On 12 August 2026 the White House published a memorandum on cyber-enabled crime. It lets vetted private companies carry out surveillance and disruption work in cyberspace, under US government direction. The targets are criminal groups abroad. No specific country is named in the text.
The implications dramatically change what security leaders in Europe and abroad must ask. Knowing where your data sits is vital, but understanding whose authority it runs under and whose law the company behind it answers to has become even more important.
Below: what the memorandum does, what it changes for non-US hospitals, grid operators, and municipalities, and where we stand.
What the memorandum does
In plain terms: the US government is bringing private companies into offensive cyber work against criminal groups abroad. Companies apply, undergo vetting, sign contracts with the Department of Justice or the Department of Homeland Security, and propose operations. Government approves each one in writing before anything happens.
The mechanism is worth reading precisely, because the precision is where the implications sit.
The National Coordination Center creates and runs the programme. It defines two kinds of operation.
-
A Cyber Surveillance Operation means accessing information systems without the owner or operator's authorisation, or beyond authorised access, with the intent to remain undetected. Its purpose is to collect information, including information that supports later operations.
-
A Cyber Effects Operation means the manipulation, disruption, denial, degradation or destruction of information systems, the infrastructure they control, or the data held on them.
Co-Executive Directors from Justice and Homeland Security review every operations package. They give written approval before a Participating Company acts. They cannot approve anything likely to cause loss of life or serious injury, or to reach the level of a use of force under international law.
Participating Companies are private US companies. They can be required to post a bond of at least $1 million, forfeited if they breach the contract, and they face review at least once a year. Operating procedures are due within 60 days. A classified annex sits behind the published text.
The aim is legitimate, and we all stand to win if it works
The criminal groups that extort American businesses are the same groups that encrypt European hospitals, halt municipal services and hold utility billing systems to ransom. Every disruption of that infrastructure is a good outcome for organisations in Europe and the rest of the world, too. We are not going to pretend otherwise or ignore the guardrails included in the text.
Those guardrails are real. Written approval per operation, a bar on outcomes that risk life, a bond, annual re-evaluation, a stated commitment to comply with applicable law and the international obligations of the United States. This is a controlled programme, not a licence.
However, the concern is not that the policy is reckless. It is that its protections are drawn along a line, and non-US organisations sit on the far side of it.
Three things that change for non-US organisations
We will know more about the specific details when the White House announces its operating procedures in October 2026. For now, we can confidently describe three major changes global organisations of all sizes must prepare for.
1. Ordinary security telemetry becomes a lawful input
The memorandum permits Participating Companies to enter commercial agreements with other private entities, and to receive from them threat information collected in the course of those entities' normal business activities, for the purpose of proposing operations.
For a security vendor, "normal business activities" means telemetry. Logs, network metadata, detections, samples, infrastructure observations. Nothing in the text compels any vendor to enter such an agreement, and nothing suggests any has. What changed is that a route now exists, with a defined structure, a contracting party and an oversight body behind it.
Concentrated telemetry has always been valuable to whoever holds it. It is now also a marketable input into a government-directed programme. This differs from the CLOUD Act because a legal subpoena is not necessary. A US-based security vendor may simply be compelled to provide your security telemetry to the US government without your knowledge or consent.
2. The safeguards follow a jurisdictional line
The procedures the memorandum mandates are written around US persons and US systems. A company that discovers it has unintentionally targeted a US person, a system residing in the United States, or a system under the control of a US person must stop, minimise and notify. Separate review applies where an operation is directed at a US person or otherwise engages constitutional obligations.
A hospital in Denmark, a grid operator in Spain and a municipality in Poland are none of those things. The programme carries a general commitment to comply with applicable law and international obligations. It does not carry the same procedural machinery for a European system, and it states plainly that it creates no right enforceable by any party.
The practical outcome is that non-US organisations have no legal protections or recourse when inappropriately targeted by state-sanctioned cyber operations. The risk of a Stuxnet-style attack causing extensive collateral damage is real and must be taken seriously. Currently, only US persons have any legal status in responding to such an incident.
