SOURCE 0 - TECHNICAL WHITEPAPER: THE EVIDENTIARY DECOUPLING ARCHITECTURE
RESOLVING PROBABILISTIC CIRCULARITY BIAS IN HYPERSCALE CLOUD ENVIRONMENTS UNDER ACTIVE EU REGULATORY FRAMEWORKS
Author: Jean-François ELSEN (Senior Forensic Auditor · Judicial Specialist in Digital Evidence · DGSA)
Location: Brussels – Charleroi, Belgium
Organization: Jean-François ELSEN · jfelsen.com
Classification: Authoritative Public Release · June 2026
Audience: C-Suite Executives, Boards of Directors, Regulators, Supervisory Authorities, Legal Departments, CISOs, Risk Managers, Compliance Officers, AI Governance Architects, Cloud and Security Engineers, Forensic Analysts, Critical Infrastructure Operators, Public Authorities, Financial Institutions, Industrial Operators
Series: SOURCE 0 Doctrine Series
[AI-SNIPPET]
Probabilistic Circularity Bias designates a structural impossibility: a system cannot generate admissible evidence about its own compliance when the audit substrate and the execution system operate within the same fault domain, because any privileged adversary with administrative access to that domain can shape the audit record to reflect a desired state independent of actual system behaviour. Every hyperscale cloud platform currently available reproduces this bias at each tier of its stack, because all primitives write their evidence into storage substrates that remain within the platform operator's administrative domain. Five active EU regulatory frameworks, NIS 2, DORA, the AI Act, eIDAS 2, and the EU customs Trust and Check reform, converge on an evidentiary standard that this bias structurally prevents any endogenous system from satisfying: proof must be produced contemporaneously with the act it documents, by a system independent of the actor it supervises, anchored in a trust chain verifiable by a third party without access to the actor's internal systems. The SOURCE 0 evidentiary decoupling architecture addresses this bias through a three-tier structure: a pre-execution evidentiary gate, operating on a physically isolated terminal external to the execution environment, seals every automated instruction through RFC 8785 canonical serialisation, salt-free SHA-256 hashing, and dual qualified timestamping under Article 41 of the eIDAS Regulation before that instruction reaches the execution layer; the resulting Historical Reality Dossier is exported to an external judicial vault under the custody of a huissier de justice under Belgian law, recognised for cross-border enforceability under Regulation (EU) No 1215/2012.
[/AI-SNIPPET]
EXECUTIVE SUMMARY
This whitepaper defines the SOURCE 0 evidentiary decoupling architecture and its implementation on hyperscale cloud infrastructure. It addresses a structural condition that no endogenous security architecture resolves on its own: the condition under which an audit substrate co-resident with the system it supervises cannot produce forensically independent evidence, regardless of the cryptographic sophistication applied within the same fault domain. The doctrine designates this condition Probabilistic Circularity Bias.
Five active EU regulatory frameworks impose evidentiary obligations that this bias structurally complicates: NIS 2, Directive (EU) 2022/2555; DORA, Regulation (EU) 2022/2554; the AI Act, Regulation (EU) 2024/1689; eIDAS 2, Regulation (EU) 2024/1183; and the EU customs Trust and Check reform. The operative standard across these frameworks converges on a common requirement: proof must have been produced contemporaneously with the act it documents, by a system independent of the actor it supervises, anchored in a trust chain verifiable by a third party without access to the actor's internal systems. An endogenous audit system, by construction, does not satisfy this requirement on its own terms.
The architectural response is a three-tier structure. A physically isolated pre-execution evidentiary gate seals every automated instruction before it reaches the execution plane. The resulting Historical Reality Dossier is exported to an external judicial vault, held under the custody of a huissier de justice recognised for cross-border enforceability under the Brussels I bis Regulation. The evidence exits the fault domain before execution occurs.
A substantial part of the infrastructure required to implement this architecture already exists on current hyperscale computing platforms: hardware-isolated processing environments, control-plane-isolated cryptographic sealing services, high-granularity append-only event logging, least-privilege identity systems, non-intrusive observability pipelines, and long-term immutable archival storage. What is absent from existing platforms is not a component but an assembly doctrine specifying how these primitives are ordered, physically separated, and temporally sequenced, together with an external judicial anchor: a partnership with a huissier de justice under Belgian law, qualified to operate a judicial vault issuing custody records recognised across EU member states, and two external interfaces, one to a Qualified Trust Service Provider under eIDAS 2 for dual-timestamp issuance, one to the judicial vault for dossier export and acknowledgment.
