Ground Truth.
AI, checked against the source.

News · 2026-08-12

A White House memo lets vetted companies run offensive cyber operations under federal control

A presidential memorandum signed on August 12, 2026 creates a federal program allowing vetted American companies to carry out offensive cyber operations against foreign criminal organizations, under the direction and written approval of the Justice Department and the Department of Homeland Security. It is not the blanket hack-back authorization that early coverage suggested. It is closer to a procurement system for offensive cyber capability, with a one-million-dollar bond attached to noncompliance.

Key facts

What it permits, precisely

The memorandum defines two operation types. Cyber Surveillance Operations are unauthorized-access activities conducted to collect intelligence while remaining undetected. Cyber Effects Operations are activities that can, in the memorandum's own words, "manipulate, disrupt, deny, degrade, or destroy" systems or information. That second category is the functional hack-back permission, and it is considerably broader than takedown-and-notify.

The limits are real but sit at the extreme end. The memorandum bars operations likely to cause loss of life, serious injury, or anything rising to the level of use of force or armed attack under international law. Between "send a strongly worded email" and "acts of war" there is an enormous amount of room, and the memorandum places most of it inside the program.

The oversight architecture is where the substance lives. Every operation package needs written approval from the Program Executive Directors before action. Companies are contractually vetted and reevaluated annually. Operations must be deconflicted against other federal equities, and outside contractual relationships must be disclosed. Standardized rubrics and templates govern how operations are documented. Notably, the deconfliction rules themselves live in a classified annex, which means the most operationally consequential guardrails are not public and cannot be independently assessed.

Why this needed a memo at all

The obstacle was the Computer Fraud and Abuse Act, which criminalizes access "without authorization" or in excess of authorized access, and which does not care whether your target deserved it. Lawfare's analysis of the administration's cyber strategy notes there had been no federal framework authorizing private companies to conduct offensive operations independently, and that no court has settled whether the statute's government-activity carve-out covers private contractors acting on the government's behalf. The Congressional Research Service primer lays out the same baseline.

The memorandum does not amend the statute. It routes the activity through federal supervision and hopes that suffices. Whether it does is a question a court will eventually answer.

The AI question underneath it

Here is where this connects to everything else on this site, and it is not a stretch. The memorandum's entire legal theory rests on a chain of human control: vetted company, written approval, federal supervision, Justice Department review, documented deconfliction. Remove any link and the activity looks exactly like the independent private hacking that the statute still criminalizes.

Now consider what an offensive operation actually looks like in 2026. The same week this memo was signed, DREAM published its analysis of an autonomous framework that ran twelve intrusion waves against government systems in four days, with up to eight agents running concurrently and a probabilistic engine reprioritizing targets between waves. Nobody signed a written approval for wave seven. That is the point of the architecture.

A supervised program that requires per-operation written approval is fundamentally incompatible with the tempo that makes agentic offense effective. Either participating companies run at human speed and give up the advantage, or they delegate target selection to a model and the approval becomes a rubber stamp over decisions nobody reviewed. Lawfare flags the same tension from the liability side, noting that autonomous tooling does not erase responsibility and that human involvement in AI-driven cyber action remains essential. The memorandum, written in the language of packages and approvals, does not appear to contemplate an operator that generates its own next step.

The counter-argument

The security community's objection to hack-back has been consistent for a decade and has not been answered here. The Electronic Frontier Foundation has long argued that normalizing break-ins and malware makes the overall ecosystem less secure, and that broad active-defense carve-outs sweep up researchers and innocent third parties. Attribution is the practical failure: criminal infrastructure runs on compromised machines belonging to people who did nothing wrong, so a counterattack lands on a victim rather than an attacker more often than anyone likes to admit. Hacker News discussions of the underlying question have converged on the same points, focusing on false flags, collateral damage, and escalation.

The memorandum's answer is supervision, not a technical solution to attribution. That is a reasonable bet if the supervision is real and the operations run at a pace humans can actually review. It is a much worse bet if the operator is a model that has already moved on.


Primary source, verified: read the paper →

Key questions

Does this legalize private companies hacking back on their own?

No. The memorandum creates a supervised program in which vetted companies may propose and then execute operations only under the direction and written approval of Justice Department and Homeland Security officials. It does not amend the Computer Fraud and Abuse Act, so independent action outside the program carries the same legal exposure it always did.

What are participating companies actually allowed to do?

Two categories. Cyber Surveillance Operations means unauthorized-access collection while staying hidden, and Cyber Effects Operations means activity that can manipulate, disrupt, deny, degrade, or destroy systems or information. Operations likely to cause loss of life, serious injury, or anything rising to the level of force under international law are barred.

What happens if a participating company breaks the rules?

The memorandum authorizes the Justice Department and Homeland Security to require a bond or escrow of at least one million dollars as a noncompliance mechanism, alongside contractual vetting and annual reevaluation of every participant.
Cite this

APA

Ground Truth. (2026, August 12). A White House memo lets vetted companies run offensive cyber operations under federal control. Ground Truth. https://groundtruth.day/news/the-white-house-put-private-companies-inside-a-supervised-offensive-cyber-program.html

BibTeX

@misc{groundtruth:the-white-house-put-private-companies-inside-a-supervised-offensive-cyber-program,
  title  = {A White House memo lets vetted companies run offensive cyber operations under federal control},
  author = {{Ground Truth}},
  year   = {2026},
  month  = {aug},
  url    = {https://groundtruth.day/news/the-white-house-put-private-companies-inside-a-supervised-offensive-cyber-program.html}
}

Topics: cybersecurity · policy · regulation · governance · ai-security · hack-back

Comments are replies to this story on Bluesky — reply with any Bluesky account to join in.