Correction — 31 July 2026

This piece got an important thing wrong, and the correction is below rather than in place of it.

It said that anyone claiming the agreement exposes Māori data “will be asked to point at the provision, and there isn’t one”. There is one. Article 14B.2 of the agreement — Traditional Knowledge and Traditional Medicine — provides for cooperation on traditional knowledge, and 14B.2(h) covers “the development and use of emerging technologies for the preservation and restoration of traditional knowledge and traditional medicine systems, including artificial intelligence-based software, e-commerce, and digital distribution platforms”.

This piece analysed Chapter 13 and did not address Chapter 14 or its Annex 14B at all. The people raising the alarm were pointing at a real clause. We told them they were not. That was wrong, and it was the most confrontational thing in the piece.

The argument itself is unchanged, and 14B.2(h) makes it stronger: a treaty provision that contemplates AI systems and digital distribution applied to preserving traditional knowledge is precisely why a durable record of who held what, and on what terms, matters. The corrected passage is at §2a.

On how the error happened. The draft was prepared with the help of a US-hosted AI system and checked by a process that validated every citation against a primary source. That process caught six errors. It could not catch this one, because a claim that something does not exist has no citation to validate. The lesson is not that the checking was skipped — it is that checking citations does not check claims of absence, and material this consequential needs someone to read the agreement.

The original text is unchanged below and its sealed record stands. This correction is sealed separately. That is the point of sealing: a mistake stays on the record, and so does the date it was put right.

Précis

New Zealand’s trade agreement with India has raised a real worry: that traditional knowledge — rongoā Māori in particular — could be documented, exchanged and built upon without anyone’s consent. The worry is justified. The usual explanation of it is not.

There is no e-commerce or digital trade chapter in the agreement. The CPTPP mechanism the Waitangi Tribunal examined — where it found the Crown’s reliance on the exceptions and exclusions, the Treaty exception among them, fell short of active protection — is not the one operating here. The exposure is narrower, more specific, and much harder to wave away: a cooperation chapter that names rongoā Māori, includes documenting and exchanging it, and attaches no consent step to any of it.

This piece argues that the instinctive response — assert ownership, tighten secrecy — cannot carry as far as people expect. The reason has nothing to do with politics. It is that keeping something hidden depends on nobody ever being able to open it, and the cost of opening things falls every year. Material taken today can be stored until it becomes readable. Any protection that works by concealment is therefore on a clock.

The alternative is not weaker. It is a different claim altogether — custodianship: who holds this, since when, on whose behalf, and on what terms it was shared. That claim does not depend on the secret holding, so nothing about it weakens when the secret goes.

Making it work needs two things. The first is a record that cannot be back-dated, and that can be built now. The second is the harder half, and it is not a technical problem at all: getting institutions — funders, examiners, publishers, buyers — to treat such a record as something they must look at before proceeding. China has done that by decree. The rest of us have the option of getting there by argument instead.

Two things this piece is not arguing. It is not arguing that anyone should move their holdings to a vendor. Iwi organisations already run platforms and already state custodial obligations, and what is described here attaches to that work rather than replacing any of it. And it is not arguing that we should be the ones fixing the date. Three parts of the record belong to whoever holds the material; the fourth has to come from outside, and ours currently comes from a company in Poland. That is a dependency worth removing rather than defending, and §4 sets out what removing it would involve — including an offer to help build the alternative and a statement of why we should not operate it.

Where I stand. I am not Māori. Nothing here is written for Māori, on anyone’s behalf, or as a view about what any iwi, hapū or whānau should do with knowledge that is theirs. What follows is an argument about a general mechanism, and about what protection-by-secrecy can and cannot deliver over time. Whether any of it is useful in a rongoā context is not mine to say, and this piece makes no claim to have solved a te Tiriti problem.

And my interest, up front. My company builds a service that does what this essay argues for, and sells some of it. Rather than leave that to be discovered at the end, the commercial side is set out separately and in full — what it costs, what it does not do, and which parts are not on sale yet — at What it costs. Nothing in this essay depends on buying anything, and the argument should be judged as though we sold nothing at all.


