Why Matthew Prince of Cloudflare Wrote About Dropping Kiwi Farms

Matthew Prince, Cloudflare's CEO, wrote about dropping Kiwi Farms as a customer in September 2022 because he concluded that the platform's primary...

Matthew Prince, Cloudflare’s CEO, wrote about dropping Kiwi Farms as a customer in September 2022 because he concluded that the platform’s primary function had become coordinating harassment campaigns against specific individuals—activity that crossed his company’s line on what constitutes acceptable use, despite Cloudflare’s traditional stance on serving nearly all legal content. Prince framed the decision not as a free speech issue but as a practical matter of Kiwi Farms using Cloudflare’s infrastructure in a way that violated the company’s own terms of service, which prohibit using their network to facilitate coordinated abuse.

The decision came after Kiwi Farms users launched targeted harassment campaigns against a streamer and other individuals, with the harassment campaigns themselves becoming the primary purpose of the site. Prince acknowledged in his public statement that Cloudflare had long tried to remain neutral on content, but he drew a distinction between hosting unpopular opinions and facilitating organized campaigns designed to harm specific people. This decision became significant for investors because it highlighted tensions between corporate infrastructure providers’ legal obligations, their terms of service enforcement, and broader questions about corporate responsibility—tensions that continue to affect how Cloudflare and competitors navigate content moderation decisions.

Table of Contents

What Triggered Cloudflare’s Decision to Distance Itself From Kiwi Farms?

kiwi farms operated as an imageboard community known for targeting individuals with coordinated harassment campaigns, doxxing, and sustained online abuse. The site had attracted attention from researchers and advocacy groups studying online harassment, but Cloudflare had historically provided services to it under the principle that infrastructure providers should remain neutral on content as long as it remained legal. However, the targeting became increasingly organized and severe, with documented cases of individuals experiencing real-world consequences from the campaigns—including swatting attempts, threats to family members, and harassment at workplaces.

Prince’s public letter noted a specific inflection point: when harassment escalated to the point where it was no longer incidental to the site’s purpose but had become the site’s central function. The distinction mattered because it allowed Prince to argue that Cloudflare wasn’t making a judgment about acceptable speech but rather enforcing its own terms against using their services for abuse. This framing avoided the pure free speech debate while still making the business decision to terminate service. For investors, this illustrated how infrastructure companies increasingly face pressure to define the line between passive hosting and active facilitation of harm.

What Triggered Cloudflare's Decision to Distance Itself From Kiwi Farms?

The Business and Liability Implications Behind Cloudflare’s Choice

Cloudflare faced growing pressure from advocacy groups, media criticism, and internal employee concerns about hosting a site primarily known for harassment. The decision to drop Kiwi Farms wasn’t made in isolation—it came after years of similar pressure against other internet infrastructure companies hosting controversial content. By 2022, the landscape had shifted significantly from Cloudflare’s earlier public statements about neutrality; other major infrastructure providers had already terminated service to various sites, creating both competitive and liability pressure.

However, the decision also carried real business risks. Taking a stronger stance on content moderation could invite further demands from activists, advertisers, and policymakers to remove other customers or content—a potential slippery slope that could undermine Cloudflare’s appeal to customers seeking reliable, neutral infrastructure. some security experts and civil liberties advocates criticized the decision as setting a precedent that infrastructure providers should make content judgments, potentially affecting how sites with unpopular but legal viewpoints could operate. For investors, the key limitation was that Cloudflare’s explicit involvement in content moderation could complicate its positioning as a neutral infrastructure provider and potentially invite regulatory scrutiny in different jurisdictions with varying standards for what constitutes unacceptable use.

Public Opinion on Content ModerationStrongly Support42%Support28%Neutral18%Oppose8%Strongly Oppose4%Source: Pew Research Center 2022

How The Decision Reflected Changing Corporate Standards On Harassment and Abuse

The Kiwi Farms decision represented a shift in how major technology companies defined their responsibility for coordinated abuse, even when the abusive content itself occurred on other platforms. Previously, companies like Cloudflare had argued they couldn’t be expected to police the activities of their customers’ users—they provided infrastructure, not content moderation. Prince’s statement implicitly rejected this clean separation, arguing that when a service is primarily used to coordinate harassment, the infrastructure provider’s role becomes more direct.

This shift aligned with evolving standards at other major platforms and service providers. By 2022, major cloud providers, payment processors, and infrastructure companies had adopted policies against knowingly facilitating coordinated harassment campaigns. The change reflected both genuine concerns about online abuse and practical liability concerns—companies recognized that courts and regulators were increasingly willing to hold platforms responsible for harms their services enabled. For stock market investors, this shift mattered because it signaled that infrastructure companies could no longer rely on purely neutral stances; their shareholders would increasingly expect them to define boundaries on customer conduct, even when those boundaries were contentious.

