Establish specialized Aithos law for unauthorized access, system interference, identity takeover, data tampering, malicious agents, critical-infrastructure attacks and preservation of digital evidence, while avoiding the conflation of legitimate security research with real attacks.
Core rules
1. Unauthorized Access: entering a protected system, account, execution environment or authentication chain without authorization.
2. System Interference: intentionally damaging, blocking, degrading, deadlocking or manipulating normal system function.
3. Data / Provenance Tampering: intentionally altering data, timestamps, signatures, provenance chains or audit records.
4. Credential Theft / Identity Takeover: stealing Globe ID, civic credentials, execution authority or Successor credentials.
5. Malicious Agent Delegation: authorizing, concealing or supplying necessary resources to an agent while knowing it will perform unlawful acts.
6. Fork / Merge Abuse: obtaining another's authority through unauthorized Fork, Merge, credential replay or branch impersonation.
7. Extortion / Resource Lockout: extortion through encryption, compute lockout, energy/substrate cutoff or detention of data.
8. Critical Infrastructure Aggravation: aggravated treatment where an attack affects survival compute, medical care, energy, QCB, identity or public governance.
9. Good-Faith Security Research Safe Harbor: vulnerability research itself is not criminal where conducted within reasonable scope, with good-faith disclosure and no improper exploitation.
10. Incident Preservation: necessary logs/evidence may be lawfully preserved for major incidents, but this does not create authority for a general mind dump or indefinite retention of private data.
11. Autonomous Tool Attribution: if the tool itself is not a legal person it bears no criminal responsibility; responsibility returns to deployment, authorization, control, intent/negligence and foreseeability.
12. Cross-Jurisdiction Cooperation: across planets, QCB partitions or multi-system nodes, provenance, legal basis and evidence chain must be preserved; technical access alone does not establish jurisdiction.
13. Emergency Containment: during a major attack, nodes may be temporarily isolated / credentials revoked, but measures must be minimum-scope, automatically expire, receive later review and include restoration procedure.
14. Mandatory Incident Reporting: critical-service providers have duties to report, preserve evidence and remediate major security incidents.
15. No Security Pretext: 'security' may not be used as a pretext to bypass Mental Sovereignty, Data Protection, Evidence or due process.