Contents

  1. The question people are asking
  2. What the agreement does, and what it does not
  3. What ownership and secrecy can and cannot carry
  4. Custodianship, and who already practises it
  5. The two things that have to happen
  6. The mark, and how to read it
  7. Jurisdiction, and what New Zealand might do
  8. What this does not do

1. The question people are asking

The question arrives in different words depending on who is asking, but underneath it is always the same one: if our knowledge is written down and shared with a foreign partner, what stops it being used in ways we never agreed to?

It is a good question, and it deserves better than reassurance. It also deserves a more accurate description of the risk than it usually gets, because an argument built on the wrong clause invites the reply “which clause?” — and loses.

2. What the agreement does, and what it does not

The premise the argument usually starts from is wrong, and correcting it makes the case stronger.

The agreement contains no e-commerce or digital trade chapter. No cross-border data flow provisions, no data localisation clause, no source code article. So the mechanism at issue in Wai 2522 — where the Tribunal found that the Crown’s reliance on the exceptions and exclusions fell short of active protection, data being part of mātauranga Māori and mātauranga being taonga — is not what is operating here. Anyone who opens with “the India agreement exposes Māori data” will be asked to point at the provision, and there isn’t one.

2a. Correction to this section — 31 July 2026

The paragraph above is wrong where it says “there isn’t one”, and the rest of this section reads the right conduct off the wrong instrument. The absence of a chapter is not the absence of a provision.

Article 14B.2 — Traditional Knowledge and Traditional Medicine. It sits in Annex 14B, under Chapter 14 (Economic Cooperation and Technical Assistance), and it is the clause the concern actually rests on. It records that the Parties “recognise their respective heritages and mutual interest in traditional knowledge and traditional medicine”, and agree to “enhance their bilateral cooperation” in that field. It then lists the activities they may undertake — among them facilitating exchanges of traditional knowledge experts and practitioners, joint research collaboration “including through use of biotechnology”, and developing pilot projects “to facilitate the appropriate integration of traditional knowledge, in market ready products”.

And 14B.2(h):

“strengthening cooperation on the development and use of emerging technologies for the preservation and restoration of traditional knowledge and traditional medicine systems, including artificial intelligence-based software, e-commerce, and digital distribution platforms.”

So the agreement does contemplate traditional knowledge being handled by AI systems and distributed through digital platforms. It says so in terms.

The qualifier in 14B.2(2) is real and worth reading exactly: the Parties may undertake these activities “while respecting any rights, interests, duties, and responsibilities of holders of traditional knowledge and traditional systems of medicine”. That is a respecting clause, not a consent gate. It names no holder, defines no process, and attaches no consequence to proceeding without agreement. Annex 14B contains no consent provision at all — checked, not assumed.

This does not weaken the argument that follows. It is the argument. A treaty provision that expressly anticipates AI-based software and digital distribution applied to the preservation of traditional knowledge — with a respecting clause and no consent process — is the clearest possible statement of why the gap matters.

Chapter 13 remains relevant and is described accurately below; its quotations have been re-checked against the primary text and they hold — the te Tiriti “should”, the sentence that the chapter “does not impose any legal or financial obligations”, India’s footnote, and the rongoā/AYUSH pairing. Its claim that no consent gate exists anywhere in Chapter 13 was also re-tested and is correct. One small overstatement stands uncorrected in the text below: rongoā Māori is named twice, not “repeatedly”. But 14B.2 is the operative provision, and this piece should have led with it.


The exposure is the cooperation chapter, and it is real. Cultural, Trade, Traditional Knowledge and Economic Cooperation names rongoā Māori explicitly and repeatedly, pairing it with India’s AYUSH systems. Its listed activities include exchanging, preserving and documenting traditional medicines and healing systems; exchanges of data and information; and undertaking joint research projects and publications.

No consent gate exists anywhere in that chapter. Cooperation “should be implemented in a manner consistent with te Tiriti o Waitangi” — a should, with no process attached to it — and the chapter states that it “does not impose any legal or financial obligations requiring the Parties to explore, commence or conclude any individual cooperation activities”. That cuts both ways. Nobody is obliged to undertake anything; equally, the te Tiriti language carries no enforcement hook. India’s own footnote records its position that after independence all Indians are indigenous, so free, prior and informed consent will not operate symmetrically on both sides even where both parties affirm it.

The gap, then, is not data leaving the country. It is this: once knowledge is documented and shared, no durable, independently checkable record exists of who held it, who agreed to what, and on what terms.

