SOURCE 0 - THE CHECK THAT LEFT NO RECORD
Georgia's Supreme Court sanctioned a prosecutor for fabricated AI citations and vacated a trial court order tainted by the same errors — then made clear a policy against it isn't proof it was followed. SOURCE 0 examines the gap.
SOURCE 0 - THE SECOND GLANCE NO ONE CAN VERIFY
Background-agent architectures promise to fix low AI adoption by moving humans to occasional review. That review becomes the sole surviving record of human diligence — and nothing currently proves it happened.
SOURCE 0 - THE NEXT ITSME IS A PROOF LAYER, NOT AN APP
Geert Van Mol's call for sector-wide ambition on phishing echoes what itsme achieved for authentication. SOURCE 0 examines the layer itsme was never built to cover — proving what was actually instructed, not just who was logged in.
SOURCE 0 - THE AUTHORIZATION ONLY ONE PARTY CAN SHOW
Amazon v. Perplexity turned on who "accesses" a platform through an AI agent. The ruling depends on a fact — what a session actually authorized — that only the AI company operating the agent can currently show.
SOURCE 0 - THE MONITOR THE COURT DECLINED TO APPOINT
A New Mexico court reasoned its way to leaving Meta's compliance self-reported — a deliberate choice, not an oversight. This article examines the evidentiary structure that leaves in place.
SOURCE 0 - REGULATION IS NOT PROOF
Trump's remarks on AI regulation, Texas data centers, and China all argue about how much to regulate. None of them reach the separate question of how compliance is proven — a gap NIST's guidelines and Texas's own audit both share.
SOURCE 0 - THE CRITICAL THRESHOLD NO ONE ELSE HAS MEASURED
OpenAI's Astra disclosure raises a Critical-level cybersecurity flag on the basis of an evaluation record only OpenAI has seen. This article examines what would, and would not, make that determination independently verifiable.
SOURCE 0 - THE AUDIT TRAIL THAT REPLACED THE SEAL
WORM storage made a record impossible to alter once written. In 2022, the SEC added an alternative that lets a firm's own system log the alterations instead — and verify itself.
SOURCE 0 - THE CERTIFICATION THAT NEVER REACHES THE RECORD
Federal Rule of Evidence 902(13) and 902(14) remove the need for a foundation witness. They do not remove the question of who is making the underlying assertion, or when it was made.
SOURCE 0 - THE SEAL THAT NEVER TOUCHES THE EVIDENCE
From 18 August 2026, EU judicial authorities can order any service provider — including AI companies — to produce or preserve electronic evidence within days. The regulation requires a qualified eIDAS seal on the order. It requires nothing of the kind on the evidence itself, and says so in its own recitals.
SOURCE 0 - THE REGISTRY NOBODY HAD TO INVENT
AI governance keeps reaching for nuclear and chemical weapons treaties when it looks for a verification precedent. A lighter, working version has run since 1965: Articles 6 and 7 of the Hague Apostille Convention bind a certifying authority, distinct from the officer whose act it certifies, to answer any interested party — no standing required, no exception.
SOURCE 0 - THE FACT THAT IT EXISTED
Article 1(a) of the 1961 Hague Apostille Convention names the huissier de justice. Article 1(d), read past by most commentary, names something more useful for anteriority disputes: the fact that a document already existed on a certain date. A second, independent treaty foundation for SOURCE 0's pre-execution architecture.
SOURCE 0 - CBAM VOCABULARY
Fourteen questions professionals ask about proving CBAM compliance — default values, carbon-price certification, quarterly certificates, delegation — each mapped to the SOURCE 0 term that answers it, and to the article it rests on.
SOURCE 0 - CSDDD VOCABULARY
Fifteen questions professionals ask about proving CSDDD compliance — due diligence, remediation, civil liability, transition plans — each mapped to the SOURCE 0 term that answers it, and to the article it rests on.
SOURCE 0 - DATA ACT VOCABULARY
Fifteen questions professionals ask about proving Data Act compliance — trade-secret refusal, compensation, contract dates, cloud switching — each mapped to the SOURCE 0 term that answers it, and to the article it rests on.
SOURCE 0 - CYBER RESILIENCE ACT VOCABULARY
Fourteen questions professionals ask about proving Cyber Resilience Act compliance — the 24-hour clock, SBOMs, support periods, substantial modifications — each mapped to the SOURCE 0 term that answers it, and to the article it rests on.
SOURCE 0 - DATA GOVERNANCE ACT VOCABULARY
Fourteen questions professionals ask about proving Data Governance Act compliance — intermediation conduct, altruism registration, consent timing, third-country transfers — each mapped to the SOURCE 0 term that answers it, and to the article it rests on.
SOURCE 0 - GDPR VOCABULARY
Fifty questions professionals ask about proving GDPR compliance — consent, breach notification, DPIAs, international transfers — each mapped to the SOURCE 0 term that answers it, and to the article of Regulation (EU) 2016/679 it rests on.
SOURCE 0 - PROVING A FIX WAS IN PLACE BEFORE A DATE
Commits, tickets, and scans prove what your own systems recorded about a fix. None of them, on their own, fixes when it actually took effect — before an independent third party, and before the dispute began.
SOURCE 0 - WHEN THE VICTIM LIST STAYS SEALED
OpenAI says four accounts were breached. Only two are named, and neither naming came from OpenAI. The count itself is a disclosure, not a finding.

