BMG Rights Management (US) LLC v. Cox Communications, Inc. is the case that turned the DMCA's repeat infringer condition from fine print into a forfeit you can lose in court. A federal jury in the Eastern District of Virginia ordered Cox to pay $25 million in December 2015 for its subscribers' BitTorrent piracy, not because Cox infringed anything itself, but because it had no enforceable safe harbor left. The Fourth Circuit later vacated that number, and the parties settled confidentially, but the core holding still governs platforms today: a repeat infringer policy that lives on paper while nothing happens in practice forfeits DMCA safe harbor under 17 U.S.C. § 512(i).

If you operate a platform, this case defines what your enforcement record has to look like. If you file takedowns, it is the authority that moves a conversation from "we removed that link" to "what are you doing about this account." This page walks the full timeline, the holdings you can rely on, and what to do with them today.

How BMG v. Cox reached a jury

BMG, the music rights company, sued Cox in 2014 in Alexandria, Virginia. Its enforcement partner, Rightscorp, joined BitTorrent swarms sharing BMG's catalog, recorded the internet addresses involved, and sent Cox a relentless stream of copyright notices identifying subscribers by IP address. The strategy was deliberate. Rather than chase individual file-sharers the way the industry had since the Napster era, BMG aimed at the pipe, on a contributory infringement theory built on the framework MGM v. Grokster articulated.

Judge Liam O'Grady shaped the trial with two pretrial rulings. He rejected BMG's vicarious liability theory outright, so that claim never reached a jury. And in the ruling that defined the case, he held as a matter of law that Cox had not reasonably implemented its repeat infringer policy and therefore could not invoke Section 512 safe harbor at all. The safe-harbor question never went to the jury, because there was nothing left for a jury to decide.

The jury returned its verdict in December 2015: Cox was contributorily liable, and the damages figure was $25 million.

Cox's repeat infringer policy: paper versus practice

Section 512(i) requires a provider to have adopted and reasonably implemented a policy providing for termination, in appropriate circumstances, of subscribers and account holders who are repeat infringers, and to inform subscribers the policy exists. Cox had the paperwork. Its acceptable use policy warned that repeat copyright infringers could lose service, and internally Cox ran a graduated response program that ran to thirteen escalating stages of warnings and suspensions, with termination waiting at the end.

Practice was another story. The trial record showed a system engineered to avoid the outcome it promised on paper. Cox's "soft termination" practice suspended an account briefly and then automatically reversed it, restoring service without any human deciding the subscriber deserved to stay. Actual terminations for repeat infringement across the period in evidence were vanishingly rare, and internal emails showed termination being treated as something to steer around rather than an endpoint. Cox knew who its heavy repeat infringers were. The gap between what the policy said and what the abuse desk did was the whole case.

That gap is the lesson for operators. Cox passed "adopted" and passed "informed." It failed "reasonably implemented," because a policy that contemplates termination, paired with a practice engineered never to reach it, is exactly what Section 512(i) does not protect. Our guide to building a repeat infringer policy covers the drafting side of this problem.

What the Fourth Circuit held on safe harbor

Cox appealed after its post-trial motions were denied, and the appeal was briefed and argued in 2016. This is why you will sometimes see the appellate ruling described as a 2016 decision. The published opinion did not issue until February 2018, reported at 881 F.3d 1013 (4th Cir. 2018). If you cite the case, cite the 2018 decision; the 2016 date is argument, not holding.

Three holdings matter.

Safe harbor stays lost. The panel affirmed that Cox was ineligible for Section 512 protection because it never reasonably implemented its repeat infringer policy. The court preserved provider discretion, nothing in the statute fixes a strike count or mandates termination on any schedule, but discretion about when to terminate is not a license to never terminate, and soft terminations that reverse themselves did not count as implementation.

No monitoring duty was created. Cox argued that treating Rightscorp's notices as awareness would force constant policing of its network. The panel rejected that. Section 512(m) still bars any general monitoring obligation, but a provider staring at years of notices about the same accounts cannot invoke 512(m) as a reason to do nothing.

