SOURCE 0 - THE 72 HOURS THAT START WHEN THE COMPANY SAYS SO
A supervisory authority fined Booking.com €475,000 in 2021 after applying an earlier awareness date than the one the company itself claimed. The same signals, read two ways, decided the case.
SOURCE 0 - THE PANELIST WHO WAS NEVER THERE EVALUATES THE EVALUATOR
Synthetic-persona providers label a minority of their population "human-grounded" to distinguish it from algorithmically sampled records. That label confirms a record traces to a real panellist's account — not that the person who supplied the answers matches the account's demographic profile. The market research industry already documents this failure as participant misrepresentation. Where the mismatched respondent is a minor, GDPR Article 8's parental-consent verification duty becomes unreachable by design.
SOURCE 0 - THE EVALUATOR THAT EVALUATES THE EVALUATOR
Providers of general-purpose AI models with systemic risk must document adversarial testing and any involvement of independent external evaluators under Article 55 of the AI Act. Population-scale synthetic-persona simulation infrastructure is a plausible candidate for that role — external to the model provider, but not independent of itself when its own population and validation figures are self-reported. No such case has been identified; this article examines the structural gap that would arise if one did.
SOURCE 0 - THE CERTIFICATE THAT CERTIFIES ITSELF
A market has formed around cryptographic certification of synthetic datasets — SHA-256 fingerprints, Ed25519 signatures, publicly verifiable registries. The better providers state plainly what this proves: integrity and authenticity of the certificate, not generation quality. That honesty does not close the gap that matters under Article 10 of the AI Act, especially where the same platform both generates the data and signs its own certificate.
SOURCE 0 - ONE DISCLOSURE, TWO KINDS OF PROOF
One OpenAI disclosure, two incidents: UK AISI detected and independently confirmed its own findings; Irregular's account exists only through OpenAI's retelling of an audit still in progress. The same document treats both as equally settled.
SOURCE 0 - THE COLDCARD THEFT HAD TWO CAUSES, NEITHER PROVEN
A firmware flaw drained over $130 million from Coldcard wallets. Coinkite says an attacker likely used AI to find it — and admits its own AI review missed it. Both claims rest on the same unverifiable ground.
SOURCE 0 - CSSF CIRCULARS DO NOT FIX THE DETECTION TIME
Two CSSF circulars restructure Luxembourg's DORA incident-reporting transition. Neither requires independent verification of the detection, classification, or resolution timestamps entities self-report.
SOURCE 0 - ONE TIMELINE, TWO REGULATORS
Under DORA, a cross-border group does not file one report of a major ICT incident — it files several, one per entity, each to its own competent authority. Each is drafted independently. Nothing reconciles them.
SOURCE 0 - A PRE-EXECUTION EVIDENTIARY BLUEPRINT FOR DSA DILIGENCE TIMELINES
Following the AliExpress decision, this blueprint sets out how any very large platform can seal its detection and compliance-check timelines with an independent third party, before the fact.
SOURCE 0 - THE FOUR-LAYER ARCHITECTURE
The four categories of the SOURCE 0 Doctrine are not parallel classifications. They constitute a causal sequence — problem domain, methodological response, legal operationalization, normative constraint field — whose coherence depends on the formal articulation of three inter-layer interfaces. This article makes that architecture explicit, disambiguates its shared vocabulary across eleven distinct definitions, establishes the material modification threshold, closes the deliberate misclassification escape route, and maps each layer against its precise regulatory obligations. The four-layer architecture is not a model. It is a condition of proof.
SOURCE 0 - ACCULTURATION DEBT AND THE EVIDENTIARY TRAP
Faced with Shadow Runs and systemic frontier model drift, standard downstream observability (SIEM/EDR) fails. The SOURCE 0 doctrine introduces Opposability-as-a-Service (OaaS): an ex-ante cryptographic baseline and judicial escrow designed to protect directors by shifting the burden of proof back to the regulator.

