Business Ethics · Corporate Accountability
Should Apple Answer for What Happens Downstream?
Apple does not run a single factory that assembles an iPhone from raw ore to retail box. It sits atop a pyramid of contractors, sub-contractors, and mineral traders, some it audits closely, some it has never directly met. This guide works through the legal boundaries, the competing moral arguments, what Apple actually does, and what a defensible middle ground looks like when a company’s product is the end point of a chain it does not fully control.
01 · Definition
What do we mean by “supply chain responsibility”?
Supply chain responsibility, in the business-ethics sense, refers to the question of how far a company’s moral and legal accountability extends beyond its own operations into the conduct of the independent firms it buys from, contracts with, and depends on to bring a finished product to market.
The phrase is often used loosely, as a synonym for corporate social responsibility generally, but the more precise question it points to is narrower and harder: when a named brand, Apple in this case, sells a product assembled from parts sourced through dozens of intermediary companies across multiple countries, and a labor violation, an environmental harm, or a human rights abuse occurs at one of those intermediary companies, who bears the responsibility? The company that committed the act directly, the brand whose name is on the box, both, or something more graduated than either extreme?
Answering that question requires separating three distinct concepts that get collapsed together in casual conversation: legal liability, which asks what a court can actually hold Apple accountable for under existing law; moral responsibility, which asks what a reasonable ethical framework would hold Apple accountable for regardless of what current law says; and reputational exposure, which asks what consumers, investors, and the press will hold Apple accountable for whether or not either of the first two categories technically applies. A full answer to the original question has to address all three, because they frequently point in different directions.
Entity in focus: the multi-tier supply chain
It is worth being precise about what “supply chain” actually names here, because the term hides an enormous amount of structural complexity. A Tier 1 supplier sells directly to Apple, an assembler like Foxconn, for instance. A Tier 2 supplier sells components to that Tier 1 assembler. Tier 3 and Tier 4 suppliers sit further back still, refining raw materials, mining ore, or running the small workshops that produce screws, connectors, or capacitors. Apple’s direct contractual relationship, and therefore its direct legal leverage, is strongest at Tier 1 and weakens sharply the further back the chain runs, even though the ethical stakes, particularly around child labor in mineral extraction, often concentrate at exactly those distant, low-visibility tiers.
02 · Supply chain structure
How is Apple’s supply chain actually structured?
Apple does not own or directly employ the workers who assemble most of its products; instead, it designs devices in-house and contracts manufacturing out to a small number of very large assembly partners, who in turn rely on thousands of their own component suppliers spread across dozens of countries.
The best-known Tier 1 partners are contract manufacturers such as Foxconn, Pegatron, and Wistron, Taiwanese-headquartered firms that operate enormous assembly campuses, mostly in China, along with a growing number of facilities in India and Vietnam. These companies are not Apple subsidiaries. They are independent, publicly traded corporations with their own boards, their own other clients, which include competitors of Apple, and their own labor practices, which Apple can influence contractually but does not directly control the way it controls its own retail stores or its own corporate campuses.
Beneath the assemblers: component and material suppliers
Below the assembly tier sits a much larger and less visible layer of component manufacturers, firms producing camera modules, displays, batteries, semiconductors, and connectors, many of which also supply Apple’s competitors. Apple publishes a list of roughly 200 companies that account for the large majority of its direct procurement spending, a level of disclosure that is unusually high for the industry, but that list still represents only the uppermost layer of a supply chain that, by Apple’s own estimate, involves many thousands of entities once sub-suppliers and material processors are included.
The deepest tier: raw material extraction
At the very base of the chain sit mines and mineral processing operations, cobalt from the Democratic Republic of Congo, tin from Indonesia, tantalum from Rwanda and the DRC, tungsten from a range of sources, and lithium and rare earth elements from several countries. These materials frequently pass through multiple traders and smelters before reaching any company with a direct contractual relationship to a Tier 1 or Tier 2 Apple supplier, and a meaningful share of cobalt extraction in particular occurs through small-scale, informal, artisanal mining operations that are not run by any identifiable corporate entity at all, which is precisely what makes this tier the hardest one for any brand, Apple included, to monitor or influence directly.
03 · Documented lapses
What ethical lapses have actually been documented in Apple’s supply chain?