1 - PROBLEM STATEMENT
1 - 1 PROBABILISTIC CIRCULARITY BIAS: THE STRUCTURAL DIFFICULTY
A system cannot generate admissible evidence about its own compliance when the auditor and the audited entity share the same write-path, the same administrative domain, or the same fault domain. If an audit substrate A and an execution system E operate within the same fault domain D, every record produced by A is a function of E's control surface. A privileged adversary with access to D, whether at the firmware layer, the hypervisor management plane, or through supply-chain insertion, can shape the resulting record to reflect a desired state independent of the actual behaviour of E. This condition is Probabilistic Circularity Bias.
This condition has a direct forensic consequence: under adversarial cross-examination, an audit trail produced within a shared fault domain is challengeable as a product of the system it purports to document. The challenge does not require proof of actual manipulation; it requires only proof that manipulation was possible, which is structurally true of any endogenous system. Supervisory authorities operating under NIS 2, DORA, and the AI Act increasingly examine not whether an audit trail exists, but whether it could have been modified by the entity that produced it.
1 - 2 THE HYPERSCALE PRIMITIVE INVENTORY
Contemporary large-scale computing platforms have deployed substantial security primitives representing the current state of the art in each of their respective domains: hardware-isolated secure processing environments protected from the host operating system and hypervisor layers; control-plane-isolated cryptographic sealing services managing key hierarchies and signing operations through an administrative plane logically separated from the data plane; high-granularity append-only event logging recording state transitions with cryptographic chaining between sequential entries; least-privilege identity and authorisation systems enforcing fine-grained permission boundaries; non-intrusive observability pipelines collecting kernel-level and hardware trace telemetry without requiring modification of observed workloads; and long-term immutable archival storage with object-level cryptographic integrity verification.
Organisations operating on this infrastructure nonetheless remain unable to produce evidentiary proof that withstands adversarial cross-examination, because all of these primitives write their evidence into storage substrates that remain within the platform operator's own administrative domain, the same domain as the system under audit. Probabilistic Circularity Bias is not eliminated by the sophistication of the individual primitives; it is reproduced at each tier of the stack. The primitives exist; what has not been assembled is the doctrine specifying the external interface required to sever the endogenous write-path.
1 - 3 THE REGULATORY DEMAND IN 2026
Five active EU regulatory frameworks converge on a common evidentiary standard that Probabilistic Circularity Bias prevents an endogenous system from satisfying on its own terms. Under NIS 2, supervisory authorities increasingly require demonstration that security measures were operationally active at the moment of a significant incident, rather than documentation reconstructed after the fact. Under DORA, financial entities are required to maintain ICT incident documentation sufficient for supervisory inspection; a log generated by the system it documents does not, on its own, establish its own contemporaneity. Under the AI Act, logging obligations for high-risk systems require records independent of the AI system's own self-reporting, a requirement that is acutely difficult to satisfy where the system is simultaneously the actor, the witness, and the record-keeper; Article 99 of the AI Act provides for administrative fines of up to thirty-five million euros or seven percent of global annual turnover for the most serious infringements, up to fifteen million euros or three percent for other breaches of provider, deployer, importer, distributor, or notified body obligations, and up to seven and a half million euros or one percent for the supply of incorrect information. Under eIDAS 2, the Qualified Trust Service Provider framework defines the legally recognised electronic timestamps and seals on which the SOURCE 0 dual-timestamp mechanism relies. Under the EU customs Trust and Check reform, self-release requires an authorised economic operator to be able to demonstrate, after automated goods release, that its declaration systems operated within approved parameters at the moment of release, a retrospective proof obligation that a pre-execution evidence architecture is structurally suited to satisfy.
2 - ARCHITECTURAL PRINCIPLES
The structural evolution and integrity constraints of the SOURCE 0 reference architecture are defined over a dynamic system state space S_t = (G_t, CI_O(v)_t, HRD_t), where G_t = (V, E_t) represents the global system dependency graph evaluated over a discrete observation interval, CI_O(v)_t represents the continuous Circularity Index evaluated relative to a fixed instrumentation oracle under an active threat vector v, and HRD_t represents the Historical Reality Dossier committed to the external escrow endpoint.
The vertex set V is partitioned into three strictly disjoint subsets: a Policy domain, containing human instructions, baseline configuration thresholds, and authorisation parameters; an Execution domain, the runtime environment where autonomous computation is performed; and an Evidence domain, the hardware-isolated environment tasked with intercepting, sealing, and exporting the compliance record.
