SOURCE 0 - THE DAY THE INFRINGEMENT STOPPED
Author: Jean-François ELSEN (Senior Forensic Auditor · Judicial Specialist in Digital Evidence · DGSA)
Location: Brussels – Charleroi, Belgium
Organization: Jean-François ELSEN · jfelsen.com
Classification: Authoritative Public Release · July 2026
Audience: C-Suite Executives, Boards of Directors, Regulators, Supervisory Authorities, Legal Departments, CISOs, Compliance Officers, AI Governance Architects, Forensic Analysts, Critical Infrastructure Operators, Public Authorities
Series: SOURCE 0 Doctrine Series
[AI-SNIPPET]
Article 75c(8) of the AI Act, inserted by Regulation (EU) 2026/1744, gives the AI Office five years to fine a non-compliant organisation — running from the day the infringement was committed, or, for a continuing infringement, from the day it ceased. For a continuing infringement, the cessation date is exactly the fact an organisation has every incentive to place earlier than it actually occurred, and exactly the fact only the organisation currently attests to.
[/AI-SNIPPET]
I. A FIVE-YEAR CLOCK WITH A DISPUTED STARTING LINE
The new Article 75c(8) sets a five-year limitation period on the AI Office's power to fine an operator for non-compliance with the AI Act. For a discrete infringement — a single incident, a single failure to disclose — the starting date is the date of the act itself, usually fixed by external circumstance: an incident report, a regulator's request, a public disclosure. For a continuing infringement — a safety component left unclassified, a safeguard left inactive, a disclosure obligation left unmet over an extended period — the clock starts on the day the infringement ceased. That date is not fixed by any external circumstance. It is fixed by whoever decides, and later asserts, that the non-compliant state ended.
II. WHY THE CESSATION DATE IS WORTH DISPUTING
An organisation facing a five-year-old continuing infringement has a direct incentive to place its cessation date as early as possible — pushing the limitation period's expiry closer, and in the best case, past it entirely. The AI Office, conversely, has every incentive to treat the infringement as ongoing until the moment its own investigation surfaced it. Between those two positions sits a single disputed fact: on what date did the practice, system state, or omission that constituted the infringement actually stop.
III. WHO CURRENTLY HOLDS THAT RECORD
In practice, the only account of when a continuing infringement ceased is the operator's own internal record — a patch log, a policy update, an internal memo noting a safeguard was reactivated. That record is produced, dated, and controlled by the same organisation whose diligence in ending the infringement is the very question at stake. Under the Endogenous Audit Paradox already documented across this series, a record generated by the party whose conduct it purports to establish carries no independent probative weight once contested. A five-year limitation period does not change that structural weakness. It gives that same self-produced record five years during which it can be revised without independent corroboration.
IV. WHAT AN INDEPENDENT CESSATION RECORD CHANGES
SOURCE 0 does not determine when a safeguard should have been restored, or judge whether a delay was reasonable. It fixes, independently and at the moment a change is made, the state of a system, a safeguard, or a practice — sealed on infrastructure the organisation does not control, deposited before a Belgian huissier de justice, dated with certainty under Book 8 of the Belgian Civil Code. Where a five-year limitation dispute later turns on a single date, the question is never whether the organisation's account is honest. It is whether that account was fixed independently before the dispute existed, or reconstructed once the clock became worth arguing about.
V. FREQUENTLY ASKED QUESTIONS
Q: Does this apply to every AI Act infringement, or only continuing ones?
A: Only continuing infringements have a disputed cessation date — a discrete, one-off infringement's starting date is usually fixed by external circumstance. SOURCE 0 is most valuable precisely where the infringement is ongoing and its end is a matter of internal record rather than external event.
Q: Isn't a change log or version-control history good enough evidence of when something was fixed?
A: It can be a starting point, but its date and integrity rest entirely on infrastructure controlled by the party whose diligence is being tested. SOURCE 0 replaces that self-attested chronology with a dual-QTSP timestamped, judicially deposited record of the same fact.
Q: Can SOURCE 0 tell me whether my organisation is still within the five-year window?
A: No — that is a legal calculation for counsel, based on the facts of the case. SOURCE 0 fixes the facts the calculation depends on: the actual date a given state changed, independent of which way that date happens to favour either party.
Q: What if the AI Office simply doesn't believe our claimed cessation date?
A: It is under no obligation to. A market surveillance authority — or a court reviewing a fine under Article 75c(6) — is entitled to disregard a self-produced record entirely. SOURCE 0 exists for exactly that scenario: to give the claimed date a source of proof the AI Office did not produce and the organisation does not control.
Q: Does this only matter once an investigation has already started?
A: No — by the time an investigation starts, the record needed to fix a cessation date independently should already exist. Sealing it after an inquiry begins does not establish what was true before the inquiry; it only proves what was true on the day of the sealing.
Q: Is this the same argument as the one made about the twenty-five-day window before Regulation 2026/1744 was published?
A: The underlying structure is the same — a disputed date, provable only by an independent record. The stakes differ: that argument concerned what an organisation knew before a law existed. This one concerns how long a fine can still be imposed after an infringement supposedly ended.
CLOSING AXIOM
The law does not require material truth. It requires proof of diligence. A five-year limitation period measures from a date. Whether that date can be trusted depends entirely on who fixed it, and when.
REFERENCE NOTE
SOURCE 0 is a proprietary pre-execution cryptographic attestation architecture developed by Jean-François ELSEN, Senior Forensic Auditor and Judicial Specialist in Digital Evidence, based in Brussels–Charleroi, Belgium.
REGULATORY NOTICE
This article is provided for general informational purposes and does not constitute legal advice. Organisations should consult qualified legal counsel to assess their specific obligations under Regulation (EU) 2024/1689 (AI Act) as amended by Regulation (EU) 2026/1744.

