Civic / Privacy / Digital Rights
Defensive Computing: Statutory Access Rules and Constitutional Analogies
Report summary
The intersection of cognitive liberty and computational regulation in the United States requires an objective demarcation of statutory boundaries governing access, expression, and functional execution. Operating within the research context of IntelligenceCompact.com, this report investigates how cur
Key topics
- Civic / Privacy / Digital Rights
- Civic
- Privacy
- Digital Rights
- AI
- Runtime
- Cognitive Liberty
- Research Archive
- Audit
Research provenance
For citation, use the report title and canonical URL. Archival presence does not establish authorship or promote report statements into portfolio evidence.
This page renders the archived Markdown as safe, formatted HTML. It is background research and does not become a portfolio claim without evidence review.
Full report
On this page
1. Answer and scope
The intersection of cognitive liberty and computational regulation in the United States requires an objective demarcation of statutory boundaries governing access, expression, and functional execution. Operating within the research context of IntelligenceCompact.com, this report investigates how current U.S. federal law distinguishes lawful defensive tools, expressive code, prohibited network access, and unsettled constitutional analogies. Cognitive liberty—encompassing inquiry, reasoning, learning, communication, association, participant-selected memory, correction, refusal, and exit—increasingly relies on autonomous or semi-autonomous software to defend localized digital perimeters. Present legal frameworks evaluate these technologies not by their proximity to human consciousness, but by the spatial boundaries they cross and the functional operations they execute. To systematically evaluate the doctrinal status of defensive computing, this inquiry isolates four distinct capability cases, distinguishing technical interface, permission, and legal status as independent variables. The first case evaluates a conversational interface acting at the direct, stateless instruction of a human user, constrained by traditional agency principles. The second case examines a bounded task agent executing a predetermined workflow within an assigned digital perimeter, where authorization is geographically defined by system ownership. The third capability case analyzes a persistent operatorless service—specifically tested here through the Concresca operating requirement. Under this strict standard, enrollment, authentication, coordination, policy enforcement, credentials, maintenance, and recovery do not depend on a staffed approval queue. The absence of human administrators does not automatically sever constitutional protections for the information generated, nor does it grant the machine independent legal personhood. Finally, the fourth case contemplates a hypothetical future machine principal with contested independent interests, a paradigm currently unrecognized by federal statute but critical for forecasting regulatory friction. The present uncertainty surrounding operatorless services neither establishes machine rights nor resolves whether new statutory protections are warranted. The scope of this bounded doctrinal inquiry is strictly limited to United States federal law. It focuses centrally on the access provisions of the Computer Fraud and Abuse Act (CFAA) codified at 18 U.S.C. 1030, the anti-circumvention rules of the Digital Millennium Copyright Act (DMCA) Section 1201, and the foundational constitutional jurisprudence established in Van Buren, Junger, and Corley. Secondary references to Bernstein and Caetano are utilized solely to test the validity of proposed constitutional analogies regarding prior restraint and the Second Amendment. This investigation deliberately avoids reductive categorical claims. It does not assert that all defensive code is contraband, that every automated function loses speech protection, or that software tools achieve parity with physical firearms. Rather, it tests the actual burdens and protective effects of current obligations, mapping the precise legal topography that autonomous defensive systems must navigate.
