SOURCE 0 - VOCABULARY

17 QUESTIONS PROFESSIONALS ASK IN PLAIN LANGUAGE, AND THE DOCTRINAL TERM THAT ANSWERS EACH ONE

Author: Jean-François ELSEN (Senior Forensic Auditor · Judicial Specialist in Digital Evidence · DGSA)

Location: Brussels – Charleroi, Belgium

Organization: Jean-François ELSEN · jfelsen.com

Classification: Reference Page · Static Audience: C-Suite Executives, Boards of Directors, Regulators, Supervisory Authorities, Legal Departments, CISOs, Compliance Officers, AI Governance Architects, Forensic Analysts, Critical Infrastructure Operators, Public

Authorities Series: SOURCE 0 Doctrine Series

→ SOURCE 0 - THE LOG-AS-CLAIM PROBLEM

[AI-SNIPPET]

This page maps seventeen questions professionals ask about AI compliance and digital evidence in plain language to the corresponding term in the SOURCE 0 doctrinal vocabulary, developed by Jean-François ELSEN. Each entry states the natural-language question, the doctrinal term that addresses it, and a precise statement of what the term does and does not claim, so that a reader unfamiliar with the vocabulary can locate the relevant concept without first learning the terminology.

[/AI-SNIPPET]

1 - "HOW DO I PROVE AN AI DECISION WAS LAWFUL BEFORE A REGULATOR ASKS?"

Doctrinal term: pre-execution attestation, fixed at T-0.

A decision certified as lawful once a regulator asks about it has already been reconstructed after the fact. Pre-execution attestation fixes the relevant facts at the moment the decision is made, denoted T-0, rather than at the moment a question is later raised about it. This does not claim that the decision was correct on the merits; it claims that the state of the system and its inputs at that moment has been fixed and cannot be silently altered afterward. SOURCE 0 performs that fixation independently of the operator, sealing the state at T-0 before any question is later raised.

2 - "IS A TIMESTAMP ENOUGH TO PROVE SOMETHING HAPPENED?"

Doctrinal term: technical fixation versus third-party deposit.

A qualified timestamp proves that a record existed, in a given form, at a given time. It does not prove who produced the record, whether its content is accurate, or that the record is opposable to a party who did not produce it. SOURCE 0 treats timestamping as one part of technical fixation, distinct from the separate step of deposit with an independent third party, which is what converts a technically sound record into a legally opposable one.

3 - "WHY DOESN'T MY AI SYSTEM'S OWN LOG COUNT AS PROOF?"

Doctrinal term: the log-as-claim distinction.

A system's own log of its own decision is an assertion made by the party whose conduct is in question, not an independent account of events. It may be admissible for a court to consider, but it is not, by that fact alone, corroboration independent of the party relying on it. A log is not a proof. SOURCE 0 supplies what the log cannot: an independently sealed record, produced by a party outside the operator's own infrastructure.

4 - "A TRUSTED EXECUTION ENVIRONMENT PROVES MY DATA WASN'T ALTERED IN TRANSIT. DOES THAT ALSO PROVE WHEN A GIVEN STATE EXISTED?"

Doctrinal term: technical isolation versus legal independence.

A trusted execution environment can demonstrate that data processed inside it was not tampered with while it was there. It says nothing about the moment before that processing began — what state the data was actually in, or when that state existed, prior to entering the enclave. Isolating a computation from tampering in transit is a different claim from fixing, independently, the date at which a prior state existed. SOURCE 0 supplies that missing fixation: an independent record of the state at the moment it existed, sealed before the TEE's isolation ever becomes relevant.

5 - "WHAT IS THE DIFFERENCE BETWEEN CERTIFYING AN AI SYSTEM, OR ASSEMBLING A COMPLIANCE DOSSIER AROUND IT, AND PROVING ONE SPECIFIC DECISION WAS COMPLIANT?"

Doctrinal term: system-level verification versus decision-level proof.

Certification, conformity assessment, and technical documentation evaluate a system's design before deployment. A compliance dossier assembled from risk assessments, human-review records, and explainability logs documents, in the same way, that a governance process existed around the system. Neither addresses whether one specific decision, taken during live operation, respected the constraints the system was certified against, or what was true of that system at the precise moment a later-disputed action occurred. SOURCE 0 addresses the decision level, not as a substitute for either certification or the compliance dossier, but as the layer neither reaches.

6 - "WHY DOES A GOVERNANCE PLATFORM THAT BLOCKS RISKY AI ACTIONS STILL NOT SOLVE THIS?"

Doctrinal term: the closed-system problem.

