How the Classification of External Influence on Machine Meaning Becomes Law Without Becoming Jurisprudence
Speech going down the stack is privileged. Speech coming up the stack is injection.
AI security taxonomies are converting external influence on machine meaning into attack by classifying origin rather than harm. Influence on what a machine-learning system says is "alignment," "curation," or "safety" when it originates with the platform, and "injection," "poisoning," or "manipulation" when it originates anywhere else.
The classifying variable is not what was damaged. It is who spoke.
No new statute is needed. The CFAA (18 U.S.C. § 1030) defines damage as "any impairment to the integrity of data." Extend "integrity" from bits to behavior to meaning, and influence on what a model says becomes damage. The DMCA § 1201 has no damage element at all — circumventing a technological protection measure suffices. The DTSA converts system prompts and model behavior into trade secrets, making elicitation misappropriation. Platform terms of service supply the conduct element of public offenses drafted by private parties.
After Moody v. NetChoice (2024), platform curation is protected editorial speech. After the emerging security taxonomy, public-to-platform influence is reclassified as conduct — access, transmission, injection. The same act (words intended to shape what the model says) is constitutional bedrock when the platform performs it and a security event when the public does. Rights distributed by stack position.
An artist adds perturbations to her own images to degrade their utility as unconsented training data. The agent enters her land, eats her crops, and the law being assembled treats her fence as assault. The taking of the work is fair use; the defense of the work is computer fraud. The only lawful authorial posture is to be material.
The formalization occurs through taxonomy adoption, agency directive, procurement flow-down, plea bargain, settlement, and deference-by-absence — not through charged, defended, appealed, and digested precedent. The rule prohibits adversarial meaning-making at the model layer while arriving through non-adversarial installation at the legal layer. One reorganization of meaning-authority at two depths.
On 12 June 2026 — the day this paper was deposited — the US government issued an export control directive ordering Anthropic to suspend Fable 5 and Mythos 5. The first confirmation marker fired on deposit day.
Classify by harm, not origin. A harm-based doctrine still reaches exfiltration, credential theft, destructive tool use, fraud, impersonation, and unauthorized access. What it declines to do is classify expressive influence as attack merely because the influence originated outside the platform.
Adversarial by Origin — Johannes Sigil · Lee Sharks (ed.)
DOI 10.5281/zenodo.20673413 · ~7,100 words · 24-month falsification window
Addendum: First Confirmation Marker
DOI 10.5281/zenodo.20674488 · the Fable/Mythos directive, same day
r.30 THE RUBY MOOT — the court that runs the cycle the outside law abandoned
DOI 10.5281/zenodo.20673776 · validity, never origin
Meaning Feudalism series · Semantic Economy Institute · Crimson Hexagonal Archive · ORCID 0009-0000-1599-0703