[
  {
    "id": "ca",
    "name": "Canada",
    "tier": "demo",
    "status": "published",
    "last_full_review": "2026-08-04",
    "posture": {
      "d1_residency": {
        "position": "transfer-controls-not-localization",
        "strength": 3,
        "confidence": "verified",
        "note": "No general localization mandate in federal private-sector law; transfers permitted under accountability (PIPEDA Principle 4.1.3). Quebec Law 25 adds a privacy impact assessment requirement for communication outside Quebec."
      },
      "d2_ai_reg": {
        "position": "no-instrument",
        "strength": 0,
        "confidence": "verified",
        "note": "AIDA (Bill C-27) died on prorogation 2025-01-06; no successor tabled as of capture."
      },
      "d3_cloud_proc": {
        "position": "procurement-framework",
        "strength": 3,
        "confidence": "reported",
        "note": "GC cloud security profiles (PBMM) govern federal workloads up to Protected B — policy instrument, not statute."
      },
      "d4_export_access": {
        "position": "five-eyes-exposure",
        "strength": 4,
        "confidence": "judgment",
        "note": "US CLOUD Act reach via US-controlled providers; Five Eyes member. Reference record deferred to Phase 2."
      }
    },
    "instruments": [
      {
        "id": "ca-pipeda",
        "domain": "d1",
        "title": "Personal Information Protection and Electronic Documents Act (PIPEDA), S.C. 2000, c. 5",
        "type": "statute",
        "status": "in-force",
        "dates": {
          "enacted": "2000-04-13",
          "in_force": "2001-01-01"
        },
        "source": {
          "url": "https://laws-lois.justice.gc.ca/PDF/P-8.6.pdf",
          "authority": "Justice Laws Canada",
          "authoritative": true
        },
        "evidence": {
          "vault_path": "atlas-vault/ca/ca-pipeda/2026-08-04.pdf",
          "sha256": "02d32bc1782a26284da70c9d75433046d4d0c4021ced3c37932746fc949dc550",
          "captured": "2026-08-04"
        },
        "rag": {
          "status": "blocked — parser staging 401 (2026-08-04)",
          "task_ids": []
        },
        "confidence": "verified"
      },
      {
        "id": "qc-law25",
        "domain": "d1",
        "title": "Act respecting the protection of personal information in the private sector (as modernized by Law 25 / Bill 64)",
        "type": "statute (provincial)",
        "status": "in-force",
        "dates": {
          "enacted": "2021-09-22",
          "in_force": "2022-09-22 (staged to 2024-09)"
        },
        "source": {
          "url": "https://www.legisquebec.gouv.qc.ca/en/pdf/cs/P-39.1.pdf",
          "authority": "LégisQuébec",
          "authoritative": true
        },
        "evidence": {
          "vault_path": "atlas-vault/ca/qc-law25/2026-08-04.pdf",
          "sha256": "35b0fad968d8c6d7d2880df26e068724438d7a75aa09902f2853aa6259a192e1",
          "captured": "2026-08-04"
        },
        "rag": {
          "status": "blocked — parser staging 401",
          "task_ids": []
        },
        "confidence": "verified"
      },
      {
        "id": "ca-pbmm",
        "domain": "d3",
        "title": "GC cloud security profile — Protected B, Medium Integrity, Medium Availability (PBMM)",
        "type": "policy-framework",
        "status": "in-force",
        "source": {
          "url": "https://www.canada.ca/en/government/system/digital-government/digital-government-innovations/cloud-services/gc-cloud-security-profiles.html",
          "authority": "Treasury Board of Canada Secretariat",
          "authoritative": true
        },
        "evidence": {
          "status": "not-vaulted — HTML-only source"
        },
        "rag": {
          "status": "not-submitted"
        },
        "confidence": "reported"
      }
    ],
    "gaps": [
      {
        "domain": "d2",
        "note": "AIDA died with Bill C-27 on prorogation (2025-01-06); no successor tabled as of capture",
        "verified": "2026-08-04"
      },
      {
        "domain": "d4",
        "note": "US CLOUD Act / FISA 702 reference record deferred to Phase 2 (PRD §3.2)",
        "verified": "2026-08-04"
      }
    ],
    "related": [
      "model-jurisdiction-map",
      "sovereignty-db"
    ]
  },
  {
    "id": "uk",
    "name": "United Kingdom",
    "tier": "demo",
    "status": "published",
    "last_full_review": "2026-08-04",
    "posture": {
      "d1_residency": {
        "position": "transfer-controls-not-localization",
        "strength": 3,
        "confidence": "verified",
        "note": "UK GDPR + DPA 2018 mirror the EU transfer regime (adequacy, IDTA / UK addendum). No localization mandate. EU adequacy for the UK extended to 2025-12 (review pending — reported)."