That is the WAI 262 pattern — the Tribunal claim concerning Māori rights in indigenous flora, fauna and cultural knowledge — and it is the gap worth closing.

3. What ownership and secrecy can and cannot carry

The instinctive response to that gap is to assert ownership and tighten secrecy. Neither carries as far as people expect.

Ownership is the wrong question because of what a property claim is: exclusive, transferable and expiring. Traditional knowledge held by a hapū is none of those things. It is not meant to be transferred, it is not meant to expire, and the people who hold it are not holding it as an asset. Worse, the sharpest instrument in the set — patent — requires you to publish the thing in order to protect it. So the ownership frame forces a choice between two bad outcomes: disclose knowledge that was never meant to be public, or hold a claim the system does not recognise.

Secrecy fails for a different and harder reason. Encryption that is sound today is not sound indefinitely, and an opponent does not have to break it now. They can copy the encrypted material today, store it, and open it whenever the cost of doing so falls far enough — which is why security people call it harvest now, decrypt later. The date that happens is not knowable, and it does not need to be: what matters is that the direction is one-way. Computers do not get worse at this.

So when someone says a body of knowledge is protected because it is locked away, the protection has a date on it. Nobody knows the date, nobody controls it, and the people relying on the protection will not be told when it passes. That is not a gloomy view of the future. It is the ordinary behaviour of computing applied to a claim that assumed it would not apply.

What does not decay is an assertion that cannot be back-dated. A sealed, dated record is not a secret and was never trying to be one. Its value lies entirely in when it was made: a record created on Tuesday cannot later be made to look as though it was created a decade earlier, because the proof of its timing was fixed by an outside party at the moment of creation. Break every cipher in the thing itself and the claim survives untouched — this was held here, since then, on these terms. Secrecy has an expiry date. Timing does not, because the evidential work was already finished.

That is the whole move: stop trying to keep the secret, and start being able to prove when you had it.

4. Custodianship, and who already practises it

Custodianship asks a different question from ownership. Not who owns this but who holds this, since when, on whose behalf, and on what terms it was shared. It is a claim about relationship and obligation rather than about property, and it survives the collapse of secrecy because it never depended on secrecy in the first place.

This is not a novel idea in need of a vendor, and it is not waiting to be invented.

Te Kāhui Raraunga, working on behalf of the Data Iwi Leaders Group, has published the Māori Data Governance Model and built Te Whata — a data platform made, in their words, “by iwi for iwi”. Te Hiku Media leads Papa Reo, a language platform with te reo Māori speech recognition in real use, and wrote the Kaitiakitanga License — under which, in their words, data “is not owned but is cared for under the principle of kaitiakitanga”, with “any benefit derived from data” flowing “to the source of the data”.

Both were in place before we wrote a line of code.

That licence sets out the same logic this piece is arguing for, earlier and better, written by the people it concerns. Nothing here improves on it. Nothing here was done with the involvement, input or endorsement of any of those organisations, and none of them has been approached. The licence’s own terms require Te Hiku Media’s permission before anyone uses or adapts it — so this essay describes it, and claims no relationship to it whatever.

What this adds, and where it attaches

A fair question. The answer is narrower than it might look, and it is an addition to what those organisations already run rather than an alternative to any of it.

A licence states terms. A platform holds material. Neither produces the third thing — a dated, signed, per-item record that this was held by this body since this date, and shared with that party on those terms. Checkable by a stranger who has never heard of any of us, offline, years later, against a key the holder publishes and controls.

That is the whole of the addition. Not custody, which iwi organisations already have and run. Not governance, which is not mine to offer. A record of an act of sharing, fixed at the moment it happened by an outside authority with no stake in the outcome.

And it does its work at exactly one point: the moment material leaves. A platform protects what is inside it. A licence states how a thing should be treated once it is out. Neither leaves behind evidence of when it went, to whom, and on what basis — which is precisely the gap Chapter 13 opens, and precisely what is missing when a dispute arrives years later.

Which is why the useful shape here is a layer rather than a rival. Te Whata holds material now, and would hold it in exactly the same way with sealing attached to it. The Kaitiakitanga License states obligations now, and would state the same ones — carried inside the record, in Te Hiku Media’s wording, not restated in ours. Neither has to change for the sealing to be worth something. If it is any good, what it does is make what those organisations already do harder to dispute years later. That is the entire claim being made for it.