The damages award fell. The jury instruction on volitional conduct was erroneous, so the $25 million could not stand. The liability findings survived; the number did not. The case went back for a new trial on damages, which is where the story ends below.

The vacated award and the settlement

Vacatur meant Cox owed nothing under the verdict. A jury's number attached to a defective instruction is not a debt, so the $25 million was never collectible as awarded. The full Fourth Circuit declined to rehear the case, Cox petitioned the Supreme Court, and the dispute ended before the Court acted: Cox and BMG settled on confidential terms, with reporting placing the settlement in 2019. You will see the endgame dated slightly differently across secondary accounts, the rehearing denial, the certiorari petition, and the settlement cluster close together, and no terms were ever disclosed. There was no damages retrial.

Two things survived. First, the Section 512(i) holding stands as binding precedent in the Fourth Circuit and persuasive authority everywhere else, because the settlement took Supreme Court review off the table. Second, the stakes it exposed. Statutory damages for willful infringement reach $150,000 per work, so a provider that loses safe harbor with a large catalog at issue faces numbers that make $25 million look like an opening bid. Later suits against the same defendant followed the same road: a case brought by other record labels ended in a $1 billion jury verdict against Cox in December 2019, a figure that then spent years moving through appeals. The exposure is not theoretical.

What DMCA safe harbor actually requires

Section 512 offers four conditional shelters, conduit (a), caching (b), hosting (c), and linking (d), and the repeat infringer condition sits in 512(i), gating all four. Cox lost under the conduit harbor, but a hosting platform or marketplace with the same implementation gap loses under 512(c) the same way. You can meet the takedown mechanics perfectly and still forfeit everything on 512(i). For grounding, see how DMCA safe harbor works generally, then run through our safe harbor requirements checklist.

In plain terms, a provider relying on Section 512 must:

  1. Register a DMCA agent with the Copyright Office and keep the listing current, so notices have an address.
  2. Remove or disable access to material expeditiously upon a proper notice.
  3. Run a working counter-notice process, restoring material within the statutory window unless the complainant files suit.
  4. Avoid a direct financial benefit attributable to infringing activity in cases where the provider has the right and ability to control it.
  5. Adopt, reasonably implement, and inform users of a repeat infringer policy, the condition Cox turned into a cautionary tale.

Notice what is absent: any obligation to police proactively. Section 512(m) forbids that. Safe harbor is a system that responds, to notices, to counter-notices, and to repeat behavior it has already recorded.

What platforms must implement after BMG v. Cox

BMG v. Cox turned one sentence of boilerplate into an operational requirement. If your service lets users post, host, upload, or transmit, a forum, a marketplace, a hosting reseller, an ISP, a defensible repeat infringer program has these parts:

  1. Publish the policy. Put the termination promise in your terms or acceptable use policy, in plain language. Cox passed this step; you need to as well.
  2. Define and track strikes. Decide what counts as a DMCA strike, tie it to the account, and log every valid notice against it. Tracking that lives in a shared inbox is not tracking.
  3. Escalate for real. Consequences have to escalate, and the escalation has to be capable of ending in termination. A soft suspension that reverses itself was Cox's fatal move.
  4. Actually terminate sometimes. The statute demands neither perfection nor a fixed count, but a program under which termination never arrives invites the Cox problem. Document each decision, including decisions not to terminate and why.
  5. Handle counter-notices without getting played. Repeat infringers file bad counter-notices to trigger automatic restoration and buy time. Know what happens after a counter notice, and count the pattern against the account.
  6. Apply the rules uniformly. Quiet exceptions for revenue accounts are exactly the discovery a plaintiff wants.
  7. Keep the records for years. The dispute that tests your program will concern conduct from long before it began.

One boundary note: this is US law. Platform strike systems you see elsewhere, including the EU's notice-and-action regime, are driven by different statutes, so export the principle, not the compliance plan.

Starting from scratch is easier than litigating the gap. A repeat infringer policy template gets the language right, and the seven points above are the questions a court will ask about your practice.

