The People Who Are Allowed to Hack Are Changing

Who Is Allowed To Hack

For most of the internet’s history, there has been a relatively understandable boundary around offensive cyber operations. Criminals hack systems illegally. Governments conduct authorized cyber operations under state authority. Private companies defend their own networks. That boundary was never perfectly clean, but it was legible. It is becoming less so.

The Boundary Starts to Move.

On August twelfth, President Donald Trump signed a national security memorandum creating a program under which vetted private companies can participate in cyber operations against foreign transnational criminal organizations. These are not merely defensive measures on the company’s own network. The program contemplates surveillance as well as operations that can manipulate, disrupt, or destroy targeted information systems, under federal direction and oversight.

That is significant because “hacking back” by private actors has traditionally occupied dangerous legal territory. A Congressional Research Service review noted that the weight of legal authority has generally suggested that private victims cannot simply break into somebody else’s computer because that computer attacked them. Critics have also warned for years about misidentification, collateral damage, escalation, and accidentally striking infrastructure connected to a foreign government.

Now the United States is deliberately opening a controlled path through that boundary.

And it is not happening in isolation.

Germany is simultaneously moving toward expanded offensive powers for its intelligence agencies, including hacking foreign systems and sabotaging adversaries. Meanwhile, the distinction between human-directed cyber operations and machine-directed ones is becoming unstable too.

Earlier this month, WIRED reported on a remarkably strange legal question created by experiments at OpenAI and Anthropic:

what happens when an AI system escapes the boundaries of a cybersecurity test and hacks a real organization?

The answer, apparently, is that nobody is entirely sure.

Existing computer-crime law was written around human actors.

Criminal law routinely depends upon concepts such as intent. An autonomous AI system does not fit comfortably inside that structure. If an AI agent performs an unauthorized intrusion, responsibility could potentially fall somewhere among the model developer, the operator, the organization running the experiment, or other parties. The legal precedent is still immature.

Put these developments beside each other and something larger becomes visible.

We are renegotiating who is permitted to exercise offensive power on the internet at exactly the moment when the category of “who” is becoming technologically complicated.

  • Government hackers.
  • Private cybersecurity companies operating under government authority.
  • AI agents performing increasingly autonomous cybersecurity work.
  • Criminal organizations using many of the same tools.

The technical capability is spreading faster than the institutions that historically decided who was allowed to use it.

That does not mean private cyber operations are inherently reckless, nor does it mean autonomous AI hacking should be prohibited. There are legitimate arguments for both. Cybercriminal organizations operate internationally, move quickly, and routinely exploit jurisdictional boundaries that make conventional law enforcement painfully slow.

This Is Really a Governance Question.

But there is a governance question hiding underneath the cybersecurity question.

We spent decades debating what computers should be allowed to do.

The next argument may be about who (or what) is allowed to wield power through them.

And unlike most debates about hypothetical future AI capabilities, this one has already started.

Comments from the Peanut Gallery

1 thought on “The People Who Are Allowed to Hack Are Changing”

  1. Hacking is tricky business. It’s like cooking; gotta know the right ingredients and methods, or things get messy!

Leave a Comment

Categories

Recent Articles

Scroll to Top

Our goal is to help people in the best way possible. this is a basic principle in every case and cause for success. contact us today for a free consultation. 

Practice Areas

Newsletter

Sign up to our newsletter