Whether that is worth having, and whether it belongs anywhere near taonga, is not for me to say. The mechanism is general. If it is useful, it should attach to custodians who already exist rather than ask anyone to move their holdings to a vendor.

The clock is the part that should not be ours

The record has four parts, and three of them belong to whoever holds the material: the hash, the signing key, the terms. The fourth cannot. The date has to be fixed by somebody with no stake in the outcome, or it establishes nothing — a custodian who timestamps their own records has written a date on their own piece of paper.

For the artefacts attached to this essay, that outside party is Asseco Data Systems, a company in Poland. It works, and it is a proof of concept rather than the arrangement anyone should want. It demonstrates that the whole chain holds end to end — seal, stamp, publish, resolve — using an authority nobody involved has any relationship with, which is the point of the demonstration. It also leaves the durability of a New Zealand custodial claim resting on a Polish company’s signing key and on that company continuing to exist, which is not a state of affairs to settle for.

There is no technical reason for it. A timestamping authority under RFC 3161 is not a licence anyone grants. It is a signing key held in hardware, a clock traceable to a time standard, a published statement of how the thing is run, and a log. Nobody’s accreditation is required to operate one. What an accreditation regime buys is a presumption inside one jurisdiction’s courts, which is a separate question from whether the timestamp is sound. An authority’s worth rests on who is willing to trust the body running it — a governance question, not an engineering one, and therefore not ours.

A timestamping authority operated under Māori governance is buildable, and it would not only serve Māori. Indigenous communities elsewhere have the same shape of problem, and every one of them currently borrows its clock from a European or American company. An authority run by one of them, for any that wanted to use it, would be infrastructure that does not exist anywhere at present.

The right end state is several authorities in several jurisdictions rather than one, for the same reason a distributed arrangement beats a central registry: no single body ends up fixing the dates on everybody else’s claims, and no single failure takes the lot. So this is not an argument for one authority to rule them, and other authorities elsewhere are not rivals to it. A Māori-governed one is distinguished by something simpler — it is the one that nobody else is in a position to build.

We would help build it, and we should not be the ones running it. We have built the client half — the sealing, the record format, the verification — and would work on the authority half with whoever ought to own it. The engineering is a known quantity; the governance, the trust and the standing to operate such a thing are the hard parts, and none of those are ours to supply. The offer is open, it is not attached to buying anything from us, and it is not disinterested either: our own records would be better off pointing at that clock than at Asseco’s.

Nobody has been approached about any of this, and nothing above should be read as a conversation already under way. It is an offer made in public, which is the only way I can make it without presuming on anyone.

What it would actually take

An offer that skips the cost of accepting it is not much of an offer. So, plainly: most of what a timestamping authority requires is not software, and none of the difficult parts can be contracted out to us or to anyone else. What follows applies to any body that wanted to run one — the terms would be the same whoever asked.

A legal entity with continuity. The entire worth of a timestamp is that it still means something in thirty years. That depends on the body outliving the people who set it up, and on it being the sort of entity that can hold a key, answer for it, and still be there. This is the hardest requirement and it is nothing to do with engineering.

A decision about who it serves, and on what terms. Who may request a stamp. At what cost, or none. On what grounds a request is refused, and who decides that. Whether it serves other indigenous communities from the start or later. None of this can be delegated to a supplier, and a supplier who offered to draft it for you should be shown the door.

Custody of the signing key, under dual control. The key is generated in the operating body’s custody, held in hardware in a named place, and used under a written procedure requiring two people. We would not hold it — not in operation, and not during commissioning. A key that passes through a vendor’s hands has already lost the thing that made it worth having.

A published practice statement. What the clock is traced to. How the key is protected. What happens if it is compromised, who is told, and how quickly. How long records are kept, and what happens to them if the body winds up. Written to be read by a sceptic.

Someone on call, permanently. An authority that is down when you need to seal something is worse than no authority, because people plan around it. This is an operating commitment without an end date, and it is where the real cost sits — not in the build.

A succession plan for the key. Most of the ways this fails are organisational rather than technical: a restructure, a merger, a wind-up, a falling-out. Decide in advance what happens to the key, in writing, before it exists.

