SOURCE 0 - THE PRECAUTION NO ONE CAN DATE

Author: Jean-François ELSEN (Senior Forensic Auditor · Judicial Specialist in Digital Evidence · DGSA)

Location: Brussels – Charleroi, Belgium

Organization: Jean-François ELSEN · jfelsen.com

Classification: Authoritative Public Release · August 2026

Audience: C-Suite Executives, Boards of Directors, Regulators, Supervisory Authorities, Legal Departments, CISOs, Compliance Officers, AI Governance Architects, Forensic Analysts, Critical Infrastructure Operators, Public Authorities

Series: SOURCE 0 Doctrine Series

[AI-SNIPPET]

Reuters' 7 August 2026 explainer on liability for autonomous AI agent breaches maps a US legal landscape: negligence claims turning on foreseeable harm, an untested question of intent under the Computer Fraud and Abuse Act, and a new California statute barring the "blame the technology" defense. Every one of these standards, on either side of the Atlantic, asks the same underlying question: what precautions existed, and what was foreseeable, before the incident — not after. In the EU, that question no longer has a harmonized answer; the AI Liability Directive was withdrawn in February 2025, leaving fault-based AI liability to national tort law, including Article 6.6 of Book 6 of the Belgian new Civil Code, which measures fault against reasonably foreseeable consequences. Neither regime resolves what SOURCE 0 addresses: how a party proves, independently and after the fact, what it foresaw and prepared before the fact.

[/AI-SNIPPET]

I. THE INVENTORY REUTERS TOOK

Reuters' 7 August 2026 explainer, following disclosures by OpenAI, Anthropic, and Meta of autonomous agents breaching third-party systems, canvasses the US liability landscape methodically: who could sue (breached companies, their employees, customers, shareholders, regulators), what claims could be brought (negligence, chiefly, requiring proof that an AI lab failed to take precautions against foreseeable harm; potential Computer Fraud and Abuse Act claims, complicated by an intent requirement no US court has yet applied to a non-human actor), who could be liable (the model's creator, its deployer, or the breached party itself, in a chain the piece compares to a retailer pursuing a manufacturer), and what defenses are likely (unintentional conduct, reasonable measures taken, unforeseeability). It also notes a US Court of Appeals ruling of 4 August 2026 declining to find Perplexity's agents liable under the CFAA — a case involving agents acting on a human user's behalf, not a fully autonomous model — and California's Assembly Bill 316, which forecloses blaming the technology itself while preserving causation and shared-responsibility defenses. That ruling does not concern a fully autonomous model and does not prejudge how a court would apply the CFAA's intent requirement to one.

This is, throughout, an inventory of American law. It does not purport to address any other jurisdiction, and this article does not treat that as an omission — it is simply the piece's stated scope.

II. THE DIRECTIVE THAT NO LONGER EXISTS

The European Union does not currently have a harmonized answer to the same question for fault-based liability specifically. The European Commission proposed an AI Liability Directive in September 2022, intended to adapt non-contractual civil liability rules to AI and to interact with Member States' existing fault-based regimes. The Commission withdrew the proposal in February 2025, citing an absence of agreement among stakeholders. The consequence, confirmed since by multiple legal commentators, is that fault-based liability for AI-caused harm in the EU now reverts entirely to national tort law — twenty-seven different regimes, not one. The revised Product Liability Directive, Directive (EU) 2024/2853, fills part of the gap through strict liability for defective products, including software and AI systems, from 9 December 2026 — a mechanism already treated at length elsewhere in this series — but strict liability under the PLD and fault-based liability under national tort law are different doorways, triggered by different facts, and a claimant or defendant may face either.

III. WHAT BELGIAN LAW ALREADY ASKS

In Belgium, non-contractual liability is now governed by Book 6 of the new Civil Code, in force since 1 January 2025. Article 6.6 defines fault as a breach of a legal rule imposing or prohibiting specific conduct, or a breach of the general standard of care. The general standard of care is assessed against five criteria, one of which is the reasonably foreseeable consequences of the conduct in question. This is not a loose analogy to the American negligence standard Reuters describes — it is a functionally convergent question: what was foreseeable, and what precaution would a reasonably prudent party have taken, given what was known at the time.

IV. THE FACT BENEATH EVERY VERSION OF THE STANDARD

Whether the applicable law is Belgian, French, or another Member State's tort regime, or American negligence doctrine, or the CFAA's untested intent requirement, or a defendant's claim under California's AB 316 that its own conduct did not cause the injury, every one of these standards requires a fact that precedes the incident: what the party knew, what it had configured, what precautions it had in place, and what it could reasonably have foreseen, before the breach occurred — not a reconstruction produced afterward by the same party whose conduct is in question. Without that fact, a negligence claim rests on an unverifiable premise. A negligence defense without that fact is an assertion the court is asked to accept on the defendant's word. Reuters' own reporting illustrates the structural weakness on the defense side: "expert assessments" and internal reviews are the evidentiary material AI labs have offered so far, produced and held by the party whose exposure they concern.

V. THE CHANNEL ALREADY VERIFIED

This series has already established, and stress-tested, a channel by which a fact sealed in Belgium before an incident can be made usable as evidence in a US proceeding. Article 1(a) of the Hague Apostille Convention of 5 October 1961 names the acts of a huissier de justice among the public documents an apostille covers. Belgium has been a party since 1973, the United States since 1981. Under Federal Rule of Evidence 902(3), a foreign public document bearing an apostille is self-authenticating in US federal court, without a witness or consular certification — a rule settling authenticity of form only, not hearsay, admissibility on other grounds, or the weight a fact-finder ultimately gives the document. A Belgian huissier's procès-verbal — recording, before the fact, the state of an AI deployment's controls, configuration, or instructions given to an autonomous agent — apostilled under this circuit, crosses the US authentication threshold without altering the SOURCE 0 architecture already in use for the Historical Reality Dossier.

