Product1 distinct publisher3 min readUpdated
A presidential memorandum drops the court-approval requirement for private offensive cyber operations. The procedures that would define legal exposure are not due for two months.
The Product Desk · Product desk
Compiled by The Product DeskSomething wrong?How this is made
The White House issued a presidential memorandum last week allowing vetted private companies to initiate cyberattacks against hacker groups, reversing prior policy that prohibited companies from doing so without a court's approval [1][2]. On liability, according to Fast Company's reading of the document, the memo says nothing, and the procedures meant to resolve the open questions are due in 60 days [3][4].
The stated rationale is capacity. "American businesses' innovative capabilities have historically been underutilized in efforts to identify and disrupt criminal networks operating in cyberspace," the memorandum reads, adding that it is US policy "to use all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime" [5]. Over the next two months the government will fill in requirements companies must meet [6], which is the same window as the 60-day procedures deadline [19].
That window is the problem for anyone deciding whether to volunteer. The memo offers little if any legal shield, and questions such as what happens if an employee is arrested by a foreign government in connection with an authorized attack are unlikely to be addressed [3][7]. "Sending someone into this environment with ambiguous government backing and figuring out their status after they are arrested would be irresponsible," said Eric O'Neill, a cybersecurity expert and former FBI operative, who added that "U.S. authorization does not magically erase another country's laws" [8]. Jud Dressler, who heads the Risk Operations Center at cyber risk firm Resilience, told Fast Company the memo grants private firms no special rights and that "there is no explicit legal entitlement to government assistance," with arrest risk, extradition requests and becoming a target to be treated as real operational risk [9][10].
There is also confusion about who holds the keyboard. "One section has federal personnel conducting the operations, another has the companies doing it, and the procedures that should resolve it are due in 60 days," said Rob T. Lee, chief AI officer at the SANS Institute. "Until then, nobody can price the personal risk" [11].
Durable protection would have to come from Congress. The memo arrived days after a cyber letters of marque bill was proposed in both chambers, introduced by Republicans Mike Lee in the Senate and Tim Burchett in the House, which would let the president commission private hackers [12]. Until something passes, civil and criminal protections for participating companies are theoretical [13].
The case for private operators is visibility: it is private-sector infrastructure that international attackers hit and use, and firms including Google, Microsoft and Cloudflare see attacks before federal agencies do [14]. In February, Google disrupted a global cyber espionage campaign known as Gridtide by revoking API access [15]. "No government on earth can revoke a Google Sheets API key," Lee said [16]. Dressler notes the government cannot monitor private networks without specific legal authority [17].
Speed is the weaker part of the pitch. The memo requires two Executive Directors, one at Justice and one at Homeland Security, to give written approval on every operations package before a company acts, inside an interagency deconfliction loop [18], which means at least two sign-offs per package [20]. "That is not faster than an interagency process," Lee said. "It is one, with a contractor attached" [18].
What to watch over the next 60 days: whether the procedures assign operations to federal personnel or company employees, whether they include any indemnification or consular commitment for staff detained abroad, and whether the letters of marque bill advances far enough to convert theoretical protection into statute [11][13].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
On the point of liability the memo says nothing, and it does not offer much, if any, legal shield, though experts argue it should.
Procedures that should resolve unresolved questions in the memo are due in 60 days.
Over the next two months, the government will fill in some of the blanks about the requirements companies will have to meet.
Eric O'Neill, a cybersecurity expert, former FBI operative and author of Spies, Lies, and Cybercrime, said: "Sending someone into this environment with ambiguous government backing and figuring out their status after they are arrested would be irresponsible. But U.S. authorization does not magically erase another country's laws. A foreign government may consider an intrusion into infrastructure within its borders a crime regardless of what Washington authorized."
Jud Dressler, head of the Risk Operations Center at cyber risk company Resilience, agrees the memo grants private-sector firms no special rights, and says companies taking part could put their employees at risk.
Dressler told Fast Company: "There is no explicit legal entitlement to government assistance. Participating firms must treat personnel exposure - arrest risk, extradition requests from jurisdictions friendly to the targets, and increased risk of being targeted - as a real operational risk."
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Primary document quoted, one publisher
The core facts rest on direct quotation of the memorandum's policy language plus three named, identified experts (a former FBI operative, the head of Resilience's Risk Operations Center, and SANS's chief AI officer), which is solid attribution. But the cluster has a single publisher, no link to or full text of the memo, no government comment, and the operative details - who conducts operations, what liability attaches - are explicitly described as unresolved until the pending procedures publish.
Policy issued, no participants disclosed
Adoption evidence is limited to the memorandum's issuance and one pre-existing private-sector disruption (Google revoking API access against Gridtide in February) that predates and does not depend on the memo. No vetted firm, contract, operations package, or completed authorized operation is disclosed, and the requirements companies must meet are still 60 days out.
Promise of private-sector speed outruns the documented process
The policy's stated premise - unleashing private-sector innovative capability against cybercrime - is modestly overstated relative to what the source establishes: every operations package needs two written Executive Director approvals inside an interagency deconfliction loop, no liability protection is granted, and no participating firm exists yet. The gap is positive but small because this coverage itself surfaces the counterweights rather than amplifying the promise.
Vendor, institute and author voices around a policy that creates their market
The reporting leans on interested parties: a cyber risk company executive whose firm sells risk assessment and who calls the memo 'a great start' while urging other measures, a commercial training institute's chief AI officer, and a cybersecurity author promoting a book named in his attribution. The memorandum's own language is an administration policy statement with an obvious interest in framing private-sector involvement favorably, and the parallel letters of marque bill carries sponsor incentives. Nothing suggests these interests are hidden - all speakers are named with affiliations - which limits the score.
Well-sourced but uncorroborated and provisional
Confidence is mid-range: the facts are attributed and quoted from the primary document, but a single publisher carries the entire cluster, no official response is included, and the substantive questions the story turns on - operator identity and liability - are by the memo's own design unresolved for another two months.
invest
Washington licenses private hacking, and hands the contractor the liability1 distinct publisher
product
Washington's secret AI test is coming for open weights, and release dates go with it2 distinct publishers
invest
Washington deputises private cyber firms, and hands their customers a liability question1 distinct publisher
build
Grok 4.6 lands in Copilot two days after launch, and the model picker becomes a procurement problem1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 18, 2026