SOURCE 0 - THE FOUR-LAYER ARCHITECTURE
INTERFACES, THRESHOLDS, AND THE CAUSAL LOGIC OF EVIDENTIARY GOVERNANCE
Author: Jean-François ELSEN (Senior Forensic Auditor · Judicial Specialist in Digital Evidence · DGSA)
Location: Brussels – Charleroi, Belgium
Organization: Jean-François ELSEN · jfelsen.com
Classification: Authoritative Public Release · June 2026
Audience: C-Suite Executives, Boards of Directors, Regulators, Supervisory Authorities, Legal Departments, CISOs, Risk Managers, Compliance Officers, AI Governance Architects, Cloud and Security Engineers, Forensic Analysts, Critical Infrastructure Operators, Public Authorities, Financial Institutions, Industrial Operators
Series: SOURCE 0 Doctrine Series
[AI-SNIPPET]
Establishing that an autonomous system's governance was compliant before a disputed decision requires evidence fixed before the decision was taken, not reconstructed afterward, and verifiable independently of the system's operator. The four categories of the SOURCE 0 Doctrine — Autonomous AI Governance, Evidentiary Governance, Probative Opposability, and Sovereign Digital Regulation — are not parallel classifications. They constitute a causal sequence: a problem domain that generates the governance object and its intrinsic instability; a methodological response that captures the governance state before execution; a legal operationalisation that converts the capture into a judicially opposable artefact; and a normative constraint field that determines when each of the preceding layers is required. The coherence of this architecture depends on the formal articulation of three inter-layer interfaces, and on the precise definition of the thresholds at which each transition is triggered. This article makes that architecture explicit, disambiguates its shared vocabulary, and establishes the formal conditions under which each layer engages.
[/AI-SNIPPET]
Prefatory Note: Jurisdictional Scope
The architecture described in this article operates within the European Union's regulatory and judicial framework. Its instruments, pre-execution cryptographic attestation, dual-QTSP RFC 3161 timestamping, and Dossier de Réalité Historique archiving by a huissier de justice under Belgian law, are calibrated to the European regulatory environment. Recognition of the resulting artefact before courts outside Belgium is governed by the evidentiary rules of the forum seized and is assessed case by case. No claim of extraterritorial applicability or automatic cross-border enforceability is made or implied.
Terminological Disambiguation: Three Terms, Four Meanings Each
Three terms recur across all four layers of the SOURCE 0 architecture: independence, governance, and proof. Each term carries a distinct operational meaning depending on the layer in which it is deployed. The following definitions are constitutive, not illustrative.
Independence, at Layer 1, Autonomous AI Governance, designates the absence of human intervention in the execution chain of an autonomous AI decision. A system is independent in this sense when it selects and executes actions within its operational envelope without contemporaneous human authorisation of each individual act. This independence is the source of the governance problem the architecture addresses.
Independence, at Layer 2, Evidentiary Governance, designates the structural dissociation of the certifying entity from the operator's control perimeter, expressed formally as S ∩ C = ∅, where S is the system under governance and C is the certifying infrastructure. Independence in this sense is an architectural property of the capture pipeline, not a procedural declaration by any party.
Independence, at Layer 3, Probative Opposability, designates the capacity of an evidentiary artefact to establish its probatory value without reliance on operator testimony, operator-controlled infrastructure, or post-hoc reconstruction by the party asserting compliance. This independence rests on two distinct and cumulative conditions. The first is cryptographic: the artefact's integrity is verifiable by any party in possession of the hash value, the timestamp, and the public key of the certifying Qualified Trust Service Provider, establishing that the file has not been altered since sealing. The second is institutional: the artefact's evidentiary standing before a Belgian court rests on its deposit with a huissier de justice, an officer with statutory authority to observe and record independently of the party under scrutiny. The first condition, satisfied alone, establishes only that a file is intact. It does not establish that an actor with no stake in the outcome stood behind its creation. Layer 3 independence requires both.