Across more than a decade of investigative reporting, NGO monitoring, and Apple’s own audit disclosures, several categories of documented lapses recur consistently: excessive and sometimes forced overtime, unsafe working conditions, underage labor, allegations connected to forced labor of Uyghur workers, and child labor risk in artisanal cobalt mining.
Worker suicides and excessive overtime at Foxconn
The most widely publicized episode remains a cluster of worker suicides at Foxconn’s Longhua and Guanlan campuses in Shenzhen between 2010 and 2011, which drew global attention to working hours, dormitory conditions, and management practices at the plants producing Apple products alongside devices for other electronics brands. Subsequent investigations, including Apple’s own commissioned audits, documented recurring excessive overtime beyond both Chinese legal limits and Apple’s own supplier code, in some periods substantially above the maximum Apple’s code allows.
Underage and student labor
Several audits and independent investigations over the years have identified underage workers at component suppliers, as well as the use of student “interns,” some reportedly below the legal working age or working hours inconsistent with their enrolled coursework, placed at supplier factories through vocational school partnerships during periods of high production demand, most notably ahead of major product launches.
Allegations connected to Xinjiang and forced labor
Human rights researchers and investigative outlets have documented labor transfer programs moving Uyghur and other minority workers from China’s Xinjiang region into factories elsewhere in China, including facilities connected to Apple’s supply chain, under conditions researchers have characterized as bearing indicators of forced labor, including restricted movement and coercive recruitment. Apple has stated it found no evidence of forced labor in its own audits of the specific facilities named in these reports, a conclusion some human rights organizations have publicly disputed, citing the structural difficulty of detecting coercion through announced or semi-announced factory audits.
Cobalt mining and child labor risk
Investigations into the cobalt supply chain, cobalt being essential to lithium-ion batteries, have repeatedly documented child labor and dangerous working conditions at artisanal mining sites in the Democratic Republic of Congo, several tiers removed from any direct Apple contract. Apple, along with most major electronics brands sourcing cobalt from the region, has faced legal and public pressure over this issue, including a widely reported lawsuit filed on behalf of Congolese families alleging harm connected to cobalt used across the broader tech industry’s supply chains, Apple among the named companies.
The hardest lapses to prevent are rarely the ones closest to the brand’s own contract; they cluster at the tier where no single company has a direct relationship, a direct audit right, or a direct name attached to the harm. Recurring pattern across supply chain accountability reporting
04 · Legal boundaries
What are the legal boundaries of Apple’s responsibility?
Under traditional corporate law, Apple is not legally liable for the independent misconduct of its suppliers, because those suppliers are separate legal entities bound to Apple only by contract, not by ownership, and courts have historically been reluctant to pierce that separation absent direct evidence of Apple’s own knowledge, direction, or control of the specific wrongdoing.
This is not a loophole invented for Apple specifically; it reflects a foundational principle of corporate law, sometimes called the doctrine of separate legal personality, which treats each incorporated entity as legally distinct from the companies it does business with, even when one is far larger and more powerful than the other. A parent company is not automatically liable for its own subsidiary’s conduct in most jurisdictions, let alone for an unrelated contractor’s conduct several tiers removed. Extending liability that far would require either an unusually direct showing of Apple’s knowledge and control, or a new statutory basis created by legislation specifically designed to reach into supply chains.
Where statutory law has started to intervene
That statutory basis is precisely what a newer wave of legislation has begun supplying. The UK’s Modern Slavery Act of 2015 requires large companies operating in the UK to publish an annual statement describing the steps they have taken to identify and address forced labor risk in their supply chains, though it does not itself create liability for a supplier’s underlying conduct, only a disclosure obligation. The US Uyghur Forced Labor Prevention Act, in force since 2022, goes further for goods connected to Xinjiang specifically, creating a rebuttable presumption that such goods were made with forced labor and barring their import unless the importer can prove otherwise with clear and convincing evidence, which has directly affected import compliance obligations for electronics companies including Apple.
Germany, the EU, and mandatory due diligence
Germany’s Supply Chain Due Diligence Act, in force since 2023, moves further still, requiring large companies to actively identify, prevent, and address human rights and environmental risks across their supply chains, not merely disclose their existence, with regulatory penalties for failure to maintain adequate due diligence processes. The European Union’s Corporate Sustainability Due Diligence Directive extends a broadly similar obligation across the EU, phasing in over several years and reaching companies well beyond Germany’s borders if they do sufficient business inside the EU, Apple included.
