[
  {
    "authorityState": "BOUNDED PRIVATE DEFENSE; NO GENERAL EXTERNAL CYBER OR COUNTER-UAS FORCE AUTHORITY",
    "id": "JMX-K05-US-PRIVATE",
    "name": "United States — private critical-infrastructure operator",
    "qualification": "Not legal advice; sector, state, local, contract and emergency authorities may alter a case.",
    "rows": [
      {
        "boundary": "Protect owned or authorized systems; no general authority to access third-party systems.",
        "issue": "Internal cyber defense",
        "status": "GENERALLY AVAILABLE SUBJECT TO LAW, CONTRACT, PRIVACY, SAFETY AND SECTOR RULES"
      },
      {
        "boundary": "The August 2026 federal program requires contractual participation, federal control, package approval and written direction.",
        "issue": "Cyber surveillance or effects outside owned systems",
        "status": "REQUIRES SPECIFIC GOVERNMENT OR OTHER COMPETENT AUTHORITY"
      },
      {
        "boundary": "Detection does not automatically authorize interception, interference, seizure or destruction.",
        "issue": "UAS detection and tracking",
        "status": "ACTOR-, METHOD- AND DATA-SPECIFIC"
      },
      {
        "boundary": "47 U.S.C. §333 prohibits willful or malicious interference; identify an express authority before design or use.",
        "issue": "RF jamming",
        "status": "NO GENERAL PRIVATE AUTHORITY IDENTIFIED"
      },
      {
        "boundary": "A proposed restriction process is not final mitigation authority.",
        "issue": "Critical-infrastructure airspace restriction",
        "status": "FAA PROPOSED PETITION PROCESS AT K05 CUTOFF"
      }
    ],
    "slug": "united-states-private-critical-infrastructure-operator",
    "sourceIds": [
      "SRC-WH-CYBER-CRIME-MEMO-2026",
      "SRC-FAA-CI-UAS-NPRM-2026",
      "SRC-USC-47-333"
    ]
  },
  {
    "authorityState": "LICENSE- AND FACILITY-SPECIFIC",
    "id": "JMX-K05-US-NRC-LEGACY",
    "name": "United States — NRC Part 50/52 security path",
    "qualification": "Not legal advice; The current license, orders, exemptions and NRC-approved program control.",
    "rows": [
      {
        "boundary": "Applies to covered systems and support systems within the licensee program and current license basis.",
        "issue": "Cybersecurity",
        "status": "10 CFR 73.54 PATH"
      },
      {
        "boundary": "Requirements, DBT assumptions, security plan and response force are facility-specific and safeguards-sensitive.",
        "issue": "Physical protection",
        "status": "10 CFR 73.55 PATH"
      },
      {
        "boundary": "Co-location or behind-the-meter supply does not erase nuclear security boundaries.",
        "issue": "Datacenter integration",
        "status": "REQUIRES BOUNDARY AND LICENSE REVIEW"
      },
      {
        "boundary": "Public strategy must omit sensitive target sets, response tactics, vulnerabilities and detailed layouts.",
        "issue": "Public disclosure",
        "status": "LIMITED BY SAFEGUARDS AND SECURITY INFORMATION RULES"
      }
    ],
    "slug": "united-states-nrc-part-50-52-security",
    "sourceIds": [
      "SRC-NRC-10CFR-73-54",
      "SRC-NRC-10CFR-73-55"
    ]
  },
  {
    "authorityState": "OPTIONAL FRAMEWORK; LICENSEE ELECTION AND NRC APPROVAL REQUIRED",
    "id": "JMX-K05-US-NRC-PART53",
    "name": "United States — NRC Part 53 and Part 73 Subpart J path",
    "qualification": "Not legal advice; Final-rule status is verified; application to a named reactor requires licensing analysis.",
    "rows": [
      {
        "boundary": "Performance-based does not mean unregulated or automatically staff-free.",
        "issue": "Physical protection",
        "status": "73.100 AVAILABLE TO QUALIFYING PART 53 LICENSEES THAT ELECT IT"
      },
      {
        "boundary": "Exact protected systems and controls remain facility-specific.",
        "issue": "Digital systems and networks",
        "status": "73.110 AVAILABLE WITH THE ELECTED FRAMEWORK"
      },
      {
        "boundary": "Program design remains subject to the rule, guidance, license and NRC oversight.",
        "issue": "Access authorization",
        "status": "73.120"
      },
      {
        "boundary": "K05 rejects a universal zero-armed-responder claim.",
        "issue": "Security staffing alternatives",
        "status": "FACILITY SHOWING REQUIRED"
      }
    ],
    "slug": "united-states-nrc-part-53-security",
    "sourceIds": [
      "SRC-NRC-ADVANCED-REACTOR-PHYSICAL-SECURITY",
      "SRC-NRC-10CFR-73-SUBPART-J-2026"
    ]
  },
  {
    "authorityState": "FEDERAL CONTROLLED PROGRAM; NOT GENERAL PRIVATE AUTHORITY",
    "id": "JMX-K05-US-FED-CYBER",
    "name": "United States — Federal CE-TCO cyber program",
    "qualification": "Not legal advice; Implementing guidance and actual program activity were not observed.",
    "rows": [
      {
        "boundary": "Eligibility criteria and procedures are established by federal program leadership.",
        "issue": "Participating company eligibility",
        "status": "CONTRACT, VETTING, TECHNICAL AND SECURITY STANDARDS"
      },
      {
        "boundary": "No action may be taken under the program before package approval.",
        "issue": "Operations package",
        "status": "FEDERAL REVIEW, WRITTEN APPROVAL AND DIRECTION REQUIRED"
      },
      {
        "boundary": "Federal law-enforcement, diplomatic, military, justice and intelligence equities are included.",
        "issue": "Deconfliction",
        "status": "MANDATORY"
      },
      {
        "boundary": "Operations likely to cause loss of life, serious injury, use of force or armed attack are outside approval authority.",
        "issue": "Critical outcomes",
        "status": "PROGRAM APPROVAL PROHIBITED"
      },
      {
        "boundary": "Unintentional U.S.-person, U.S.-system or other approved-parameter exceedance triggers stop and reporting procedures.",
        "issue": "Scope exceedance",
        "status": "CEASE, MINIMIZE AND NOTIFY"
      }
    ],
    "slug": "united-states-federal-ce-tco-cyber-program",
    "sourceIds": [
      "SRC-WH-CYBER-CRIME-MEMO-2026"
    ]
  },
  {
    "authorityState": "DODD 3000.09 APPLICABILITY-BOUND",
    "id": "JMX-K05-US-DOD-WEAPON",
    "name": "United States DoD — autonomous weapon-system scope",
    "qualification": "Not legal advice; The directive is not a universal autonomy standard.",
    "rows": [
      {
        "boundary": "Includes force application and automated target selection within directive scope.",
        "issue": "Covered systems",
        "status": "AUTONOMOUS AND SEMI-AUTONOMOUS WEAPON SYSTEMS"
      },
      {
        "boundary": "Do not map the directive as a governing autonomous-cyber standard.",
        "issue": "Autonomous cyberspace capability",
        "status": "EXPRESSLY EXCLUDED"
      },
      {
        "boundary": "Other safety, acquisition, cybersecurity and sector authorities may still apply.",
        "issue": "Unarmed or non-weapon autonomous system",
        "status": "EXPRESSLY EXCLUDED"
      },
      {
        "boundary": "Appropriate judgment, robust testing, transparent status, auditability and bounded behavior are scope-specific requirements.",
        "issue": "Human judgment and V&V/T&E",
        "status": "REQUIRED WITHIN COVERED WEAPON-SYSTEM SCOPE"
      }
    ],
    "slug": "united-states-dod-autonomous-weapon-system",
    "sourceIds": [
      "SRC-DODD-3000-09"
    ]
  },
  {
    "authorityState": "FACT- AND STATE-POSITION-DEPENDENT; MULTIPLE DOCTRINES DISPUTED",
    "id": "JMX-K05-INTERNATIONAL",
    "name": "International law — cyber and autonomous effects",
    "qualification": "Not legal advice; K05 records disputes and decision factors; it does not issue a dispositive international-law opinion.",
    "rows": [
      {
        "boundary": "Some states treat sovereignty as a primary rule; others use it as a principle tied to intervention or force thresholds.",
        "issue": "Sovereignty",
        "status": "STATE POSITIONS DIFFER"
      },
      {
        "boundary": "Technical intrusion alone does not answer every intervention question.",
        "issue": "Non-intervention",
        "status": "COERCION AND DOMAINE RÉSERVÉ ANALYSIS REQUIRED"
      },
      {
        "boundary": "Must not be treated as an unrestricted license for private retaliation.",
        "issue": "Countermeasures and necessity",
        "status": "STRICT CONDITIONS AND ATTRIBUTION QUESTIONS"
      },
      {
        "boundary": "Capability, intent, last opportunity, scale/effects, necessity and proportionality remain material.",
        "issue": "Self-defense and imminence",
        "status": "CONTESTED FOR ANTICIPATORY AND NON-STATE-ACTOR CASES"
      },
      {
        "boundary": "Formal government control can increase state attribution and accountability rather than privatize it away.",
        "issue": "State responsibility for contractors",
        "status": "DIRECTION, CONTROL AND ATTRIBUTION ANALYSIS"
      }
    ],
    "slug": "international-law-cyber-and-autonomous-effects",
    "sourceIds": [
      "SRC-WH-CYBER-CRIME-MEMO-2026"
    ]
  },
  {
    "authorityState": "UNAVAILABLE FOR CURRENT OPERATIONAL RELIANCE",
    "id": "JMX-K05-NONUS",
    "name": "Non-U.S. national authorities — review-required matrix",
    "qualification": "Not legal advice; Unavailable is a deliberate evidence state, not permission to infer the law.",
    "rows": [
      {
        "boundary": "The supplied reports are research inputs, not a substitute for current statutes, NCF doctrine, warrants, oversight and case-specific authority.",
        "issue": "United Kingdom",
        "status": "CURRENT OFFICIAL SOURCE REVIEW REQUIRED"
      },
      {
        "boundary": "Separate civilian defense, military cyber, sovereignty positions, EU law and national implementation.",
        "issue": "France / European Union",
        "status": "CURRENT OFFICIAL SOURCE REVIEW REQUIRED"
      },
      {
        "boundary": "Separate ASD/AFP authority, telecommunications law, warrants and private-operator limits.",
        "issue": "Australia",
        "status": "CURRENT OFFICIAL SOURCE REVIEW REQUIRED"
      },
      {
        "boundary": "Do not rely on report claims until current official texts and translations are reviewed.",
        "issue": "Republic of Korea and other surveyed states",
        "status": "CURRENT OFFICIAL SOURCE REVIEW REQUIRED"
      }
    ],
    "slug": "non-us-jurisdiction-review-required",
    "sourceIds": []
  }
]