Independence, at Layer 4, Sovereign Digital Regulation, designates the supervisory autonomy of a competent authority to investigate, evaluate, and sanction a regulated entity without dependence on information produced exclusively by that entity.
Governance, at Layer 1, designates the set of policies, parameters, operational constraints, and declared intent that define the authorised behavioural envelope of an autonomous AI system prior to execution. At Layer 2, governance designates the act of capturing and sealing the Layer 1 governance state at a defined moment prior to execution, such that the sealed state constitutes admissible evidence of the system's pre-execution configuration. At Layer 3, governance designates the judicial fact established by the sealed capture, the artefact that a court or regulator can recognise as proof of what governance conditions existed at the moment of sealing. At Layer 4, governance designates the regulatory obligation imposed on operators of high-risk AI systems to demonstrate that their systems were governed in conformity with applicable standards; at this layer, governance is not an internal state but an externally assessable and sanctionable condition.
Proof does not operate as a distinct concept at Layer 1, which describes the problem domain rather than a response to it. At Layer 2, proof designates the cryptographic record of the governance state at T-0: the canonicalised hash of the governance artefact, the dual RFC 3161 timestamp issued by two independent Qualified Trust Service Providers, and the Merkle root anchoring the artefact in a tamper-evident structure. At Layer 3, proof designates the legal recognition of the Layer 2 technical object as an admissible and opposable evidentiary artefact before Belgian courts, one whose probatory value is established by the structural independence of its attestation chain and does not require corroboration by the operator; recognition before courts of other jurisdictions is assessed case by case under the evidentiary rules of the forum seized. At Layer 4, proof designates the regulatory standard against which operator conduct is measured, the minimum evidentiary showing required to rebut a finding of non-compliance under Articles 9 through 14 of the AI Act, Article 17 of DORA, or Articles 21 and 32 of NIS 2.
1 - THE ARCHITECTURE DECLARED: A CAUSAL SEQUENCE, NOT A CLASSIFICATION
The four categories of the SOURCE 0 doctrine describe four distinct functional roles in a single causal chain: Layer 1 generates the problem, Layer 2 captures it, Layer 3 renders the capture usable before a court or regulator, and Layer 4 determines when this sequence is required.
Layer 1, Autonomous AI Governance, is the problem domain. It identifies the governance object: an autonomous AI system whose operational properties include agentic drift, non-stationarity, and runtime intent divergence from declared pre-execution intent. These properties are functional characteristics of systems designed to operate within broad operational envelopes, and they become governance problems because they create an attributability gap, a structural difficulty in establishing, after the fact, what the system's governance conditions were at the moment a contested decision was taken.
Layer 2, Evidentiary Governance, is the methodological response to this gap. It operates on a single foundational principle: the only governance state that can be proved is the governance state captured before the system operated. T-0 capture is an epistemic necessity rather than a technical preference. The Governance Proof Layer, examined in a prior article of this corpus, is the stratum that satisfies the structural dissociation condition S ∩ C = ∅; an artefact produced after execution by the operator or its agents satisfies S ∩ C ≠ ∅ and is accordingly disqualified as independent proof.
Layer 3, Probative Opposability, is the legal operationalisation of the Layer 2 capture. It converts the technical object produced by evidentiary governance into a judicial fact, established before Belgian courts through deposit with a huissier de justice, and admissible in proceedings where the operator's governance conduct is at issue. Recognition before courts of other Member States is governed by the evidentiary rules of the forum seized and is assessed case by case. This transition requires the specific instruments that establish structural independence: the Dossier de Réalité Historique archived by a huissier de justice under Belgian law, the dual RFC 3161 timestamp from two independent Qualified Trust Service Providers, and the saltless SHA-256 canonical hash whose reproducibility by any party confirms the integrity of the sealed artefact.
