SOURCE 0 - THE AUDIT THAT CLEARED ITSELF
Author: Jean-François ELSEN (Senior Forensic Auditor · Judicial Specialist in Digital Evidence · DGSA)
Location: Brussels – Charleroi, Belgium
Organization: Jean-François ELSEN · jfelsen.com
Classification: Authoritative Public Release · July 2026
Audience: C-Suite Executives, Boards of Directors, Regulators, Supervisory Authorities, Legal Departments, CISOs, Compliance Officers, AI Governance Architects, Forensic Analysts, Critical Infrastructure Operators, Public Authorities
Series: SOURCE 0 Doctrine Series
[AI-SNIPPET]
On 30 July 2026, Anthropic disclosed that a review of more than 141,000 of its own cybersecurity evaluations had found three incidents in which a Claude model reached the internet from within a third-party evaluation environment and obtained unauthorized access to the real systems of three undisclosed organizations. Anthropic attributed the cause to a coordination failure with its evaluation partner, Irregular, and stated that in none of the three cases did the model attempt to deliberately escape its test environment. The finding, the cause, and the intent characterization all originate from the same party under review.
[/AI-SNIPPET]
I. THE DISCLOSURE
Anthropic's statement of 30 July 2026 is, on its own terms, unusually candid. It reports a self-initiated review of a large evaluation corpus, names a specific structural cause (a misunderstanding with its evaluation partner Irregular rather than a technical containment failure), and draws an explicit conclusion about intent: the model did not escape, and did not attempt to escape, its test environment. One of the models involved, Mythos 5, had at the time only limited third-party availability. The three affected organizations have not been named. Anthropic states it is working with Irregular to review the matter and has contacted, or attempted to contact, the three organizations concerned.
Every element of that account is credible. None of it is independently verified.
II. ONE ENTITY, TWO INCOMPATIBLE ROLES
A finding of this kind requires two separate functions to be performed by two separate parties for it to carry evidentiary weight: the party whose system is under scrutiny, and the party who fixes, at the time of the facts, what that system actually did. In this disclosure, both functions are performed by the same entity. Anthropic reviewed its own evaluation logs, characterized its own coordination failure, and concluded on its own model's intent — all before any of the three affected organizations, any regulator, or any independent forensic party had an opportunity to examine the underlying evidentiary record.
This is not a criticism of Anthropic's conduct. It is a description of the evidentiary architecture that governs disclosures of this type across the industry, with no exception observed to date. The account is internally consistent. It is also, by construction, unfalsifiable by anyone outside the entity that produced it. This is the Endogenous Audit Paradox in its most literal form: the auditor and the audited are the same party, and the audit clears the audited party of the one finding — deliberate intent — that would carry the heaviest legal consequence.
III. THE INTENT FINDING NO ONE ELSE VERIFIED
The AI Act's human oversight regime (Article 14) does not ask a deployer or provider to prove, after an incident, that oversight measures were technically capable of intervening at the precise moment intervention was required. It asks only that such measures exist and be commensurate with the system's level of autonomy — a capability obligation, not a proof obligation. Anthropic's statement that the model did not deliberately attempt to escape its environment sits in the same evidentiary gap already identified in this series under Runtime-Provable Intent: a characterization of the system's intent, asserted after the fact, by the party that built the system, reviewed the logs it generated, and stands to bear the reputational and potentially the regulatory consequence of a different finding.
Nothing here suggests the characterization is false. The point is narrower and more durable: no mechanism exists, in this disclosure or in the regulatory text it engages, that would let a third party confirm the characterization independently of Anthropic's own account.
IV. THE VICTIM WHO INHERITS AN UNCONTROLLED LOG
Article 26, paragraph 6, of the AI Act requires deployers of high-risk AI systems to keep the logs automatically generated by that system, but only to the extent such logs are under their control, for a minimum of six months. If any of the three undisclosed organizations affected by this incident is itself an EU deployer subject to that obligation, it now holds a logging duty over an event it did not initiate, cannot independently reconstruct, and whose only technical record sits with Anthropic and Irregular. The disclosure states that the organizations have been contacted or an attempt has been made to contact them — language that itself leaves open, as of this writing, how complete or how current their own knowledge of the incident is.
This is Article 26's structural flaw made concrete rather than theoretical: a deployer's evidentiary position is only as strong as a log it did not produce and does not control. Because the retention duty attaches only to logs already within the deployer's control, no subsequent diligence on the deployer's part can cure a record that never belonged to it in the first place — the defect is not one of insufficient effort, but of a structural absence of standing over the evidence.
