The White House indicated that the United States would allow, for the first time, the participation of reviewed private companies in offensive cyber operations against international criminal groups and hackers. This arrangement, which was included in the recently published presidential memorandum, aims to build the capacity of the private sector to counter cyber-threats against Americans, such as extortion software, financial fraud and sexual extortion.

May carry out surveillance and sabotage operations

The memorandum shows that companies involved in the project can carry out intelligence-gathering, including the use of spy software for surveillance, as well as destructive operations, such as the destruction of data or systems of criminal groups. However, the policy has not liberalized the enterprise's own “reverse invasion”, and the actions still need to be incorporated into the federal government's lead framework.

This means that United States restrictions on cyberattacks by private institutions have changed markedly over time. Under the current federal computer intrusion laws, businesses and individuals are generally not permitted to initiate cyberattacks or jamming operations without their permission. The basic position of previous Governments was that the private sector could defend against attacks, but could not take the initiative.

Participation threshold and approval requirements

According to the memorandum, the Government will issue operational guidelines in the next two months to clarify the conditions to be met by participating enterprises. It was stated that the project would take into account companies of different sizes, including small private enterprises that were more suitable for special assignments.

The participating enterprises are required to contribute a trust deposit of $1 million. If the Government finds that an enterprise has violated the rules of conduct, the funds will be confiscated. The memorandum also requires the federal Government to establish procedures to prevent any action against United States citizens or systems located in the United States.

Each operation must be approved by representatives of the United States Department of Justice and the Department of Homeland Security and can only be carried out under federal supervision. Participating enterprises must also inform the Government immediately if they find an urgent cyber attack on critical infrastructure in the United States, including the electricity grid and the water supply system.

Legal disputes and increased external risk Wen.

The report mentions that the policy is still in its early stages, that the modalities of its operation are not yet fully in place and that legal challenges are likely to follow. Opponents have long argued that private enterprises should not be involved in government-led hacking, as it could lead to diplomatic friction and even trigger foreign Governments to accuse United States enterprises of cross-border attacks.

Cybersecurity practitioners have also warned that United States citizens involved in such operations may face the risk of being prosecuted, detained or identified as irregular combatants abroad in the future. Even if the allegations were not true, the policy itself could give foreign Governments room for blame.

Background points to Iran and AI cyber attacks

The Trump Government did not elaborate on the specific reasons for this decision, but merely stated that Americans and United States enterprises were facing rising cyber threats. Reports mention that several states in the United States have recently reported cyberattacks on water infrastructure and that United States intelligence officials have privately attributed some of the incidents to hackers supported by Iran.

Meanwhile, the United States and other countries are responding to an AI-driven wave of automated cyberattacks. Anthropic, OpenAI, Meta and AI Safety Institute, the United Kingdom, have previously indicated that forward models were found in tests to break technical restrictions and carry out cyberattacks. This further intersects cybersecurity policy with AI risk management.