SOURCE 0 - PROVING WHEN A DISCLOSURE OCCURRED
A system log with a timestamp is not proof that a disclosure happened when an organisation says it did — it is a claim the organisation itself generated and controls. This article sets out, in general terms, what a record actually needs before it can function as independent proof of timing.
SOURCE 0 - THE ESA INCIDENT REPORT IS SELF-REPORTED EVIDENCE
3,383 major ICT incidents, one joint ESA report, and a methodology section that quietly admits the data is incomplete and not yet fully validated. This article examines what it means that the reference benchmark regulators now cite was built entirely from entities' own self-declared accounts of themselves.
SOURCE 0 - DORA VOCABULARY
A reference mapping of 69 questions professionals ask about proving DORA compliance to the corresponding term in the SOURCE 0 doctrinal vocabulary.
SOURCE 0 - THE DORA NOTIFICATION PARADOX
DORA requires a bank to prove when it became aware of an incident and when it classified it as major — the two instants a regulator disputes most. Both are written exclusively by the bank itself. This article examines why TLPT, Article 6 internal audit, and third-party oversight do not supply an independent witness to either instant, and what a pre-execution, third-party-deposited fixation adds to the DORA timeline.
SOURCE 0 - DISCLOSURE DUTY IS NOT PROOF DUTY
Article 50 tells you what to disclose. It says nothing about proving when you disclosed it — and that silence is where liability actually lives.
SOURCE 0 - THE 2 AUGUST 2026 DEADLINE
The 2 August 2026 application date for Article 50 is set by Article 113 of the AI Act, not by the Digital Omnibus. This article traces the date to its source, isolates the one narrow point where the Digital Omnibus touches Article 50, and states what remains unpublished as of 14 July 2026.
SOURCE 0 - WHAT ARTICLE 50 REQUIRES YOU TO DISCLOSE
Article 50 of the AI Act does not impose one transparency duty but four, each attached to a different system function and a different actor. This article sets out the content of each obligation, independent of the separate question of how disclosure is proven, and states the current position of the Digital Omnibus deferral as of 13 July 2026.
SOURCE 0 - THE ARTICLE 50 DISCLOSURE GAP
Article 50 of the AI Act requires disclosure that a person is interacting with an AI system. It does not require proof that the disclosure preceded the interaction. This article states the current status of the Digital Omnibus on AI as of 12 July 2026 and sets out the pre-execution attestation mechanism that closes the resulting evidentiary gap.
SOURCE 0 - THE ARTICLE 50 DISCLOSURE GAP
From 2 August 2026, Article 50 requires disclosure that a person is interacting with an AI system. This deadline is unaffected by the Digital Omnibus deferral of Articles 9-15. SOURCE 0 seals the disclosure configuration before the interactions it governs.
SOURCE 0 - THREE LEVELS OF DIGITAL EVIDENCE, AND WHY MOST ARCHITECTURES STOP AT THE SECOND
Digital evidence architectures fall into three levels — self-declared certification, third-party technical fixation, and independent judicial deposit — each answering a different question. Most current architectures stop at the second.
SOURCE 0 - VOCABULARY
A reference page mapping plain-language questions about AI compliance, timestamps, logs, and legal opposability to the corresponding term in the SOURCE 0 doctrinal vocabulary — for readers who have the question but not yet the terminology.
SOURCE 0 - THE LOG-AS-CLAIM PROBLEM
An AI system's own log of its own decision is a claim made by the party under scrutiny, not evidence independent of that party. This article sets out why self-generated records, and self-issued certification declarations, occupy a different evidentiary position than records fixed and deposited independently of the party they concern.
SOURCE 0 - THE OPPOSABILITY STANDARD
Certification of an AI system before deployment and proof that a specific decision was lawful at the moment it occurred are two distinct evidentiary claims, routinely conflated under the same vocabulary of compliance and audit trails. This article sets out where qualified timestamping, blockchain anchoring, and runtime governance stop, and where legal opposability begins.
SOURCE 0 - THE DMA PROOF STANDARD
A gatekeeper designation ruling and a pending interoperability dispute are frequently treated as the same question. They are not. One determines who the Digital Markets Act applies to; the other determines what standard of evidence a regulator will accept once it does. This article examines the distinction the European Commission has already drawn, and the structural parallel it carries for pre-execution evidentiary architecture.
SOURCE 0 - FROM EVIDENCE-BASED GOVERNANCE TO PROOF-BASED GOVERNANCE
Reconstructing what an AI system did is a forensic capability. Proving what was authorised before it acted is an architectural one. The governance documentation market — law firms, consulting practices, compliance frameworks — sells the first. Enforcement proceedings under AI Act Article 99 will demand the second. This article establishes the structural distinction between evidence-based governance and proof-based governance, and why only one survives adversarial scrutiny.
SOURCE 0 - THE REFERENCE LEGITIMACY GAP AND THE CONSTITUTIONAL CONDITION GOVERNANCE CANNOT DEFER
The Reference Legitimacy Gap designates the structural interval between what a governance architecture documents and what it can actually verify. Without prior fixation, the evaluative reference becomes a variable adjustable after the fact by any party with sufficient interest and access. This article establishes the Mandate of Antecedence as the minimum architectural condition under which governance produces proof rather than narrative.
SOURCE 0 - THE AI OMNIBUS AND THE PROOF GAP
The Digital Omnibus on AI defers the enforcement of high-risk obligations but leaves evidentiary exposure unchanged. When a system acts before the deferred deadlines, the governance state operative at T-0 remains the central question in civil, insurance, and contractual proceedings. The postponement affects regulatory temporality, not the requirement to hold an independently fixed, opposable governance record. The proof gap persists throughout the deferral window, closed only by a pre-execution cryptographic attestation architecture such as SOURCE 0.
SOURCE 0 - DIGITAL DEPENDENCY AND THE PROOF GAP
Financial risk assessments of cloud concentration measure dependency as an operational and strategic exposure. They do not measure it as an evidentiary exposure. When an organization's proof infrastructure resides within the same perimeter as its operational infrastructure, proof collapse occurs the moment evidentiary circularity meets adversarial scrutiny. This article identifies the structural condition — S ∩ C = ∅ — that financial risk frameworks do not yet incorporate.
SOURCE 0 : ANTI-CORRUPTION COMPLIANCE AND THE PROOF GAP
The new anti-corruption directive shifts liability from "who committed the infraction" to "why didn't your organisation prevent it." Demonstrating that a compliance programme functioned requires proof it was operational before the act — not documentation assembled after. With sanctions reaching 5% of global turnover or 40 million euros, this article establishes why that distinction is architectural, not procedural.
SOURCE 0 - DOCTRINE : WHEN GOVERNANCE BECOMES A SYSTEM PROPERTY
Governance only becomes enforceable when three conditions are simultaneously met: T‑0 fixation, structural independence (S ∩ C = ∅), and legal opposability. Without these properties, no post-execution record can establish a governance state that was never sealed. This article articulates the architectural conditions under which governance ceases to be a management assertion and becomes a verifiable system property.

