SOURCE 0 - THE FOOTNOTE THAT OUTLIVED ITS REGULATION
The current EU guidance on management verifications under the Common Provisions Regulation defines its own core methodology by citing a 2015 guide written for a regulation no longer in force — without independently re-verifying that the definitions still hold. SOURCE 0 examines what a citation across an expired regulatory boundary does and does not establish.
SOURCE 0 - THE SUBSIDY NO ONE ELSE LOGGED
Two of the largest EU merger cases of 2026 turn on the same regulation: what foreign financial contributions a party received over three years. Both are answered from the same source — the recipient's own accounting.
SOURCE 0 - THE WEEK BEFORE ARTICLE 50
With days remaining before Article 50's transparency obligations take effect, the question for a DPO, CISO, or AI compliance officer is no longer what the law requires. It is what can still be independently fixed about current practice before the deadline arrives.
SOURCE 0 - THE HACK ONLY OPENAI COULD CONFIRM
Two Cornell computer scientists gave the same incident two different readings within one statement: no reason to think the details are wrong, and no way to be sure they aren't shaped by the telling. Both readings are correct, because nothing outside OpenAI's own account fixed what happened before OpenAI chose how to tell it.
SOURCE 0 - THE DEFERRAL THAT HADN'T HAPPENED YET
A postponement everyone expects is not the same as a postponement that has happened. Until the Digital Omnibus is published in the Official Journal, Articles 9 to 15 of the AI Act still apply from 2 August 2026 exactly as written.
SOURCE 0 - THE DISCLOSURE THAT ISN'T DATED
Article 9 of Directive (EU) 2024/2853 presumes a product defective if the manufacturer won't hand over technical evidence. That closes the refusal problem. It leaves untouched a narrower one: whether the evidence handed over was dated before the dispute began.
SOURCE 0 - THE VERIFIER WHO NEVER SAW THE LOT
The Carbon Border Adjustment Mechanism already has an independent verifier — the definitive regime made sure of that. What the verifier attests is a methodology over a reporting period, not the embedded emissions of the specific lot an importer clears today. SOURCE 0 closes that narrower gap.
SOURCE 0 - THE ACCUSED STATE FILES THE PROOF
Regulation (EU, Euratom) 2020/2092 evaluates a Member State using courts, auditors, OLAF, GRECO — never the state's own word. One narrow provision breaks that pattern: the follow-up report on whether beneficiaries were actually paid. SOURCE 0 closes that one gap.
SOURCE 0 - SANCTIONS WITHOUT PROOF OF DILIGENCE
Non-compliance with Article 50 of the AI Act falls under Article 99, paragraph 4, point (g) — up to 15 million euros or 3% of worldwide turnover. The actual amount depends on factors the operator must prove, not declare: measures implemented, absence of intent, cooperation. Without a sealing third party, these proofs remain produced by the very operator under investigation.
SOURCE 0 - THE SPACE ACT'S MISSING WITNESS
The same proposal that requires a qualified technical body to certify a satellite's environmental footprint asks nothing of the sort for its incident reports. Self-detection, self-logging, self-declaration. SOURCE 0 fixes the record before the operator writes it.
SOURCE 0 - THE VERIFIER WHO ARRIVED TOO LATE
A certified sustainability claim is not the same as a provable one. Directive (EU) 2024/825 puts the burden of proof on the advertiser — not the certifier. SOURCE 0 closes the gap between verification and timing.
SOURCE 0 - PEER REVIEW IS NOT OPPOSABLE PROOF
Elon Musk has proposed that leading AI companies hold regular calls to review each other's frontier models before deployment, following OpenAI's disclosure of a sandbox escape that compromised Hugging Face's infrastructure. Peer review breaks a single company's closed loop of self-evaluation, but replaces it with a closed loop of two. Without independent sealing of what was reviewed and when, the resulting report remains an assertion between two interested competitors, not opposable evidence.
SOURCE 0 - SANCTIONS SANS PREUVE DE DILIGENCE
Le manquement à l'article 50 de l'AI Act relève de l'article 99, paragraphe 4, point g) — jusqu'à 15 millions d'euros ou 3 % du chiffre d'affaires. Le montant effectif dépend de facteurs que l'opérateur doit prouver, non déclarer : mesures mises en œuvre, absence d'intention, coopération. Sans tiers de scellement, ces preuves restent produites par l'opérateur poursuivi lui-même.
SOURCE 0 - GOOGLE'S DMA FINE: WHO VERIFIES COMPLIANCE?
The DMA does give the Commission a power to appoint independent external experts. It is discretionary, and it verifies after deployment. Here is what closes the gap it leaves regardless.
SOURCE 0 - INDEPENDENT EVALUATION IS NOT OPPOSABLE PROOF
The CeSIA-led coalition's call for mandatory independent evaluation of general-purpose AI models correctly identifies who should assess these systems. It leaves open a separate question: once produced, can the evaluation record itself survive adversarial contestation, or does it remain alterable by any party with a later interest in what it says.
SOURCE 0 - YOUR OWN AUDIT TRAIL CANNOT PROVE YOUR DILIGENCE
Article 6 of DORA requires financial entities to review and internally audit their ICT risk framework at least once a year. But the "independence" the Regulation demands is segregation within the entity, not independence from it — leaving the only record of diligence in the hands of the party whose diligence is in question.
SOURCE 0 - THE STOP BUTTON THAT WAS NEVER TIMED
Article 14 of the EU AI Act requires high-risk systems to be stoppable by human oversight — a capability obligation, never a timing proof. The 21 July 2026 OpenAI/Hugging Face containment failure, reported by Reuters, shows why that distinction has direct financial exposure under Article 99.
SOURCE 0 - THE GENERATION DATE ONLY THE GENERATOR CAN CLAIM
The Commission's Article 50 Guidelines confirm that AI-generated content produced before 2 August 2026 escapes retroactive marking — unless published afterward, when the full obligation returns. This article sets out why the generation date at the centre of that rule is a claim, not a fact, and what an independent seal would add.
SOURCE 0 - WHY A SIEM LOG IS NOT LEGAL PROOF
A SIEM platform can be complete, tamper-evident, continuous, and actively reviewed — and still prove nothing about its independence from the party it is meant to hold accountable. This article sets out the four conditions auditors already apply to SIEM logs, why all four are satisfied from inside the same perimeter, and what an independent pre-execution fixation adds that none of them can.
SOURCE 0 - SHEIN'S PENDING DSA INVESTIGATION: WHAT TEMU AND ALIEXPRESS ALREADY SHOW
Unlike Temu and AliExpress, Shein's investigation has not yet concluded — which is precisely when an evidentiary architecture has the most to offer, before the record is fixed.

