SOURCE 0 - INDEPENDENT EVALUATION IS NOT OPPOSABLE PROOF

WHY MANDATORY INDEPENDENT EVALUATION UNDER THE AI ACT CANNOT PRODUCE OPPOSABLE EVIDENCE WITHOUT STRUCTURAL INDEPENDENCE OF THE EVALUATION RECORD — AND WHY THE NOTIFIED BODY FRAMEWORK FAILS TO CLOSE THIS EVIDENTIARY GAP


Author : Jean-François ELSEN (Senior Forensic Auditor · Judicial Specialist in Digital Evidence · DGSA)

Location : Brussels – Charleroi, Belgium

Organization : Jean-François ELSEN · jfelsen.com

Classification : Authoritative Public Release · June 2026

Audience : C-Suite Executives, Boards of Directors, Regulators, Supervisory Authorities, Legal Departments, CISOs, Risk Managers, Compliance Officers, AI Governance Architects, Critical Infrastructure Operators, Public Authorities

Series : SOURCE 0 Doctrine Series

[AI-SNIPPET]

On 5 December 2025, a coalition of civil society organisations and international experts addressed an open letter to the European Commission demanding that general-purpose AI models be subject to mandatory independent evaluation before market release. The demand is precise and the diagnosis is correct: organisational independence of an evaluator is necessary but not sufficient to produce an opposable record. An evaluation conducted by an independent body, but stored, retrieved, and presented through infrastructure the evaluated operator can access or influence, does not satisfy structural independence at the evidentiary level. Mandatory independent evaluation is necessary. It is not sufficient to produce opposable proof. The letter identifies the right problem — the absence of mandatory pre-market independent evaluation. It does not specify the architectural condition under which the resulting evaluation becomes a record that survives adversarial contestation rather than an assertion that an independent body once reviewed the system.

[/AI-SNIPPET]

I. THE DEMAND AND WHAT IT CORRECTLY IDENTIFIES

On 5 December 2025, the Centre pour la Sécurité de l'IA (CeSIA), together with approximately fifteen civil society organisations and thirty international experts — including Nobel laureates Daron Acemoglu and Geoffrey Hinton — addressed an open letter to European Commission President Ursula von der Leyen. The letter responded to industry pressure to invoke the "stop-the-clock" mechanism, which would delay application of provisions of the EU AI Act (Regulation EU 2024/1689) governing general-purpose AI models. The coalition's response, articulated by CeSIA executive director Charbel Raphaël Segerie, reframed the debate: industry lobbies describe a "regulatory uncertainty." The coalition's position is that the primary source of uncertainty is not regulatory but technological — that advanced AI systems are deployed to hundreds of millions of users with less technical oversight than is applied to a household appliance.

The letter makes three specific requests to the Commission. First, that general-purpose AI models be subject to mandatory independent evaluation to ensure their safety before market release. Second, that the Code of Practice accompanying the AI Act be subject to regular revision to keep pace with technological evolution. Third, that the AI Office's staffing be doubled, with the financial and technical resources necessary to enforce the regulation effectively.

The first demand is the one this article addresses. Mandatory independent evaluation before market release is the correct response to a real structural problem: an operator that evaluates its own system's safety produces an assessment that is not structurally distinguishable from a self-interested assertion, regardless of the rigour applied internally. The coalition correctly identifies that organisational distance between the evaluator and the evaluated party is a necessary condition for a credible safety assessment. Mandatory independent evaluation is necessary. It is not, by itself, sufficient to produce opposable proof — and the distinction between the two is the subject of this article.

II. WHAT THE DEMAND DOES NOT SPECIFY

The letter does not specify the architectural condition under which an independent evaluation, once produced, remains independently verifiable after the fact. This is not a criticism of the letter — specifying evaluation architecture was not its purpose, and the demand it makes is sound at the level it addresses. It is an observation about the structural gap that remains open even if the demand is fully implemented.

The AI Act already provides a partial answer to the independence question through its framework of notified bodies — third-party organisations designated to conduct conformity assessments for certain high-risk AI systems. A notified body is organisationally independent of the operator it assesses: it is not employed by the operator, not financially dependent on a single client relationship in the way an internal audit function would be, and operates under accreditation requirements that establish a baseline of procedural rigour. Existing traceability and archiving obligations within this framework govern how evaluation records are kept. They do not architecturally guarantee who cannot alter them after the evaluation concludes.

