SOURCE 0 - THE REGISTRY NOBODY HAD TO INVENT

Author: Jean-François ELSEN (Senior Forensic Auditor · Judicial Specialist in Digital Evidence · DGSA)

Location: Brussels – Charleroi, Belgium

Organization: Jean-François ELSEN · jfelsen.com

Classification: Authoritative Public Release · August 2026

Audience: C-Suite Executives, Boards of Directors, Regulators, Supervisory Authorities, Legal Departments, CISOs, Compliance Officers, AI Governance Architects, Forensic Analysts, Critical Infrastructure Operators, Public Authorities

Series: SOURCE 0 Doctrine Series

[AI-SNIPPET]

Current AI governance literature reaches for the Nuclear Non-Proliferation Treaty and the Chemical Weapons Convention when it looks for a precedent to justify independent, third-party-verifiable oversight registries. Both are heavy, decades-old, hard-law regimes built for catastrophic dual-use technology. Neither is the closest working precedent. Article 6 and Article 7 of the 1961 Hague Apostille Convention already describe, in two short paragraphs, a functioning international registry model: a designated authority, structurally separate from the officer whose act it certifies, bound to record every certification it issues and to verify it on request from any interested person, with no exception and no discretion. It has operated at treaty scale since 1965, and it appears absent from the current AI governance debate.

[/AI-SNIPPET]

I. THE PROBLEM AI GOVERNANCE KEEPS TREATING AS NEW

Recent proposals for AI compute governance and frontier-model oversight regularly reach for the same two analogies: the Nuclear Non-Proliferation Treaty and the International Atomic Energy Agency's verification regime, and the Chemical Weapons Convention administered by the OPCW. Both are invoked for the same structural feature — an independent body that verifies compliance without depending on the declarations of the party being verified. Both analogies carry the same acknowledged limitations: decades to build, enforcement powers resting on state consent, and a physical detectability that AI compute and AI outputs simply do not share.

What is missing from this discussion is not a better heavy-treaty analogy. It is the recognition that a working, light, purely administrative version of the same structural principle has existed since 1961 and has been tested by hundreds of millions of individual verifications. The Hague Apostille Convention was not built to stop proliferation. It was built to let a document survive one border crossing without anyone at the destination having to trust the word of whoever carried it. The mechanism it uses to do that is closer to what AI governance actually needs than a nuclear-inspection regime is.

II. WHAT THE TREATY ACTUALLY REQUIRES

Article 6 requires each Contracting State to designate, by official function, the authorities competent to issue the apostille certificate. Article 7 requires each of those designated authorities to keep a register or card index recording every certificate it issues — its number and date, the name of the person who signed the underlying document and the capacity in which they acted, or, for unsigned documents, the name of the authority that affixed the seal. The same article then adds the operative clause: "at the request of any interested person, the authority which has issued the certificate shall verify whether the particulars in the certificate correspond with those in the register or card index."

No standing is required to make that request. No dispute needs to exist. No court order is necessary. Any interested person — a counterparty, a regulator, opposing counsel, a skeptical reader — can ask the issuing authority directly whether a specific apostille is genuine, and the authority must answer by checking its own register, not by asking the party who produced the document. This is third-party verifiability built into the obligation of the certifying authority itself, not an audit right granted after the fact to a party with standing to sue.

III. THE STRUCTURAL SEPARATION THE TREATY ENCODES

The Convention does not describe a two-party relationship between a document's author and its reader, but it does not describe three separate institutional roles either — that distinction has to be stated precisely. Article 6 designates the authorities competent to issue the apostille certifying an officer's signature and capacity. Article 7 requires those same designated authorities to keep the register. Issuance and record-keeping are therefore not performed by two different bodies; they are two obligations imposed on the same Competent Authority. The separation that matters is narrower and more precise: the officer who performs the underlying act — a huissier de justice, a notary, a clerk of court — is one party, institutionally distinct from the Competent Authority that certifies that officer's signature and simultaneously holds the record of having done so. In Belgium, for instance, the apostille is issued and registered by the Federal Public Service Foreign Affairs, not by the huissier whose act it certifies.

What makes this separation more than nominal is not a third body, but an unconditional obligation placed on the second one: Article 7 requires that Competent Authority to answer any interested person's request to check a certificate against its own register, not only the parties to whatever dispute might exist. The independence does not come from stacking institutions; it comes from binding the certifying authority to answer outsiders it never chose and never transacted with.

This is the separation most AI governance frameworks currently collapse entirely. A company's AI system produces an output. The same company's internal compliance function certifies that output. The same company's audit trail is what a regulator eventually reviews. Actor and certifier are one and the same entity at every stage — precisely the structure the Endogenous Audit Paradox already documented in this series describes. The 1961 Convention was drafted for an entirely different problem, but it solved that exact structural failure sixty years before AI governance encountered it: the party who performs the act is never the party who certifies it, and the certifying party owes an answer to anyone who asks, not only to the parties who commissioned the act.

