Summary
Safety gathered questions that had been appearing at every boundary: what the model represents internally and how oversight scales, what permissions a tool call carries and how runtime policy is enforced, what happens under attack, what data is remembered, whether a serving path can prove its privacy promise with attested hardware rather than a contract, and, once harm is done, what law or governance structure applies. The questions are related, yet they do not live at one layer.
That mismatch is the main source of false confidence. A policy sentence, a classifier, a permission boundary, a red-team report, and a legal duty each control a different object. A safety claim becomes credible only when its evidence, authority, enforcement point, and failure mode are located in the stack.
There is no single switch to find. The work is to trace where control is asserted, and where it can be tested. The open question is how governance should adapt as models gain more autonomy, tool access, and cross-border deployment while the technical evidence remains incomplete. Part IX moves below the policy surface to the physical and operational substrate: silicon, power, cluster failures, data limits, and frontier measurement decide what those controls can scale to.
Comments
Log in to comment