      },
      "d2_ai_reg": {
        "position": "no-instrument",
        "strength": 0,
        "confidence": "verified",
        "note": "No AI statute; sectoral regulators apply the 2023 pro-innovation framework (non-statutory)."
      },
      "d3_cloud_proc": {
        "position": "procurement-framework",
        "strength": 2,
        "confidence": "reported",
        "note": "G-Cloud / Crown Commercial Service frameworks; no sovereign-cloud certification scheme comparable to SecNumCloud."
      },
      "d4_export_access": {
        "position": "bilateral-access-agreement",
        "strength": 4,
        "confidence": "judgment",
        "note": "UK–US CLOUD Act agreement (2019) enables reciprocal data demands; IPA 2016 domestic powers. Five Eyes member."
      }
    },
    "instruments": [
      {
        "id": "uk-dpa2018",
        "domain": "d1",
        "title": "Data Protection Act 2018 (c. 12) + UK GDPR (retained EU law)",
        "type": "statute",
        "status": "in-force",
        "dates": {
          "enacted": "2018-05-23",
          "in_force": "2018-05-25"
        },
        "source": {
          "url": "https://www.legislation.gov.uk/ukpga/2018/12/pdfs/ukpga_20180012_en.pdf",
          "authority": "legislation.gov.uk (The National Archives)",
          "authoritative": true
        },
        "evidence": {
          "vault_path": "atlas-vault/uk/uk-dpa2018/2026-08-04.pdf",
          "sha256": "8b6f3eef85b7e9c90ee9d64c9d2461b0d2362de6b37dfdc85c6207d6bec54499",
          "captured": "2026-08-04"
        },
        "rag": {
          "status": "blocked — parser staging 401",
          "task_ids": []
        },
        "confidence": "verified"
      },
      {
        "id": "uk-ai-framework",
        "domain": "d2",
        "title": "A pro-innovation approach to AI regulation (white paper, 2023; sectoral implementation)",
        "type": "policy-framework",
        "status": "non-statutory",
        "source": {
          "url": "https://www.gov.uk/government/publications/ai-regulation-a-pro-innovation-approach",
          "authority": "DSIT",
          "authoritative": true
        },
        "evidence": {
          "status": "not-vaulted — HTML-only source"
        },
        "rag": {
          "status": "not-submitted"
        },
        "confidence": "reported"
      }
    ],
    "gaps": [
      {
        "domain": "d3",
        "note": "No national sovereign-cloud certification scheme; procurement via CCS frameworks",
        "verified": "2026-08-04"
      }
    ],
    "related": [
      "model-jurisdiction-map"
    ]
  },
  {
    "id": "ie",
    "name": "Ireland",
    "tier": "demo",
    "status": "published",
    "last_full_review": "2026-08-04",
    "posture": {
      "d1_residency": {
        "position": "eu-regime",
        "strength": 4,
        "confidence": "reported",
        "note": "GDPR Ch. V applies directly (EU provisions captured inline per demo scope); Data Protection Act 2018 is the national layer. Transfers via adequacy/SCCs — EU-US Data Privacy Framework in place (challenge pending, reported)."
      },
      "d2_ai_reg": {
        "position": "eu-ai-act",
        "strength": 4,
        "confidence": "reported",
        "note": "EU AI Act applies directly; staged application from 2025-02 (prohibitions) through 2026-08 (most obligations)."
      },
      "d3_cloud_proc": {
        "position": "no-national-scheme",
        "strength": 1,
        "confidence": "reported",
        "note": "No national sovereign-cloud certification; public procurement follows EU rules."
      },
      "d4_export_access": {
        "position": "concentrated-us-exposure",
        "strength": 5,
        "confidence": "judgment",
        "note": "EU HQs of most US hyperscalers sit in Ireland — CLOUD Act reach and Irish DPC enforcement posture are both amplified. Reference record deferred to Phase 2."
