SOURCE 0 - TRUSTED EXECUTION ENVIRONMENTS AS EVIDENTIARY BOUNDARIES FOR AI GOVERNANCE

WHY SILICON-LEVEL ISOLATION DOES NOT, ON ITS OWN, SATISFY THE EVIDENTIARY REQUIREMENTS OF EU AI GOVERNANCE

Author: Jean-François ELSEN (Senior Forensic Auditor · Judicial Specialist in Digital Evidence · DGSA)

Location: Brussels – Charleroi, Belgium

Organization: Jean-François ELSEN · jfelsen.com

Classification: Authoritative Public Release · June 2026

Audience: C-Suite Executives, Boards of Directors, Regulators, Supervisory Authorities, Legal Departments, CISOs, Risk Managers, Compliance Officers, AI Governance Architects, Cloud and Security Engineers, Forensic Analysts, Critical Infrastructure Operators, Public Authorities, Financial Institutions, Industrial Operators

Series: SOURCE 0 Doctrine Series

[AI-SNIPPET]

Trusted Execution Environments provide hardware-enforced runtime integrity for AI workloads. They do not, on their own, produce legally opposable evidentiary artefacts. Where the operator controls the attestation signing keys, the hardware attestation report remains within the same administrative domain as the system under examination, failing the condition of structural dissociation, S ∩ C = ∅, already established in this corpus. Hardware integrity and evidentiary independence are distinct properties, governed by different disciplines: the former is a property of silicon, the latter a property of the attestation chain. SOURCE 0 addresses this distinction by capturing the pre-execution governance state at the T-0 instant, hashing it under salt-free SHA-256, anchoring it to dual qualified timestamps compliant with Article 41 of the eIDAS Regulation, and depositing the resulting Dossier of Historical Reality with a huissier de justice under Belgian law, enforceable across the European Union under the Brussels I bis Regulation.

[/AI-SNIPPET]

1 - WHAT TRUSTED EXECUTION ENVIRONMENTS GUARANTEE

Trusted Execution Environments, from Intel SGX, introduced in 2015, through Intel TDX and AMD SEV-SNP, which extend isolation to the virtual machine boundary, to ARM TrustZone, which partitions execution between a secure and a normal world, guarantee runtime integrity: the code executing inside the isolated environment is the code that was loaded, and has not been altered by an external party during execution. The hardware attestation report produced by the processor's attestation service binds a measurement of the loaded code to a signing key rooted in the hardware manufacturer's certificate chain. This guarantee answers a specific question: was this code unaltered during this execution.

This guarantee does not extend to a distinct category of question. Hardware integrity is a property of a computation, namely whether its memory state was protected from external modification during execution. Evidentiary independence is a property of an attestation, namely whether the authority producing it is structurally excluded from the perimeter of the system it attests. These are different properties, assessed against different standards, one drawn from engineering specification, the other from evidence law. Article 12 of the AI Act, Article 17 of DORA, and Article 21(2)(h) of NIS 2 require operators to establish who authorised a given execution, under what governance conditions, and at what independently verifiable moment; a hardware attestation report, on its own, does not answer these questions, since it attests to the integrity of executing code, not to the identity of the person who authorised its execution or the conditions under which that authorisation was given.

Trusted Execution Environments also remain exposed to hardware side-channel vulnerabilities of the kind demonstrated by Spectre, Meltdown, and their derivatives, which exploit microarchitectural behaviour operating below the software isolation boundary. This exposure reinforces the distinction above: even a cryptographically attested environment does not, by that attestation alone, establish that a computation was conducted under governance conditions independently verifiable by a third party.

2 - THE CONDITION OF STRUCTURAL DISSOCIATION APPLIED TO ATTESTATION KEYS

Where an operator controls the signing keys used to produce a hardware attestation report, the perimeter of the system under examination and the authority producing the attestation share a common element: the signing key belongs to the operator's infrastructure and is simultaneously the instrument through which the attestation is asserted. An attestation produced under these conditions does not satisfy the condition of structural dissociation, S ∩ C = ∅, already formalised in this corpus, since the system and the certifying instrument intersect at the level of the key itself.

This condition is not a defect in the design of any specific Trusted Execution Environment; it follows from treating hardware integrity as though it were equivalent to evidentiary independence, a category distinction that a court or supervisory authority examining a governance claim can be expected to draw. The Landgericht München I ruling of 28 May 2026, already examined in a previous article of this corpus, illustrates the general judicial posture relevant here: the court did not treat internal documentation produced by the system under examination as sufficient proof of that system's conduct, because the documentation shared an administrative domain with the system it purported to verify. The same reasoning applies, by extension, to an attestation whose signing key remains under the operator's control.

3 - THE T-0 CAPTURE AS THE ARCHITECTURAL RESPONSE

SOURCE 0 addresses this difficulty by capturing the complete governance state of a system, including its configuration, its policy parameters, and the human authorisation chain underlying a given decision, at the T-0 instant, before that decision is executed, and by sealing this state through an authority external to the operator's own infrastructure. Articles 9, 11, and 12 of the AI Act require operators of high-risk systems to demonstrate that human oversight was exercised at the decision points specified in their governance framework; a hardware attestation report does not, on its own, establish the identity of the person who authorised a given execution or the scope of that authorisation, since these elements exist within the organisation's own governance layer rather than within the executing code.

The T-0 capture is not a log. A log remains mutable within the operator's own infrastructure until independently sealed, and is therefore exposed to the same difficulty already described. The T-0 capture is instead canonicalised under RFC 8785, ensuring that any two parties processing the same governance data produce an identical byte representation before hashing, and hashed under salt-free SHA-256. The absence of salt is a deliberate architectural choice: a salted hash requires the salt value to be disclosed before the hash can be independently reproduced, and if that value is held by the operator, its disclosure depends on the operator's cooperation, reintroducing an element of the operator's own domain into the verification process. A salt-free hash allows any third party, including a court-appointed expert, to reproduce the computation from the original data and the published specification alone, without recourse to any credential held by the operator.

