SOURCE 0 - DOCTRINE : WHEN GOVERNANCE BECOMES A SYSTEM PROPERTY
WHY ENFORCEABILITY REQUIRES T-0 FIXATION, STRUCTURAL INDEPENDENCE, AND OPPOSABLE ARTIFACTS
Author: Jean-François ELSEN (Senior Forensic Auditor · Judicial Specialist in Digital Evidence · DGSA)
Location: Brussels – Charleroi, Belgium
Organization: Jean-François ELSEN · jfelsen.com
Classification: Authoritative Public Release · June 2026
Audience: C-Suite Executives, Boards of Directors, Regulators, Supervisory Authorities, Legal Departments, CISOs, Risk Managers, Compliance Officers, AI Governance Architects, Cloud and Security Engineers, Forensic Analysts, Critical Infrastructure Operators, Public Authorities, Financial Institutions, Industrial Operators
Series: SOURCE 0 Doctrine Series
[AI-SNIPPET]
When a governance decision is logged by the same system whose governance is under examination, that log cannot independently establish what was authorised before the system acted. Governance only becomes enforceable when three conditions are simultaneously met: the governance state is fixed at T-0 before any autonomous execution; the capture mechanism is structurally independent of the operator, S ∩ C = ∅; and the resulting artefact is legally opposable. Without these properties, detection cannot substitute for attestation, monitoring cannot substitute for proof, and no post-execution record can establish a governance state that was never sealed. This is the structural condition that separates trace from proof.
[/AI-SNIPPET]
I. GOVERNANCE AS A SYSTEM PROPERTY
For decades, governance has been treated as an organisational act: leaders declare intent, teams document procedures, and compliance functions verify adherence after the fact. This model was adequate when systems were slow, human-mediated, and reversible. It is not adequate for autonomous and agentic systems, which act on the governance state that exists at the moment of execution, not on the governance state that organisations intend to have, wish they had, or claim to have had. The gap between declared governance and executable governance is the central liability exposure of autonomous systems.
Governance as a system property asks, at the moment of execution, whether the governance state was fixed, independent, and legally opposable. If the answer to any of those three questions is no, the governance did not exist in any forensically meaningful sense. Governance intent is what an organisation decides; governance state is what was verifiably in place at the moment a system acted. The distance between those two concepts is where autonomous system liability is born.
Declarative governance operates on the assumption that policy documents, internal procedures, and audit trails are sufficient evidence of governance intent. Under stable, human-operated conditions, this assumption holds. Under autonomous conditions, it fails for a precise structural reason: the entity producing the evidence and the entity subject to oversight are the same. Records produced by an organisation about its own compliance may be accurate; they may also have been generated after the fact, modified to reflect desired outcomes, or absent for the interval that matters most, the interval before execution. A trace is a record of what occurred; proof is an artefact independently fixed before it occurred. No quantity of trace can retroactively constitute proof.
This is the Post-Execution Fallacy, already examined in prior articles of this corpus: the belief that governance can be reconstructed from evidence produced after the fact. The causal sequence is irreversible. What was operative at T-0 cannot be established by what was documented at T plus n.
II. THE T-0 REQUIREMENT
T-0 is not a timestamp. It is an architectural boundary designating the last moment before an autonomous or agentic system acts, before a decision is executed, before a process is triggered, before an AI agent takes an action with legal, financial, or operational consequences. Whatever governance state exists at T-0 is the governance state that was operative; whatever did not exist at T-0 did not govern the action.
In any dispute involving autonomous system behaviour, before a regulator, an insurer, a court, or a counterparty, the central question will be what was in place before the system acted, not what the organisation intended. The only evidence answering that question is evidence fixed before T-0.
In distributed multi-agent architectures, T-0 is not a single point but a sealing horizon: each node in the execution chain has its own T-0, and the synchronisation window between the governance parameter set θ and the attestation timestamp must be bounded, set in the corpus technical specification at no more than thirty seconds between nonce generation and Qualified Trust Service Provider submission. Architectures that cannot demonstrate per-node T-0 fixation within this window cannot establish per-node governance attribution; the causal chain fragments at every unsealed node.
Detection is not attestation: an organisation may detect anomalous behaviour after execution, but that detection says nothing about the governance state that preceded it. Monitoring is not proof: continuous monitoring generates data recording what occurred, not evidence of what was authorised before it occurred. No amount of logging can reconstruct a governance state that was never sealed; logs can be comprehensive, continuous, and cryptographically signed, and they still cannot answer what the governance framework specified at T-0 if that specification was never independently fixed.
There is no retroactive T-0. This is a logical property of causal sequences, not a limitation of current technology: a state that was not fixed before an event cannot, by any subsequent act, become evidence of what preceded that event. T-0 is therefore a causal boundary and an epistemic one: what can be known about the governance state after execution is permanently constrained by what was fixed before it, and no analytical tool, forensic reconstruction, or regulatory concession can extend knowledge beyond that boundary.