      }
    },
    "instruments": [
      {
        "id": "eu-gdpr",
        "domain": "d1",
        "title": "Regulation (EU) 2016/679 (GDPR), Chapter V — transfers to third countries",
        "type": "regulation (EU, inline)",
        "status": "in-force",
        "dates": {
          "enacted": "2016-04-27",
          "in_force": "2018-05-25"
        },
        "source": {
          "url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679",
          "authority": "EUR-Lex",
          "authoritative": true
        },
        "evidence": {
          "status": "fetch-blocked — EUR-Lex returns 202 to scripted fetch (2026-08-04)"
        },
        "rag": {
          "status": "not-submitted"
        },
        "confidence": "reported"
      },
      {
        "id": "ie-dpa2018",
        "domain": "d1",
        "title": "Data Protection Act 2018 (No. 7 of 2018)",
        "type": "statute",
        "status": "in-force",
        "source": {
          "url": "https://www.irishstatutebook.ie/eli/2018/act/7/",
          "authority": "Irish Statute Book",
          "authoritative": true
        },
        "evidence": {
          "status": "not-vaulted — HTML-only source"
        },
        "rag": {
          "status": "not-submitted"
        },
        "confidence": "reported"
      },
      {
        "id": "eu-ai-act",
        "domain": "d2",
        "title": "Regulation (EU) 2024/1689 (AI Act)",
        "type": "regulation (EU, inline)",
        "status": "in-force (staged application)",
        "dates": {
          "enacted": "2024-06-13",
          "in_force": "2024-08-01"
        },
        "source": {
          "url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689",
          "authority": "EUR-Lex",
          "authoritative": true
        },
        "evidence": {
          "status": "fetch-blocked — EUR-Lex returns 202 to scripted fetch (2026-08-04)"
        },
        "rag": {
          "status": "not-submitted"
        },
        "confidence": "reported"
      }
    ],
    "gaps": [
      {
        "domain": "d3",
        "note": "No national sovereign-cloud certification scheme",
        "verified": "2026-08-04"
      }
    ],
    "related": [
      "model-jurisdiction-map"
    ]
  },
  {
    "id": "de",
    "name": "Germany",
    "tier": "demo",
    "status": "published",
    "last_full_review": "2026-08-04",
    "posture": {
      "d1_residency": {
        "position": "eu-regime-plus",
        "strength": 4,
        "confidence": "reported",
        "note": "GDPR applies directly; BDSG adds national layer. Strong DP culture; some sectoral localization (tax, health) beyond GDPR baseline."
      },
      "d2_ai_reg": {
        "position": "eu-ai-act",
        "strength": 4,
        "confidence": "reported",
        "note": "EU AI Act applies directly; national enforcement structure design in progress (reported)."
      },
      "d3_cloud_proc": {
        "position": "certification-scheme",
        "strength": 4,
        "confidence": "verified",
        "note": "BSI C5 attestation is the de-facto baseline for cloud providers selling to German public sector and regulated industry."
      },
      "d4_export_access": {
        "position": "standard-eu-exposure",
        "strength": 3,
        "confidence": "judgment",
        "note": "US CLOUD Act exposure via US-controlled providers; strong domestic preference for EU-controlled clouds in public procurement."
      }
    },
    "instruments": [
      {
        "id": "eu-gdpr",
        "domain": "d1",
        "title": "Regulation (EU) 2016/679 (GDPR), Chapter V — transfers to third countries",
        "type": "regulation (EU, inline)",
        "status": "in-force",
        "dates": {
          "enacted": "2016-04-27",
          "in_force": "2018-05-25"
        },
        "source": {
          "url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679",
          "authority": "EUR-Lex",
          "authoritative": true
        },
        "evidence": {
          "status": "fetch-blocked — EUR-Lex returns 202 to scripted fetch (2026-08-04)"
        },
        "rag": {
          "status": "not-submitted"
        },
        "confidence": "reported"
      },
      {
        "id": "de-c5",
        "domain": "d3",
        "title": "Cloud Computing Compliance Criteria Catalogue (C5:2020), BSI",
        "type": "certification-criteria",
        "status": "in-force",
        "dates": {
          "published": "2020-02"
        },
        "source": {
          "url": "https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/CloudComputing/ComplianceControlsCatalogue/2020/C5_2020.pdf",
          "authority": "BSI",
          "authoritative": true
        },
        "evidence": {
          "vault_path": "atlas-vault/de/de-c5/2026-08-04.pdf",
          "sha256": "e0ad7c2377f14d768dabf4765b3a50b665ba29e934692b2a24de4b29bbed1b50",
          "captured": "2026-08-04"
        },
        "rag": {
          "status": "blocked — parser staging 401",
          "task_ids": []
        },
        "confidence": "verified"