The legal gap that remains
Even under these newer laws, the legal target is process, not outcome. A company can generally satisfy its legal due diligence obligations by demonstrating that it maintained reasonable, documented systems to identify and respond to risk, even if a violation still occurred somewhere in a supply chain too large and too deep to monitor with certainty. This is the central legal reality shaping the entire debate: the law increasingly asks whether Apple looked hard enough and acted reasonably in response to what it found, not whether Apple is directly answerable, the way a parent company answers for its own subsidiary, for every act committed anywhere in its supply chain.
05 · The case for
What is the moral case that Apple should be held responsible?
The strongest moral argument for extending responsibility down Apple’s supply chain rests on three related claims: that Apple’s purchasing power gives it real capacity to prevent harm, that Apple profits directly from the low costs those harms often make possible, and that a company which designs, specifies, and commissions a product bears some responsibility for the full process required to make it.
The capacity-to-prevent argument
A recurring position in business ethics holds that moral responsibility tracks capacity, that an entity with genuine power to prevent a foreseeable harm, and reasonable knowledge that the harm is occurring, bears some responsibility for exercising that power. Apple is, by most measures, the single largest customer many of its Tier 1 suppliers have. A supplier that loses its Apple contract loses a defining share of its business, which gives Apple leverage few smaller companies could exert over the same supplier. Under this view, Apple’s failure to use that leverage, when it plausibly could improve conditions, is itself a moral failing, distinct from and additional to the supplier’s own direct misconduct.
The complicity and benefit argument
A second line of argument focuses less on Apple’s capacity to intervene and more on the fact that Apple structurally benefits from the cost advantages that lax labor and environmental standards further down the chain can produce. Aggressive production timelines tied to Apple’s own launch schedules, and pricing pressure passed down through the contract structure, are frequently cited by labor researchers as contributing factors to the excessive overtime and rushed conditions documented at some supplier facilities. Under this argument, Apple is not merely a passive bystander to harms committed by others; its own commercial demands are one of the causal inputs that make those harms more likely, which moves Apple from bystander toward something closer to a contributing party.
The design and specification argument
A third, related argument points out that Apple does not simply buy finished components off a shelf; it specifies exact materials, exact tolerances, exact timelines, and in many cases works directly with suppliers to develop custom manufacturing processes for its products. A company that exercises that degree of specification and control over how a product is made, the argument runs, has taken on enough practical involvement in the production process that it cannot credibly claim the same moral distance a company simply purchasing a generic, off-the-shelf part might reasonably claim.
Moral responsibility scales with capacity to prevent a foreseeable harm and knowledge that the harm is likely.
Premise 2Apple has substantial capacity, through its purchasing volume and specification control, to influence supplier conditions.
Premise 3Documented patterns, overtime, underage labor, cobalt mining risk, are foreseeable and have been repeatedly reported to Apple over more than a decade.
ConclusionApple bears meaningful moral responsibility for supply chain conditions it has the demonstrated capacity to influence, distinct from direct legal liability for a supplier’s specific act.
06 · The case against
What is the moral case against extending responsibility that far?
The strongest counter-argument does not deny that supply chain harms are serious; it argues instead that holding Apple morally equivalent to the party that directly committed a violation, several tiers removed and often without Apple’s knowledge, misassigns responsibility away from the actors with the most direct control, and risks consequences that can make affected workers worse off rather than better off.
The agency and proximity argument
A foundational principle in most ethical frameworks is that responsibility attaches most strongly to the party with the most direct agency over the harmful act. A supplier’s factory manager who falsifies time records, a labor broker who coerces a worker’s recruitment, or a local mine operator who employs children, has direct, immediate agency over that specific decision in a way Apple, operating through several layers of contract and geographic distance, simply does not. Collapsing that distinction, treating Apple as equally responsible as the party that made the immediate decision, can be criticized as diluting moral accountability rather than sharpening it, since it risks letting the most directly responsible actors recede from scrutiny behind a much larger and more visible target.
The sovereignty and jurisdiction argument
A second objection notes that labor law, minimum age requirements, and environmental standards are, in the first instance, the responsibility of the national governments where the relevant facilities operate. China, the Democratic Republic of Congo, and other sourcing countries each have their own labor codes, their own enforcement agencies, and their own sovereign authority over conditions within their borders. Assigning primary moral responsibility to a foreign customer company, rather than to the domestic employer and the domestic regulator with actual jurisdiction and enforcement power, can be seen as a kind of accountability displacement that lets under-resourced or unwilling local enforcement off the hook while symbolically punishing the most visible, most reputationally exposed name in the chain.
