Blog
Security11 Aug 2026

Apple is in court again over encrypted backups.

A second UK order to reach encrypted iCloud data is now before the Investigatory Powers Tribunal. Eighteen months into the dispute, the strongest iCloud encryption is still switched off for an entire country.

On 3 August 2026 the Financial Times reported, and TechCrunch summarised, that Apple has filed a fresh complaint with the UK's Investigatory Powers Tribunal. The complaint challenges a technical capability notice from the Home Office requiring Apple to provide access to encrypted iCloud data belonging to British users. Reporting on 4 August put the filing itself in July, with the notice narrowed to the UK after the earlier, broader version was dropped.

This is the second notice in the same fight. According to the case page kept by Privacy International, which is challenging the regime alongside Liberty and two individual claimants, the existence of the first notice surfaced in February 2025; the government withdrew it in October 2025 and issued a replacement scoped to British users, and Apple's appeal was dismissed. A case management hearing is listed for September 2026 and a substantive hearing on the Privacy International claim for December 2026.

A notice nobody is allowed to describe

Technical capability notices are issued under the Investigatory Powers Act 2016 and carry a duty of secrecy. The recipient may not confirm that a notice exists, which is why neither Apple nor the Home Office has described the demand in its own words. In April 2025 the Tribunal published a judgment rejecting the government's position that the entire case should be heard in private, and it has since worked from assumed facts so that argument can happen in the open without confirming classified detail.

The practical effect is that a rule about the security of consumer cloud storage is being written in a forum where the subject matter cannot be stated aloud. Users of the affected service learn what is happening from journalists and court listings.

The encryption is still switched off

Apple's response to the first notice was to stop offering the feature rather than weaken it. Advanced Data Protection is the setting that extends end-to-end encryption to iCloud backups, photos and files, with the keys held only on the user's devices. Apple's own support note records that it can no longer offer Advanced Data Protection to new users in the United Kingdom, and existing users there had to turn it off to keep using iCloud.

That is the state of play eighteen months later. The legal question of whether the capability can be compelled is unresolved, and in the meantime the option is gone for everyone in one country. Standard iCloud storage remains encrypted, with Apple holding keys it can be ordered to use.

The capability is the liability

A notice of this kind is only coherent because a capability exists to preserve. Where a provider can decrypt, that ability is a durable property of the system: reachable by a court in any jurisdiction the provider operates in, by an insider with the right access, and by an attacker who reaches the same key material. Removing it is what Advanced Data Protection was for, and removing it is what the notice appears to contest.

Courts decide who can be compelled. Key placement decides who has anything to hand over.

What it means for sensitive files

Most people do not choose a cloud provider by reading surveillance law. But anyone who handles files that carry consequences (case documents, medical records, source material, unpublished engineering data) is making a bet about custody every time they upload. If the file can be read by the provider, the protection you have is the provider's willingness to litigate, in a proceeding you will not be told about.

Design settles the question that policy leaves open. When keys never leave the sender's device, there is no capability to preserve, no key to escrow, and nothing to produce beyond ciphertext. We wrote about the general shape of this problem in The problem with cloud backdoors; the Apple case is that argument being tested in a real court.

How SpaceBox handles custody

SpaceBox Lite encrypts on the sender's device. Files are sealed with AES-256-GCM, and the file key is wrapped to the recipient's public key using post-quantum ML-KEM-768, the key exchange standardised by NIST as FIPS 203. Private keys stay on the device, our servers hold ciphertext, and a sender needs no account and gives no personal data. Post-quantum key exchange is not unique to us and is becoming standard practice; the part that matters for this story is simpler, which is where the keys live. For files that should not be reachable over a network at all, the SpaceBox hardware vault keeps an air-gapped, append-only copy on your own premises. See Why SpaceBox for the full comparison.

The Tribunal will decide what a government may require of a company that holds keys. That ruling matters, and it will take until at least December to hear. The choice available today is whether your files sit in a system that has an answer to give.

Storage that cannot read youEnd-to-end encrypted, post-quantum, ciphertext only. Start free.

Keep reading

All articles →