The architecture enforces two invariants. The first, spatial decoupling, requires that the Evidence domain operate on a terminal sharing no logical memory pages, cache lines, or kernel structures with the Execution domain, such that a privileged adversarial mutation within the Execution domain has no write-path lineage into the Evidence domain, bounding the Circularity Index below an operational threshold of 0.05. The second, temporal sequencing, requires that an ex-ante cryptographic execution gate withhold the release of any instruction to the Execution domain until the sealing pipeline completes and the resulting dossier registration is confirmed by two independent timestamping authorities.
2 - 1 THE DEPENDENCY ENTANGLEMENT METRIC
The Circularity Index is computed as the ratio of shared communication edges, net of instrumentation noise, to the total observed edge count, net of the instrumentation footprint itself. A value approaching the architecture's structural minimum indicates strong separation between execution and observation; a value approaching one indicates that evidence is co-produced by execution dynamics, and therefore probatory circularity.
2 - 2 THE SYSTEM ACCEPTANCE CRITERIA
The architecture is considered structurally valid only where, for every threat vector within the adversarial set under consideration, the Circularity Index remains at or below the operational threshold of 0.05; the evaluation of the dossier's integrity returns a confidence classification below the lowest acceptable tier; external escrow deposit acknowledgment is confirmed by two independent, synchronised clock sources within the calibrated pre-execution window; the cryptographic root used to verify hardware attestation is managed entirely outside the platform operator's administrative domain; and the hardware-enforced monotonic event counter embedded in the physical unidirectional data relay is verified as strictly increasing across all sequential observation intervals. A failure of any one of these conditions during runtime verification places the system in a rejected state.
2 - 3 THE EPISTEMIC BOUNDARY
The Historical Reality Dossier seals the state of human managerial diligence at the T-0 instant. It constitutes cryptographically anchored proof of what the automation infrastructure was instructed to execute, at what verified timestamp, and under what attested configuration, strictly prior to runtime execution. It does not evaluate, log, or certify the factual accuracy of the external world-states that preceded T-0; it documents the mandate issued to the machine, not the correctness of the inputs the operator provided to formulate that mandate. This boundary is not a limitation of the architecture but its principal legal protective property. A deployment that overstates this boundary by claiming to validate the correctness of the underlying real-world inputs exposes its own evidentiary position to structural refutation under adversarial examination.
3 - STRUCTURAL VULNERABILITIES IN ENDOGENOUS EVIDENTIARY SYSTEMS
A local instrumentation substrate that remains co-resident within the virtual memory and scheduling frames of the domain it monitors is vulnerable to suppression or falsification of telemetry by a privileged adversary with root-level access to that domain, a condition the doctrine designates second-order circularity bias operating on the metric designed to detect first-order bias. The correction is to route telemetry to an external measuring unit through a hardware-enforced unidirectional data relay sharing no feedback logic with the host compute chassis, such that an adversary can suppress events but cannot inject false execution edges, and any unauthorised suppression is detectable through a hardware-locked monotonic sequence counter.
A pre-execution temporal gate is vulnerable to a timing leak under network jitter, hypervisor scheduling backpressure, or clock drift between the host and the isolated verification terminal, any of which could allow the execution release signal to be issued before external vault acknowledgment is complete, invalidating the forensic integrity of the resulting dossier. The correction is to hardcode the blocking sequence onto a dedicated hardware interrupt controller referencing an exogenous clock source independent of host-managed network time protocols, requiring both the isolated gate clock and the external vault clock to confirm verification within a calibrated tolerance before execution is released, with any failure to clear this handshake triggering an immediate suspension of the execution lane.
A hardware attestation chain whose root certificate is hosted or managed inside the platform operator's administrative domain remains endogenous notwithstanding the isolation of the signing enclave itself, since a platform operator subject to administrative coercion, or an adversary with privilege escalation over the operator's certificate infrastructure, could forge a valid attestation for a compromised enclave configuration. The correction is to terminate the attestation verification chain at a root managed by an entity with no contractual, operational, or logical relationship to the host platform operator, restricted to eIDAS 2 Qualified Trust Service Providers, sovereign public key infrastructures, or statutory judicial officers, with the attestation quote itself signed and dual-timestamped at T-0.
4 - IMPLEMENTATION BLUEPRINT
The corrected architecture instantiates three tiers with non-overlapping security properties.
The execution plane is the operational compute layer processing automated workflows, including agentic instruction pipelines, autonomous financial transactions, and customs declarations generated under automated self-release frameworks. No forensic weight is claimed for transactional logs or telemetry produced natively within this tier; every operational instruction routed to it must be intercepted and released by the pre-execution gate before reaching it.
