Cloud IAM & identity attacks, RAG/Knowledge-Base poisoning, graph/relational data exfiltration, agentic excessive agency, model manipulation, multi-region failover abuse
Horizon boundaries are roadmap intent, not commitments โ the platform deliberately stays static through 2027 (FUTURE_ARCHITECTURE.md ยง2.6). H3 threats are pre-modeled so that controls are designed before the first managed service is provisioned.
Platform content stays public; H3 Cognito introduces authenticated user accounts whose saved searches/alerts reveal political interest (GDPR Art. 9) and must be protected
๐ Integrity
High
Critical
Real-time voting data, expanded AI content, and H3 authoritative managed stores (Aurora/Neptune/forecasts) increase integrity requirements
โก Availability
High
Critical
Real-time dashboards and H3 public API / multi-region services require higher availability during parliamentary sessions and election windows
Note: This table describes the future Riksdagsmonitor system security classification. The CIA classification badges in the Document Control section represent the classification of this document itself, not the future system, and may therefore differ from the future system's target classification. The H3 authenticated tier is the first time the platform processes per-user personal data โ a DPIA is mandatory before Cognito launch (see F6 and FUT-013/FUT-014).
๐๏ธ Future Architecture Threat Analysis
๐ญ STRIDE per Future Component
Future Component
S (Spoofing)
T (Tampering)
R (Repudiation)
I (Info Disclosure)
D (DoS)
E (Elevation)
Risk Level
CIA Data Pipeline
Source API spoofing
Cached data poisoning
Pipeline execution denial
Data leakage via cache
Pipeline backlog/timeout
Pipeline credential escalation
HIGH
Real-Time Voting Dashboard
WebSocket connection spoofing
Vote data manipulation in transit
Connection state denial
Vote counting information leak
WebSocket flood/connection exhaustion
Client-side privilege via WebSocket
CRITICAL
Politician Profile Pages
Profile data source spoofing
Historical record tampering
Profile edit denial
Biographical data exposure
Profile page DoS via complex queries
SEO manipulation for profile ranking
MEDIUM
Automated Translation Pipeline
Source language spoofing
Translation output manipulation
Translation attribution denial
Source text leakage
Translation queue exhaustion
LLM model access escalation
HIGH
Enhanced Dashboards (5 new)
Data source spoofing for charts
Chart data injection/manipulation
Dashboard interaction denial
Data aggregation leakage
Large dataset rendering DoS
Dashboard admin escalation
MEDIUM
EU Parliament Cross-Reference
EP MCP Server spoofing
Cross-reference data tampering
Data linkage denial
EU political data leakage
API rate limiting/timeout
Cross-system privilege escalation
MEDIUM
IMF Data Integration (TypeScript client โ scripts/imf-client.ts)
IMF origin DNS hijack / TLS MITM
IMF JSON response tampering in transit or at rest
Stale / mis-vintaged WEO projections cited as current
Aggregate public-only; negligible
IMF rate-limit (10 req / 5 s) trips workflow
Pure-TS client inside the npm SBOM; no new runtime
Cross-workflow consistency validation, independent fact-checking per workflow, rate limiting on AI content volume, mandatory human review for correlated outputs
The scenarios above (F1โF4) are Horizon 2 threats โ they materialise while the platform is still static. The scenarios below (F5โF12) are Horizon 3 threats that only become live once managed AWS services are provisioned; they are pre-modeled so controls ship with each service (FUTURE_ARCHITECTURE.md ยง3, ยง11.4 AWS Security Services).
