Section 230, Generative-AI Ad Tools and Facilitator Liability: The Two Bouck v. Meta Rulings

Bouck v Meta

Section 230 Doesn't Shield Meta's AI-Generated Scam Ads

U.S. District Court for the Northern District of California, Chief Judge Richard Seeborg — Bouck et al v. Meta Platforms, Inc., No. 3:25-cv-05194-RS; order on the motion to dismiss dated 24 March 2026, followed by a subsequent dismissal on securities-preemption grounds reported June 2026.

Two successive rulings in the US Bouck v. Meta Platforms case deserve the attention of anyone working on the accountability of intermediaries that enable online investment fraud. In the first, a federal court held that Section 230 of the Communications Decency Act did not immunise Meta for advertising content that its own generative-AI tools had helped create, a genuine narrowing of a near-absolute liability shield — and allowed claims for aiding and abetting fraud and negligence to proceed. In the second, the same claims were dismissed as preempted by federal securities law. The sequence is instructive precisely because it separates two questions that are often conflated: whether an intermediary can be treated as a participant in the fraud, and whether the particular legal vehicle chosen to pursue it survives. Neither ruling is a final judgment on the merits; both arise at the motion-to-dismiss stage, and the first was decided with leave to amend.

Background

The litigation arises from a pump-and-dump scheme in the shares of China Liberal Education Holdings Ltd. (Nasdaq: CLEU). Retail investors were solicited through Facebook and Instagram advertising promising outsized returns; when the operators liquidated, the share price collapsed from USD 7.90 to USD 0.15 in a single trading day, with reported losses exceeding USD 300 million. The plaintiffs are individual investors proceeding as a putative class, represented by Morris Kandinov LLP.

The feature that distinguishes the case from ordinary “platform hosted a bad ad” litigation is the role of Meta’s advertising technology. The complaint alleges that the fraudsters used Meta’s AI-driven creative tools — Advantage+ Creative, Dynamic Creative and Flexible Format — to generate and optimise the deceptive advertisements, producing “at least 86 different variations” of the ads; Advantage+ Creative uses AI to generate the text and images themselves. The reach of that automation has been illustrated elsewhere by a Reuters journalist who tested the tool and received AI-generated ad pitches he had never written.

The first ruling (24 March 2026): Section 230 and the surviving tort claims

Section 230. Meta invoked Section 230 of the Communications Decendy Act of 1996, which generally shields online companies from claims over content posted by their users.  The court applied the Ninth Circuit’s development standard from Fair Housing Council of San Fernando Valley v. Roommates.com, LLC, 521 F.3d 1157 (9th Cir. 2008) (en banc): a service loses immunity where it “contributes materially to the alleged illegality of the conduct.” Because the plaintiffs had adequately pleaded that Meta’s tools generated the images and text of the ads, the court found the immunity defence could not be resolved on the pleadings and denied the motion as to Section 230, observing that “that degree of participation is not protected by section 230.” The companion case Suddeth v. Meta, by contrast, was dismissed under Section 230: there the plaintiffs alleged only algorithmic amplification of pre-existing ads, which the court treated as protected distribution rather than content creation.

The surviving claims. The court allowed three theories to proceed: aiding and abetting fraud, negligence and unjust enrichment. The aiding-and-abetting holding is the analytically significant one. The court accepted that knowledge was adequately pleaded, from Meta’s ad-review apparatus, prior fraud litigation and the involvement of its AI tools, and held that even “routine operations may constitute substantial participation if done with knowledge.” On the wilful-blindness point, the court declined to let Meta disclaim awareness merely because ad screening had been delegated to automated systems. The negligence claim survived as one grounded in misfeasance (active involvement) rather than mere nonfeasance, and was not barred by the economic-loss rule because the alleged conduct fell outside the contract.