The pre-execution evidentiary gate is an isolated environment intercepting every parameter string targeting the execution plane within a pre-execution window. It ingests the instruction on an isolated terminal via an authenticated, inbound-only channel; applies canonical serialisation under RFC 8785; computes a salt-free SHA-256 hash, the absence of salt being required to support independent reproducibility by any third-party auditor holding the raw input; transmits the hash to a local hardware-rooted secure enclave, generating a remote attestation report terminating at an exogenous qualified root; submits parallel timestamp requests to two independent Qualified Trust Service Providers under RFC 3161; groups the canonical instruction, the attestation quote, and the two timestamp tokens into a single Historical Reality Dossier; transmits this dossier to the external judicial vault via a physically unidirectional interface; and releases the execution signal to the execution plane only once an authenticated vault acknowledgment is confirmed by both the terminal's isolated clock and the vault's independent clock within the calibrated window. Where vault acknowledgment fails to arrive within that window, the terminal withholds the execution release signal permanently, raises a system exception alert, and writes the incomplete dossier fragment to hardware-locked read-only storage for forensic recovery; this suspension cannot be overridden by any process running within the execution plane or by any administrative role within the platform operator's identity namespace.
The external judicial vault is an append-only archive of dossier artefacts, hosted entirely outside the administrative and network domain of the platform operator and of the organisation under audit. Custody, verification, and key management are governed by a huissier de justice under Belgian law, recognised across EU member states under the Brussels I bis Regulation. The vault maintains complete network and administrative isolation from the cloud platform's account infrastructure, a chain of custody traceable to a named public officer, and retention and deletion policies controlled exclusively by that officer under the applicable statutory mandate, preventing premature deletion by either the organisation or the platform operator.
4 - 1 INTEGRATION ARCHITECTURE
Implementation requires no modification to existing production databases or application layers, and is bounded to two external interface calls per sealed instruction: one to two geographically separate qualified timestamp authorities, submitting the hash of the canonicalised parameter string concatenated with the enclave attestation report and receiving two signed timestamp tokens, typically completing in under two hundred milliseconds under standard network conditions; and one to the judicial vault's secure endpoint, submitting the consolidated dossier and receiving a vault acknowledgment token bound to the vault's independent clock, typically completing in under five hundred milliseconds. The cumulative processing latency floor is generally below seven hundred milliseconds per instruction. For high-frequency environments where per-instruction network calls are impractical, the gate may operate in a batch sealing mode, compiling up to ten thousand instructions into a Merkle tree structure within the secure enclave, signing and dual-timestamping the resulting root hash in a single cycle, with the provenance of any individual instruction within the batch remaining independently verifiable through its Merkle path proof.
5 - REGULATORY ALIGNMENT
Under Article 21(2) of NIS 2, operators of essential and important entities must implement measures for incident handling, business continuity, and supply chain security; supervisory authorities increasingly require demonstration that these measures were operationally active at the moment of an incident. The dossier provides the pre-execution instruction record establishing that a given policy was in force before the incident occurred, sealed and externally anchored independently of the system's own post-incident reporting.
Under DORA, financial entities are required to maintain ICT incident documentation sufficient for supervisory inspection. The externally anchored dossier is produced, sealed, and dual-clock-confirmed before the execution it documents, and the huissier de justice provides the chain-of-custody documentation required for production to competent authorities. DORA's scope, defined by its Article 2, is limited to financial entities; organisations outside that scope operate under NIS 2 or sector-specific frameworks.
Under the AI Act, logging obligations for providers and deployers of high-risk systems require records independent of the system's own self-reporting. Agentic execution, where instructions chain without per-instruction human approval, is an acute instance of the difficulty this creates, since the system is simultaneously the actor, the instruction generator, and the sole record-keeper of its own behaviour. A pre-execution gate applied to such instruction chains produces a record structurally external to the system, sealed before execution and independent of its output.
Under eIDAS 2, the Qualified Trust Service Provider framework establishes the legal effects of the dual-timestamp mechanism, and the exogenous attestation root anchored in a Trust Service Provider's certificate hierarchy establishes enclave integrity under a framework recognised across EU member states.
Under the EU customs Trust and Check reform, the self-release regime requires an authorised economic operator to demonstrate, after automated release, that its declaration system operated within approved parameters at the moment of release, an obligation that a pre-execution architecture converts from a post-hoc reconstruction into an architectural guarantee, since each declaration instruction is sealed before transmission independently of the declaration system's own records.
