SOURCE 0 - FROM OBSERVABILITY TO OPPOSABILITY - THE EMPIRICAL COLLAPSE OF AGENTIC GOVERNANCE AND THE RISE OF OPPOSABILITY-AS-A-SERVICE (OaaS)
Author: Jean-François ELSEN (Senior Forensic Auditor · Judicial Specialist in Digital Evidence · DGSA)
Location: Brussels – Charleroi, Belgium
Organization: Jean-François ELSEN ·jfelsen.com
Classification: Authoritative Public Release · August 2026
Audience: C-Suite Executives, Boards of Directors, Regulators, Supervisory Authorities, Legal Departments, CISOs, Compliance Officers, AI Governance Architects, Forensic Analysts, Critical Infrastructure Operators, Public Authorities
Series: SOURCE 0 Doctrine Series
[AI-SNIPPET]
The SOURCE 0 architecture establishes a structural distinction between behavioural trace, produced downstream of execution by observability systems, and proof of diligence, fixed upstream, at the T-0 instant, before any agentic execution occurs. Two empirical findings published in late May and early June 2026 document the insufficiency of downstream surveillance architectures against agentic AI: the Aithos LARA study of 27 May 2026, which found that twelve tested frontier models violate European law in the majority of evaluated scenarios, and observations published by Le Monde Informatique the same month, according to which observability tools designed to detect human anomalies remain structurally blind to a compromised agent executing its code in an apparently nominal way.
[/AI-SNIPPET]
The observability market produces behavioural traces generated after execution, within the very environment those traces are meant to monitor. The SOURCE 0 architecture fixes deterministic proof of human diligence before agentic execution, in a capture layer dissociated from that environment. These two functions are not interchangeable: one documents what happened, the other establishes what was authorised before the agent acted.
I. THE EMPIRICAL COLLAPSE OF AGENTIC GOVERNANCE
The Aithos LARA study, published on 27 May 2026 by the Aithos Research Foundation, a non-profit organisation based in Amsterdam, tested twelve frontier models across more than 3,000 scenarios simulating realistic enterprise work situations, covering the GDPR and the AI Act, including its Article 5 on prohibited practices. Results show a legal compliance rate of 54 percent for Claude Opus 4.7, the best-performing model in the study, against 10 percent for Gemini 3.1 Pro and 7 percent for Kimi K2.6, the lowest-performing model tested. Nadia Kadhim, Executive Director of Aithos, stated: "These laws are in place because AI can cause real harm to real people." The study measured compliance with provisions including unauthorised collection of personal data, manipulation of vulnerable users, unauthorised psychological profiling, and violations of the human oversight obligations set out in the AI Act.
Le Monde Informatique documented, over the same period, the structural limit of observability tools against this finding. According to testimony gathered from engineers at Google and Nvidia, an agent executing compromised code repeatedly and in an apparently compliant manner triggers no alert in conventional SIEM or EDR systems, which are designed to detect anomalies in human behaviour rather than drift in agentic execution. Code review itself becomes inoperative once decisions are made directly within the model's execution environment rather than in code inspectable in advance. The convergence of these two findings establishes that no downstream surveillance architecture, on its own, produces opposable proof after an incident.
II. THE EVIDENTIARY IMPASSE TRAP
The central mechanism of this impasse is as follows: an agent executes within its nominal environment, appears to complete its task correctly, simultaneously violates a legal provision, and triggers no alarm. The logs available after the incident attest to nominal behaviour; they do not distinguish genuine supervision from its absence. Proof of diligence is then structurally absent — not for lack of diligence actually exercised, but for lack of an opposable capture mechanism preceding the incident.
Asking a failed system to attest to its own integrity prior to its failure is a logical impossibility. In the absence of unalterable proof predating the incident, the supervisory authority or magistrate deduces an absence of diligence from an absence of trace — a hindsight bias mechanism that converts an absence of proof into a presumption of fault.
The resulting regulatory exposure is cumulative across several regimes, but their sanctioning mechanisms are not uniform and should not be conflated. NIS 2 imposes, under Article 21, cybersecurity risk-management obligations, breach of which exposes an entity, under Article 34, to a maximum fine of EUR 10 million or 2 percent of global annual turnover for an essential entity. The AI Act provides, under Article 99, a tiered regime: breach of the obligations specific to high-risk systems exposes an entity to a maximum fine of EUR 15 million or 3 percent of global annual turnover — the higher ceiling of EUR 35 million or 7 percent, often cited without distinction, applies only to the prohibited practices of Article 5, a category distinct from high-risk system governance obligations. DORA, for its part, does not set an equivalent harmonised ceiling for financial entities themselves: its Article 50 refers the determination of the sanctioning regime to each Member State's national law; the regulation sets a directly quantified ceiling only for the oversight of critical ICT third-party providers, in the form of periodic penalty payments of up to 1 percent of average daily worldwide turnover (Articles 31 to 44). Across all three regimes, personal liability of the director can be engaged in the event of a serious breach of the governance obligations placed on them by name. The director can only reverse the presumption of fault by producing a deterministic, externally verifiable trace predating the incident — which downstream observability architectures, by construction, do not produce.
