403 Forbidden · which barriers the law will actually defend
The last article ended on an unpaid promise. Computer-misuse statutes reach conduct that gets around a protective measure, and a passive signal is not one. So what is? The answer is a ladder rather than a line, and three weeks ago a court climbed several rungs of it in public.
We had to answer a narrower version of this about ourselves, and the answer is not in a statute. UnGovrBot identifies itself and signs its requests under RFC 9421, with its public key where any server can fetch it. For some hosts that is the only way it is ever allowed to arrive: there is a list, in code, of sites that see the identified crawler and nothing else, and it carries a floor that holds even if the configuration behind it goes missing or unread.
The first name on that list is another transparency nonprofit, and the reason it is there has nothing to do with any of the statutes below. It is that there are places where being recognisable matters more than getting the page. Deciding which sites belong on a list like that is the same judgment this article is about, and it is the half no court will make for you.
One hinge, phrased four ways
Nearly every statute in this family turns on the same question: was there something in the way, and did you get around it? The phrasings differ, and the differences decide cases.
-
United States, the Computer Fraud and Abuse Act
Access "without authorization". The Supreme Court read that in Van Buren (2021) as a "gates-up-or-down inquiry", and hiQ v. LinkedIn (2022) applied it: where a network generally permits public access, reading that public data is not access without authorisation. The gate was never down.
-
United States, the Digital Millennium Copyright Act
Section 1201 reaches circumvention of a measure that "effectively controls access" to a copyrighted work. This is the provision doing the real work in 2026, and the one the July ruling below turns on.
-
Germany, section 202a of the criminal code
Reaches data that is besonders gesichert, specially secured against unauthorised access, obtained by circumventing that protection. Two elements, and both have to be present: a protection, and your getting past it.
-
The EU, Directive 2013/40 on attacks against information
systems
Article 3 reaches access "committed by infringing a security measure". Member states implement it in their own criminal codes, so the floor is common and the ceiling is national.
Then there is the outlier. The United Kingdom's Computer Misuse Act 1990 is not phrased on a breached measure at all. Section 1 asks whether access was unauthorised and whether the person knew it was, which on its face could reach further than any of the four above, since a crawler that has read a prohibition arguably knows. It has apparently never been applied to a crawler in a reported case. That is the state of it, and a gap in the case law is not a safe harbour: it means nobody can tell you the answer, which is a different thing from the answer being no.
The line moved on 31 July 2026
Two orders eleven months apart now bracket the question, and both are from the same court.
The first was Ziff Davis v. OpenAI, in December 2025, where the Southern District of New York dismissed a section 1201 claim built on a crawler disregarding robots.txt: such files do not effectively control access "any more than a sign requesting that visitors 'keep off the grass' effectively controls access to a lawn". That set the floor. A published request is not a technological measure.
The second is Reddit v. Perplexity. On 31 July 2026 Judge Paul A. Engelmayer, in a 63-page opinion, largely denied the motions to dismiss and let Reddit's section 1201(a) circumvention claims proceed against both Perplexity and the scraping service SerpApi. The measure at issue was Google's SearchGuard, the challenge-based system standing in front of Google Search results, which the court treated as a measure controlling access to the work. Reddit, the court held, "epitomizes the 'global digital on-line marketplace for copyrighted works' that the DMCA sought to promote", and its injuries fall within the statute's zone of interests. A section 1201(b) trafficking claim against SerpApi was dismissed, along with unfair-competition and unjust-enrichment counts against both.
Read the two together and the ladder has a marked rung. A file that asks is below it. A challenge a requester has to satisfy before the content is served is above it. Everything in between is currently unlit.
Two cautions, because this order is younger than most of the commentary about it. It resolves a motion to dismiss, so the allegations are taken as true and nothing has been proved. And the circumvented measure belonged to Google, not to the plaintiff, which is an unusual shape: the copyright owner sued over a barrier a third party had erected around its own copies. If that survives, it widens section 1201 considerably, because the person who put up the wall and the person who owns the work no longer have to be the same person.
