Peter Ormerod

Research

  1. 2026

    Distilling Knowledge Work

    Essay

    Working Draft (Aug. 2026)

    Generative AI has begun converting records of work into the work itself, making the capacity to perform knowledge work alienable and reproducible. This Essay names that process and traces the recursive conflict it has ignited among workers, firms, and the frontier labs.

    Abstract

    Generative artificial intelligence has begun converting records of work into the work itself. Employers have long recorded their workers, but a century of surveillance produced only archives that couldn’t perform anything. Now, though, AI systems trained on those records are reproducing the judgment they contain. Pairing records with processing transforms expertise: memorialized as work data and analyzed by a capable AI model, the capacity to perform knowledge work is becoming alienable and reproducible.

    This Essay names this phenomenon the distillation of knowledge work, and it shows how this process has ignited a recursive conflict over who will cede and who will capture wealth in the age of AI.

    Within firms, employers capture workers’ judgments and corrections as proprietary training assets. But recording and processing need not occur in the same hands: the firm that surveils its workers typically rents AI processing capacity—the still—from a frontier AI lab. In search of a viable business model, the labs are attempting to burrow into the place where work is represented—the place where work data accrues, market opportunities become visible, and the intelligence can be monetized. So the enterprises eagerly distilling their workers’ expertise are simultaneously threatened by the labs. It’s little wonder, then, that the capital class is increasingly adopting the rhetoric of the proletariat.

    Who will distill whom? This Essay shows how inherited legal endowments will prove instrumental to workers’ dispossession, whereas the contest between firms and the labs is likely to be decided either by private ordering among the powerful or by one side enlisting the state. The labs’ unconditional victory, however achieved, could summon a regulatory paradigm older than antitrust. But whatever happens in the contest above, the worker below holds no claim to any version of the learning loop her judgment fills.

    The monetization of data about people defined the prior era of information capitalism. The monetization of work itself will define the next.

  2. 2027

    Data Governance’s First Amendment Opportunity

    Article

    105 North Carolina Law Review ___ (forthcoming 2027)

    The conventional wisdom says the First Amendment blocks most data-based regulation. This Article shows that the current Supreme Court has proven unexpectedly receptive to laws burdening profit-motivated information processing, and it guides policymakers who want to seize the opening.

    Abstract

    The conventional wisdom says that the First Amendment stands as an insurmountable hurdle to most forms of data-based regulation. Though scholars disagree about what exactly makes free-speech doctrine excessively deregulatory, most agree that it is. This Article challenges that conventional wisdom by showing how the current Supreme Court has proven unexpectedly receptive to laws that burden profit-motivated information processing, and it guides policymakers who wish to enact the future of data governance.

    In three recent First Amendment cases, the Court’s conservative majority pointedly declined technology companies’ invitation to invalidate laws that seriously interfered with their businesses’ information-processing activities. These decisions all narrowly characterized the challenged laws’ burden on expression. That critical and unexpected move limited the First Amendment’s coverage, lowered scrutiny, helped laws survive that scrutiny, and dampened industry’s ability to easily invalidate large swaths of informational regulation. Together, the decisions mark a sharp methodological break—abandoning the categorical rules and sweeping rhetoric of the early Roberts Court and instead embracing a calibrated, discretionary approach.

    This is not to suggest that the Court will characterize all future speech burdens so narrowly, as a deregulatory First Amendment paradigm continues to govern corporate-speech cases and those involving the specter of coercive ideological conformity. But Silicon Valley executives gambled that the Court would mechanically apply laissez-faire principles to unshackle their businesses from meddlesome policymakers, and that was a grave miscalculation.

    The implications for information-age reform are profound. The circuit courts are already operationalizing narrowed burdens to rebuff industry’s facial challenges and sustain youth-safety regulations from red and blue states alike. The Court’s new approach is thus breathing new life into efforts to ameliorate addictive digital design, address dangerously sycophantic chatbots, increase transparency and oversight, restrict minors’ access to social media, and more. Because a discretionary regime provides latitude rather than guarantees, this Article offers concrete guidance to policymakers seeking to seize data governance’s First Amendment opportunity.

  3. 2026

    Regulating Manipulative Design Is Not Preempted by CDA 230 or the First Amendment

    Article

    75 Emory Law Journal 1101 (2026)(with Brett M. Frischmann)

    States retain considerable discretion to regulate digital platforms’ design and engineering decisions. Neither Section 230 nor the First Amendment categorically immunizes platforms for the content-agnostic harms their manipulative designs cause.

