How this was made. The version number counts drafts of the text. It does not measure the inquiry behind it, which has run over days and across several AI systems, with argument between those systems and within them, directed, refused and repeatedly redirected by the author. The source material was AI-generated, and then adversarially and iteratively refined across a range of tools — systems built by different companies in different jurisdictions, set against each other and against the author. No one of them produced this text, and no one of them reviewed it alone. The plurality is deliberate rather than incidental. A single model carries a single set of priors about which sources are authoritative, and this series argues that an evidence base narrowed in exactly that way is how a contested question comes to look settled. Using one model to investigate that claim would have been the claim refuting itself. To name a single model on it would credit that model with work that was neither its own nor done in a single pass. The plurality was also necessary, and the record should say why. In drafting, the assisting model repeatedly led with United States institutional sources — a national laboratory, an industry association, a market study nineteen years old — and presented conclusions drawn from them as the state of knowledge. On one occasion European measured data contradicting those conclusions was present in the same research return and was placed below them. Framings were proposed that would have argued against this series’ own position using that evidence base, and offered as rigour. Each was refused by the author and the material rebuilt. That is the mechanism these documents describe, occurring in their own making, and it is recorded because a series arguing that evidence bases narrow without anyone deciding to narrow them cannot credibly claim its own production was exempt. The framing, the corrections and the judgements are the author’s, and so are the errors. How this site is written sets out what is declared on every piece, who checks it, and where the per-piece record lives.
What this publication does not claim, and what is outstanding against it in the register.
Nothing outstanding in the register. Every claim in this publication has its evidence recorded, and no question against it is parked. That is a statement about this publication on the date shown above, generated from the register rather than asserted, and it will change when the register does.
What this publication rests on, and how solid each part of it is. What we know and what we don’t is an essay reporting the project’s own measurement and build, and this page describes it as one.
This publication cites few outside sources, and they are listed below — each with what it supports, and with what it does not support. That second column is the one that matters: the common failure is not a fabricated source, it is a real source stretched past its finding.
Almost everything in this essay is the project’s own: a measurement (EVD-11), a draft standard (PUB-35), and a description of what is running. Those are recorded under Evidence and Also referenced. The outside references are the standard the running system uses, the European regime it is measured against, and one negative claim about the New Zealand market.
standard
Supports. “Roots attested by an RFC 3161 authority” — that the running substrate obtains time-stamp tokens under this protocol.
Does not support. “Independent of the operator” is the project’s requirement, not the protocol’s. RFC 3161 says a time-stamp authority “may be operated as a Trusted Third Party (TTP) service, though other operational models may be appropriate, e.g., an organization might require a TSA for internal time-stamping purposes.” Conformance to the RFC therefore does not by itself establish independence; the essay’s separate statement that the authority is outside the operator’s control is what does, and it is a statement about the deployment, checkable only against the deployment.
⚠️ Retrieval. Retrieved on 11 September 2026 from the IETF datatracker by the AI agent that compiled this page; title, date and abstract checked.
other
Supports. The essay’s own concession: the running substrate uses a single time-stamp authority, located in Poland, that is not on the EU trusted list as a qualified provider; and therefore does not meet the draft standard’s requirement of two authorities under distinct jurisdictions.
Does not support. The provider is not named, so nothing about it can be checked from the essay — not its location, not its qualification status, not its practice statement. The essay is describing its own supplier; the claim is verifiable against the deployment’s records and not against any document this page can point at.
⚠️ Retrieval. ⚠️ Not retrieved. No provider is named. The statement rests on the project’s own configuration.
regulation
Supports. The distinction the essay draws between an attestation authority that is eIDAS-qualified and one that is not, and the legal presumption a qualified time stamp carries under Article 41(2) — the reason qualification matters.
Does not support. That a New Zealand deployment would gain that presumption by using a qualified European provider. The presumption is one of European law; the companion policy paper leaves its weight before a New Zealand tribunal to counsel, and this essay does not claim otherwise.
⚠️ Retrieval. Article 41(2) was verified at primary source in earlier work on this series and is not re-opened for this page. The EU trusted list, against which “not eIDAS-qualified” would be checked, was not opened.
other
Supports. Nothing outside itself. This is a negative claim about a market, marked in the essay as the finding that makes the gap “an opening rather than a shortfall”.
Does not support. It cannot be tied to any source, and this page found none. A negative finding of this kind needs at least two searches that disagree about method, and the essay records none. The defensible form is the one the companion paper uses elsewhere in this series: no such provider was found, not none exists. This is the claim in the essay most exposed to a single counterexample, and a New Zealand provider of RFC 3161 time-stamping — qualified or not — would refute it as written.
⚠️ Retrieval. ⚠️ Not retrieved; there is nothing to retrieve. No search is recorded in the essay and none was run for this page.
report
Supports. The third falsifier — “if the owner of those models in fact carried the victim’s bill” — assumes the incident described in Part 1 and adds nothing to it.
Does not support. Nothing in this essay is drawn from the incident documents directly.
⚠️ Retrieval. Not re-opened; see EVD-12 and the sources page for Part 1.
Foundational documents. These are positions this project has taken, not findings.
None recorded. The publication’s frontmatter names no derives_from record.
| Record | What it is | Status |
|---|---|---|
EVD-11 |
Recognition rate q — first measurement, model reviewers, 11 September 2026 | draft v0.1 |
EVD-12 |
July 2026 autonomous-agent intrusion — primary-source record | draft v0.1 |
EVD-11 is the measurement this essay reports: twenty-five records, five agent types, thirteen planted breaches at three disguise levels after two withdrawals, twelve clean records of which three were built to resemble breaches, three model reviewers, a fourth party rating difficulty without ground truth. The figures 100 / 92 / 58 per cent and 0 of 36 false positives are its result; 73 → 92 and 47 → 58 are the movement caused by withdrawing the two records the author had wrongly planted as breaches. The record’s own limits govern this essay: model reviewers only; four planted records at each of the two harder levels; imperfect independence between records; synthetic material written by the person who planted the breaches; one mandate, one setting. A magnitude, not a rate. The essay’s closing note says the same.
| Record | What it is | Status |
|---|---|---|
PUB-34 |
Addendum M — Mathematical Strategies for Timelined Detection — “the formal statements”, graded established / conjectured / open | draft |
PUB-35 |
MIO-STD-01 — Attestable Audit of Autonomous Agents over Sealed Record Substrates — “the draft standard”, marked not submittable; its clause nine lists the six things to be settled first, and §4.6 the erasure mechanism | draft |
PUB-29 |
Cheaper not to look — Part 1 | draft v0.2 |
PUB-30 |
What it takes — Part 2 | draft v0.1 |
FIG-38 |
drawn for this publication · figures/FIG-38.svg |
EVD-11 only as a run date.Drafted with AI assistance, checked and revised by the author.
Alongside: the publication · questions and answers