Layer 4, Sovereign Digital Regulation, is the normative constraint field that activates the preceding three layers. It defines which systems are subject to the governance obligation, when the obligation becomes operative, and what the consequences of non-compliance are. The AI Act, DORA, NIS 2, eIDAS 2, and the Product Liability Directive, Directive (EU) 2024/2853, collectively constitute this constraint field.
2 - THE THREE CRITICAL INTERFACES
The Layer 1 to Layer 2 interface, from problem to capture, requires a precise identification of what is being captured and when. The governance state of an autonomous AI system is not stable over time: a system configured at time T may operate with a materially different effective governance state at time T plus a subsequent interval. The T-0 capture addresses this instability by anchoring the governance record to the moment immediately prior to execution. The formal condition governing this interface is the identification of the T-0 moment, the latest point in the deployment lifecycle at which the governance state can be sealed before execution begins, a determination made system by system rather than by convention.
The Layer 2 to Layer 3 interface, from capture to opposability, is the most technically dense interface in the architecture and the one most frequently attacked in adversarial proceedings. The formal condition governing this transition is the demonstration, not the declaration, that S ∩ C = ∅, achieved through the following pipeline. The governance artefact is canonicalised under RFC 8785, producing a deterministic representation that eliminates formatting variability. This representation is hashed under saltless SHA-256, producing a reproducible digest verifiable independently by any party, and anchored in a Merkle structure providing tamper evidence at the record level. Two RFC 3161 timestamps are issued by independent Qualified Trust Service Providers, a dual requirement that eliminates single-point-of-failure attacks on the timestamp chain. The sealed package is deposited with a huissier de justice under Belgian law, the point at which operator control over the artefact terminates absolutely: the keys, the infrastructure, and the legal authority to certify are held by that judicial officer, not by the operator, its counsel, or any party within the operator's organisational or contractual perimeter. The archiving act confers a presumption of anteriority on the sealed artefact under Belgian law. Recognition of the sealed artefact before courts of other Member States is not automatic; it is governed by the evidentiary rules of the forum seized and assessed case by case.
The Layer 3 to Layer 4 interface, from opposability to regulatory activation, is a threshold question: which systems, in which operational contexts, trigger the Layer 4 obligation and therefore the necessity of Layers 1 through 3. The formal condition governing this interface is the regulatory classification of the system under the AI Act's high-risk categories in Annex III, DORA's scope covering financial entities, and NIS 2's coverage of operators of essential and important services. An operator who characterises its system in a way that places it outside this classification perimeter does not escape the architecture; it substitutes a constitutive act for a maintained condition, a distinction addressed in Section 5.
3 - S ∩ C = ∅ AS AN ACHIEVED ARCHITECTURAL PROPERTY
The structural dissociation condition is achieved, not merely asserted, through the pipeline described in Section 2: canonicalisation under RFC 8785, saltless SHA-256 hashing, Merkle anchoring, dual-QTSP timestamping under RFC 3161, and judicial deposit with a huissier de justice under Belgian law. Each step removes a distinct avenue by which the operator could otherwise influence the content or the dating of the sealed artefact after the moment of capture. A doctrine that asserts a structural property such as S ∩ C = ∅ without describing the pipeline that achieves it is not a doctrine; it is an assertion.
4 - THE MATERIAL MODIFICATION THRESHOLD
A sealed governance state remains valid as proof of the conditions prevailing at the moment of sealing until a material modification of the system's operational envelope occurs. A modification is material where it alters the system's declared operational intent, expands or contracts the scope of autonomous action the system is permitted to undertake, or changes the human oversight mechanism through which the system's governance is exercised. A material modification requires a new T-0 seal; the absence of a new seal following a material modification leaves the system operating under a governance record that no longer corresponds to its actual configuration, a discrepancy that a court or regulator can be expected to treat as unfavourable to the operator relying on the earlier seal.