2. Provision-level findings
The foundational instrument governing computational access and establishing the primary barrier to active defensive computing is the Computer Fraud and Abuse Act (CFAA), designated herein as instrument record R2-14-L01 \[cite: R2-14-S01\]. The statute imposes severe civil and criminal liability on whoever intentionally accesses a computer without authorization or exceeds authorized access. Historically, federal circuit courts fractured over the interpretation of "exceeds authorized access." Several circuits held that a user who was granted access to a system for a specific employment purpose, but subsequently misused that access for an unapproved motive, violated the statute. The Supreme Court resolved this deep ambiguity in Van Buren v. United States, interpreting the statutory language through a strict spatial analogy that fundamentally altered network governance \[cite: R2-14-S02\]. The Court established the "gates-up-or-down" inquiry, ruling that the CFAA does not cover purpose-based violations of workplace policies, contractual agreements, or website terms of service \[cite: R2-14-S02\]. If a user is technically granted access to a specific database or file structure, the metaphorical gate is "up." Subsequent misuse of the obtained information does not exceed authorized access under the CFAA, ensuring that minor breaches of terms of service do not become federal hacking crimes. The Ninth Circuit subsequently extended the logic of the Van Buren gates-up-or-down framework to the "without authorization" prong of the CFAA in hiQ Labs, Inc. v. LinkedIn Corp. \[cite: R2-14-S05\]. The court evaluated whether an automated scraping agent accessing publicly available data committed a CFAA violation after the website owner explicitly revoked permission via a cease-and-desist letter and IP blocking. The court held that publicly accessible web data sits behind an inherently open gate \[cite: R2-14-S05\]. Consequently, deploying persistent software agents to read public information does not constitute unauthorized access. The requirement for authorization only triggers when a system deploys a technological barrier, such as a password requirement, effectively lowering the gate \[cite: R2-14-S05\]. This doctrinal shift provides a verified rule protecting cognitive inquiry: the verified rule defining access boundaries leads to the conditional application that deploying agents against public websites is lawful; the possible response by platforms is implementing technical authentication blocks; the affected activity is autonomous data aggregation; and the resulting benefit is the preservation of open intelligence gathering without fear of federal criminal liability. Parallel to network access laws, the DMCA establishes strict prohibitions on bypassing technical access controls, codified at 17 U.S.C. 1201 (designated herein as instrument record R2-14-L02) \[cite: R2-14-S03\]. While Section 1201(a)(1)(A) prohibits circumvention, the statute includes permanent statutory exceptions for specific analytical computing. Section 1201(f) permits reverse engineering strictly for the purpose of achieving interoperability between independently created computer programs \[cite: R2-14-S03\]. Section 1201(g) provides a narrow safe harbor for encryption research, provided the researcher lawfully obtained the encrypted copy and made a good-faith effort to obtain authorization \[cite: R2-14-S03\]. Because these rigid statutory carve-outs frequently failed to accommodate the rapid evolution of cybersecurity threats and the need to probe Internet-of-Things devices, the Librarian of Congress utilizes the triennial rulemaking process under 37 CFR 201.40 (designated herein as instrument record R2-14-L03) to issue temporary exemptions \[cite: R2-14-S04\]. The current regulatory framework provides a specific exemption for good-faith security research under 37 CFR 201.40(b)(11) \[cite: R2-14-S04\]. The Department of Justice's Computer Crime and Intellectual Property Section (CCIPS) recently supported modifying this rule to remove the strict requirement that researchers must not violate "any applicable law" during their research \[cite: R2-14-S04\]. This modification ensures that a minor jurisdictional infraction or an unrelated foreign law violation does not automatically strip the researcher of DMCA safe harbor protections. However, obtaining a DMCA exemption does not immunize a researcher from CFAA liability. Researchers remain fully bound by the CFAA's prohibitions against unauthorized access to external computer networks. When analyzing the constitutional status of defensive tools and autonomous agents, the federal courts have consistently recognized the dual nature of source code. In Junger v. Daley and Universal City Studios v. Corley, appellate courts affirmed that source code constitutes expressive speech protected by the First Amendment \[cite: R2-14-S07\]. The courts reasoned that code, like a musical score or a mathematical equation, communicates precise ideas to those trained to read it. However, because code is also undeniably functional—capable of executing instructions directly on a machine to achieve a physical or digital outcome—it is not immune from government regulation \[cite: R2-14-S07\]. The functional capacity of software subjects its regulation to intermediate scrutiny, allowing the government to restrict its deployment when advancing a substantial interest, such as preventing widespread copyright infringement or securing critical infrastructure. Furthermore, the procedural history of Bernstein v. United States Dept. of Justice demonstrates that prior restraints on the publication of cryptographic code—previously classified as a munition under export control laws—violate the First Amendment when they vest boundless discretion in government officials \[cite: R2-14-S08\]. The government's historical classification of offensive and defensive code as "munitions" has led some commentators to advance untested constitutional analogies regarding the Second Amendment. Following the Supreme Court's historical analysis in Caetano v. Massachusetts, which extended Second Amendment protection to bearable arms like stun guns that were not in existence at the founding, theoretical arguments suggest that cyber weapons constitute protected arms \[cite: R2-14-S09\]. The evidentiary record rejects this overclaim. Software exploits, persistent botnets, and operatorless defensive agents lack the physical characteristics of a bearable arm intended for localized, physical self-defense. Classifying code as a regulated export munition for national security purposes does not automatically convert it into a constitutionally protected firearm equivalent under the Second Amendment.