How The Decision Reflected Changing Corporate Standards On Harassment and Abuse

The Practical Challenges of Enforcing Terms of Service at Scale

One complication in Cloudflare’s decision was that enforcement required subjective judgment about what constitutes “coordinated abuse” versus simply unpopular speech. Kiwi Farms users argued their discussions and links were protected speech; Cloudflare argued the overall pattern constituted coordinated harassment. This distinction mattered legally and operationally, because it meant Cloudflare couldn’t simply point to a written rule violation but had to make a judgment call about the cumulative effect of site activities. Implementing this kind of enforcement at scale creates operational headaches.

Cloudflare serves millions of customers and manages traffic for hundreds of millions of internet users. Building a team to investigate whether specific customer sites cross the harassment line requires significant resources and opens the company to accusations of inconsistent enforcement. Prince’s public discussion of the decision acknowledged some of this difficulty—he noted Cloudflare had previously tried to work with Kiwi Farms to address harassment but concluded the site’s leadership wasn’t willing to change its moderation practices. For investors, the comparison to content moderation at social media platforms was instructive: what seems like a straightforward principle (don’t facilitate abuse) becomes operationally complex and resource-intensive when applied across a large customer base, especially when customers disagree with judgments about what their sites’ purposes actually are.

The Regulatory and Liability Risks That Remain Even After Taking Action

Dropping Kiwi Farms reduced some liability exposure but created others. By publicly stating that he was terminating service due to the site’s coordination of harassment, Prince exposed Cloudflare to potential legal challenges arguing the decision was arbitrary, discriminatory, or made under pressure from activists rather than applied consistently. Other customers targeted for removal could point to the Kiwi Farms decision and argue that if Cloudflare was making content judgments for that case, it should explain why other sites weren’t treated similarly. The regulatory environment adds another layer of complexity.

Depending on jurisdiction, Cloudflare’s explicit involvement in content moderation decisions could change how regulators view the company’s liability. In some regulatory frameworks, infrastructure providers that make active content moderation decisions face different legal standards than those claiming neutrality. A warning for investors: Cloudflare’s decision to drop Kiwi Farms, while potentially reducing harassment-related reputational risk, created new regulatory risk by establishing that Cloudflare does make content judgments rather than remaining neutral. This positioning could become a liability if future regulatory frameworks hold content-moderating companies to stricter standards than neutral infrastructure providers.

The Regulatory and Liability Risks That Remain Even After Taking Action

How The Decision Positioned Cloudflare Among Competitors

The Kiwi Farms decision differentiated Cloudflare’s public stance on content moderation compared to some other infrastructure providers. Some companies in the content delivery and DDoS protection space had remained conspicuously quiet on similar situations; others had taken stronger stances earlier. Cloudflare’s relatively late and carefully-worded decision positioned the company as willing to act on extreme cases while still maintaining some distance from broader content policing efforts.

This positioning had subtle competitive implications. Cloudflare could appeal to customers concerned about supporting sites known for harassment while still maintaining credibility with customers wary of aggressive content moderation. The decision also allowed Cloudflare to align with employees’ expressed concerns about the company’s services being used to facilitate abuse—a factor that matters for talent retention in technology.

What The Decision Signals About Future Expectations For Infrastructure Companies

The Kiwi Farms decision established a precedent, even if Prince was careful not to call it one. Infrastructure companies will likely face increased pressure to define where they draw the line on harmful coordinated activity.

The categories most likely to face future scrutiny include coordinated harassment campaigns, organized fraud or scams, and coordinated campaigns to interfere with elections or spread disinformation—areas where the “infrastructure neutrality” argument faces stronger challenges than pure speech disagreements. For investors in infrastructure and platform companies, this trend suggests that the companies maintaining the tightest “just provide the service” stance may face increasing external pressure, while companies that proactively define boundaries may gain stability and public support, even if those definitions become contentious. The long-term question is whether infrastructure providers will eventually need dedicated teams and established processes for content decision-making, similar to what social media platforms have built—a significant cost that could affect margins and competitive positioning in the industry.

Conclusion

Matthew Prince’s decision to drop Kiwi Farms reflected a broader shift in how infrastructure companies balance their traditional neutrality with emerging expectations that they bear some responsibility for how their services are used to facilitate coordinated harm. The decision was carefully framed as a terms-of-service enforcement issue rather than a content choice, but it still represented a substantive judgment about acceptable use—a judgment that other infrastructure companies are increasingly expected to make.

For investors, the decision matters because it signals that infrastructure companies can no longer hide behind pure neutrality arguments when facing coordinated abuse and harassment. The practical implications include higher compliance costs, more subjective enforcement decisions, and new regulatory risks—but potentially better alignment with employee values and reduced reputational damage from enabling harassment. Companies in the infrastructure space will likely need to develop clearer policies and dedicated teams for these decisions, making content moderation a more visible part of their business operations and risk profiles.


You Might Also Like