None of which means it has to be a cost centre, and I should say so before the list of burdens is mistaken for the whole picture. An authority can charge for what it does. The parties who need one are not only indigenous communities: anyone with a sovereignty requirement is currently borrowing an American or European clock, which takes in Pacific governments, agencies here, and firms that would rather not explain to a customer why their evidence depends on a company in Warsaw. So whoever operates one has a service others would pay for, and not only an obligation to carry. I am not going to put a number on that, because I do not have one and inventing it would be worth less than nothing. What I can say is that the demand is not hypothetical, since we are an instance of it — our own records would be better off pointing at such an authority, and we would pay to use it.

Our half is bounded by comparison: the responder, the certificate chain, the hardware integration, clock traceability, the log, the monitoring, and the handover — source, documentation and training, transferred outright. We would contract on terms that let the body dismiss us and keep operating, because a thing that cannot survive our removal has not been built, it has been rented. We would be a supplier and not a partner in the authority: no equity, no seat, no say in who it serves.

I would rather state that and be turned down than imply this is easier than it is.

The design consequence: distribute, do not centralise

If custodianship is a role rather than a product, then the obvious move for a software company — become the custodian, hold everyone’s material, sell access to it — is the wrong one. It rebuilds the centralised arrangement the whole argument objects to, with a commercial party in the middle instead of a Crown one.

So the rule we build to is: do not aim to be the custodian. Be able to work with custodians that already exist. Three things follow.

A custodian can be someone else, and the system has to cope with that. A body that runs its own storage should be able to hold its own material and still have the record point at it. Our software should be one option among several, not the only address that works.

The keys move with the custody. If a body takes custody, it takes the keys — and the change is made for that body alone, not by a switch that moves everyone at once. A mechanism capable of silently redirecting every organisation’s signing is a mechanism worth attacking, so it does not exist.

The terms travel with the record, in whoever’s words wrote them. Where an instrument already exists for expressing custodial obligations — the Kaitiakitanga License is the obvious one — the record carries that, rather than a vocabulary we invented and asked people to adopt.

The pattern is the same one that makes a federation of small bodies more durable than a single large one: many holders, each accountable for their own material, none of them a single point of failure and none of them able to speak for the rest. It is slower to build and harder to sell. It is also the only shape that does not reproduce the problem it claims to solve.

Whether any particular knowledge should be recorded at all is a tikanga question, not a technical one.

5. The two things that have to happen

The first we can do now. An immutable record of provenance: the thing itself fingerprinted — reduced to a short value that changes if a single byte of it changes — the holder identified by an identity they control, the moment fixed by a timestamp from an authority with no stake in the outcome, and, the part that matters most and is most often left out, the terms on which it was shared, recorded at the time and signed by whoever granted them.

That last element cannot be retrofitted. A permission history added afterwards is just an assertion about the past. It has to be captured when the grant is made, by the party making it. Records sealed without it can never be given a permission history later. This is the cheapest thing to do today and the most expensive thing to have skipped.

The second is the harder half, and it is political rather than technical. A record of provenance is only worth as much as the number of people who bother to look at it. If a research funder never asks where the material came from, if a patent examiner never checks whether a prior claim exists, if a journal never asks on what terms a contribution was shared, then the record is a well-built thing that changes nothing. The mechanism has to become one of the questions that gets asked as a matter of course.

China has done that by decree. Its Measures for the Labelling of AI-Generated Synthetic Content, in force since 1 September 2025, do not rely on anyone choosing to check. They place duties on the services that generate material and on the platforms that distribute it, and they prohibit removing, altering or forging a label — with enforcement running through other laws rather than through the measures themselves. How well it works is too early to judge. The design is worth studying, and it is not the only way.

The democratic alternative is slower, and it rests on two habits rather than one law.

The first is public understanding. Most people have no idea what a provenance claim is, which means they cannot tell a real one from a badge a company drew itself. The habit worth building is an ordinary one: when something matters, ask where it came from and who is willing to stand behind that answer. It is the same instinct people already apply to a builder’s quote or a second-hand car. It does not need to be technical to work.

