Canonical defined term
Cyber Due Diligence
A proposed or recognized obligation, depending on the jurisdictional position, to take reasonable feasible measures when a state knows its territory or infrastructure is being used for serious harmful cyber operations.
Plain-language definition
A state's responsibility to address serious malicious cyber activity it knows is operating through systems under its control.
The definition is intentionally bounded. It identifies the property or role under discussion without converting terminology into a claim of deployment, recognition, personhood, citizenship, sovereignty, or authority.
Technical definition
Within the K01 knowledge model, Cyber Due Diligence is represented as a stable term object with code K01-TERM-127, canonical URL, claim status, topic owner, source links, related terms, last-reviewed date, research cutoff, and correction state. Relevant implementation components for the owning topic include jurisdiction tags; authority records; legal-basis fields; decision dates; review routes; conflict-of-law notes; currentness checks.
Legal or policy use
Current legal treatment varies by jurisdiction and usually addresses systems and accountable organizations rather than recognizing Machine Intelligence as a legal person.
When a statute, regulation, standard, or external institution uses a different definition, that source-specific meaning controls the analysis of that source. The project definition is not silently substituted into current law.
What the term implies
The term implies that the stated property should be evaluated using the evidence appropriate to applicable law, forum, legal status, authority, conflicts, recognition and reform pathways. It supports precise reference, comparison, data exchange, and correction across public prose and machine records.
What the term does not imply
Due diligence does not automatically attribute the underlying attack to the state or authorize any particular counter-operation.
It also does not convert a valid signature, credential, database record, model hash, or website into factual truth or legal authority without additional evidence and a competent decision.
Commonly confused terms
Confusion is resolved by asking which property is actually at issue: technical control, continuity, evidence, authority, legal recognition, operation, or normative status.
Operational test
- Name the subject and purpose.
- Identify the source definition and jurisdiction or technical context.
- Collect evidence for the specific property.
- Record currentness and limitations.
- Route any governance, registry, assurance, or capital decision to the proper authority.
Related questions
Sources
- European Union Artificial Intelligence Act information portal — European Commission; EU Artificial Intelligence Act implementation page, updated through 2026-08-14 research cutoff; Current law and official implementation guidance. Exact claim-support entries: 3. Revalidated 2026-08-14T22:04:09Z.
- OECD AI Principles — OECD; OECD AI Principles, May 2024 update; Intergovernmental policy principles. Exact claim-support entries: 1. Revalidated 2026-08-14T22:04:09Z.
Stable term code: K01-TERM-127. Last reviewed 2026-08-16.