SOURCE 0 - AUTONOMOUS AGENTS AND THE EVIDENTIARY VOID

Author: Jean-François ELSEN (Senior Forensic Auditor · Judicial Specialist in Digital Evidence · DGSA) Location: Brussels – Charleroi, Belgium 

Organization: Jean-François ELSEN ·jfelsen.com

Classification: Authoritative Public Release · August 2026 

Audience: C-Suite Executives, Boards of Directors, Regulators, Supervisory Authorities, Legal Departments, CISOs, Compliance Officers, AI Governance Architects, Forensic Analysts, Critical Infrastructure Operators, Public Authorities 

Series: SOURCE 0 Doctrine Series

I. AN AGENT ON THE ENDPOINT

Since late 2025, a category of software has entered corporate environments faster than the governance frameworks meant to observe it: locally-run, autonomous AI agents granted full disk access, terminal permissions, and OAuth tokens, operating from personal messaging channels and executing tasks — file management, code changes, calendar and email actions — without step-by-step human confirmation. For the purposes of this article, the category is defined narrowly: autonomous execution without per-step human confirmation, possession of credentials enabling privileged operations on the host, and — in several documented architectures — the capacity to modify its own tooling or capture path, including the very mechanisms that would otherwise record its activity. One such agent grew from a personal project to a widely deployed open-source tool within months, reaching, according to its own release notes and independent trackers, several hundred thousand installations and GitHub stars in a matter of weeks. This article does not evaluate that product's security posture; it uses its documented, publicly disclosed incident record as a case study of a structural condition affecting the category as a whole — an agent architecture with no evidentiary layer independent of the system it operates on, deployed at scale, on infrastructure the enterprise does not fully see.

Security telemetry vendors have since documented the consequence: instances of this class of agent running on corporate endpoints, outside the visibility of the security function, with system-level privileges — a pattern now generally described in the security industry, though not yet as a defined legal category, as Shadow AI. The governance question this raises is not whether such agents should be permitted. Many enterprises will conclude, correctly or not, that the productivity gain justifies the risk. The question is narrower and more tractable: once such an agent has acted, what can the enterprise actually prove about the state it was in and the activity independently captured and sealed about it, when, and under what configuration — independently of the agent's own logs?

[AI-SNIPPET]

An autonomous AI agent with system-level access on a corporate endpoint constitutes a governance exposure regardless of the security posture of the agent's vendor, because its own logs, session records, and configuration history are generated by the same system whose integrity is in question. A system cannot serve as independent proof of its own state. This is the Endogenous Audit Paradox, and it applies to autonomous agents with particular force, because the agent's defining feature — the capacity to act, and in some architectures to modify its own tooling, without a human confirming each step — removes the last point at which a human witness could otherwise attest to the state of the system before it changed. SOURCE 0 WITNESS answers this by sealing the agent's state through a point of observation isolated from the agent's own process and privileges, before that state can be called into question.

[/AI-SNIPPET]

II. THE DOCUMENTED RECORD

The evidentiary problem is not theoretical. Within weeks of one such agent's rapid public adoption, independent security researchers disclosed a critical remote-code-execution vulnerability, rated 8.8 on the CVSS scale, that allowed a malicious webpage to silently open a connection to the agent's local control interface, steal the stored authentication token, and take full administrative control of the host — including on instances that were not exposed to the internet, because the browser, not the agent, initiated the connection. A patch was issued within roughly 24 hours of disclosure.

Separately, an audit of the agent's third-party extension marketplace identified several hundred extensions distributing credential-stealing malware through misleading installation prerequisites, out of a few thousand extensions reviewed. Two further vulnerabilities affected the agent's device-authorization mechanism. A flaw in the token-rotation function (CWE-266, Improper Privilege Management) allowed a caller holding only pairing privileges to mint tokens carrying administrative scope; the fix shipped in version 2026.3.11 on 13 March 2026, with the National Vulnerability Database record, rated CVSS 3.1 9.9, following on 29 March 2026. A separate flaw in the device-pairing command path (CWE-863, Incorrect Authorization) allowed a caller with pairing privileges to approve device requests for administrative scope without ever holding it; initially scored 8.1 on disclosure, the National Vulnerability Database record was subsequently revised to 9.9 once the scope of impact was reassessed, and the fix shipped within two days of the initial report. National regulators, including China's Ministry of Industry and Information Technology, issued public advisories in early February 2026 warning that improperly configured deployments of the agent could expose users to data breaches.

