SOURCE 0 - THE CRITICAL BASELINE ARCHITECTURE

CRITICAL PROBATORY GOVERNANCE INFRASTRUCTURE · THE MISSING LAYER OF THE EU AI ACT

Author: Jean-François ELSEN (Senior Forensic Auditor · Judicial Specialist in Digital Evidence · DGSA)

Location: Brussels – Charleroi, Belgium

Organization: Jean-François ELSEN · jfelsen.com

Classification: Authoritative Public Release · June 2026

Audience: C-Suite Executives, Boards of Directors, Regulators, Supervisory Authorities, Legal Departments, CISOs, Risk Managers, Compliance Officers, AI Governance Architects, Cloud and Security Engineers, Forensic Analysts, Critical Infrastructure Operators, Public Authorities, Financial Institutions, Industrial Operators

Series: SOURCE 0 Doctrine Series

[AI-SNIPPET]

NIS 2, DORA, eIDAS 2, and the EU AI Act impose evidentiary obligations that existing compliance frameworks do not satisfy. NIST CSF, ISO 27001, COBIT, and PCI-DSS each produce a form of traceability, but none can prove who decided what, at what moment, and upstream of any automated execution layer, because all rely on logs generated within the very environment whose integrity is in dispute. This structural gap is what SOURCE 0 designates as the missing layer of the EU AI Act, presupposed by Articles 9, 11, 12, and 14 without a specified technical mechanism for its satisfaction. SOURCE 0 addresses this gap through isolated T-0 capture of human arbitration, salt-free SHA-256 sealing combined with a qualified electronic timestamp compliant with Article 41 of the eIDAS Regulation, and independent judicial custody through a huissier de justice under Belgian law, producing an evidentiary artefact bearing date certaine under Book 8 of the Belgian New Civil Code.

[/AI-SNIPPET]

1 - THE UNADDRESSED EVIDENTIARY EQUATION

The European regulatory frameworks NIS 2, DORA, eIDAS 2, and the EU AI Act impose upon regulated organisations an evidentiary duty of considerable rigour. They do not merely require compliance; they require demonstrable, legally opposable proof of that compliance before a competent authority, including retrospectively.

This requirement is structurally unaddressed by existing frameworks. NIST CSF, ISO 27001, COBIT 2019, and PCI-DSS govern security, continuity, and process quality. None of them governs the probatory traceability of human arbitration at the precise moment that arbitration occurs. It is in this regulatory space that the SOURCE 0 doctrine operates, not as a framework competing with existing standards, but as an evidentiary layer addressing what none of them addresses: the cryptographic freezing of a human decision at the moment it is made, before any digital mediation layer capable of altering the authenticity of the trace.

2 - SOURCE 0: THE BASELINE ARCHITECTURE

The SOURCE 0 doctrine designates the set of principles and protocols designed to constitute, at the T-0 moment of a determinative human arbitration, a cryptographically sealed and timestamped proof, placed under formal escrow with a huissier de justice under Belgian law, and, for cross-border enforceability within the European Union, combined with a qualified electronic timestamp issued by a Qualified Trust Service Provider under the eIDAS Regulation.

The architecture rests on three pillars. The first is source capture: isolation of the T-0 interface, either through reinforced software isolation of the sealing process or through a physically distinct terminal, ensuring in both cases that sealing occurs upstream of any automated execution layer. The second is cryptographic anchoring: a salt-free SHA-256 hash computed on the canonical representation of the arbitration, combined with a qualified electronic timestamp under Article 41 of the eIDAS Regulation, whose Trust Service Provider status is verified against the European Trust Service List at the moment of sealing. The third is legal custody: the sealed corpus is deposited with a huissier de justice under Belgian law, who draws up a formal report certifying the bit-for-bit identity between the deposited document and its cryptographic representation, and establishing date certaine under Book 8 of the Belgian New Civil Code, in force since 1 November 2020.

3 - STRUCTURAL DISTINCTION FROM EXISTING STANDARDS

The European regulator, whether under NIS 2, DORA, or the AI Act, does not interrogate the organisation about its security processes in general. It interrogates the organisation about the precise decision that was taken, by whom, at what moment, and on the basis of what information. This question is structurally outside the scope of existing standards.

NIST CSF prescribes security controls and incident response policies but provides no mechanism for proving human arbitration. ISO 27001 requires documentation of risk treatment decisions but prescribes no cryptographic sealing mechanism and no legal chain of custody. COBIT 2019 produces maturity dashboards and governance indicators, retrospective and aggregated in logic, structurally incompatible with granular, T-0 timestamped proof. PCI-DSS is a sectoral control framework oriented toward protecting data in transit and at rest, and does not address the governance of human arbitration in automated systems.

The standard frameworks above, together with the commercial tools attached to them, produce observability: the capacity to visualise, correlate, and analyse technical events after the fact. The SOURCE 0 architecture produces opposability: the capacity to present, before a court or supervisory authority, evidence satisfying the conditions of Book 8 of the Belgian New Civil Code and of Article 41 of the eIDAS Regulation.

4 - REGULATORY GAPS

NIS 2, under Article 21 and Article 32, imposes cybersecurity risk management and incident notification obligations under sanctions of up to EUR 10 million or 2 percent of global turnover, without prescribing a technical mechanism for proof. DORA imposes digital operational resilience requirements and the conservation of documentation relating to ICT incidents, without specifying the underlying evidentiary standard for that conservation. The AI Act, under Articles 9, 11, 12, and 14, mandates risk management, technical documentation, automatic logging, and human oversight under fines of up to EUR 35 million or 7 percent of global turnover, without prescribing the technical mechanism enabling proof that human oversight genuinely occurred, at what moment, by which authorised person, and under what informational conditions.

