Sources and provenance — What a Record Must Prove

Sources and provenance for What a Record Must Prove · v0.1 · 11 September 2026

How this was made. The version number counts drafts of the text. It does not measure the inquiry behind it, which has run over days and across several AI systems, with argument between those systems and within them, directed, refused and repeatedly redirected by the author. The source material was AI-generated, and then adversarially and iteratively refined across a range of tools — systems built by different companies in different jurisdictions, set against each other and against the author. No one of them produced this text, and no one of them reviewed it alone. The plurality is deliberate rather than incidental. A single model carries a single set of priors about which sources are authoritative, and this series argues that an evidence base narrowed in exactly that way is how a contested question comes to look settled. Using one model to investigate that claim would have been the claim refuting itself. To name a single model on it would credit that model with work that was neither its own nor done in a single pass. The plurality was also necessary, and the record should say why. In drafting, the assisting model repeatedly led with United States institutional sources — a national laboratory, an industry association, a market study nineteen years old — and presented conclusions drawn from them as the state of knowledge. On one occasion European measured data contradicting those conclusions was present in the same research return and was placed below them. Framings were proposed that would have argued against this series’ own position using that evidence base, and offered as rigour. Each was refused by the author and the material rebuilt. That is the mechanism these documents describe, occurring in their own making, and it is recorded because a series arguing that evidence bases narrow without anyone deciding to narrow them cannot credibly claim its own production was exempt. The framing, the corrections and the judgements are the author’s, and so are the errors. How this site is written sets out what is declared on every piece, who checks it, and where the per-piece record lives.

Status of these claims#

What this publication does not claim, and what is outstanding against it in the register.

Nothing outstanding in the register. Every claim in this publication has its evidence recorded, and no question against it is parked. That is a statement about this publication on the date shown above, generated from the register rather than asserted, and it will change when the register does.

What this publication rests on, and how solid each part of it is. What a Record Must Prove is a policy paper, and this page describes it as one: it quotes instruments, and each quotation is checked below against what the instrument says.

What it cites from outside#

This publication cites outside sources, and they are listed below — each with what it supports, and with what it does not support. That second column is the one that matters: the common failure is not a fabricated source, it is a real source stretched past its finding.

Regulation (EU) No 910/2014 (eIDAS), Article 41(2)

regulation

Supports. §2.1, quoted: a qualified electronic time stamp “shall enjoy the presumption of the accuracy of the date and the time it indicates and the integrity of the data to which the date and time are bound.” The Summary’s “European law already attaches a legal presumption to one of them.”

Does not support. §2.2’s “obtained by almost none” — the regulation is silent on uptake and the paper offers no figure. Nor does the presumption travel: the paper’s Status note says the weight a New Zealand tribunal would give it is for counsel, and that qualification governs every use of the Article in the paper.

⚠️ Retrieval. Verified at primary source in earlier work on this series; not re-opened for this page.

Regulation (EU) 2024/1183 (the eIDAS amendment) — qualified electronic ledgers

regulation

Supports. §2.1: that the 2024 amendment “extends comparable standing to qualified electronic ledgers.” The amendment introduces electronic ledgers as a trust service and gives qualified ledgers a legal effect concerning the ordering and integrity of their records.

Does not support. The paper is careful to say “comparable”, not “the same”, and this page cannot tighten that: the ledger provision was not opened for this page, so the exact presumption it grants — and whether it reaches date and time in the way Article 41(2) does — is not quoted here and should not be inferred from the paper’s wording.

⚠️ Retrieval. ⚠️ Not retrieved. EUR-Lex returned no readable text to the fetcher on two address forms on 11 September 2026. The provision should be quoted from the Official Journal before this line is relied on.

The EU trusted lists — “a published register of qualified providers is maintained”

other

Supports. §2.1’s statement that a register of qualified trust service providers exists and is published. Under eIDAS each member state maintains a trusted list and the Commission publishes the compiled lists.

Does not support. Nothing about which providers are on it. The companion essay’s claim that the project’s own provider is “not eIDAS-qualified” would be checked against this register, and was not for this page.

⚠️ Retrieval. ⚠️ Not retrieved.

EU AI Act, Articles 12, 19 and 26(6)

regulation

Supports. §2.3 as written. Article 12(1): “High-risk AI systems shall technically allow for the automatic recording of events (logs) over the lifetime of the system.” Article 19 places the duty to keep those logs on providers, for “a period appropriate to the intended purpose … of at least six months, unless provided otherwise in the applicable Union or national law.” Article 26(6) places the parallel duty on deployers, “to the extent such logs are under their control”, for the same minimum period. The paper’s negative — that none of the three requires unalterability by the holder, independent time, third-party verifiability or graded disclosure — is borne out: the three Articles address what is recorded and for how long, not how the record is secured or who can check it.