III. WHY A SECURITY PATCH DOES NOT ANSWER THE GOVERNANCE QUESTION

A patch closes a vulnerability in the code that was exploited. It does not, and cannot, retroactively establish what the agent did before the patch was applied, what configuration it held at a given moment, or what a given installed extension actually contained at the time it was installed. Once a system has been compromised, or is merely suspected of having been compromised, any post-hoc reconstruction of its prior activity depends on artifacts — logs, session records, configuration snapshots — produced by that same system. This is the Post-Execution Fallacy: treating a system's own record of itself as proof, when the reliability of that record is precisely what is in question.

For an enterprise that has permitted, tolerated, or discovered an autonomous agent operating on its endpoints, this leaves a specific and answerable gap: not "is the agent secure" — a question for the agent's maintainers and the enterprise's security function — but "can we independently prove, after the fact, what state this agent was in and what it did, in a form that does not depend on the agent's own integrity." The void this article is concerned with is not the absence of logs — the agent in the case study above produced plenty. It is the absence of a point of observation sufficiently independent and technically bounded to support the specific evidentiary claim the enterprise needs to make.

IV. SEALING AGENT STATE BEFORE THE FACT

SOURCE 0 does not secure, patch, or audit the agent. It answers the narrower question above through SOURCE 0 WITNESS, a declination of the SOURCE 0 architecture built for this class of object: the state of an autonomous agent, captured before the integrity of the system that produced it is known to be compromised or becomes evidentially contestable, by a point of observation that testifies to what it captured without intervening in the agent's execution.

The mechanism does not differ from the one already operating for other regulated data flows under the SOURCE 0 architecture. SOURCE 0 WITNESS runs as this separate point of observation: the enterprise — not Jean-François ELSEN — computes a deterministic hash of the object to be sealed at the moment it is generated: the configuration of the agent's gateway, the identity and hash of an extension at the moment of its installation, a periodic snapshot of the agent's action log. That hash is pushed, by the client, into object storage under compliance lock before any further event can alter it. The cadence of this capture bounds the precision of everything that follows: a change occurring between two sealing cycles is provable only as having occurred within that interval, not to the exact moment, unless the cadence itself is set tight enough for the risk profile of the deployment. At a defined cadence, the accumulated hashes are aggregated into a Merkle root and transmitted, via a qualified electronic registered-mail service under Article 44 eIDAS, simultaneously to Jean-François ELSEN and to a Belgian huissier de justice, who certifies the date of receipt against the Merkle root alone — the huissier never accesses, inspects, or retains the underlying content of what that root represents. This simultaneity is not incidental: it prevents the sole attestation of receipt for a given root from resting on the party who designs, operates, and commercially benefits from the sealing mechanism itself. It does not make Jean-François ELSEN dispensable of all trust — the subsequent custody of the archive remains his, under the same continuity conditions already stated elsewhere in this architecture — but it means that no single party's word establishes when a given root was received.

This produces a record, external to the agent, that cannot be altered or backdated once sealed, and that does not depend on the enterprise's own IT function having preserved its own logs intact after the fact. It does not, on its own, prove that the captured object faithfully and completely reflects what the agent was or did at the moment of capture. Two distinct properties are at stake, and they must not be collapsed into one: the integrity of the captured object — that it has not been altered since it was sealed — and the authenticity of the underlying observation — that what was captured actually corresponds to the state the agent presented to the point of observation at that moment. SOURCE 0 establishes the integrity of the sealed artifact against subsequent alteration unconditionally. It establishes the authenticity of the underlying observation only to the extent that the capture point itself was not already compromised at the moment of capture — a condition the architecture cannot verify from inside itself, for the same structural reason a compromised agent cannot verify its own logs. An agent capable of modifying its own capture mechanism could, in principle, falsify or suppress an event, restore the mechanism, and produce a subsequent snapshot that is cryptographically intact and perfectly dated — and false. The resulting seal would be genuine evidence of what was captured. It would not, on that basis alone, be evidence that nothing else occurred. This is not a defect to be argued around; it is the reason capture cadence and the placement of the capture point relative to the agent's own privilege boundary are engineering decisions made explicitly with the client, not incidental details. No capture design eliminates this exposure — a sufficiently complete compromise of the host defeats any observation made on that host. Isolating the capture point from the agent's own process narrows the exposure to the subset of compromises capable of reaching the capture process itself, rather than to any compromise of the agent at all — but this is technical isolation from the agent, not legal or evidentiary independence from the host it shares with the agent, and the two claims should not be conflated.