    Abstract

    For over two decades, there has been a heated debate among legal scholars, activists, judges, and others about the scope of Section 230 of the Communications Decency Act. A persistent theme in those debates has been hyperbolic claims about the necessity of immunity from state laws for digital tech platforms and fearmongering that anything less than maximum immunity will destroy the Internet.

    This Article argues that states retain considerable discretion to regulate digital platforms’ design and engineering decisions. We argue that manipulation, engineered behavior, and even habituation and normalization of engineered behavior by digital platforms are content-agnostic harms attributable to defective designs, and neither Section 230 nor the First Amendment categorically immunizes platforms for causing such harms.

    We develop a typology that distinguishes between direct harms perpetuated by the platforms’ own design decisions, secondary harms caused by user-generated content and the platforms’ content-moderation failures, and further attenuated tertiary harms. Our approach enables and empowers policymakers and judges to distinguish the platforms’ regulable conduct from their expressive decisions immunized by Section 230 and the First Amendment.

    We focus on personal-data-driven algorithmic targeting, a manipulative design feature of social media systems that directly causes primary harm. Other design features—such as infinite scrolling and other dark patterns—also directly cause primary harm, and this form of manipulation also includes hijacking attention, disabling or overriding user autonomy, undermining self-governance, scripting behaviors, and engineering addiction.

    We show how this approach is consistent with current law and is already surfacing in recent state regulations and in litigation over social media platforms’ tortious design. This Article illustrates how careful delineation of the relevant actors, actions, causal relationships, effects, and harms is crucial for understanding the proper scope of Section 230 and the First Amendment.

  4. 2026

    Regulating Data Monetization

    Article

    13 Texas A&M Law Review 1003 (2026)

    Holding the information age’s real power to account requires regulating how companies turn data into money — through the individualized differentiation of products, services, and prices — rather than relying on individual control over personal information.

    Abstract

    Companies today generate hundreds of billions of dollars each year by collecting massive amounts of information about human activity and wringing predictive insights from it. The scale of these influence activities is stunning: your driving habits dictate your car insurance rates, buying the wrong thing will increase your borrowing costs, and the information ecosystem you inhabit is finely tuned for keeping your attention available to the highest bidder.

    States have recently enacted new consumer privacy laws that confer on individuals a series of generally applicable rights over their personal information. But this approach has proven ineffective at disciplining firms’ data activities, especially amid a raft of other doctrines that increasingly ensure that corporate platforms exercise all the real power over user-derived data. More fundamentally, conflating privacy with individual control over data misapprehends that privacy is a social phenomenon with a rich array of collective benefits and that the firms that threaten it operate at scale.

    This Article charts a different course. Rather than relying on individual decision-making to govern scalar processes and collective effects, holding the information age’s real power and profit to account requires going to the source, regulating how companies transform data into money. They do so through individualized differentiation—the process of offering customized, personalized, or otherwise distinct products, services, and prices to their customers, users, employees, and other counterparties. Recognizing that the law already regulates some aspects of these differentiation activities, the Article then proposes that these efforts should be expanded, improved, and systematized in two ways: by disrupting the surveillance trade that fuels differentiation and by imposing new restrictions on the differentiated offerings themselves.

    This Article’s contributions—uncovering firms’ data-monetization strategies, exposing how law already governs them, and proposing how it should in the future—lay the foundation for a data-governance regime that infuses democratic accountability into the informational processes that govern modern life.

  5. 2026

    Disciplining Mechanisms: Governing Data Markets with Competition and Regulation

    Essay

    27 Yale Journal of Law & Technology 308 (2026)

    Neo-Brandeis antitrust and structural data governance share an objective but can work at cross purposes. This Essay exposes the friction between them and offers policymakers guidance on when to reach for each.

    Abstract

    The past decade has witnessed conceptual renewals in both competition law and information privacy law. These regulatory movements—Neo-Brandeis antitrust and structural data governance—share the objective of recalibrating the balance of power between individuals and the massive data-processing firms that now dominate modern life.

    Despite their common ends, policy interventions drawn from these schools of thought can work at cross purposes: competitive pressure can induce data exploitation, and privacy rules tend to benefit the largest firms.

    This Essay exposes the friction in their relationship and offers guidance on how to mediate their tension. Competition policy alone will prove ineffective at indirectly disciplining most data activities, so policymakers should largely favor the structural data-governance approach to address the information economy’s pathologies. But pro-competition policies will nevertheless be essential to reining in firms that are too big to meaningfully regulate and may also prove helpful in solving certain discrete data-processing problems. Policymakers today have two distinct mechanisms for disciplining firms’ data-driven activities. This Essay describes them, exposes their contours, and offers those policymakers guidance on how best to deploy them.