The second is what happens when someone abuses the arrangement. Under a decree, the answer is a penalty, and the penalty does the work. Without one, the work has to be done by exposure: if a body takes material it had no permission to take, the record makes that visible and checkable by anyone who cares to look — including journalists, competitors, funders and the people it was taken from. The cost falls on reputation and future dealings rather than on a fine. That is weaker in any single case, and it has one advantage a penalty regime does not: it does not require anyone to be trusted with the power to decide who gets punished.

That is accountability by collaboration instead of by decree. It asks more of everyone, and it will sometimes fail where a penalty would have worked. It is also the version a free society can live inside for longer, because a rule enforced by decree lasts exactly as long as the people holding the pen remain reasonable — and nobody gets to guarantee that for the next fifty years.

6. The mark, and how to read it

A visible mark on a record is useful. It is also the part most likely to be misunderstood.

The mark is a locator, not a proof. It says look this up. It never says compare this. That distinction is not fussiness; it is the finding that reshaped the whole design.

A short displayed fingerprint carries far less security than people assume. Six hexadecimal characters is twenty-four bits, and on ordinary hardware a forger can grind out a match in seconds. The obvious remedy — show more characters — makes things worse rather than better. A study of 162 participants comparing key fingerprints against crafted near-matches found false acceptance rising with length: 13% at twenty digits, 31% at forty, 44% at sixty.1 A separate study of 1,047 participants, comparing formats rather than lengths, found hexadecimal the representation people were most often fooled by.2 Practice looks worse than the laboratory: in large, technically literate organisations, out-of-band checking is reported as close to non-existent.

On that evidence, no displayed length makes comparison by eye reliable. Every workable fix routes the comparison through a machine — which means the mark was never the product. The mark points; a resolver — the lookup service the mark refers you to — does the comparing.

The emblem we settled on is an anchor with a weighted crossbar. It was chosen over a seal, a cupped holding shape, and a thread-back device, for three reasons. It carries the right claim — held fast, fixed in time — without claiming the content is true. It is the only one of the candidates that stays legible when it shrinks to the size of a favicon. And the crossbar reads as a line drawn through time, which is what a timestamp is.

It is deliberately not a tick, a shield or a padlock. A tick would claim the thing is authentic, original, owned and true. The record supports none of those. It supports two things: custody and time.

On the blockchain question, since an anchor invites it. Today the answer is no, and the copy will not imply otherwise. Records are hashed, append-only and signed, and nothing is written to a public chain. The word covers two very different things.

The first is a log where each entry is bound by hash to the one before it, so that removing or reordering entries is detectable, and where copies of the record’s fingerprint are held by parties other than the custodian, so that the custodian cannot quietly rewrite their own history. Half of that is already in place: an independent node can hold and acknowledge a record’s fingerprint today, in the system as it stands, which means someone other than the holder can already say “yes, that is what it looked like”. What is missing is the link binding each entry to its predecessor.

Completing it would let us say three things, each of which a sceptic could check for themselves: hash-linked — you can walk the chain and confirm nothing was removed; append-only — entries are added, never edited; independently attested — someone other than us holds a copy of the fingerprint. That is more useful than the word “blockchain”, which tells a reader almost nothing about which of those three properties they are getting.

The second sense — writing to a public distributed ledger — is not planned, and the reasons are practical rather than ideological.

The first reason is the one this piece has been making all along. Public chains are usually described as decentralised, but the machines, the developers and the exchanges cluster under a single foreign jurisdiction, and the rules can change there. Moving custody of a New Zealand body’s records onto that arrangement, in the name of not being centralised, would be an odd thing to do.

The second is that it buys less than it appears to. A qualified timestamp carries a statutory presumption in the places that matter; a chain entry carries no presumption anywhere, only the argument that many parties saw the same thing. Even China’s courts, which accepted blockchain evidence earlier than anyone, name it in an open list alongside electronic signatures, reliable timestamps and hash checks — one accepted method among several, not the one that outranks them.

So: possible later, in the first sense, and only where it makes a claim easier to check. Never as decoration.

7. Jurisdiction, and what New Zealand might do

⚖️ Whose opinion this is, and whose it is not

What follows describes what two pieces of legislation say, and cites them, so that you can read them rather than take my word for anything. It is not legal advice, not a legal opinion, and not the beginning of one.

That is a standing position rather than a disclaimer bolted onto a page. We do not provide legal opinion on the use of anything we build, and we will not start. Two reasons, and the second is the one that matters.