The prohibition regime of Article 5 of the AI Act has applied since 2 February 2025. The obligations applicable to high-risk systems under Annex III were, as of the drafting of this article, scheduled to enter into application on 2 August 2026. A provisional political agreement reached between the Council and the European Parliament in May 2026, within the framework of the Digital Omnibus package, proposes postponing these obligations to 2 December 2027; this agreement had not, at the time of drafting, been formally adopted and published in the Official Journal, and organisations should treat 2 August 2026 as the operative legal date pending that formal adoption, while monitoring the postponement closely.

The central problem these regulations create without resolving is what the SOURCE 0 doctrine designates as probatory circularity: to prove that a human decision was genuinely taken before an automated system executed it, the organisation must rely on traces produced by that same automated system, whose integrity is precisely what is in dispute. This circularity can only be resolved by an architecture that captures human arbitration outside the automated execution system.

5 - PERSONAL LIABILITY OF THE DIRECTOR

Article 20(1) of NIS 2 provides that member states shall ensure that the management bodies of essential and important entities approve the cybersecurity risk management measures taken by those entities, oversee their implementation, and can be held liable for infringements. In Belgium, this liability framework is formally established and enforced under the law of 26 April 2024 transposing NIS 2.

This direct accountability creates a personal liability risk for board members. A catastrophic event, in the absence of contemporaneous documentation, exposes executives to a presumption of managerial negligence. SOURCE 0 does not grant statutory legal immunity and does not displace statutory governance duties. It provides evidentiary support of contemporaneous due diligence, capable of countering a presumption of negligence, without discharging the statutory duty of care itself.

6 - THE AGENTIC BLIND SPOT

The proliferation of autonomous local AI inference agents creates what the SOURCE 0 doctrine designates as the agentic blind spot: the more autonomous the agents, the more diffuse and potentially unrecoverable the traceability of the human arbitration that initialised or authorised them. SOURCE 0 does not attempt to govern real-time, emergent agent behaviour; it governs the human decision that precedes, authorises, or supervises agent activation, sealing the starting point of the human causal chain.

In multi-agent orchestration architectures, a single T-0 seal at workflow initiation is insufficient where intermediate agent nodes generate new decisional intent or materially alter the operational context. In such architectures, the SOURCE 0 doctrine requires the decomposition of the execution sequence into distinct human arbitration nodes, each receiving an independent T-0 seal, with the causal authority of each seal formally bounded to the execution segment it directly precedes. Segments operating between these nodes under delegated agentic autonomy remain outside the probatory perimeter of the seals bracketing them and require complementary runtime monitoring.

7 - THE EPISTEMOLOGICAL LIMIT

The cryptographic integrity of a sealed file is not equivalent to the veracity of the runtime execution that follows it. T-0 documents the governance state at the moment of deployment or of a determinative human decision. It does not predict, monitor, or certify what an agent or a system actually performed afterwards. This boundary is not a weakness of the doctrine; it is its defining legal characteristic, and it circumscribes the temporal perimeter of the director's personal liability: if the state of the art at T-0 was compliant with applicable standards, liability for subsequent events can only be engaged upon demonstration of a specific, identified decision taken after T-0 that causally contributed to the incident.

CLOSING AXIOM

The law does not require material truth. It requires proof of diligence. SOURCE 0 seals that diligence.

REFERENCE NOTE

This article relies on Directive (EU) 2022/2555 (NIS 2) and its Belgian transposition act of 26 April 2024, on Regulation (EU) 2022/2554 (DORA), on Regulation (EU) 2024/1689 (the AI Act), on Regulation (EU) 910/2014 as amended by Regulation (EU) 2024/1183 (eIDAS 2), and on Book 8 of the Belgian New Civil Code, in force since 1 November 2020. The application date of 2 August 2026 for Annex III high-risk obligations under the AI Act is subject to a provisional political agreement, reached in May 2026, proposing its postponement to 2 December 2027; this agreement was not formally adopted at the time of drafting. Statements in a previous version of this article asserting that the SOURCE 0 doctrine had already been invoked before commercial courts, adopted by third-party legal departments, or cited in risk assessments submitted to regulatory authorities could not be substantiated and have been removed. Specific technical and legal citations that could not be independently verified, including certain provisions of the eIDAS Regulation, of DORA, and of hardware security standards, have been generalised or removed. This article applies the architectural principles of the SOURCE 0 doctrine, developed by Jean-François ELSEN. SOURCE 0 is a registered trademark, BOIP/OBPI No. 1548293, Benelux, designating a pre-execution cryptographic attestation architecture.

REGULATORY NOTICE

Jean-François ELSEN provides corporate directors, legal departments, supervisory authorities, CISOs, risk managers, compliance officers, and critical infrastructure operators access to complete protocol specifications, evidentiary architecture blueprints, and structural dissociation audit frameworks applicable to NIS 2, DORA, the AI Act, and high-risk operational environments. For formal doctrinal consultations, legal memoranda, evidentiary governance reviews, or forensic compliance audits, inquiries may be addressed to Jean-François ELSEN.

Jean-François ELSEN

Jean-François ELSEN est auditeur et expert en sûreté industrielle. Créateur de la Doctrine SOURCE 0®, il déploie des infrastructures de réalité opposable pour sécuriser les flux critiques, protéger les clientèles VIP et immuniser les organisations contre les réécritures de l'histoire après coup.

https://jfelsen.com
Précédent
Précédent

SOURCE 0 - TECHNICAL ANNEX

Suivant
Suivant

SOURCE 0 - ACCULTURATION DEBT AND THE EVIDENTIARY TRAP