lin-0243
20.7 What the architecture does not guarantee
Structural auditability is valuable only if its limits remain explicit.
External truth.
Agreement among sources may reproduce a shared error. Source manifests and gluing cannot substitute for independent measurement or domain expertise.
Cover completeness.
An omitted population, risk class, reporting period, or stakeholder may make all recorded overlaps look compatible. Cover design is itself a scientific and governance claim.
Causal identification.
A coherent causal story is not an identified effect. Interventional and latent-confounding assumptions still require the diagnostics developed in Chapters 5 and 11.
Audit independence.
Agents built from the same model family may share blind spots. Deterministic checks, heterogeneous models, external tools, and human review provide different forms of independence, none of them automatic.
Adversarial robustness.
Typed artifacts expose attack surfaces but do not eliminate prompt injection, poisoned sources, compromised tools, or malicious operators. Security must surround the foundry.
Normative legitimacy.
An admission contract can make a policy explicit and auditable; it cannot by itself establish that the policy is fair, lawful, or socially legitimate.
The strongest defensible claim is not “the architecture makes foundation models safe.” It is that the architecture makes specific trust obligations, failures, repairs, and promotion decisions representable and inspectable. That is a precondition for serious safety work, not its completion.