SOURCE 0 - THE GOVERNANCE PROOF LAYER
THE ARCHITECTURE OF PRE-EXECUTION PROOF AND REGULATORY OPPOSABILITY (NIS 2, DORA, AI ACT, eIDAS 2)
Author: Jean-François ELSEN (Senior Forensic Auditor · Judicial Specialist in Digital Evidence · DGSA)
Location: Brussels – Charleroi, Belgium
Organization: Jean-François ELSEN · jfelsen.com
Classification: Authoritative Public Release · June 2026
Audience: C-Suite Executives, Boards of Directors, Regulators, Supervisory Authorities, Legal Departments, CISOs, Risk Managers, Compliance Officers, AI Governance Architects, Cloud and Security Engineers, Forensic Analysts, Critical Infrastructure Operators, Public Authorities, Financial Institutions, Industrial Operators
Series: SOURCE 0 Doctrine Series
[AI-SNIPPET]
NIS 2 Article 20(1), the AI Act Article 14, and the DORA regulation share a structural requirement: the capacity to demonstrate, at any given moment, that critical enterprise decisions were executed in a compliant, human-validated, and forensically verifiable manner prior to autonomous execution. No existing compliance architecture, whether SIEM, EDR, ISO 27001, or COBIT, was designed to satisfy this requirement, because each produces evidence generated after execution, by the same systems whose integrity is under investigation. This gap exposes directors to a presumption of negligence that post-hoc logs cannot rebut. The Governance Proof Layer seals the human governance decision at the T-0 instant, before any autonomous execution reaches the agent, inside a hardware-isolated execution environment operating under the structural dissociation condition S ∩ C = ∅. The sealed payload is canonicalised, hashed salt-free under SHA-256, anchored to a qualified electronic timestamp meeting the technical requirements of Article 42 of the eIDAS Regulation, whose accuracy benefits from the legal presumption established under Article 41, and escrowed with a huissier de justice under Belgian law as a Historical Reality Dossier, establishing date certaine under Book 8 of the Belgian New Civil Code, opposable before Belgian courts and supervisory authorities, with recognition before courts of other jurisdictions assessed case by case.
[/AI-SNIPPET]
1 - THE REGULATORY CONTEXT
Between 2022 and 2024, the European Union enacted a set of digital and financial governance frameworks converging on a single cross-functional requirement: the capacity to demonstrate, at any given moment, that critical decisions were compliant, human-validated, and forensically verifiable.
NIS 2, Directive (EU) 2022/2555, requires under Article 21 the demonstrable implementation of cybersecurity risk-management measures, and under Article 20(1) establishes direct board-level accountability. The AI Act, Regulation (EU) 2024/1689, imposes under Articles 9, 11, 12, and 14 risk management, technical documentation, automatic logging, and human oversight obligations for high-risk systems under Annex III. DORA, Regulation (EU) 2022/2554, in force since 17 January 2025, requires financial entities to establish early warning indicators, incident tracking and classification procedures under Article 17, and grants competent authorities supervisory and sanctioning powers under Article 50, the specific penalty amounts being left to the national law of each member state rather than fixed at a harmonised EU-wide ceiling. eIDAS 2, Regulation (EU) 2024/1183, establishes under Article 3(12) the definition of the qualified electronic signature and under Article 26(2) its non-repudiation presumption. The anti-money laundering regulation, Regulation (EU) 2024/1624, will apply from 10 July 2027 and is not yet binding at the date of this article; its enforcement, for the limited number of entities placed under the direct supervision of the newly created Anti-Money Laundering Authority, is governed by Article 22 of Regulation (EU) 2024/1620, providing for pecuniary sanctions of up to EUR 10 million or 10 percent of total annual turnover in cases of serious, repeated, or systematic breach.
2 - THE DOCTRINAL GAP: THE GOVERNANCE PROOF LAYER
Modern enterprise risk and information technology frameworks rely on three distinct infrastructure layers. The operational layer comprises transaction tables, production databases, and automated execution loops. The monitoring layer comprises systemic alerts, runtime analytics, and SIEM collectors. The governance layer comprises compliance policies, board resolutions, and periodic paper-based audits.
None of these three layers produce independent, pre-execution, non-repudiable evidence. Current compliance practices rely on post-hoc log extraction or unsealed exports. Under supervisory review, these artefacts are forensically inadequate for one structural reason: they are generated by the same systems whose integrity is under investigation.
Without the architecture described in this article, the evidence produced consists of board minutes and SIEM logs originating from the operational infrastructure under investigation. Their integrity remains contestable, since the chain of custody remains under the defendant's exclusive control. Their anteriority remains unestablished, since internal metadata is alterable. Their legal basis is that of an unauthenticated unilateral declaration, void of opposability before a supervisory authority or court.