Least-privilege IAM per function (one role per Lambda), VPC isolation + private endpoints, KMS key policies with grant constraints, CloudTrail data events on all stores, GuardDuty + Security Hub correlation, IAM Access Analyzer in CI
Scenario F8: Bedrock Agent Excessive Agency (H3)
Attribute
Detail
Threat Agent
AI-enabled adversary
Attack Vector
Indirect prompt injection (via voice, KB context, or user query) steers a Bedrock Agent to chain tools beyond intent โ triggering writes, external calls, or content publication
Target
Conversational AI multi-agent system (Bedrock Agents, Lex, AppSync subscriptions)
Impact
Autonomous publication of manipulated content or unauthorized state changes without human review
Poison SageMaker Feature Store / training data or forge inference inputs to skew published seat or coalition forecasts ahead of the 2026 (and later) elections
Route 53 / health-check spoofing forces failover to a weaker-controlled region; replication-stream tampering or split-brain writes corrupt Aurora Global / DynamoDB Global tables
Target
Active-passive multi-region deployment (Aurora Global DB, DynamoDB Global Tables, S3 CRR, Route 53)
Impact
Integrity divergence between regions, stale or tampered data served during failover
Spoof or tamper a foreign-parliament feed (DK/NO/FI or EU Parliament) so comparative cross-country analysis carries manipulated data through a trusted federation boundary
Target
Shared data-mesh comparative analytics across Nordic & EU parliaments
Impact
Cross-border disinformation laundered through Riksdagsmonitor's neutrality reputation
Likelihood
Low-Medium (each new source widens the trust boundary)
๐ก Medium โ Over-trusting AI-generated political analysis
Mandatory human editorial review, confidence scoring
LLM10
Model Theft
๐ข Low โ Using commercial API, not custom model
API key rotation, access logging
Mapping note: the table above uses the OWASP LLM Top-10 (2023/2024) IDs already established in this document. For Horizon 3 the same risks intensify as the platform moves from build-time MCP agents to managed Bedrock Agents, Knowledge Bases (RAG) and SageMaker models. The H3-specific intensification is summarised below.
๐ H3 Bedrock / Agentic AI Threat Intensification
OWASP LLM Risk
H3 Driver
H3-Specific Mitigation
LLM01 Prompt Injection
Indirect injection via RAG KB context, voice (Transcribe), and user queries to Bedrock Agents
Fielding the Political-Intelligence Capability Catalog (C1โC32) creates a new, high-value attack surface: an adversary who can corrupt the intelligence pipeline can launder a manipulated judgment through the platform's own credibility. These threats are distinct from generic web threats โ they target analytic integrity, calibration, neutrality and provenance. The catalog's assurance pillar (C26โC32) exists specifically to counter them.
STRIDE per intelligence-capability component
Component
Threat (STRIDE)
Scenario
Counter-capability
Multi-INT fusion graph (C6)
Tampering
Poisoned edge fabricates a personโfunding link
C8 evidence anchor (no edge without graded dok_id); human-review hold
Entity resolution (C1)
Spoofing
Adversary games identifiers to merge/split entities
FIMI targeting the platform itself โ adversary narratives crafted to trigger false advisories
High โ platform amplifies adversary frame
Hard โ designed to look organic
Attribution-confidence floors, ethics gate, human framing, advisory-only output
Mapping to standards
Scenario
STRIDE
MITRE ATT&CK / ATLAS
OWASP LLM Top 10
PI-T1 poisoning
Tampering
ATLAS: ML Supply-Chain / Data Poisoning
LLM03 Training-Data Poisoning
PI-T2 injection
Tampering / EoP
ATLAS: LLM Prompt Injection
LLM01 Prompt Injection
PI-T3 provenance forgery
Spoofing
T1565 Data Manipulation
LLM08 Excessive Agency (citation)
PI-T4 neutrality
Repudiation / bias
โ (governance)
LLM09 Overreliance
PI-T5 warning suppression
DoS
T1499 Endpoint DoS (signal)
LLM04 Model DoS
PI-T6 calibration gaming
Repudiation
โ (integrity)
LLM09 Overreliance
PI-T7 FIMI targeting
Information abuse
DISARM TTPs
LLM09 Overreliance
Governing principle. Every intelligence-capability threat is met by an integrity-by-construction control, not by trust in the model: evidence anchoring, immutable calibration, provenance signing, neutrality-as-a-CI-gate, and a mandatory human-on-the-loop before any estimative product is published. See FUTURE_SECURITY_ARCHITECTURE.md for the corresponding controls.
The platform's mission is democratic transparency โ any threat that subverts, distorts, or undermines public accountability is existential regardless of technical sophistication.
Riksdagsmonitor occupies a unique position: a neutral, AI-powered democratic-intelligence platform whose outputs influence citizen understanding of parliamentary proceedings. This creates a category of threats distinct from generic cybersecurity โ threats to democratic processes, institutional trust, and political neutrality that no standard web-security framework adequately covers.
