VERIK / V112 / 05 AUG 2026
Substrate Governance ObjectGovernance

Three Instruments, Three Cadences, One Gap

Over eight days between July 28 and August 3, 2026, three governance-adjacent artifacts were published into the same air. Read separately, each looks like ordinary institutional output. Read together, they draw a triangle whose interior is the operational gap every AI-touching security program is now sitting inside.

On July 30, CISA published Open Source Software Security Principles and Practices, implementing Executive Orders 14144 and 14306. The guidance extends the federal open-source instrument to open-source AI, then immediately separates the two evaluation regimes. Open-source software carries an audit premise that closes over the deployed artifact through source-code visibility. Open-source AI cannot be treated the same way for risk management unless the agency has sufficient transparency into all relevant components, including the training data. The instrument treats the two as adjacent. The function the instrument can perform on the two is not adjacent. The audit premise does not carry over.

On July 28, OpenAI submitted arXiv 2607.26115, GPT-Red: Automated Red Teaming via Self-Play at Scale, described in its own abstract as the largest LLM safety training run documented. An attacker initialized from GPT-5.5 weights was trained via reinforcement learning against a defender population at post-training compute scale. On an indirect prompt injection benchmark replicated from prior work, GPT-Red elicited failure at 84 percent against held-out defenders where human red-teamers reached 13 percent. The report is retained. The offensive model is not distributed. The executable attack prompts are not published. The evaluation record is a lower bound whose currency is a function of the compute frontier rather than the elicitation methodology used to reach it.

On August 3, NIST published Internal Report 8578, the Workshop Summary Report for the first Cyber AI Profile Hybrid Workshop. The workshop convened in April 2025. The preliminary draft of the profile, NIST IR 8596, appeared in December 2025 and closed for public comment on January 30, 2026. The workshop summary was finalized sixteen months after the workshop. The three focus areas of the profile are Secure, Defend, and Thwart. Each names a category of risk. None yet carries an enforcement floor. Priority labels of High, Moderate, and Foundational are a schedule of what to build if an organization has decided to build. They are not the instrument by which the organization is required to have built it.

Why the three do not synchronize

The three artifacts fail to synchronize because they operate at three different cadences.

The CISA open-source software instrument runs at the cadence of federal policy consensus. The two executive orders it implements were signed six months apart in 2025. The guidance itself lands eighteen months after the first order. The instrument moves at the speed of interagency drafting and public-comment cycles measured in quarters.

The NIST Cyber AI Profile runs at the cadence of standards-community consensus. Community Profiles under the Cybersecurity Framework are built by convening stakeholders, publishing concept papers, holding workshops, releasing preliminary drafts, closing comment periods, and iterating. That cadence is measured in years. The workshop-to-workshop-summary interval alone was sixteen months.

GPT-Red runs at the cadence of frontier training compute. Post-training self-play consumes on the order of hundreds of thousands of GPU hours. That cadence is measured in weeks between successive checkpoints and in months between successive named releases.

The result is a governance stack that is three layers deep and running at three different speeds. When the layers were governing the same object, the mismatch was survivable because the top layer moved slowly enough to still describe the bottom layer by the time it was published. That is no longer the case. The evaluation floor updates faster than the audit premise. The audit premise updates faster than the policy instrument. By the time the policy instrument is a policy instrument, the object it was written for is no longer the object being deployed.

Where the interior of the triangle falls

The interior of the triangle is the space where an organization has to answer three questions at once, and no single retained artifact answers all three.

The audit premise instrument tells the organization what it can and cannot claim to have inspected. It does not tell the organization what its defenses will withstand.

The evaluation instrument tells the organization what defenses withstood a particular adversary at a particular compute scale on a particular date. It does not tell the organization what the auditor will accept as evidence.

The policy instrument tells the organization what outcome to target and what priority label to assign it. It does not tell the organization what artifact of adherence to retain.

Any two of the three can be satisfied while the third is silent. All three can be retained while none of the three governs the actual model deployment on the actual date the incident occurred. The retained artifact and the retained function do not align.

Open questions

The next series of pieces will unpack each vertex of the triangle. Before the reader turns the page, three questions force the confrontation.

If a regulator, an insurer, or a counterparty asked a security program today which specific AI model deployment was operating at which specific date under which specific defense posture and which specific adversarial exposure, would the program produce a governance record that ties those four attributes together, or would it produce three retained artifacts each describing one attribute in isolation and none of the four together.

When a security program cites its adherence to a governance instrument, is the instrument the current version of the instrument at the time the model was deployed, or the version of the instrument that existed at the time the control framework was written; and if those two versions differ, which version does the evidence chain rest on.

If the answer to the first question is three retained artifacts and the answer to the second question is the older version, what is the security program actually optimizing for: the outcome the instrument names, or the artifact the instrument produced.

The audit premise does not carry over. The evaluation floor moves with compute. The community profile arrives after the community has moved. The governance artifact is retained. The governance function is not.