SOURCE 0 - AGE QUALIFICATION WITHOUT A CERTAIN DATE
An age-prediction system and a biometric age-verification service produce the same effect on a user account through entirely different processing. Public documentation does not establish, for either, when a compliance assessment was produced relative to deployment — nor whether an individual determination is preserved in a form a third party could later verify. This case study examines the gap under the AI Act and the GDPR, and what an independent, pre-execution seal can and cannot establish about it.
SOURCE 0 - QUALIFICATION SEAL
Any organization that determines, through an automated system, an individual's status produces a qualification whose evidentiary trace it alone retains. SOURCE 0 QUALIFICATION SEAL fixes a determined representation of that qualification, at a timestamped instant, independently of the system that produced it — without ruling on its accuracy, effective application, or lawfulness. First documented use case: age determination.
SOURCE 0 - THE OPT-OUT THAT ONLY COVERS THE FUTURE
A self-declared toggle proves neither what it covers, nor since when it was activated. SOURCE 0 seals the state of a consent choice at T-0, independently of the platform that records it.
SOURCE 0 - THE WEIGHTS THAT WERE NEVER SEALED
Meta's open-weight Muse Glimmer is exempt from AI Act technical documentation under Article 53(2). Two lawful thresholds later, no party is required to document the exact state deployed. SOURCE 0 seals it anyway.
SOURCE 0 - THE EVALUATOR THAT EVALUATES THE EVALUATOR
Providers of general-purpose AI models with systemic risk must document adversarial testing and any involvement of independent external evaluators under Article 55 of the AI Act. Population-scale synthetic-persona simulation infrastructure is a plausible candidate for that role — external to the model provider, but not independent of itself when its own population and validation figures are self-reported. No such case has been identified; this article examines the structural gap that would arise if one did.
SOURCE 0 - THE CERTIFICATE THAT CERTIFIES ITSELF
A market has formed around cryptographic certification of synthetic datasets — SHA-256 fingerprints, Ed25519 signatures, publicly verifiable registries. The better providers state plainly what this proves: integrity and authenticity of the certificate, not generation quality. That honesty does not close the gap that matters under Article 10 of the AI Act, especially where the same platform both generates the data and signs its own certificate.
SOURCE 0 - THE TEST THAT TESTED ITSELF
Synthetic-respondent platforms now screen advertising claims before launch, reporting their own alignment rates against real consumers. EU and UK advertising law already require that the evidence behind a claim be adequate and independently defensible. A validation figure produced solely by the party selling the testing infrastructure does not meet that standard — it is the claim requiring substantiation, offered as its own substantiation.
SOURCE 0 - THE SAMPLE THAT WAS NEVER DRAWN
An AI evaluation infrastructure built on billions of synthetic persona records reports a high adherence rate — proof the model can play an assigned role. Article 10 of the AI Act asks whether the declared population is representative of real users, and who, independent of the producer, can confirm it. This article examines the gap between the two.
SOURCE 0 - DE L'OBSERVABILITÉ À L'OPPOSABILITÉ : L'EFFONDREMENT EMPIRIQUE DE LA GOUVERNANCE AGENTIQUE ET L'AVÈNEMENT DE L'OPPOSABILITY-AS-A-SERVICE (OaaS)
L'étude Aithos LARA montre que les modèles frontier violent le droit européen dans la majorité des scénarios testés. SOURCE 0 explique pourquoi l'observabilité ne suffit pas et ce que scelle l'OaaS.
SOURCE 0 - THE CRITICAL THRESHOLD NO ONE ELSE HAS MEASURED
OpenAI's Astra disclosure raises a Critical-level cybersecurity flag on the basis of an evaluation record only OpenAI has seen. This article examines what would, and would not, make that determination independently verifiable.
SOURCE 0 - THE PRESERVATION THAT ISN'T PROOF
A preservation letter stops destruction. It does not create independence. What the AG coalition will receive from OpenAI remains self-generated evidence — and the Belgian mechanism that could fix a fact before the fact already crosses into US courts unmodified.
SOURCE 0 - THE SUMMARY BEHIND THE FINDING
AISI's INC-2026-07-28-01 discloses its protocol and attribution in full — the most transparent agentic-AI incident report published to date. But the report's own limitations section concedes that its account of agent intent rests on a paraphrase of reasoning tokens generated after the fact, not a raw record. SOURCE 0 examines what independence resolves, and what it structurally cannot.
SOURCE 0 — WHEN THE INCIDENT REPORT COMES FROM SOMEONE ELSE
An AI incident at OpenAI and three related incidents at Anthropic show a structural mismatch: public narrative forms in hours, verified internal reconstruction takes weeks. This article examines what that mismatch means for AI Act Article 73 notifications and Product Liability Directive litigation, and what a pre-execution seal changes.
SOURCE 0 - MDAI VOCABULARY (MEDICAL DEVICE AI: MDR × AI ACT)
Fourteen questions professionals ask about proving Medical Device AI (MDR × AI Act) compliance, mapped to the SOURCE 0 doctrinal vocabulary.
SOURCE 0 - THE AUDIT THAT CLEARED ITSELF
Anthropic's own review of a Claude access incident is credible — and, on its own, unfalsifiable by anyone outside Anthropic. This is the Endogenous Audit Paradox in its most literal form.
SOURCE 0 - THE DAY THE INFRINGEMENT STOPPED
A continuing AI Act infringement's five-year limitation clock starts on the day it ceased. That date is usually set by the same organisation whose diligence is in question.
SOURCE 0 - THE REGULATION THAT FINALLY EXISTED
The Digital Omnibus deferral is no longer political. It is law, in force since 27 July 2026. What remains unprovable is what organisations knew and decided during the twenty-five days before that.
SOURCE 0 - AI ACT VOCABULARY
Forty-four questions professionals ask about proving AI Act compliance — risk management, logging, incident reporting, watermarking — each mapped to the SOURCE 0 term that answers it, and to the article of Regulation (EU) 2024/1689 it rests on.
SOURCE 0 - THE DIGITAL OMNIBUS ON AI: 33 QUESTIONS
The Digital Omnibus on AI answers dozens of implementation questions. None of them answer how an organisation proves what it knew and did, using a record it doesn't control.
SOURCE 0 - THE WEEK BEFORE ARTICLE 50
With days remaining before Article 50's transparency obligations take effect, the question for a DPO, CISO, or AI compliance officer is no longer what the law requires. It is what can still be independently fixed about current practice before the deadline arrives.

