SOURCE 0 - GATEKEEPER CONCENTRATION AND THE PROOF PROBLEM
WHY DMA DESIGNATION DOES NOT PRODUCE EVIDENTIARY INDEPENDENCE
Author: Jean-François ELSEN (Senior Forensic Auditor · Judicial Specialist in Digital Evidence · DGSA)
Location: Brussels – Charleroi, Belgium
Organization: Jean-François ELSEN · jfelsen.com
Classification: Authoritative Public Release · June 2026
Audience: C-Suite Executives, Boards of Directors, Regulators, Supervisory Authorities, Legal Departments, CISOs, Risk Managers, Compliance Officers, AI Governance Architects, Cloud and Security Engineers, Forensic Analysts, Critical Infrastructure Operators, Public Authorities, Financial Institutions, Industrial Operators
Series: SOURCE 0 Doctrine Series
[AI-SNIPPET]
Organisations relying on cloud infrastructure to store their compliance evidence face a structural problem that gatekeeper designation under the Digital Markets Act does not resolve: a regulated cloud perimeter remains a perimeter, and proof generated within it remains contestable as self-generated documentation. On 25 June 2026, the European Commission notified Amazon and Microsoft of its preliminary assessment that their cloud services, AWS and Azure, should be designated as gatekeepers under the Digital Markets Act. The Commission identified lock-in effects, high switching costs, and AI tool portfolios as determinative factors. This preliminary assessment is a regulatory fact; it is not an evidentiary solution. Gatekeeper designation under the DMA governs market conduct and does not establish the independence of the proof infrastructure operating within a gatekeeper's perimeter. The structural condition of evidentiary independence remains S ∩ C = ∅: the operating system S and the capture and attestation layer C must have no intersection, C operating outside the perimeter of S. A gatekeeper-designated cloud environment does not satisfy this condition by virtue of its regulatory status. The proof problem and the market concentration problem are distinct, and resolving one does not resolve the other.
[/AI-SNIPPET]
1 - THE REGULATORY FACT
On 25 June 2026, the European Commission notified Amazon Web Services and Microsoft Azure of its preliminary assessment that their cloud computing services should be designated as gatekeepers under Regulation (EU) 2022/1925, the Digital Markets Act. The Commission's preliminary findings identified both services as important access points between businesses and their customers in the European Union, with solidly established user bases, lock-in effects, high switching costs, and extensive ecosystems, and further noted that AI tool portfolios and cloud partnerships have become a determinative factor in cloud purchasing decisions.
These preliminary conclusions do not prejudge the outcome of the investigation. A final designation decision has not been adopted, and the regulatory process remains open. What the preliminary assessment establishes, as a matter of public record, is that the European regulatory authority has formally characterised the cloud computing market as structurally concentrated around a small number of operators whose position is durable, entrenched, and self-reinforcing.
2 - WHAT GATEKEEPER STATUS DOES AND DOES NOT ESTABLISH
A gatekeeper designation under the DMA imposes obligations of market conduct: interoperability, fair access, prohibition of self-preferencing, and data portability. It subjects the designated operator to enhanced regulatory scrutiny and potential fines for non-compliance. It does not establish the evidentiary independence of the proof infrastructure operating within the gatekeeper's perimeter.
The DMA is an instrument of competition law. It governs the relationship between a dominant platform and its business users. It does not govern the relationship between an organisation's operational infrastructure and the proof that organisation produces to demonstrate its own compliance, diligence, or good faith before a court or regulator. These are distinct legal registers, and conflating them produces a category error with direct governance consequences: an organisation that believes its compliance posture is strengthened by its cloud provider's regulatory status has confused market regulation with evidentiary architecture.
The gatekeeper designation of a cloud provider does not make the logs that provider generates on behalf of its clients any more independent, any more externally verifiable, or any more resistant to adversarial challenge. It makes the provider subject to competition law obligations. The proof problem remains unaddressed. Regulation modifies conduct, not technical perimeters; a regulated dependency remains a dependency, and a regulated perimeter remains a perimeter.
3 - THE STRUCTURAL CONCENTRATION OF PROOF WITHIN A GATEKEEPER PERIMETER
The Commission's preliminary assessment identified lock-in effects and high switching costs as defining characteristics of the cloud services under review. From an evidentiary architecture perspective, these characteristics have a direct probatory consequence: an organisation whose operational data, logs, audit trails, and compliance documentation reside within a single gatekeeper's perimeter has concentrated its proof infrastructure within the same structural dependency as its operational infrastructure.
The Commission further identified AI tool portfolios as a determinative factor in cloud purchasing decisions. This observation carries a specific evidentiary implication: when an organisation deploys AI systems within a gatekeeper cloud environment, the outputs of those systems, including the logs and audit trails meant to constrain them, are generated, stored, and managed within the same concentrated perimeter. The system generates both the action and the evidence meant to constrain that action. This is not a market concentration problem; it is the evidentiary circularity problem, already examined in prior articles of this corpus, operating at infrastructure scale.