      },
      {
        "id": "eu-ai-act",
        "domain": "d2",
        "title": "Regulation (EU) 2024/1689 (AI Act)",
        "type": "regulation (EU, inline)",
        "status": "in-force (staged application)",
        "dates": {
          "enacted": "2024-06-13",
          "in_force": "2024-08-01"
        },
        "source": {
          "url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689",
          "authority": "EUR-Lex",
          "authoritative": true
        },
        "evidence": {
          "status": "fetch-blocked — EUR-Lex returns 202 to scripted fetch (2026-08-04)"
        },
        "rag": {
          "status": "not-submitted"
        },
        "confidence": "reported"
      }
    ],
    "gaps": [
      {
        "domain": "d4",
        "note": "US CLOUD Act / FISA 702 reference record deferred to Phase 2 (PRD §3.2)",
        "verified": "2026-08-04"
      }
    ],
    "related": [
      "model-jurisdiction-map"
    ]
  },
  {
    "id": "fr",
    "name": "France",
    "tier": "demo",
    "status": "published",
    "last_full_review": "2026-08-04",
    "posture": {
      "d1_residency": {
        "position": "eu-regime-plus",
        "strength": 4,
        "confidence": "reported",
        "note": "GDPR applies directly; Loi Informatique et Libertés (78-17, amended) is the national layer. Health data (HDS) and some public-sector data carry hosting requirements."
      },
      "d2_ai_reg": {
        "position": "eu-ai-act",
        "strength": 4,
        "confidence": "reported",
        "note": "EU AI Act applies directly; CNIL active on AI guidance."
      },
      "d3_cloud_proc": {
        "position": "sovereign-cloud-flagship",
        "strength": 5,
        "confidence": "reported",
        "note": "SecNumCloud (ANSSI) is the strictest sovereign-cloud qualification in the EU — French doctrine pushes EU-level sovereignty requirements (EUCS sovereignty debate, reported)."
      },
      "d4_export_access": {
        "position": "defended-eu-exposure",
        "strength": 3,
        "confidence": "judgment",
        "note": "Explicit policy goal of immunity from extraterritorial statutes (CLOUD Act) for qualified services; 'cloud de confiance' doctrine."
      }
    },
    "instruments": [
      {
        "id": "eu-gdpr",
        "domain": "d1",
        "title": "Regulation (EU) 2016/679 (GDPR), Chapter V — transfers to third countries",
        "type": "regulation (EU, inline)",
        "status": "in-force",
        "dates": {
          "enacted": "2016-04-27",
          "in_force": "2018-05-25"
        },
        "source": {
          "url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679",
          "authority": "EUR-Lex",
          "authoritative": true
        },
        "evidence": {
          "status": "fetch-blocked — EUR-Lex returns 202 to scripted fetch (2026-08-04)"
        },
        "rag": {
          "status": "not-submitted"
        },
        "confidence": "reported"
      },
      {
        "id": "fr-secnumcloud",
        "domain": "d3",
        "title": "SecNumCloud referential (v3.2), ANSSI — cloud service qualification",
        "type": "certification-criteria",
        "status": "in-force",
        "source": {
          "url": "https://www.cyber.gouv.fr/le-label-expertsecnumcloud",
          "authority": "ANSSI",
          "authoritative": true
        },
        "evidence": {
          "status": "not-vaulted — referential page; PDF capture pending"
        },
        "rag": {
          "status": "not-submitted"
        },
        "confidence": "reported"
      },
      {
        "id": "eu-ai-act",
        "domain": "d2",
        "title": "Regulation (EU) 2024/1689 (AI Act)",
        "type": "regulation (EU, inline)",
        "status": "in-force (staged application)",
        "dates": {
          "enacted": "2024-06-13",
          "in_force": "2024-08-01"
        },
        "source": {
          "url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689",
          "authority": "EUR-Lex",
          "authoritative": true
        },
        "evidence": {
          "status": "fetch-blocked — EUR-Lex returns 202 to scripted fetch (2026-08-04)"
        },
        "rag": {
          "status": "not-submitted"
        },
        "confidence": "reported"
      }
    ],
    "gaps": [
      {
        "domain": "d4",
        "note": "US CLOUD Act / FISA 702 reference record deferred to Phase 2 (PRD §3.2)",
        "verified": "2026-08-04"
      }
    ],
    "related": [
      "model-jurisdiction-map"
    ]
  },
  {
    "id": "ch",
    "name": "Switzerland",
    "tier": "demo",
    "status": "published",
    "last_full_review": "2026-08-04",
    "posture": {
      "d1_residency": {
        "position": "transfer-controls-not-localization",
        "strength": 3,
        "confidence": "reported",
        "note": "revFADP (in force 2023-09-01) modernized the regime toward GDPR; transfers per Federal Council adequacy list. EU adequacy for Switzerland in place; Swiss–US and UK–Swiss data frameworks operational (reported)."