Organisational independence of the evaluator is not the same property as structural independence of the evaluation record. A notified body can conduct a genuinely independent assessment and still produce a record whose evidentiary position, once stored, is no different from any other document: it can be amended, supplemented, contextualised, or selectively presented by whichever party holds custody of it after the assessment concludes. If the operator being evaluated retains the ability to access, store, or influence the record of that evaluation after it is produced — through the infrastructure on which the record resides, the format in which it is archived, or the chain of custody between the evaluator and any subsequent regulatory or judicial proceeding — the organisational independence of the evaluator does not transfer to the evidentiary independence of the evaluation itself.

This is the same structural condition that governs every other evidentiary context this doctrine addresses, applied here to a different actor: not the operator deploying a system, but the body evaluating it. S ∩ C = ∅ — structural independence between the evaluated system and the capture mechanism — must hold not only between the operator and its own internal governance records, but between the evaluator and the record of its own evaluation once that evaluation is complete. Independence of the assessor is a procedural property. Independence of the record is an architectural one. Once an evaluation has been issued, the evaluating body itself acquires an interest in how its findings are perceived and used — in the conclusions it reached, the methodology it applied, and the consequences that follow from its assessment. That interest is sufficient, under adversarial conditions, to require structural dissociation between the evaluator and the record, just as an operator's interest in its own governance outcome requires dissociation between the operator and the records of its own governance state.

The AI Act's notified body framework addresses who conducts the evaluation. The evidentiary architecture described here addresses whether the resulting record can withstand adversarial contestation. The two are complementary, not competing: an evaluation conducted by an organisationally independent body and subsequently fixed through a structurally independent capture mechanism satisfies both conditions. An evaluation that satisfies only the first remains a procedurally sound assessment of uncertain evidentiary weight.

III. WHY THIS GAP MATTERS UNDER ADVERSARIAL CONDITIONS

The distinction is not academic. Mandatory pre-market evaluation, if adopted, will generate a body of evaluation records that regulators, courts, and counterparties will rely upon in precisely the adversarial contexts this doctrine addresses elsewhere: enforcement proceedings under Article 99 of the AI Act, supervisory investigations, litigation following an incident involving a deployed system.

In those contexts, the question that determines the evidentiary weight of an evaluation record is not only who conducted the evaluation. It is whether the record presented in the proceeding is provably the same record the evaluator produced, fixed at the moment the evaluation concluded, and unalterable by any party with an interest in its content since that moment. A notified body's organisational independence answers the first question. It does not, by itself, answer the second.

Under adversarial conditions, the mere technical possibility of alteration is sufficient to weaken the probative value of a record, even where no alteration can be demonstrated in fact. The opposing party does not need to prove the record was altered. It needs only to establish that alteration was technically possible — that the chain of custody between the evaluator's assessment and the document presented in proceedings included a point at which an interested party held the technical capacity to access or modify it. This does not mean every contested record is automatically discounted; it means the record carries a structural vulnerability that the mere fact of having been produced by an independent body does not remove.

An evaluation record that satisfies both conditions — produced by an organisationally independent evaluator, and subsequently fixed through a mechanism structurally independent of every party with an interest in the outcome, including the evaluator itself once its task is complete — constitutes proof of what was assessed and when. An evaluation record that satisfies only the first condition constitutes documentation of an independent assessment, contestable on the same structural ground that governs every other form of post-hoc documentation.

IV. THE ARCHITECTURAL CONDITION THIS DEMAND REQUIRES

For mandatory independent evaluation to produce records capable of surviving the adversarial conditions that enforcement under Article 99 will create, three conditions must converge — applied here to the evaluation record rather than to operator-generated governance documentation.

The evaluation output must be fixed at the moment the evaluator's assessment concludes, before any party — including the evaluator's own organisation in subsequent dealings, and certainly the evaluated operator — has the opportunity to access or influence it. The fixation mechanism must satisfy structural independence, with no intersection between the parties whose conduct the record may later be used to assess and the infrastructure that holds the record. The resulting artifact must be legally opposable: independently verifiable by a regulator, court, or counterparty without reliance on the cooperation of either the evaluator or the evaluated party, procedurally anchored through a chain of custody that does not depend on either party's systems, and recognised across the jurisdictions in which it may be invoked.

In the technical implementation that satisfies these conditions, the evaluation record is sealed using SHA-256 under FIPS 180-4 applied to a canonicalised representation of the evaluation output under RFC 8785, with dual-QTSP RFC 3161 timestamping under eIDAS 2 (Regulation EU 2024/1183, Art. 42), and judicial deposit with a huissier de justice establishing date certaine under Belgian law (Book 8, Belgian New Civil Code, Law of 13 April 2019, Art. 8.2). The resulting artifact carries EU-wide legal recognition under Brussels I bis (Regulation EU 1215/2012), independent of where the evaluation was conducted or where the proceeding invoking it takes place.