๐๏ธ Democratic Threat Landscape
flowchart TB subgraph DEMOCRATIC_THREATS["๐ณ๏ธ Democratic Integrity Threats"] direction TB DT1["๐ญ Neutrality Subversion<br/>Asymmetric framing across parties"] DT2["๐ Forecast Weaponization<br/>Biased predictions influence voters"] DT3["๐๏ธ Information Laundering<br/>Adversary narratives gain platform credibility"] DT4["๐ Accountability Suppression<br/>Hide/downplay political misconduct"] DT5["โก Election-Window Exploitation<br/>Time-critical attacks during campaigns"] DT6["๐ Cross-Border Influence<br/>Foreign interference via federation"] end
subgraph DEMOCRATIC_CONTROLS["๐ก๏ธ Democratic Safeguards"] direction TB DC1["โ๏ธ Party-Symmetry CI Gate<br/>Automated neutrality enforcement"] DC2["๐ Calibration Ledger<br/>Immutable forecast accuracy tracking"] DC3["๐ Source-Grade Floor<br/>Minimum evidence threshold"] DC4["๐๏ธ Human-on-the-Loop<br/>Mandatory editorial oversight"] DC5["๐ซ Election Cooling Period<br/>Restricted AI during election silence"] DC6["๐ค Federation Trust Boundaries<br/>Per-source integrity verification"] end
subgraph DEMOCRATIC_ACTORS["๐ฅ Democratic Threat Actors"] direction TB DA1["๐๏ธ State-Sponsored IO<br/>Foreign influence operations"] DA2["๐ช Domestic Political Operatives<br/>Partisan manipulation attempts"] DA3["๐ค Autonomous AI Agents<br/>Unintended bias amplification"] DA4["๐ฐ Disinformation Networks<br/>Coordinated inauthentic behavior"] end
Scenario F13: Gradual Neutrality Erosion via AI Drift
Attribute
Detail
๐ญ Threat Agent
Autonomous AI drift (unintentional), sophisticated insider, domestic political operative
โ๏ธ Attack Vector
Subtle, consistent asymmetry in AI-generated content: tone, coverage depth, or framing favors one bloc over another across hundreds of articles over weeks/months
๐ฏ Target
The platform's core neutrality invariant โ equal treatment of all 8 Riksdag parties
๐ฅ Impact
Institutional credibility destroyed; platform becomes a perceived partisan tool; cited in political campaigns as evidence of bias
๐ Likelihood
Medium-High (LLM training biases are well-documented; drift is natural without active correction)
FUT-023: Party-symmetry CI gate (automated), FUT-024: longitudinal sentiment-balance monitoring, dual-review for cross-party articles, mandatory bloc-parity metrics in every weekly review
Election interference actor, nation-state information operation
โ๏ธ Attack Vector
Timing-aware attack: manipulate SageMaker forecast inputs or translation pipeline during the 30-day pre-election window when media amplification is maximal
๐ฏ Target
Published seat/coalition predictions, pre-election news coverage, voter information pages
๐ฅ Impact
Biased forecasts amplified by media; potential violation of Swedish election silence conventions; voter behavior influence; legal/regulatory consequences
๐ Likelihood
Medium (high-value target with clear temporal window)
FUT-025: Election cooling-period protocol (restricted AI autonomy, mandatory human approval for all election-relevant content), elevated monitoring, cross-validation with SCB/Valmyndigheten, explicit uncertainty disclosure
Domestic political operative, insider threat, sophisticated lobbyist
โ๏ธ Attack Vector
Manipulate content pipeline to suppress, delay, or downplay politically inconvenient information (votes, motions, committee decisions) while amplifying favorable narratives
๐ฏ Target
News article generation, politician profile pages, voting record displays
๐ฅ Impact
Platform becomes complicit in accountability evasion; undermines democratic oversight function; erosion of public trust
๐ Likelihood
Low-Medium (requires insider access or pipeline compromise)
FUT-026: Completeness audit (automated check that all Riksdag decisions/votes are covered), source-of-record reconciliation with riksdagen.se, time-to-publish SLA monitoring, dual-control on content deletion
Scenario F16: Information Laundering via Platform Credibility
Attribute
Detail
๐ญ Threat Agent
Foreign information operation (FIMI), coordinated inauthentic network
โ๏ธ Attack Vector
Seed manipulated data into upstream sources (Riksdag API responses, government press releases via g0v.se, foreign parliament feeds) knowing Riksdagsmonitor will automatically ingest, validate, and republish โ laundering disinformation through the platform's trusted reputation
FUT-027: Multi-source cross-validation (never rely on single source), anomaly detection on ingest deltas, provenance chain verification, source-grading with confidence floors, human escalation for statistically improbable data changes
๐ Privacy, GDPR & Data Protection Threats
Horizon 3 introduces the platform's first authenticated user tier โ transforming privacy from a non-concern to a critical obligation.
