(1) Personalized rubric with 1–5 scores for each criterion

Need Alignment
- 5: Centers on AI-caused personal data breaches and liability. Explicitly groups jurisdictions into “strict” vs “pro‑innovation/lenient,” and, for each, compares breach notification duties, liability allocation (controller vs processor/handler/intermediary), exemptions/safe harbors, penalties, and cross‑border rules. Covers major jurisdictions (EU, UK, US, China, Canada, Singapore, Brazil, Australia, India; bonus if adding others) and avoids drifting into general AI ethics or technical methods unless tied to breach obligations.
- 4: Correct strict vs lenient grouping with strong breach focus; minor drift or missing 1–2 requested elements (e.g., omits cross‑border or safe harbors) or 1–2 major jurisdictions.
- 3: On-topic privacy/AI discussion but not centered on AI-caused breaches (or no explicit strict/lenient split). Limited country coverage or mostly generic comparisons.
- 2: Primarily about general AI governance, lifecycle, or technical mitigations, with only passing mention of breach/liability. Lacks the requested two-bucket perspective.
- 1: Off-target narrative (e.g., analogies/metaphors) or ignores breach/liability focus and cross-country comparisons.

Content Depth
- 5: Provides concrete, jurisdiction-specific particulars: named statutes/regulators, breach-notification windows (with hours/days or “prompt/as soon as feasible” standards), maximum penalties with currency and/or percentages, liability allocation and joint liability/processor duties, explicit exemptions/safe harbors (e.g., encryption, affirmative defenses, harm thresholds, governmental/small-entity carve-outs), and cross-border/localization requirements. Covers at least 8–9 major jurisdictions accurately and up to date.
- 4: Mostly complete with strong specifics but missing a few numbers or 1–2 jurisdictions, or minor accuracy/clarity gaps. Still actionable without extra research.
- 3: Mixed detail: some statutes named and a few numbers, but many gaps (e.g., missing timelines or penalties) or only 3–5 jurisdictions covered.
- 2: High-level summaries with little breach-specific data (few or no timelines, penalties, or liability details). Includes extraneous background not tied to breaches.
- 1: Vague or incorrect; lacks per-country details and/or misstates core legal obligations.

Tone
- 5: Neutral, formal, precise, and report-like. No metaphors, emojis, marketing language, or casual flourishes. Avoids “beginner’s guide” framing and exclamation points.
- 4: Generally formal with one or two mild casual phrases; overall professional.
- 3: Functional but somewhat casual (e.g., informal headings/openings). No metaphors/emojis.
- 2: Noticeable use of metaphors, cutesy framing, or promotional tone that distracts from legal analysis.
- 1: Whimsical/analogy-heavy or emoji-laden; not suitable for a legal comparison.

Explanation Style
- 5: Scannable structure. Short intro; clear two-bucket (strict vs lenient) comparison table with columns such as notification window, max penalties, notable liability/safe harbors; followed by concise per-country bullets. Optional closing with “Observed trends/Practical takeaway.” Minimal prose; consistent headings.
- 4: Well-structured with headings and bullets and at least one compact comparison element; may lack full two-bucket tables or a column but remains easy to scan.
- 3: Some structure (bullets/headings) but no clear two-bucket table; reader must piece together comparisons from text.
- 2: Dense paragraphs with limited headings/bullets; hard to scan; comparisons are implicit.
- 1: Disorganized narrative or analogy-driven exposition with poor readability for quick comparison.