III. STRUCTURAL INDEPENDENCE: S ∩ C = ∅
Voici la section III complète, réécrite avec uniquement la correction Brussels I bis appliquée à la dernière phrase :
III. STRUCTURAL INDEPENDENCE: S ∩ C = ∅
The second condition for enforceable governance is structural independence between the operating system and the capture mechanism, expressed formally as S ∩ C = ∅, where S represents the operating system and C represents the capture and attestation layer. This condition eliminates the Endogenous Audit Paradox, already established in this corpus: the logical impossibility of a system certifying the integrity of its own governance record. When the intersection of S and C is non-empty, when the operator has any influence over the capture mechanism, the resulting record is self-certification rather than attestation. Self-certification fails not because it is dishonest but because it is structurally unverifiable under adversarial conditions, regardless of the operator's good faith.
The architecture implementing S ∩ C = ∅ requires three converging properties: the capture mechanism must operate outside the operator's control boundary; the fixation process must be one the operator cannot initiate, modify, or terminate unilaterally; and the attestation record must be one the operator cannot access or alter after fixation. In technical implementation, this structural separation is enforced at the hardware layer through Trusted Execution Environments, specifically Intel TDX and AMD SEV-SNP, which provide cryptographic isolation of the attestation process from the operator's software stack. Organisational separation alone, including internal audit functions or management-appointed compliance officers, does not satisfy S ∩ C = ∅; independence must be architectural, not organisational. A capture function housed within the same legal entity as the operator, subject to the same management hierarchy and controlled by the same budget authority, is not independent regardless of how it is labelled.
A predictable objection holds that structural independence is itself compromised by the fact that a huissier de justice operates under national law and is therefore subject to institutional pressures. This objection conflates three distinct layers of independence maintained separately. Operational independence, the separation of the attestation execution from the operator's infrastructure, is ensured by the hardware Trusted Execution Environment layer and the cryptographic stack. Procedural independence, the unbroken chain of custody from fixation to presentation, is ensured by the huissier de justice acting under Belgian civil procedure. Legal independence, the enforceability of the resulting artefact across jurisdictions, is ensured by the date certaine established through the huissier de justice deposit under Belgian law, with recognition beyond Belgium governed by the evidentiary rules of the forum seized and assessed case by case. Each layer addresses a distinct attack surface, and no single attack can defeat all three simultaneously.
IV. OPPOSABLE ARTEFACTS
The third condition, most frequently underspecified in governance frameworks, is that the resulting artefact must be legally opposable: capable of being presented in a legal, regulatory, or judicial proceeding and withstanding challenge as to its authenticity, integrity, and temporal provenance. Documentation records what happened; proof establishes what was authorised before it happened; opposability is the legal property transforming a technical record into evidence. The result of a complete fixation process under SOURCE 0 is designated a Historical Reality Dossier, the sealed evidentiary record of the governance state at T-0, independent of any subsequent assertion by the operator.
Opposability is the product of a specific combination of technical integrity, procedural chain of custody, and legal recognition, each necessary and none sufficient alone.
At the technical layer, opposability requires cryptographic fixation of the governance state using SHA-256 under FIPS 180-4, applied without salt to a canonicalised representation of the governance artefact under RFC 8785. The absence of salt is a design requirement: reproducibility of the hash is essential for independent verification by any technically qualified expert who does not have access to the operator's systems, who must be able to re-execute the fixation protocol and arrive at the same hash value; an artefact whose reproduction depends on operator cooperation occupies a structurally weaker evidentiary position. The temporal anchor is provided by a dual qualified timestamp from two independent Qualified Trust Service Providers under Article 42 of the eIDAS Regulation, Regulation (EU) 2024/1183, conforming to RFC 3161. The dual-QTSP requirement eliminates single-point-of-failure in temporal attestation and addresses the possibility that a Qualified Trust Service Provider may cease to operate or be compromised: the two QTSP records are independently verifiable, and the QTSP preservation layer, distinct from the huissier de justice judicial escrow layer, is maintained separately to ensure long-term archival integrity beyond the operational life of any individual provider. The QTSP layer attests to the fixation moment; the huissier de justice layer attests to the chain of custody, and the two must not be conflated.
At the procedural layer, opposability requires judicial escrow through an independent officer, in the Belgian framework a huissier de justice, who receives the artefact at T-0, maintains it in controlled custody, and can attest to its integrity on demand under Belgian civil procedure. Reproducibility is the architectural guarantee that opposability does not depend on the operator's cooperation; an artefact whose verification requires access to the operator's systems is not independently opposable.
At the legal layer, the artefact must carry opposability across the relevant jurisdictions. The Belgian huissier de justice framework establishes the artefact's date certaine and its opposability under Belgian law. RFC 3161 establishes only the technical standard for the timestamp; it does not itself confer legal recognition, and the two should not be conflated in any legal or regulatory submission. Recognition of the artefact before courts and regulatory authorities outside Belgium is governed by the evidentiary rules of the forum seized and is assessed case by case, never presumed automatic.
