Prove, Don't Disclose
The European Union's Carbon Border Adjustment Mechanism (CBAM) entered its definitive period on 1 January 2026. From 2027, EU importers of cement, iron and steel, aluminium, fertilisers and hydrogen must surrender certificates for the emissions embedded in their imports; a legislative package still awaiting Parliament's plenary mandate, and therefore not yet in trilogue, would extend the mechanism from 2028 to several hundred downstream steel- and aluminium-containing products and commit the Commission to reviewing the product list annually. Embedded emissions must either be verified actual values supplied by the non-EU producer — and, for complex goods, by that producer's own suppliers — or punitive default values carrying a mark-up that rises from 10 % to 30 % over 2026–2028 for most sectors. The Commission's own Operators Portal already addresses the single-installation case: an operator registers once and its verified embedded emissions are available to every declarant, as the number and not the activity data. Three gaps remain. The portal centrally holds each installation's figure in an EU-operated registry; it is per installation, so it cannot assemble a complex or downstream good's emissions from precursor values held by independent suppliers; and it transports a number without the rule version that produced it. This paper addresses those three gaps by combining two techniques not previously applied together to border-carbon compliance. First, rules as code: the CBAM methodology (Regulation (EU) 2023/956 Annex IV, as implemented by Implementing Regulation (EU) 2025/2547, with default values, benchmarks and mark-ups) is encoded per sector as an executable, tested, versioned rule bundle whose cryptographic hash identifies exactly which rules were applied. Second, zero-knowledge proofs: a producer executes the codified methodology over its private activity data and attested inputs and produces a succinct proof that the declared figure is the correct output of the identified rule version — without revealing the data. Proofs compose recursively along the supply chain, so a manufacturer of a complex or downstream good can incorporate precursor emissions from installations it never sees. We describe the rule-bundle and proof formats, the trust anchors connecting proofs to the accredited verification the Regulation requires, deployment models including fully air-gapped operation for producers in jurisdictions with cross-border data-transfer restrictions, and a worked scenario following metal from a smelter through an extruder and a downstream manufacturer to an EU declaration. Aluminium is used as the running example; the architecture is sector-agnostic by construction, and we set out how it applies to steel, cement, fertilisers, hydrogen and the proposed downstream scope. We are explicit that the approach complements rather than replaces accredited verification, and we state limitations, open questions and a roadmap. A reference implementation is being developed as open source under Apache 2.0.
Authors
- Yiu Ming Patrick Ma (ORCID: https://orcid.org/0009-0008-9061-6859)
Institutions
- Keldysh Institute of Applied Mathematics (RU)
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-09-15
- DOI
- https://doi.org/10.5281/zenodo.22740284
- Primary Topic
- Environmental Policies and Emissions
- Type
- article
- Field-Weighted Citation Impact
- 0.00