Trump’s New Project: Cyber Pirates in Cyberspace

Following the decision to bar foreigners from access to Anthropic’s latest AI models last June, the American administration has just crossed a new threshold in technological unilateralism.

On August 12, 2026, Donald Trump publicly released a memorandum titled “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime.” The document overturns the doctrine that had guided the United States, and Western countries more broadly, which had resisted the involvement of private firms in cyberattacks.

By formally authorizing companies to carry out offensive surveillance and neutralization operations against transnational criminal organizations, Washington is indeed making a major doctrinal shift: after the mercenaries of the condottiere Erik Prince, the time has come for the privateers of the network.

From the European perspective, this text goes far beyond the United States’ internal affairs. It challenges international law, destabilizes cyberspace, and deprives third countries of any influence over what happens on their networks. In the face of this paradigm shift, the Union can no longer rely on a purely normative stance.

If it wishes to avoid becoming a battlefield for digital piracy conducted by private actors acting on behalf of foreign entities, it must urgently accelerate the deployment of cloud and cyber infrastructures under its full control, equip itself with autonomous capabilities to detect and identify the origins of cyberattacks, and strengthen the regulatory framework prohibiting any unauthorized intrusion into its networks. This memorandum should be read as a warning. Without true technological autonomy, the Union will irreversibly lose its digital sovereignty.

Strengthening capabilities to combat transnational cybercrime

Presidential Memorandum, dated August 12, 2026

To the:

Mr. Vice President

Mr. Secretary of State

Mr. Secretary of the Treasury

Mr. Secretary of War

Mr. Attorney General

Mr. Secretary of Commerce

Mr. Secretary of Energy

Mr. Secretary of Homeland Security

Ms. Chief of Staff to the President

Mr. Director of National Intelligence

Mr. President’s Science and Technology Advisor

Mr. Director of the CIA

Mr. Director of the Office of Management and Budget

Mr. National Security Advisor

Mr. Deputy Assistant to the President, the Deputy Chief of Staff for Policy, and the Assistant to Homeland Security

Mr. National Cyber Director

Mr. Chairman of the Joint Chiefs of Staff

Mr. Director of the NSA

Under the powers vested in me as President by the Constitution and the laws of the United States of America, I order as follows:

Art. 1. Purpose.

Transnational criminal organizations (TCOs) pose a growing threat to American citizens, businesses, and national security. These organizations conduct sustained cyber-enabled campaigns to commit fraud that undermines the prosperity, security, and liberty of the United States. By Presidential Decree No. 14390 dated March 6, 2026 (Fighting Cybercrime, Fraud, and Abusive Practices against American Citizens), I directed the federal government to implement various measures to combat cybercrime harming American citizens. This memorandum broadens the fight against cybercrime perpetrated by TCOs by leveraging the resources of the private sector.

The American private sector is the most innovative and technologically advanced in the world, and its scale, speed, and capabilities give the United States a decisive cyber-offensive edge. Yet, the innovation capacities of American companies have historically been underutilized in efforts to identify and dismantle networks operating in cyberspace. It is therefore United States policy to use all instruments of national power, including the private sector’s innovation capabilities, to fight cybercrime. By forming partnerships with carefully selected American companies, subjected to the directives and oversight of the federal government, we will strengthen our ability to counter threats posed by transnational criminal organizations (TCOs) and to combat transnational cybercrime, fraud, and other predatory practices aimed at American citizens.

Art. 2. Establishment of the Program.

( a ) The National Coordination Center (NCC), established under Article 6(d) of Presidential Decree No. 14159 of January 20, 2025 (Protection of the American People Against Invasion), shall create, manage, and ensure the operation of a program authorizing participating companies, as defined in Article 4(f) of this memorandum, to carry out cyber-surveillance operations and cyber-effects operations against foreign transnational criminal organizations leveraging cyber technologies (CE-OCT), under the control and supervision of the federal government.