๐ Privacy Threat Landscape (H3)
flowchart LR subgraph USER_DATA["๐ค H3 User Data at Risk"] UD1["๐ Saved Searches<br/>Reveal political interests"] UD2["๐ Alert Subscriptions<br/>Track political monitoring"] UD3["๐ Personalization<br/>Behavioral profile"] UD4["๐ฌ Chat History<br/>Political questions asked"] end
subgraph GDPR_THREATS["โ ๏ธ Privacy Threats"] GT1["๐ Art. 9 Violation<br/>Special-category data exposure"] GT2["๐ต๏ธ Profiling Risk<br/>Political opinion inference"] GT3["๐ Cross-Border Transfer<br/>Multi-region data residency"] GT4["๐๏ธ Erasure Complexity<br/>Right-to-be-forgotten across replicas"] GT5["๐ Linkage Attack<br/>De-anonymization via query patterns"] end
subgraph PRIVACY_CONTROLS["๐ก๏ธ Privacy Controls"] PC1["๐ DPIA Mandatory<br/>Before Cognito launch"] PC2["๐ Data Minimization<br/>No opinions stored server-side"] PC3["๐ EU Data Residency<br/>eu-west-1 primary"] PC4["โฑ๏ธ Auto-Purge<br/>Configurable retention"] PC5["๐ญ Pseudonymization<br/>Query-level privacy"] end
Scenario F17: Political-Opinion Inference from Usage Patterns (H3)
Attribute
Detail
๐ญ Threat Agent
Data breach attacker, insider, law enforcement overreach
โ๏ธ Attack Vector
Aggregate saved searches, alert patterns, and chatbot questions to infer a user's political opinions โ GDPR Article 9 special-category data โ without explicit consent for that processing purpose
๐ฏ Target
Cognito user profiles + associated DynamoDB/Aurora query history
๐ฅ Impact
Violation of GDPR Art. 9 (processing special-category data without lawful basis); regulatory fines up to 4% annual turnover; chilling effect on civic engagement
๐ Likelihood
Medium (inference is technically straightforward once data is collected)
FUT-028: Privacy-by-design architecture (no server-side political-opinion storage), client-side encryption for saved queries, aggregate-only analytics, automated data minimization, DPIA gate before any new data collection, privacy-preserving personalization (on-device ML)
Scenario F18: Cross-Region Data Residency Violation (H3)
FUT-029: Geo-fenced replication (user PII stays in eu-west-1), AWS Config rules enforcing data residency, SCP preventing PII table replication to non-EU regions, automated compliance drift detection
๐ Supply Chain & AI Model Governance Threats
The platform's AI supply chain extends beyond npm packages to foundation models, training data, and MCP tool ecosystems โ each a potential vector for subtle, high-impact compromise.
