SOURCE 0 - THE REGISTRY NOBODY HAD TO INVENT
AI governance keeps reaching for nuclear and chemical weapons treaties when it looks for a verification precedent. A lighter, working version has run since 1965: Articles 6 and 7 of the Hague Apostille Convention bind a certifying authority, distinct from the officer whose act it certifies, to answer any interested party — no standing required, no exception.
SOURCE 0 - THE FACT THAT IT EXISTED
Article 1(a) of the 1961 Hague Apostille Convention names the huissier de justice. Article 1(d), read past by most commentary, names something more useful for anteriority disputes: the fact that a document already existed on a certain date. A second, independent treaty foundation for SOURCE 0's pre-execution architecture.
SOURCE 0 - THE PRESERVATION THAT ISN'T PROOF
A preservation letter stops destruction. It does not create independence. What the AG coalition will receive from OpenAI remains self-generated evidence — and the Belgian mechanism that could fix a fact before the fact already crosses into US courts unmodified.
SOURCE 0 - ONE DISCLOSURE, TWO KINDS OF PROOF
One OpenAI disclosure, two incidents: UK AISI detected and independently confirmed its own findings; Irregular's account exists only through OpenAI's retelling of an audit still in progress. The same document treats both as equally settled.
SOURCE 0 - THE COLDCARD THEFT HAD TWO CAUSES, NEITHER PROVEN
A firmware flaw drained over $130 million from Coldcard wallets. Coinkite says an attacker likely used AI to find it — and admits its own AI review missed it. Both claims rest on the same unverifiable ground.
SOURCE 0 - THE SUMMARY BEHIND THE FINDING
AISI's INC-2026-07-28-01 discloses its protocol and attribution in full — the most transparent agentic-AI incident report published to date. But the report's own limitations section concedes that its account of agent intent rests on a paraphrase of reasoning tokens generated after the fact, not a raw record. SOURCE 0 examines what independence resolves, and what it structurally cannot.
SOURCE 0 - CBAM VOCABULARY
Fourteen questions professionals ask about proving CBAM compliance — default values, carbon-price certification, quarterly certificates, delegation — each mapped to the SOURCE 0 term that answers it, and to the article it rests on.
SOURCE 0 — WHEN THE INCIDENT REPORT COMES FROM SOMEONE ELSE
An AI incident at OpenAI and three related incidents at Anthropic show a structural mismatch: public narrative forms in hours, verified internal reconstruction takes weeks. This article examines what that mismatch means for AI Act Article 73 notifications and Product Liability Directive litigation, and what a pre-execution seal changes.
SOURCE 0 - CSDDD VOCABULARY
Fifteen questions professionals ask about proving CSDDD compliance — due diligence, remediation, civil liability, transition plans — each mapped to the SOURCE 0 term that answers it, and to the article it rests on.
SOURCE 0 - DATA ACT VOCABULARY
Fifteen questions professionals ask about proving Data Act compliance — trade-secret refusal, compensation, contract dates, cloud switching — each mapped to the SOURCE 0 term that answers it, and to the article it rests on.
SOURCE 0 - MDAI VOCABULARY (MEDICAL DEVICE AI: MDR × AI ACT)
Fourteen questions professionals ask about proving Medical Device AI (MDR × AI Act) compliance, mapped to the SOURCE 0 doctrinal vocabulary.
SOURCE 0 - CYBER RESILIENCE ACT VOCABULARY
Fourteen questions professionals ask about proving Cyber Resilience Act compliance — the 24-hour clock, SBOMs, support periods, substantial modifications — each mapped to the SOURCE 0 term that answers it, and to the article it rests on.
SOURCE 0 - DATA GOVERNANCE ACT VOCABULARY
Fourteen questions professionals ask about proving Data Governance Act compliance — intermediation conduct, altruism registration, consent timing, third-country transfers — each mapped to the SOURCE 0 term that answers it, and to the article it rests on.
SOURCE 0 - GDPR VOCABULARY
Fifty questions professionals ask about proving GDPR compliance — consent, breach notification, DPIAs, international transfers — each mapped to the SOURCE 0 term that answers it, and to the article of Regulation (EU) 2016/679 it rests on.
SOURCE 0 - CSSF CIRCULARS DO NOT FIX THE DETECTION TIME
Two CSSF circulars restructure Luxembourg's DORA incident-reporting transition. Neither requires independent verification of the detection, classification, or resolution timestamps entities self-report.
SOURCE 0 - ONE TIMELINE, TWO REGULATORS
Under DORA, a cross-border group does not file one report of a major ICT incident — it files several, one per entity, each to its own competent authority. Each is drafted independently. Nothing reconciles them.
SOURCE 0 - PROVING A FIX WAS IN PLACE BEFORE A DATE
Commits, tickets, and scans prove what your own systems recorded about a fix. None of them, on their own, fixes when it actually took effect — before an independent third party, and before the dispute began.
SOURCE 0 - THE AUDIT THAT CLEARED ITSELF
Anthropic's own review of a Claude access incident is credible — and, on its own, unfalsifiable by anyone outside Anthropic. This is the Endogenous Audit Paradox in its most literal form.
SOURCE 0 - THE DEFAULT NO ONE ELSE SAW
TikTok says its teen accounts have had 50+ preset safety features "from the moment they set up an account." The Commission tested today's configuration and found it wanting. Neither account fixes what a specific default actually was at an earlier date.
SOURCE 0 - WHEN THE VICTIM LIST STAYS SEALED
OpenAI says four accounts were breached. Only two are named, and neither naming came from OpenAI. The count itself is a disclosure, not a finding.

