Skip to content
Artwork for The Evidence Layer - English

The Evidence Layer - English

Attesto.eu

The Evidence Layer – EN is a podcast about AI, cybersecurity, compliance, digital sovereignty, and the regulations shaping the future of technology.

In a world increasingly driven by artificial intelligence, cloud platforms, and automated decision-making, one question is becoming more important than ever:

How do you prove that something actually happened?

In this podcast, we explore the AI Act, NIS2, DORA, cybersecurity, digital identity, auditability, governance, accountability, and the challenges faced by organizations, governments, and innovators in an increasingly complex digital landscape.

Each episode breaks down complex topics into clear, accessible insights, combining real-world examples, emerging trends, and expert-level analysis. We examine the technologies, regulations, and societal shifts that are redefining trust in the digital age.

From AI decisions and compliance requirements to European digital sovereignty and the future of verifiable systems, The Evidence Layer explores the layer beneath the technology we use every day — the layer of evidence.

The podcast takes an independent and educational approach. In the first episode, listeners are introduced to Attesto, a Dutch initiative focused on bringing cryptographic evidence and verifiability to AI systems. From there, the series expands into the broader worlds of technology, regulation, security, governance, and innovation.

For technology professionals, business leaders, entrepreneurs, policymakers, investors, and anyone who wants to understand how trust is established in a digital world.

Play
  • 8 episodes
  • English
  • S1 · E8
    June 13 · length unknown

    S01E08 - The day the model disappeared: what the Fable 5 export block teaches European organisations about AI evidence liability

    June 9, 2026: Anthropic launches Claude Fable 5 — the most capable AI model ever made available for general use, state-of-the-art on nearly all benchmarks, with major advances in software engineering, knowledge work, and scientific research. Three days later, on June 12 at 5:21 PM ET, Anthropic receives an export control directive from the US government: all access for foreign nationals — including Anthropic's own foreign national employees — must be suspended immediately. Fable 5 and Mythos 5 are abruptly disabled for all customers worldwide. Anthropic complied but publicly objected: the demonstrated jailbreak technique involved known, minor vulnerabilities also discoverable via other publicly available models including OpenAI's GPT-5.5. This is the first time an AI model itself has been treated as strategic export-controlled technology. Michael and Nadine work through four concrete scenarios that emerge the moment the block hits: an EU AI Act audit where a regulator asks which AI version supported which decision; legal proceedings where a customer disputes an AI-driven outcome; vendor dependency and executive liability under NIS2, DORA, and the Dutch Cybersecurity Act; and a cyber insurance claim requiring proof of operational impact. In every scenario the core question is the same: can you prove what actually happened — even when the model is no longer available? Attesto does not prevent a model from disappearing or a government from issuing export controls. But Attesto ensures that every AI interaction — model identity, version, timestamp, prompt hash, output hash, digital signature — is cryptographically recorded beyond dispute via the Proof of Evolution system. The cryptographic black box above AI systems. The Nova/IVC layer is already running live in production.

  • S1 · E7
    June 12 · length unknown

    S01E07 - Sovereign storage is not enough: why European data lakes are missing the evidence layer

    US cloud providers control more than 70% of European cloud infrastructure. Microsoft confirmed under oath at a French Senate hearing in 2025 that it cannot guarantee data sovereignty for European customers facing a legally justified US order. The market's response: European sovereign data lakes that centralise business data from accounting, CRM, HR, and ERP into a private database environment with no CLOUD Act exposure. Sovereign cloud spending in Europe grows 83% year-over-year in 2026. Michael and Nadine explain what a European sovereign data lake does — and what it does not. They walk through how these platforms deliver EU-only data residency, no US sub-processors, open standards without vendor lock-in, and direct AI connectivity. But they also ask the question most providers do not answer: what happens when a regulator does not ask where your data is, but what was done with it — when, by whom, and on which legal basis? An audit log inside a database is not proof — it is a file that can be altered. Built-in logging without cryptographic anchoring is not tamper-evident. And the evolution of compliance over time is something no data lake records. That is the missing layer that leaves organisations exposed during investigations under EU AI Act Article 12, NIS2, DORA, and GDPR Chapter V — even when they run fully European infrastructure. Attesto delivers that layer: cryptographically irrefutable proof via the Proof of Evolution system, on top of any sovereign data lake. The Nova/IVC layer is already running live in production.

  • June 11 · length unknown

    S01E06 - Data is stored in Europe — but does Europe control it? Data sovereignty and the proof of data transport

    Data on a European server is not automatically European. The US CLOUD Act compels American cloud providers to hand over data to the US government — regardless of server location. European supervisory authorities imposed over €7.1 billion in GDPR fines in 2025, a significant share for cross-border transfer violations. The question is no longer whether data leaves the EU — the question is whether organizations can prove it when it happens, and whether they can demonstrate that the legal basis was valid at the time of transfer. Meta's €1.2 billion fine in 2023 set the precedent: paper compliance is not enough. Michael and Nadine walk through the full legislative framework: GDPR Chapter V with its Schrems II obligations (Transfer Impact Assessment mandatory for every Article 46 transfer), the EU Data Act (Regulation EU 2023/2854, applicable from September 12, 2025) requiring cloud providers to block non-EU government access to EU-stored data, and the Data Governance Act as the foundation for European common data spaces. They cover GAIA-X Trust Framework 3.0 "Danube" (November 2025) and the 15+ operational European data spaces — from Catena-X in manufacturing to GAIA-X Health. And they draw the critical distinction: data residency means your data sits on a European server. Data sovereignty means your data is demonstrably subject only to European law — and those are two fundamentally different things. The core insight: contracts, SCCs, and TIAs prove intent, not execution. Supervisory authorities ask for technical evidence of actual data transport. Attesto delivers that layer — tamper-evident logging of every data event as cryptographically irrefutable proof via the Proof of Evolution system. The Nova/IVC layer is already running live in production.

