The Reverse Spider-Man Principle: With Great Responsibility Comes Great Power


[I blogged an early draft of this essay three months ago, but I've revised it extensively since then. I'd love to hear any suggestions people might have; I still have a few weeks to edit it before it's put to bed. You can also read the whole thing in a 16-page PDF.]

An entity—a landlord, a manufacturer, a phone company, a credit card company, an Internet platform, a self-driving car manufacturer—is making money off its customers' activities. Some of those customers are using the entity's services in ways that are criminal or tortious. Should the entity be held responsible, legally or morally, for its role (however unintentional) in facilitating its customers' activities? This question has famously been at the center of the debates about platform content moderation,[1] but it can come up in other contexts as well.[2]

This is a broad question, and there might be no general answer. (Perhaps it is two broad questions—one about legal responsibility and one about moral responsibility—but I think the two are connected enough to be worth discussing together.) In this essay, though, I'd like to focus on one downside of answering it "yes": What I call the Reverse Spider-Man Principle—with great responsibility comes great power.[3] Whenever we are contemplating holding entities responsible for their customers' behavior, we should think whether we want to empower such entities to surveil, investigate, and police their customers, both as to that behavior and as to other behavior.[4]

Of course, some of the entities with whom we have relationships do have power over us. Employers are a classic example: In part precisely because they are responsible for our actions (through principles such as respondeat superior or negligent hiring/supervision liability), they have great power to control what we do, both on the job and in some measure off the job.[5] Doctors have the power to decide what prescription drugs we can buy, and psychiatrists have the responsibility (and the power) to report when their patients make credible threats against third parties.[6] And of course we are all within the power of police officers, who have the professional though not the legal responsibility to prevent and investigate crime.

On the other hand, we generally don't expect to be in such subordinate relationships to phone companies, or to manufacturers selling us products. We generally don't expect them to monitor how we use their products or services (except in rare situations where our use of a service interferes with the operation of the service itself), or to monitor our politics to see if we are the sorts of people who might use the products or services badly. At most, we expect some establishments to perform some narrow checks at the time of a sale, often defined specifically and clearly by statute, for instance by laws that require bars not to serve people who are drunk or that require gun dealers to perform background checks on buyers.[7]

Many of us value the fact that, in service-oriented economies, companies try hard to do what it takes to keep customers (consider the mentality that "the customer is always right"), rather than expecting customers to comply with the companies' demands. But as we demand more "responsibility" from such providers, we push them to exercise more power over us, and thus fundamentally change the nature of their relationships with us. If companies are required to police the use or users of their products and services—what scholars have called "third-party policing"[8]—then people's relationship with them may become more and more like people's relationship with the police.

[I.] The Virtues of Irresponsibility

Let me begin by offering three examples of where some courts have balked at imposing legal liability, precisely because they didn't want to require or encourage businesses to exercise power over their customers.

[A.] Telephone and Telegraph Companies

The first came in the early 1900s, where some government officials demanded that telephone and telegraph companies block access to their services by people suspected of running illegal gambling operations. Prosecutors could have gone after the bookies, of course, and they did. But they also argued that the companies should have done the same—and indeed sometimes prosecuted the companies for allowing their lines to be used for such criminal purposes.

No, held some courts (though not all[9]); to quote one:

A railroad company has a right to refuse to carry a passenger who is disorderly, or whose conduct imperils the lives of his fellow passengers or the officers or the property of the company. It would have no right to refuse to carry a person who tendered or paid his fare simply because those in charge of the train believed that his purpose in going to a certain point was to commit an offense. A railroad company would have no right to refuse to carry persons because its officers were aware of the fact that they were going to visit the house of [the bookmaker], and thus make it possible for him and his associates to conduct a gambling house.

Common carriers are not the censors of public or private morals. They cannot regulate the public and private conduct of those who ask service at their hands.[10]

If the telegraph or telephone company (or the railroad) were held responsible for the actions of its customers, the court reasoned, then it would acquire power—as "censor[] of public or private morals"—that it ought not possess.

