Roman Storm, co-founder of the privacy-focused cryptocurrency protocol Tornado Cash, has directly challenged the legal reasoning behind his conviction by pointing to the widespread use of mainstream artificial intelligence tools by the same sanctioned actors the government cited in his case.
In a post published on August 14, 2026, Storm argued that the Department of Justice’s (DOJ) theory—holding a software developer responsible when third parties misuse a neutral tool—should, if applied consistently, also ensnare Google and OpenAI.
Storm was convicted in August 2025 of one count of conspiracy to operate an unlicensed money-transmitting business after a multi-week trial in the Southern District of New York (SDNY).
Prosecutors alleged that Tornado Cash, the non-custodial mixing service he helped create, facilitated the movement of more than $1 billion in criminal proceeds, including funds linked to North Korean cyber operations.
The jury hung on the more serious charges of money laundering conspiracy and sanctions violations, leaving Storm exposed to a maximum of five years in prison on the remaining count.
Throughout the proceedings and afterward, Storm has maintained that he wrote open-source code and never controlled user funds or directed any illicit activity.
In his recent post, Storm quoted reporting on North Korean IT workers whose salaries help finance the regime’s weapons programs.
The workers, according to the investigation, routinely used OpenAI’s ChatGPT for writing, coding, and completing technical assignments, while preferring Google’s Gemini for image alteration and document forgery.
Storm noted that both companies have long been aware of such misuse yet continue to offer the services and collect subscription revenue.
Applying the same logic the government used against him, Storm asked whether Google and OpenAI should therefore be viewed as facilitating or enabling crime.
He called the idea of jailing their founders “absurd,” then immediately turned the point around: the identical theory underpins the prosecution of United States v. Roman Storm—build a neutral tool, bad actors abuse it, and the developer, not the criminal, faces prison.
“If that logic is absurd for Google and OpenAI,” he wrote, “it’s absurd for Roman Storm. You prosecute the criminal, not the toolmaker. Writing code is not a crime.”
To underscore the inconsistency, Storm proposed that authorities treat the AI companies the same way they treated him: issue sweeping subpoenas to employees, scour internal messages for any indication of knowledge about DPRK use, and seek indictments under the International Emergency Economic Powers Act that could carry twenty-year sentences.
The remarks arrive amid continuing debate over developer liability in both the crypto and broader technology sectors.
Advocates for Storm see his partial conviction as a dangerous precedent that threatens open-source and privacy-enhancing software.
Others contend that developers who design and promote services with clear knowledge of substantial criminal exploitation cross a legal threshold. Legislative efforts such as the Digital Asset Market CLARITY Act seek to draw clearer lines protecting code authors from liability for third-party misuse, though the bill’s prospects remain uncertain.
Storm’s comparison forces a broader question: when dual-use technology is abused by sanctioned actors, should responsibility fall on the toolmaker or solely on the criminals who choose to misuse it? By placing Google and OpenAI under the same theoretical spotlight that was trained on him, he has reframed a high-profile crypto case as a test of consistent legal principle.