How copyright complainants cite BMG v. Cox

This is also the strongest authority a rights holder can invoke when a platform shrugs at a serial infringer. You know the pattern: your takedown works, the file disappears, the same account, or a fresh one, re-uploads it within days, and the loop repeats until you stop filing. That loop is what Cox ran for years, and it is what cost the company its safe harbor.

Work the case deliberately:

  1. Build the record first. Dated copies of every notice, every platform response, the re-registrations, the screenshots. The takedown evidence checklist exists for exactly this, and it works the same whether the target is re-posting your photography, your course videos, or a podcaster's entire feed.
  2. Escalate with the platform's own words. Quote its published policy, count the strikes that account has earned, and ask for the specific action the policy promises.
  3. Cite the standard, not an empty threat. Name BMG v. Cox, quote the "reasonably implemented" requirement, and state that a documented pattern of non-termination raises a real question about the platform's Section 512(i) compliance. Most platforms' counsel know the case. It shifts the conversation.
  4. Route around obstacles properly. If the host hides behind a proxy, Cloudflare abuse reports can reach the origin. If the infringer runs its own site, report the website to its host. If your notice was refused, see what to do when a takedown is rejected.

Know the limits, because they are real. Only a court can declare safe harbor forfeited; a letter cannot. A residential ISP will not disconnect a customer on your demand, establishing when that matters is what the litigation was for. Keep your own filings accurate, because misrepresentations invite 512(f) exposure. Hosting cases also turn on knowledge and red flags differently than conduit cases, which is why the Viacom v. YouTube case study is the companion read. When the pattern persists, our copyright removal escalation ladder maps the sequence from repeat notice to lawsuit.

BMG v. Cox: frequently asked questions

Did Cox have to terminate subscribers after a first or second notice?

No. Section 512(i) leaves providers to define what counts as a repeat infringer and what circumstances warrant termination. Neither the statute nor the Fourth Circuit's opinion fixes a strike count. Discretion survived the case; pretext did not. What defeated Cox was a policy engineered so that termination essentially never happened.

Did BMG ever collect the $25 million?

No. The Fourth Circuit vacated the award in 2018 over a faulty jury instruction on volitional conduct, so the figure was never enforceable as a judgment. The parties settled confidentially instead of retrying damages, reporting placed the settlement in 2019, and neither the amount nor the terms were disclosed.

Does the ruling apply to hosting platforms, or only to ISPs?

Both. Cox leaned on the conduit harbor in Section 512(a), but the repeat infringer condition sits in 512(i) and gates every safe harbor, conduit, caching, hosting, and linking. A hosting platform or marketplace running an unenforced policy faces the same forfeiture risk. The facts differ; the condition does not.

How many strikes does the DMCA require before termination?

None is required and none is set. The statute says "appropriate circumstances" and leaves the threshold to the provider. Many platforms use three strikes, but that is a policy choice, not law. Courts ask whether the policy is real, consistent, and actually enforced. A high threshold frankly applied beats a low threshold that never ends in disconnection.

Can I sue a platform just for ignoring repeat notices?

Not directly, and the distinction matters. Safe harbor is a defense to infringement liability, not a standalone claim. You sue for infringement, as BMG did, and the provider loses the defense if its repeat infringer policy was never reasonably implemented. That is the pathway the case created, but it is full-blown litigation: slow, expensive, and best attempted with counsel after escalation fails.

Where to go from here

  1. If you operate a platform, audit the gap between your written policy and your abuse desk's actual decisions this quarter. The audit is the defense; the gap is the exposure.
  2. If you file takedowns, open a dated evidence file per infringer today, and confirm every notice is complete before escalating, our walkthrough of how to file a DMCA takedown notice is the reference.
  3. File the straightforward ones yourself. The DIY takedown process covers the mechanics, and self-filing keeps your strike file clean and dated.
  4. Cite the case when the pattern appears. Quote the platform's own policy, count the strikes, and name the reasonably-implemented standard from the Fourth Circuit's decision.
  5. Get help when the pattern persists. Read when to hire a copyright lawyer for the decision factors, or have our team run the escalation for you end to end.