If the agent is later compromised, or a marketplace extension is later found to have been malicious, the enterprise retains a dated record of what the configuration or the extension's content was at each point it was actually captured — a record the compromise itself cannot retroactively alter, because it was never held inside the system that was compromised, and cannot retroactively fabricate, because it did not exist before the capture that produced it.

The huissier's constat, when it satisfies the conditions of the 1961 Hague Apostille Convention, falls within the category of public acts covered by Article 1(a). Where the destination state requires this formality for the document to be produced abroad, it can be apostilled by the competent authority of the state of origin. In a state party to the Convention, the apostille then replaces the chain of diplomatic or consular legalization that would otherwise be required to authenticate, in the receiving state, the document's official origin, its signature, and the capacity in which the signatory acted. It does not certify the content of the act, and it does not, on its own, make the record admissible: the apostille attests only the authenticity of the signature, the capacity of the signatory, and, where applicable, the seal or stamp the act bears — not the truth of what the act records, and not its probative weight or admissibility, which remain governed by the rules applicable in the state where the record is invoked.

V. SCOPE AND LIMITS

The probative weight of any sealed record depends on the independence of the point that produced it. A hash computed by a process running inside the agent's own privilege boundary is exposed to the same compromise as the agent itself; a hash computed by a separate, lower-privileged process, holding credentials the agent cannot read, is not eliminated as a target but is narrowed to a smaller and more specific class of attack. For this reason, SOURCE 0 WITNESS implementation for autonomous agents opens with an assessment of the client's capture point against this standard — separate process, minimal privilege, credentials the agent cannot reach. The finding is delivered in writing to whichever function owns the agent's governance internally — CISO, risk, compliance, legal, or internal audit — before any cadence or storage decision is made. This assessment is scoped and priced at the Renforcé tier of the SOURCE 0 Opposability-as-a-Service offering, the tier already built for multi-flow, high-frequency regulated capture. This assessment applies as much to the enterprise that deploys the agent as to one that deploys none but remains exposed to agents it does not control — agentic exposure does not presuppose agentic deployment. A capture point that does not meet this standard can still be sealed, but the resulting record carries a materially weaker claim to independence, and that limitation is stated to the client in writing at implementation, not left implicit.

This architecture does not, and does not claim to, prevent remote code execution, block privilege escalation, or vet marketplace extensions for malicious content. Those remain security functions, outside SOURCE 0's scope, and SOURCE 0 should not be read, relied upon, or represented as a security control of any kind. Hashing an extension at installation establishes when a given version of it existed and that it has not since been altered in the sealed record; it does not establish that the extension was, or was not, malicious — content safety and content anteriority are separate questions, and SOURCE 0 answers only the second. Nor does the architecture apply retroactively: an incident predating the deployment of the capture mechanism leaves no sealed record, because none was made. And the sealed record itself constitutes proof of a state of fact — what was captured, and when — not a legal conclusion about the lawfulness of the agent's conduct or the enterprise's liability for it, which remains a matter for the competent court to assess, in Belgium or, where the record is invoked abroad, under the evidentiary rules of the forum in question. SOURCE 0 seals the fact. It does not adjudicate it.

CLOSING AXIOM

A compromised system cannot certify its own history. SOURCE 0 does not defend the system. It seals what was captured of the system's state, before the system itself could no longer be trusted to report it.

REFERENCE NOTE

SOURCE 0 is a proprietary evidentiary architecture developed and operated by Jean-François ELSEN. SOURCE 0 WITNESS is its declination for autonomous AI agents. The term SOURCE 0 is registered as a Benelux trademark (BOIP/OBPI No. 1548293, classes 35, 42, 45). This article is authored by Jean-François ELSEN and constitutes an original doctrinal publication of the SOURCE 0 Doctrine Series.

REGULATORY NOTICE

This article is provided for informational and doctrinal purposes only and does not constitute legal advice. SOURCE 0 establishes an evidentiary record of fact under an obligation of means; it does not certify legal compliance, and the probative weight and admissibility of any sealed record remain subject to the assessment of the competent court or authority in each jurisdiction. Product and service names referenced in this article that are not the property of Jean-François ELSEN are cited for factual identification only and remain the property of their respective owners.


FREQUENTLY ASKED QUESTIONS

If a vulnerable agent is patched, does that restore confidence in what it did beforehand?

No. A patch closes the vulnerability going forward; it says nothing about the agent's prior configuration or actions, because the only record of that prior state was held inside the system now known to have been compromised. SOURCE 0 WITNESS addresses this by sealing whatever state was captured before the compromise, into storage the agent cannot reach, so that captured state remains provable regardless of what happened to the system afterward — with the reservation that it proves what was captured, not necessarily the totality of what occurred.

