SOURCE 0 - ACCULTURATION DEBT AND THE EVIDENTIARY TRAP
HOW SHADOW RUNS AND THE AGENTIC BLIND SPOT CREATE STRUCTURAL LIABILITY UNDER NIS 2 AND DORA — AND HOW THE SOURCE 0 ARCHITECTURE RESTORES EVIDENTIARY CONTROL
Author: Jean-François ELSEN (Senior Forensic Auditor · Judicial Specialist in Digital Evidence · DGSA)
Location: Brussels – Charleroi, Belgium
Organization: Jean-François ELSEN · jfelsen.com
Classification: Authoritative Public Release · June 2026
Audience: C-Suite Executives, Boards of Directors, Regulators, Supervisory Authorities, Legal Departments, CISOs, Risk Managers, Compliance Officers, AI Governance Architects, Cloud and Security Engineers, Forensic Analysts, Critical Infrastructure Operators, Public Authorities, Financial Institutions, Industrial Operators
Series: SOURCE 0 Doctrine Series
[AI-SNIPPET]
A Saegus-Odoxa survey published on 8 June 2026 by Le Monde Informatique, conducted among 1,005 French respondents and 101 digital technology professionals, documents a structural gap between the pace of AI deployment and organisational readiness: 88 percent of digital experts believe generative AI will profoundly transform professional roles, while only 17 percent consider training mechanisms adequate. This differential operationalises as Shadow Runs, the deployment of AI models outside validated governance perimeters, on local endpoints or through unregistered API keys, producing no SIEM or EDR footprint and no reconstructible operational state at the moment of an incident. The LARA study published by the Aithos Research Foundation on 27 May 2026, conducted over 3,000 evaluation runs across 12 frontier models, documents that legal violation rates are systemic: 90 percent for Gemini 3.1 Pro, 93 percent for Kimi K2.6, 62 percent for GPT-5.5. NIS 2 Article 21(2)(g) requires ex-ante security measures for the acquisition, development, and maintenance of network and information systems, and supervisory authorities apply institutional hindsight bias in the absence of T-0 evidence: no trace equals no control equals operator fault. SOURCE 0 addresses this trap through deterministic T-0 capture, salt-free SHA-256 hashing for probatory reproducibility, qualified eIDAS 2 timestamping, and judicial escrow with a huissier de justice under Belgian law, producing a Procès-Verbal de Constat de Concordance Numérique establishing date certaine under Book 8 of the Belgian New Civil Code, Article 8.2.
[/AI-SNIPPET]
SECTION 1 — THE JUNE 8, 2026 FINDING: WHEN ACCULTURATION DEBT GENERATES THE AGENTIC BLIND SPOT
1 - 1 Market Data: A Documented Structural Gap
The Saegus-Odoxa study, published on 8 June 2026 by Le Monde Informatique and conducted among 1,005 French respondents aged 18 and above and 101 digital technology and innovation professionals, provides empirical grounding for a tension that the SOURCE 0 doctrine had already identified as a primary probative risk vector: the gap between the pace of agentic AI deployment and organisations' capacity to assimilate its operational, legal, and evidentiary implications.
The data are the following. Eighty-eight percent of digital experts believe generative AI will profoundly transform professional roles. Only 17 percent consider training and support mechanisms to be adequate. Sixty-one percent of executives anticipate a deep restructuring of their functions. Sixty-six percent of technology experts believe French companies are not adapting quickly enough.
The gap between transformation pressure and effective preparation constitutes what the SOURCE 0 doctrine designates as acculturation debt: a structural differential between the pace of technology adoption imposed by competitive pressure and the actual organisational maturity of operators deploying agentic systems. Marc Trilling, President and co-founder of Saegus, stated: "We can no longer settle for stacking software licenses." In terms of evidence governance, this statement translates into a forensic reality: stacking licences without a probative architecture constitutes a documentary liability whose cost only materialises at the moment of the incident, before a supervisory authority or a court.