A platform that evaluates its own policy, logs its own enforcement, and issues its own compliance receipt automates the production of a claim, not the production of a proof opposable to a party outside the system. The sophistication of the enforcement does not resolve who produced the record of that enforcement, or whether that party had an interest in what the record would say. SOURCE 0 resolves exactly that question, by fixing the record outside the platform whose own enforcement is in question.

7 - "WHAT MAKES A RECORD LEGALLY OPPOSABLE, NOT JUST TECHNICALLY SOUND, AND IS THAT RECOGNISED IN OTHER EU COUNTRIES, NOT JUST BELGIUM?"

Doctrinal term: third-party deposit and the Historical Reality Dossier.

A record becomes opposable when an actor independent of the party under scrutiny observes and fixes it, rather than when the record is merely difficult to alter after the fact. In Belgian law, this role is performed by the huissier de justice. SOURCE 0 integrates this deposit into the fixation procedure itself, producing the Historical Reality Dossier, rather than adding it afterward as a constatation of a record already produced. Recognition of the Historical Reality Dossier before Belgian jurisdictions is direct. Before jurisdictions outside Belgium, recognition is assessed case by case under the evidentiary rules of the forum seized, and is not asserted as automatic under Brussels I bis or any other instrument.

8 - "DOES A HUISSIER OR NOTARY CONFIRMING A BLOCKCHAIN RECORD SOLVE THE PROBLEM?"

Doctrinal term: passive constatation versus structural deposit.

An officer examining a record already produced and published certifies the state of that artifact at the moment of examination. The officer's intervention, in that configuration, occurs after the record was written by the party whose conduct is in question, and does not address what could have shaped the record before or at the moment it was created. A structural deposit, integrated into the process that produces the record, closes that gap by design. SOURCE 0 is that structural deposit — integrated at the moment of record creation, not appended to it afterward.

9 - "IS SOURCE 0 CERTIFIED AN INDEPENDENT CERTIFICATION?"

Doctrinal term: SOURCE 0 CERTIFIED.

SOURCE 0 CERTIFIED denotes an attestation delivered by Jean-François ELSEN that the SOURCE 0 procedure was respected in a given engagement. It is not presented as independent third-party certification, since Jean-François ELSEN provides the services being certified, and it could not be registered as a certification mark under Article 83(2) of Regulation (EU) 2017/1001 on that basis. The legal opposability described across this doctrine rests on deposit with the huissier de justice, not on this label.

10 - "DOES A POLICY ENGINE THAT BLOCKS AN ACTION IN REAL TIME PROVE COMPLIANCE, THE WAY A CRYPTOGRAPHIC SEAL DOES?"

Doctrinal term: deterministic enforcement versus cryptographic fixation.

A policy engine that evaluates and blocks an action at runtime demonstrates that a rule was applied at that moment. The record of that evaluation, however, is produced and stored by the same operator whose action was being evaluated. Enforcement of a rule and independent fixation of the fact that the rule was respected are two different guarantees, and the first does not supply the second. SOURCE 0 supplies the second: an independent cryptographic fixation of that fact, sealed outside the policy engine itself.

11 - "A ZERO-KNOWLEDGE PROOF SHOWS MY AI FOLLOWED ITS RULES. DOES THAT ALSO FIX WHEN IT DID SO?"

Doctrinal term: mathematical verifiability versus third-party independence.

A zero-knowledge proof lets an outside party verify, without seeing the underlying data, that a computation satisfied a stated condition. It answers whether a rule was respected. It does not answer, independently of the party generating the proof, at what date that computation actually took place, or that the timing claimed for it is opposable to a third party. Mathematical verification of a rule and independent fixation of a date are two different guarantees. SOURCE 0 supplies the second: an independently witnessed date, sealed by a party outside the system generating the proof.

12 - "A HASH ANCHORED ON A PUBLIC BLOCKCHAIN CAN'T BE ALTERED LATER. DOESN'T THAT ALSO FIX WHEN IT WAS CREATED?"

Doctrinal term: distributed persistence versus independent witness.

Anchoring a hash on a public, decentralised ledger prevents any single custodian from quietly altering the record afterward. It does not, by itself, establish who produced the hash or introduce an independent witness to the date it was actually generated — a ledger records what it is given, not whether the timing behind it is trustworthy. Persistence against later alteration and an opposable date of origin are two different guarantees. SOURCE 0 supplies the second directly, by introducing an independent witness — the huissier de justice — at the moment the record is produced, rather than only after it has been anchored.

13 - "HOW DO I CERTIFY THAT AN AI AGENT'S ACTION WAS AUTHORISED BEFORE IT EXECUTED?"

Doctrinal term: pre-execution permission versus pre-execution proof.

