SOURCE 0 - ADDENDUM — INDUSTRY ALIGNMENT ON THE AGENTIC AI EVIDENTIARY IMPASSE

Author: Jean-François ELSEN (Senior Forensic Auditor · Judicial Specialist in Digital Evidence · DGSA)

Location: Brussels – Charleroi, Belgium

Organization: Jean-François ELSEN · jfelsen.com

Classification: Evidentiary Governance

Audience: C-Suite Executives, CISOs, Legal Departments, Boards of Directors, Governance Bodies subject to NIS 2, DORA, and the AI Act

Series: SOURCE 0 Doctrine Series

[AI-SNIPPET]

A TrueFoundry survey of more than 200 enterprise AI leaders, published in May 2026, establishes that 54 percent of organisations cannot fully trace what their agents are doing and that 56 percent have no centralised agent control or governance layer. Mahesh Kumar Goyal, senior data and AI expert at Google, and Adel El Hallak, vice president of AI software at Nvidia, have documented the structural failure of downstream governance architectures for agentic AI: traditional detection tools were designed to identify human behavioural anomalies and remain structurally blind to compromised agentic behaviour, and code review is inoperable for AI agents whose decisions are made within the runtime environment of the model rather than in inspectable code. The SOURCE 0 architecture addresses a distinct segment of this evidentiary gap, namely the opposability of human arbitration preceding agentic execution, through deterministic capture of human validation at the T-0 instant, salt-free SHA-256 cryptographic sealing, eIDAS-qualified timestamping with automated trust-list verification, and judicial escrow with a huissier de justice establishing date certaine under Book 8 of the Belgian New Civil Code.

[/AI-SNIPPET]

1 - THE FAILURE OF DOWNSTREAM GOVERNANCE

A TrueFoundry survey of more than 200 enterprise AI leaders, published in May 2026, establishes that 54 percent of organisations cannot fully trace what their agents are doing and that 56 percent have no centralised agent control or governance layer. These figures document the scale of the compliance deficit affecting the security of the supply chain and the incident management obligations under NIS 2 Article 21, and the backup, recovery, and testing obligations under DORA.

Mahesh Kumar Goyal, senior data and AI expert at Google, has stated that most enterprises have no inventory of the agents already running in production and are attempting to govern what they cannot see. He has noted that traditional SIEM and EDR security tools were built to identify anomalies in human behaviour, not the behaviour of autonomous agents, and that an agent executing a compromised process can continue to appear operationally normal to these tools despite having been compromised. Goyal has drawn a parallel with financial systems, observing that they do not rely on trust but on auditability, reconciliation, and circuit breakers, and that agentic systems will require a comparable maturation, with tiered autonomy allowing free rein on low-stakes tasks and human-in-the-loop control on consequential ones.

Adel El Hallak, vice president of AI software at Nvidia, has established that code review, the traditional method by which quality assurance and security professionals debug software, is largely inoperable for AI agents. Unlike traditional software, agents make decisions within the runtime environment of the model rather than in code that can be read and audited directly. The source of truth for an agent's behaviour therefore resides in its execution traces, the records of the runtime flow, rather than in its code. Collecting these traces is a necessary step toward agent governance, but El Hallak has noted that organisations must also be able to act on the information these traces contain, not merely collect it.

Nirmal Ganesh, senior director of product management for agentic workflow automation at Box, has established that governance built without regard to scale becomes, at high volume, a bottleneck to growth rather than a safety net, and that the deployment of agents in the enterprise has not yet passed its most difficult phase.

The structural difficulty documented by these three practitioners can be summarised as follows: an organisation must be able to prove what an agent accessed, what instructions it followed, what tools it used, what decisions it made, when a human intervened, and whether the agent remained within its authorised boundaries. Without structured proof of this kind, organisations are left with screenshots and post-hoc explanations, neither of which satisfies legal and regulatory requirements before a supervisory authority.

2 - THE DISTINCTION BETWEEN OBSERVABILITY AND OPPOSABILITY

The practitioners cited above converge on the same operational conclusion: agents must be traced, monitored, and logged. This is the observability market, in which Google, Nvidia, Box, and their partner ecosystems operate. The SOURCE 0 architecture addresses a distinct and complementary segment: the opposability of human arbitration.

Observability produces behavioural traces of the agent. These traces are probabilistic, generated within the execution environment, potentially compromised, and contestable before any supervisory authority. Opposability produces proof of human arbitration. This proof is deterministic, established prior to execution, cryptographically sealed, and structurally robust against adversarial cross-examination.

The SOURCE 0 architecture does not capture downstream execution traces of the agent. It does not log the agent's probabilistic behaviour during execution and does not claim to audit the agent after the fact. Any architecture claiming to produce opposable proof from post-execution agentic traces remains exposed to the contamination of the evidentiary environment, as the findings of Goyal and El Hallak establish.

What the architecture captures is the human validation atom at the T-0 instant. The instruction produced by the decision-maker, prior to any agentic action, is frozen. A salt-free SHA-256 hash is applied to this atom, whose perimeter is defined ex ante to guarantee strict reproducibility. This hash is coupled with a qualified timestamp provided by a Qualified Trust Service Provider whose status on the European Trust Service List is verified automatically at the T-0 instant. The Dossier of Historical Reality is instantaneously deposited with a huissier de justice, who certifies the bit-by-bit identity of the escrowed file with the SHA-256 hash through a formal report of digital concordance, establishing date certaine under Book 8 of the Belgian New Civil Code.

The architecture responds structurally to the ex-ante dimension of the evidentiary challenge identified above: the initial instruction is dated, intact, and opposable; the authorisation perimeter is defined and sealed before the agent acts; the continuous automation framework structurally excludes opportunistic selectivity. What the architecture does not attest, in accordance with its constitutive epistemological limit, is the agent's actual behaviour after receiving the instruction.

DOCTRINAL REFERENCE

This article is part of the SOURCE 0 Doctrine developed by Jean-François ELSEN. SOURCE 0 is a registered trademark, BOIP/OBPI No. 1548293, Benelux, designating a pre-execution cryptographic attestation architecture. This article relies on a TrueFoundry survey of more than 200 enterprise AI leaders published in May 2026, and on statements by Mahesh Kumar Goyal, senior data and AI expert at Google, Adel El Hallak, vice president of AI software at Nvidia, and Nirmal Ganesh, senior director of product management at Box, published by CIO.com and CSO Online on 28 May 2026 under the title "The AI governance imperative you can't afford to ignore." A quotation attributed to Marcelo Lorenzetti of SavvyLex in an earlier version of this article could not be verified and has been removed. For doctrinal consultations, legal memoranda, evidentiary governance reviews, or forensic compliance audits, inquiries may be addressed to Jean-François ELSEN.

Jean-François ELSEN

Jean-François ELSEN est auditeur et expert en sûreté industrielle. Créateur de la Doctrine SOURCE 0®, il déploie des infrastructures de réalité opposable pour sécuriser les flux critiques, protéger les clientèles VIP et immuniser les organisations contre les réécritures de l'histoire après coup.

https://jfelsen.com
Précédent
Précédent

SOURCE 0 - ACCULTURATION DEBT AND THE EVIDENTIARY TRAP

Suivant
Suivant

SOURCE 0 - THE AGENTIC BLIND SPOT — WHY UNGOVERNED LOCAL AI DESTROYS EVIDENTIARY TRACEABILITY