TL;DR: EFF joined 18 civil-society organizations in a letter asking Governor Kathy Hochul to veto New York Senate Bill S9934A, the Stealth Crawler Prohibition Act [1]. The bill, sponsored by Senator Michael Gianaris and Assemblymember Steven Otis, passed both chambers in June 2026. It would let any "covered" news publisher obtain a court subpoena to unmask anonymous automated visitors and let the Attorney General fine operators up to $15,000 per day per violation [2][3]. EFF argues the mechanism reaches far beyond AI scrapers and would chill investigative reporting, security research, and tools like Privacy Badger.

What S9934A Actually Does

S9934A adds a new Article 48 to New York's General Business Law. It targets "stealth crawlers," defined as any "online crawler, spider, fetcher, client, bot, user agent, AI agent, or equivalent tool" that does not identify itself before accessing a covered news source [2]. A covered source is a publication or broadcaster that performs journalism functions, publishes at least monthly, and has at least 1,000 monthly active users or subscribers in New York [2][3].

To comply, a crawler must identify itself through "a valid and accurate user-agent string" that names the software, version, and the company behind it, and it must disclose "the specific nature and purpose of such crawler, which shall include all uses and purposes" [2][3]. Anything that fails to do so becomes a stealth crawler, and it is unlawful to deploy one in a way that "damages, impairs, or burdens" a covered source's operation or causes economic harm [2].

The enforcement tools are the part the coalition finds dangerous. The New York Attorney General can seek injunctions and civil penalties of up to $15,000 per day per violation, with no requirement to prove actual injury [2][3]. Separately, any "journalism provider" can ask a court for a subpoena to force ISPs, hosting providers, and other service providers to hand over the identity of an anonymous operator, without first showing misconduct [1][2]. The bill passed the Senate 60-1 before winning Assembly approval; the session ended in June 2026 [3][4].

Who Is Backing the Bill

The proposal has the strong backing of the news industry. News/Media Alliance, the trade group whose members include most major US newspapers, celebrated passage in a June 2026 statement calling the law a needed response to AI crawlers that scrape publisher content without consent [4]. Governor Hochul's office has not said publicly whether she will sign or veto the bill [5].

Advance Media New York, the publisher of syracuse.com and The Post-Standard, and the New York News Publishers Association also backed the bill publicly before passage [5]. The publishers' framing is straightforward: more than half of the traffic at some news sites is non-human, and the server bills, bandwidth costs, and lost subscription value belong to the people who paid to produce the journalism.

EFF's Argument: The Mechanism Is the Problem

EFF staff attorneys Rindala Alajaji and Tori Noble made the coalition case on August 3. Their argument is not that publishers have no real complaint about aggressive scraping. It is that S9934A does not narrowly target the practice, it targets anonymity on the open web [1].

EFF's letter points to four concrete uses the bill would chill:

  • The Markup sent anonymous crawlers identifying as Firefox to investigate Amazon prioritizing its own brands in search results [1].
  • ProPublica used automated tools simulating ordinary customers to reveal Amazon steering shoppers to more expensive products [1].
  • Cybersecurity professionals, including SANS-certified incident responders, scrape cybercrime forums under cover to collect indicators of compromise [1].
  • EFF's own Privacy Badger crawls sites anonymously to detect third-party trackers that would otherwise hide from users [1].

Noble wrote in a July 20 analysis of the bill's framing that the term "stealth crawler" is doing the rhetorical work: "the term 'stealth crawlers' sounds quite nefarious. In reality, they're anything but" [6]. Anonymous crawling is the default mode of every browser, every search engine, and most academic research on the live web, she argued. A law that assumes hidden automation is malicious puts the burden on the researcher, the journalist, and the defender to register before they can work [1][6].

The Subpoena Power Is the Real Threat

The 60-1 Senate vote and the unanimous industry support suggest the bill's framing is popular. The technical mechanism is less popular with anyone who has read the second half of the statute.

Under S9934A, a "journalism provider" who believes a stealth crawler accessed their site can ask a court for a subpoena aimed at an ISP, hosting provider, or other intermediary. They do not have to show the crawler was used for anything harmful. They do not have to show they were damaged. They do not have to give the operator notice before the subpoena issues [1][2]. EFF's letter warns that this is a deanonymization tool with First Amendment reach, and it sits inside a statute nominally aimed at AI training data.

EFF's earlier 2026 work on anonymous speech, including an amicus brief in In re Subpoena to Reddit, makes the structural concern explicit: administrative subpoenas aimed at identifying anonymous online speakers have a long history of misuse, including against journalists, activists, and critics of powerful targets [6]. S9934A removes the gatekeeper role of a prosecutor or judge weighing the request. The plaintiff just has to be a covered news source, and the request goes to a service provider with no statutory damages cap.

What to Watch

Hochul's decision. The bill is on her desk. She can sign, veto, or let it lapse without action. A spokesperson said in June 2026 that she was reviewing the bill and had not taken a position [5]. Past state privacy fights in Albany suggest a late-session or post-session decision is most likely.

Other statehouses. News/Media Alliance has signaled it wants similar laws elsewhere [4]. If Hochul signs, expect copycat bills in states where local newspapers are politically organized. If she vetoes, expect the industry to push for a narrower, technical version that targets only AI scrapers.

Existing tools. The bill does not stop publishers from using robots.txt, rate limits, or paywalls, all of which are mentioned in EFF's analysis as the right way to handle overaggressive scraping without deanonymizing researchers [6]. Cloudflare's bot-blocking whitelist program, used by Reuters and Time, is the practical model EFF points to as a working alternative [6].

Sources

  1. Electronic Frontier Foundation, Rindala Alajaji and Tori Noble: "EFF Joins 18 Civil Rights Organizations Calling on Governor Hochul to Reject the Stealth Crawler Prohibition Act" (August 3, 2026)
  2. NY State Senate: S9934A (2025-2026 session)
  3. Clark Hill: "New York Targets Surveillance Pricing, Stealth Crawlers" (June 2026)
  4. News/Media Alliance: "New York Passes the 'New York Stealth Crawler Prohibition Act'" (2026)
  5. GovTech: "New York May Ban Identity-Concealing Bots From News Sites" (June 6, 2026)
  6. Electronic Frontier Foundation, Tori Noble: "'Stealth Crawlers' Are Not a Threat to the Open Web. Bills Targeting Them Would Be." (July 20, 2026)