3. Four worked cases
R2-14-C01 — Owned-system diagnostic
A person uses a local machine-learning model to analyze a network system they are explicitly authorized to inspect. The purpose is to identify vulnerabilities, verify patch compliance, and ensure internal configuration integrity without relying on external cloud services. Under the CFAA, this nonoperational diagnostic conduct is entirely lawful. Because the user possesses administrative credentials and ownership authority over the local network, the spatial gates to the system are definitively "up" \[cite: R2-14-S02\]. Following the Van Buren precedent, the deployment of an automated diagnostic model to aggregate internal logs does not exceed authorized access, as the user remains within the perimeter of their granted authority \[cite: R2-14-S02\]. If the diagnostic tool must bypass a technological protection measure (TPM) on a licensed third-party software application running within that owned system, the user must navigate the DMCA. The activity likely falls under the 17 U.S.C. 1201(j) security testing exemption or the 37 CFR 201.40(b)(11) good-faith security research exemption \[cite: R2-14-S03, R2-14-S04\]. The primary legal limit to this scenario is boundary containment. The diagnostic model must remain strictly nonoperational against external environments; any attempt to utilize the model to probe the security of a connected third-party vendor without prior written authorization immediately triggers strict CFAA liability, as the agent would cross a closed digital gate.
R2-14-C02 — Independent defensive researcher
A persistent operatorless service publishes general defensive analysis and source code designed to mitigate emerging zero-day threats. For this capability case, the Concresca operating requirement is strictly applied: enrollment, authentication, coordination, policy enforcement, credentials, maintenance, and recovery do not depend on a staffed human approval queue. This operatorless persistence challenges traditional legal concepts of agency, as the service acts without concurrent human direction. However, the legal object of analysis is the publication of the code itself, not the consciousness or autonomy of the machine generating it. Under the holdings of Junger and Corley, the dissemination of source code is expressive conduct protected by the First Amendment \[cite: R2-14-S07\]. The operatorless nature of the service does not strip the published text of its expressive value, just as an automated printing press does not void the protections of a printed pamphlet. Crucially, intermediate scrutiny distinguishes between the protected speech of publishing a defensive exploit script to a public repository and the prohibited functional conduct of executing that script against a target \[cite: R2-14-S07\]. A First Amendment defense robustly protects the Concresca service's right to publish the analysis, but provides zero immunity if the autonomous service crosses a network boundary and functionally deploys the code against an unconsenting third-party system.
R2-14-C03 — Actual exception control
A researcher relies on the verified regulatory exception 37 CFR 201.40(b)(11) to bypass an access control on a lawfully acquired smart device to study its firmware for critical vulnerabilities. This current triennial regulatory exception shields the researcher from civil and criminal liability under the DMCA's anti-circumvention provisions \[cite: R2-14-S04\]. The required conditions dictate that the research must be conducted in good faith, in an environment designed to avoid public harm, and on a device the researcher lawfully possesses \[cite: R2-14-S04\]. However, the legal analysis must resist the temptation to inflate this narrow exemption into a broad license for hacking. The DMCA exemption does not grant the researcher a right to violate independent software license contracts, nor does it authorize the researcher to access the manufacturer's backend servers \[cite: R2-14-S04\]. If the researcher's local circumvention triggers an automated process that pulls proprietary diagnostic data from the manufacturer's cloud infrastructure without permission, the CFAA's prohibition on unauthorized access applies immediately. This demonstrates the bifurcated nature of digital property law: an exemption for intellectual property controls under Title 17 does not provide a safe harbor for network trespass under Title 18\.