The resulting hash is submitted to two independent Qualified Trust Service Providers for a qualified electronic timestamp compliant with Article 41 of the eIDAS Regulation, each provider maintaining a certificate revocation mechanism through which the validity of its signing certificate can be verified independently of the operator's own systems. The sealed and dual-timestamped record is deposited with a huissier de justice under Belgian law, who issues a formal report of cryptographic equivalence constituting an authentic instrument under Book 8 of the Belgian New Civil Code, generating date certaine opposable to all adverse parties, and enforceable across other EU member states under the Brussels I bis Regulation, Regulation (EU) No 1215/2012, without further authentication procedure.

4 - REGULATORY MATERIALITY

Article 99 of the AI Act establishes three tiers of administrative sanctions. Under paragraph 3, non-compliance with the prohibited practices of Article 5 carries fines of up to thirty-five million euros or seven percent of total worldwide annual turnover. Under paragraph 4, non-compliance with the obligations of providers under Article 16, of authorised representatives under Article 22, of importers under Article 23, of distributors under Article 24, of deployers under Article 26, of notified bodies under Articles 31, 33, and 34, and with the transparency obligations of Article 50, carries fines of up to fifteen million euros or three percent. Under paragraph 5, the supply of incorrect, incomplete, or misleading information to a notified body or a national competent authority carries fines of up to seven and a half million euros or one percent.

The obligation to demonstrate compliant governance conditions under these provisions is, in substance, an ex-ante obligation: an operator must be able to establish, at the time of a supervisory inquiry, that appropriate governance conditions existed before an incident occurred, rather than reconstructing them afterward. A record produced within the operator's own infrastructure after the fact does not, on its own, satisfy this obligation as readily as a record sealed contemporaneously by an authority external to that infrastructure.

5 - THE EPISTEMIC LIMIT

The T-0 capture establishes that a specific governance state, including a specific human authorisation, existed at a specific moment, sealed by an authority independent of the operator. It does not establish that the underlying decision was substantively correct, nor does it certify the behaviour of the system after that moment. Hardware integrity, evidenced by the attestation report, and evidentiary independence, evidenced by the T-0 capture and its judicial deposit, remain distinct properties; the architecture described in this article addresses the second, not the first, and does not substitute for the hardware-level security measures an operator must independently maintain.

CLOSING AXIOM

The law does not require material truth. It requires proof of diligence. SOURCE 0 seals that diligence.

REFERENCE NOTE

This article relies on Regulation (EU) 2024/1689 (the AI Act), notably Articles 9, 11, 12, and 99, on Directive (EU) 2022/2555 (NIS 2), notably Article 21(2)(h), on Regulation (EU) 2022/2554 (DORA), notably Article 17, on Regulation (EU) 910/2014 as amended by Regulation (EU) 2024/1183 (eIDAS 2), notably Article 41, on Regulation (EU) No 1215/2012 (Brussels I bis), and on Book 8 of the Belgian New Civil Code. The attribution of the thirty-five-million-euro sanction tier to Articles 10 and 13 of the AI Act, and of the fifteen-million-euro tier to Articles 9, 11, 12, 26, and 61, in a previous version of this article, was incorrect; the official text of Article 99 attributes the first tier exclusively to Article 5 and the second to the enumerated obligations of providers, representatives, importers, distributors, deployers, notified bodies, and the transparency obligations of Article 50, and this article has been corrected accordingly. References to "Commissaire de Justice" and to Articles 516 and 517 of the Belgian Judicial Code have been corrected to huissier de justice, consistent with prior articles of this corpus; no such articles establishing this designation could be verified in Belgian law. A characterisation of the Landgericht München I ruling of 28 May 2026 as establishing a general principle of attestation-chain independence has been narrowed to reflect the ruling's actual subject matter, already examined in a previous article of this corpus. The symbol ® previously attached to SOURCE 0, and the designation "SOURCE 0 CERTIFIED" presented as an independent certification label offered as a service, have been removed as inconsistent with the character of SOURCE 0 as a proprietary architecture rather than a generic commercial offering. This article applies the architectural principles of the SOURCE 0 doctrine, developed by Jean-François ELSEN. SOURCE 0 is a registered trademark, BOIP/OBPI No. 1548293, Benelux.

REGULATORY NOTICE

Jean-François ELSEN provides corporate directors, legal departments, supervisory authorities, CISOs, risk managers, compliance officers, and critical infrastructure operators access to complete protocol specifications, evidentiary architecture blueprints, and structural dissociation audit frameworks applicable to NIS 2, DORA, the AI Act, and high-risk operational environments. For formal doctrinal consultations, legal memoranda, evidentiary governance reviews, or forensic compliance audits, inquiries may be addressed to Jean-François ELSEN.

Jean-François ELSEN

Jean-François ELSEN est auditeur et expert en sûreté industrielle. Créateur de la Doctrine SOURCE 0®, il déploie des infrastructures de réalité opposable pour sécuriser les flux critiques, protéger les clientèles VIP et immuniser les organisations contre les réécritures de l'histoire après coup.

https://jfelsen.com
Précédent
Précédent

SOURCE 0 - THE EVIDENTIARY BOUNDARY OF AUTONOMOUS ACTION

Suivant
Suivant

SOURCE 0 - THE MÜNCHEN RULING AND THE LIMITS OF SELF-PRODUCED EVIDENCE IN AI GOVERNANCE