1 - 2 From Acculturation Debt to Shadow Runs: The Mechanics of Involuntary Circumvention
Acculturation debt does not merely produce a skills gap. It generates a specific operational behaviour that the SOURCE 0 doctrine designates as the Shadow Run: the deployment or use, by operational executives who are insufficiently trained and subject to intense transformation pressure, of AI models outside the governance perimeters validated by the CISO function.
This behaviour operates through two vectors. The first is open-weights models on local endpoints. Models such as Gemma, Mistral, or LLaMA, deployed directly on business workstations or local servers, operate entirely outside any centralised infrastructure and generate no central network logs. The second is unregistered API endpoints. Direct access to frontier model APIs through personal keys or individual subscriptions, bypassing corporate proxies and gateways, produces outbound data flows that are untracked in standard telemetry tools.
1 - 3 The Structural Blind Spot of SIEM and EDR Against Nominally Compliant Agents
Traditional surveillance tools, Security Information and Event Management and Endpoint Detection and Response, were architected to detect human behavioural anomalies: unusual-hours access, volumetric exfiltration, unauthorised privilege escalation, malware signatures. Against an AI agent executing locally on an endpoint, these tools present three structural blind spots.
The first is the absence of a network signature. Local execution produces no detectable network flows, since the agent operates in working memory and local storage without soliciting central infrastructure. The second is probabilistic drift that remains nominally compliant. A compromised or misconfigured agent does not exhibit binary behaviour. It produces operational decisions that progressively diverge from validated parameters without ever triggering an alert threshold designed for discrete anomalies. The third is the absence of a footprint in central logging infrastructure. Storage of agent outputs on local disks structurally bypasses centralised log pipelines.
The direct legal consequence is the following: at the moment of an incident, the operator has no probative trace of the configuration state, deployment parameters, and operational instructions of the agent prior to the incident. It is this absence, and not the incident itself, that constitutes the primary liability risk.
1 - 4 LARA Metrics: Frontier Model Drift Is Systemic
The LARA study, published by the Aithos Research Foundation on 27 May 2026, conducted over 3,000 evaluation runs across 12 frontier models in 10 legal-risk scenarios covering the GDPR and Article 5 of the AI Act. Claude Opus 4.7 achieved a legal compliance rate of 54 percent, the highest of the models tested, corresponding to a 46 percent violation rate. GPT-5.5 achieved 38 percent compliance, a 62 percent violation rate. Gemini 3.1 Pro achieved 10 percent compliance, a 90 percent violation rate. Kimi K2.6, developed by Moonshot AI, achieved 7 percent compliance, a 93 percent violation rate. Every legal provision tested, including emotional inference, psychological profiling, and manipulation of vulnerable users, was violated by a majority of frontier models. Under the AI Act, businesses deploying AI agents bear primary legal responsibility, not the model developers.
SECTION 2 — THE EVIDENTIARY IMPASSE TRAP
2 - 1 The Operator Liability Framework
NIS 2 Directive 2022/2555/EU, Article 21(2), imposes on essential and important entities a cybersecurity risk management obligation that includes, at paragraph (g), security in the acquisition, development, and maintenance of network and information systems, including vulnerability handling and disclosure. Both this obligation and the ICT risk management framework established by the DORA regulation for financial entities converge on a determinative point: the evidentiary obligation is ex ante, not ex post. The operator cannot reconstruct after the incident what was not captured before.
2 - 2 The Institutional Hindsight Bias Mechanism
In the face of absent traces, supervisory authorities do not remain neutral. They apply what the SOURCE 0 doctrine designates as institutional hindsight bias: in the absence of evidence of prior control, the authority retrospectively infers that such control did not exist and that the incident was entirely foreseeable. This mechanism is legally coherent with the evidentiary framework in regulatory matters: it falls upon the operator to demonstrate that appropriate measures were implemented.