The dismissed claims. The court dismissed the breach-of-contract claim, holding that Meta’s terms of service used aspirational language (“aim[s] to protect”) that created duties for users but no binding contractual promise by Meta; the related promissory-estoppel and good-faith-covenant theories fell with it. The California Unruh Civil Rights Act claim was dismissed because the plaintiffs alleged they were targeted for inclusion, not excluded from a service on the basis of a protected characteristic. Leave to amend was granted.

The second ruling (reported June 2026): securities-law preemption

The victory on Section 230 proved largely pyrrhic. In a subsequent order, the surviving claims were dismissed as preempted by the Securities Litigation Uniform Standards Act (SLUSA), 15 U.S.C. § 78bb(f), which bars state-law class actions predicated on material misrepresentations in connection with the purchase or sale of covered securities. The court reasoned that “a suit in which a plaintiff claims the defendant made false statements which led the plaintiff to purchase securities … is quintessentially one sounding in the securities laws.” The plaintiffs faced a structural dilemma: characterising Meta’s AI-generated statements as material misrepresentations was necessary to defeat Section 230, but it also brought the action within SLUSA; treating them as immaterial would have defeated the claims on their own terms. The dismissal is therefore a preemption outcome — the claims were channelled into a federal securities regime that forecloses the state-law class vehicle — not a merits adjudication that an intermediary bears no responsibility for facilitating the fraud.

Our Assessment

For victim-protection practitioners the more durable contribution of Bouck is not the securities-preemption defeat but the two propositions the court was willing to accept at the pleading stage. First, an intermediary that actively shapes the harmful output, here, by generating advertising content through its own AI tools, can be treated as a participant rather than a neutral conduit. Second, and more portable, “routine operations may constitute substantial participation if done with knowledge,” and a provider cannot manufacture ignorance by delegating oversight to automated systems it has chosen to run. That reasoning speaks directly to the theme EFRI has pressed for years: the “neutral service” defence of payment providers, banks and platforms narrows sharply once knowledge and a material contribution are shown, and deliberately limited or automated monitoring is not a shield.

The reason the Bouck plaintiffs ultimately lost is narrower than it first appears, and the limit matters for the fraud EFRI most often sees. SLUSA preempts only class actions alleging misrepresentation “in connection with the purchase or sale of a covered security“, a nationally exchange-listed security or a registered fund,  and the Supreme Court construed that requirement strictly in Chadbourne & Parke LLP v. Troice, 571 U.S. 377 (2014), allowing state-law fraud claims to proceed where the fraud did not concern covered securities.

The bar applied in Bouck only because the scheme targeted a Nasdaq-listed stock (CLEU).

The investments at the centre of most online-broker fraud, contracts for difference, spot forex, commodities such as gold, and many crypto arrangements, are generally not securities at all; and where a scheme is structured as an investment contract that does qualify, it will typically still not be an exchange-listed “covered” security. In those cases the securities-preemption obstacle that defeated Bouck would not arise, and the Section 230 breakthrough, together with the surviving aiding-and-abetting-fraud and negligence theories, could carry through to the merits. Read this way, Bouck is a more useful precedent than its outcome suggests: the defeat is an artefact of the victims having been steered into a listed stock, not a limit on facilitator liability for the ordinary run of investment fraud.

The remaining reservations must still be stated plainly. The rulings are motion-to-dismiss decisions, not findings of liability, and the first came with leave to amend; whether a given non-listed investment is a “security” at all remains a fact-specific question. The dividing line Section 230 draws — content authorship — is a United States doctrine with no European counterpart; in Europe the equivalent question turns on the hosting privilege under the Digital Services Act and on knowledge-based accessory liability, a different axis, and neither Section 230 nor SLUSA has an analogue in European delict or consumer-protection law. The transferable insight,  that active contribution plus knowledge defeats the neutrality defence, survives the loss intact, and belongs in the broader movement toward redress for the victims of online and investment fraud, where the ability to identify and quantify an affected group (here, a class and a USD 300 million loss) is what makes accountability actionable.

More about this topic.