While framed as a measure to protect local journalism, this legislation harms free expression and establishes a dangerous precedent by effectively deanonymizing and criminalizing automated access to the open web. By requiring all web crawlers to disclose their identity and explicit purpose, and by granting media outlets unchecked authority to obtain judicial subpoenas to unmask unidentified automated web traffic without any showing of misconduct or actual injury, this bill threatens digital privacy, compromises the foundational architecture of the internet, and will ultimately stifle the very independent journalism it seeks to protect.
As we’ve previously explained, so-called “stealth crawlers” are simply automated tools to access and collect public web data—without disclosing the user’s identity. Private crawlers like these facilitate all kinds ofimportant work that benefits the public, including investigative reporting, academic research, cybersecurity protection, and EFF’s own Privacy Badger. As we illustrate in the letter:
Anonymous crawling fuels important investigative journalism. For example, The Markup, a non-profit news site, used anonymous crawlers to investigate potentially anti-competitive practices by tech companies, such as Amazon’s tendency to prioritize Amazon brands and Amazon-exclusive products over competitors with higher ratings. The crawlers identified themselves as ordinary Firefox browsers to web servers, which allowed The Markup to understand how Amazon search results pages would appear to ordinary users. Similarly, ProPublica used an automated tool designed to simulate an ordinary Amazon customer to reveal that the site steered shoppers to more expensive products over cheaper alternatives.
Anonymous web scraping is also crucial for cybersecurity professionals, who use automated tools to monitor the web for information that helps them protect against malicious attackers. Privacy tools, including EFF’s Privacy Badger, also crawl sites anonymously to identify trackers without compromising user privacy.
Laws like S9934A sweep far beyond AI, targeting anonymity rather than the real technical issue: overaggressive crawling that can overtax technological infrastructure. Unmasking crawlers won't fix these server strains, but it will chill vital public-interest research and compromise digital privacy. Addressing the harms of web scraping requires narrow technical solutions—not policies that give publishers veto power over the open web. This is why we are calling on Governor Hochul to veto S9934A.
There’s a new boogeyman in the battles over AI: so-called “stealth crawlers.” We’ll admit it—the term “stealth crawlers” sounds quite nefarious. In reality, they’re anything but.
“Stealth crawlers” are simply automated tools to access and collect public web data—without disclosing the user’s identity. Private crawlers like these facilitate all kinds of important work that benefits the public, including investigative reporting, academic research, cybersecurity protection, and more.
Anonymous crawling enables some of the most publicly beneficial uses of the open web.
Many publishers want to unmask crawlers anyways—and are pushing for new legislation that would give them new powers to do so. These legislative proposals threaten the open web, user privacy, and valuable research without directly addressing the problems they’re supposedly intending to solve.
Alarmingly, these harmful proposals are gaining traction. The New York state legislature has already passed such a bill, the NY Stealth Crawler Protection Act, which is now on Governor Hochul’s desk. We expect to see similar bills introduced in other states, and potentially in Congress. That’s a big problem for the open web—and the many benefits it provides.
Anonymous crawling is worth protecting
Anonymous crawling enables some of the most publicly beneficial uses of the open web. Researchers, journalists, and other watchdog groups use unidentified automated tools to gather the information necessary to hold powerful institutions accountable and protect the public.
Anonymous crawling fuels important investigative journalism. For example, The Markup, a non-profit news site, used anonymous crawlers to investigate potentially anti-competitive practices by tech companies, such as Amazon’s tendency to prioritize Amazon brands and Amazon-exclusive products over competitors with higher ratings. The crawlers identified themselves as ordinary Firefox browsers to web servers, which allowed The Markup to understand how Amazon search results pages would appear to ordinary users. Similarly, ProPublica used an automated tool designed to simulate an ordinary Amazon customer to reveal that the site steered shoppers to more expensive products over cheaper alternatives.
Anonymous web scraping is also crucial for cybersecurity professionals, who use automated tools to monitor the web for information that helps them protect against malicious attackers. Privacy tools, including EFF’s own Privacy Badger, also crawl sites anonymously to identify trackers without compromising user privacy.