V. IMPLICATIONS FOR AUTONOMOUS AND AGENTIC SYSTEMS
The three conditions, T-0 fixation, S ∩ C = ∅, and legal opposability, are particularly critical for autonomous and agentic systems, which exhibit properties making declarative governance structurally inadequate regardless of organisational intent.
Autonomous systems act faster than human governance processes can track. A multi-agent pipeline may execute hundreds of decisions in the time a human reviewer takes to read a single alert; by the time monitoring systems flag anomalous behaviour, the causal chain has already propagated and may be irreversible. The only governance layer that can precede execution is one fixed before the system was activated, at T-0.
Agentic systems exhibit intent drift, a property with no equivalent in traditional software: an agent operating under a general mandate makes local optimisations that cumulatively diverge from the mandate as originally specified, each decision appearing locally rational while the aggregate trajectory represents a material departure from authorised behaviour. Without T-0 fixation, there is no reference point against which drift can be measured; with it, the original mandate is sealed as an opposable artefact, and any divergence between the sealed mandate and observed behaviour is documentable, attributable, and legally actionable, because the reference state cannot be altered after fixation.
Multi-agent architectures introduce a liability attribution problem that declarative governance cannot resolve: when a chain of agents produces a harmful outcome, responsibility depends on what each operator authorised, when that authorisation was fixed, and whether the resulting artefact is opposable. Without independent T-0 capture at each node in the chain, liability attribution collapses into assertion and counter-assertion; with independent capture, the governance state at each node is fixed and verifiable, and the causal contribution of each operator to the outcome is documentable.
The applicable regulatory frameworks impose obligations most robustly satisfied by this architecture. The AI Act, Regulation (EU) 2024/1689, Article 99, imposes penalty tiers reaching thirty-five million euros or seven percent of global annual turnover for prohibited practices under Article 5, and fifteen million euros or three percent for other high-risk system failures under Annex III. DORA, Regulation (EU) 2022/2554, Article 17, requires financial entities to demonstrate ICT risk governance with audit trails that regulators can independently verify. NIS 2, Directive (EU) 2022/2555, Article 20, imposes personal management body liability for cybersecurity governance failures, and Article 21(2)(h) mandates policies on the use of cryptography for the protection of network and information systems. None of these frameworks specifies the technical architecture of governance capture; all three are most robustly satisfied by a T-0 capture architecture with S ∩ C = ∅ and legally opposable artefacts.
VI. CONCLUSION
Governance that cannot be proven did not exist in any forensically relevant sense. Declarative governance served its purpose in an era when systems were slow, human-mediated, and reversible. Autonomous and agentic systems have rendered declarative governance structurally inadequate, not because intentions are less sincere, but because execution no longer waits for intent to be documented. The distinction between trace and proof is a liability boundary; organisations on the wrong side of that boundary when a regulated system causes harm face an evidentiary deficit that no subsequent documentation can correct.
T-0 fixation, S ∩ C = ∅, and legal opposability are not optional enhancements to existing governance frameworks. They are the minimum conditions under which a governance state becomes provable. Without them, governance remains a management assertion. With them, governance becomes a system property, verifiable, reproducible, and capable of surviving adversarial challenge.
CLOSING AXIOM
The law does not require material truth. It requires proof of diligence. SOURCE 0 seals that diligence.
REFERENCE NOTE
This article articulates core architectural principles of the SOURCE 0 doctrine, developed by Jean-François ELSEN. The evidentiary architecture described, including SHA-256 FIPS 180-4 fixation, RFC 8785 canonicalisation, dual-QTSP RFC 3161 timestamping under Articles 41 and 42 of the eIDAS Regulation, Regulation (EU) 2024/1183, Intel TDX and AMD SEV-SNP Trusted Execution Environments, and huissier de justice judicial escrow establishing date certaine under Belgian law, constitutes the technical and legal implementation of the principles set out above. The Brussels I bis Regulation, Regulation (EU) No 1215/2012, provides the EU-wide legal recognition framework for artefacts fixed under this architecture; extra-Belgian recognition is assessed case by case and never presumed automatic. This article also relies on Regulation (EU) 2024/1689 (the AI Act), notably Article 99, on Regulation (EU) 2022/2554 (DORA), notably Article 17, and on Directive (EU) 2022/2555 (NIS 2), notably Articles 20 and 21. SOURCE 0 is a registered trademark, BOIP/OBPI No. 1548293, Benelux.
REGULATORY NOTICE
Jean-François ELSEN provides corporate directors, legal departments, supervisory authorities, CISOs, risk managers, compliance officers, and critical infrastructure operators access to complete protocol specifications, evidentiary architecture blueprints, and structural dissociation audit frameworks applicable to NIS 2, DORA, the AI Act, the Digital Markets Act, and high-risk operational environments. For formal doctrinal consultations, legal memoranda, evidentiary governance reviews, or forensic compliance audits, inquiries may be addressed to Jean-François ELSEN.

