GitHub’s stance on copyright liability and user protections
GitHub has reiterated its developer-first approach to copyright enforcement, pushing back against blanket “three strikes” account bans that can unfairly penalize open source maintainers. The company argues that code is inherently collaborative and frequently reused, so a single takedown notice can have outsized consequences across an entire ecosystem of projects. Instead of automated blocks, GitHub reviews each case individually and provides transparency through public DMCA notices.
This position carries particular weight now, as the U.S. Supreme Court weighs Cox Communications v. Sony Music Entertainment. At issue is whether internet service providers and platforms should be held liable for user copyright infringement based on mere awareness, or only on conscious, culpable conduct. GitHub joined Google, Microsoft, Amazon, Mozilla, and Pinterest in an amicus brief advocating for the stricter liability standard. A ruling favoring the entertainment industry’s interpretation, the company warns, could force platforms to over-remove content in response to flawed or automated notices, stifling innovation and collaboration.
With over 150 million developers and 518 million projects hosted on the platform, GitHub processes hundreds of DMCA takedown requests monthly but also receives thousands of automated, incomplete, or inaccurate ones. The DMCA’s Section 512 safe harbor shields platforms from liability when they comply with notice-and-takedown procedures, and GitHub’s policies align with that framework. The company publishes every valid notice to a public repository and offers a clear appeal and reinstatement path for affected developers.
The case has drawn broad support from civil society groups, including Engine Advocacy, the Electronic Frontier Foundation, and Public Knowledge, all of which filed amicus briefs on behalf of free expression and the open internet. A Supreme Court decision in favor of Cox Communications, with the culpable-conduct standard it endorses, would be a landmark victory for platforms and the developers who rely on them.
Transparency Center reporting clarified for 2025
GitHub also updated its Transparency Center with first-half 2025 data, alongside a public repository of structured data files. Several reporting categories were refined to address ambiguity in how government takedown requests are classified.
Government takedown requests citing either local law or Terms of Service violations are now combined into a single “Government takedowns received” category. This reflects the reality that most requests are simply official demands for content removal, without a clear legal classification. However, the processed categories remain distinct. Content that violates GitHub’s Terms is handled like any other report, while content that only violates local law is geo-restricted to the affected jurisdiction and published in the gov-takedowns repository.
The README for that repository was clarified to state that it exclusively contains official government requests resulting in local-law-based removals. These are minor terminology changes, but GitHub notes they improve accuracy for researchers studying platform moderation. The company invites feedback via issues in the transparency center repository.
Proposed Acceptable Use Policy reorganization
GitHub has opened a pull request initiating a 30-day notice-and-comment period on a proposed update to its Acceptable Use Policies. The change would split existing provisions into four distinct policies governing Child Sexual Abuse Material (CSAM), Terrorist & Violent Extremist Content (TVEC), Non-Consensual Intimate Imagery, and Synthetic Media and AI Tools.
The Synthetic Media and AI Tools policy would be expanded to explicitly prohibit the use of deepfake tools to generate CSAM and TVEC, consistent with international laws. The company invites comment on the proposal through October 16.