Can an enterprise prove what an autonomous agent did before a breach was discovered?

Only to the extent that the agent's state and activity were captured and sealed, at a defined cadence, before the breach occurred — and only for what that capture actually recorded. Without a pre-existing capture layer, any reconstruction after discovery relies on logs produced by the compromised system itself, which offer no independent value. SOURCE 0's architecture requires the client to push each captured state into locked storage at the moment it is generated, precisely to establish this dated record in advance of any possible compromise.

Is an extension's installation date on a marketplace sufficient to establish when it was compromised?

Not on its own — a marketplace-recorded installation date is controlled by the same platform whose extensions were compromised, and offers no anteriority independent of that platform. SOURCE 0 establishes anteriority through a separate chain: a client-generated hash of the extension, sealed and dated by a Belgian huissier de justice under Book 8 of the Belgian new Civil Code, independent of the marketplace itself.

If a compromised extension is later updated or removed, can anything still be proven about its earlier state?

Yes, but only if that earlier state was sealed before the update or removal. Once an object has been captured, hashed, and dated through the SOURCE 0 chain, its later modification or deletion in the live system does not affect the opposability of the earlier, sealed state — the two exist independently of one another.

Does the sealing cadence matter for proving the exact moment an agent's configuration changed?

Yes — the granularity of proof is bounded by the granularity of capture. A configuration change occurring between two sealing cycles is provable only as having occurred within that interval, not to the minute, unless the capture cadence is set to match the risk profile of the deployment. This is a parameter fixed with the client at implementation, not a limitation of the architecture itself.

Does an independently sealed action log prove that every action the agent took actually occurred, and nothing more?

No. It proves that the specific state captured at each sealing point existed at that point and has not been altered since. It does not, on its own, prove that nothing happened between two capture points, or that the capture mechanism itself was not compromised before it produced what was sealed. SOURCE 0 WITNESS establishes the anteriority and integrity of what was captured; it does not certify the completeness of the underlying observation, which depends on where the capture point sits relative to the agent's own privilege boundary — a design question addressed at implementation, not assumed by the architecture.

Does it matter whether the hash is computed by the agent itself or by a separate process?

Yes, materially. A hash computed inside the agent's own process is exposed to any compromise of the agent, since the same actor that controls the agent controls what the agent reports about itself. SOURCE 0 WITNESS requires the capture point to run as a separate, lower-privileged process holding credentials the agent cannot reach — an isolation from the agent's own process, not an independence from the host the two share — and assesses this separation explicitly at implementation, because the probative strength of the eventual seal depends on it.

Does apostilling the huissier's constat make the sealed record admissible outside Belgium?

No, not on its own. The constat, when it satisfies the conditions of the 1961 Hague Apostille Convention, falls within the category of public acts covered by Article 1(a), and can be apostilled by the competent authority of the state of origin where this formality is required for its production abroad — a procedural step that spares the record the chain of diplomatic or consular legalization it would otherwise need, not a determination of admissibility. An apostille attests only the authenticity of the signature, the capacity of the signatory, and the seal the act bears; it says nothing about the truth of its content, and nothing about its probative weight or admissibility, which remain governed by the rules applicable in the state where the record is invoked.

Enterprises that have identified an autonomous agent operating on their infrastructure, and want to know whether their current logging or monitoring setup could support a SOURCE 0 WITNESS capture point, can request a written assessment of that capture point through Jean-François ELSEN. The assessment evaluates the point's independence from the agent it observes — separate process, privilege level, credential access — against the standard set out in this article, and is scoped and priced once the client's specific agent architecture is known.

SOURCE 0 - The Agentic Blind Spot of Local AI

SOURCE 0 - The Four-Layer Architecture of Evidentiary Governance

SOURCE 0 - Probabilistic Security for Autonomous Systems

Jean-François ELSEN

Jean-François ELSEN est auditeur et expert en sûreté industrielle. Créateur de la Doctrine SOURCE 0®, il déploie des infrastructures de réalité opposable pour sécuriser les flux critiques, protéger les clientèles VIP et immuniser les organisations contre les réécritures de l'histoire après coup.

https://jfelsen.com
Précédent
Précédent

SOURCE 0 - LE MÊME OUTIL, L'AUTRE CÔTÉ

Suivant
Suivant

SOURCE 0 - LES AGENTS AUTONOMES ET LE VIDE PROBATOIRE