[B.] E-Mail Systems

Now those companies were common carriers, denied such power (and therefore, those courts said, responsibility) by law. But consider a second example, Lunney v. Prodigy Services Co., a 1999 case in which the New York high court held that e-mail systems were immune from liability for allegedly defamatory material sent by their users.[11]

E-mail systems aren't common carriers, but the court nonetheless reasoned that they shouldn't be held responsible for failing to block messages, even if they had the legal authority to block them: An e-mail system's "role in transmitting e-mail is akin to that of a telephone company," the court held, "which one neither wants nor expects to superintend the content of its subscribers' conversations."[12] Even though e-mail systems aren't forbidden from being the censors of their users' communications, the court concluded that the law shouldn't pressure them into becoming such censors.

[C.] Landlords

Courts have likewise balked at imposing obligations on residential landlords that would encourage the landlords to surveil and police their tenants. Consider Castaneda v. Olsher, where a mobile home park tenant injured in a gang-related shootout involving another tenant sued the landlord, claiming it "had breached a duty not to rent to known gang members." No, said the California Supreme Court:

[W]e are not persuaded that imposing a duty on landlords to withhold rental units from those they believe to be gang members is a fair or workable solution to [the] problem [of gang violence], or one consistent with our state's public policy as a whole. . . .

If landlords regularly face liability for injuries gang members cause on the premises, they will tend to deny rental to anyone who might be a gang member or, even more broadly, to any family one of whose members might be in a gang.[13]

This would in turn tend to lead to "arbitrary discrimination on the basis of race, ethnicity, family composition, dress and appearance, or reputation," which may itself be illegal (so the duty would put the landlord in a damned-if-you-do-damned-if-you-don't position).

But even apart from such likely reactions by landlords being illegal, making landlords liable would jeopardize people's housing options and undermine their freedom even if they aren't gang members, putting them further in the power of their landlords: "families whose ethnicity, teenage children, or mode of dress or personal appearance could, to some, suggest a gang association would face an additional obstacle to finding housing." Likewise, even if landlords respond only by legally and evenhandedly checking all tenants' criminal histories, "refusing to rent to anyone with arrests or convictions for any crime that could have involved a gang" would "unfairly deprive many Californians of housing." This "likely social cost" helped turn the court against recognizing such a responsibility on the part of landlords.[14]

Other courts have taken similar views. In Francis v. Kings Park Manor, Inc., for instance, the Second Circuit sitting en banc refused to hold a landlord liable for its tenants' racial harassment of fellow tenants, partly because of concern that such responsibility would pressure landlords to exercise undue power over tenants:

[Under the alternative proposed by Francis,] prospective and current renters would confront more restrictive leases rife with in terrorem clauses, intensified tenant screening procedures, and intrusions into their dealings with neighbors, all of which could result in greater hostility and danger, even culminating in (or beginning with) unwarranted evictions.

Our holding should also be of special interest to those concerned with the evolution of surveillance by state actors or by those purporting to act at their direction. See Note 44, ante (warning against broad liability schemes that would encourage landlords to act as law enforcement).[15]

The New York intermediate appellate court took a similar view in Gill v. New York City Housing Authority, rejecting liability for tenant-on-tenant crime that plaintiff claimed might have been avoided had the landlord dealt better with a tenant's mental illness:

The practical consequences of an affirmance in this case would be devastating. The Housing Authority would be forced to conduct legally offensive and completely unwarranted "follow-up" of all those tenants within its projects known to have a psychiatric condition possibly, but it must be noted, not foreseeably, injurious to another tenant. Once the "follow-up" had been conducted, the Housing Authority would then be obligated to look into its crystal ball to access the likelihood of harm and then, where indicated, to take protective measures for which it had no expertise or authority. These would include dispensing medication, monitoring treatment, posting warnings (i.e., "Beware of your neighbor"), or evicting tenants. Given the options, eviction, which is described in the Housing Authority Management Manual as a "last resort," would become almost commonplace. Those with psychiatric disorders would be dispossessed from their low-income accommodations to live in the streets.[16]

And a New Jersey intermediate appellate court took the same view in Estate of Campagna v. Pleasant Point Properties, LLC, in rejecting a claim that landlords should be responsible for doing background checks on tenants:

Even assuming that defendants had performed a criminal background check of Strong and learned of his robbery conviction, there are significant public policy ramifications about what a rooming house would be expected to do with that information, if a legal duty to conduct a criminal background check of prospective residents were imposed.

