikes and… You’re Still Online?: New Challenges to DMCA Safe Harbor Protections
In 2026, digital piracy accounted for 24% of global internet traffic, amounting to over 190 million visits to piracy websites annually and an estimated 29–71 billion dollars in losses for the U.S. economy [1]. This begs the question: Who’s on the hook for this criminal activity? It would be completely infeasible for copyright holders to collect reasonable damages from each user, whose personal infractions might amount in the low hundreds of dollars, while requiring a separate lawsuit for each infringer. In practice, this makes copyright practically unenforceable, violating the holder’s congressionally guaranteed right to exclusive reproduction, a right enshrined since the Patent Act of 1790 [2]. Instead, the courts have historically relied on a “best positioned to prevent harm” doctrine articulated in MGM v. Grokster (2005) [3], which seeks to remedy copyright violations through secondary liability, or the liability incurred by the facilitator of a crime. This presents a major threat to internet service providers (ISPs), because the Wiretap Act criminalizes the monitoring of user transmissions for any reason other than directly protecting the rights or property of the ISP [4]. Thus, secondary liability claims require proof of “affirmative action,” actions or policies that knowingly promote the direct infringer’s copyright infringement, not just actions that facilitate infringement [5].
However, the doctrine remained underdeveloped, and, in 1995, ISPs won protection from the secondary liability of automatic transmissions [6]. The United States codified this right in 1998 with the passage of the Digital Millennium Copyright Act (DMCA), which established a route to “safe harbor” protections for ISPs, shielding them from secondary liability if the ISPs act “to expeditiously remove, or disable access to, the material that is claimed to be infringing upon notification” from the copyright holder [7]. This clause has become the center of a legal war between ISPs and major copyright holders.
The latest battle is Cox Communications, Inc. v. Sony Music Entertainment Group (2026). Sony Music Entertainment group has sued Cox Communications, a major United States ISP, for contributory and vicarious liability, seeking damages for an estimated $1 billion in copyright infringement by Cox Communications’ clients. The case goes right to the heart of DMCA safe harbor regulations, and asks what it means to act “expeditiously” under the DMCA. During initial oral arguments before the Supreme Court, Cox Communications held that its thirteen-strike policy of “graduated enforcement” satisfied its DMCA obligations, granting it safe harbor protections [8]. Sony’s argument is more compelling: Cox’s lackluster enforcement constitutes affirmative action, allowing claims of secondary liability against the company.
Cox Communications’ enforcement policy followed a thirteen-strike rule, where if a user received thirteen copyright infringement notices in a six-month period, their service might be terminated [9]. After six months, however, the slate was wiped clean as if it never happened. Users were not even notified after their first strike, and the first several strikes merely resulted in an email warning against copyright infringement [10]. Further, no matter how many copyright infringements occurred in a single day, Cox would only issue one strike per day, leading to many users racking up dozens of infringements with minimal penalties. Cox further limited the amount of infringement notices received by “blacklisting” disfavored copyright holders. Any company on the “blacklist” would have its notices silently deleted by Cox Communications with no action taken. When users manage to collect 13 strikes, Cox would only terminate the first 300 users to receive their 13th strike in one day, and could promptly restore their service after a warning, resetting their strikes in the process [11].
In previous cases of secondary liability, the Court has relied on the “affirmative action” standard, holding that organizations could be held secondarily liable for the actions of consumers only when they had taken an active role by knowingly promoting the usage of their services for illicit activities. This “affirmative action” could take the form of a software designed and promoted specifically for illicit peer-to-peer downloads of copyrighted material, as it did in MGM v. Grokster (2005) [12]. But the courts have repeatedly held mere “generalized knowledge” of illicit transmissions as insufficient in establishing secondary liability. Most recently, in Twitter, Inc. v. Taamneh (2023), the Supreme Court held that Twitter’s generalized knowledge of all automatically occurring transmissions on its platform was not sufficient to establish contributory liability for the actions of its users [13].
Cox Communications’ records go beyond “generalized knowledge” about customers’ illicit downloads, and their brief to the court outlines as much [14]. In this brief, Cox Communications specifically identifies 49 clients known to be major infringers, who will, in all likelihood, continue infringing. Cox Communications declined to terminate its services to any of these 49 offenders, despite copyright holders’ repeated notifications of violations. Further, from the 163,000 complaints by Sony and other copyright holders over a 22-month period, only a few dozen clients had their service terminated.
Since major offenders tend to be multi-user clients such as universities, hospitals, and regional ISPs, Cox argues that termination would disproportionately affect non-infringers. This is a reasonable argument at first glance. However, in taking no action to reduce access to pirated content, Cox Communications fails to fulfill its DMCA obligations. Cox’s argument completely ignores commonly used network controls that restrict access and allow institutions to monitor which users are responsible for the infringing transmissions. Thus, Cox can still hold an institution responsible for failing to prevent copyright infringement on its networks without punishing every member of the institution. Further, by having specific knowledge of these particular users’ actions and habitual infringement and continuing to provide service to them, Cox Communications commits an extremely standard form of affirmative action, similar to that outlined in Smith & Wesson Brands v. Estados Unidos Mexicanos (2025) [15]. In that case, the defining standard was whether Smith & Wesson Brands had specific knowledge of the purchaser’s intent to use their products for illegal activity. Cox Communications absolutely fails this test; its own internal records acknowledge that any user who received six strikes or more was most likely actually infringing or had failed to secure their network [16]. In both circumstances, continuous infringement from the client is likely, yet Cox Communications’ official policy was to continue providing service.
