{
  "canonicalClaimUrl": "https://xn--mwe.com/questions/can-private-company-lawfully-hack-back/#clm-k04-q-078",
  "claimStatus": "DISPUTED",
  "correctionStatus": "CURRENT K04 RECORD",
  "id": "CLM-K04-Q-078",
  "lastReviewed": "2026-08-15",
  "machineRecordUrl": "https://xn--mwe.com/data/claims/clm-k04-q-078.json",
  "name": "Can a private company lawfully hack back?",
  "ownerAnchor": "clm-k04-q-078",
  "ownerId": "K01-Q-078",
  "ownerRoute": "/questions/can-private-company-lawfully-hack-back/",
  "ownerType": "question",
  "proposition": "Technical capability is not legal authority. Whether a private company may access or disrupt an external system depends on domestic computer-crime law, explicit government authorization, contractual scope, location, target status, international law, effects, oversight, and responsibility. Independent retaliation creates acute attribution, third-party harm, escalation, and liability risks.",
  "qualification": "The answer preserves contested legal states and does not create mission authority, target status, or verified current law.",
  "releaseId": "K12-2026-08-16",
  "releaseVersion": "2.1.0",
  "researchCutoff": "2026-08-15",
  "scope": "K04 direct answer for Can a private company lawfully hack back?",
  "slug": "clm-k04-q-078",
  "sourceIds": [
    "SRC-EU-AI-ACT",
    "SRC-OECD-AI-PRINCIPLES"
  ],
  "sourceSections": [
    {
      "section": "Application timeline",
      "sourceId": "SRC-EU-AI-ACT",
      "supportRelationship": "QUALIFIES OR SUPPORTS WITHIN STATED SCOPE",
      "supports": "The Act became broadly applicable on 2026-08-02, with listed exceptions and later transition dates for specified high-risk systems.",
      "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai#application-timeline"
    },
    {
      "section": "AI Omnibus simplification timeline",
      "sourceId": "SRC-EU-AI-ACT",
      "supportRelationship": "QUALIFIES OR SUPPORTS WITHIN STATED SCOPE",
      "supports": "The AI Omnibus entered into force on 2026-07-27 and set 2027-12-02 and 2028-08-02 dates for specified high-risk categories.",
      "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai#how-has-the-commission-simplified-the-implementation-of-the-ai-act"
    },
    {
      "section": "Governance and enforcement",
      "sourceId": "SRC-EU-AI-ACT",
      "supportRelationship": "QUALIFIES OR SUPPORTS WITHIN STATED SCOPE",
      "supports": "From 2026-08-02 the AI Office and Member State authorities are responsible for implementation, supervision, and enforcement under the official timeline.",
      "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai#governance-and-enforcement"
    },
    {
      "section": "Principles overview",
      "sourceId": "SRC-OECD-AI-PRINCIPLES",
      "supportRelationship": "QUALIFIES OR SUPPORTS WITHIN STATED SCOPE",
      "supports": "The principles promote innovative and trustworthy AI consistent with human rights and democratic values and guide policy development.",
      "url": "https://oecd.ai/en/ai-principles"
    }
  ],
  "type": "ClaimRecord"
}