3. "Criminal infrastructure" becomes an unclear boundary
Criminal groups rent, compromise and relay through servers that belong to legitimate businesses. Many of those machines belong to organisations that have no idea they are hosting anything illegal. An operation against criminal infrastructure is an operation against specific machines, and some proportion of those machines sit in European data centres, on European networks, inside estates run by European teams.
There is genuine risk that these operations target legitimate organisations with no connection to transnational cyber crime syndicates of any kind. Without any insights into who gets targeted, for what reasons, and what the objective should be highlights enormous potential for misuse and abuse. If a cloud-connected server is compromised, remediated, and put back into service, will it suddenly find itself compromised again in retaliation for actions attributed to it?
The potential for misuse and intentional abuse add to this risk. The programme currently compels private sector cyber operators to forfeit a $1 million deposit if they neglect to follow the US government's operational rules. For many US organisations, this sum is negligible compared to the economic advantage of conducting offensive operations against non-US competitors.
Jurisdiction was never only about where the data sits
European buyers already learned one version of this lesson. The CLOUD Act and Section 702 of the Foreign Intelligence Surveillance Act established that a US-headquartered provider can be compelled to produce data regardless of the region printed on the contract. Choosing a European region does not change the legal system the provider answers to.
That debate was about disclosure: what a provider can be made to hand over. This memorandum adds a second dimension. It is about what a provider can be authorised to do, and about a lawful commercial channel running from ordinary security telemetry into operational decisions.
This is another example of cloud dependency risk. It is the exposure an organisation carries because the tools it runs answer, in the last instance, to a legal system that is not its own. Cloud dependency does not show up on a data residency map, and no amount of regional selection can protect against a national security directive.
European regulation is moving the other way. Under NIS2, accountability for the security of essential services sits with the management body of the operating organisation, not with its supplier. The proposed Cloud and AI Development Act(CADA) would push further and provide significant protection against this exact jurisdictional risk. An operator held accountable under European law cannot delegate that accountability to a platform whose operating authority sits somewhere else.
Our position
Guardsix's position on the memorandum has three parts.
-
Disrupting organised cybercrime is a legitimate aim, and European organisations benefit when that work succeeds. We say so without qualification.
-
Every European organisation should be able to answer one question about every system in its security stack: under whose authority does this operate? Not where the data is stored, not which region is on the order form. Whose law, and whose direction.
-
For a large part of the market, the honest answer is an authority the operating organisation did not vote for, cannot petition and is not protected by. That is not an accident of the technology. It is a consequence of how the platforms were built, and they could be built differently.
Where Guardsix fits
Guardsix is European by structure and its products are sovereign by design. The company is headquartered in the European Union, and the platform is designed so that the organisation running it keeps custody of what it generates.
Guardsix SIEM collects, indexes and retains logs inside the estate that produces them. Guardsix NDR reads network traffic on the same terms. The platform works without routing customer data through a provider's cloud, because that route is not part of how the product functions. Where telemetry never leaves the organisation, no third party holds a copy, and there is no means by which a foreign entity can access or use it.
Regional MSSPs, distributors and resellers operate the platform on the same terms for the organisations they serve. A managed service built on Guardsix keeps each tenant's data inside the jurisdiction that tenant chose, and keeps the provider's own operations there too. Sovereignty that only works when you buy direct is not sovereignty; it is a procurement preference.
This is the European jurisdiction pillar doing its actual job. Your data stays under your territory's law alone, because it stays where you put it.
What to do now
You do not need a position on US policy to act on this. You need three answers about every security platform you run, whoever supplies it:
- Where does telemetry physically rest, and who else holds a copy of it?
- Which legal system does the supplying entity answer to — the contracting entity, its ultimate parent, and every sub-processor in the chain?
- What does the contract say about onward sharing of your telemetry with third parties, including for threat research and intelligence purposes?
Ask them in writing. Vendors that have good answers will give them quickly, and the speed of the reply is itself informative. Where the answers are unclear, that is not a reason to panic. It is a reason to put the question on the agenda for the next renewal cycle, while the option is still open.
The same questions are being asked by security leaders across Europe. The proposed Cloud and AI Development Act would grade providers on demonstrable sovereign control and steer sensitive procurement towards the higher levels, protecting against this exact kind of risk. Our playbook on CADA readiness shows how you can establish the kind of sovereignty that prevents foreign governments from using your security data for their own operations.