๐ญ AI Supply Chain Threat Model
flowchart TD subgraph AI_SUPPLY_CHAIN["๐ค AI Supply Chain Attack Surface"] direction TB SC1["๐ง Foundation Model Updates<br/>Behavioral regression on upgrade"] SC2["๐ฆ MCP Server Dependencies<br/>Tool-level supply chain"] SC3["๐ Training Data Provenance<br/>Poisoned public datasets"] SC4["๐ง Prompt Template Integrity<br/>Workflow instruction tampering"] SC5["๐ External API Dependencies<br/>Riksdag/SCB/IMF availability"] end
subgraph GOVERNANCE_THREATS["โ๏ธ AI Governance Threats"] direction TB AG1["๐ EU AI Act Non-Compliance<br/>Regulatory classification change"] AG2["๐ฏ Model Behavior Drift<br/>Post-update output degradation"] AG3["๐ Vendor Lock-In Exploitation<br/>AWS service discontinuation"] AG4["๐ Transparency Debt<br/>Unexplainable model decisions"] end
subgraph SUPPLY_CONTROLS["๐ก๏ธ Supply Chain Controls"] direction TB SCC1["๐ Model Version Pinning<br/>+ regression testing"] SCC2["๐ SLSA Level 3<br/>Build provenance"] SCC3["โ Output Regression Suite<br/>Golden-set validation"] SCC4["๐ AI Model Cards<br/>Transparency documentation"] SCC5["๐ Multi-Model Fallback<br/>Provider redundancy"] end
Scenario F19: Foundation Model Behavioral Regression
Attribute
Detail
๐ญ Threat Agent
Model provider (unintentional), adversary targeting model training
โ๏ธ Attack Vector
A Claude or Bedrock model update introduces subtle behavioral changes: different political framing, altered fact-selection preferences, or degraded neutrality in Swedish-language outputs
๐ฏ Target
All AI-generated content (14 news workflows, translation, analysis)
๐ฅ Impact
Gradual quality/neutrality degradation across all outputs; potentially undetected for days if regression is subtle
๐ Likelihood
Medium (model updates are frequent; political-content testing is specialized)
FUT-030: Model regression test suite (golden-set political content), automated neutrality scoring on model upgrade, staged rollout (canary โ full), model version pinning with explicit upgrade gates
Scenario F20: EU AI Act Regulatory Reclassification
Attribute
Detail
๐ญ Threat Agent
Regulatory environment change
โ๏ธ Attack Vector
EU AI Act enforcement classifies the platform's election forecasting or political analysis as "high-risk AI" (Annex III, Category 8: administration of justice/democratic processes), triggering mandatory conformity assessment, transparency obligations, and human-oversight requirements
๐ฏ Target
Platform operational model, AI governance framework, compliance posture
Medium (political-analysis AI is an emerging regulatory gray area)
โ ๏ธ Risk Score
6.5/10 MEDIUM
๐๏ธ MITRE ATT&CK
N/A (regulatory threat)
๐ก๏ธ Planned Controls
FUT-031: Proactive EU AI Act alignment (maintain documentation as if high-risk), model cards per Bedrock model, human-oversight architecture already designed, transparency reports, regular legal-counsel review of classification guidance
Compromise an MCP server dependency (riksdag-regering, scb, world-bank, or upstream npm packages) to inject malicious tool responses into agentic workflows
FUT-032: MCP server integrity verification (SHA-pinned versions, SBOM tracking), response schema validation, anomaly detection on MCP responses, sandboxed tool execution, SLSA Level 3 provenance for all build inputs
๐ Geopolitical & Information Environment Threats
As Riksdagsmonitor expands to Nordic and EU parliaments, it enters a contested information environment where state-level actors actively seek to undermine democratic institutions.
๐บ๏ธ Geopolitical Threat Landscape
flowchart TB subgraph GEO_CONTEXT["๐ Geopolitical Context (2026โ2037)"] direction LR GC1["๐ท๐บ Hybrid Warfare<br/>Information operations<br/>targeting Nordic democracies"] GC2["๐จ๐ณ Influence Operations<br/>United Front Work targeting<br/>diaspora communities"] GC3["๐ด Non-State FIMI<br/>Coordinated inauthentic<br/>behavior networks"] GC4["๐ค AI-Powered IO<br/>Synthetic media &<br/>automated propaganda"] end
subgraph PLATFORM_EXPOSURE["๐ก Platform Exposure Points"] direction LR PE1["๐ 14-Language Surface<br/>Each language = unique<br/>disinformation vector"] PE2["๐ฎ Forecast Outputs<br/>Election predictions as<br/>influence leverage"] PE3["๐ค Federation Trust<br/>Nordic/EU data mesh<br/>as attack vector"] PE4["๐ Credibility Capital<br/>Platform trust as<br/>laundering vehicle"] end
subgraph GEO_DEFENSES["๐ก๏ธ Geopolitical Defenses"] direction LR GD1["๐ FIMI Detection (C20)<br/>Early-warning indicators"] GD2["๐ Source Grading<br/>Confidence-floor enforcement"] GD3["๐ Per-Language Review<br/>Native-speaker verification"] GD4["โ๏ธ Advisory-Only Output<br/>No accusatory attribution"] end
Threat landscape update, control effectiveness assessment
Updated risk scores, new mitigations
Future Threat Monitoring KPIs
KPI
Target
Measurement Method
New feature threat coverage
100% STRIDE per component
Feature threat model completeness
Time to detect data manipulation
< 15 minutes
Integrity check monitoring
Cross-workflow anomaly detection rate
> 95%
Consistency check pass rate
Translation integrity score
> 98% accuracy
Back-translation verification rate
Pipeline data freshness SLA
< 24 hours
Cache timestamp monitoring
WebSocket connection security
100% TLS 1.3
Connection protocol audit
RAG / Knowledge-Base source provenance (H3)
100% allow-listed
Bedrock KB ingestion audit
Bedrock Agent action-scope conformance (H3)
100% within least-privilege policy
Agent action-group / guardrail audit
Cognito MFA enrolment for authenticated tier (H3)
100% of accounts
Identity provider compliance report
IAM least-privilege drift (H3)
0 over-privileged roles
IAM Access Analyzer findings
Multi-region replication integrity (H3)
100% checksum match
Cross-region reconciliation audit
โ๏ธ Future Risk Assessment
Quantitative Risk Matrix โ Future Threats
Scores split by horizon. H2 threats can materialise 2026โ2027 while the platform is still static; H3 threats only become live once managed AWS services are provisioned (2027+).