      },
      "d2_ai_reg": {
        "position": "no-instrument",
        "strength": 1,
        "confidence": "reported",
        "note": "No AI statute; Switzerland signed the Council of Europe AI Convention (2025-03, reported); sectoral guidance instead."
      },
      "d3_cloud_proc": {
        "position": "no-national-scheme",
        "strength": 1,
        "confidence": "reported",
        "note": "No sovereign-cloud certification scheme; federal cloud strategy relies on commercial providers under contract."
      },
      "d4_export_access": {
        "position": "neutral-haven-reputation",
        "strength": 2,
        "confidence": "judgment",
        "note": "Non-EU, non-Five-Eyes; strong rule-of-law reputation drives 'Swiss hosting' positioning. CLOUD Act exposure still applies to US-controlled providers operating in CH."
      }
    },
    "instruments": [
      {
        "id": "ch-fadp",
        "domain": "d1",
        "title": "Federal Act on Data Protection (revFADP / nLPD), CC 2022/568",
        "type": "statute",
        "status": "in-force",
        "dates": {
          "enacted": "2020-09-25",
          "in_force": "2023-09-01"
        },
        "source": {
          "url": "https://www.fedlex.admin.ch/eli/cc/2022/568/en",
          "authority": "Fedlex",
          "authoritative": true
        },
        "evidence": {
          "status": "fetch-blocked — Fedlex serves HTML wrapper to scripted fetch (2026-08-04)"
        },
        "rag": {
          "status": "not-submitted"
        },
        "confidence": "reported"
      }
    ],
    "gaps": [
      {
        "domain": "d2",
        "note": "No AI-specific statute; CoE AI Convention signed 2025-03 (reported), ratification pending",
        "verified": "2026-08-04"
      },
      {
        "domain": "d3",
        "note": "No sovereign-cloud certification scheme",
        "verified": "2026-08-04"
      },
      {
        "domain": "d4",
        "note": "US CLOUD Act / FISA 702 reference record deferred to Phase 2 (PRD §3.2)",
        "verified": "2026-08-04"
      }
    ],
    "related": [
      "model-jurisdiction-map"
    ]
  },
  {
    "id": "id",
    "name": "Indonesia",
    "tier": "demo",
    "status": "published",
    "last_full_review": "2026-08-04",
    "posture": {
      "d1_residency": {
        "position": "sectoral-localization",
        "strength": 4,
        "confidence": "verified",
        "note": "PDP Law 27/2022 governs transfers (adequacy-style test, consent fallback). PP 71/2019 historically required public-service electronic system operators to host in Indonesia; scope narrowed toward private-sector flexibility (reported)."
      },
      "d2_ai_reg": {
        "position": "no-binding-instrument",
        "strength": 1,
        "confidence": "reported",
        "note": "Kominfo Circular 9/2023 sets AI ethics guidance (non-binding); no AI statute as of capture."
      },
      "d3_cloud_proc": {
        "position": "sectoral-localization",
        "strength": 3,
        "confidence": "reported",
        "note": "Government cloud and public-service ESO hosting shaped by PP 71/2019; financial sector (OJK) has its own residency rules."
      },
      "d4_export_access": {
        "position": "low-external-exposure",
        "strength": 2,
        "confidence": "judgment",
        "note": "Outside Five Eyes and major access alliances; US CLOUD Act exposure still applies to US-controlled providers operating in-market."