The unintended consequences argument
A third and more practical objection concerns what actually happens when a Western brand responds to supply chain criticism by abruptly cutting ties with an implicated supplier or region. Labor researchers have repeatedly documented cases in which withdrawal, rather than engagement, left workers unemployed with no improvement in underlying conditions, since the facility often simply continued producing for a less scrutinized brand instead. Under this argument, treating Apple as morally responsible in a way that incentivizes exit rather than engagement can produce outcomes that are worse, not better, for the very workers the responsibility claim is meant to protect.
The proportionality argument
Finally, a proportionality-based objection argues that even accepting some responsibility does not justify treating Apple’s responsibility as equivalent to a supplier’s. A company managing thousands of suppliers across a genuinely global, multi-tiered chain cannot plausibly guarantee zero violations at every sub-tier without either withdrawing from complex manufacturing regions entirely, an outcome with its own serious costs, or claiming a standard of omniscient control no company of Apple’s scale and structure can realistically meet.
07 · Market power
Does Apple’s market power change the ethical calculus?
Most business ethicists treat Apple’s scale as ethically relevant but not, on its own, decisive; leverage expands the range of actions a company can reasonably be expected to take, without automatically converting every harm a supplier commits into a harm Apple is equally responsible for.
The underlying intuition is a common one outside business ethics too: a bystander who could easily prevent a harm at negligible cost is generally judged more harshly for failing to act than a bystander who lacks any realistic ability to intervene, even though neither bystander directly caused the harm. Applied to Apple, this suggests that its scale raises the bar for what counts as an adequate response, more resources should mean more thorough audits, more worker education investment, more willingness to absorb short-term cost to fix a documented problem, without collapsing the distinction between Apple’s obligation to respond well and the supplier’s obligation not to have committed the violation in the first place.
Leverage is uneven across the supply chain
It is worth noting that leverage is not evenly distributed across Apple’s own supply chain. Apple’s leverage over a Tier 1 assembler that depends on Apple for a large share of its revenue is substantial. Apple’s leverage over an artisanal cobalt mining operation in the DRC, which may sell through several layers of traders before the material ever reaches a company with an Apple contract, is comparatively minimal, since Apple has no direct commercial relationship, no contract, and often no reliable way to even trace which specific mine a given shipment of cobalt originated from. A responsibility standard built purely on capacity, then, would logically assign Apple far greater responsibility for conditions at its Tier 1 assemblers than for conditions several tiers deeper, which is precisely the gradient most due diligence frameworks, discussed later in this guide, attempt to formalize.
Power as a two-edged consideration
Apple’s scale cuts in a second direction critics of the pure leverage argument sometimes underweight: the same purchasing power that gives Apple influence over supplier conditions also gives Apple’s own commercial decisions, price targets, launch timelines, order volume, an outsized effect on the working conditions.that follow. Under intense pressure to meet a fixed launch date, a supplier facing thin margins may resort to excessive overtime not out of independent choice but because the customer’s own commercial terms have made that the path of least resistance. This suggests Apple’s leverage is not simply a dormant tool it could choose to use for good; Apple’s ordinary commercial behavior is already shaping conditions on the factory floor, for better or worse, whether or not Apple frames that influence in ethical terms at all.
08 · Corporate practice
What has Apple actually done in response?
Apple maintains one of the more extensive supplier oversight programs among major electronics brands, including a published Supplier Code of Conduct, hundreds of announced and unannounced factory assessments each year, a public annual Supplier Responsibility Report, and targeted programs addressing overtime, education, and clean energy across its supply base.
The Supplier Code of Conduct and audit program
Apple’s Supplier Code of Conduct sets standards covering working hours, wages, worker treatment, health and safety, and environmental performance, and requires suppliers to contractually commit to those standards as a condition of doing business with Apple. Apple backs the code with a large annual audit program, conducted by Apple’s own compliance team and third-party auditors, assessing suppliers against the code and publishing aggregate results, including violation categories and corrective action rates, in its annual report.
