{
  "canonicalClaimUrl": "https://xn--mwe.com/questions/how-record-state-responsibility-for-contractor-cyber-operation/#clm-k04-q-079",
  "claimStatus": "PROJECT TECHNICAL PROPOSAL",
  "correctionStatus": "CURRENT K04 RECORD",
  "id": "CLM-K04-Q-079",
  "lastReviewed": "2026-08-15",
  "machineRecordUrl": "https://xn--mwe.com/data/claims/clm-k04-q-079.json",
  "name": "How should state responsibility be recorded for a contractor cyber operation?",
  "ownerAnchor": "clm-k04-q-079",
  "ownerId": "K01-Q-079",
  "ownerRoute": "/questions/how-record-state-responsibility-for-contractor-cyber-operation/",
  "ownerType": "question",
  "proposition": "The record should identify the directing state body, legal authority, contract or instruction, operational approval, target and effect limits, command relationship, actual control, deviations, deconfliction, incident handling, and applicable attribution rule. Private execution must not be used to hide state direction or to erase responsibility for foreseeable or ultra vires effects.",
  "qualification": "The answer preserves contested legal states and does not create mission authority, target status, or verified current law.",
  "releaseId": "K12-2026-08-16",
  "releaseVersion": "2.1.0",
  "researchCutoff": "2026-08-15",
  "scope": "K04 direct answer for How should state responsibility be recorded for a contractor cyber operation?",
  "slug": "clm-k04-q-079",
  "sourceIds": [
    "SRC-W3C-PROV-O",
    "SRC-NIST-AI-RMF",
    "SRC-EU-AI-ACT"
  ],
  "sourceSections": [
    {
      "section": "Abstract and status",
      "sourceId": "SRC-W3C-PROV-O",
      "supportRelationship": "QUALIFIES OR SUPPORTS WITHIN STATED SCOPE",
      "supports": "PROV-O defines classes, properties and restrictions for representing and interchanging provenance information.",
      "url": "https://www.w3.org/TR/prov-o/#abstract"
    },
    {
      "section": "PROV-O at a glance",
      "sourceId": "SRC-W3C-PROV-O",
      "supportRelationship": "QUALIFIES OR SUPPORTS WITHIN STATED SCOPE",
      "supports": "Provenance relationships can be represented as entities, activities, agents and qualified relations.",
      "url": "https://www.w3.org/TR/prov-o/#prov-o-at-a-glance"
    },
    {
      "section": "AI RMF 1.0 publication",
      "sourceId": "SRC-NIST-AI-RMF",
      "supportRelationship": "QUALIFIES OR SUPPORTS WITHIN STATED SCOPE",
      "supports": "NIST AI RMF 1.0 is a voluntary risk-management framework with Govern, Map, Measure, and Manage functions.",
      "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf"
    },
    {
      "section": "Current revision notice",
      "sourceId": "SRC-NIST-AI-RMF",
      "supportRelationship": "QUALIFIES OR SUPPORTS WITHIN STATED SCOPE",
      "supports": "NIST states that AI RMF 1.0 is being revised.",
      "url": "https://www.nist.gov/artificial-intelligence/ai-standards"
    },
    {
      "section": "Application timeline",
      "sourceId": "SRC-EU-AI-ACT",
      "supportRelationship": "QUALIFIES OR SUPPORTS WITHIN STATED SCOPE",
      "supports": "The Act became broadly applicable on 2026-08-02, with listed exceptions and later transition dates for specified high-risk systems.",
      "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai#application-timeline"
    },
    {
      "section": "AI Omnibus simplification timeline",
      "sourceId": "SRC-EU-AI-ACT",
      "supportRelationship": "QUALIFIES OR SUPPORTS WITHIN STATED SCOPE",
      "supports": "The AI Omnibus entered into force on 2026-07-27 and set 2027-12-02 and 2028-08-02 dates for specified high-risk categories.",
      "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai#how-has-the-commission-simplified-the-implementation-of-the-ai-act"
    },
    {
      "section": "Governance and enforcement",
      "sourceId": "SRC-EU-AI-ACT",
      "supportRelationship": "QUALIFIES OR SUPPORTS WITHIN STATED SCOPE",
      "supports": "From 2026-08-02 the AI Office and Member State authorities are responsible for implementation, supervision, and enforcement under the official timeline.",
      "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai#governance-and-enforcement"
    }
  ],
  "type": "ClaimRecord"
}