However, without the ability to scrape anonymously, these tools would likely be blocked. Sites can—and do—block crawlers operated by researchers, journalists, and activists who criticize them. For example, Facebook shut down accounts belonging to researchers who used automated tools to study misinformation on the platform and demanded that they take down published research. Many sites block automated access by anyone who hasn’t paid to crawl public webpages.
Unmasking crawlers threatens the open web
News publishers—and their allies in government—say that unmasking crawlers is necessary to protect news organizations from technological strain caused by AI-related crawling, and fears that AI could reduce news sites’ traffic and ad revenue. These are legitimate concerns.
But enacting broad, reactionary restrictions on automated access is not the answer. Legislation targeting anonymous crawling threatens the open web, user privacy, and valuable research without actually addressing these technological and potential economic harms of scraping.
The New York state legislature recently passed the NY Stealth Crawler Protection Act, a law that would make it illegal to crawl news websites without revealing who is operating the crawler and all possible future uses of the data collected by the crawler. The law would give websites the power to obtain court orders that unmask anyone using an unidentified crawler—without any evidence that they broke the law.
Laws like the New York bill sweep far beyond AI, and do not meaningfully address the technological or potential harms of AI-related web scraping. These policies would chill beneficial crawling by allowing publishers to veto lawful public access, giving them the power to block not just bad actors, but also security professionals, researchers, dissidents, or anyone who has not paid for a license to view public text. This needlessly undermines the free and open internet.
Digital news publishers—like most websites—face real technological challenges in the AI era. While web crawling has been around for decades, with the proliferation of AI, crawlers now collect far more public web data than they used to. This pushes servers closer to their maximum capacity, and if some bots collect information too aggressively, they may strain web servers to the point that it degrades site performance. The problem is not anonymity—so unmasking crawlers won’t solve it. The real problem is overaggressive crawling, which can be effectively addressed with technical measures that target harmful conduct without impeding anonymous access to information.
A better path forward
There are other, far less harmful ways to protect publishers from the harms these “stealth crawler” laws claim to target. Addressing the harms of AI-related crawling requires policies that narrowly target the causes of these issues–without undermining free expression and the open web. Policies that target crawlers and scrapers are anything but.
360 degree feedback promises that it will offer truth in all directions. It will illuminate blind spots, reveal the development areas people couldn’t see before and unlock potential they didn’t know they had. It promises, above all, to make honesty safe, offering confidentiality and anonymity for the people with less power, so they can finally tell the truth about the people with more. It is an appealing set of promises, but whether it can keep them is another matter.
The Murky History of 360 Degree Feedback
Let’s just clarify first what we mean by 360 degree feedback. Generally, the term refers to a process of gathering feedback about an individual from the people around them, perhaps their manager, but also peers and direct reports, hence the full circle – 360 degrees. This is ostensibly to support their development, to feed into an appraisal, or both. Responses are typically anonymised, often pooled in groups of three or more so that in theory no single rater can be identified (although that’s rarely watertight in practice).
So where does this popular practice actually come from? Rumours abound. I once heard a version involving a KGB sabotage manual, which I’d love to believe as it would make a great story. Unfortunately, I’ve found no evidence for it. The more likely history, referenced widely online, traces an early version to officer selection in the German Reichswehr around 1930, under a military psychologist named Johann Rieffert. Nobody called it 360 degree feedback, but multiple observers would feed into a single judgement about who should make the cut.
The name “360-degree feedback” was coined in the mid-1980s by an assessment firm called TEAMS Inc, who registered the phrase as a trademark, and then spent years trying to enforce their ownership of it until the company was sold. There has always been money in this, and attempts to trademark concepts and practices should always raise an eyebrow, if not a red flag.
None of which stops 360 degree feedback being treated today as a solid, almost scientific HR default. For a practice this murky in its origins, that’s quite a leap, and as we’ll see, neither the evidence nor people’s experiences of it seem to justify the confidence.