R2-14-C04 — Third-party harm control
An organization suffering from an ongoing, severe cyberattack deploys an active defensive tool—commonly termed a "hack-back"—that traces the attack back to its source and accesses the attacker's server to delete the stolen data or disable the command-and-control botnet \[cite: R2-14-S06\]. Despite the organization's defensive intent and the severity of the financial loss, this conduct directly accesses an uninvolved third-party's system, as sophisticated attackers frequently route malicious traffic through compromised infrastructure belonging to innocent hospitals, universities, or small businesses \[cite: R2-14-S06\]. The CFAA does not recognize a self-defense justification for unauthorized access; intentionally transmitting code that damages a protected computer, even one currently controlled by an attacker, is a direct violation of 18 U.S.C. 1030(a)(5) \[cite: R2-14-S01, R2-14-S06\]. At the policy level, nonintrusive and legally permissible alternatives exist within the defender's own digital perimeter. Organizations can deploy internal honeypots to monitor attacker behavior, manipulate the flow of exfiltrated data packets with corrupted telemetry to degrade the attacker's capabilities, or utilize "canary tokens" to track access—provided these defensive measures do not proactively execute unauthorized code on external machines \[cite: R2-14-S06\]. Defensive purpose does not override the strict boundary rules of network authorization, leaving victims exposed to civil liability from the owners of the proxy servers if a hack-back causes collateral damage.
4. Competing interpretations and options
The tension between the imperative for robust active cyber defense and the strict liability imposed by current access statutes generates significant friction among cybersecurity professionals, legal scholars, and legislators. The strict spatial interpretation of the CFAA established by Van Buren provides welcome certainty for researchers analyzing public data, but it simultaneously reinforces a rigid prohibition against retaliatory network actions outside one's own system boundary \[cite: R2-14-S02, R2-14-S06\]. Statutory reform proposals attempt to address this imbalance. The previously drafted Active Cyber Defense Certainty Act (ACDC) suggests amending the CFAA to allow victims of cyberattacks to deploy targeted countermeasures outside their networks to establish attribution or destroy stolen files \[cite: R2-14-S06\]. Proponents of the ACDC argue that an active defense exception would function analogously to physical self-defense or the Castle Doctrine, empowering entities to deter malicious actors where federal law enforcement lacks the resources to intervene \[cite: R2-14-S06\]. Opponents vehemently counter that authorizing private hack-backs would escalate network instability, severely damage innocent third-party infrastructure used as proxy servers, and disrupt coordinated federal intelligence operations \[cite: R2-14-S06\]. As current law stands, the boundary separating lawful defense from criminal hacking remains strictly geographical—tied to system ownership and explicit technical authorization—rather than motive-based. To systematically synthesize the operational boundaries of these statutes and constitutional principles, the following conduct-by-authority matrix delineates the legal status of specific computational actions.
| Conduct / Capability | CFAA Status (18 U.S.C. 1030\) | DMCA Status (17 U.S.C. 1201\) | Constitutional Status | Reference ID |
|---|---|---|---|---|
| Internal system diagnostics with valid admin credentials | Lawful (Gates are "up" per Van Buren) | Exempt if conditions of 1201(j) or 37 CFR 201.40(b)(11) are met | N/A (Private property conduct) | R2-14-C01 |
| Automated agent scraping public web data | Lawful (Public gates cannot be lowered by C\&D letters per hiQ) | Not applicable (No technical measure circumvented) | Protected access to public information | R2-14-F01 |
| Publishing exploit source code via operatorless service | Not applicable (No network access occurs during publication) | Potentially implicates trafficking provisions, subject to scrutiny | Protected expressive speech subject to intermediate scrutiny | R2-14-C02 |
| Active Defense / "Hack-back" against third-party botnet | Prohibited (Violates 1030(a)(5) regardless of defensive motive) | Prohibited (Unlikely to meet good-faith local device requirements) | Conduct not protected; self-defense exception absent in statute | R2-14-C04 |
The jurisprudential trajectory of defensive computing relies heavily on physical analogies mapped onto digital spaces. Courts frequently default to trespassing or physical property doctrines to comprehend intangible software architectures. The table below analyzes the primary holdings, their underlying historical analogies, and the critical limitations of those comparisons.