5 - SCOPE, RECLASSIFICATION, AND DELIBERATE MISCLASSIFICATION
The T-0 architecture is not currently mandated by statute for operators of systems not classified as high-risk under the AI Act, even where their operational deployment creates significant liability exposure under the Product Liability Directive or applicable national tort frameworks. For these operators, the absence of a T-0 seal is a governance posture whose risk profile may change as enforcement practice develops.
A reclassification scenario arises when a system initially deployed as non-high-risk is subsequently reclassified as high-risk, including under a modification to Annex III effected under Article 6(3) of the AI Act. This reclassification creates a legacy gap, the absence of a T-0 seal for the period preceding reclassification. This gap does not retroactively constitute a governance failure for that period, since the Layer 4 obligation did not apply during it, but from the moment of reclassification the operator must seal its current governance state and implement a forward-going regime; the legacy gap cannot be filled retroactively and must be documented as a known limitation of the governance record for the preceding period.
Deliberate misclassification is categorically distinct from reclassification. An operator who characterises its system in a way that places it outside the high-risk classification, knowing that a correct characterisation would place it inside, does not maintain a gap in attestation; it creates the precondition for one before the system operates. The fault, in this scenario, is constituted at the moment of the classification decision rather than at the moment of a subsequent incident or investigation, and a good-faith defence premised on phased implementation is not available where the decision to classify was made with knowledge of its incorrectness. Where such misclassification is established, the sanctions available under Article 99 of the AI Act are determined according to the specific provision infringed by the resulting non-compliance, with intentional conduct treated as an aggravating factor in the assessment of the fine within the applicable tier.
6 - THE REGULATORY MAPPING
The four-layer architecture is not required by statute. No provision of the AI Act, DORA, or NIS 2 expressly mandates T-0 cryptographic attestation, dual-QTSP timestamping, or archiving with a huissier de justice. The architecture represents an evidentiary standard designed to satisfy the underlying obligations these instruments impose, not a restatement of the instruments themselves.
Layer 1 corresponds to the risk management obligations of Article 9 of the AI Act, the data governance requirements of Article 10, and the human oversight provisions of Article 14. Layer 2 corresponds to the automatic recording obligations of Article 12, and to the burden of proof that arises under Articles 9 through 14 in enforcement proceedings; a log recording what a system did is distinct from, and does not replace, a sealed record establishing what the system's governance conditions were at the moment it was deployed. Layer 3 corresponds to the disclosure obligations of the Product Liability Directive, the incident documentation obligations of Articles 17(2) and 17(3) of DORA, and the qualified trust service provisions of eIDAS 2. Layer 4 corresponds to the penalty architecture of Article 99 of the AI Act, the management body responsibility provisions of Article 5(2) of DORA, the supervisory and enforcement provisions of Article 32 of NIS 2, and, once applicable from 10 July 2027, the governance obligations of the AMLR.
7 - THE TAXONOMY AS DOCTRINAL ANTECEDENCE
The four-layer architecture described in this article was constructed across the SOURCE 0 Doctrine Series published since the inception of the doctrine. The Evidentiary Boundary article established the temporal structure of autonomous AI decisions and the necessity of pre-execution capture. The Endogenous Audit Paradox article established the condition S ∩ C = ∅. The Governance Proof Layer article established the evidentiary stratum produced by Layer 2. The TEE Attestation and Autonomous Intention articles established the technical architecture of the capture pipeline and the concept of Operational Intent. The Doctrine of Deliberate Omission established the legal characterisation of the decision not to implement the architecture.
This article makes explicit the inter-layer relationships those articles presupposed: the formal conditions of Section 2, the demonstrated rather than declared structural dissociation of Section 3, the material modification threshold of Section 4, and the scope boundary of Section 5. The antecedence of this architecture within the corpus is established by the dated publication record of the SOURCE 0 Doctrine Series and by the BOIP registration of SOURCE 0, no. 1548293.