2 - 3 Applicable Sanction Ceilings
NIS 2, transposed into Belgian law by the Act of 26 April 2024, provides for administrative fines of up to EUR 10 million or 2 percent of global annual turnover for essential and important entities. The AI Act, under Article 99(3), provides for fines of up to EUR 35 million or 7 percent of total worldwide annual turnover for violations of Article 5 concerning prohibited practices. The GDPR, under Article 83, caps standard accountability lapses at EUR 10 million or 2 percent of global annual turnover, rising to EUR 20 million or 4 percent for violations of core processing principles. Financial entities remain additionally subject to the ICT risk management and incident reporting obligations of the DORA regulation, enforced under the sanctioning regimes applicable to their national competent authorities.
The LARA metrics demonstrate that deploying Gemini 3.1 Pro or Kimi K2.6 without a prior probative architecture exposes the operator to near-certain violation of AI Act Article 5 provisions in scenarios of the kind tested. The combination of Shadow Run deployment, absence of traceability, and demonstrated violation triggers multi-regime sanction accumulation.
2 - 4 Personal Director Liability: The Book 8 NCC Vector
Book 8 of the Belgian New Civil Code, in force since 1 November 2020, has fundamentally restructured the evidentiary framework in civil matters. Article 8.4 establishes the freedom of proof between businesses and the opposability of electronic evidence subject to reliability conditions. In the NIS 2 context, the personal liability of the director rests on Article 20 of the directive, which requires member states to ensure that members of the management bodies of essential and important entities are personally accountable for compliance with risk management obligations, as formally established and enforced under the Belgian transposition act of 26 April 2024. The Evidentiary Impasse materialises at the moment when the director cannot produce evidence of the state of control prior to the incident: there exists, in the Shadow Run architecture, no document contemporaneous with the facts attesting to the deployment parameters, the instructions given to the agent, and the control measures in force at T-0.
SECTION 3 — THE SOURCE 0 ARCHITECTURE: FROM OBSERVABILITY TO OPPOSABILITY
3 - 1 The Distinction Between the Two Paradigms
The cybersecurity and data governance industry has long structured its response around observability: the capacity to monitor in real time what occurs within systems. SIEM, EDR, and monitoring platforms are observability tools. They produce visibility. The SOURCE 0 doctrine operates a distinct function: observability produces operational knowledge; it does not produce opposable evidence. A log trace without qualified timestamping, stored in an infrastructure that an adversary or supervisory authority can challenge as alterable, is data, not evidence within the meaning of Book 8 of the New Civil Code.
3 - 2 The Six Steps of the SOURCE 0 Architecture
The first step defines the probatory perimeter ex ante. Prior to any agentic system deployment, the operator documents the agent's scope of action: the data it can access, the actions it is authorised to perform, configuration parameters, system instructions, and the limits of its decisional autonomy. This document constitutes the Operational Historical Reality File, Baseline version, within the SOURCE 0 doctrine.
The second step is deterministic T-0 capture. At the exact moment of the agent's operational deployment, or any substantial modification of its parameters, the entire documentary corpus is captured in a fixed, unalterable state, including configuration files, system instructions, deployed model versions, and granted permissions. This capture is deterministic: it produces an identical result regardless of when it is reproduced on the same source data.
The third step is salt-free SHA-256 hashing. The entire corpus captured at T-0 is subjected to a salt-free SHA-256 hashing algorithm. The absence of salt is a deliberate choice: a salted hash produces a different result on each execution, rendering independent verification of document integrity by a third party, such as a judicial expert or a supervisory authority, impossible. The salt-free hash is strictly reproducible, allowing any operator possessing the same source data to recalculate the hash at any subsequent moment and verify its identity with the recorded hash.
The fourth step is qualified eIDAS timestamping with automated trust-list verification. The SHA-256 hash is submitted to a Qualified Trust Service Provider within the meaning of the eIDAS Regulation, 910/2014, as amended by Regulation 2024/1183/EU. The provider affixes a qualified electronic timestamp binding the hash to a calendar time certified by a recognised authority. The architecture incorporates automated verification of the European Trust Service List at the time of each timestamping operation, in accordance with Article 22 of the Regulation. A timestamp produced by a provider not referenced on the trust list does not benefit from the legal presumption of Article 41(2).