It may also be argued that, despite the low number of terminations, Cox Communications’ policy is effective at reducing copyright infringement of its users. Their internal numbers do suggest that the policy ultimately prevents infringement by 98% of users before they receive their 13th strike [17]. However, these numbers collapse when you realize that Cox Communications ignores massive amounts of infringement notices from “blacklisted” vendors [18]. Further, resetting the 13 strikes every six months means that users who infringe infrequently appear to have ceased infringement, when they simply stopped being tracked. This calls into question the 98% figure Cox asserts and reduces the credibility of the 13-strike policy as an effective means of reducing copyright infringement.
However, if Cox’s policies are deemed ‘expeditious,’ questions of secondary liability are irrelevant because DMCA safe harbor protections apply. The ambiguity stems from the DMCA’s lack of specificity as to what constitutes “expeditiously remov[ing] or disabl[ing] access to illegal content.” Unfortunately, there is little binding precedent from the courts to look to. Instead, we can examine the ISP industry’s policies themselves and determine what ISPs have defined as “expeditious.” [19] The common thread is a policy to terminate repeat offenders, regardless of their user counts [20]. By contrast, Cox’s 13-strike policy routinely fails to terminate repeat offenders, implying they are insufficiently expedient to qualify for safe harbor protection.
If the courts correctly hold that Cox Communications’ policy of “graduated enforcement” does not qualify the company for “safe harbor protection” and, in fact, constitutes “affirmative action” that engenders secondary liability, Cox Communications and other major ISPs will likely take steps to re-evaluate their policies towards copyright infringement and adopt a far more aggressive posture in terminating infringing clients. ISPs may begin to require multi-user clients, such as universities and hotels, to implement stricter copyright infringement protections. Finally, there will exist a binding precedent on affirmative action in digital copyright infringement that protects artists and producers from theft. If, instead, the Court affirms Cox Communications’ strategy of graduated enforcement, it will call into question whether providers even need to seek DMCA safe harbor protections by taking down illegal content: Why would an ISP ever terminate a paying customer, when all that’s necessary to avoid contributory liability is to send warning emails every couple of months? A favorable ruling for Cox Communications would all but overturn the DMCA, calling into question every principle of digital regulation.
Editor’s Note: This article was written prior to the Supreme Court’s 9-0 decision in favor of Cox Communications. As you will see, the author disagrees with their findings.
Footnotes:
[1] “Piracy Is Back: Piracy Statistics for 2026 | Dataprot,” Dataprot, accessed March 8, 2026, https://dataprot.net/blog/piracy-statistics/; U.S. Chamber Staff, “Unlocking Creativity: The Socioeconomic Benefits of Copyright,” U.S. Chamber of Commerce, June 24, 2025, https://www.uschamber.com/intellectual-property/unlocking-creativity-copyright-report;
[2] Patent Act of 1790, Ch. 7, Stat. 109-112 (April 10, 1790) https://ipmall.info/sites/default/files/hosted_resources/lipa/patents/Patent_Act_of_1790.pdf.
[3] MGM v. Grokster (2005), 545 U.S. 913 (2005).
[4] Wiretap Act, 18 U.S.C. § 2511(2)(a)(i). https://www.law.cornell.edu/uscode/text/18/part-I/chapter-119.
[5] “Secondary Copyright Infringement,” Copyright Alliance, September 15, 2022, https://copyrightalliance.org/education/copyright-law-explained/copyright-infringement/secondary-copyright-infringement/.
[6] Religious Tech. Center v. Netcom On-Line Comm, 907 F. Supp. 1361 (N.D. Cal. 1995).
[7] H.R.2281 - Digital Millennium Copyright Act https://www.congress.gov/bill/105th-congress/house-bill/2281/text.
[8] Cox Communications v. Sony Music Entertainment Group, 607 U.S. ___ (2026).
[9] Brief for Cox Communications, Cox Communications v. Sony Music Entertainment Group (S. Ct. 2026) (no. 24-171), https://www.supremecourt.gov/DocketPDF/24/24-171/373201/20250829115733612_250829a%20Brief%20for%20efiling.pdf.
[10] Ibid.
[11] Ibid.
[12] MGM, 545 U.S. 913.
[13] Religious Tech. Center, 907 F. Supp. 1361; Twitter, Inc. v. Taamneh, 598 US _ (2023); Viacom International, Inc. v. Youtube, Inc, 676 F.3d 19 (2nd Cir., 2012).
[14] Brief for Cox Communications.
[15] Smith & Wesson Brands v. Estados Unidos Mexicanos, 605 U.S. 280 (2025).
[16] Brief for Sony Music Entertainment Group, Cox Communications v. Sony Music Entertainment Group (S. Ct. 2026) (no. 24-171), https://www.supremecourt.gov/DocketPDF/24/24-171/383316/20251103104556739_24-171%20Sony%20Response%20Brief%20w%20JA%20cites.pdf.
[17] Brief for Cox Communications.
[18] Brief for Sony Music Entertainment Group.
[19] The TJ. Hooper, 60 F.2d 737 (2d Cir. 1932) held that industry customs may be admissible in the absence of defined statutory or case law definitions.
[20] “Copyright Policies,” Spectrum, accessed March 1, 2026, https://www.spectrum.com/policies/copyright-infringe-claim; “Xfinity Help & Support,” Xfinity, accessed February 28, 2026, https://www.xfinity.com/support/articles/comcast-dmca-compliance-policy; “Copyright / DMCA”, T-Mobile, accessed February 28, 2026, https://www.t-mobile.com/responsibility/legal/copyright.