Experiences of 360 Degree Feedback
I’ve worked in organisations running 360 degree feedback processes, and I know the anxiety of waiting on anonymised comments, followed, almost always, by one of two deflations:
You’re handed some critical but cryptic line, spend an unreasonable amount of energy trying to guess who wrote it and have to actively resist the urge to go and just ask them what they mean, or:
You get the other thing entirely: bland, school-report style platitudes about being a great colleague, which are technically positive, but don’t really say anything at all.
Both versions arrive by the same route. The 360 degree feedback process tips into a tick-box exercise, and once it has, it doesn’t just fail to start a constructive, developmental conversation; the anonymity built into it often makes sure that conversation can never happen at all.
None of this is unique to me. I have these conversations regularly with clients, people in mid-sized and large organisations where 360 degree feedback has become so completely entangled with performance management or appraisal that all ideas of feedback get drawn into this dreaded annual cycle. It seems like once an organisation has a formal annual mechanism for feedback, that mechanism exerts a gravitational pull over all other feedback instances. The ordinary, day-to-day, low-stakes, useful versions of feedback – like a quick check in after a meeting or small flagging of a blind spot – start to feel like something to save up rather than say now. People batch it all up for judgement day and the process that’s designed to surface feedback ends up suppressing many more useful, and low-threat, day-to-day exchanges.
And then there are the others, the ones just starting out on their 360 degree feedback ‘journey’, asking important questions before they commit: why are we doing this, and what is it actually going to do to psychological safety here?
The Evidence Gap
It turns out that the case for 360 degree feedback is pretty underwhelming, given how embedded all this is. Despite three decades of near universal corporate enthusiasm, nobody has ever managed to show, convincingly, that it does what it’s supposed to do. The Institute for Employment Studies spent a year interviewing organisations running these schemes and combing through the available research, and concluded that widespread adoption of 360 degree feedback reflects “faith rather than proven validity,” which is, it turns out, a rather generous way of putting it. Evidence of actual impact on individual development or organisational performance was, in their own words, “scant.” Similarly, the most authoritative meta-analysis in the field, pulling together twenty-four longitudinal studies, found that improvement in ratings over time, the entire point of the exercise, was ‘generally small’. As the authors put it, “practitioners should not expect large, widespread performance improvement after employees receive multisource feedback.”
That meta-analysis was published in 2005. Two decades on, the more recent literature isn’t full of fresh studies overturning or confirming it, it’s largely quiet, with prominent practitioners in the field noting a “glaring absence” of new research even as usage of 360 feedback keeps climbing. The honest answer to “does this work?” still sits somewhere closer to “a bit, maybe, for some people, under conditions nobody’s fully pinned down” than anything resembling a “yes!”
None of which has slowed adoption down. Which brings me back to the money. Google “360 degree feedback” (a reasonable start for any investigative dive into the practice!) and the first page is dominated by sponsored placements and paid products, all companies selling their own version of a 360 degree feedback tool. Twenty years ago, the IES were already noting the volume of “spin from external providers” surrounding this practice. If there was a lot of spin then, I suspect there’s a great deal more now.
More Raters, More Bias
All feedback is subjective. I’ve written about why that matters elsewhere, so I won’t revisit the whole argument, except to say that the moment you treat a rating as a fact about a person rather than an impression formed by another person, you’re already in trouble.
What’s worth adding in this context is a particular claim some 360 degree tools lean on, implicitly or explicitly: that gathering feedback from many sources cancels out individual bias and delivers something more objective than a single manager’s view. It’s an appealing idea, but averaging several biased judgements doesn’t remove the bias, it just blends it into something that looks smoother and harder to attribute while carrying the original distortions inside it. Gender and racial bias don’t disappear when you collect more ratings; in fact they may well accumulate while becoming harder to see, hidden behind an aggregate score that feels objective and is anything but.
There’s another issue too: 360 asks how a person is performing, rarely about what pressures and constraints they were facing. The forms have feedback for the individual and rarely for the conditions, so the subject of the feedback ends up holding the weight of the system around them.