Cloud governance mechanisms, including audit tools, policy engines, logical separation frameworks, and tenant isolation, improve internal governance. They do not produce external opposability. The proof infrastructure and the operational infrastructure remain within the same perimeter regardless of the sophistication of the internal controls applied to it. The DMA designation reveals the concentration; it does not dissolve it. A gatekeeper cloud does not merely host the proof; it is the system that produces it.
4 - S ∩ C = ∅ AS A CONDITION INDEPENDENT OF REGULATORY STATUS
The structural condition of evidentiary independence, S ∩ C = ∅, is indifferent to the regulatory status of the infrastructure on which the operating system operates. A gatekeeper-designated cloud environment does not satisfy this condition by virtue of its DMA status. The designation establishes that the provider is subject to competition law obligations; it does not establish that the provider's infrastructure operates outside the evidentiary perimeter of its clients. The opposite is structurally true: a gatekeeper cloud environment is, by the Commission's own characterisation, an environment of concentrated dependency from which exit is costly and constrained.
Hybrid architectures, including TPM-based attestation, remote attestation protocols, and partial enclave deployments, reduce the attack surface and improve internal security posture. They do not satisfy S ∩ C = ∅ for the purposes of strong opposability; reducing the intersection is not equivalent to eliminating it. The condition is binary in its evidentiary consequence: either the capture and attestation layer operates outside the perimeter of the operating system it certifies, or it does not.
Digital sovereignty, in this sense, is not a question of regulatory classification but of exclusive control over the chain of proof. A proof infrastructure that resides within a gatekeeper's perimeter, regardless of that gatekeeper's DMA status, geographic location, or certification level, remains subject to the same structural dependency as the operational data it is meant to attest. The condition S ∩ C = ∅ is satisfied only when the capture and attestation layer, C, operates on infrastructure and logic entirely distinct from those of the operating system, S, and its cloud dependencies, an architectural condition that cannot be delegated to a cloud provider, however rigorously regulated.
5 - THE DOCTRINAL IMPLICATION FOR SOURCE 0
The Landgericht München I ruling of 28 May 2026, examined in a prior article of this corpus, revealed the temporal impossibility of reconstructing a dissolved generative event. The DMA preliminary assessment of 25 June 2026 reveals the infrastructural impossibility of escaping a concentrated perimeter. The convergence of these two regulatory developments is not normative, since the München ruling operates in civil liability and the DMA in competition law; it is structural, since both expose the same architectural gap from two different directions.
An organisation that deploys AI systems within a gatekeeper cloud environment, without an independent proof infrastructure operating outside that perimeter, is simultaneously exposed to the generative event liability established by the München ruling and to the evidentiary circularity produced by gatekeeper concentration, and these two exposures compound.
The SOURCE 0 architecture addresses both through the T-0 sealing sequence already detailed in prior articles of this corpus: canonicalisation under RFC 8785, salt-free SHA-256 hash-chaining, enclave-based extraction under Intel TDX or AMD SEV-SNP, and dual-QTSP timestamping under eIDAS 2, all operating outside the perimeter of any cloud provider, gatekeeper-designated or otherwise. Enclave-based extraction operates below the hypervisor layer, outside the control perimeter of any cloud provider including a gatekeeper-designated one; this architecture is inaccessible by design to the hosting infrastructure under normal operational conditions, and its claim is one of structural separation from the infrastructure that hosts it, not of absolute inviolability. The subsequent structured deposit with a huissier de justice under Belgian law, establishing date certaine under Belgian law, produces an evidentiary artefact whose legal opposability is independent of the regulatory status of any underlying infrastructure; recognition of the resulting constat beyond Belgian jurisdiction is assessed case by case and is not presumed automatic.
CLOSING AXIOM
The law does not require material truth. It requires proof of diligence. SOURCE 0 seals that diligence.
REFERENCE NOTE
This article relies on Regulation (EU) 2022/1925 (the Digital Markets Act), on the European Commission's preliminary gatekeeper assessment of Amazon Web Services and Microsoft Azure notified on 25 June 2026, on the judgment of the Landgericht München I of 28 May 2026, already examined in a prior article of this corpus, on Regulation (EU) 910/2014 as amended by Regulation (EU) 2024/1183 (eIDAS 2), and on RFC 8785. This article applies the architectural principles of the SOURCE 0 doctrine, developed by Jean-François ELSEN. SOURCE 0 is a registered trademark, BOIP/OBPI No. 1548293, Benelux.
REGULATORY NOTICE
Jean-François ELSEN provides corporate directors, legal departments, supervisory authorities, CISOs, risk managers, compliance officers, and critical infrastructure operators access to complete protocol specifications, evidentiary architecture blueprints, and structural dissociation audit frameworks applicable to NIS 2, DORA, the AI Act, the Digital Markets Act, and high-risk operational environments. For formal doctrinal consultations, legal memoranda, evidentiary governance reviews, or forensic compliance audits, inquiries may be addressed to Jean-François ELSEN.

