Apple Files New UK Court Challenge Over iCloud Encryption
Photo: Garry Knight / CC BY 2.0
Apple has gone back to court over the UK's demand for a way into encrypted iCloud data, filing a fresh complaint at the Investigatory Powers Tribunal against a rewritten Technical Capability Notice. The new challenge, first reported by the Financial Times and picked up on 3 August 2026, restarts a fight over an encryption backdoor that the British government has never publicly confirmed and that Apple is legally forbidden from describing.
The stakes are larger than one company's cloud service. This is the first serious legal test of whether a state can order a vendor to keep the technical ability to read what it has promised it cannot read.
What a Technical Capability Notice actually demands
A Technical Capability Notice is issued under section 253 of the Investigatory Powers Act 2016. It does not ask for a named account. It orders a company to retain the ability to produce readable content if a warrant arrives later. For a service built on end-to-end encryption, that is not a disclosure request, it is a design instruction.
Apple's Advanced Data Protection extends end-to-end encryption to iCloud backups, photos, notes and most other categories. The keys are generated and stored on the user's own devices, so Apple never holds them and cannot decrypt the content even when it wants to. Preserving the capability a notice describes therefore means changing the architecture: keeping a key, a copy, or a path that someone at Apple could walk down on request.
Rather than build that path, Apple switched Advanced Data Protection off for UK users in February 2025. British customers lost the option; the rest of the world kept it.
Apple vs the UK government: how the encryption case reached this point
| Date | Event |
|---|---|
| February 2025 | The Washington Post reports a secret notice served on Apple under the Investigatory Powers Act. Its reported scope covers iCloud data worldwide, not only British users. |
| February 2025 | Apple withdraws Advanced Data Protection for UK users instead of building access. |
| March 2025 | Apple lodges its first complaint with the Investigatory Powers Tribunal. |
| April 2025 | The tribunal publishes a judgment confirming the bare details of the case and rejecting the government's argument that even its existence must stay secret. |
| July 2025 | A case management order directs both sides to agree a set of assumed facts for a seven-day hearing. |
| Autumn 2025 | After objections from Washington, the worldwide demand is dropped and a narrower notice limited to UK users takes its place. |
| August 2026 | Apple files a new tribunal complaint, this time against the UK-only notice. |
The second notice is narrower, not smaller
Shrinking the order to British accounts solved a diplomatic problem. US lawmakers had objected that a foreign government was reaching into American users' data, and the White House treated the demand as a bilateral issue rather than a domestic British one. Limiting the notice to UK residents removed that friction.
It did not remove the engineering one. A backdoor scoped to one country still has to exist inside a single global codebase. Once a mechanism for lawful access is built, the boundaries around it are policy, not physics, and policy is exactly what changes when governments change.
Why a UK ruling will be read far outside the UK
The Investigatory Powers Tribunal is the only UK court that can hear a challenge of this kind, and it usually works behind closed doors. It has already had to concede ground on that: after public comments about the case from senior figures on both sides of the Atlantic, the tribunal accepted that open justice outweighed a blanket secrecy claim, and agreed to hear argument on an agreed set of assumed facts rather than on classified detail. Privacy International and Liberty are pursuing a parallel challenge to the notice regime itself.
Whatever the tribunal decides will function as a template. If a government can require a vendor to keep a decryption capability it has publicly retired, then any promise of the form "we cannot access this" becomes conditional on the law of the country the provider answers to. That question does not stop at cloud backups. It is the same question that sits under every no-logs claim in the privacy industry: whether a provider does not hold your data, or merely does not hold it yet, depends less on marketing than on the jurisdiction that can compel a redesign.
For users, the practical read is narrower. Advanced Data Protection remains unavailable in the UK while this runs, which means iCloud backups of British accounts stay in a form Apple can decrypt under a warrant. Anyone who wants end-to-end protection for that data in the meantime has to keep it outside iCloud.