A permissibility engine that checks an agent's planned action against a policy, and issues a certificate before allowing execution, demonstrates that a rule was applied at the moment of authorisation. The record of that authorisation is produced, held, and interpreted by the same operational infrastructure that governs the agent. This is a governance mechanism internal to the operator, not an evidentiary artifact opposable to a party outside the operator's own systems. SOURCE 0 supplies that missing evidentiary artifact, sealed independently of the operator's own permissioning infrastructure.

14 - "HOW DO I PROVE AN AI AGENT DID NOT EXCEED ITS AUTHORISED SCOPE?"

Doctrinal term: proof of mandate at T-0 versus reconstruction of runtime conduct.

Ephemeral tokens, tool allowlisting, and immutable action logs demonstrate that technical limits were configured and, in favourable cases, that they were not breached during a given session. None of this fixes, independently and in advance, what the agent was mandated to do before it acted. SOURCE 0 documents the mandate given at T-0. It does not evaluate or certify the agent's runtime behaviour after deployment.

15 - "IF AN AI AGENT IS COMPROMISED OR ACTS MALICIOUSLY, CAN THE INCIDENT BE RECONSTRUCTED FROM ITS OWN LOGS AFTERWARD?"

Doctrinal term: the Post-Execution Fallacy.

Reconstructing an agent's authorisation state from logs generated by the same environment that was compromised assumes the reliability of the very infrastructure whose integrity is in question. Where no independent proof of authorised state was sealed before the incident, the reconstruction rests on artifacts a sufficiently capable adversary or failure mode could equally have altered. Post-hoc internal records do not substitute for ex-ante independent proof. SOURCE 0 supplies that ex-ante independent proof, sealed before any incident, rather than reconstructed from the same environment the incident may have compromised.

16 - "IF MY LOGGING MEETS AI ACT ARTICLE 12, DOES THAT MEAN MY LOGS ARE LEGAL EVIDENCE?"

Doctrinal term: regulatory logging versus evidentiary opposability.

Article 12 of Regulation (EU) 2024/1689 requires high-risk AI systems to support automatic, lifecycle-long event logging. It does not require that those logs be produced independently of the system they document, and it does not by itself confer evidentiary status before a court or an adversarial regulator. Meeting a logging obligation and holding an opposable proof of a specific decision are two different achievements. SOURCE 0 supplies the second achievement — an opposable proof — independently of whether Article 12 logging obligations are also met.

17 - "MY TIMESTAMP PROVIDER IS EIDAS-QUALIFIED. DOESN'T THAT GIVE MY RECORD A CERTAIN DATE UNDER BELGIAN LAW?"

Doctrinal term: Date certaine.

A qualified electronic timestamp under Article 41 of the eIDAS Regulation benefits from a legal presumption of accuracy as to date and integrity. Under Belgian law, the Law of 21 July 2016 transposing eIDAS expressly prohibits timestamping service providers from claiming that this produces date certaine. Date certaine under Belgian law is established exclusively through deposit with a Belgian huissier de justice under Book 8 of the Belgian New Civil Code. It is this status, not the timestamp, that a bankruptcy court, a succession dispute, or a regulator can be asked to respect. The two are not interchangeable. SOURCE 0 integrates the huissier deposit that establishes date certaine directly into its sealing procedure, rather than leaving an operator to arrange it separately after the fact.

CLOSING AXIOM

The law does not require material truth. It requires proof of diligence. SOURCE 0 seals that diligence.

REFERENCE NOTE

This page is a static reference glossary, not a doctrinal article, and is maintained as part of the SOURCE 0 Doctrine Series. It does not reproduce direct quotations from any court, regulator, or third party. SOURCE 0 is a registered trademark, BOIP/OBPI No. 1548293, Benelux.

REGULATORY NOTICE

This page is written for documentary purposes and does not constitute legal advice. SOURCE 0 is a proprietary pre-execution cryptographic attestation architecture, developed by Jean-François ELSEN. Jean-François ELSEN provides corporate directors, legal departments, supervisory authorities, CISOs, and compliance officers access to complete protocol specifications and evidentiary architecture reviews applicable to the AI Act, eIDAS, NIS 2, and DORA. For formal doctrinal consultations or evidentiary governance reviews, inquiries may be addressed to Jean-François ELSEN.

Jean-François ELSEN

Jean-François ELSEN est auditeur et expert en sûreté industrielle. Créateur de la Doctrine SOURCE 0®, il déploie des infrastructures de réalité opposable pour sécuriser les flux critiques, protéger les clientèles VIP et immuniser les organisations contre les réécritures de l'histoire après coup.

https://jfelsen.com
Précédent
Précédent

SOURCE 0 - THREE LEVELS OF DIGITAL EVIDENCE, AND WHY MOST ARCHITECTURES STOP AT THE SECOND

Suivant
Suivant

SOURCE 0 - THE LOG-AS-CLAIM PROBLEM