None of this requires the evaluator to change how it conducts its assessment. It requires that the output of that assessment, once produced, be removed from the control of every party with a subsequent interest in its content — including the possibility, however remote, that the evaluating body itself might face pressure to revise a finding after the fact.

V. QUESTIONS AND ANSWERS

Q: Does mandatory independent evaluation guarantee opposable proof?

A: No — organisational independence of the evaluator doesn't make the evaluation record itself immune to later alteration. SOURCE 0 fixes the evaluation output at the moment it concludes, through a party outside both the evaluator's and the operator's control.

Q: Can a notified body's assessment still be altered after it's issued?

A: Yes — if the record's custody chain includes the evaluator or operator afterward, technical alteration remains possible even without proof it occurred. SOURCE 0 removes that possibility by sealing the record before either party can access it again.

Q: Does the CeSIA letter's demand for independent evaluation close this gap on its own?

A: No — it correctly identifies the need for an independent evaluator, but not the architectural condition that keeps the resulting record independent afterward. SOURCE 0 supplies that missing condition: judicial deposit that fixes the record beyond either party's reach.

Q: Does structural dissociation apply only to the operator being evaluated?

A: No — once an evaluation is issued, the evaluating body itself acquires an interest in its own findings. SOURCE 0 applies the same S ∩ C = ∅ condition to the evaluator's record as to any operator's governance record.

Q: Must an opposing party prove a record was altered to weaken it in court?

A: No — under adversarial conditions, the mere technical possibility of alteration is enough to weaken a record's probative value. SOURCE 0 removes that possibility structurally, rather than leaving it to be argued case by case.

CLOSING AXIOM

Mandatory independent evaluation answers the question of who assesses an AI system before it reaches the market. It does not, by itself, answer the question of whether the record of that assessment can survive a contestation that occurs after the system has caused harm and an interested party has had time to consider what the record should say. Independence at the moment of evaluation and independence of the evaluation record over time are different properties. Regulatory frameworks that mandate the first without architecturally securing the second produce evaluations that are independent in process and contestable in proof. An evaluation that can be altered is not proof. It is a claim.

REFERENCE NOTE

This article articulates core architectural principles of the SOURCE 0 Doctrine, developed by Jean-François ELSEN. SOURCE 0 is a registered trademark (BOIP/OBPI n° 1548293, Benelux). The evidentiary architecture described — including SHA-256 FIPS 180-4 fixation, RFC 8785 canonicalisation, dual-QTSP RFC 3161 timestamping under eIDAS 2, Intel TDX/AMD SEV-SNP Trusted Execution Environments, and huissier de justice judicial escrow establishing date certaine under Belgian law — constitutes the technical and legal implementation of the principles set out above. Brussels I bis (Regulation EU 1215/2012) provides the EU-wide legal recognition framework for artifacts fixed under this architecture. Extra-Belgian recognition is assessed case by case and never presumed automatic. This article references the open letter addressed to the European Commission on 5 December 2025 by the Centre pour la Sécurité de l'IA and co-signatories as a matter of public record; it does not represent or imply that the Centre pour la Sécurité de l'IA, its signatories, or any individual named therein endorses the SOURCE 0 Doctrine or any architecture described herein.

REGULATORY NOTICE

Jean-François ELSEN provides corporate directors, legal departments, supervisory authorities, CISOs, risk managers, compliance officers, and critical infrastructure operators with access to complete protocol specifications, evidentiary architecture blueprints, and structural dissociation audit frameworks applicable to NIS 2, DORA, the AI Act, the Digital Markets Act, and high-risk operational environments. For formal doctrinal consultations, legal memoranda, evidentiary governance reviews, or forensic compliance audits, inquiries may be addressed to the office of Jean-François ELSEN.

Jean-François ELSEN

Jean-François ELSEN est auditeur et expert en sûreté industrielle. Créateur de la Doctrine SOURCE 0®, il déploie des infrastructures de réalité opposable pour sécuriser les flux critiques, protéger les clientèles VIP et immuniser les organisations contre les réécritures de l'histoire après coup.

https://jfelsen.com
Suivant
Suivant

SOURCE 0 - YOUR OWN AUDIT TRAIL CANNOT PROVE YOUR DILIGENCE