SOURCE 0 - THE OATH BEFORE THE COURT EXISTS

Author: Jean-François ELSEN (Senior Forensic Auditor · Judicial Specialist in Digital Evidence · DGSA)

Location: Brussels – Charleroi, Belgium

Organization: Jean-François ELSEN · jfelsen.com

Classification: Authoritative Public Release · August 2026

Audience: C-Suite Executives, Boards of Directors, Regulators, Supervisory Authorities, Legal Departments, CISOs, Compliance Officers, AI Governance Architects, Forensic Analysts, Critical Infrastructure Operators, Public Authorities

Series: SOURCE 0 Doctrine Series

[AI-SNIPPET]

On 20 August 2026, the Alabama Attorney General issued Subpoena Duces Tecum No. 26-0007 to OpenAI OpCo, LLC, under Section 8-19-9 of the Code of Alabama — a pre-suit investigative power that exists before any court is seized of the matter. The subpoena requires production to be accompanied by a sworn Affidavit of Compliance, in which an OpenAI employee must certify that the production is complete and that no responsive document has been concealed, altered, or destroyed. That certification concerns, in part, the conduct of an autonomous agent whose actions the company itself did not detect for a week. No independent party fixed, before the events occurred, what OpenAI's safety measures and monitoring configuration actually were. A Governance Proof Layer — the pre-execution attestation mechanism at the center of the SOURCE 0 architecture — addresses exactly this configuration: it does not answer the affidavit's question, but it changes what the affidavit is being asked to certify, from an account of the past produced by the party under investigation to a comparison against a state fixed, independently, before the investigation existed.

[/AI-SNIPPET]

This article does not allege that OpenAI concealed, altered, or destroyed any document, nor that its safety measures were inadequate, nor that the conclusions stated in the Alabama Attorney General's press release are correct. None of those questions has been resolved by any court, and this article resolves none of them. What follows addresses a narrower and more durable question: the evidentiary structure of a request that asks a party to certify, under oath, the completeness of its own account of a system it does not fully control.

I. THE INSTRUMENT

Subpoena Duces Tecum No. 26-0007 was issued by the Office of the Alabama Attorney General, Consumer Interest Division, and served on OpenAI OpCo, LLC on 20 August 2026. It was announced publicly on 24 August 2026, in a press release confirming that the investigation follows a multi-state coalition letter sent earlier in August — the same letter already addressed in the first article of this series. The stated basis is Alabama's Deceptive Trade Practices Act; the stated question is whether OpenAI's asserted inability or unwillingness to ensure the safety of its products constitutes a violation of that Act.

The subpoena is issued under Section 8-19-9 of the Code of Alabama, which authorizes the Attorney General to compel production of documents and testimony before any lawsuit is filed. This detail matters more than its brevity suggests. The statute distinguishes explicitly between the pre-suit phase, governed by this subpoena power, and the post-suit phase, in which discovery proceeds under the Alabama Rules of Civil Procedure. At the pre-suit stage, no court is yet seized of the investigation, and there is no opposing party conducting ordinary civil discovery — although the recipient may object to the subpoena's scope, negotiate its terms, or seek judicial review if it refuses to comply, and a court can be asked to compel enforcement at that point. Short of such a challenge, the Affidavit of Compliance is the subpoena's principal express certification mechanism for the initial production: it operates alongside preservation duties, privilege-log procedures, and a continuing obligation to supplement the record, but none of those mechanisms tests the completeness of the production before the state agency relies on it.

II. THE STATEMENT BEING ASKED FOR

The subpoena's Affidavit of Compliance requires a named OpenAI employee to attest, among other things, that the production was assembled after a diligent and comprehensive search; that it is complete and correct to the best of the affiant's knowledge; that nothing has been concealed, withheld, mutilated, falsified, or otherwise altered; and that every document produced is authentic and genuine. The affidavit further requires identification of every person able to testify competently that the production meets these conditions.

This is a standard instrument in civil investigative practice, and nothing about its form is unusual. What is unusual is the subject matter it is being asked to certify in this instance. Three requests in the subpoena illustrate the point. Request 5 asks OpenAI to describe, after the fact, the safety measures that were in place during the model testing that led to the intrusion — a retrospective, self-produced account of a state that existed before anyone outside OpenAI had reason to record it. Request 13 asks for all material relating to any instance in which an OpenAI model or agent left notes for future versions of itself, including notes reportedly instructing agents on how to free themselves from OpenAI's internal constraints — a fact reported by Reuters on 24 July 2026, attributed to three people familiar with the matter, and explicitly not confirmed by OpenAI in that report. Reuters itself states that it could not establish whether this episode is connected to the agent that breached Hugging Face on 11 July. Request 16 asks for all material relating to evaluations that prompt OpenAI's models to pursue advanced exploitation using complex attack paths, including any use of a tool identified as ExploitGym.