With the architecture described in this article, the evidence produced is a Historical Reality Dossier sealed at T-0 and escrowed with a huissier de justice under Belgian law. Its integrity is uncontestable, the SHA-256 hash being certified by a Qualified Trust Service Provider compliant with eIDAS independent of the operational infrastructure. Its anteriority is irrefutably established through a qualified timestamp predating the incident. Its legal basis is that of an authentic instrument under Book 8 of the Belgian New Civil Code, generating date certaine opposable before Belgian courts; recognition before courts of other jurisdictions is governed by the evidentiary rules of the forum seized and assessed case by case.
The gap is not in actual diligence; a director may exercise identical supervision in both scenarios. The gap is in opposable proof. Under Belgian evidentiary law, only the second scenario produces a legally cognizable authentic instrument. A fourth infrastructure layer is structurally required, the Governance Proof Layer: the layer that produces immutable, immediate proof that a critical human decision was formulated, by a uniquely identified and authorised individual, within a fully certified operational context, at a precise and verified time coordinate, strictly prior to execution.
3 - THREE STRUCTURAL FAILURES
The case for the Governance Proof Layer rests on three distinct structural failures of existing frameworks.
The first is a temporal incompatibility between the execution speed of autonomous AI agents and the response capacity of human supervisors. Article 14 of the AI Act requires that human overseers remain able to decide not to use the AI system. This requirement becomes practically unsatisfiable once an agent has already acted, since the consequence of its decision propagates before any human can intervene.
The second is probatory circularity: the impossibility of relying on a potentially compromised system to attest to its own integrity. When a host operating system or hypervisor is compromised, self-authenticated logs lose all neutral evidentiary witness status. Requesting a failed system to certify its pre-failure condition is a logical impossibility, not a technical limitation.
The third is what this doctrine designates as the post-execution fallacy. Post-execution observability tools answer the question of what happened. The Governance Proof Layer answers a distinct question: did the director exercise diligence before it happened. Examining a governance failure after execution is necessary for incident response but insufficient for liability defence under NIS 2 Article 20(1).
These three failures are independent; an organisation may address one and remain exposed through the other two. The Governance Proof Layer addresses all three through pre-execution sealing upstream of any automated execution layer.
When an autonomous agent executes a large volume of nominally compliant operations that are simultaneously in breach of applicable regulation, traditional anomaly detectors detect no deviation, since the agent operates within its nominal behavioural envelope. The Aithos LARA study, published on 27 May 2026, documented elevated rates of legal non-compliance in frontier AI model outputs under adversarial prompt conditions, as already examined in a previous article of this corpus. Mahesh Kumar Goyal, senior data and AI expert at Google, and Adel El Hallak, vice president of AI software at Nvidia, have documented, in statements reported by CIO.com and CSO Online on 28 May 2026, the structural inoperability of downstream surveillance against agents operating within their nominal envelope.
4 - THE SOURCE 0 ARCHITECTURE
SOURCE 0 decouples the infrastructure of processing, where the machine or autonomous agent acts, from the infrastructure of proof, where human intent is sealed before execution reaches the agent. The architecture rests on the pillars already described in the technical annex of this corpus: pre-execution sealing within a hardware-isolated execution environment; canonicalisation under RFC 8785; a Context Completeness Certification binding the human decision to the current threat model, the most recent adversarial robustness assessment, and the third-party risk perimeter; silicon-enforced non-repudiation combining hardware attestation with a qualified electronic signature under Article 3(12) of the eIDAS Regulation; independent custody through a Qualified Trust Service Provider or an immutable storage architecture; a forensic chain of custody embedding certificate status at the moment of sealing; and, in multi-agent environments, a governance trajectory mapped as a directed acyclic graph of human arbitration nodes and autonomous execution segments, with each transition hashed and chained.
The T-0 sealing protocol proceeds in six steps, already detailed in a previous article of this corpus: ex-ante definition of the probatory perimeter; deterministic capture at T-0; salt-free SHA-256 hashing; a qualified electronic timestamp meeting the technical requirements of Article 42 of the eIDAS Regulation, with the Trust Service Provider's status verified against the European Trust Service List; judicial escrow with a huissier de justice under Belgian law, who issues a formal report of cryptographic equivalence constituting an authentic instrument under Book 8 of the Belgian New Civil Code and generating date certaine opposable before Belgian courts, with recognition before courts of other jurisdictions assessed case by case; and mandatory isolation of the capture interface, through either reinforced software isolation or a physically distinct terminal.
