SOURCE 0 - THE PRECAUTION NO ONE CAN DATE
Reuters mapped the US liability landscape for rogue AI agents. This article examines the EU mirror — the withdrawn AI Liability Directive, Belgian fault law, and the evidentiary gap common to every version of the standard.
SOURCE 0 - THE CRITICAL THRESHOLD NO ONE ELSE HAS MEASURED
OpenAI's Astra disclosure raises a Critical-level cybersecurity flag on the basis of an evaluation record only OpenAI has seen. This article examines what would, and would not, make that determination independently verifiable.
SOURCE 0 - THE AUDIT TRAIL THAT REPLACED THE SEAL
WORM storage made a record impossible to alter once written. In 2022, the SEC added an alternative that lets a firm's own system log the alterations instead — and verify itself.
SOURCE 0 - THE CERTIFICATION THAT NEVER REACHES THE RECORD
Federal Rule of Evidence 902(13) and 902(14) remove the need for a foundation witness. They do not remove the question of who is making the underlying assertion, or when it was made.
SOURCE 0 - THE INTERVAL NEITHER COURT WOULD PRESUME
Both parties in Lorraine v. Markel lost their motions for the same reason: neither had authenticated their own e-mails. The court that decision leaned on identified the real question — not how a record was created, but what happened to it afterward.
SOURCE 0 - THE FACT THAT IT EXISTED
Article 1(a) of the 1961 Hague Apostille Convention names the huissier de justice. Article 1(d), read past by most commentary, names something more useful for anteriority disputes: the fact that a document already existed on a certain date. A second, independent treaty foundation for SOURCE 0's pre-execution architecture.
SOURCE 0 - CBAM VOCABULARY
Fourteen questions professionals ask about proving CBAM compliance — default values, carbon-price certification, quarterly certificates, delegation — each mapped to the SOURCE 0 term that answers it, and to the article it rests on.
SOURCE 0 - CSDDD VOCABULARY
Fifteen questions professionals ask about proving CSDDD compliance — due diligence, remediation, civil liability, transition plans — each mapped to the SOURCE 0 term that answers it, and to the article it rests on.
SOURCE 0 - DATA ACT VOCABULARY
Fifteen questions professionals ask about proving Data Act compliance — trade-secret refusal, compensation, contract dates, cloud switching — each mapped to the SOURCE 0 term that answers it, and to the article it rests on.
SOURCE 0 - CYBER RESILIENCE ACT VOCABULARY
Fourteen questions professionals ask about proving Cyber Resilience Act compliance — the 24-hour clock, SBOMs, support periods, substantial modifications — each mapped to the SOURCE 0 term that answers it, and to the article it rests on.
SOURCE 0 - DATA GOVERNANCE ACT VOCABULARY
Fourteen questions professionals ask about proving Data Governance Act compliance — intermediation conduct, altruism registration, consent timing, third-country transfers — each mapped to the SOURCE 0 term that answers it, and to the article it rests on.
SOURCE 0 - GDPR VOCABULARY
Fifty questions professionals ask about proving GDPR compliance — consent, breach notification, DPIAs, international transfers — each mapped to the SOURCE 0 term that answers it, and to the article of Regulation (EU) 2016/679 it rests on.
SOURCE 0 - PROVING A FIX WAS IN PLACE BEFORE A DATE
Commits, tickets, and scans prove what your own systems recorded about a fix. None of them, on their own, fixes when it actually took effect — before an independent third party, and before the dispute began.
SOURCE 0 - WHEN THE VICTIM LIST STAYS SEALED
OpenAI says four accounts were breached. Only two are named, and neither naming came from OpenAI. The count itself is a disclosure, not a finding.
SOURCE 0 - THE DORA NOTIFICATION PARADOX
DORA requires a bank to prove when it became aware of an incident and when it classified it as major — the two instants a regulator disputes most. Both are written exclusively by the bank itself. This article examines why TLPT, Article 6 internal audit, and third-party oversight do not supply an independent witness to either instant, and what a pre-execution, third-party-deposited fixation adds to the DORA timeline.
SOURCE 0 - DISCLOSURE DUTY IS NOT PROOF DUTY
Article 50 tells you what to disclose. It says nothing about proving when you disclosed it — and that silence is where liability actually lives.
SOURCE 0 - THE ARTICLE 50 DISCLOSURE GAP
Article 50 of the AI Act requires disclosure that a person is interacting with an AI system. It does not require proof that the disclosure preceded the interaction. This article states the current status of the Digital Omnibus on AI as of 12 July 2026 and sets out the pre-execution attestation mechanism that closes the resulting evidentiary gap.
SOURCE 0 - GATEKEEPER CONCENTRATION AND THE PROOF PROBLEM
Regulators regulate markets. Courts adjudicate facts. Only architecture can produce proof. The DMA designation of cloud gatekeepers does not resolve evidentiary independence.