  6. 2024

    Privacy Law’s Incumbency Problem

    Article

    58 UC Davis Law Review 179 (2024)

    Consent-based privacy laws confer three distinct powers on entrenched incumbents — the power to comply, to restrict, and to circumvent — and thereby further entrench the dominant platforms they were meant to discipline.

    Abstract

    Policymakers and scholars concerned with the power of informational platforms are questioning how traditional doctrinal silos like privacy law and antitrust law interact in digital markets. Their interaction has taken on new urgency in recent years as states have enacted a flurry of consent-based privacy laws and as digital markets have become increasingly dominated by the same few firms.

    Contemporary debates about the interaction of competition and privacy tend to ask what role, if any, privacy should play in the antitrust analysis. Little has been written about how new privacy laws shape the competitive landscape. This Article argues that consent-based privacy laws confer three distinct powers on entrenched incumbent firms.

    The first is the power to comply. Dominant firms realize economies of scale in any regulatory compliance regime, but they are uniquely advantaged by the need to obtain consent to collect and process users’ information. The second is the power to restrict. By constraining information flows, privacy laws deprive insurgents of access to data that could prove valuable in challenging incumbents’ dominance, and consent mechanisms exacerbate the dynamic by supplying incumbents with a legal justification for refusing to share their data and circumscribing competitors’ access to it. The third is the power to circumvent. A private-sector initiative that limits the collection and sharing of advertising-related information shows that stringent consent mechanisms may deprive all firms of some data, but incumbents with sufficient scale—and only such firms—can circumvent and overcome these restrictions.

    Taken together, the three powers of incumbency suggest that laws like the California Consumer Privacy Act will further entrench dominant informational platforms like Meta’s and Google’s—and they thereby raise difficult questions for those who seek to curb platform power. Ultimately, privacy law’s incumbency problem suggests pessimism about pursuing competition to the exclusion of other policies and about the prevailing approach to privacy law.

  7. 2022

    Privacy Qui Tam

    Article

    98 Notre Dame Law Review 267 (2022)

    Public enforcement of privacy law is under-resourced and private rights of action are increasingly infeasible. Qui tam offers a hybrid: individuals empowered to sue lawbreakers without the obstacles that now defeat private suits.

    Abstract

    Privacy law keeps getting stronger, but surveillance-based businesses have proven immune to these new legal regimes. The disconnect between privacy law in theory and in practice is a multifaceted problem, and one critical component is enforcement.

    Today, most privacy laws are enforced by governmental regulators—the Federal Trade Commission, the nascent California Privacy Protection Agency, and state attorneys general. An enduring impasse for proposed privacy laws is whether to supplement public enforcement by using a private right of action to authorize individuals to enforce the law.

    Both of these conventional enforcement schemes have significant shortcomings. Public enforcement has proven inadequate because resource-constrained regulators only rarely bring enforcement actions, and the resulting consent decrees tend to entrench the status quo. Meanwhile, private enforcement is increasingly infeasible thanks to defendant-friendly Supreme Court decisions about the Federal Arbitration Act, Article III standing, and class action certification.

    This Article proposes a hybrid approach: policymakers should enact privacy laws that authorize qui tam enforcement. A qui tam is an ancient legal action that authorizes a private plaintiff called a relator to redress an injury suffered by society, and successful relators are entitled to a portion of the recovery. A privacy qui tam is responsive to the shortcomings with both public and private enforcement: individuals are empowered to sue lawbreakers, but these suits don’t face the same obstacles as private rights of action.

    Qui tam has traditionally protected collective rights, so a crucial question about the viability of a privacy qui tam is whether violations of privacy law could be considered collective injuries amenable to qui tam enforcement. Fortunately, privacy scholars in recent years have convincingly shown that privacy is a social phenomenon that requires policy intervention at a structural level. A privacy qui tam therefore operationalizes privacy theory and promises to fill the enforcement void left by overwhelmed regulators and infeasible private rights of action.

  8. 2022

    Making Privacy Injuries Concrete

    Article

    79 Washington & Lee Law Review 101 (2022)

    The Supreme Court’s intangible-injury cases suffer from a line-drawing problem and a counter-majoritarian one. Building on contextual integrity, this Article gives courts a principled way to tell injurious informational practices from harmless ones.

    Abstract

    In recent years, the U.S. Supreme Court has repeatedly said that the doctrine of Article III standing deprives the federal courts of jurisdiction over some lawsuits involving intangible injuries. The lower federal courts are carrying out the Supreme Court’s instructions, and privacy injuries have borne the brunt of the Court’s directive. This Article identifies two incoherencies in the Court’s recent intangible injury decisions and builds on the work of privacy scholars to fashion a solution.