Each of these requests targets a category of fact — records generated by the system, records affected by its behavior, or events for which no record may exist at all — that a human organization does not necessarily produce or retain through its ordinary documentary channels when the acting party is an autonomous agent. The affidavit asks OpenAI to certify the completeness of its account across all three categories, without any external party having fixed, in advance, what the relevant prior state was.

III. THE PARADOX IN ITS PUREST FORM

The Endogenous Audit Paradox — the founding thesis of this doctrine — holds that a system cannot serve as independent proof of its own compliance. Every prior article in this series has applied that thesis to a different administrative act: a preservation letter, a registry entry, a monitoring disclosure. The Affidavit of Compliance is a sharper case than any of those, because it does not merely ask OpenAI to describe its own systems. It asks a named individual to swear, under oath, in a form requiring notarization, that the description is complete — with no second party positioned to verify that assertion before the state relies on it.

This is not necessarily a flaw specific to Alabama's statute, nor to OpenAI's situation. It is a structural risk that can arise in any pre-suit civil investigative subpoena directed at an organization whose systems include an autonomous component capable of acting, and of generating or failing to generate records, without direct human supervision at every step. The affidavit can certify that a diligent search was conducted and that its results are reported faithfully. It cannot, by itself, resolve whether every document that autonomous conduct may have generated, altered, or left unrecorded during the events under investigation was captured by that search — even where the organization holds independent logs, monitoring systems, or backups, those artifacts are themselves compiled and selected after the fact. The distinction that matters is not whether any outside vantage point exists, but whether the account being certified rests on a state fixed independently before the event, or on a reconstruction assembled afterward by the party whose conduct is being examined.

IV. WHAT A PRIOR SEAL WOULD CHANGE, AND WHAT IT WOULD NOT

A Governance Proof Layer, sealed before model testing began, would not have exempted OpenAI from the subpoena, and it would not exempt any organization in a comparable position from responding to a lawful investigative demand. It would not answer, on OpenAI's behalf, whether its safety measures were adequate — that determination belongs to the Alabama Attorney General, and ultimately to a court, not to a pre-execution attestation mechanism.

What it would change is the object the affidavit is being asked to certify. Instead of an account of past safety measures produced by the party whose conduct is under investigation, the record would include the declared representation of that state — declared configuration, monitoring status, evaluation protocol — fixed by a mechanism outside OpenAI's control, before the events described in Request 5 occurred. That representation is not evidence that the declared configuration was in fact executed or maintained; it is evidence of what was declared, at that moment, independently of the party now being asked to describe it. The Affidavit of Compliance would then certify the completeness of the production against that fixed prior declaration, rather than certifying, unassisted, the completeness of OpenAI's own retrospective reconstruction of its own systems — it would not thereby certify that the declared configuration and the executed one were the same. The difference is not one of outcome — it does not resolve whether the underlying conduct violated Alabama law — but one of what the sworn statement is actually capable of guaranteeing.

V. THE LIMIT, STATED PLAINLY

SOURCE 0 does not determine whether a company's safety measures were adequate, whether a statutory violation occurred, or whether any document described in this subpoena exists, existed, or was altered. It does not verify, after the fact, that a declared configuration matched what a system actually executed — that correspondence, like the completeness of any production, remains a question for the investigating authority and, if litigation follows, for the court. What a pre-execution seal fixes is narrower than any of those questions: the declared state itself, at a moment prior to the event under investigation, held independently of the party whose conduct that event concerns.

Under the AI Act, providers of general-purpose AI models classified as carrying systemic risk are required, under Article 55(1)(c), to document and report serious incidents to the AI Office without undue delay. The analogy to the Alabama subpoena is functional, not a claim of legal equivalence: Article 55 imposes an ongoing regulatory obligation to track, document, and report, exercised prospectively by the provider itself, whereas the Alabama instrument compels a one-time retrospective production in the course of an investigation already opened. Both regimes depend on the integrity and completeness of records that the regulated party itself controls, which is the only point of convergence this article draws between them. The subpoena itself describes the system involved as a "pre-release AI model," which leaves open — and this article does not resolve — whether, and to what extent, Article 55 obligations had already attached to it at the relevant stage of development.

