Author: Orin S. Kerr Format: Law review essay (Columbia Law Review)
A 2022 law-review essay by Orin S. Kerr arguing that authorization to access a computer under laws such as the Computer Fraud and Abuse Act (CFAA) is contingent on trespass norms — shared social understandings of what kind of access invades another person's private space. The essay supplies a doctrinal framework now applied to AI agent and platform-liability questions, including the dispute in Amazon v. Perplexity AI.
Summary of argument
Kerr argues that courts have struggled to interpret the CFAA's "without authorization" language because they lack a doctrinal theory for distinguishing authorized from unauthorized access. His framework holds that authorization tracks norms, not contracts: a user who violates a website's terms of service does not necessarily commit computer trespass, because the norm against trespass operates differently from the norm against contractual breach. On this account, whether access invades a private space is determined by shared social understandings of trespass rather than by the terms a service provider has written.
Application to AI agent and platform-liability questions
The essay's framework is treated as the doctrinal anchor for several agent-platform conflicts.
In Amazon v. Perplexity AI, the N.D. Cal. preliminary injunction of March 9, 2026 blocking Perplexity's Comet shopping agent from accessing Amazon turns on CFAA-style theories. The central question is whether agentic-AI access to Amazon violates trespass norms or merely violates Amazon's terms of service — the distinction Kerr's framework draws.
The framework bears on AI Agentic Browsers, which raise CFAA questions on every page they visit; Kerr's norms determine which kinds of agent access count as trespass. It also relates to IH-Challenge: A Training Dataset to Improve Instruction Hierarchy on Frontier LLMs (OpenAI, March 2026): instruction-hierarchy compliance ensures models follow trust hierarchies, but which hierarchies count for CFAA purposes is, on Kerr's account, a question of trespass norms rather than of model behavior alone.
The essay is paired with the companion doctrinal primer An Introduction to Section 230 — Eric Goldman (Section 230 Primer, 2022). Section 230 and the CFAA together form the regulatory floor for online services; Kerr addresses the access side and Goldman addresses the liability side. As agentic-AI deployments multiply — Comet, Operator, Agentforce, and others — the essay is applied across the wiki's coverage of agent-platform conflicts, and Orin S. Kerr (planned) anchors Kerr as the academic voice on CFAA doctrine.
Relationships
- supports: Amazon v. Perplexity AI (doctrinal anchor), AI Agentic Browsers, Agentic AI
- related: An Introduction to Section 230 — Eric Goldman (Section 230 Primer, 2022) (companion doctrinal primer), IH-Challenge: A Training Dataset to Improve Instruction Hierarchy on Frontier LLMs (OpenAI, March 2026), Orin S. Kerr (planned)
- instance-of: AI Safety Cases and Frameworks (legal-doctrinal anchor)