Threat
Horizon
Likelihood (1-5)
Impact (1-5)
Risk Score
Treatment
Real-time vote data manipulation
H2
3
5
15 CRITICAL
MITIGATE (FUT-001, FUT-009)
CIA pipeline cache poisoning
H2
2
4
8 HIGH
MITIGATE (FUT-002, FUT-003)
Multi-workflow AI orchestration attack
H2
2
4
8 HIGH
MITIGATE (FUT-004)
Translation integrity attack
H2
3
3
9 HIGH
MITIGATE (FUT-005)
Dashboard rendering DoS
H2
3
2
6 MEDIUM
MITIGATE (FUT-007)
Politician profile defacement
H2
2
3
6 MEDIUM
MITIGATE (FUT-006)
EU Parliament API compromise
H2
1
3
3 LOW
ACCEPT + MONITOR (FUT-008)
Lambda/IAM privilege escalation & data exfiltration
Major expansion: Three-Horizon framework, Crown Jewel analysis, Attack Trees, Kill Chain mapping, OWASP LLM Top 10, Political-Intelligence capabilities
1.0
2026-04-15
James Pether Sรถrling
Initial future threat model with STRIDE and basic scenarios
Framework Compliance
๐ฏ Framework Alignment:
๐ Evolving the Current IMF Threat Model โ Future-State STRIDE Expansion
Baseline: the already-implemented IMF STRIDE coverage (T-IMF-01..07) lives in THREAT_MODEL.md ยงIMF. The rows below (T-IMF-F-01..08) add future-state threats that emerge when the runtime migrates to Lambda + Aurora โ they extend the baseline rather than replace it.
Script in-repo; reviewed; no dynamic eval; harden-runner egress audit
Mapping to MITRE ATT&CK (data-source threats)
Tactic
Technique
IMF-specific application
TA0006 Credential Access
T1552 Unsecured credentials
Datamapper transport is unauthenticated; SDMX 3.0 uses an Azure APIM subscription key (IMF_SDMX_SUBSCRIPTION_KEY) stored only as a GitHub Actions secret (never on disk, never logged); rotation playbook in analysis/imf/agentic-integration.md
TA0007 Discovery
T1083 File and directory discovery
Cache directory permissions (read-only to article workers)
TA0009 Collection
T1530 Cloud storage object
Aurora row-level access controls
TA0040 Impact
T1485 Data destruction
Supersedes-chain prevents destructive overwrite
Egress hosts (allow-list): www.imf.org (Datamapper REST ยท WEO/FM, unauthenticated), api.imf.org (SDMX 3.0 REST ยท IFS/BOP/DOTS/GFS/PCPS/ER/MFS_IR/MFS_PR, subscription-key authenticated via the Azure APIM Ocp-Apim-Subscription-Key header / IMF_SDMX_SUBSCRIPTION_KEY secret). Both HTTPS-only; payloads are public macro statistics with no PII.
Canonical rule. Every economic claim in a Riksdagsmonitor article cites an IMF dataflow first; World Bank citations are reserved for governance, environment and social residue (the classes IMF does not publish). SCB is the Swedish-specific ground truth layer. See ECONOMIC_DATA_CONTRACT.md v2.1 for the banned-phrase list and vintage discipline (>6 mo โ annotation).