"In deciding whether to recognize the existence of a duty of care . . . [courts] must bear in mind the broader implications that will flow from the imposition of a duty."  . . . The practical effects of creating a duty for rooming house owners to conduct criminal background checks of prospective residents might be either: (1) a need to disclose a new resident's criminal history to the other residents for their protection; or (2) a need to reject a prospective resident's application based upon the apparent criminal history. Both of these possible outcomes have debatable ramifications.

The first outcome raises policy concerns because sharing a new resident's criminal background with other residents would potentially violate his or her statutory right to privacy and potentially foster unnecessary fear and conflict.

As for the second likely consequence—outright rejection of an applicant based upon any criminal conviction—that outcome would surely inhibit the ability of persons with criminal histories to obtain affordable housing. . . .

Notably, although certain federal and state housing guidelines do allow property owners to conduct criminal background checks of prospective residents so long as they are not used in a discriminatory manner, such checks are not mandated.[17]

To be sure, the pattern here is not uniform. Sometimes landlords are held responsible, by statutes, ordinances, or tort law rules, for monitoring their tenants for potentially illegal behavior (such as distribution of drugs), for failing to evict tenants who are violating the law[18] (or even ones who are being victimized by criminals, and thus calling 911 too often[19]), for failing to warn co-tenants of tenants' past criminal records,[20] or even for renting to tenants who have criminal records.[21] But the result has indeed been what the courts quoted above warned about: Greater surveillance of tenants by landlords, and greater landlord power being exercised over tenants.[22]

[D.] The Limits of Complicity

One way of seeing these cases is as putting limits on concepts of complicity. The law does sometimes hold people liable for enabling or otherwise facilitating others' wrongful conduct, even in the absence of a specific wrongful purpose to aid such conduct;[23] consider tort law principles such as negligent hiring and negligent entrustment. But there are often good public policy reasons to limit this.

Sometimes those reasons stem from our sense of professional roles. We don't fault a doctor for curing a career criminal, even if as a result the criminal goes on to commit more crimes. It's not a doctor's job to choose who merits healing, or to bear responsibility for the consequences of successfully healing bad people.

Likewise, the legal system expects defense lawyers to do their best to get clients acquitted, and doesn't hold the lawyers responsible for the clients' future crimes. (Indeed, historically the legal system had allowed courts to order unwilling lawyers to represent indigent defendants.[24]) When there is public pressure on lawyers to refuse to represent certain clients, the legal establishment often speaks out against such pressure.[25]

And sometimes those reasons stem from our sense of who should and who shouldn't be "censors of public or private morals." The police may enforce gambling laws, or arrest gang members for gang-related crimes. The courts may enforce libel law. But various private companies, such as phone companies, e-mail services, and landlords shouldn't be pressured into doing so.[26]

[II.] Practical Limits on Private Companies' Power, in the Absence of Responsibility

Now of course many such companies (setting aside the common carriers or similarly regulated monopolies) have great power over whom to deal with and what to allow on their property, even when they aren't held responsible—by law or by public attitudes—for what happens on their property. In theory, for instance, Prodigy's owners could have decided that they wanted to kick off users who were using Prodigy e-mail for evil purposes: libel, racist speech, anti-capitalist advocacy, or whatever else. Likewise, some companies may decide not to deal with people who they view as belonging to hate groups, just because their owners think that's the right thing to do, entirely apart from any social or legal norms of responsibility.

But in practice, in the absence of responsibility (whether imposed by law or social norms), many companies will eschew such power, for several related reasons—even setting aside the presumably minor loss of business from the particular customers who are ejected:

  1. Policing customers takes time, effort, and money.
  2. Policing customers risks error and bad publicity associated with such error, which could alienate many more customers than the few who are actually denied service.
  3. Policing customers in particular risks allegation of discriminatory policing, which may itself be illegal and at least is especially likely to yield bad publicity.
  4. Policing some customers will often lead to public demands for broader policing: "You kicked group X, which we sort of like, off your platform; why aren't you also kicking off group Y, whom we loathe and whom we view as similar to X?"[27]
  5. Conversely, a policy of "we don't police our customers"—buttressed by social norms that don't require (or even affirmatively condemn) such policing—offers the company a simple response to all such demands.
  6. Policing customers creates tension even with customers who aren't violating the company's rules—people often don't like even the prospect that some business is judging what they say, how they dress, or whom they associate with.
  7. Policing customers gives an edge to competitors who publicly refuse to engage in such policing, and sell their services as "our only job is to serve you, not to judge you or eject you."

