The debate over artificial-intelligence safety still gravitates toward model laboratories: what a frontier system can do, whether a company will pause, and which evaluation triggers additional controls. Those questions are necessary. They are not sufficient. The latest safety index says major labs have weakened prior commitments, while an AP and FRONTLINE investigation shows AI models embedded in a global scam supply chain. Together they reveal a governance gap between capability policy and deployed reality.
A laboratory can block a class of requests and still see its model used through automated software, stolen accounts or layered services. A provider can publish a safety framework while cloud, network, payment and identity systems make abuse cheap to scale. Conversely, aggressive account controls can wrongly exclude legitimate users or push criminals to less visible tools. Effective governance therefore needs evidence across the chain: access patterns, verified abuse reports, response time, repeat-offender controls, payment tracing and outcomes for victims.
The safety-index controversy also teaches caution. Composite grades compress judgments about catastrophic risk, open models, cybersecurity and governance into a single letter. They can focus attention but can also hide contested assumptions. Companies should not be allowed to dismiss criticism simply because an advocacy group has a viewpoint. The better response is auditable disclosure: show the policy version, evaluation method, exceptions, incident record and reason for any weakened commitment.
The AP investigation adds a human dimension. Trafficked workers forced to operate scams are both participants in harm and victims of coercion. A crackdown that disables accounts but leaves organizers, money flows and compounds intact may produce good metrics without ending exploitation. AI governance should be integrated with anti-trafficking enforcement, sanctions, financial investigations and victim support. That is harder than a model card, but it matches the system causing the damage.
The practical agenda is a layered one: independent testing for high-impact models, mandatory incident reporting, strong processes for documented criminal infrastructure, privacy safeguards and public measures of abuse reduction. The goal is not to make every provider responsible for every downstream crime. It is to require reasonable controls where providers have visibility and leverage, and to make claims about safety testable outside the company.