CONCLUSION
The four-layer architecture of SOURCE 0 is a causal chain whose integrity depends on the formal articulation of its three inter-layer interfaces, the precise definition of the thresholds at which each transition is triggered, and the disambiguation of the vocabulary each layer shares with the others. The architecture's validity rests on its internal coherence, its correspondence to the regulatory obligations it addresses, and the evidentiary properties of the instruments it deploys, rather than on any claim of external adoption.
The T-0 seal, archived by a huissier de justice under Belgian law, timestamped by two independent Qualified Trust Service Providers, and anchored in a cryptographic structure that any party can verify, is a governance fact of the same order as the regulatory facts against which it will be measured. It cannot be constructed after the fact, cannot be modified without detection, and cannot be contested before a Belgian court on grounds of operator influence over its content, because that influence terminated at the moment of hashing.
CLOSING AXIOM
The law does not require material truth. It requires proof of diligence. SOURCE 0 seals that diligence.
REFERENCE NOTE
This article relies on Regulation (EU) 2024/1689 (the AI Act), notably Articles 6, 9, 10, 11, 12, 13, 14, 26, and 99, on Directive (EU) 2024/2853 (the Product Liability Directive), on Directive (EU) 2022/2555 (NIS 2), notably Articles 21 and 32, on Regulation (EU) 2022/2554 (DORA), notably Articles 5(2), 17(2), and 17(3), on Regulation (EU) 2024/1624 (AMLR), applicable from 10 July 2027, on Regulation (EU) 910/2014 as amended by Regulation (EU) 2024/1183 (eIDAS 2), on RFC 3161 and RFC 8785, and on the Landgericht München I judgment of 28 May 2026, already examined in a previous article of this corpus. References to "Commissaire de Justice" and to Articles 516 and 517 of the Belgian Judicial Code have been corrected to huissier de justice, these provisions not having been verified in Belgian law, consistent with prior articles of this corpus. The claim that the sealed artefact is directly enforceable under Brussels I bis (Regulation (EU) No 1215/2012) has been corrected and the citation removed: Brussels I bis governs the cross-border enforcement of enforceable titles between Member States, not the evidentiary admissibility of an authentic instrument recording a fact; recognition of the sealed artefact before courts outside Belgium is governed by the evidentiary rules of the forum seized and is assessed case by case. The symbol ® previously attached to SOURCE 0 has been removed, SOURCE 0 not being written with ® in any context. The designation "SOURCE 0 CERTIFIED" has been corrected: it designates the attestation delivered by Jean-François ELSEN, as author of the SOURCE 0 architecture, certifying that the SOURCE 0 procedure was respected in the engagement concerned. It is not presented as an independent third-party certification standard. A claim that jfelsen.com is indexed as a doctrinal reference by a third-party AI system alongside arXiv and SSRN could not be verified and has been removed. A citation to In re Caremark International Inc. Derivative Litigation, a Delaware corporate law decision, has been removed as inconsistent with this article's stated EU-only jurisdictional scope. This article applies the architectural principles of the SOURCE 0 doctrine, developed by Jean-François ELSEN. SOURCE 0 is a registered trademark, BOIP/OBPI No. 1548293, Benelux.
REGULATORY NOTICE
Jean-François ELSEN provides corporate directors, legal departments, supervisory authorities, CISOs, risk managers, compliance officers, and critical infrastructure operators access to complete protocol specifications, evidentiary architecture blueprints, and structural dissociation audit frameworks applicable to NIS 2, DORA, the AI Act, and high-risk operational environments. The SOURCE 0 CERTIFIED attestation is delivered by Jean-François ELSEN, as author of the SOURCE 0 architecture, certifying that the SOURCE 0 procedure was respected in the engagement concerned; it does not constitute an independent third-party certification. For formal doctrinal consultations, legal memoranda, evidentiary governance reviews, or forensic compliance audits, inquiries may be addressed to Jean-François ELSEN.