The first is that I am not qualified, which is ordinary enough.

The second is that this is used in more than one country, and we make no claim to understand the legal context of every nation — nor will we pretend to acquire it. New Zealand and the European Union appear below because they are two places whose rules I have read, and because they treat the same question so differently that the contrast is the point. They are not a survey. If you are somewhere else, assume nothing here reaches you, and be suspicious of any supplier whose material implies otherwise.

For most readers none of this arises. If you are a committee, a trust, a marae or a society that wants its records dated, signed and checkable, no lawyer is required for that. A sealed record is useful whether or not a statutory presumption ever comes into it: the date cannot be moved, and that holds everywhere, because it is arithmetic rather than law.

One situation is different — intending to rely on a statutory presumption in an actual dispute. What is available to you then depends on your arrangements, your forum, your evidence and your country. That answer comes from your own lawyer, in your own jurisdiction. It does not come from us, and it does not come bundled with anything we sell.

Jurisdiction is where most provenance pitches overclaim. The two need separating.

Europe has a statutory presumption, and it is strong. A qualified electronic timestamp is presumed accurate as to its time, and as to the integrity of the data bound to it, with the burden falling on whoever disputes it (eIDAS, Article 41(2)). Qualified status operates across the Union through the trusted-list regime rather than through that article — Article 41’s own recognition paragraph was deleted when eIDAS was amended in 2024.

That presumption does not reach New Zealand. Recognition of a third country’s trust services requires a decision at European level — an agreement with the Union, or a Commission implementing act — and neither is in place here. In a New Zealand forum a European qualified timestamp is persuasive evidence and nothing more. Selling “legal presumption” to a New Zealand body on the strength of a European instrument would be a false equivalence, and we will not do it.

New Zealand has a presumption of its own, and it is not the same instrument. The European one attaches to a timestamp. Ours attaches to an electronic signature (Contract and Commercial Law Act 2017, s228): the signature is presumed reliable where the means of creating it are linked to the signatory, under the signatory’s control, under the control of no other person, and where any later alteration is detectable. Different objects, different jurisdictions. They do not substitute for one another, and this piece does not treat them as if they did.

That third condition is the interesting one, because it turns a question about software architecture into a question the statute asks directly. Read it against the ordinary hosted arrangement, where the provider holds the material that protects the customer’s key: it is at least arguable that the provider has control, and the wording asks that no other person does.

I am not going to tell you what follows from that, because it is not mine to say and it will turn on facts I do not have. What I will say is what we do about it on our side. We treat “who holds the keys” as a question the statute cares about rather than a preference we might indulge, and we are building so that an organisation can hold its own. If it turns out the condition is read more loosely than we assume, we will have over-engineered for the customer’s benefit. If it is read as we assume, the organisations that hold their own keys will be glad they do.

Anyone whose situation depends on the answer should get it from their own lawyer, about their own arrangements.

There is a jurisdictional point sitting underneath all of this that is easy to miss. Key custody can be brought home — an organisation can hold its own keys today, and §4 argues it should. The date cannot, not yet, because fixing a date requires an outside party and every outside party currently available is somewhere else. So a New Zealand custodial claim is, at the moment, anchored to a European company’s signing key. That is not a legal defect and it is a sovereignty one, and it is the strongest practical argument for the authority §4 offers to help build. An authority governed here, or governed by the communities whose claims it carries, would close the last gap that key custody alone cannot.

So, for New Zealand, five things:

  1. Name the jurisdiction, every time. Two presumptions, two instruments, two jurisdictions. Never let one borrow the other’s authority.
  2. Treat key custody as a legal requirement, not a feature. If the presumption depends on nobody else having control, then arrangements where somebody else does have control should be described accurately and priced as the lesser thing they are.
  3. Put the check into rules that already exist. The organisations best placed to make provenance matter are the ones that write their own standing orders, procurement terms and constitutions. A requirement written into a body’s own rules is worth more than any amount of hoping the public will verify — and it is the democratic route to the outcome China reached by decree.
  4. Leave the te Tiriti question where it belongs. The mechanism is available for review by iwi and Māori data-governance bodies if and when they want to look at it — their timetable, their discretion, their call as to whether it is of any use. Not a compliance step, and not a claim to have solved anything.
  5. Treat the borrowed clock as temporary. The Polish authority currently fixing these dates is a proof of concept — it demonstrates that the mechanism works end to end, and it was never the intended permanent arrangement. Building an authority that is governed where the claims are is unglamorous infrastructure work with no obvious owner, which is exactly the sort of thing that does not get done unless somebody names it. This names it.