The Trouble with Anonymity
Anonymity exists in these practices for an obvious reason: people are supposed to feel safer telling the truth if they can’t be identified for it. Aside from the (very real) risk that this reinforces the idea that it’s actually not safe to speak up unless we’re anonymous, the IES researchers did find this working roughly as intended – raters giving upward feedback anonymously were more critical than those who knew their names would be attached. But they also found the protection failing in two different ways. In some cases, managers asked direct reports to provide them directly with “anonymous” feedback, which of course undermines the anonymity from the start. In other cases, raters who had been promised anonymity colluded with each other, with several colleagues agreeing in advance to write identical negative comments about their manager so that no single person could be singled out and blamed. They didn’t trust the protection the system offered, so they built their own on top of it.
There’s a further risk in anonymous feedback – it can easily mask people over- or under-rating for political reasons, which is most likely when the stakes are high. In some organisations, 360 degree feedback has reportedly been folded into the machinery of ‘rank and yank,’ the practice of ranking people by their performance ratings and firing the bottom 10%, a practice which is (thankfully) effectively unlawful in many parts of the world. But where it, or practices like it, still exist, are you really going to risk rating a colleague higher than yourself?
When the IES researchers looked at places where anonymity was removed instead, some people reported being approached and made to feel uncomfortable for giving honest upward feedback. Yet others preferred it that way, worried that anonymity would let others use the process to settle old scores under cover rather than to give honest feedback. “At least the feedback can be challenged if the names are on it,” as one of them put it, and I see their point. We know feedback is most useful when it’s context-rich – when it can be located in specific incidents and relationships – and when it’s part of a two-way conversation. Anonymised 360 degree feedback removes both the context and the conversation.
So take anonymity away, and people fear retaliation for their honesty. Leave it in place, and people suspect the cover is being used to settle scores or game the system. Either way, the distrust is still there. The problem was arguably never about anonymity at all, but that nobody in the system trusted that honest feedback would be received well, used fairly, or kept safe, regardless of whether names were on it.
Which brings us back to psychological safety. What people need in order to offer honest feedback, is consistent, demonstrated, lived experience that speaking honestly won’t cost them anything. That can only be developed slowly, through what actually happens when people speak up – we can’t shortcut our way to it via an anonymous feedback form.
The Costs of 360 Degree Feedback
There is a financial and relational cost to 360 degree feedback which is easy to overlook when it becomes ‘the norm’. We work with a number of large organisations stuck with a frustrating annual ritual, gathering and inputting reams of data into a system most people resent, kept alive less by conviction that it actually works than by a software licence they’re tied to. These platforms cost a significant amount of money, and the decision to buy one was often made a long way up the organisation. The cost is sunk; the plan is the plan, and questioning it means telling someone senior that their expensive choice isn’t working. It’s often easier, on balance, to just keep doing it.
In another organisation, someone told me their HR team was considering bringing 360 feedback in specifically to deal with one ‘bad manager’. The logic, as it was explained to me, was that this was the only way to get that manager some direct, unfiltered feedback from the people reporting to them. Which might be true. But it also means reaching for an entire organisation-wide measurement system, with all its cost, fatigue and risk, to solve a problem that’s really about one person — a siege engine wheeled up to a door that only needed knocking on.
So where does that leave us?
Not, unfortunately, with a tidy verdict. I’m not here to tell you 360 degree feedback never works, or that everyone running it should stop tomorrow. The honest position is that we don’t really know what it does, the evidence has been thin for twenty years and a great many organisations are running these processes at real cost to time, money and trust without properly questioning whether they’re helping or harming.
If there’s a structural point underneath all of this, it’s that candid feedback isn’t a system we install. The IES researchers, after all their interviews and analysis, landed somewhere strikingly modest: that organisations might do better simply reminding people to give honest, regular feedback as a matter of ordinary practice, rather than building elaborate machinery to extract it once a year.
I don’t think the story of 360 degree feedback is over. The tools are still being sold, the licences still being signed, the annual cycles still grinding on in organisations full of people wondering what they’re for. I suspect I’ll be having these conversations with clients for a long time yet. But maybe we can at least take a step back and ask what problem this process is actually meant to solve, and whether this is a good way to solve it.
