AI Policy Wiki
Dashboard

Norms of Computer Trespass — Orin S. Kerr (Essay, 2022)

high confidence · updated 2026-06-06

Orin Kerr's foundational law-review essay arguing that authorization to access a computer is contingent on trespass norms — shared understandings of what kind of access invades private space. The wiki's canonical doctrinal anchor for CFAA-and-AI / agent-platform liability questions including Amazon v. Perplexity.

Author: Orin S. Kerr Format: Law review essay (Columbia Law Review)

A 2022 law-review essay by Orin S. Kerr arguing that authorization to access a computer under laws such as the Computer Fraud and Abuse Act (CFAA) is contingent on trespass norms — shared social understandings of what kind of access invades another person's private space. The essay supplies a doctrinal framework now applied to AI agent and platform-liability questions, including the dispute in Amazon v. Perplexity AI.

Summary of argument

Kerr argues that courts have struggled to interpret the CFAA's "without authorization" language because they lack a doctrinal theory for distinguishing authorized from unauthorized access. His framework holds that authorization tracks norms, not contracts: a user who violates a website's terms of service does not necessarily commit computer trespass, because the norm against trespass operates differently from the norm against contractual breach. On this account, whether access invades a private space is determined by shared social understandings of trespass rather than by the terms a service provider has written.

Application to AI agent and platform-liability questions

The essay's framework is treated as the doctrinal anchor for several agent-platform conflicts.

In Amazon v. Perplexity AI, the N.D. Cal. preliminary injunction of March 9, 2026 blocking Perplexity's Comet shopping agent from accessing Amazon turns on CFAA-style theories. The central question is whether agentic-AI access to Amazon violates trespass norms or merely violates Amazon's terms of service — the distinction Kerr's framework draws.

The framework bears on AI Agentic Browsers, which raise CFAA questions on every page they visit; Kerr's norms determine which kinds of agent access count as trespass. It also relates to IH-Challenge: A Training Dataset to Improve Instruction Hierarchy on Frontier LLMs (OpenAI, March 2026): instruction-hierarchy compliance ensures models follow trust hierarchies, but which hierarchies count for CFAA purposes is, on Kerr's account, a question of trespass norms rather than of model behavior alone.

The essay is paired with the companion doctrinal primer An Introduction to Section 230 — Eric Goldman (Section 230 Primer, 2022). Section 230 and the CFAA together form the regulatory floor for online services; Kerr addresses the access side and Goldman addresses the liability side. As agentic-AI deployments multiply — Comet, Operator, Agentforce, and others — the essay is applied across the wiki's coverage of agent-platform conflicts, and Orin S. Kerr (planned) anchors Kerr as the academic voice on CFAA doctrine.

Relationships