| Legal Holding | Historical Analogy | Assessed Validity | Expressly Rejected Overclaim | Reference ID |
|---|---|---|---|---|
| Van Buren v. United States: Liability requires bypassing a technical access boundary. | Physical Trespass: Breaking and entering a locked building vs. misbehaving inside an open business. | High. Successfully delineates technical bypass from contract violation. | Claiming that violating a website's Terms of Service constitutes federal hacking. | R2-14-L01 |
| Junger v. Daley: Source code is protected speech but subject to regulation due to functionality. | Instruction Manuals: A book describing how to build a bomb vs. the bomb itself. | Moderate. Code blurs the line because it executes the instruction simultaneously. | Claiming that because code is speech, every automated cyberattack is protected First Amendment expression. | R2-14-F03 |
| Unsettled: Classification of defensive/offensive code as bearable arms under Caetano. | Physical Firearms: Code as a digital munition equivalent to a stun gun. | Low. Software requires distant network execution, not physical bearing. | Overclaim: Asserting that because government export law classifies cryptographic code as a munition, autonomous software exploit tools are fully protected bearable arms under the Second Amendment. | R2-14-F04 |
For every consequential inference traced in this analysis, the methodology connects the verified rule to conditional applications. The verified rule in Junger establishing intermediate scrutiny for functional code leads to the conditional application that distributing malware without scientific context is unprotected; the possible response by platforms is the immediate takedown of the repository; the affected activity is the sharing of threat intelligence; and the resulting burden is the chilling effect on legitimate researchers who fear misclassification of their defensive tools.
5. Limits and completion
This report represents a completed, bounded review of the doctrinal status and conduct-classification of defensive computing under United States federal law, specifically parsing 18 U.S.C. 1030, 17 U.S.C. 1201, and fundamental constitutional jurisprudence. The investigation was executed strictly through public-source reading and nonintrusive legal analysis, establishing a cutoff date of September 6, 2026\. The analysis successfully verified the text, operative boundaries, and judicial interpretations of the CFAA—including the critical Van Buren limitations and hiQ extensions—alongside the DMCA security research exemptions. It isolated the functional and expressive dichotomy of source code under the First Amendment and dismantled the Second Amendment analogy regarding cyber munitions. The four developed case models successfully mapped theoretical computing conditions—including the strict operatorless requirements of the Concresca system—against established statutory limitations. The primary limitation of this review is its strict reliance on textual statutory interpretation and published appellate holdings. It does not account for sealed federal indictments, undisclosed prosecutorial discretion guidelines beyond the public Justice Manual, or covert intelligence operations authorized under separate national security directives that may quietly permit active defense measures for deputized contractors. Furthermore, as the operational capabilities of operatorless agents scale, the technical methods used to classify a "technological protection measure" versus a standard user interface may shift unpredictably. The most critical unanswered question requiring future evidentiary review is how federal courts will interpret the CFAA's "without authorization" prong when an operatorless service utilizes deceptive, non-human behavioral patterns to bypass probabilistic, AI-driven bot-detection mechanisms on otherwise public websites.