    The first incoherency is a line-drawing problem: the Court has never explained why some intangible injuries create an Article III injury in fact while others do not. The second problem is more fundamental: the Court has never provided a justification for using counter-majoritarian constitutional standing to deprive plaintiffs of a remedy against companies engaged in abusive informational practices. These incoherencies have sparked much confusion in the lower courts and have invited curious arguments that the Constitution prohibits courts from adjudicating all but the narrowest sliver of privacy disputes.

    To address the line-drawing and counter-majoritarian problems, this Article builds on Helen Nissenbaum’s contextual integrity framework. Contextual integrity observes that privacy is context specific and that privacy violations are the byproduct of practices that violate entrenched informational norms.

    Constructing a legal framework based on contextual integrity solves both problems: contextual integrity provides courts with a principled way to distinguish between informational practices that are injurious and those that are not, and contextual integrity supplies courts with a persuasive justification for dismissing cases divorced from shared conceptions about abusive informational practices.

  9. 2021

    Privacy Injuries and Article III Concreteness

    Article

    48 Florida State University Law Review 133 (2021)

    Spokeo’s concreteness inquiry is eroding Congress’s ability to create remedies for new harms. Identifying four distinct informational injuries in the Court’s cases, this Article proposes binding deference to Congress in a defined set of circumstances.

    Abstract

    The Supreme Court’s 2016 decision in Spokeo, Inc. v. Robins requires federal courts to investigate the “concreteness” of a plaintiff’s injury, even after Congress has recognized the injury by statute. Spokeo’s concreteness discussion is a confusing mixture of several distinct considerations, and there is little rhyme or reason to how the lower courts have interpreted and applied Spokeo to other statutorily authorized injuries.

    This Article identifies four distinct informational injuries in the Court’s past cases: injuries arising from the withholding, acquiring, using, and disseminating of information. To avoid Spokeo’s mistakes, federal courts should give binding deference to Congress’s decision to make an injury privately enforceable when three conditions are met: when the plaintiff alleges one of these informational injuries; when the defendant is a non-governmental actor; and when Congress has effectively personalized the injury and the plaintiff is among the injured.

    The Court’s approach—an unmoored judicial investigation into an informational injury’s amorphous “concreteness”—erodes Congress’s ability to provide avenues of redress for new and novel harms, and this erosion is already undermining privacy protections. Since Spokeo, lower courts have refused to enforce provisions of the Fair Credit Reporting Act, the Fair and Accurate Credit Transactions Act, and the Cable Communications Policy Act, among other statutes.

  10. 2019

    A Private Enforcement Remedy for Information Misuse

    Article

    60 Boston College Law Review 1893 (2019)

    Companies externalize the costs of information misuse, producing chronic under-investment in security and excessive data retention. This Article proposes a state-law strict-liability fiduciary remedy designed to reshape those incentives.

    Abstract

    Misuse of users’ personally identifiable information is persistent and pervasive. This Article addresses two questions: why is information misuse so common and so severe and how could domestic law change to make it less so? I use a simple model to illustrate that companies externalize information misuse costs onto users, which has two related but distinct effects: chronic underinvestment in information security and excessive retention of user data.

    I then seize on this observation to propose a specific legal vehicle at the heart of this Article—a private enforcement remedy. This private enforcement remedy has four essential features. First, the remedy must be created under state law. State law provides a viable alternative when federal courts have used the constitutional standing doctrine to express overt hostility to privacy harms. Second, the law should impose a fiduciary duty on entities that collect or retain users’ information. Structuring the remedy this way insulates it from attack by a weaponized First Amendment. Third, breach of an information fiduciary’s duty should be a strict liability tort. The arguments for strict liability in products liability cases apply with even greater force to informational harms. Fourth, the statute that creates this private enforcement remedy should prescribe a schedule that begins with nominal damages and attorney’s fees for strict liability, and it should increase monetary penalties with a defendant’s culpability.

  11. 2019

    WannaCry, Ransomware, and the Emerging Threat to Corporations

    Article

    86 Tennessee Law Review 503 (2019)(with Lawrence J. Trautman)

    An account of the WannaCry ransomware attack and what it revealed about corporate exposure, written for the executives and directors who bear the resulting duties.

    Abstract

    The WannaCry ransomware attack began on May 12, 2017, and is unprecedented in scale—quickly impacting nearly a quarter-million computers in over 150 countries. The WannaCry virus exploits a vulnerability to Microsoft Windows that was originally developed by the U.S. National Security Agency and operates by encrypting a victim’s data and demanding payment of a ransom in exchange for data recovery.