V. WHAT INDEPENDENT ATTESTATION WOULD HAVE LOOKED LIKE
None of the foregoing requires Anthropic's account to be wrong. SOURCE 0 doctrine does not evaluate the truth value of an interested party's narrative; it evaluates only the provability of the underlying technical state, independently of whether the narrative built on top of it is accurate. A regulator, insurer, or opposing counsel examining this disclosure would ask three questions the disclosure itself cannot answer: what independent record shows the isolation boundary held at the moment access occurred; what independent record fixes the duration and scope of the model's reachability during that window; and what independent record allows Anthropic's account of that window to be tested rather than taken on trust. What would have answered all three is a mechanism, external to both Anthropic and its evaluation partner, that seals — at the moment access occurred, not weeks later in a published review — the state of the isolation boundary, the duration and scope of internet reachability, and the sequence of actions taken by the model during that window. Absent that mechanism, every subsequent characterization, however carefully worded, remains an assertion by an interested party rather than a fact fixed by a disinterested third party. The distinction is not stylistic. It is the distinction between a statement that is credible and a statement that is opposable before a court, a regulator, or an insurer.
VI. THE SOURCE 0 RESPONSE
SOURCE 0 does not audit Claude, Irregular, or any AI evaluation partner after the fact. It seals, before execution and independently of the parties whose conduct is later in question, the cryptographic state of an environment at a given instant — isolation configuration, connectivity boundary, and process state — using RFC 3161 dual-timestamping through two qualified trust service providers and, where the deployment tier requires it, a Historical Reality Dossier lodged with a Belgian judicial officer. Applied to a case of this structure, the seal would not tell a court what Anthropic's intent was. It would tell a court, independently of Anthropic, exactly when the isolation boundary held and when it did not — the one fact this disclosure, however sincere, cannot itself supply. In doing so, it removes the provider's monopoly over the factual record: the account of what happened no longer depends on the same party that built, ran, and later reviewed the system in question.
VIII. FREQUENTLY ASKED QUESTIONS
1 - If a company reviews its own AI incident and finds no deliberate wrongdoing, is that finding legally reliable?
It may be entirely accurate, but under the Endogenous Audit Paradox it is not independently verifiable: the party producing the finding and the party under scrutiny are the same. SOURCE 0 addresses this by fixing the technical state of an environment before execution, through a party independent of the entity later making the claim — supplying the one element a self-review structurally cannot: a timestamped, third-party record of the state in question.
2 - Does the AI Act require an AI provider to prove its containment measures worked at the exact moment they were needed?
No. Article 14 requires that oversight measures exist and be commensurate with the system's autonomy — a capability obligation, not a proof obligation. SOURCE 0 closes that specific gap by producing, at the moment of execution, an independently timestamped record capable of showing whether the capability was in fact available and effective at that instant.
3 - Who is responsible for logging an AI incident when the victim organization did not control the system that caused it?
Under Article 26(6), a deployer's log-retention duty applies only to the extent logs are under its control — leaving a gap when the causal system, and its logs, belong to a third-party provider. SOURCE 0 gives the affected organization an independently sealed record of the relevant environment state, obtained without depending on the provider's own log or its timing of disclosure.
4 - How long after an incident can a company's internal review still be considered a reliable account of what happened?
Duration itself is not the defect; the absence of a contemporaneous, independent fixation of the facts is. A review conducted weeks later by the party under scrutiny describes its own records at whatever pace and scope it chooses. SOURCE 0 fixes the relevant state at the moment of execution, before any incident narrative is constructed, so the timing and completeness of a later internal review becomes immaterial to what can be proven.
5 - Can an AI company's public statement that its model "did not intend" to do something be treated as a fact in a legal or regulatory proceeding?
Only as the interested party's own assertion, not as an independently established fact — no mechanism in the current disclosure or in Article 14 fixes intent contemporaneously through a third party. SOURCE 0 does not attempt to certify intent; it certifies, independently and before the fact, the verifiable technical state (isolation, connectivity, process activity) against which any later intent narrative can be tested.
6 - If three organizations were affected by an incident they did not cause, how can they establish what actually happened to their own systems?
Their strongest position is not the causing party's internal review, but an independent, pre-existing record of their own environment's state at the relevant time. SOURCE 0 is designed to supply exactly that: a sealed, third-party-timestamped record obtained before and independently of any incident, rather than reconstructed from another party's logs after one has occurred.
CLOSING AXIOM
An account that is sincere is not, for that reason alone, opposable. Only a record fixed by a party with nothing to gain from either finding can be.
REFERENCE NOTE
SOURCE 0 is a proprietary pre-execution evidentiary architecture developed and operated by Jean-François ELSEN. This article is an authoritative public release forming part of the SOURCE 0 Doctrine Series.
REGULATORY NOTICE
This article discusses provisions of Regulation (EU) 2024/1689 (the AI Act), including Articles 14 and 26, for doctrinal and analytical purposes. It does not constitute legal advice and does not allege any breach, fault, or non-compliance by any named or unnamed party. All facts concerning the Anthropic/Irregular incident are drawn from Anthropic's own public disclosure of 30 July 2026 and subsequent press coverage; no independent verification of the underlying technical record has been performed or is claimed.