Does not support. Article 12(2) does require logging sufficient for “a level of traceability of the functioning of a high-risk AI system” appropriate to its purpose, and Article 12(3) sets minimum log contents for biometric systems. “Duties to keep” is accurate, but the Act is not silent on log content; it is silent on evidential quality, which is the narrower and correct claim the paper makes in §2.5.

⚠️ Retrieval. The three Articles were retrieved on 11 September 2026 by the AI agent that compiled this page from artificialintelligenceact.eu, a third-party mirror of the Act’s text, not from EUR-Lex. The wording matched the paper’s description; the Official Journal text was not opened.

EU AI Act — amendments approved June 2026 and the deferred application dates

regulation

Supports. §2.4: high-risk obligations for stand-alone systems apply from 2 December 2027 and for product-embedded systems from 2 August 2028.

Does not support. Anything about the content of the June 2026 amendments beyond the dates, which the paper does not describe.

⚠️ Retrieval. Verified at primary source in earlier work on this series and reused here; not re-opened for this page.

Hallmarking Act 1973 (United Kingdom), consolidated text

statute

Supports. §4.1, checked clause by clause. Section 1 makes it an offence, “in the course of a trade or business”, to apply to an unhallmarked article a description indicating it is wholly or partly gold, silver, platinum or palladium (palladium having been added to the consolidated text by later amendment). The approved hallmark comprises the assay office mark, the standard (fineness) mark and further marks; section 3 provides that the sponsor’s mark is struck before the article is submitted for assay — that is, by or for the maker or sponsor — while the assurance marks are the assay office’s. §4.3’s “exemptions are per article, by weight” is borne out by Schedule 1 Part II: gold under 1 gram, silver under 7.78 grams, platinum under 0.5 gram, palladium under 1 gram.

Does not support. Two refinements. First, the Act allows “the assay office and the manufacturer or sponsor of an article [to] make arrangements for the sponsor’s mark to be struck by that assay office” — so “the sponsor’s mark is the maker’s own” is right as to whose mark it is, and the maker ordinarily strikes it, but the statute does not forbid the assay office striking it on the maker’s behalf. The paper’s operative sentence — that the two assurance elements may be applied by nobody but the assay office — is the one that carries the argument and it is correct. Second, the paper describes the mark as three elements; the Act’s approved hallmark for a single-metal article lists the assay office mark, the standard mark, a pictorial mark and a date letter, with the sponsor’s mark treated separately. “Three elements” is the customary summary and the paper uses it as such.

⚠️ Retrieval. Retrieved on 11 September 2026 from legislation.gov.uk by the AI agent that compiled this page; sections 1–4 and Schedule 1 checked.

“A statute of 1300”

statute

Supports. §4.1’s closing line, “The scheme dates from a statute of 1300” — the ordinance of Edward I that established the leopard’s-head assay in London.

Does not support. The 1973 Act does not refer to 1300, and the date is not in any document opened for this page. It is the standard history of the London assay office and is recorded here as that.

⚠️ Retrieval. ⚠️ Not retrieved. The London Assay Office’s history page returned 404 when fetched on 11 September 2026; no other source for the date was opened.

Criticism of content-provenance schemes — “any party may sign and trust reduces to the governance of the accepted-signer list”

other

Supports. §4.4’s claim that an independently maintained register of eligible authorities answers a criticism that has been made of content-provenance schemes.

Does not support. No scheme, critic or document is named. The criticism is a recognisable one — it has been made of signed-manifest provenance standards — but as written the paper cites nothing, and this page cannot supply a source without inventing an attribution.

⚠️ Retrieval. ⚠️ Not retrieved; nothing to retrieve was identified.

European Data Protection Board, Guidelines 02/2025 on processing of personal data through blockchain technologies

framework

Supports. §5.3, each element checked against the text. Keyed hashing with the key held separately as one available measure: paragraph 52, “Another measure is to store only a salted or keyed hash of the personal data on the blockchain. The unhashed data itself, as well as the secret key or the long random salt used, are stored confidentially off the chain.” That the hash is itself personal data: same paragraph, “the hash will also be considered personal data.” That unlinkability after key destruction is conditional: “after deletion of the secret key or salt, the hash should not be linkable to the original data, provided that the algorithm has not been broken, the keys have not been compromised or leaked, and the salt was not leaked or poorly chosen.” That storing personal data in clear, encrypted or hashed form on an immutable structure is not advisable: paragraphs 103–104, “it is therefore not advisable to register personal data in those forms on a blockchain. Instead, personal data in those forms should be stored off-chain,” and paragraph 48, “In general, it is not advisable to store personal data on the blockchain.” That alternative tools are recommended where the integrity property is not required: paragraph 103, “the EDPB recommends looking at other tools if the strong integrity property of blockchains is not needed.”