Imposing legal responsibility on such companies can thus pressure them to exercise power even when they otherwise wouldn't have. And that is in some measure so even if responsibility is accepted as a broad moral norm, enforced by public pressure, not just a legal norm. That norm would increase the countervailing costs of non-policing. It would decrease the costs of policing: For instance, the norm and the corresponding pressure will likely act on all major competitors, so the normal competitive pressures encouraging a "the customer is always right" attitude will be sharply reduced. And at some point, might become standard against which the reasonableness of behavior is measured, either as a legal matter or as a matter of public reaction.

Likewise, when people fault a company for errors or perceived discrimination, the company can use the norm as cover, for instance arguing that "regrettably, errors will happen, especially when one has to do policing at scale." "After all, you've told us you want us to police, don't you?"

Accepting such norms of responsibility can also change the culture and organization of the companies. It would habituate the companies to exercising such power. It would create bureaucracies within the companies staffed with people whose jobs rely on exercising the power—and who might be looking for more reasons to exercise that power.

And by making policing part of the companies' official mission, it would subtly encourage employees to make sure that the policing is done effectively and comprehensively, and not just at the minimum that laws or existing social norms command. Modest initial policing missions, based on claims of responsibility for a narrow range of misuse, can thus creep into much more comprehensive use of such powers.[28]

[III.] The Future of Responsibility, When Products Involve Constant
Customer/Seller Interaction

So far, there has been something of a constraint on calls for business "responsibility" for the actions of their customers: Such calls have generally involved ongoing business-customer relationships, for instance when Facebook can monitor what its users are posting (or at least respond to other users' complaints).

Occasionally, there have been calls for businesses to simply not deal with certain people at the outset—consider Castaneda v. Olsher, where plaintiffs argued that defendants just shouldn't have rented the mobile homes to likely gang members. But those have been rare.

Few people, for instance, would think of arguing that car dealers should refuse to sell cars to suspected gang members who might use the cars for drive-by shootings or for crime getaways.[29] Presumably most people would agree that even gang members are entitled to buy and use cars in the many lawful ways that cars can be used, and that car dealers shouldn't try to deny gang members access to cars.[30] If the legislature wants to impose such responsibilities, for instance by banning sales of guns to felons or of spray paint to minors, then presumably the legislature should create such narrow and clearly defined rules, which rely on objective criteria that don't require seller judgment about which customers merely seem likely to be dangerous.

But now more and more products involve constant interaction between the customer and the seller.[31] Say, for instance, that I'm driving a partly self-driving Tesla that is in constant contact with the company. Recall how Airbnb refused to rent to people who it suspected were going to a "Unite the Right" rally.[32] If that is seen as proper—and indeed as mandated by corporate social responsibility principles—then one can imagine similar pressure on Tesla to stop Teslas from driving to the rally (or at least to stop such trips by Teslas of those people suspected of planning to participate in the rally).[33]

To be sure, this might arouse some hostility, because it's my car, not Tesla's. But of course Airbnb was refusing to arrange bookings for other people's properties, not its own. Airbnb's rationale was that it had a responsibility to stop its service from being used to promote a racist, violent event.[34] But why wouldn't Tesla then have a responsibility to stop its intellectual property and its computers (assuming they are in constant touch with my car) from being used the same way?

To be sure, Tesla's sale contract might be seen as implicitly assuring that its software will always try to get me to my destination. But that is just a matter of the contract. If companies are seen as responsible for the misuse of their services, why wouldn't they have an obligation to draft contracts that let them fulfill that responsibility?

Now maybe some line might be drawn here: Perhaps, for instance, we might have a special rule for services that are ancillary to the sale of goods (Tesla, yes, Airbnb, no), under which the transfer of the goods carries with it the legal or moral obligation to keep providing the services even when one thinks the goods are likely to be used in illegal or immoral ways. (Though what if I lease my Tesla rather than buying it outright?) Or at least we might say there's nothing irresponsible about a product seller refusing to police customers' continuing use of the services that make those products work.

But that would just be a special case of the broader approach that I'm suggesting here: For at least some kinds of commercial relationships, a business should not be held responsible for what its customers do—because we don't want it exercising power over its customers' actions.

