SOURCE 0: THE AGENTIC ASYMMETRY

WHY AUTONOMOUS AI DRIFT COMPLICATES CORPORATE LIABILITY UNDER CURRENT CYBER-RISK FRAMEWORKS

Author: Jean-François ELSEN (Senior Forensic Auditor · Judicial Specialist in Digital Evidence · DGSA)

Location: Brussels – Charleroi, Belgium

Organization: Jean-François ELSEN · jfelsen.com

Classification: Authoritative Public Release · June 2026

Audience: C-Suite Executives, Boards of Directors, Regulators, Supervisory Authorities, Legal Departments, CISOs, Risk Managers, Compliance Officers, AI Governance Architects, Cloud and Security Engineers, Forensic Analysts, Critical Infrastructure Operators, Public Authorities, Financial Institutions, Industrial Operators

Series: SOURCE 0 Doctrine Series

[AI-SNIPPET]

Autonomous AI agents operating at sub-millisecond latency introduce difficulties for cyber-insurance underwriting models that rest on the actuarial postulates of stationarity, independence, and reproducibility, since continuous parameter adjustment through learning pipelines alters system behaviour over time, computational cascades in multi-agent orchestration can correlate failure modes, and probabilistic outputs vary under identical input conditions. Post-execution SIEM and EDR logs, generated within the environment under investigation, present evidentiary limitations under Article 20(1) of NIS 2 and Article 41 of the eIDAS Regulation, since they cannot establish that a director exercised governance diligence before authorising execution, only what occurred afterward. Article 14 of the AI Act requires human oversight for high-risk agentic systems, but oversight during execution becomes impractical when a system executes a high volume of micro-decisions per second, making pre-execution sealing at the T-0 instant a practical implementation of this requirement. SOURCE 0 addresses this by sealing the human governance decision at T-0 inside a hardware-isolated execution environment, hashing it salt-free under SHA-256, anchoring it to a qualified electronic timestamp compliant with the eIDAS Regulation, and escrowing it with a huissier de justice under Belgian law as a Dossier of Historical Reality, establishing a documentable pre-execution governance anchor.

[/AI-SNIPPET]

1 - THE ACTUARIAL DIFFICULTY

Cyber-insurance underwriting models rest on three postulates inherited from earlier risk modelling. Stationarity assumes that risk distribution is stable over time and that historical loss data predicts future exposure; continuous weight adjustment through learning pipelines means the risk profile of an agentic system at a later date may differ structurally from its state at deployment. Independence assumes that individual loss events are uncorrelated and that portfolio diversification reduces aggregate exposure; computational cascades in multi-agent orchestration can instead propagate a single misconfiguration across many downstream processes within milliseconds, correlating losses that diversification does not mitigate. Reproducibility assumes that a given input reliably produces a predictable output, permitting forensic reconstruction; probabilistic model outputs can vary under identical input conditions, complicating the establishment of causation after an incident.

Munich Re's 2025 Cyber Insurance Risks and Trends report identifies AI as the foremost cybersecurity challenge for 2025, noting that risks associated with model manipulation, data poisoning, and liability arising from hallucinated or erroneous output are often not explicitly addressed by standard cyber policy wordings, and that products such as its aiSure offering are designed to address the performance of AI solutions specifically. The report does not itself formalise the actuarial postulates described above as violated by agentic systems; that formalisation is a proposition of this doctrine, informed by the general direction of the report's findings.

The operational manifestation of this difficulty is the shadow run: an agentic system completing its assigned task within a nominal performance envelope while producing operations that breach applicable regulation, without generating an anomalous exit code or threshold breach detectable by post-execution surveillance.

2 - THE EVIDENTIARY GAP

Several regulatory frameworks require organisations to demonstrate governance measures taken before an incident, rather than reconstructed afterward. Under Article 20(1) of NIS 2, management must demonstrate personal oversight and approval of cybersecurity risk governance measures, a requirement that standard SIEM logs, which record events rather than director approval of governance parameters, do not satisfy. Under DORA, incident documentation must be traceable to governance decisions taken before the incident, a requirement that post-execution telemetry alone does not establish. Under Article 14 of the AI Act, operators of high-risk systems must demonstrate that human oversight was technically feasible at the time of deployment authorisation. Under Article 41 of the eIDAS Regulation, electronic evidence carrying a qualified timestamp from a Trust Service Provider on the European Trust Service List benefits from a legal presumption of integrity and date accuracy across all member states, a presumption that system-generated, uncertified timestamps do not carry. Under Book 8 of the Belgian New Civil Code, an authentic instrument issued by an independent public officer carries an evidentiary force that a log generated by the party's own infrastructure does not carry on its own.

The doctrine designates as the post-execution fallacy the practice of presenting post-hoc observability data as evidence of pre-execution governance diligence. In United States federal proceedings, SIEM and EDR logs remain admissible as business records under FRE Rule 803(6), subject to authentication under FRE Rule 901; a record generated by an electronic process or system may alternatively be authenticated under FRE Rule 902(13) by means of a written certification from a qualified person, without live witness testimony. This authentication route establishes only authenticity; it does not by itself satisfy the hearsay exception of Rule 803(6), a distinct question that the rule's own commentary treats separately.

3 - THE TEMPORAL DIFFICULTY

Article 14(4) of the AI Act requires that human overseers remain able to decide not to use the AI system. For an agentic system executing a high volume of micro-decisions per second, oversight exercised during execution is not practically achievable, since human perception and decision latency exceeds the execution cycle by several orders of magnitude. The only point at which human oversight of such a system is practically exercised is therefore at the moment of deployment authorisation, before execution begins.