Does not support. The guidelines are about blockchains — distributed, disintermediated, replicated ledgers — and the paper’s §5.4 says so: a scheme sealing the shape of events and never their content “is a materially different object from the ledgers that guidance addresses.” The guidelines do not consider an append-only audit substrate held by one operator with external time attestation, so they neither approve nor condemn the paper’s construction; the paper’s R4 (specify the erasure mechanism and defend it against this guidance) is the right consequence. The guidelines also address the hash of personal data stored on-chain; whether a keyed pseudonym in a sealed event record is the same object is an argument MIO-STD-01 §4.6 has to make, not one the guidelines settle.

⚠️ Retrieval. Retrieved on 11 September 2026 by the AI agent that compiled this page as the PDF of Version 1.1, adopted on 8 April 2025, marked “Adopted – version for public consultation.” Paragraphs 48, 52, 103 and 104 were read and are quoted above. ⚠️ A later version adopted after consultation may exist and was not checked; paragraph numbers and wording may differ in it.

Standards New Zealand — NZS ISO/IEC 42001:2025 and NZS ISO/IEC 23894:2025

standard

Supports. §6.1. Both were published by Standards New Zealand on 17 October 2025; each product page describes the standard as “identical to and has been reproduced from” the ISO/IEC 2023 edition — 42001 for AI management systems, 23894 for AI risk management.

Does not support. Anything about the standards’ requirements, which the paper does not describe and this page did not open. “The standards are adopted” means the national standards body has published identical adoptions; it does not mean any organisation is bound by them.

⚠️ Retrieval. The two Standards New Zealand product pages were retrieved on 11 September 2026 by the AI agent that compiled this page. The standards themselves were not opened.

New Zealand’s national AI strategy, July 2025

report

Supports. §6.2’s word counts: “standards” once, in “standards bodies”; assurance, audit, certification and conformity absent; the International Organization for Standardization not named. §6.3’s two quotations — “light-touch and principles-based” and “does not require additional regulatory overlay beyond existing law” — and §6.4’s statement that the 2027 Digital Nations chairmanship is “stated in the strategy”.

Does not support. That the absence of those words is a decision rather than an omission. The paper’s inference — “no assurance programme accompanies them” — is a reasonable reading of the strategy’s silence and is stated as such; it is not something the strategy says about itself. §6.3’s “New Zealand exporters operate within [conformity assessment] for every other regulated good” is the paper’s own generalisation about trade and is not sourced to the strategy or to anything else.

⚠️ Retrieval. The word counts were verified at primary source in earlier work on this series and are reused here. The two quoted phrases in §6.3 were not separately re-checked for this page; they should be confirmed against the document before it goes to the audience named in its frontmatter.

Digital Nations, 2027 meeting chaired by New Zealand

other

Supports. §6.4: New Zealand chairs the 2027 meeting; “a scheduled platform.”

Does not support. §6.4’s preceding sentence — that influence in standards development follows from a national body vote, a working-group seat or an editorship — is a statement about how ISO and IEC work, not about Digital Nations, and is not sourced in the paper.

⚠️ Retrieval. Verified at primary source in earlier work on this series and reused here.

What it derives from#

Foundational documents. These are positions this project has taken, not findings.

None recorded. The publication’s frontmatter names no derives_from record.

Evidence#

Record What it is Status
EVD-11 Recognition rate q — first measurement, model reviewers, 11 September 2026 draft v0.1
EVD-12 July 2026 autonomous-agent intrusion — primary-source record draft v0.1

This paper is tagged requires-evidence and references both records, but quotes neither: it concerns the record substrate, and the measurement in EVD-11 belongs to the detection paper (MIO-POL-02). The incident in EVD-12 is the occasion for the series rather than a premise of any numbered section here.

Also referenced#

Record What it is Status
PUB-33 When an Agent Exceeds Its Authority — “MIO-POL-02”, the detection paper this one is a precondition of draft v0.2
PUB-35 MIO-STD-01 — Attestable Audit of Autonomous Agents over Sealed Record Substrates — §4.6 holds the erasure mechanism §5.4 points at draft

Claims this page could not tie to a source#


Drafted with AI assistance, checked and revised by the author.

Alongside: the publication · questions and answers