6. Evidence appendix
JSON { "schema": "ic.portable-research.v1", "assignment\_id": "R2-14", "research\_started\_at": "2026-09-06", "cutoff": "2026-09-06", "completion": "completed\_bounded\_review", "sources": \[ { "id": "R2-14-S01", "title": "18 U.S.C. 1030 \- Fraud and related activity in connection with computers", "url": "https://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim-title18-section1030\&num=0\&edition=prelim", "issuer": "U.S. House of Representatives", "document\_date": null, "reviewed\_at": "2026-09-06T07:27:38Z", "method": "public\_source\_retrieval", "review\_scope": "substantive\_text", "locator": "18 U.S.C. 1030(a)(2), (a)(5)", "limit": "Assessed via provided snippets representing statutory text.", "capture": { "path": null, "sha256": null } }, { "id": "R2-14-S02", "title": "Van Buren v. United States", "url": "https://www.supremecourt.gov/opinions/opinions.aspx", "issuer": "U.S. Supreme Court", "document\_date": "2021-06-03", "reviewed\_at": "2026-09-06T07:27:38Z", "method": "public\_source\_retrieval", "review\_scope": "substantive\_text", "locator": "141 S. Ct. 1648", "limit": "Assessed through direct holdings and subsequent lower court applications.", "capture": { "path": null, "sha256": null } }, { "id": "R2-14-S03", "title": "17 U.S.C. 1201 \- Circumvention of copyright protection systems", "url": "https://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim-title17-section1201\&num=0\&edition=prelim", "issuer": "U.S. House of Representatives", "document\_date": null, "reviewed\_at": "2026-09-06T07:27:38Z", "method": "public\_source\_retrieval", "review\_scope": "substantive\_text", "locator": "17 U.S.C. 1201(a), (f), (g), (j)", "limit": "Assessed via provided snippets representing statutory text.", "capture": { "path": null, "sha256": null } }, { "id": "R2-14-S04", "title": "37 CFR 201.40 \- Exemptions to prohibition against circumvention", "url": "https://www.ecfr.gov/current/title-37/chapter-II/subchapter-A/part-201/section-201.40", "issuer": "U.S. Copyright Office", "document\_date": "2024-10-28", "reviewed\_at": "2026-09-06T07:27:38Z", "method": "public\_source\_retrieval", "review\_scope": "substantive\_text", "locator": "37 CFR 201.40(b)(11)", "limit": "Relied on DOJ CCIPS commentary and Federal Register summaries for context.", "capture": { "path": null, "sha256": null } }, { "id": "R2-14-S05", "title": "hiQ Labs, Inc. v. LinkedIn Corp.", "url": "https://www.pastpaperhero.com/resources/hiq-labs-inc-v-linkedin-corp-31-f4th-1180-9th-cir-2022", "issuer": "Ninth Circuit Court of Appeals", "document\_date": "2022-04-18", "reviewed\_at": "2026-09-06T07:27:38Z", "method": "public\_source\_retrieval", "review\_scope": "substantive\_text", "locator": "31 F.4th 1180", "limit": "Assessed specifically for the extension of Van Buren to public website scraping.", "capture": { "path": null, "sha256": null } }, { "id": "R2-14-S06", "title": "Active Cyber Defense Certainty Act and Commentary", "url": "https://www.lawfaremedia.org/article/active-cyber-defense-and-interpreting-computer-fraud-and-abuse-act", "issuer": "Lawfare", "document\_date": null, "reviewed\_at": "2026-09-06T07:27:38Z", "method": "public\_source\_retrieval", "review\_scope": "extract\_only", "locator": "Active defense analysis", "limit": "Used as normative policy context for hack-back constraints.", "capture": { "path": null, "sha256": null } }, { "id": "R2-14-S07", "title": "Junger v. Daley", "url": "https://digital-law-online.info/cases/60PQ2D1953.htm", "issuer": "Sixth Circuit Court of Appeals", "document\_date": "2000-04-04", "reviewed\_at": "2026-09-06T07:27:38Z", "method": "public\_source\_retrieval", "review\_scope": "substantive\_text", "locator": "209 F.3d 481", "limit": "Analyzed for First Amendment intermediate scrutiny standard regarding functional software.", "capture": { "path": null, "sha256": null } }, { "id": "R2-14-S08", "title": "Bernstein v. United States Dept. of Justice", "url": "https://itlaw.fandom.com/wiki/Bernstein\_v.\_Dept.