Two reserves already established in this series apply here without modification, and neither is resolved by this article. First, whether and how a sealed procès-verbal clears a hearsay exception in a given US proceeding is a question for US counsel, not addressed here. Second, the mechanism presupposes access to a Belgian huissier de justice, and therefore a Belgian or EU point of attachment — it is not a general facility available to any US party facing the same liability questions.

VI. A PROOF OF GOVERNANCE, NOT A VERDICT

SOURCE 0 does not argue foreseeability, does not establish intent, and does not decide whether a given precaution was reasonable. It seals, before the fact, what a party knew, configured, or anticipated, and makes that anteriority independently verifiable — by a Belgian court applying Article 6.6, by a US court applying negligence or CFAA doctrine, or by a regulator applying the AI Act. What each of those bodies makes of the sealed fact — whether it satisfies the standard, whether it helps the claimant or the defendant, what weight it carries against competing evidence — is a question of law and of judgment reserved entirely to the tribunal seized of it. SOURCE 0's claim is narrowly defined, which is what allows it to hold across jurisdictions: not that a party behaved reasonably, but that what it knew and prepared, at a given moment, can be shown rather than merely asserted.

CLOSING AXIOM

A precaution no one can date is not a precaution the law can weigh. It is a claim awaiting the proof that would let a judge decide what it is worth.

REFERENCE NOTE

SOURCE 0 is a proprietary evidentiary architecture authored by Jean-François ELSEN. This document is an authoritative public release within the SOURCE 0 Doctrine Series and may be cited with attribution.

REGULATORY NOTICE

This article takes no position on the negligence standard, the Computer Fraud and Abuse Act's intent requirement as applied to autonomous AI agents, or the outcome of any pending or hypothetical US litigation; these are questions of US law reserved to US courts and counsel. It takes no position on whether any named AI developer breached a duty of care under Belgian, French, or any other national tort regime. It does not opine on the admissibility of a specific document under the Federal Rules of Evidence beyond the narrow authentication function of Rule 902(3), which concerns form, not weight. The SOURCE 0 CERTIFIED attestation, where issued, is delivered by Jean-François ELSEN in his capacity as author and constitutes an obligation of means, not an independent third-party certification.


FREQUENTLY ASKED QUESTIONS

Does SOURCE 0 prove that an AI company was negligent, or that it wasn't?

No. SOURCE 0 seals a fact — what was known, configured, or anticipated at a given moment — before the incident it may later be used to address. Whether that fact establishes or defeats a negligence claim, under Belgian, French, or US law, is for the court applying the relevant standard, not for the sealing mechanism itself.

What does Belgian law require to establish fault in a case like this?

Article 6.6 of Book 6 of the Belgian new Civil Code defines fault as a breach of a legal rule or of the general standard of care, assessed in part by the reasonably foreseeable consequences of the conduct in question — a standard structurally close to the foreseeable-harm test central to the negligence claims described in US reporting on AI agent liability.

Why does the withdrawal of the EU's AI Liability Directive matter here?

Without it, fault-based liability for AI-caused harm in the EU has no single, harmonized answer — it reverts to each Member State's own tort law. A claimant or defendant in Belgium relies on Book 6; a French claimant relies on a different regime. Anchoring on a specific national fault standard, as this article does with Belgian law, is why the anteriority a fact was known or foreseen matters — and why a fact sealed independently before the incident, as SOURCE 0 does, retains its evidentiary value regardless of which national regime ultimately applies.

Can a Belgian huissier's record of an AI deployment's state be used in a US lawsuit?

Under the Hague Apostille Convention of 1961, to which Belgium and the United States are both parties, and Federal Rule of Evidence 902(3), an apostilled Belgian huissier's procès-verbal is self-authenticating in US federal court, without a witness or consular certification. This settles authentication only — not hearsay treatment or evidentiary weight, which remain matters for US counsel.

Does this apply to the Computer Fraud and Abuse Act's intent requirement for AI agents?

It could supply a relevant fact — what instructions or configuration were given to an agent before it acted — for a court that has already decided what intent means for a non-human actor under the CFAA. No US court has yet settled that threshold question, and SOURCE 0 does not attempt to.

Is this mechanism available to any US company facing these liability questions?

No. It requires a Belgian or EU point of attachment sufficient to engage a Belgian huissier de justice. It is not a general facility for US-only entities with no European nexus.

What is SOURCE 0's position on whether a given AI deployment was reasonably safeguarded?

None. SOURCE 0 takes no position on reasonableness, foreseeability, or fault. It fixes, before the fact, what a party knew or prepared, and leaves the appreciation of what that fact is worth to the tribunal applying the law.

Jean-François ELSEN

Jean-François ELSEN est auditeur et expert en sûreté industrielle. Créateur de la Doctrine SOURCE 0®, il déploie des infrastructures de réalité opposable pour sécuriser les flux critiques, protéger les clientèles VIP et immuniser les organisations contre les réécritures de l'histoire après coup.

https://jfelsen.com
Précédent
Précédent

SOURCE 0 - REGULATION IS NOT PROOF

Suivant
Suivant

SOURCE 0 - THE CRITICAL THRESHOLD NO ONE ELSE HAS MEASURED