  • S1 · E5
    June 11 · length unknown

    S01E05 - Secure-by-design or off the market: the Cyber Resilience Act explained

    The Cyber Resilience Act — Regulation EU 2024/2847 — entered into force on December 10, 2024, and rewrites the rules for anyone placing software or hardware on the EU market. From smart thermostats to industrial firewalls: all products with digital elements must now meet mandatory cybersecurity requirements. Manufacturers who cannot demonstrate compliance will no longer be permitted to sell in Europe. Maximum penalties: €15 million or 2.5% of global annual turnover. The regulation applies to non-EU companies too — if your product reaches the European market, the CRA applies. Michael and Nadine break down the four risk categories — from the default category (approximately 90% of all products, self-assessment permitted) to Important Class I and II (identity management systems, firewalls, intrusion detection — mandatory third-party or Notified Body assessment) and Critical (Annex IV). They go deep on the core Annex I obligations: secure-by-design and secure-by-default, vulnerability management across the full product lifecycle, mandatory SBOM documentation, a minimum 5-year security update period, and reporting deadlines of 24 hours (early warning) and 72 hours (full notification) via ENISA's CRA Single Reporting Platform. Two CRA obligations apply before the final enforcement date of December 11, 2027: from June 11, 2026, conformity assessment bodies must be notified; from September 11, 2026, vulnerability and incident reporting is mandatory. The core insight of this episode: the CRA does not ask for a snapshot — it demands continuous, demonstrable proof of security across the entire product lifecycle. Attesto delivers that evidence layer: tamper-evident logging for all Annex I obligations, and the Proof of Evolution system to document the measurable progression of vulnerability management and security updates over time. The Nova/IVC cryptographic layer is already running live in production.

  • S1 · E4
    June 11 · length unknown

    S01E04 - DORA in practice: five pillars, one burden of proof

    The Digital Operational Resilience Act — Regulation EU 2022/2554 — has been in force since January 17, 2025, applying to approximately 22,000 financial entities across the EU: banks, insurers, investment firms, payment service providers, and their critical ICT third-party providers. Yet only half are fully compliant. Fines can reach 10% of global annual turnover, and national supervisors across all 27 member states have begun active enforcement. On November 18, 2025, the European Supervisory Authorities designated 19 critical ICT providers — including AWS, Microsoft Azure, and Google Cloud — now subject to direct EU oversight. Michael and Nadine walk through all five DORA pillars in detail. Pillar 1 mandates a full ICT risk management framework with board-level governance responsibility. Pillar 2 requires standardized classification and prompt reporting of major ICT incidents to competent authorities without undue delay. Pillar 3 makes periodic resilience testing mandatory — including Threat-Led Penetration Testing (TLPT) for significant institutions. Pillar 4 holds financial entities accountable for the ICT risks of their suppliers: outsourcing is no longer a liability shield. Pillar 5 requires the structured sharing of cyber threat intelligence between financial entities. The core insight of this episode: DORA does not ask for a one-time certification — it demands continuous, demonstrable evidence of operational resilience. That is exactly what Attesto delivers: tamper-evident event logging for Pillars 1 and 2, and the Proof of Evolution system for Pillars 3 and 4. The Nova/IVC cryptographic layer is already running live in production.

  • S1 · E3
    June 10 · length unknown

    S01E03 - The law is here: EU AI Act and the Dutch Cybersecurity Act, unpacked

    August 2, 2026 is no longer on the horizon — it's now. Michael and Nadine break down what Article 12 of the EU AI Act technically demands, why the Dutch Cybersecurity Act makes executives personally liable, and how organizations can achieve demonstrable compliance — not just on paper, but with cryptographically verifiable proof.

  • S1 · E2
    June 10 · length unknown

    S01E02 - Can You Trust What You See? The Rise of C2PA

    AI can now generate images, videos, voices, and documents that are nearly indistinguishable from reality. As synthetic content becomes increasingly common, a new question emerges: how can we verify what is authentic? In this episode, we explore C2PA (Coalition for Content Provenance and Authenticity), the emerging open standard designed to bring transparency and provenance to digital content. We explain how content credentials work, which companies are adopting them, and why provenance may become one of the most important building blocks of trust in the AI era. From deepfakes and manipulated media to journalism, compliance, and digital evidence, we examine how C2PA aims to answer one of the defining questions of our time: Can we still trust what we see online?

  • S1 · E1
    June 10 · length unknown

    S01E01 - Why Trust Is No Longer Enough

    Artificial Intelligence is making decisions, cybersecurity threats are becoming more sophisticated, and new regulations are reshaping the digital landscape. Yet most organizations still rely on a surprisingly fragile foundation: trust. In this premiere episode of The Evidence Layer, we explore why trust alone is no longer sufficient in a world of AI systems, cloud platforms, automated decisions, and growing regulatory demands. We discuss the rise of verifiable systems, cryptographic evidence, auditability, and accountability, and why proving what happened may soon become more important than claiming it happened. We also introduce Attesto, a Dutch initiative focused on bringing cryptographic proof and verifiability to AI systems and digital processes. Whether you're a technology professional, business leader, policymaker, or simply curious about the future of trust in the digital world, this episode lays the foundation for everything that follows.

Showing 1–8 of 8 episodes