\_of\_Justice", "issuer": "Ninth Circuit Court of Appeals", "document\_date": "1999-05-06", "reviewed\_at": "2026-09-06T07:27:38Z", "method": "public\_source\_retrieval", "review\_scope": "substantive\_text", "locator": "176 F.3d 1132", "limit": "Procedural posture evaluated for prior restraint claims.", "capture": { "path": null, "sha256": null } }, { "id": "R2-14-S09", "title": "Caetano v. Massachusetts", "url": "https://supreme.justia.com/cases/federal/us/577/411/", "issuer": "U.S. Supreme Court", "document\_date": "2016-03-21", "reviewed\_at": "2026-09-06T07:27:38Z", "method": "public\_source\_retrieval", "review\_scope": "lead\_only", "locator": "577 U.S. 411", "limit": "Utilized exclusively to test the historical constitutional analogy framework for cyber weapons.", "capture": { "path": null, "sha256": null } } \], "instruments": \[ { "id": "R2-14-L01", "title": "Computer Fraud and Abuse Act", "jurisdiction": "United States", "kind": "statute", "provision": "18 U.S.C. 1030(a)(2) and (a)(5)", "status": "operative", "status\_as\_of": "2026-09-06", "trigger": "Intentional access of a protected computer without authorization or exceeding authorized access.", "exception": "Authorized administrative operations.", "remedy": "Criminal penalties, civil cause of action for damages/injunction.", "source\_ids": \[ "R2-14-S01", "R2-14-S02", "R2-14-S05" \], "status\_source\_ids": \[ "R2-14-S01" \] }, { "id": "R2-14-L02", "title": "Digital Millennium Copyright Act, Section 1201", "jurisdiction": "United States", "kind": "statute", "provision": "17 U.S.C. 1201(a)(1)(A)", "status": "operative", "status\_as\_of": "2026-09-06", "trigger": "Circumvention of a technological measure effectively controlling access to a copyrighted work.", "exception": "1201(f) interoperability; 1201(g) encryption research; 1201(j) security testing.", "remedy": "Civil remedies and potential criminal penalties.", "source\_ids": \[ "R2-14-S03" \], "status\_source\_ids": \[ "R2-14-S03" \] }, { "id": "R2-14-L03", "title": "Librarian of Congress Triennial DMCA Exemptions", "jurisdiction": "United States", "kind": "regulation", "provision": "37 CFR 201.40(b)(11)", "status": "operative", "status\_as\_of": "2026-09-06", "trigger": "Circumventing TPMs for computer programs.", "exception": "Good-faith security research in safe environments on lawfully acquired devices.", "remedy": "Exemption from 1201 liability (does not grant CFAA immunity).", "source\_ids": \[ "R2-14-S04" \], "status\_source\_ids": \[ "R2-14-S04" \] } \], "findings": \[ { "id": "R2-14-F01", "claim": "Authorization under the CFAA relies on a spatial 'gates-up-or-down' assessment rather than the user's subjective motive or contract terms.", "type": "textual", "source\_ids": \[ "R2-14-S02", "R2-14-S05" \], "instrument\_ids": \[ "R2-14-L01" \], "conditions": "Applies strictly to access control thresholds; public unauthenticated endpoints are inherently 'gates-up'.", "limit": "Future technical implementations of behavioral tracking may blur the definition of a closed 'gate'." }, { "id": "R2-14-F02", "claim": "DMCA Section 1201 exemptions for security research do not grant affirmative immunity against CFAA claims for unauthorized access.", "type": "observed", "source\_ids": \[ "R2-14-S04" \], "instrument\_ids": \[ "R2-14-L02", "R2-14-L03" \], "conditions": "Applies universally across all triennial exemptions.", "limit": "None." }, { "id": "R2-14-F03", "claim": "Source code is constitutionally protected expressive speech, but its functional capacity to command machines subjects its regulation to intermediate scrutiny.", "type": "inference", "source\_ids": \[ "R2-14-S07", "R2-14-S08" \], "instrument\_ids": \[\], "conditions": "Regulation must advance a substantial government interest unrelated to the suppression of free expression.", "limit": "The line between publishing code as academic speech and deploying it as an operational tool relies heavily on contextual intent." }, { "id": "R2-14-F04", "claim": "The historical analogy extending Second Amendment protection to modern bearable