Targeted programs: overtime, education, and clean energy
Apple has run a specific initiative tracking maximum weekly working hours across its supply chain and reporting compliance rates publicly, alongside a supplier employee education program that has funded courses for hundreds of thousands of workers across its manufacturing base. Apple’s Clean Energy Program commits major suppliers to transitioning toward renewable electricity for Apple-related production, addressing the environmental dimension of supply chain responsibility alongside the labor dimension.
Where critics say the program falls short
Labor rights organizations and investigative journalists have raised a consistent set of criticisms of this apparatus. Audits, even unannounced ones, can be anticipated or gamed by supplier management in ways that make coercive practices, forced overtime, or underage labor harder to detect than a document review alone would reveal, since workers may be coached before an audit or reluctant to speak candidly to an auditor whose findings could affect their employer’s most important customer relationship. Apple’s disclosure, while more extensive than most competitors, still stops well short of full independent, worker-led verification, and its visibility into the deepest tiers of its mineral supply chain remains structurally limited by the same tracing difficulties that affect the rest of the industry. Apple has also, on a small number of occasions, removed suppliers from its approved list following serious violations, which supporters cite as evidence the program has real teeth, and critics note happens rarely enough to raise questions about how consistently the harshest available consequence is actually applied.
09 · Comparative frameworks
How do global frameworks treat this question?
The dominant international framework, the United Nations Guiding Principles on Business and Human Rights, resolves the responsibility question not by asking whether a company caused a harm directly, but by distinguishing between causing, contributing to, and being directly linked to a harm, and assigning a different, graduated expectation to each.
Adopted by the UN Human Rights Council in 2011, the Guiding Principles establish that states have a duty to protect human rights, but that businesses have an independent responsibility to respect human rights regardless of whether the state where they operate enforces that standard. Crucially for this question, the framework does not treat a company as equally responsible whether it directly caused a harm, contributed to a harm through its own business decisions, such as unrealistic timelines or pricing, or is merely linked to a harm through a business relationship, such as a distant supplier, without having caused or contributed to it. Each category triggers a different expected response: a company that causes harm should cease the conduct and remedy it; a company that contributes to harm should cease its contributing conduct and use its leverage to mitigate remaining harm; a company merely linked to harm through a relationship should use whatever leverage it has to influence the responsible party, without being treated as though it had committed the harm itself.
The OECD Due Diligence Guidance
The OECD’s Due Diligence Guidance for Responsible Business Conduct, along with its mineral-specific supplement, provides the operational blueprint many companies, Apple included, cite as the basis for their own supply chain due diligence programs: embed responsible conduct into policy, identify and assess actual and potential harms, cease or prevent identified harms, track the effectiveness of the response, and communicate publicly about it. This five-step structure is echoed closely in Apple’s own published methodology, and forms the basis against which most independent evaluators, and increasingly regulators, now judge whether a company’s supply chain program is adequate.
How competitors and industry peers compare
Apple’s disclosure and audit volume generally exceed those of many peers in the consumer electronics industry, though direct comparison is complicated by inconsistent reporting standards across companies. Coalitions such as the Responsible Business Alliance, of which Apple is a founding member, have attempted to standardize supplier codes of conduct and audit protocols across the electronics industry specifically so that a given factory faces one consistent standard rather than a different bespoke standard from every brand it supplies, an approach that addresses part of the fragmentation problem while leaving the deepest, most informal tiers of extraction largely outside any single company’s or coalition’s direct reach.
10 · A defensible position
What does a defensible middle ground look like?
Most contemporary business ethics scholarship and the newest generation of regulation converge on a similar answer: Apple should not be treated as the direct author of a distant supplier’s misconduct, but should be held to a standard of proportionate, continuously improving due diligence, with the expected intensity of that duty scaling to how much leverage and proximity Apple actually has at each tier.
Why full responsibility overstates the claim
Treating Apple as fully, directly responsible for every act committed anywhere in a supply chain involving thousands of entities across dozens of countries asks Apple to guarantee an outcome, zero violations, that no company managing a chain of that scale and depth can realistically deliver without either exiting complex manufacturing regions altogether, with its own serious costs to the workers currently employed there, or making disclosures no more meaningful than an unverifiable promise. It also risks the accountability-displacement problem described earlier, shifting scrutiny away from the local employer and local regulator with the most direct legal jurisdiction and the most direct agency over the specific violation.
