GitHub has published updates across several developer policy fronts, covering a recent U.S. Supreme Court ruling on intermediary liability, the next round of DMCA exemptions, and refreshed transparency data for 2025. The posts touch on legal standards that shape how platforms like GitHub handle user-generated code and content.

Supreme Court clarifies secondary liability standard

The U.S. Supreme Court's March decision in Cox v. Sony addressed the limits of secondary copyright liability for online services. GitHub, along with other developer platforms, provided examples in an industry amicus brief for why balanced liability standards matter for intermediaries hosting user-generated content.

The Court's opinion made clear that service providers are not automatically liable for user copyright infringement absent evidence of intent to encourage or materially contribute to the infringement. That distinction matters for developers: overly expansive liability theories would make it difficult for neutral infrastructure platforms to operate at scale, and the clarified standard helps preserve lawful activity on platforms like GitHub.

DMCA Section 1201: Preparing for the next triennial review

The next triennial review of exemptions under Section 1201 of the DMCA is upcoming. Section 1201 restricts bypassing digital access controls, and its exemptions affect activities like security research, interoperability, repair, accessibility, and other lawful work. The most recent triennial cycle concluded in 2024, with exemptions in effect for the current three-year period.

GitHub has participated in the Section 1201 process for years. In 2021, it filed comments supporting a broad safe harbor for good-faith security research. The 2024 cycle included submissions of interest to developers, such as an Authors Alliance petition on access and preservation, and a security research petition focused on AI safety-related research and analysis. That petition drew supporting comments from HackerOne, the Hacking Policy Council, and academic researchers.

The generative AI security research petition was not ultimately adopted in 2024, but the questions it raised about applying existing DMCA frameworks to AI-related research remain open. Emerging issues include AI systems, model inspection, safety research, and interoperability. GitHub is soliciting developer input on which use cases matter most and how these questions should be approached in the 2027 triennial review.

Transparency Center: Full-year 2025 data released

GitHub's Transparency Center now includes full-year 2025 data. The update includes clearer charts and revised visualizations for abuse-related restrictions, appeals, and reinstatements.

The 2025 data shows the highest number of DMCA circumvention claims since transparency reporting began. GitHub attributes this to a few very large takedowns, but notes the figures underscore the importance of a balanced DMCA approach for software developers, collaboration platforms, and the open source ecosystem.

Coming next: Age assurance laws and developer impact

GitHub is tracking age assurance laws emerging in U.S. states, Brazil, and Europe. The concern is that requirements aimed at commercial, consumer-facing products could unintentionally sweep in open source operating systems, package managers, and other critical digital infrastructure.

An upcoming policy blog post and a May Maintainer Month session will focus on these topics. GitHub says it will continue advocating for policies that reflect technical realities and support open development.