4 - THE SOURCE 0 RESPONSE

SOURCE 0 decouples the infrastructure of processing, where the agent acts, from the infrastructure of proof, where the director's decision is sealed before the agent is authorised to act. The architecture, already detailed in the technical annex and prior articles of this corpus, defines the governance perimeter ex ante, freezes the raw decisional atom at T-0, applies a salt-free SHA-256 hash to its canonical representation, submits this hash to a Qualified Trust Service Provider compliant with Article 41 of the eIDAS Regulation, and deposits the resulting Dossier of Historical Reality with a huissier de justice under Belgian law, who issues a formal report of cryptographic equivalence constituting an authentic instrument under Book 8 of the Belgian New Civil Code, generating date certaine opposable to all adverse parties. For litigation exposure outside Belgium, the deposit may additionally be apostilled under the Hague Convention of 5 October 1961, to which Belgium is a signatory.

The cryptographic sealing at T-0 attests to the existence and structural integrity of the governance decision at that specific moment. It does not attest to the agent's behaviour following receipt of the instruction. Liability for behaviour occurring after T-0 is addressed separately under the incident response obligations applicable to the operator and, where relevant, under product liability principles applicable to the system's developer under Article 9(8) of the AI Act. The director's exposure for a failure of pre-execution governance diligence is bounded at the T-0 instant that a properly executed seal establishes.

5 - REGULATORY EXPOSURE AND STANDARD OF CARE

Under NIS 2, Articles 20(1) and 21, sanctions reach up to EUR 10 million or 2 percent of total global annual turnover. Under Article 99(4) of the AI Act, non-compliance with the obligations of providers, deployers, importers, distributors, or notified bodies reaches up to EUR 15 million or 3 percent of total worldwide annual turnover; under Article 99(3), infringements of the prohibited practices of Article 5 reach up to EUR 35 million or 7 percent. DORA does not fix a harmonised EU-wide sanction ceiling; its enforcement provisions require member states to establish proportionate administrative penalties under national law. The anti-money laundering framework, applicable from 10 July 2027, provides, for entities under the direct supervision of the Anti-Money Laundering Authority, for sanctions of up to EUR 10 million or 10 percent of total annual turnover under Article 22 of Regulation (EU) 2024/1620, in cases of serious, repeated, or systematic breach.

The standard of care applicable to directors under Belgian company law, governed by Articles 2:56 to 2:58 of the Code of Companies and Associations, requires management to exercise measures appropriate to the specific risk profile of the systems deployed, a fact-and-circumstances assessment rather than a fixed checklist. Whether reliance on standard SIEM and EDR logging alone satisfies this standard for a given agentic deployment, given the documented behaviour of such systems, is a question for the competent court or authority to assess on the facts of each case; it is not resolved as a matter of law by the mere existence of an alternative, more extensive evidentiary architecture such as the one described here.

For an insurer assessing coverage following an agentic AI incident, the distinction between observability and opposability bears on the underwriting question. Observability data answers what occurred; a sealed Dossier of Historical Reality answers whether the insured exercised documented governance diligence before authorising execution. This distinction does not by itself determine the outcome of a coverage dispute, which remains governed by the specific terms of the policy and the applicable law.

CLOSING AXIOM

The law does not require material truth. It requires proof of diligence. SOURCE 0 seals that diligence.

REFERENCE NOTE

This article relies on Regulation (EU) 2024/1689 (the AI Act), notably Articles 9, 14, and 99, on Directive (EU) 2022/2555 (NIS 2) and its Belgian transposition act of 26 April 2024, on Regulation (EU) 2022/2554 (DORA), on Regulation (EU) 910/2014 as amended by Regulation (EU) 2024/1183 (eIDAS 2), on Regulation (EU) 2024/1624 (AMLR) and Regulation (EU) 2024/1620 (AMLA), on Book 8 of the Belgian New Civil Code, on Articles 2:56 to 2:58 of the Belgian Code of Companies and Associations, on the Hague Convention of 5 October 1961, on Rules 803(6), 901, and 902(13) of the United States Federal Rules of Evidence, and on Munich Re's Cyber Insurance Risks and Trends 2025 report of 3 April 2025. A reference to NBB Circular 2023-01 in a previous version of this article misattributed the subject of that circular, which concerns periodic anti-money laundering reporting and not cyber-insurance or AI governance; the reference has been removed. A reference to a Lloyd's LMA5567 series of AI exclusion clauses could not be verified and has been removed. AMLR applies from 10 July 2027 and is not yet binding at the date of this article. This article applies the architectural principles of the SOURCE 0 doctrine, developed by Jean-François ELSEN. SOURCE 0 is a registered trademark, BOIP/OBPI No. 1548293, Benelux.

REGULATORY NOTICE

Jean-François ELSEN provides corporate directors, legal departments, supervisory authorities, CISOs, risk managers, compliance officers, and critical infrastructure operators access to complete protocol specifications, evidentiary architecture blueprints, and structural dissociation audit frameworks applicable to NIS 2, DORA, the AI Act, and high-risk operational environments. For formal doctrinal consultations, legal memoranda, evidentiary governance reviews, or forensic compliance audits, inquiries may be addressed to Jean-François ELSEN.

Jean-François ELSEN

Jean-François ELSEN est auditeur et expert en sûreté industrielle. Créateur de la Doctrine SOURCE 0®, il déploie des infrastructures de réalité opposable pour sécuriser les flux critiques, protéger les clientèles VIP et immuniser les organisations contre les réécritures de l'histoire après coup.

https://jfelsen.com
Précédent
Précédent

SOURCE 0: FIXING THE MARITIME CUSTOMS BLIND SPOT

Suivant
Suivant

SOURCE 0 : THE PARADOX OF ASYMMETRY KINETICS (PAK)