Why zero responsibility understates the claim
Treating Apple as bearing no responsibility at all, on the other hand, ignores the well-documented ways Apple’s own commercial decisions, launch timelines, pricing pressure, order volume, causally contribute to the conditions under which violations become more likely, and it ignores the genuine leverage Apple has, and has in specific documented instances used, to change supplier behavior when it chooses to. A pure no-responsibility position also sits uneasily with ordinary moral intuitions about capacity: an actor with substantial, demonstrated power to reduce a foreseeable harm at reasonable cost is not usually excused from all responsibility simply because it did not commit the harm with its own hands.
The graduated due diligence standard
The position most of the evidence in this guide points toward is a graduated one: Apple’s responsibility is strongest, and closest to direct accountability, at the tiers where its leverage, contractual relationship, and visibility are greatest, its Tier 1 assemblers, and weakens, without disappearing entirely, at the tiers where its leverage, relationship, and visibility are weakest, artisanal mineral extraction several layers removed from any direct Apple contract. At every tier, the standard Apple can fairly be held to is not a guarantee of zero violations, but a demonstrable, good-faith, continuously improving process: identify foreseeable risks, use available leverage to prevent them, respond meaningfully when they occur, and be transparent about where the process still falls short, rather than treating an audit report as a closed case.
The honest answer is not “fully responsible” or “not responsible at all.” It is that responsibility is real, proportionate to leverage, and measured by the quality of the process, not by an impossible guarantee of a perfect outcome. Synthesis of UN Guiding Principles, OECD due diligence guidance, and mainstream business ethics scholarship
11 · Where this is heading
Where is corporate accountability regulation heading?
The regulatory trend across major markets is unmistakably toward converting what was once a voluntary, reputation-driven standard into a binding legal one, with mandatory due diligence, import restrictions tied to forced labor risk, and civil liability exposure for inadequate supply chain oversight all expanding rather than contracting.
From disclosure to mandatory due diligence
The regulatory arc over roughly the past decade runs from simple disclosure requirements, such as the UK Modern Slavery Act’s reporting obligation, toward substantive due diligence mandates, such as Germany’s Supply Chain Act and the EU’s Corporate Sustainability Due Diligence Directive, which require companies to actively act on identified risks, not merely describe their existence in an annual statement. This shift matters for the underlying ethical question because it effectively legislates a version of the graduated middle-ground standard described above: not a guarantee of zero harm, but a legally enforceable obligation to run an adequate risk identification and mitigation process, with real penalties, and in some frameworks real civil liability exposure, for companies that fail to do so.
Import enforcement as a parallel track
Separately from due diligence mandates, import enforcement mechanisms like the US Uyghur Forced Labor Prevention Act are creating a second, more blunt pressure point, restricting market access for goods connected to specific high-risk regions or practices regardless of a company’s broader due diligence quality, which pushes companies toward more granular supply chain mapping simply to maintain the ability to sell in major markets at all.
What this means for the underlying ethical debate
As this regulatory infrastructure matures, the philosophical debate over how far moral responsibility should extend down a supply chain is gradually being answered, in practice if not in theory, by legislatures rather than by ethicists: companies including Apple are increasingly required, not merely encouraged, to build the kind of graduated, leverage-proportionate due diligence process this guide describes as the most defensible middle ground, with the details of exactly how far that obligation reaches into the deepest, most informal tiers of extraction remaining the most actively contested frontier of the law.
Closing
Key takeaways on Apple’s supply chain responsibility
Apple is not the direct legal author of every violation committed somewhere across a supply chain involving thousands of entities and multiple tiers of contractors, sub-contractors, and mineral traders, and treating it as though it were overstates what corporate law, and most defensible ethical frameworks, actually support. But Apple is also not a mere bystander. Its purchasing power, its specification control over how products are made, and its own commercial decisions about timelines and price all causally shape the conditions under which supplier-level violations become more or less likely, which is precisely why a pure no-responsibility position understates the case as well. The most defensible answer sits in between: responsibility that is real, that scales with leverage and proximity, and that is discharged not by a guarantee of a perfect supply chain, an outcome no company of Apple’s scale can credibly promise, but by a transparent, continuously improving process of identifying risk, using available leverage to prevent it, and responding meaningfully when it is found. That is also, not coincidentally, the direction the law itself is now moving, which suggests the debate over how much responsibility Apple should bear is converging, from ethics and from regulation alike, on roughly the same graduated answer.
12 · Notes