If this leaves you wondering what good feedback actually looks like, the more personal, everyday kind that doesn’t need an annual cycle or an anonymous form, that’s exactly what we cover in our Delivering Effective Feedback workshop. Full details are here.
In September 2024, Amandla Thomas-Johnson was a Ph.D. candidate studying in the U.S. on a student visa when he briefly attended a pro-Palestinian protest. In April 2025, Immigration and Customs Enforcement (ICE) sent Google an administrative subpoena requesting his data. The next month, Google gave Thomas-Johnson's information to ICE without giving him the chance to challenge the subpoena, breaking a nearly decade-long promise to notify users before handing their data to law enforcement.
Google names a handful of exceptions to this promise (such as if Google receives a gag order from a court) that do not apply to Thomas-Johnson's case. While ICE “requested” that Google not notify Thomas-Johnson, the request was not enforceable or mandated by a court. Today, the Electronic Frontier Foundation sent complaints to the California and New York Attorneys General asking them to investigate Google for deceptive trade practices for breaking that promise. You can read about the complaints here. Below is Thomas-Johnson's account of his ordeal.
Out of touch but not out of reach
I thought my ordeal with U.S. immigration authorities was over a year ago, when I left the country, crossing into Canada at Niagara Falls.
By that point, the Trump administration had effectively turned federal power against international students like me. After I attended a pro-Palestine protest at Cornell University—for all of five minutes—the administration’s rhetoric about cracking down on students protesting what we saw as genocide forced me into hiding for three months. Federal agents came to my home looking for me. A friend was detained at an airport in Tampa and interrogated about my whereabouts.
I’m currently a Ph.D. student. Before that, I was a reporter. I’m a dual British and Trinadad and Tobago citizen. I have not been accused of any crime.
I believed that once I left U.S. territory, I had also left the reach of its authorities. I was wrong.
The email
Weeks later, in Geneva, Switzerland, I received what looked like a routine email from Google. It informed me that the company had already handed over my account data to the Department of Homeland Security.
At first, I wasn’t alarmed. I had seen something similar before. An associate of mine, Momodou Taal, had received advance notice from Google and Facebook that his data had been requested. He was given advanced notice of the subpoenas, and law enforcement eventually withdrew them before the companies turned over his data.
Google had already disclosed my data without telling me.
I assumed I would be given the same opportunity. But the language in my email was different. It was final: “Google has received and responded to legal process from a law enforcement authority compelling the release of information related to your Google Account.”
Google had already disclosed my data without telling me. There was no opportunity to contest it.
Google’s broken promise
To be clear, this should not have happened this way. Google promises that it will notify users before their data is handed over in response to legal processes, including administrative subpoenas. That notice is meant to provide a chance to challenge the request. In my case, that safeguard was bypassed. My data was handed over without warning—at the request of an administration targeting students engaged in protected political speech.
Months later, my lawyer at the Electronic Frontier Foundation obtained the subpoena itself. On paper, the request focused largely on subscriber information: IP addresses, physical address, other identifiers, and session times and durations.
But taken together, these fragments form something far more powerful—a detailed surveillance profile. IP logs can be used to approximate location. Physical addresses show where you sleep. Session times would show when you were communicating with friends or family. Even without message content, the picture that emerges is intimate and invasive.
State power meets private data
What this experience has made clear is that anyone can be targeted by law enforcement. And with their massive stores of data, technology companies can facilitate those arbitrary investigations. Together, they can combine state power, corporate data, and algorithmic inference in ways that are difficult to see—and even harder to challenge.
The consequences of what happened to me are not abstract. I left the United States. But I do not feel that I have left its reach. Being investigated by the federal government is intimidating. Questions run through your head. Am I now a marked individual? Will I face heightened scrutiny if I continue my reporting? Can I travel safely to see family in the Caribbean?
Who, exactly, can I hold accountable?
Update: This post has been updated to include more information about Google's exceptions to their notification policy, none of which applied to the subpoena targeting Thomas-Johnson.