The ladder a builder actually faces
From weakest to strongest, with what each is worth in this specific argument. None of this speaks to contract or to copyright, which are separate routes with separate answers.
-
robots.txt, and the per-purpose signals beside it
Directly addressed and rejected as a technological measure in December 2025. Still legally useful, but under copyright and contract rather than here.
-
A rate limit
Regulates pace, not entry, and serves the content to everyone eventually. No case treats slowing you down as controlling access.
-
An address block, unannounced
A real refusal, and the first rung a court might call a gate down. Untested on its own. Its litigated form always comes with a letter.
-
An address block plus a cease-and-desist letter
The strongest United States authority in the whole ladder, and it is not a technological argument. Facebook v. Power Ventures and Craigslist v. 3Taps both turned on an individually addressed letter followed by continued access. Authorisation was revoked from you, by name.
-
A bot-management challenge
The rung the July 2026 order put in play. Treated as controlling access, on the pleadings. Also where our own standing rule sits: a challenge is a stop, never a puzzle to solve.
-
A login wall, or a paywall behind one
Uncontroversial in every jurisdiction here. Credentials are the textbook case of specially secured data, and using someone else's is the textbook offence.
-
Encryption
Beyond argument, and beyond the interesting part of the question.
What this means if you operate a crawler
The practical reading is narrower than the anxious one. Fetching a page that a server hands to anyone who asks is not, on current authority in any of these jurisdictions, a computer-misuse offence merely because a file asked you not to. What changes the answer is conduct: getting past something that was refusing you, or continuing after you personally were told to stop.
That second half is the one operators underrate. It needs no technology at all. An email naming your company and telling you to stop, followed by your continuing, is the fact pattern that has actually produced United States liability, more reliably than any argument about walls. If you receive one, the engineering question is over and the legal one has begun.
And if you publish rather than crawl, the ladder reads as a menu with prices. Every rung above a signal costs you real visitors, real accessibility, and real search traffic. The reason to climb it is that the law only defends the rungs where you were genuinely refusing, and it does not much care how strongly you felt about the ones below.
Terms of use are the route that most often decides these cases while getting the least engineering attention, and they are the next article in this series. Meanwhile the Law pages carry the per-jurisdiction posture we hold today, and LexLint itself will read your app's declared profile and report which of these attach to it.
Sources and further reading
- 17 U.S.C. section 1201 The anti-circumvention provision itself, including the definition of a measure that "effectively controls access to a work".
- Van Buren v. United States, 593 U.S. 374 (2021) The Supreme Court's narrowing of "exceeds authorized access", and the source of the gates-up-or-down framing every scraping case now uses.
- hiQ Labs v. LinkedIn, 9th Cir. (2022) Public data and the Computer Fraud and Abuse Act. Note what it does not decide: LinkedIn went on to win on contract.
- German Criminal Code section 202a, official English translation Data "specially protected against unauthorised access", and the requirement that the offender circumvent that protection.
- Directive 2013/40/EU on attacks against information systems Article 3, and the EU-wide floor for what member-state computer-misuse offences must reach.
- Computer Misuse Act 1990, section 1 The United Kingdom outlier, phrased on unauthorised access and knowledge rather than on a breached measure.
- Crown Prosecution Service, Computer Misuse Act guidance How United Kingdom prosecutors read that section in practice, which is the closest thing available to an answer on scraping.
- Reddit advances scraping suit against Perplexity and SerpApi Reporting on the 31 July 2026 order, including what survived and what was dismissed.
- Are robots.txt instructions legally binding? Ziff Davis v. OpenAI Analysis of the December 2025 order that set the floor, including the keep-off-the-grass reasoning.
- Legal weapons in the fight against data scraping A comparative survey, and useful for how thin the reported case law is outside the United States.
This article is a research summary of published law, with every source linked above. It is not legal advice, it creates no attorney-client relationship, and it is not authorisation to access any system. Law cited as of 19 August 2026; Reddit v. Perplexity is live litigation at the pleading stage and will move.