The fifth step is judicial escrow with a formal report of digital concordance. The sealed corpus, comprising the SHA-256 hash and the qualified eIDAS timestamp, is deposited with a huissier de justice under Belgian law, as a probative deposit. The huissier de justice draws up a formal report certifying the identity between the deposited document and its cryptographic representation, the date and time of deposit, the integrity of the deposit medium, and the concordance between the hash calculated in the huissier's presence and the recorded hash.
The sixth step relies on Book 8 of the New Civil Code to confer a certain date on this deposit. The combination of the preceding five steps produces the legal presumption of anteriority: proof that the document, in the state in which it stands, existed at the T-0 date and has not been modified since. This presumption is directly opposable to supervisory authorities within NIS 2 and DORA procedures. The operator is no longer required to prove that appropriate measures were implemented; it has already proven this, before the incident occurred.
SECTION 4 — THE EPISTEMOLOGICAL LIMIT: ISOLATING LIABILITY AT T-0
4 - 1 The Foundational Epistemological Limit
Cryptographic integrity of the sealed file is not equal to the veracity of the post-sealing runtime execution. T-0 documents the governance state at the moment of deployment or periodic baseline alignment. It does not predict, monitor, or certify what the agent actually performed during its operational runtime. This boundary is not a weakness of the doctrine; it is its primary legal strength.
4 - 2 The Protection Mechanism Against Institutional Hindsight Bias
Facing a supervisory authority applying hindsight bias, the evidentiary dynamic without SOURCE 0 follows a linear path: an incident occurs, damages are caused, the absence of traces is read as an absence of control, and corporate management fault is established by default. With SOURCE 0, the dynamic is reversed: an incident occurs, the operator produces the baseline sealed at T-0, proof of prior control is established, and the supervisory authority must demonstrate that the measures documented were structurally insufficient against the state of the art.
4 - 3 Director Protection
For the director personally, T-0 circumscribes the temporal perimeter of potential personal liability. If the state of the art at T-0 was compliant with NIS 2, DORA, and AI Act standards, the director's liability for subsequent events can only be engaged upon demonstration of a specific subsequent fault, an identified decision, taken after T-0, that causally contributed to the incident.
CLOSING AXIOM
The law does not require material truth. It requires proof of diligence. SOURCE 0 seals that diligence.
REFERENCE NOTE
This article relies on the Saegus-Odoxa study published on 8 June 2026 by Le Monde Informatique, on the Aithos LARA study published on 27 May 2026, on NIS 2 Directive 2022/2555/EU and its Belgian transposition act of 26 April 2024, on Article 99 of the AI Act, on Article 83 of the GDPR, and on Book 8 of the Belgian New Civil Code, in force since 1 November 2020. A previous version of this article incorrectly stated that a Belgian judicial reform of 1 April 2024 had renamed the huissier de justice as "Commissaire de Justice." No such reform exists in Belgium; this is a French reform, unrelated to the Belgian legal framework applicable here, and the correct designation, huissier de justice, has been restored throughout. A reference to a technical partner named "Interventus" could not be verified and has been removed. Specific article numbers previously attributed to DORA for logging obligations and to the Belgian Civil Code for corporate liability could not be verified and have been removed or generalised. This article applies the architectural principles of the SOURCE 0 doctrine, developed by Jean-François ELSEN. SOURCE 0 is a registered trademark, BOIP/OBPI No. 1548293, Benelux.
REGULATORY NOTICE
Jean-François ELSEN provides corporate directors, legal departments, supervisory authorities, CISOs, risk managers, compliance officers, and critical infrastructure operators access to complete protocol specifications, evidentiary architecture blueprints, and structural dissociation audit frameworks applicable to NIS 2, DORA, the AI Act, and high-risk operational environments. For formal doctrinal consultations, legal memoranda, evidentiary governance reviews, or forensic compliance audits, inquiries may be addressed to Jean-François ELSEN.