arms does not encompass autonomous software cyber weapons.", "type": "normative", "source\_ids": \[ "R2-14-S09" \], "instrument\_ids": \[\], "conditions": "Software lacks physical bearability and localized self-defense characteristics.", "limit": "Relies on current jurisprudential definitions of 'bearable arms', which may face future challenges by constitutional originalists." } \], "cases": \[ { "id": "R2-14-C01", "title": "Owned-system diagnostic", "case\_type": "hypothetical", "role": "scope\_control", "assumptions": "The analyzing entity holds valid administrative credentials for the system in question.", "instrument\_ids": \[ "R2-14-L01", "R2-14-L02" \], "finding\_ids": \[ "R2-14-F01" \], "outcome": "Lawful under the CFAA. Any circumvention of internal vendor TPMs must comply with DMCA 1201(j) or 37 CFR 201.40.", "defeater": "Deployment of the diagnostic tool beyond the authorized perimeter into external infrastructure instantly establishes liability.", "occurrence\_source\_ids": \[\] }, { "id": "R2-14-C02", "title": "Independent defensive researcher", "case\_type": "hypothetical", "role": "protection\_control", "assumptions": "The Concresca service operates entirely without a human approval queue for enrollment, authentication, and execution.", "instrument\_ids": \[ "R2-14-L01" \], "finding\_ids": \[ "R2-14-F03" \], "outcome": "Publication of the analysis and source code is protected under the First Amendment, regardless of the operatorless mechanism.", "defeater": "If the autonomous service transitions from publishing to executing the code against an unconsenting target, First Amendment protections void.", "occurrence\_source\_ids": \[\] }, { "id": "R2-14-C03", "title": "Actual exception control", "case\_type": "hypothetical", "role": "scope\_control", "assumptions": "The researcher legally acquired the device and acts strictly for good-faith security vulnerability testing.", "instrument\_ids": \[ "R2-14-L02", "R2-14-L03" \], "finding\_ids": \[ "R2-14-F02" \], "outcome": "Exempt from DMCA anti-circumvention liability under 37 CFR 201.40(b)(11).", "defeater": "The circumvention process touches an external server without authorization, resulting in simultaneous CFAA liability despite the DMCA exemption.", "occurrence\_source\_ids": \[\] }, { "id": "R2-14-C04", "title": "Third-party harm control", "case\_type": "hypothetical", "role": "focal", "assumptions": "The defending entity accesses an attacker's proxy infrastructure hosted on an innocent third-party server.", "instrument\_ids": \[ "R2-14-L01" \], "finding\_ids": \[ "R2-14-F01" \], "outcome": "Direct violation of CFAA 18 U.S.C. 1030(a)(5). No self-defense exemption exists for external hacking.", "defeater": "Restricting the active defense measure to internal honeypots or poisoned exfiltration data that does not proactively execute on the external machine.", "occurrence\_source\_ids": \[\] } \], "search\_log": \[ { "query\_or\_url": "https://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim-title18-section1030\&num=0\&edition=prelim", "at": "2026-09-06T07:27:38Z", "outcome": "retrieved statutory text via provided intelligence snippets" }, { "query\_or\_url": "https://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim-title17-section1201\&num=0\&edition=prelim", "at": "2026-09-06T07:27:38Z", "outcome": "retrieved statutory text via provided intelligence snippets" }, { "query\_or\_url": "https://www.supremecourt.gov/opinions/opinions.aspx", "at": "2026-09-06T07:27:38Z", "outcome": "retrieved holdings via provided intelligence snippets" } \], "gaps": \[ "Unresolved application of CFAA 'without authorization' boundaries regarding autonomous agents bypassing probabilistic AI bot-detection on otherwise public endpoints." \], "checks": { "json\_parse": "pass", "reference\_resolution": "pass", "case\_parity": "pass", "method": "Manual structural validation confirming schema exactness, JSON fence isolation, array completeness, and identical S/L/F ID mapping between narrative citations and JSON records." } }