Within the framework of legal investigative, protective, or intelligence operations conducted by federal law enforcement, this program must:

( i ) be overseen by two joint executive directors, one from the Department of Justice, appointed by the Attorney General, and the other from the Department of Homeland Security, appointed by the Secretary of Homeland Security (the “program executive directors”). The program’s executive directors shall be delegated the authority to approve, after consultation, cyber operations conducted under the program by personnel from their respective departments, with the exception of operations that could entail “critical consequences” as defined in section 4(b) of this memorandum. Cyber operations shall be approved only after coordination between the program executive directors, and any resulting operational action will be conducted exclusively on behalf of and under the supervision of the federal government, in accordance with its legal powers;

(ii) require participating companies to enter into contractual agreements with the Department of Justice or the Department of Homeland Security, which will ensure that participating companies are subject to rigorous checks and that their performance adheres to the strict operational procedures described in the implementing directives referred to in section 3 of this memorandum; and

( iii ) authorize participating companies to enter into commercial agreements with:

( A ) private-sector entities, from which participating companies may receive, to offer to the NCC tailored cyber-operations, any threat information gathered in the ordinary course of those entities’ business activities; and

( B ) federal, state, local, tribal, and territorial agencies, which will identify CE-OCT threats for participating companies so that they can propose cyber operations to the NCC to counter those threats.

( b ) The NCC shall conduct all program activities in accordance with the Constitution and all other applicable laws and with the United States’ international obligations, including 18 U.S.C. § 1030, thereby ensuring that participating companies act under the control and supervision of the United States government.

Art. 3. Implementation Directives

( a ) Within 60 days of the date of this memorandum, the program’s executive directors, in coordination with the Homeland Security Council, shall jointly establish operational procedures for the program, ensuring full federal government supervision and control over the performance of participating companies. No operation may be approved unless it complies with these procedures. These procedures must:

( i ) establish the minimum standards that participating companies must meet to participate in the program; these must include appropriate levels of technical mastery, proven performance in cyberspace operations, facility security, personnel background checks, competence, reliability, and any other factors that the program’s executive directors, in coordination with the Homeland Security Council, deem relevant or necessary to ensure a high level of confidence in a participating company’s ability to carry out its missions within the program;

( ii ) ensure that the program’s eligibility criteria allow the participation of both large companies, which bring essential capabilities, and smaller, more agile firms, which may be better suited to specialized or occasional tasks;

( iii ) require participating companies to disclose to the NCC all contractual relationships entered into under section 2(a)(iii) of this memorandum;

( iv ) authorize the Department of Justice and the Department of Homeland Security to require, as a condition of their contractual agreements with participating companies under section 2(a)(ii) of this memorandum, that these companies post a bond or fiduciary deposit of at least 1 million dollars, which will be forfeited if the participating company fails to comply with its contractual agreement described in section 2(a)(ii) of this memorandum;

( v ) pursuant to the memorandum’s classified annex, define the program’s operational flow, including operational coordination among federal law enforcement, the Department of State, the Department of the Treasury, the Department of Defense, the Department of Justice, and the United States intelligence community;

( vi ) pursuant to the memorandum’s classified annex, provide a decision-making framework ensuring that operational activities target only CE-OCT and take into account other United States government interests;

( vii ) define standardized criteria and models for target identification as well as for the creation and processing of case files relating to cyber-surveillance operations and cyberspace operations;

( viii ) include reporting obligations for participating companies that will enable a better understanding of the activities and impact of foreign CE-OCTs, particularly regarding the American population and economy, and will ensure that the NCC is fully informed of the participating companies’ operational activities;

( ix ) provide procedures, including review by the Department of Justice, guaranteeing that any program activity targeting an American person or involving the United States government’s constitutional, federal, or international obligations receives all necessary authorization, judicial or otherwise, before operation approval;

( x ) provide procedures ensuring that a participating company encountering operational activity exceeding the parameters and restrictions of the cyber operation approved by the program’s executive directors — such as inadvertent targeting (1) of an American person, (2) a US-based information system, or (3) an information system under the control of an American person — immediately ceases the operation, implements minimization measures, and promptly informs the NCC, which will inform the Department of Justice;