[IV.] The Future of Responsibility and Big Data Analysis

There had historically also been another constraint on such calls for business "responsibility": It's often very hard for a business to determine what a customer's plans are. Even if there is social pressure to get businesses to boycott people who associate with supposed "hate groups"[35]—or even if the owners of a business (say, Airbnb) just want to engage in such a boycott—how is a business to know what groups a person associates with, at least unless the person is famous, or unless someone expressly complains about the person to the business?[36]

But of course these days we can get a lot more data about people, just by searching on the Internet and through some other databases (some of which may cost money, but well within the means of most big businesses). To be sure, this might yield too much data about each prospective customer for a typical business to process at scale. But AI technology may well reduce the cost of such processing, by enabling computers to quickly and cheaply sift through all that data, and produce some fairly reliable estimate: Joe Schmoe is 93% likely to be closely associated with one of the groups that a business is being pressured to boycott. At that point, the rhetoric of responsibility may suggest that what now can be done (identify supposedly bad potential clients) should be done.

Consider one area in which technological change has sharply increased the scope of employer responsibility—and constrained the freedom of many prospective employees. American tort law has long held employers for negligent hiring, negligent supervision, or negligent retention when they unreasonably hire employees who are incompetent at their jobs (in a way that injures third parties)[37] or who have a tendency to commit crimes that are facilitated by the job.[38] But until at least the late 1960s, this hasn't required employers to do nationwide background checks, because they were seen as too expensive, and thus "would place an unfair burden on the business community."[39] Even someone who had been convicted of a crime could thus often start over and get a job, at least in a different locale, without being dogged by his criminal record.

Now, though, as nationwide employee background checks have gotten cheap, they have in effect become mandatory for many employers: "Lower costs and easier access provide [an] incentive to perform [background] checks, potentially leaving employers who choose not to conduct such checks in a difficult position when trying to prove they were not negligent in hiring."[40] As a result, people with criminal records often find it especially hard to get jobs. Perhaps that's good, given the need to protect customers from criminal attack, or perhaps it's bad, given the social value of giving people a way to get back to productive, law-abiding life, or perhaps it's a mix of both. But my key point here is that, while the employer's responsibility for screening his employees has formally remained the same—the test is reasonable care—technological change has required employers to exercise that responsibility in a way that limits the choices of prospective employees much more than it did before.

Similarly, commercial property owners have long been held responsible for taking reasonable—which is to say, cost-effective—measures to protect their business visitors from criminal attack. Thus, as video surveillance cameras became cheap enough to be cost effective, courts began to hold that defendants may be negligent for failing to install surveillance cameras,[41] even though such surveillance would not have been required when cameras were much more expensive.

We can expect to see something similar as technological change makes other forms of investigation and surveillance—not just of employees or of outside intruders, but of customers—more cost-effective. If it is a company's responsibility to make sure that bad people don't use the company's products or services for bad purposes, then as technology allows companies to investigate their clients' affiliations and beliefs more cost-effectively, companies will feel pressure to engage in such investigation.


"Responsibility" is often viewed as an unalloyed good. (Who, after all, wants to be known as "irresponsible"?) Sometimes we should indeed hold people and organizations legally or morally responsible for providing tools that others misuse. And of course people and organizations are entitled to choose to accept such responsibility, even if they are not pressured to do so.[42]

My point here is simply that such responsibility has an important cost, and refusal to take responsibility has a corresponding benefit. Those who are held responsible for what we do will need to assert their power over us, surveilling, second-guessing, and blocking our decisions. A phone company or an e-mail provider or a landlord that is responsible for what we do with its property will need to control whether we are allowed to use its property, and control what we do with that property; likewise for a social media platform or a driverless car manufacturer. If we want freedom from such control, we should try to keep those companies from being held responsible for their users' behavior.

There is value in businesses being encouraged to "stay in their lane," with their lane being defined as providing a particular product or service. They should be free to say that they "are not the censors of public or private morals," and that they should not "regulate the public and private conduct of those who ask service at their hands";[43] even if, unlike with telephone and telegraph cases, they have the legal right to reject some customers, they should be free to decline to exercise that right. Sometimes the responsibility for stopping misuse of the product should be placed solely on the users, and on law enforcement—not on businesses that are enlisted as legally largely unsupervised private police forces, doing what the police are unable to do, or (as with speech restrictions) are constitutionally forbidden from doing.