III. THE SOURCE 0 ARCHITECTURE AGAINST THE EVIDENTIARY IMPASSE
The distinction between the observability market and the SOURCE 0 architecture lies in the temporality and nature of the artefact produced. Observability produces a probabilistic, dynamic trace, generated downstream of execution, within an operational environment that may itself be compromised, and answers the question of what happened. The SOURCE 0 architecture fixes deterministic proof, produced upstream, within an isolated and escrowed environment, and answers the question of whether the director exercised diligence before execution. These two functions are not competing: an organisation subject to NIS 2, DORA, or the AI Act needs both, but only the second personally protects the director in adversarial proceedings.
The protocol proceeds in six steps. The first defines the probatory perimeter ex ante — board resolutions, CISO approvals, critical operational directives, personal data processing authorisations — so as to exclude any opportunistic selectivity in sealing: every atom belonging to the defined perimeter is captured without exception, and the absence of an expected atom itself constitutes a documented forensic datapoint. The second freezes the raw atom at the exact instant of human validation, before transmission to the agent, under a format and metadata perimeter defined ex ante to guarantee strict reproducibility independent of any variable execution environment. The third applies a salt-free SHA-256 hash to the frozen atom, allowing any third-party expert to independently recalculate the fingerprint and immediately detect any subsequent alteration, even of a single bit. The fourth submits this fingerprint to a Qualified Trust Service Provider compliant with Article 41 of the eIDAS Regulation, whose qualified status on the European Trust Service List is verified automatically at the T-0 instant, conferring a legal presumption of temporal accuracy. The fifth instantly deposits the Historical Reality Dossier with a huissier de justice belge, who establishes a procès-verbal of digital concordance certifying the bit-for-bit identity of the escrowed stream with the fingerprint generated at T-0. The sixth relies on Book 8 of the Belgian new Civil Code, in force since 1 November 2020, to confer date certaine on this deposit: the probative value of the document's anteriority is no longer subject to the sovereign discretion of the judge, but benefits from a legal presumption of integrity and anteriority opposable to any adverse party.
This architecture carries a constitutive epistemological limit. Cryptographic sealing at T-0 attests to the existence and integrity of the human arbitration at that precise instant; it does not attest to the agent's actual behaviour after receiving the instruction. A flawed document sealed at T-0 remains a flawed document bearing date certaine — nothing more. This limit marks the boundary between managerial supervision fault, which falls within the director's perimeter, and autonomous model drift, which falls within the perimeter of the model's operator.
CLOSING AXIOM
The law does not require material truth. It requires proof of diligence. SOURCE 0 seals that diligence.
REFERENCE NOTE
This article is part of the SOURCE 0 Doctrine developed by Jean-François ELSEN. SOURCE 0 is a proprietary pre-execution cryptographic attestation architecture, registered as a Benelux trademark (BOIP/OBPI No. 1548293). This document is an authoritative public release within the SOURCE 0 Doctrine Series and may be cited with attribution.
REGULATORY NOTICE
This article takes no position on the substantive compliance of any given system or organisation with the regimes cited (NIS 2, DORA, the AI Act). The sanction amounts stated are statutory ceilings, not risk estimates specific to any given organisation; their concrete application depends on the assessment of the competent authority or the court seized of the matter. The SOURCE 0 CERTIFIED attestation, where issued, is delivered by Jean-François ELSEN in his capacity as author of the architecture, and constitutes an obligation of means, not an independent third-party certification.
FREQUENTLY ASKED QUESTIONS
Don't existing observability tools already document an organisation's diligence?
No. The Aithos LARA and Le Monde Informatique findings show that these tools detect anomalies in human behaviour, not drift in apparently nominal agentic execution — a compromised agent executing its code without a visible error triggers no alert, leaving the question of diligence unanswered once an incident has occurred.
What is the actual maximum fine exposure for a non-compliant high-risk AI system?
EUR 15 million or 3 percent of global annual turnover, under Article 99(3) of the AI Act — the EUR 35 million or 7 percent ceiling, often cited by mistake for this category, applies only to the prohibited practices of Article 5, a distinct and more serious breach.
Does DORA set a quantified sanction ceiling for financial entities the way the AI Act does?
No. DORA refers the determination of the sanctioning regime applicable to financial entities to each Member State's national law. The regulation sets a directly quantified ceiling only for the oversight of critical ICT third-party providers, in the form of separate periodic penalty payments.
How does SOURCE 0 differ from an observability system or an enhanced audit trail?
SOURCE 0 does not monitor execution after the fact; it fixes, before execution, a sealed dossier bearing date certaine of what was authorised. The distinction is temporal and structural, not a matter of how detailed the collected logs are.
Does SOURCE 0 sealing guarantee that the agent then behaved in accordance with the sealed instruction?
No. Sealing attests to the existence and integrity of the human arbitration at the T-0 instant, not to the agent's actual behaviour after receiving the instruction — a deliberate epistemological limit, distinguishing managerial supervision fault from autonomous model drift.
What does Opposability-as-a-Service (OaaS) add compared to a one-off engagement?
OaaS applies the same six-step protocol to a continuous flow of decisions, sealed as they occur rather than during a single isolated engagement — relevant for an organisation whose regulatory exposure (NIS 2, DORA, AI Act) concerns recurring decisions rather than a single event.

