eIDAS 2.0 and Digital Evidence: The Timestamp On-Chain as a Guarantee of Integrity V-PROOF

Regulation · eIDAS 2.0 · Digital Evidence · September 27, 2026 · Reading time: 5 min.

A record serves as evidence only if someone who did not create it can verify two things: when it existed and that it has not changed since then. The European Regulation on electronic identification and trust services, eIDAS, is the framework that gives legal effect to these verifications throughout the Union. And its reform, known as eIDAS 2.0, expands the list of recognized tools.

What Is eIDAS 2.0?

Regulation (EU) 2024/1183 amends Regulation (EU) No. 910/2014 (eIDAS) and entered into force in May 2024. Its two major new features are the European digital identity wallet, which Member States must make available to citizens and businesses, and the expansion of recognized trust services, which now include electronic archiving, electronic attribute statements, and electronic ledgers.

With regard to AI governance, what is important is that eIDAS establishes the legal effect of an electronic record with a date and time stamp, and the difference between a qualified service—provided by a supervised provider listed on the trusted lists—and a non-qualified service.

How to Build Verifiable Evidence

Robust digital evidence does not depend on storing the document in a secure location, but rather on being able to verify its integrity from the outside. The process consists of four steps:

From Documentation to EvidenceWhat Each Step Contributes
  1. Document or decisionA report, an approval, an AI output
  2. Cryptographic fingerprintA unique hash (SHA-256): if you change a comma, the hash changes
  3. TimestampProvides evidence that the fingerprint existed on a specific date and time
  4. External anchorThe fingerprint is recorded outside the system that generated it
  5. VerificationA third party recalculates the digital fingerprint and compares it, without accessing the content

Qualified and unqualified: what changes when dealing with a judge or an auditor

eIDAS does not require the use of qualified services, but it does give them greater probative value. The basic rule is the same for time stamps (Article 41) and for the new electronic ledgers:

UnqualifiedQualified
Legal EffectIt cannot be denied legal effect or admissibility as evidence merely because it is electronic or unqualifiedLikewise, and furthermore…
Legal PresumptionThere is no presumption: its validity is assessed on a case-by-case basis, depending on how it was generated and whether it can be verifiedThe accuracy of the date and time and the integrity of the data are presumed
Who provides itAny providerA qualified provider that is supervised and listed on the EU’s trusted lists

A general overview of the eIDAS framework. For a specific case, consult your legal advisor.

Where does it fit in? V-PROOF

V-PROOF generates a cryptographic fingerprint for each piece of evidence, associates it with the date and time, and anchors it outside the organization and outside the platform itself. This allows a third party to verify the integrity of a record without accessing its content or relying on the party that stores it.

V-PROOF is not a qualified trust service provider. Its evidence is designed to be submitted as electronic evidence, and under eIDAS, it cannot be rejected solely because it is electronic; however, it does not enjoy the legal presumption afforded to qualified services. When a process requires it—for example, in a contractual signature or in a procedure with formal requirements—the organization may combine it with a qualified signature or time stamp from a registered provider. These are complementary layers.

What to Review Today

  • What AI logs might need to be provided as evidence: approvals, human oversight, model results, and code changes.
  • If those records can be verified today without accessing the systems that generated them.
  • In which processes is a specialized service also required, and which provider should be used?

Request an exposure assessment →

Previous
Previous

FFUUSS · OTS GROUP: AI compliance under five concurrent ISO certifications, without a single nonconformity

Next
Next

"V-PROOF: The Trusted Infrastructure EU AI Act by the EU AI Act "