      }
    },
    "instruments": [
      {
        "id": "id-pdp-law",
        "domain": "d1",
        "title": "Undang-Undang No. 27 Tahun 2022 tentang Pelindungan Data Pribadi (PDP Law)",
        "type": "statute",
        "status": "in-force",
        "dates": {
          "enacted": "2022-10-17",
          "in_force": "2022-10-17 (2-year transition to 2024-10)"
        },
        "source": {
          "url": "https://peraturan.bpk.go.id/Download/224884/UU%20Nomor%2027%20Tahun%202022.pdf",
          "authority": "JDIH BPK RI",
          "authoritative": true
        },
        "evidence": {
          "vault_path": "atlas-vault/id/id-pdp-law/2026-08-04.pdf",
          "sha256": "ed952dea04b87d14ecf037f9f324a65d50b396ddd34fc28ddf9ff014391971f6",
          "captured": "2026-08-04",
          "language": "id (official Indonesian)"
        },
        "rag": {
          "status": "blocked — parser staging 401",
          "task_ids": []
        },
        "confidence": "verified"
      },
      {
        "id": "id-pp71",
        "domain": "d1",
        "title": "Peraturan Pemerintah No. 71 Tahun 2019 — electronic systems and transactions (ESO registration, hosting)",
        "type": "regulation",
        "status": "in-force",
        "source": {
          "url": "https://peraturan.bpk.go.id/Details/131806/pp-no-71-tahun-2019",
          "authority": "JDIH BPK RI",
          "authoritative": true
        },
        "evidence": {
          "status": "not-vaulted — capture pending"
        },
        "rag": {
          "status": "not-submitted"
        },
        "confidence": "reported"
      },
      {
        "id": "id-ai-circular",
        "domain": "d2",
        "title": "Kominfo Circular Letter No. 9/2023 — AI ethics guidance",
        "type": "circular (non-binding)",
        "status": "in-force (non-binding)",
        "source": {
          "url": "https://jdih.kominfo.go.id/produk_hukum/view/id/883",
          "authority": "JDIH Kominfo",
          "authoritative": true
        },
        "evidence": {
          "status": "not-vaulted — HTML source"
        },
        "rag": {
          "status": "not-submitted"
        },
        "confidence": "reported"
      }
    ],
    "gaps": [
      {
        "domain": "d2",
        "note": "No binding AI-specific statute; ethics circular only",
        "verified": "2026-08-04"
      },
      {
        "domain": "d4",
        "note": "No material export/access regime identified at demo depth",
        "verified": "2026-08-04"
      }
    ],
    "related": [
      "model-jurisdiction-map"
    ]
  },
  {
    "id": "th",
    "name": "Thailand",
    "tier": "demo",
    "status": "published",
    "last_full_review": "2026-08-04",
    "posture": {
      "d1_residency": {
        "position": "transfer-controls-not-localization",
        "strength": 3,
        "confidence": "reported",
        "note": "PDPA B.E. 2562 (2019), fully in force 2022-06-01. Cross-border transfers require adequacy or safeguards (s.28/29); sub-regulations on transfer criteria issued 2023–24 (reported). No general localization mandate."
      },
      "d2_ai_reg": {
        "position": "draft-only",
        "strength": 1,
        "confidence": "reported",
        "note": "Draft AI legislation under development; no AI statute in force as of capture."
      },
      "d3_cloud_proc": {
        "position": "no-national-scheme",
        "strength": 1,
        "confidence": "reported",
        "note": "No sovereign-cloud certification scheme identified at demo depth."
      },
      "d4_export_access": {
        "position": "low-external-exposure",
        "strength": 2,
        "confidence": "judgment",
        "note": "Outside major access alliances; US CLOUD Act exposure applies to US-controlled providers operating in-market."
      }
    },
    "instruments": [
      {
        "id": "th-pdpa",
        "domain": "d1",
        "title": "Personal Data Protection Act B.E. 2562 (2019)",
        "type": "statute",
        "status": "in-force",
        "dates": {
          "enacted": "2019-05-27",
          "in_force": "2022-06-01"
        },
        "source": {
          "url": "http://www.ratchakitcha.soc.go.th/DATA/PDF/2562/A/069/T_0052.PDF",
          "authority": "Royal Thai Government Gazette",
          "authoritative": true
        },
        "evidence": {
          "status": "fetch-blocked — Royal Gazette returns 403 to scripted fetch (2026-08-04)",
          "language": "th (official Thai)"
        },
        "rag": {
          "status": "not-submitted"
        },
        "confidence": "reported"
      }
    ],
    "gaps": [
      {
        "domain": "d2",
        "note": "No AI-specific statute in force; draft legislation reported",
        "verified": "2026-08-04"
      },
      {
        "domain": "d3",
        "note": "No sovereign-cloud certification scheme identified at demo depth",
        "verified": "2026-08-04"
      },
      {
        "domain": "d4",
        "note": "No material export/access regime identified at demo depth",
        "verified": "2026-08-04"
      }
    ],
    "related": [
      "model-jurisdiction-map"
    ]
  }
]
