The instrument is a contract, and the statute stays where it was
Washington published a presidential memorandum on Wednesday that lets companies inside a new federal programme run surveillance and disruption operations against foreign criminal gangs and hackers. The first thing worth reading is what the memorandum leaves alone. US computer crime law still bars private cyberattacks, and the text stops short of allowing companies to hack back. The document neither repeals nor amends that prohibition, so the programme has to operate inside it.[1]
What the memorandum builds instead is a contractual route. A participating company signs with the Justice Department or the Department of Homeland Security, and every operation needs sign-off from representatives of both before it can be approved. Operations run exclusively under federal supervision, and that is where the legal cover comes from: the company acts as an extension of a federal law enforcement action, and holds no standing licence it could use on its own.[1]
The money makes the same point. A participating company must place 1 million dollars in escrow and forfeits it if the government finds the company is not complying with the rules on how these operations are conducted. A bond of that kind creates no new offence; it prices non-compliance and lets the government act on its own finding.[1]
Where the authorisation stops working
A federal authorisation binds US prosecutors. It has no hold on a foreign one. Jake Williams of Hunter Strategy, who called the policy half-baked, warned that Americans taking part could easily be classified as non-uniformed combatants while travelling overseas, and that such an allegation would not have to be true to be useful to a foreign government. That is the gap the design leaves open: the programme can shield participants at home while their exposure travels with them.[1]
Read narrowly, this could be ordinary contracting in new language. The memorandum's own limits point that way: it directs the government to create procedures preventing any operation from targeting Americans or US-based systems, and it requires participants to notify the government of an imminent attack on critical infrastructure such as power grids or water providers. Those are supplier obligations. The stronger reading is that the change sits in who may propose an operation rather than who may carry it out, since every operation still runs under federal supervision and cannot proceed without a federal sign-off.[1]
The guidance setting out entry requirements is due within two months, and it will settle which reading holds. If it specifies authorisation operation by operation, the leverage stays where the memorandum put it. If it grants an admitted company standing approval instead, the leverage moves to the vetting stage, and the escrow becomes the only continuing hold the government keeps.[1]