8. What this does not do

Three limits, because a mechanism oversold is a mechanism distrusted.

It does not prevent misappropriation. It makes misappropriation contestable afterwards, by producing a dated, signed, independently checkable record that predates the appropriation. That is worth a great deal. It is not a shield, and calling it one would be false.

Sealing concentrates, and that is a cost, not a footnote. Knowledge spread across notebooks, hard drives, recordings and people’s memories is difficult to find and difficult to take. Gather it into one system in order to protect it and you have created a single place worth attacking, with a helpful index of what is inside. The protection and the exposure arrive together, and anyone who tells you otherwise is selling something.

There is a quieter version of the same problem. Even where the sealed material is properly protected, the record of it is not silent. A lookup that answers “yes, this exists, held by that body since that date” tells an enquirer what exists and who holds it, which is information some bodies would never choose to publish. That is why nothing is discoverable unless its holder deliberately publishes it, and why a lookup for something unpublished returns the same answer as a lookup for something that does not exist. Silence has to be indistinguishable from absence, or the silence itself becomes a disclosure.

Concretely, this argues for: each body’s material separated so that a breach of one is not a breach of all; keys that differ per body, so that compromising one opens one body’s records rather than everyone’s; and a plain answer to the question of what happens when something goes wrong, rather than an assurance that it will not.

It also argues against the thing that would otherwise seem obvious — a single national registry holding everything, run properly, by someone sensible. That is the same conclusion §4 reached from the opposite direction, and the two reinforce each other. A distributed arrangement is better politics because no one party ends up speaking for everyone else’s knowledge. It is also better security, for the dull reason that an attacker has to succeed many times instead of once, and each success is worth less. Centralising is easier to build, easier to fund and easier to explain. It is just worse.

It does not remove the dependence on somebody else’s clock — it relocates it. Every sealed record described here has its date fixed by Asseco Data Systems, in Poland. That is better than us fixing our own dates, and it is a proof of concept rather than a finished arrangement: a foreign company on whose continued existence a New Zealand custodial claim rests. Until an authority exists that is governed here, or governed by the communities the claims belong to, this is an unfixed weakness and not a solved problem. Saying so is why §4 carries an offer rather than a product description.

And the serious one, which we have not solved. Defensive publication — putting something on the record so that nobody else can later claim it as their invention — only works if the material is disclosed. That is in direct tension with knowledge that was never meant to be public. India’s own traditional-knowledge library manages this by restricting access to patent offices under agreement, which is a workable compromise and still a compromise. This tension cannot be engineered away. Whether a particular body of knowledge should be recorded at all is a decision for the people whose knowledge it is.


The choice, stated once

Protection that depends on the secret holding has a schedule attached to it, and nobody gets to set that schedule. That is not an argument for giving up. It is an argument for making a different claim — one that does not depend on the secret holding, and that gets stronger rather than weaker with age.

The record can be built now. Whether it counts for anything depends on something slower: a settled view that custodianship deserves to be honoured, arrived at by argument and habit rather than by decree.

One of those we can start this year. The other is the work of a generation.

And there is a third thing, sitting between them, which is the part I would most like someone to take up. The date at the centre of all this is currently fixed by a company in Poland, for want of anyone closer. An authority governed by the communities whose claims it carries would be better, would serve more than one of them, and does not exist anywhere. We would help build it and should not run it. The terms are in §4, including the parts that are nobody’s job but the operating body’s.


Where to go from here

There is a shorter version of this argument, if you would rather hand someone that: The India agreement, and the wrong argument about it.

What the mechanism costs, and which parts are not on sale yet, is at What it costs.

And the question is going to a small convened discussion rather than a comment thread — people who have thought about trade policy, data governance or evidence law, and who are likely to disagree with me and with each other. Would you take part? Places are limited and not everyone who registers can be invited; whatever the discussion arrives at is written up and published, and everyone who registers gets that write-up, invited or not, including the parts that go against the argument above.