( xi ) provide procedures requiring participating companies to immediately inform the NCC, which will inform the Department of Justice, if they detect an imminent cyberattack against critical U.S. infrastructure or have reasonable grounds to believe that an approved cyberspace operation or cyber-surveillance operation could entail critical consequences;

( xii ) specify that participating companies may still conduct other lawful cyber-defensive operations legitimately authorized to them, but that any activity authorized by the program must be conducted under the supervision, operational control, and legal authority of the United States government;

( xiii ) provide procedures for evaluating each participating company to maintain its participation in the program at least once a year; and

( xiv ) require the program’s executive directors to review each cyber operation case file and provide written approval and instructions to the participating company before any action can be undertaken.

( b ) The program’s executive directors must regularly assess and continuously improve the program’s operational procedures to ensure effective and efficient implementation of the objectives set forth in this memorandum. The NCC should also employ automation to streamline program elements whenever appropriate, in accordance with applicable law and the requirements of this memorandum.

( c ) The program’s executive directors must, within 180 days of the date of this memorandum, and annually thereafter, prepare a detailed report on the program’s progress and submit it to the Deputy Assistant to the President and Chief of Staff for Policy and to the Assistant to the President for Homeland Security, as well as to the National Cyber Director.

Art. 4. Definitions

For the purposes of this memorandum:

( a ) “Cyberspace operation” means any activity conducted within or through the interconnected network of information technology infrastructure — including the Internet, telecommunications networks, computers, information systems, industrial control systems, networks, as well as embedded processors and controllers — that results in manipulation, disruption, denial of access, degradation, or destruction of information systems, networks, physical or virtual infrastructures controlled by information systems, or information stored therein.

( b ) “Critical consequences.” An action is deemed to have critical consequences if it is likely to:

( i ) cause death or serious injury; or

( ii ) reach the level of use of force or armed attack under international law.

( c ) “Transnational cyberspace-using criminal organization (CE-OCT)” means any foreign group that commits offenses using cyberspace against the Government of the United States, a US person, or American interests, and that is not an integral part of, or fully directed by, a foreign government. For the purposes of this memorandum, a foreign group is presumed not to be part of or fully directed by a foreign government unless clear intelligence establishes such a link.

( d ) “Cyber-surveillance operation” means activities conducted within or through the interconnected network of information systems — including the Internet, telecommunications networks, computers, information systems, industrial control systems, networks, and embedded processors and controllers — for the principal purpose of collecting information or intelligence — including information that could be used for future cyber-operations — from information systems, networks, physical or virtual infrastructures controlled by information systems, or information stored there, with the intention of remaining undetected. Cyber-surveillance operations involve access to these information systems without the owner’s or operator’s authorization, or beyond the limits of authorized access. Cyber-surveillance operations include the essential and inherent actions necessary for their execution, such as manipulation or temporary disruption that is not intended to produce physical effects or to impair the operation of physical or virtual infrastructures.

( e ) The term “information system” has the same meaning as defined in 44 U.S.C. § 3502.

( f ) The term “participating companies” refers to American private-sector companies admitted to the program and authorized to conduct cyber-operations under the direction of the U.S. government.

( g ) The term “American person” has the same meaning as that defined in Presidential Decree No. 12333.

Art. 5. General Provisions

( a ) No provision of this memorandum shall be construed to diminish or otherwise affect:

( i ) the powers conferred by law on any department or executive agency, or its head; or

( ii ) the functions of the Director of the Office of Management and Budget with respect to budgetary, administrative, or legislative proposals.

( b ) This memorandum shall be implemented in accordance with applicable law and subject to the availability of budgetary resources.

( c ) This memorandum is not intended to, and does not, create any right or benefit, substantive or procedural, that may be invoked at law or in equity by any party against the United States, its departments, agencies or entities, its officials, employees, or agents, or any other person.

DONALD J. TRUMP