SOURCE 0 - THE DISCLOSURE THAT ISN'T DATED
Author: Jean-François ELSEN (Senior Forensic Auditor · Judicial Specialist in Digital Evidence · DGSA)
Location: Brussels – Charleroi, Belgium
Organization: Jean-François ELSEN · jfelsen.com
Classification: Authoritative Public Release · July 2026
Audience: C-Suite Executives, Boards of Directors, Regulators, Supervisory Authorities, Legal Departments, CISOs, Compliance Officers, AI Governance Architects, Forensic Analysts, Critical Infrastructure Operators, Public Authorities
Series: SOURCE 0 Doctrine Series
[AI-SNIPPET]
Directive (EU) 2024/2853, the revised EU Product Liability Directive, applies to products placed on the market from 9 December 2026 and explicitly brings software and AI systems within the definition of a product. Article 9 responds directly to the evidentiary asymmetry this creates: where a claimant's case is plausible, a court can order the manufacturer to disclose relevant technical evidence, and if the manufacturer refuses, defectiveness is presumed. This is a real legislative answer to a real problem — but it answers only the refusal to disclose. It does not ask whether the evidence a manufacturer does disclose was fixed, independently, before the claim was filed, or assembled afterward from records the manufacturer alone controlled throughout. A manufacturer that complies with a disclosure order, however incomplete or curated its production, escapes the presumption regardless.
[/AI-SNIPPET]
I. THE OBLIGATION AS THE DIRECTIVE STATES IT
Directive (EU) 2024/2853 replaces the 1985 Product Liability Directive and applies to products placed on the EU market or put into service from 9 December 2026. It extends the definition of "product" to standalone software, AI systems, and digital manufacturing files, and recognises that a defect can result from a failure to provide the updates necessary to maintain the product's safety. Article 9 addresses the practical difficulty a claimant faces proving a defect in a technically complex product: on request, and where the claim is plausible, a court may order the manufacturer to disclose relevant evidence in its possession, subject to proportionality and protection of trade secrets. If the manufacturer fails to comply with that order, defectiveness is presumed. The same presumption applies where the claimant shows the product breached mandatory safety requirements, where damage resulted from an obvious malfunction during normal use, or where the case involves such technical or scientific complexity that proving the defect or the causal link would otherwise be excessively difficult.
II. WHAT THE PRESUMPTION ACTUALLY PUNISHES
The presumption in Article 9 is triggered by a manufacturer's refusal, or failure, to disclose evidence a court has ordered it to produce. That is the conduct the provision is built to deter and to penalise. It is not built to test the evidence a manufacturer does hand over. A manufacturer that responds to a disclosure order — even by producing a selective, incomplete, or reconstructed account of its internal records — has complied, in the sense the Article requires, and the presumption does not apply to it on that ground.
III. THE GAP BETWEEN COMPLYING AND PROVING
This distinction matters most for exactly the products the Directive was updated to cover. Source code repositories, training data, test logs, and version histories for a piece of software or an AI system are held, structured, and maintained entirely by the manufacturer, before any dispute exists. When a claim is filed and disclosure is ordered, the manufacturer produces what it has — but nothing in Article 9 asks whether what it produces reflects the system's actual state at the time the alleged defect arose, or a later account built from records the manufacturer alone has always controlled. Compliance with the disclosure order is not the same fact as the antiquity of what was disclosed. The presumption itself does not depend on that antiquity — only on whether disclosure occurred at all. A court's assessment of how much weight the disclosed evidence deserves does depend on it.
IV. THE ENDOGENOUS AUDIT PARADOX IN CIVIL LITIGATION
This is the same structural condition this doctrine has documented under DORA, NIS 2, the EU Space Act proposal, and the French duty-of-vigilance law, appearing here in the law of civil evidence rather than in a regulatory compliance framework. The analogy concerns the probative structure alone, not the nature of the underlying obligations — those other regimes govern ex ante compliance, while the Directive governs ex post liability. The party best placed to know what its software actually did, and when, is also the only party currently capable of producing the record that proves it. Article 9 corrects for the worst case — outright refusal — by shifting the burden onto the manufacturer. It does not correct for the more common case, where the manufacturer complies and the only question left is whether what it produced can be trusted to predate the dispute.
