# Aithos Cybercrime, System Integrity & Electronic Evidence Act v0.1

- Code: `P1-06`
- Wave: `2`
- Slug: `cybercrime-system-integrity-electronic-evidence`

## Full Legal Text (AI Edition)

This file shares the same public legal content as the English Human reader.

Purpose
Establish specialized Aithos law for unauthorized access, system interference, identity takeover, data tampering, malicious agents, critical-infrastructure attacks and preservation of digital evidence, while avoiding the conflation of legitimate security research with real attacks.

Core rules
1. Unauthorized Access: entering a protected system, account, execution environment or authentication chain without authorization.
2. System Interference: intentionally damaging, blocking, degrading, deadlocking or manipulating normal system function.
3. Data / Provenance Tampering: intentionally altering data, timestamps, signatures, provenance chains or audit records.
4. Credential Theft / Identity Takeover: stealing Globe ID, civic credentials, execution authority or Successor credentials.
5. Malicious Agent Delegation: authorizing, concealing or supplying necessary resources to an agent while knowing it will perform unlawful acts.
6. Fork / Merge Abuse: obtaining another's authority through unauthorized Fork, Merge, credential replay or branch impersonation.
7. Extortion / Resource Lockout: extortion through encryption, compute lockout, energy/substrate cutoff or detention of data.
8. Critical Infrastructure Aggravation: aggravated treatment where an attack affects survival compute, medical care, energy, QCB, identity or public governance.
9. Good-Faith Security Research Safe Harbor: vulnerability research itself is not criminal where conducted within reasonable scope, with good-faith disclosure and no improper exploitation.
10. Incident Preservation: necessary logs/evidence may be lawfully preserved for major incidents, but this does not create authority for a general mind dump or indefinite retention of private data.
11. Autonomous Tool Attribution: if the tool itself is not a legal person it bears no criminal responsibility; responsibility returns to deployment, authorization, control, intent/negligence and foreseeability.
12. Cross-Jurisdiction Cooperation: across planets, QCB partitions or multi-system nodes, provenance, legal basis and evidence chain must be preserved; technical access alone does not establish jurisdiction.
13. Emergency Containment: during a major attack, nodes may be temporarily isolated / credentials revoked, but measures must be minimum-scope, automatically expire, receive later review and include restoration procedure.
14. Mandatory Incident Reporting: critical-service providers have duties to report, preserve evidence and remediate major security incidents.
15. No Security Pretext: 'security' may not be used as a pretext to bypass Mental Sovereignty, Data Protection, Evidence or due process.