    Ransomware threatens institutions worldwide, but the risks for businesses are starker—potentially catastrophic. This Article provides corporate executives with much of what they need to know about the evolving threats of malware and ransomware. We provide a brief definition and history of ransomware; look at the history of hospitals as ransomware targets; describe the WannaCry virus, what is known about its development, method of action, and those who are believed to have deployed it; discuss the Petya and NotPetya attacks and municipal ransomware attacks; review the myriad and unique risks that ransomware poses for corporations; discuss the duties and responsibilities of corporate directors and the Ormerod-Trautman data security economic model; and review the cybersecurity legal landscape with a particular focus on corporate best practices.

  12. 2018

    A Descriptive Analysis of the Fourth Amendment and the Third-Party Doctrine in the Digital Age

    Article

    28 Albany Law Journal of Science & Technology 73 (2018)(with Lawrence J. Trautman)

    The Court’s twenty-first-century digital Fourth Amendment cases and its older third-party doctrine were on a collision course in Carpenter. This Article maps both lines and asks which sensitive digital information is left unprotected.

    Abstract

    There are few areas of constitutional law that raise scholars’ ire and trouble jurists like the Fourth Amendment’s third-party doctrine. Making sense of the Court’s distinctions between content and metadata and between personal communications and business records was already difficult with physical documents and analog technologies. But the proliferation of digital technologies has rendered obsolete the factual predicates underpinning those distinctions, and courts have struggled mightily with adapting third-party rules forged over thirty years ago to new technologies.

    At the same time, the Supreme Court has become more explicit in fashioning distinct Fourth Amendment rules for digital technologies. In a trio of 21st-century decisions, the Court has made clear—often by overwhelming votes—that the old rules no longer suffice. These two strains of Fourth Amendment law are on a collision course—a collision scheduled for the Court’s October 2017 Term in Carpenter v. United States.

    In this article, we first review the Court’s 21st-century digital Fourth Amendment jurisprudence to tease out the Court’s differential treatment of digital technologies. We then turn to the existing third-party doctrine and attempt to make sense of the doctrine’s distinctions. We conclude by reviewing some types of sensitive digital information that potentially lack Fourth Amendment protection under current doctrine.

  13. 2018

    Industrial Cyber Vulnerabilities: Lessons from Stuxnet and the Internet of Things

    Article

    72 University of Miami Law Review 761 (2018)(with Lawrence J. Trautman)

    Stuxnet introduced a global threat of malware aimed at industrial control devices. This Article traces the vulnerabilities that followed from its code and from the proliferation of connected consumer devices.

    Abstract

    Cyber breaches continue at an alarming pace with new vulnerability warnings an almost daily occurrence. Discovery of the industrial virus Stuxnet during 2010 introduced a global threat of malware focused toward disruption of industrial control devices. With tremendous growth in both data and devices, a security nightmare appears more reasonable than not. The proliferation of novel consumer devices and increased Internet-dependent business and government data systems introduces vulnerabilities of unprecedented magnitude. This paper adds to our understanding of the development of cyber vulnerabilities resulting directly from the Stuxnet code and its progeny and from widespread malware exposure associated with the Internet of Things.

  14. 2017

    Corporate Directors’ and Officers’ Cybersecurity Standard of Care: The Yahoo Data Breach

    Article

    66 American University Law Review 1231 (2017)(with Lawrence J. Trautman)

    Yahoo’s disclosure of two record-setting breaches during a pending acquisition raises questions about directors’ duties to provide security, to monitor, and to disclose — and about who bears inherited cyber liability.

    Abstract

    On September 22, 2016, Yahoo! Inc. announced that a data breach and theft of information from over 500 million user accounts had taken place during 2014, marking the largest data breach ever at the time. Just two months before Yahoo disclosed its 2014 data breach, it announced a proposed sale of the company’s core business to Verizon Communications. Then, during mid-December 2016, Yahoo announced that another 1 billion customer accounts had been compromised during 2013, a new record for largest data breach.

    Social media and electronic commerce websites face significant risk factors, and an acquirer may inherit cyber liability and vulnerabilities. The fact pattern in this announced acquisition raises a number of important corporate governance issues: whether Yahoo’s conduct leading up to the data breaches and its subsequent conduct constituted a breach of the duty to shareholders to provide security, the duty to monitor, the duty to disclose, or some combination thereof; the impact on Verizon shareholders of the acquisition price renegotiation and Verizon’s assumption of post-closing cyber liabilities; and whether more drastic compensation clawbacks for key Yahoo executives would be appropriate.