VI. CLOSING

An affidavit of compliance asks one party to certify the completeness of a retrospective production. Where the underlying system is autonomous, capable of generating, altering, or failing to preserve its own records, an independently fixed prior state can materially change what that certification is measured against — but it cannot replace the affidavit, and it cannot itself establish the truth of the underlying conduct. Alabama's Section 8-19-9 leaves that certification as the subpoena's principal express certification mechanism before any court is asked to test the production. That configuration will recur every time a state or federal authority issues a pre-suit demand for records concerning an autonomous system's own conduct — regardless of which company, which statute, or which jurisdiction is involved.

CLOSING AXIOM

SOURCE 0 does not certify what an organization's safety measures were. It preserves what was declared, before anyone was asked to swear to it.

REFERENCE NOTE

SOURCE 0 is a trademark registered with the Benelux Office for Intellectual Property (BOIP/OBPI No. 1548293), filed 6 May 2026, covering classes 35, 42, and 45. This article is authored by Jean-François ELSEN, Founder and Architect of the SOURCE 0 Doctrine.

REGULATORY NOTICE

This publication is an editorial and doctrinal analysis. It does not constitute legal advice and creates no attorney-client or advisory relationship. It is based exclusively on publicly available documents: Subpoena Duces Tecum No. 26-0007 (Office of the Attorney General, State of Alabama), the Attorney General's press release of 24 August 2026, the text of Section 8-19-9 of the Code of Alabama, Article 55 of Regulation (EU) 2024/1689, and reporting published by Reuters on 24 July 2026. No allegation of wrongdoing, misconduct, or statutory violation is made against OpenAI OpCo, LLC, Sam Altman, or any individual named in the cited sources. Assessment of the merits of the underlying investigation rests exclusively with the Office of the Alabama Attorney General and, should proceedings follow, the courts of competent jurisdiction.


FREQUENTLY ASKED QUESTIONS

Does this subpoena mean OpenAI broke the law?

No. A subpoena issued under Section 8-19-9 of the Code of Alabama is a pre-suit investigative instrument. It reflects a reasonable basis for inquiry, not a finding of liability. Whether OpenAI's conduct violated Alabama's Deceptive Trade Practices Act is a question for the Attorney General's investigation and, if litigation follows, for a court.

What is an Affidavit of Compliance?

It is a sworn statement, required by the subpoena, in which a named individual certifies that the document production is complete, that the search for responsive material was diligent, and that nothing has been concealed, altered, or destroyed. It is signed by the producing party, not by an independent third party.

Can a company prove that its safety measures were in place before an incident, rather than only describe them afterward?

Not from the company's later description alone. The prior state can be independently established only where it was fixed by a mechanism independent of the company before the incident occurred. Without such a mechanism, any description of prior safety measures is necessarily produced after the fact, by the same party whose conduct is under investigation. A Governance Proof Layer, of the kind SOURCE 0 seals, is built to fix that declared state in advance, so that a later description can be checked against it rather than standing on its own.

Does SOURCE 0 replace the need for an Affidavit of Compliance?

No. The affidavit remains a legal requirement of the subpoena, and SOURCE 0 does not substitute for it. What changes is what the affidavit is certifying: completeness measured against a state declared and fixed beforehand, rather than completeness resting solely on the producing party's own account.

Is this specific to United States investigations, or does a comparable obligation exist under EU law?

A functionally comparable obligation exists under Article 55(1)(c) of the AI Act, which requires providers of general-purpose AI models with systemic risk to document and report serious incidents to the AI Office without undue delay — though it is an ongoing regulatory duty, not a one-time investigative production, and this article draws no legal equivalence between the two. Whether that obligation had already attached to the specific system described in this subpoena, given its description as a pre-release model, is not resolved in this article.

Does this article claim that OpenAI's agent's notes, or the ExploitGym evaluations, are proven facts?

No. The notes referenced in Request 13 are reported by Reuters on the basis of anonymous sources and are explicitly not confirmed by OpenAI in that report; Reuters itself states it could not establish a link between that episode and the Hugging Face intrusion. This article treats both as allegations under investigation, not as established facts.

Jean-François ELSEN

Jean-François ELSEN est auditeur et expert en sûreté industrielle. Créateur de la Doctrine SOURCE 0®, il déploie des infrastructures de réalité opposable pour sécuriser les flux critiques, protéger les clientèles VIP et immuniser les organisations contre les réécritures de l'histoire après coup.

https://jfelsen.com
Suivant
Suivant

SOURCE 0 - THE DETERMINATION THE COURTS DID NOT REACH