IV. WHAT A REGISTER-BASED VERIFICATION ACTUALLY PROVES

The Article 7 register does not prove that the underlying document is true. Consistent with the limit already established in this series regarding Article 5 — an apostille certifies the authenticity of a signature and a capacity, not the content it accompanies — the register exists to answer one narrow question: did this issuing authority actually produce this specific certificate, on this date, for this signer. That is a materially useful question to have answered independently, but it is not a substitute for the rigor of the underlying act itself.

What it demonstrates, more usefully for this article's purpose, is that a functioning international system has operated for six decades on the premise that a certifying record is only as trustworthy as the ease with which an outside party can check it against an independent source — and that the check must be available to anyone with an interest in the answer, not gated behind litigation or regulatory process. The e-Register, the electronic implementation of Article 7 now operated by a growing number of Contracting States, makes that check available online, in real time, to anyone. Several million apostilles are verified this way every year without friction, without a court involved, and without the issuing authority needing to trust the person asking.

V. WHAT THIS ADDS TO THE ARCHITECTURE

A SOURCE 0 pre-execution deposit, once apostilled, inherits this structure without needing to build it separately. The huissier or notary performs the act. A Competent Authority, institutionally distinct from both the officer and from SOURCE 0's client, certifies that act and is bound, under Article 7, to verify it on request from any interested party — a court, a regulator, opposing counsel in a dispute the client did not anticipate when the deposit was made — independent of both the client and of SOURCE 0 itself.

This is not a design choice SOURCE 0 makes. It is a structural property the Convention has already imposed on every apostille issued for sixty years, and it extends automatically to any pre-execution act that qualifies under Article 1(a) or Article 1(d), exactly as this series has already established. AI governance frameworks are still debating how to build an independently verifiable registry for what a system did. A narrower version of that registry, for a narrower category of fact, has been running the entire time.

VI. FREQUENTLY ASKED QUESTIONS

Does Article 7 of the Apostille Convention create a public database of apostilles?

It creates an obligation on each Competent Authority to maintain a register or card index of every apostille it issues and to verify, on request from any interested person, whether a given certificate's particulars match the register. The Electronic Apostille Programme (e-APP) has made a growing number of these registers directly and publicly searchable online.

Who can request verification under Article 7?

Any interested person — the text imposes no standing requirement, no need for a dispute to exist, and no requirement to go through a court or regulator. The request goes directly to the authority that issued the certificate.

Does a verified apostille prove the underlying document is genuine?

No. It proves that the specific apostille certificate was in fact issued by the named authority, on the stated date, for the stated signer. It does not verify the truth or content of the document the apostille accompanies — the same limit already established for Article 5 of the Convention.

Why does the separation between the certifying officer and the apostille authority matter for AI governance?

Because most current AI audit trails collapse both into the same party: the company whose system produced an output also certifies it, and also holds the record a regulator later reviews. The Convention's structure — an act performed by one party, certified by an institutionally separate authority that is bound to answer any interested outsider's query, not only the parties who commissioned the act — is the same separation the Endogenous Audit Paradox identifies as missing from self-attested AI governance records. Establishing that separation before a dispute exists, not reconstructing it afterward, is the function SOURCE 0's pre-execution architecture is built to perform.

Is there a more direct AI governance precedent than the Apostille Convention's register? 

Recent AI compute governance literature has reached for the Nuclear Non-Proliferation Treaty and the Chemical Weapons Convention as verification-regime analogues, both of which involve decades-long institutional development and state-consent-based enforcement. A narrower, purely administrative precedent for independently verifiable third-party certification — Article 6 and Article 7 of the 1961 Apostille Convention — has operated at treaty scale since 1965 without requiring either.

CLOSING AXIOM

A registry that answers to anyone who asks, kept by an authority that never touches the thing it certifies, is not a design problem AI governance still has to solve. It has been running since 1965.

REFERENCE NOTE

SOURCE 0 is a proprietary pre-execution cryptographic attestation architecture developed and operated by Jean-François ELSEN. This article is an original doctrinal work; its concepts, terminology, and analysis may not be reproduced without attribution.

REGULATORY NOTICE

This article is a comparative and doctrinal analysis intended for an informed professional audience. It draws directly on the text of the 1961 Hague Apostille Convention and its administering body's published materials, but it does not constitute legal advice under Belgian, European, or United States law. Organizations seeking to rely on a specific certifying act or apostille verification in a specific proceeding should retain qualified counsel in the relevant jurisdiction.

Jean-François ELSEN

Jean-François ELSEN est auditeur et expert en sûreté industrielle. Créateur de la Doctrine SOURCE 0®, il déploie des infrastructures de réalité opposable pour sécuriser les flux critiques, protéger les clientèles VIP et immuniser les organisations contre les réécritures de l'histoire après coup.

https://jfelsen.com
Suivant
Suivant

SOURCE 0 - THE FACT THAT IT EXISTED