ProBackend
tech policy
3 hours ago5 min read

Google Sues SerpApi for DMCA Violations: A Deep Dive into the Legal Battle Over Web Scraping

Google filed a lawsuit against SerpApi in December 2025, accusing the web scraping company of circumventing security measures and violating the Digital Millennium Copyright Act by illegally accessing and reselling copyrighted content from Google search results. This comprehensive analysis covers the legal claims, technical measures at stake, and implications for AI companies relying on scraped data.

Google Sues SerpApi for DMCA Violations in December 2025

By Noel Johansson | Tech Policy | December 19, 2025


The Lawsuit Filed

On December 19, 2025, Google LLC filed a complaint in the U.S. District Court for the Northern District of California against SerpApi, LLC alleging violations of the Digital Millennium Copyright Act (DMCA). The lawsuit centers on claims that SerpApi unlawfully circumvents Google's technological barriers to scrape copyrighted content from its search results pages on a massive scale.

Google argued that "SerpApi's business model is parasitic," appropriating output from services that have made substantial investments to generate it. The company asserted that through "decades of experimentation, enhancements, and expenditures," Google has developed "first-in-class methods" for understanding user search intent and locating relevant content across the World Wide Web.

SearchGuard: The Technology at Issue

The core of Google's case involves a technological measure known as SearchGuard, launched in January 2025. According to the complaint, SearchGuard is the product of "tens of thousands of person hours and millions of dollars of investment." Its purpose is to prevent unauthorized third parties from automatically accessing Google's search results.

The technology works by sending a JavaScript "challenge" to search queries to validate that the request originates from a real user rather than automated software. This represents a significant escalation in how search engines protect their content from automated scraping.

How SerpApi Circumvented Protections

Google's complaint details numerous methods SerpApi employed to bypass SearchGuard:

  • Fake Browser Creation: Using "a multitude of IP addresses that Google sees as normal users" to mask automated queries
  • Device and Location Misrepresentation: Falsifying device, software, or location information to solve challenges
  • CAPTCHA Bypassing: Automated means to circumvent CAPTCHAs designed to test human versus machine users
  • Authorization Syndication: Sharing legitimate authorizations with unauthorized machines worldwide

Notably, SerpApi's founder, Julien Khaleghy, described the process as "creating fake browsers using a multitude of IP addresses that Google sees as normal users." The complaint also referenced a SerpApi blog post boasting about having "pre-solved Google's JavaScript challenge" and expressing confidence in bypassing future protection measures.

Scale of the Operation

The lawsuit highlights the staggering scale of SerpApi's operations:

  • Automated requests increased by as much as 25,000% over the last two years
  • Hundreds of millions of scraping queries executed daily
  • Billions of separate circumvention attempts against SearchGuard

This represents one of the largest enforcement actions taken against AI web scraping to date.

What SerpApi Scraped

SerpApi's business model involves scraping and reselling several types of copyrighted content:

Knowledge Panel Images

Google's Knowledge Panels often display copyrighted photographs that Google has licensed from various sources. SerpApi extracted these images and made them available to its customers for a fee.

Real-Time Search Data

Data used in Google Search real-time features is also subject to licensing agreements. SerpApi deceptively took this content and resold it, disregarding the rights of content providers.

Third-Party Licensed Content

Google Maps relies on third-party images, Google Shopping uses merchant-supplied pictures and information—content that comes with usage restrictions.

The lawsuit asserts two primary causes of action:

17 U.S.C. § 1201(a)(1)(A) – Violation prohibiting the circumvention of technological measures that control access to copyrighted works. Google may elect to recover statutory damages of at least $200 and up to $2,500 for each violation.

17 U.S.C. § 1201(a)(2) – Prohibition on trafficking in technology designed for circumvention. The complaint argues SerpApi manufactures and offers services marketed with knowledge they will be used to bypass SearchGuard.

Potential Damages

Google is seeking:

  • An injunction preventing SerpApi from circumventing Google's technological protection measures
  • Destruction of all technology involved in the alleged violations
  • Statutory damages for each violation (up to $2,500 per incident) or actual damages plus SerpApi's profits
  • Costs and attorneys' fees

The Broader Context

This lawsuit follows legal action taken by other websites against SerpApi and similar scraping companies. It is part of Google's long track record of affirmative litigation against scammers and bad actors on the web.

The case also occurs in the shadow of Google's decade-long battle over its Google Books project, which ultimately prevailed with the U.S. Court of Appeals for the Second Circuit ruling that it constituted fair use.

AI in Mental Health Care: The Scraping Connection

Google's complaint emphasizes that while crawling is a fundamental part of how the web works, there are important distinctions between:

  • Legitimate crawling following industry-standard protocols and website directives
  • Malicious scraping that overrides security measures and violates content provider rights

The lawsuit signals that companies providing scraping services as an API—particularly those marketing themselves as ways to "scrape Google"—face increasing legal risks. The mention of SerpApi's services being used by other businesses, including AI startups building tools for mental health care, underscores how these legal battles extend beyond simple data extraction into complex questions about who owns search result data and whether its repurposing for therapeutic applications constitutes fair use or infringement.

For clinicians evaluating AI tools for patient care, understanding these legal boundaries is crucial. The availability of real-time search data through scraping APIs directly impacts the quality and legality of information that AI-powered mental health platforms can access. See our analysis of assessing AI chatbot risks in mental health care for clinical perspectives on these challenges.

Similarly, the broader debate about opportunities and risks of AI psychological support highlights how legal decisions around web scraping could reshape the landscape of AI in mental health services.

A Last Resort

According to Halimah DeLaine Prado, Google's General Counsel, "When our technical security protections are circumvented in such a brazen way, as a last resort we take legal action to stop this behavior." This represents the second major lawsuit of its kind involving SerpApi and highlights the intensifying legal war between search engines and web scraping operations.

The case is expected to have significant implications for how AI companies access and use search data, particularly those building tools that integrate real-time information into therapeutic or healthcare applications.


This article was written by Noel Johansson. The views expressed are solely the author's own.

Sources:

  • IPWatchdog: Google Sues SerpApi for 'Parasitic' Scraping (December 26, 2025)
  • Google Blog: Why we're taking legal action against SerpApi's unlawful scraping (December 19, 2025)

Related reading: For more on how AI is transforming mental health care, see our coverage of artificial intelligence in healthcare and the ethical considerations surrounding automated therapy tools.

google sues serpapi for dmca violations in december

More blogs