SOURCE 0 - CSSF CIRCULARS DO NOT FIX THE DETECTION TIME
Two CSSF circulars restructure Luxembourg's DORA incident-reporting transition. Neither requires independent verification of the detection, classification, or resolution timestamps entities self-report.
SOURCE 0 - PROVING A FIX WAS IN PLACE BEFORE A DATE
Commits, tickets, and scans prove what your own systems recorded about a fix. None of them, on their own, fixes when it actually took effect — before an independent third party, and before the dispute began.
SOURCE 0 - THE AUDIT THAT CLEARED ITSELF
Anthropic's own review of a Claude access incident is credible — and, on its own, unfalsifiable by anyone outside Anthropic. This is the Endogenous Audit Paradox in its most literal form.
SOURCE 0 - THE DEFAULT NO ONE ELSE SAW
TikTok says its teen accounts have had 50+ preset safety features "from the moment they set up an account." The Commission tested today's configuration and found it wanting. Neither account fixes what a specific default actually was at an earlier date.
SOURCE 0 - WHEN THE VICTIM LIST STAYS SEALED
OpenAI says four accounts were breached. Only two are named, and neither naming came from OpenAI. The count itself is a disclosure, not a finding.
SOURCE 0 - THE PLAN ONLY ITS AUTHOR CAN DATE
Since December 2023, French courts have substantively reviewed companies' vigilance plans — not rubber-stamped them. But every review examines whatever document the company presents today. Nothing independently fixes what the plan said before the claim was filed.
SOURCE 0 - THE STATUS GRANTED BEFORE THE PROOF
The EU's Trust and Check trader status is verified once, before the Customs Data Hub is fully operational. In the interval between the two, only the trader's own records attest to its compliance.
SOURCE 0 - THE SATELLITE NEVER SAW THE TRUCK
Under the EU Deforestation Regulation, national authorities already cross-check submitted coordinates against satellite imagery. That proves the state of the land. It does not prove that the specific batch of beans, timber, or cattle in a given shipment was ever physically on it.
SOURCE 0 - THE FOOTNOTE THAT OUTLIVED ITS REGULATION
The current EU guidance on management verifications under the Common Provisions Regulation defines its own core methodology by citing a 2015 guide written for a regulation no longer in force — without independently re-verifying that the definitions still hold. SOURCE 0 examines what a citation across an expired regulatory boundary does and does not establish.
SOURCE 0 - THE SUBSIDY NO ONE ELSE LOGGED
Two of the largest EU merger cases of 2026 turn on the same regulation: what foreign financial contributions a party received over three years. Both are answered from the same source — the recipient's own accounting.
SOURCE 0 - THE WEEK BEFORE ARTICLE 50
With days remaining before Article 50's transparency obligations take effect, the question for a DPO, CISO, or AI compliance officer is no longer what the law requires. It is what can still be independently fixed about current practice before the deadline arrives.
SOURCE 0 - THE HACK ONLY OPENAI COULD CONFIRM
Two Cornell computer scientists gave the same incident two different readings within one statement: no reason to think the details are wrong, and no way to be sure they aren't shaped by the telling. Both readings are correct, because nothing outside OpenAI's own account fixed what happened before OpenAI chose how to tell it.
SOURCE 0 - THE DEFERRAL THAT HADN'T HAPPENED YET
A postponement everyone expects is not the same as a postponement that has happened. Until the Digital Omnibus is published in the Official Journal, Articles 9 to 15 of the AI Act still apply from 2 August 2026 exactly as written.
SOURCE 0 - THE DISCLOSURE THAT ISN'T DATED
Article 9 of Directive (EU) 2024/2853 presumes a product defective if the manufacturer won't hand over technical evidence. That closes the refusal problem. It leaves untouched a narrower one: whether the evidence handed over was dated before the dispute began.
SOURCE 0 - THE ACCUSED STATE FILES THE PROOF
Regulation (EU, Euratom) 2020/2092 evaluates a Member State using courts, auditors, OLAF, GRECO — never the state's own word. One narrow provision breaks that pattern: the follow-up report on whether beneficiaries were actually paid. SOURCE 0 closes that one gap.
SOURCE 0 - THE SPACE ACT'S MISSING WITNESS
The same proposal that requires a qualified technical body to certify a satellite's environmental footprint asks nothing of the sort for its incident reports. Self-detection, self-logging, self-declaration. SOURCE 0 fixes the record before the operator writes it.
SOURCE 0 - INDEPENDENT EVALUATION IS NOT OPPOSABLE PROOF
The CeSIA-led coalition's call for mandatory independent evaluation of general-purpose AI models correctly identifies who should assess these systems. It leaves open a separate question: once produced, can the evaluation record itself survive adversarial contestation, or does it remain alterable by any party with a later interest in what it says.
SOURCE 0 - YOUR OWN AUDIT TRAIL CANNOT PROVE YOUR DILIGENCE
Article 6 of DORA requires financial entities to review and internally audit their ICT risk framework at least once a year. But the "independence" the Regulation demands is segregation within the entity, not independence from it — leaving the only record of diligence in the hands of the party whose diligence is in question.
SOURCE 0 - THE STOP BUTTON THAT WAS NEVER TIMED
Article 14 of the EU AI Act requires high-risk systems to be stoppable by human oversight — a capability obligation, never a timing proof. The 21 July 2026 OpenAI/Hugging Face containment failure, reported by Reuters, shows why that distinction has direct financial exposure under Article 99.
SOURCE 0 - THE GENERATION DATE ONLY THE GENERATOR CAN CLAIM
The Commission's Article 50 Guidelines confirm that AI-generated content produced before 2 August 2026 escapes retroactive marking — unless published afterward, when the full obligation returns. This article sets out why the generation date at the centre of that rule is a claim, not a fact, and what an independent seal would add.

