How this was made. The version number counts drafts of the text. It does not measure the inquiry behind it, which has run over days and across several AI systems, with argument between those systems and within them, directed, refused and repeatedly redirected by the author. The source material was AI-generated, and then adversarially and iteratively refined across a range of tools — systems built by different companies in different jurisdictions, set against each other and against the author. No one of them produced this text, and no one of them reviewed it alone. The plurality is deliberate rather than incidental. A single model carries a single set of priors about which sources are authoritative, and this series argues that an evidence base narrowed in exactly that way is how a contested question comes to look settled. Using one model to investigate that claim would have been the claim refuting itself. To name a single model on it would credit that model with work that was neither its own nor done in a single pass. The plurality was also necessary, and the record should say why. In drafting, the assisting model repeatedly led with United States institutional sources — a national laboratory, an industry association, a market study nineteen years old — and presented conclusions drawn from them as the state of knowledge. On one occasion European measured data contradicting those conclusions was present in the same research return and was placed below them. Framings were proposed that would have argued against this series’ own position using that evidence base, and offered as rigour. Each was refused by the author and the material rebuilt. That is the mechanism these documents describe, occurring in their own making, and it is recorded because a series arguing that evidence bases narrow without anyone deciding to narrow them cannot credibly claim its own production was exempt. The framing, the corrections and the judgements are the author’s, and so are the errors. How this site is written sets out what is declared on every piece, who checks it, and where the per-piece record lives.
The duties exist and the paper cites them: Article 12 requires that events be recorded over a system’s lifetime, Article 19 places retention duties on providers and Article 26(6) on deployers.
They are duties to keep. None requires that a record be unalterable by its holder, that its time come from an independent source, that any other party be able to verify it, or that claims drawn from it say whether they are independently attested. An operator can satisfy every one of them with a log it can edit, on infrastructure it controls, stamped by its own clock. They are also not yet in force: following the June 2026 amendments, the high-risk obligations apply from 2 December 2027 for stand-alone systems and 2 August 2028 for product-embedded ones. The gap the paper names is not an absent legal instrument; it is an absent obligation to use the one that exists, and no mark by which a purchaser could tell whether it had been used.
Because an append-only store administered by the party under examination is append-only at that party’s discretion.
Property 3.1 asks for three things together: corrections appended and nothing sealed altered or removed; each seal committing to everything before it, so a record cannot be pulled from the sequence without invalidating what follows; and the sealing component unreachable by the systems whose conduct it records. The third is the one an ordinary product does not supply. The draft standard puts it as a requirement that the signing capability sit outside the write path of every agent and every operator role that creates records (MIO-STD-01 §4.3), and Addendum M carries it as assumption A3, one of the four the whole framework rests on.
A single authority is a single point of both failure and coercion. If it stops issuing, continuity ends; if it can be compelled or induced to backdate, the presumption is worth what the authority’s independence is worth.
The draft standard makes the plurality normative and says one authority is insufficient at any assurance level (§5.2.2). The jurisdictional test is stated in plain terms in its Annex C: is there a single court, regulator or executive that could compel every one of the authorities under one order or one treaty mechanism? If so they are one authority however many companies are involved. Two further scope limits: the eIDAS presumption is European law, and the weight a New Zealand tribunal would give any of this is a question for counsel here; and the standard names no approved suppliers, because a normative list becomes a trade instrument (§5.4.1).
That every statement drawn from the record says which of two clocks it rests on.
Records are sealed in batches. Ordering across batches is fixed by the outside authority and a third party may rely on it. Ordering within a batch rests on the operator’s own hash chain. Addendum M §1 writes this as an attestation grade on every temporal claim — A if it needs only the authority’s order, O if it needs the operator’s — and §2.3 establishes that any statistic requiring resolution finer than the batch interval is grade O. The practical consequence is in the paper’s §3.4: a product advertising independently timestamped records at a twenty-four-hour interval is offering independent evidence about days and operator testimony about anything shorter. That may be adequate. A purchaser should be able to see which they are buying, and the draft standard requires every temporal claim to carry its grade (§5.7).
It is used for one structural feature, and the limits of the analogy are the rest.
The feature is that the mark has three elements and the two carrying the assurance may be applied by nobody but the assay office. The sponsor’s mark identifying the maker is the maker’s own; the fineness mark and the assay mark are not. The analogue is stated at §4.2: which agent acted under what recorded authority, which tier of proof the records reach, which independent authority attested them — with the assurance elements applied by a conformity assessment body. Where the analogy does not carry is proportionality: hallmarking exemptions are per article, by weight, and say nothing about the size of the business. They supply the principle that a compulsory mark may carry a floor, and no ready threshold for records. The paper says the threshold requires argument rather than assertion, and R5 asks that the smallest deployments be exempt on an argued basis.
A published, append-only register of eligible attestation authorities, maintained independently of any operator claiming conformance, naming no suppliers.
The paper’s §4.4 and the draft standard’s §5.4 set out what the register records for each entry: identity, jurisdiction, audit status and date, practice-statement reference, and dates of entry and removal, with removals recorded rather than deleted. Eligibility is by stated criteria — an independently audited time source and issuance practice at a stated interval among them — rather than by name. The paper notes this is ordinary conformity assessment, and that it is also the answer to the criticism made of content-provenance schemes, where anyone may sign and trust reduces to the governance of the accepted-signer list.
The substrate itself does not record content. It records that an actor touched a record, under which authority, in what order relative to other events (§5.1). That property is real and it stops at the substrate.
A reviewer examining a sampled record may need to read what was written, and content-blindness is not a property of any examination layer built on top (§5.2). Sealing reads goes further still: it creates a record of individuals’ attention to their own files. The paper calls that a question of legitimacy prior to any question of detection, to be answered by those governed rather than by those building (§5.5), and the draft standard lists it among the known limits: read records require their own access rule before they are used for detection (Annex B, item 6).
The guidance is cited rather than avoided. Guidelines 02/2025 describe keyed hashing with the key held separately as one available measure and qualify it heavily: the hash is itself personal data, and unlinkability after key destruction holds only while the construction is unbroken and neither key nor salt has been disclosed. The Board advises against registering personal data in an immutable structure in clear, encrypted or hashed form.
The paper’s position is that a scheme sealing the shape of events and never their content is a materially different object from the ledgers that guidance addresses — and that anyone adopting these properties must specify an erasure mechanism and defend it against the guidance rather than assume the distinction is accepted (§5.4). The mechanism is MIO-STD-01 §4.6: keyed per-subject pseudonyms, erasure by destroying the subject’s secret, the erasure sealed without naming whose, the residual risk disclosed, and no claim that any of it is erasure in law. R4 asks that every instrument in this area do the same.
No, and §8 says so in five lines. The proposal prevents nothing; it evidences conduct after the fact. It does not detect an agent acting improperly — a trustworthy record is the precondition for that and not the achievement of it, and detection is the subject of the companion paper. It does not reach conduct that never touches the record, though use generally touches the record where acquisition does not. And an attestation does not establish that a record is true; it establishes what the record stated at a given time, which removes retrospective adjustment and no more.
Drafted with AI assistance, checked and revised by the author.
What this publication does not claim, and what is outstanding against it in the register.
Nothing outstanding in the register. Every claim in this publication has its evidence recorded, and no question against it is parked. That is a statement about this publication on the date shown above, generated from the register rather than asserted, and it will change when the register does.
Alongside: the publication · sources and provenance