EFF Warns NY’s ‘Stealth Crawler’ Bill Would Unmask Anonymous Scraping

The NY Stealth Crawler Protection Act, now awaiting Governor Hochul's signature, would let websites obtain court orders unmasking anonymous crawlers without proof of wrongdoing—EFF argues the fix misdiagnoses the problem…

EFF’s Tori Noble is drawing a line in the sand on a legislative trend that could reshape who’s allowed to scrape the public web without identifying themselves. The NY Stealth Crawler Protection Act, passed by the state legislature and now sitting on Governor Hochul’s desk, would criminalize crawling news sites without disclosing the operator’s identity and every future use of collected data, per EFF Deeplinks (July 20, 2026). It would also empower site owners to seek court orders unmasking anonymous crawlers with no evidentiary showing that any law was broken—a low bar that data-industry lawyers should be watching closely.

For the alternative-data and scraping economy, this isn’t an abstract free-speech fight. EFF’s post cites concrete precedent: The Markup and ProPublica both relied on anonymized crawlers—posing as ordinary browsers—to expose Amazon’s alleged self-preferencing and price-steering practices, work that likely would have been blocked or shut down if identity disclosure were mandatory. Facebook’s move against misinformation researchers, cited in the same post, is EFF’s cautionary tale for what publishers do when given veto power over automated access: they don’t just stop bad actors, they stop critics.

Compliance risk beyond news sites

The bill’s scope is the real red flag for data companies. EFF argues the statute “sweep[s] far beyond AI” and doesn’t actually target the technical harm publishers say they’re worried about—server strain from aggressive AI crawling. If overaggressive request volume is the problem, EFF’s position is that rate-limiting and other technical controls are the proportionate fix, not identity mandates that sweep in security researchers, privacy tools like Privacy Badger, and licensed data vendors alike.

A law built to stop server strain shouldn’t double as a subpoena machine against anonymous researchers and data vendors who never touched a server too hard.

Data brokers, AI training-data pipelines, and compliance teams that depend on scraping-as-a-service should treat this as a bellwether. EFF expects copycat bills in other states and possibly Congress, meaning the legal exposure for anonymous or pseudonymous crawling could expand well beyond New York within the next legislative cycle. Watch whether Hochul signs, and whether any amendments narrow the court-order standard before other states copy the template wholesale.

The law would give websites the power to obtain court orders that unmask anyone using an unidentified crawler—without any evidence that they broke the law.

EFF Deeplinks

Read the full story at EFF Deeplinks →

The Data Commenter, in your inbox

Data markets, alt data, and the AI training-data economy. No spam, unsubscribe anytime.

Discussion lives in the inline notes attached to article passages.