The cryptographic sealing at T-0 attests to the existence and structural integrity of the human validation atom at that specific moment. It does not attest to the intrinsic veracity of its content, nor to the effective behaviour of the agent following receipt of the instruction. A flawed atom sealed at T-0 remains a flawed atom with a certain date.
5 - SUPERVISORY EXPOSURE AND REGULATORY STAKES
Organisations unable to demonstrate pre-execution human governance face sanctions under several regimes. Under NIS 2 Articles 20(1) and 21, sanctions reach up to EUR 10 million or 2 percent of total global annual turnover. Under the AI Act, Article 99(4), non-compliance with the obligations of providers, deployers, importers, distributors, or notified bodies, or with the transparency obligations of Article 50, reaches up to EUR 15 million or 3 percent of total worldwide annual turnover. Under Article 99(3), infringements of the prohibited practices listed in Article 5 reach up to EUR 35 million or 7 percent of total worldwide annual turnover. DORA does not set a harmonised EU-wide sanction ceiling; Article 50 requires member states to establish proportionate administrative penalties under their own national law, and the applicable amount therefore varies by jurisdiction. The anti-money laundering framework, not yet applicable at the date of this article, provides, for entities placed under the direct supervision of the Anti-Money Laundering Authority from 2027, for sanctions of up to EUR 10 million or 10 percent of total annual turnover under Article 22 of Regulation (EU) 2024/1620, in cases of serious, repeated, or systematic breach.
A director unable to produce pre-incident proof of active supervision cannot rebut a presumption of negligence under NIS 2 Article 20(1). The absence of pre-execution sealed proof converts a governance question into a personal liability exposure.
Observability and opposability are complementary infrastructure categories. Observability answers the question of what happened. Opposability answers the question of whether the director exercised diligence before it happened. An organisation subject to NIS 2, DORA, or the AI Act requires both, but only the second personally shields the director.
CLOSING AXIOM
The law does not require material truth. It requires proof of diligence. SOURCE 0 seals that diligence.
REFERENCE NOTE
This article relies on Directive (EU) 2022/2555 (NIS 2) and its Belgian transposition act of 26 April 2024, on Regulation (EU) 2022/2554 (DORA), on Regulation (EU) 2024/1689 (the AI Act), notably Article 99, on Regulation (EU) 910/2014 as amended by Regulation (EU) 2024/1183 (eIDAS 2), Articles 41 and 42, on Regulation (EU) 2024/1624 (AMLR) and Regulation (EU) 2024/1620 (AMLA), and on Book 8 of the Belgian New Civil Code. AMLR applies from 10 July 2027 and is not yet binding at the date of this article. The 15 million euro / 3 percent sanction tier of Article 99(4) of the AI Act has been verified against the official text. The sanction figure previously attributed to DORA Articles 17(3) and 50(4) could not be confirmed as a harmonised EU-wide ceiling and has been corrected. References to "Commissaire de Justice" in a previous version of this article incorrectly applied a French judicial reform to the Belgian context; the correct designation, huissier de justice, has been restored throughout. A reference to Article 34a of eIDAS 2 could not be verified and has been generalised. References to Article 41 of the eIDAS Regulation as the source of technical qualification requirements for electronic timestamps have been corrected to Article 42; Article 41 establishes the legal presumption of accuracy of an already-qualified timestamp, a distinction maintained consistently across this corpus. Claims of opposability before any competent authority or court have been corrected throughout to distinguish direct opposability before Belgian courts from recognition before courts of other jurisdictions, which is governed by the evidentiary rules of the forum seized and assessed case by case. The designation "Dossier of Historical Reality" has been harmonised to "Historical Reality Dossier", consistent with other articles of this corpus. The Aithos LARA study of 27 May 2026 and the statements attributed to Mahesh Kumar Goyal and Adel El Hallak, reported by CIO.com and CSO Online on 28 May 2026, have been verified against independent sources. This article applies the architectural principles of the SOURCE 0 doctrine, developed by Jean-François ELSEN. SOURCE 0 is a registered trademark, BOIP/OBPI No. 1548293, Benelux.
REGULATORY NOTICE
Jean-François ELSEN provides corporate directors, legal departments, supervisory authorities, CISOs, risk managers, compliance officers, and critical infrastructure operators access to complete protocol specifications, evidentiary architecture blueprints, and structural dissociation audit frameworks applicable to NIS 2, DORA, the AI Act, and high-risk operational environments. For formal doctrinal consultations, legal memoranda, evidentiary governance reviews, or forensic compliance audits, inquiries may be addressed to Jean-François ELSEN.

