Modern governance failures rarely arise from a lack of stated policy. They arise from a discontinuity: assurances are produced at one layer of a system, while enforcement quietly dissolves at another. The literature surveyed here converges on a single, uncomfortable finding—governance fails not when rules are absent, but when the pipeline allows discretion to re-enter after verification has ostensibly occurred.
The paper ARPaCCino makes this explicit at the infrastructure layer. Policy-as-code, long framed as a solution to cloud misconfiguration, proves insufficient when compliance remains advisory. ARPaCCino’s contribution is not its use of automation per se, but its refusal to allow non-compliance to persist as a “temporary exception.” By embedding automated checking and repair directly into Infrastructure-as-Code workflows, it collapses the space between policy knowledge and deployable reality. The key governance move is pre-deployment refusal: configurations that violate constraints are not debated, reviewed, or deferred—they are repaired or blocked. The system does not ask whether operators intend to comply; it assumes they will not unless forced.
Yet even this approach reveals a broader pattern: enforcement mechanisms only matter if they survive the transition from design intent to operational execution. Verified Configuration and Deployment of Layered Attestation Managers demonstrates how formally verified architectures routinely fail at precisely this handoff. Verification proves properties of an abstract design; deployment reintroduces human discretion through ad hoc configuration. The paper’s insistence on a mechanized configuration and compilation pipeline reframes deployment as a governance surface in its own right. Here, refusal is not applied to runtime behavior but to assembly itself: operators are no longer permitted to construct arbitrary configurations, even if they are well-intentioned.
This concern intensifies when evidence becomes adversarial. Evidence Tampering and Chain of Custody in Layered Attestations exposes how attestation systems can be structurally compromised even when they appear to produce “trusted” measurements. The governance failure here is subtle: institutions rely on evidence flows whose integrity they cannot actually guarantee. The proposed response—algorithmic identification and elimination of tampering paths—marks a shift from trust-based evidence to custody-aware refusal. Evidence that cannot be protected from manipulation is treated as unusable, regardless of convenience. Once again, an option is removed: the option to accept evidence simply because it is customary or operationally easy.
The same logic underpins PDRIMA, which addresses the inadequacy of secure boot and static verification in Trusted Execution Environments. By enforcing policy-driven runtime measurement and attestation, PDRIMA refuses to treat integrity as a one-time event. Security-critical components that fall outside continuous appraisal lose their standing. The governance move is temporal: assurances must persist over time or be revoked. What is removed is the option to declare a system “trusted” based solely on its initial state.
CI/CD pipelines emerge as another critical site of discretionary leakage. Establishing Workload Identity for Zero Trust CI/CD identifies a structural weakness that is often normalized: pipelines act with broad authority while lacking strong identity. Shared secrets and anonymous execution blur accountability, making enforcement retrospective at best. By binding permissions to cryptographically verifiable workload identities, the system removes the possibility of unaccountable action. Governance here is not achieved by better audits, but by denying access to actors that cannot prove who—or what—they are.
Integrating Compliance-as-Code into CI/CD Pipelines for Regulated Sectors reinforces this point from a regulatory perspective. Compliance regimes that rely on post-hoc audits fail under delivery pressure; teams ship first and explain later. Embedding compliance checks as release-blocking gates repositions governance upstream, where refusal is cheap and reputational stakes are lower. The crucial insight is that enforcement must occur before incentives to bypass become overwhelming. Once again, discretion is removed at the moment it is most likely to be abused.
Only one item in the survey steps outside purely technical enforcement: Designing Incident Reporting Systems for Harms from General-Purpose AI. Its relevance lies precisely in what it lacks. The paper carefully dissects reporting system design but stops short of mandating closure mechanisms. Reporting, in many institutional contexts, remains voluntary, reputational, and weakly coupled to structural change. Its inclusion here serves as a boundary marker: governance collapses when reporting does not trigger enforced constraint updates. Without refusal—mandatory reporting, required follow-up actions, irreversible changes—incident systems risk becoming narrative devices rather than corrective ones.
The strongest throughline across these works is not automation, verification, or policy formalization, but option removal. Non-compliant configurations cannot ship. Unverified deployments cannot assemble. Evidence with weak custody cannot be trusted. Pipelines without identity cannot act. Incidents without closure cannot fade quietly. Each intervention reduces the space in which discretion can masquerade as judgment.
What these papers collectively argue—often implicitly—is that governance succeeds only when it becomes structural. Assurance must be bound to enforcement across every translation layer: design to configuration, build to deploy, runtime to evidence, incident to constraint. Wherever a handoff allows a human to say “we’ll fix it later,” governance reverts to aspiration.
The lesson for Phase 4 systems is therefore not to add intelligence, but to tighten continuity. Governance is not a property of policies or intentions; it is a property of pipelines. Where the pipeline refuses, institutions learn. Where it does not, they repeat themselves—eloquently, and indefinitely.
Member discussion: