{
  "authorityState": "BOUNDED PRIVATE DEFENSE; NO GENERAL EXTERNAL CYBER OR COUNTER-UAS FORCE AUTHORITY",
  "canonicalUrl": "https://xn--mwe.com/law/matrices/united-states-private-critical-infrastructure-operator/",
  "id": "JMX-K05-US-PRIVATE",
  "name": "United States — private critical-infrastructure operator",
  "qualification": "Not legal advice; sector, state, local, contract and emergency authorities may alter a case.",
  "releaseId": "K12-2026-08-16",
  "rows": [
    {
      "boundary": "Protect owned or authorized systems; no general authority to access third-party systems.",
      "issue": "Internal cyber defense",
      "status": "GENERALLY AVAILABLE SUBJECT TO LAW, CONTRACT, PRIVACY, SAFETY AND SECTOR RULES"
    },
    {
      "boundary": "The August 2026 federal program requires contractual participation, federal control, package approval and written direction.",
      "issue": "Cyber surveillance or effects outside owned systems",
      "status": "REQUIRES SPECIFIC GOVERNMENT OR OTHER COMPETENT AUTHORITY"
    },
    {
      "boundary": "Detection does not automatically authorize interception, interference, seizure or destruction.",
      "issue": "UAS detection and tracking",
      "status": "ACTOR-, METHOD- AND DATA-SPECIFIC"
    },
    {
      "boundary": "47 U.S.C. §333 prohibits willful or malicious interference; identify an express authority before design or use.",
      "issue": "RF jamming",
      "status": "NO GENERAL PRIVATE AUTHORITY IDENTIFIED"
    },
    {
      "boundary": "A proposed restriction process is not final mitigation authority.",
      "issue": "Critical-infrastructure airspace restriction",
      "status": "FAA PROPOSED PETITION PROCESS AT K05 CUTOFF"
    }
  ],
  "slug": "united-states-private-critical-infrastructure-operator",
  "sourceIds": [
    "SRC-WH-CYBER-CRIME-MEMO-2026",
    "SRC-FAA-CI-UAS-NPRM-2026",
    "SRC-USC-47-333"
  ]
}
