Contact

All insights

August 14, 2026Policy5 min read

What the U.S. Cyber Memorandum Actually Says

On August 12, 2026 the White House authorized vetted private companies to conduct surveillance and disruption operations against foreign criminal organizations. It is the largest shift in American cyber policy in a decade. It is also narrower, and more fragile, than the headlines suggest.

For three administrations the position of the United States government was unambiguous: private companies defend their own networks, and only the state operates outside them. On August 12, 2026, a National Security Presidential Memorandum titled Expanding Capabilities to Combat Transnational Cyber-Enabled Crime ended that position.

The reporting has been loud and imprecise. This is a reading of the text.

What the memorandum establishes

The memorandum directs the National Coordination Center to create a program authorizing “Participating Companies” to conduct two categories of operation against foreign Cyber-Enabled Transnational Criminal Organizations, under federal control.

Cyber Surveillance Operations. Defined in Section 4(d) as collection of information or intelligence with the intent to remain undetected, and explicitly entailing “accessing such information systems without authorization from the owner or operator or by exceeding authorized access.” The definition includes collection of information usable for future effects operations.

Cyber Effects Operations. Defined in Section 4(a) as activity producing “the manipulation, disruption, denial, degradation, or destruction of information systems, networks, physical or virtual infrastructure controlled by information systems, or information resident thereon.”

Two co-Executive Directors, one designated by the Attorney General and one by the Secretary of Homeland Security, must coordinate and approve every operation in writing before any action is taken. Participating companies contract directly with the Department of Justice or the Department of Homeland Security, undergo vetting of facilities and personnel, and may be required to post a bond or escrow of not less than one million dollars, forfeited on non-compliance.

The limits written into the text

The memorandum draws four lines, in descending order of firmness.

Operations may not produce Critical Outcomes, defined in Section 4(b) as results likely to cause loss of life or serious injury, or to rise to the level of use of force or armed attack under international law. The Executive Directors have no authority to approve them.

Operations may not target United States persons or systems. Section 3(a)(x) requires a participating company that discovers unintentional targeting of a U.S. person, a system residing in the United States, or a system under U.S. person control, to cease the operation, apply minimization procedures and notify immediately.

Participating companies must report any imminent attack on U.S. critical infrastructure they discover, and any reasonable belief that an approved operation may produce Critical Outcomes.

And every operation requires individual written approval, preceded by deconfliction across federal law enforcement, State, Treasury, War, Justice and the Intelligence Community. There is no standing authorization.

What the memorandum does not do

Three gaps matter more than anything the memorandum adds.

It does not amend the Computer Fraud and Abuse Act. Section 2(b) states that the program operates “in accordance with… section 1030 of title 18, United States Code.” At the same time, Section 4(d) defines a permitted operation as one entailing unauthorized access. The reconciliation rests entirely on the exception at 18 U.S.C. 1030(f) for lawfully authorized investigative, protective or intelligence activity of federal agencies, extended to companies acting as government agents. No court has held that this exception reaches private parties. Civil liability under the CFAA remains available to anyone who claims harm.

It does not define “cyber-enabled crime.” The phrase appears in the definition of the target, in Section 4(c), and nowhere is it given content. The operating procedures due in October will determine the actual perimeter. Ransomware, fraud and sextortion are named in the accompanying fact sheet. Nothing else is.

It does not preempt state or foreign law. A presidential memorandum does not displace California Penal Code 502, New York’‘s computer trespass statute, the United Kingdom’’s Computer Misuse Act or the German criminal code. A company in full compliance with the federal program may still be violating the law of a U.S. state or of the country where the targeted infrastructure sits.

Section 5(c) closes the point: the memorandum “is not intended to, and does not, create any right or benefit, substantive or procedural, enforceable at law or in equity.” It confers no immunity. It can be revoked by a future administration in an afternoon.

One further clause deserves attention. Section 4(c) inverts the burden of proof: a foreign group is presumed not to be an institutional part of a foreign government, or wholly operated under its direction, unless clear intelligence establishes the connection. Doubt therefore authorizes rather than restrains. If the intelligence surfaces after the operation, the diplomatic incident has already happened.

Why this document exists

Strip away the operational detail and the memorandum is an admission.

It says that the volume of organized illegality operating online has outrun the capacity of the institutions charged with answering it. It says the answer is to borrow capability from the private sector. It does not say this apologetically; it says it as strategy.

We wrote the same diagnosis in our manifesto a month before the memorandum was signed. Between the law as written and the law as applied, a void has opened, and impunity lives in that void. The states have written serious law and then failed to apply it at any useful speed. The conclusion we drew was not that institutions should be bypassed, but that they must be given hands.

The United States government has now reached the same conclusion in writing. It chose a specific set of hands, under a specific set of controls, for a specific class of adversary. Reasonable people will disagree about whether the controls are sufficient. The premise underneath is no longer contested.

Where we stand

Our position has not changed because of this document, and it should not be read as an endorsement of every mechanism in it.

We do not conduct offensive operations. We do not access systems we are not authorized to access. Every action we take runs through channels the law itself provides, is documented so third parties can examine it, and remains reversible. Every action with permanent consequences passes through a human decision. Those are architectural commitments, not marketing positions, and a change in American policy does not alter them.

What the memorandum changes is the surrounding argument. For years, the proposition that private capability belongs in the enforcement of digital law was treated as fringe. It is now federal policy. The question has moved from whether to under what constraints, and that is a far better question.

The two dates that matter

Deadline What is due
October 11, 2026 Operating procedures and eligibility criteria for the program
February 8, 2027 First annual report on the program’’s status

The October document is the one to read. Section 3(a)(ii) requires eligibility criteria that permit participation by “smaller, more agile companies, which may be better suited for specialized or discrete tasks.” Whether that language survives contact with the vetting requirements will tell us how serious the opening actually is.

The full text of the memorandum is published by the White House.

Frequently asked questions

No. It authorizes a narrow program in which vetted companies conduct operations exclusively under federal direction, with written approval required for each operation. Independent retaliatory action remains prohibited.

No. It is a presidential memorandum, not legislation. Section 2(b) states the program operates in accordance with 18 U.S.C. 1030. It provides no immunity and creates no enforceable rights.

Only foreign Cyber-Enabled Transnational Criminal Organizations, defined as foreign groups conducting cyber-enabled crime against the U.S. government, U.S. persons or U.S. interests, and not institutionally part of or wholly directed by a foreign government.

Operating procedures and eligibility criteria are due by October 11, 2026, sixty days from signature. The first annual status report is due by February 8, 2027.

More insights

All articles