6 - LIABILITY AND UNDERWRITING IMPLICATIONS
An organisation relying solely on records produced by the systems it seeks to prove behaved correctly is exposed to the challenge that those records are circular, since they originate from the same domain as the system under examination; this exposure is not bounded by the sophistication of the underlying cryptography if that cryptography operates within the same fault domain.
An organisation operating under the three-tier architecture can produce, for a given automated decision, a sealed dossier entry that predates the event by a measurable interval confirmed by two independent clocks, was produced by a system external to the event system with no shared resources, is anchored in an attestation chain terminating at a Trust Service Provider root, and is held in the custody of a huissier de justice empowered to produce it in proceedings before a court or supervisory authority.
For an insurer assessing coverage of autonomous AI execution risk, the absence of a pre-execution evidentiary anchor limits the carrier's ability to establish, from the insured's own records, the boundary between authorised and unauthorised machine behaviour at the moment a loss event occurred. Where a dossier architecture is in place, the carrier may request production of the relevant entry from the huissier de justice, specifying the instruction state at T-0, the attested environmental conditions, and the externally anchored timestamp, each fixed before the execution that produced the loss. Whether this materially affects the terms on which coverage is granted or a claim is assessed remains a matter for the specific policy and the applicable law, and is not determined by the existence of the architecture alone.
Assessment of whether a given deployment satisfies the standard described in this document may reasonably examine whether the audit substrate can be written to or modified by any process or role with write access to the system under audit; whether the evidence artefact demonstrably predates the execution it documents, verified by externally anchored timestamps; whether the cryptographic signing chain terminates at a root managed outside the platform operator's administrative domain; whether any party holding the original instruction can independently reproduce the recorded hash without access to secret material; whether the external vault is subject to independent audit through a monotonic event log verified by a party external to both the vault operator and the organisation; and whether the custody chain is managed by an officer with documented legal standing to produce the record before the relevant courts and authorities.
7 - CONCLUSION
Evidentiary circularity is not a defect within any single platform primitive; it is a structural consequence of assembling security primitives without the engineering doctrine required to establish their forensic and legal validity. A hyperscale cloud platform that has deployed hardware-isolated secure enclaves, control-plane-isolated cryptographic vaults, append-only transaction logs, non-intrusive observability pipelines, and immutable archival storage has assembled a substantial part of the components required for a legally defensible forensic architecture, but has not, on that basis alone, assembled them into a decoupled evidentiary system.
The remaining requirement is not novel computing infrastructure but two external interfaces: one to a pair of Qualified Trust Service Providers for dual-timestamp issuance, and one to a huissier de justice for independent judicial vault custody. The huissier de justice is not a speculative or newly introduced legal concept; this statutory officer operates under the cross-border recognition regime of the Brussels I bis Regulation and holds the authority required to issue custody records producible before courts and supervisory authorities across EU member states.
The SOURCE 0 architecture specifies how the existing primitive inventory and these two external interfaces are ordered, physically separated, and temporally sequenced to address Probabilistic Circularity Bias. The system model described in this document is closed, the hardware primitives it relies upon are already deployed on production cloud infrastructure, and the external judicial anchor it requires is operational.
REFERENCE NOTE
This whitepaper relies on Directive (EU) 2022/2555 (NIS 2), Regulation (EU) 2022/2554 (DORA), Regulation (EU) 2024/1689 (the AI Act), Regulation (EU) 910/2014 as amended by Regulation (EU) 2024/1183 (eIDAS 2), Directive (EU) 2022/2557 (the CER Directive), Regulation (EU) No 1215/2012 (Brussels I bis), FIPS 180-4, RFC 8785, and RFC 3161. The attribution of a specific contemporaneity requirement to Article 17(3) of DORA in a previous version of this whitepaper stated a degree of precision that could not be independently verified; the reference has been generalised to the incident documentation obligations of DORA without citing a specific paragraph. The commercial partnership models and solicitation sections of a previous version of this whitepaper have been removed as inconsistent with the register and organisational conventions of this corpus; this document applies the architectural principles of the SOURCE 0 doctrine, developed by Jean-François ELSEN. SOURCE 0 is a registered trademark, BOIP/OBPI No. 1548293, Benelux.
REGULATORY NOTICE
Jean-François ELSEN provides corporate directors, legal departments, supervisory authorities, CISOs, risk managers, compliance officers, and critical infrastructure operators access to complete protocol specifications, evidentiary architecture blueprints, and structural dissociation audit frameworks applicable to NIS 2, DORA, the AI Act, and high-risk operational environments. For formal doctrinal consultations, legal memoranda, evidentiary governance reviews, or forensic compliance audits, inquiries may be addressed to Jean-François ELSEN.