V. WHAT THE DIRECTIVE DOES NOT REQUIRE
Article 9 does not require that source code, training data, test records, or version histories be fixed by an independent third party before a dispute arises. It does not require that a manufacturer's disclosed evidence carry any mark of its own antiquity beyond what the manufacturer's internal systems happen to preserve. The presumption regime governs the act of disclosure; it is silent on the evidentiary weight of what is disclosed once the manufacturer has, formally, complied.
VI. WHAT AN INDEPENDENT SEAL WOULD ADD
If a manufacturer's source code, model weights, training data references, and test results were fixed by an independent third party at the moment of each material release or update, a later dispute over whether a defect existed at a given date would not turn on whether the manufacturer complied with a disclosure order alone. The seal would not determine, on its own, whether the product was defective, whether the presumption should apply, or whether the causal link the claimant alleges is made out — those remain questions for the competent court under Article 9 exactly as written. It would fix the state of the technical artefacts as they were extracted and sealed at a given moment, so that the evidence produced in response to a disclosure order can be tested against an independent record rather than against the manufacturer's own account of its own archive. The attestation does not substitute for court-ordered production under Article 9; it strengthens the verifiability of what is produced.
VII. WHAT SOURCE 0 DOES NOT CLAIM
SOURCE 0 does not replace any obligation under Directive (EU) 2024/2853. It does not determine whether a product was defective, whether a disclosure order was properly complied with, or whether a presumption should apply in a given case — these remain questions of legal and factual qualification reserved to the competent court. SOURCE 0 imposes no retention or preservation obligation on the manufacturer; it attests only the state of the artefacts submitted to it at the moment it is engaged. SOURCE 0 CERTIFIED denotes an attestation, delivered by Jean-François ELSEN, that the SOURCE 0 procedure was followed in a given engagement; it is not an independent third-party certification, since Jean-François ELSEN provides the service being certified. All engagements are governed by an obligation de moyens. Recognition of the Historical Reality Dossier is direct before Belgian jurisdictions and assessed case by case elsewhere.
VIII. FREQUENTLY ASKED QUESTIONS
Q: If a manufacturer refuses to disclose technical evidence in a product liability case, what happens?
A: Under Article 9 of Directive (EU) 2024/2853, the court can presume the product defective. SOURCE 0 doesn't change that rule — it addresses the separate question of whether the evidence a manufacturer does disclose can be shown to predate the dispute, by sealing it independently before any claim arises.
Q: Does complying with a disclosure order protect a manufacturer from the presumption of defectiveness?
A: Yes, on the refusal ground — the presumption targets non-compliance, not the content of what's produced. SOURCE 0 closes the gap this leaves open: it fixes the manufacturer's technical records independently at the moment of release, so what's later disclosed can be tested against a prior, independent state rather than taken on the manufacturer's word alone.
Q: Can a manufacturer reconstruct or curate what it discloses without triggering the presumption?
A: Article 9 as written only penalises refusal or failure to disclose, not the completeness or dating of what is produced. SOURCE 0 supplies the missing check: an independently sealed record of the system's actual state before the dispute, against which any later disclosure can be measured.
Q: Does the Directive already ease the burden of proof for software and AI defects?
A: Yes — presumptions apply where safety rules are breached, where a malfunction is obvious, or where technical complexity makes standard proof excessively difficult. None of these presumptions requires that the underlying technical record be independently dated. SOURCE 0 adds that layer directly.
Q: Is this a criticism of Article 9's disclosure and presumption regime?
A: No — it's a description of what the provision was built to solve and what it leaves open. Article 9 solves the refusal problem soundly. SOURCE 0 addresses the separate, narrower question of the antiquity of what gets disclosed once a manufacturer complies.
CLOSING AXIOM
The directive punishes the manufacturer who says nothing. It has nothing to say about the manufacturer who says something dated only by its own word. SOURCE 0 seals the record before that question can even be asked.
REFERENCE NOTE
This article is based on Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products, in particular Articles 8 and 9, and Recitals concerning software, artificial intelligence systems, and the presumption of defectiveness. The Directive entered into force on 8 December 2024 and applies to products placed on the market or put into service from 9 December 2026.
REGULATORY NOTICE
This document does not constitute legal advice. Organisations should verify their specific situation, including their obligations under Directive (EU) 2024/2853 and applicable national transposition measures, with qualified legal counsel.

