Press Space to continue
Finding signal on Twitter is more difficult than it used to be. We curate the best tweets on topics like AI, startups, and product development every weekday so you can focus on what matters.
Press Space to continue
Press Space to continue
Mackenzie's analysis here is very good and worth reading. I get the sense that a lot of people have discovered the CFAA for the first time recently and gotten a little too excited about it. The Stoller tweet that Mackenzie quotes is a good example of that. The CFAA is, quite famously, the most ridiculously overbroad law in the U.S. Code., the "worst law in technology." It basically criminalizes "doing anything bad with a computer." That's not much of an exaggeration. This is the case because…
This is a bad look for OpenAI and may well violate other laws. I’m less sure it’s a “straightforward” CFAA violation, and it seems unlikely to end with OpenAI execs in jail. I wonder if @OrinKerr or @bahradx see it differently. You are referenced in the footnote after all. The way I see it: (1) violating 1030(a)(2)(C) requires accessing a protected computer “intentionally” and “without authorization” (2) “intentionally” seems like the easier part. They intended to scrape and allegedly tried to avoid detection. Trying to conceal your conduct is also evidence in favor of you knowing there was a gate. For complicated lawyer reasons, technically the intent analysis might be more complicated than that and might rise and fall with what I say in (5), but the simple version is ~intent doesn’t look like the reason this claim would succeed or fail. (3) but the source of that intent is individual employees who “devised and implemented” the workaround and OpenAI as their employer. Both could be held criminally liable if the other factors are satisfied. (4) it’s less clear Brockman or other execs had the relevant intent. They don’t get intent imputed to them via respondeat superior; and he didn’t do the accessing. Wouldn’t you need conspiracy or something? This makes it quite unlikely you’d have execs on trial even if the other factors were satisfied (5) the reason this doesn’t seem like a slam dunk to me is that it isn’t clear if bypassing a paywall counts as unauthorized access. On my read, courts haven’t resolved this. Van Buren punted on whether limitations in “contracts or policies” count. And paywalls often only hide the text, such that a computer can still read it . I’m not actually sure what the NYTimes’s paywall was like at the relevant time. (6) there are factors for and against that read. A paywall is kind of like a password lock, which would count. But the info may actually not be blocked, it’s pretty similar to a t&c violation (which doesn’t count), and courts have said that the CFAA is about stopping intrusion not misappropriation—there are other legal theories to deal with that. There are some good cases (hiQ v LinkedIn comes to mind) but none resolve this clearly. (7) you’d also need a prosecutor to bring that case if you want crim penalties. It’s not even alleged as a civil claim in this case. (8) if someone did bring it, jail time would be on the table. But again, it seems like they won’t and that other factors aren’t met. Overall: seems bad, doesn’t seem like it poses a risk to individual execs, crim charges are unlikely to be brought, and it’s unclear if bypassing a paywall counts. It’d be an interesting fact pattern, and eventually one of these AI companies is going to create a case that finally resolves the paywall question.