01

Evidence readiness must begin before the incident

The European Union's Cyber Resilience Act has reached an important operational milestone.

From 11 September 2026, manufacturers of products with digital elements within scope must report certain actively exploited vulnerabilities and severe security incidents. An initial warning may be required within 24 hours of awareness, followed by more detailed information within 72 hours.

That timetable changes the practical value of evidence.

When an incident occurs, an organisation cannot assume that it will have days to reconstruct what happened from incomplete logs, disconnected tools and human recollection.

Evidence readiness must begin before the incident.

02

An authority decision is only one part of the record

Consider an AI-enabled software agent responding to a suspected cyberattack.

It might propose revoking credentials, isolating a service, changing a configuration or deploying a security update.

A useful incident record needs to distinguish several separate events:

  • The threat or condition detected.
  • The action proposed by the agent.
  • The governed context available at that moment.
  • The authority applied to the proposal.
  • The decision returned.
  • The action that became effective.
  • The resulting security impact.

A record showing that an action was authorised does not independently prove that the executor performed it. Nor does evidence of execution prove that the action was properly authorised.

Both sides of the boundary matter.

03

Reporting requires provenance, not merely volume

Collecting more logs does not automatically create better evidence.

Useful evidence must remain connected to the event it describes. Investigators need to understand which agent, person or system produced a request; which target and parameters were involved; whether the request changed; and how the effective outcome relates to the earlier decision.

This becomes especially important in agentic environments, where software can explore alternatives and generate actions faster than a person can review them individually.

If an agent changes the target, scope or intended effect, an earlier authority may no longer apply.

04

Evidence must support intervention

Operational evidence is not only retrospective.

Current, trustworthy information may be necessary for a system to decide whether an action should proceed at all. Where essential context or evidence is missing, stale or contradictory, the appropriate outcome may be to deny the action, reduce its scope, seek additional authority or stop the line.

PF Systems separates these responsibilities within PF OS: PF Memory knows. PF Core proves. PF Kernel decides.

PF Memory supplies governed context. PF Kernel applies authority to a proposed action. PF Core preserves linked evidence of the governed evaluation.

That evidence may contribute to investigation and reporting, but it does not replace vulnerability management, security telemetry, executor evidence, legal analysis or the reporting systems required by regulators.

PF Systems does not make the underlying probabilistic AI deterministic, certify Cyber Resilience Act conformity or guarantee that an incident will be prevented.

The wider principle is straightforward: when the reporting clock begins at awareness, evidence cannot begin with reconstruction. It must already exist in the operating path.

05

Sources

Public sources supporting the factual statements in this perspective. Reported statements and company or vendor-reported results are identified in the article.