Why Attention Was Never Built to Answer What AI Governance Requires
In 2017, eight researchers at Google showed that attention alone, with no recurrence and no convolution, could translate language better and train faster than anything before it. That result became the substrate under nearly every frontier model. Attention was never built to say what a task actually meant. Asking a correlation to do a coordinate's job explains why the debate over how to govern AI keeps missing its most critical point: a check on each action, against something fixed, before it runs. Without coordinates, interpretability can show what a model is doing but cannot determine whether an action is authorized.
"Attention Is All You Need," published by Vaswani et al. in 2017, replaced recurrence and convolution with a single mechanism, self-attention, and in doing so removed the sequential bottleneck that had made prior models slow to train. The resulting Transformer architecture trained faster, translated better, and generalized to tasks well outside its original brief. It is, without qualification, the correct foundation beneath most current frontier models. This paper credits that achievement in full, then draws a precise distinction the achievement itself does not resolve. Attention answers which tokens in a given sequence are relevant to one another, a relationship learned from training data and re-derived at every inference pass. It has never been built to answer what a specific task was asked to accomplish, independent of the sequence that happens to describe it. That distinction, correlation versus coordinate (what MindAptiv calls a Meaning Coordinate), has gone unnamed: the industry's remedies stop at three steps, embedded evaluators, certification checkpoints and coordination, all detection or pacing. The fourth step, an action-level determination check, has stayed unclaimed not for lack of proposals but because nothing upstream in a correlation-based architecture produces a fixed thing to check a proposed action against. The error is not attention. It is asking a correlation to do a coordinate's job.
Before 2017, the dominant approach to sequence tasks such as translation ran recurrent or convolutional networks in an encoder-decoder configuration, generating hidden states one position at a time. That sequential structure blocked parallelization within a training example, which became a hard ceiling as sequence length grew. Vaswani and seven co-authors proposed the Transformer: a network built solely on attention mechanisms, with no recurrence and no convolution. The result trained in a small fraction of the time the strongest prior models required, reached a new best single-model BLEU score on the WMT 2014 English-to-French translation task, and improved on the best prior ensemble results on the English-to-German task. It also generalized cleanly to English constituency parsing, a task well outside translation.
That is not an incremental result. It is the correct architectural foundation beneath most current frontier models, agentic and otherwise, and it deserves the same treatment given to Falcon Guardian in Paper 74: credited fully, on its own terms, before any distinction is drawn against it.
Self-attention computes, for each element of a sequence, a weighted relevance to every other element, using representations learned entirely from training data. Multiple attention heads let the model track several such relationships at once. This is a genuine advance over fixed-window or strictly sequential relevance, and it is why a single word can be resolved differently depending on the sentence around it. But every part of that mechanism is contextual and re-derived: the weights come from the specific sequence in front of the model, at the specific pass being computed, using representations shaped by whatever the model was trained on. Change the surrounding tokens, the model checkpoint, or the training corpus, and the same input can resolve to a different attended relationship.
That is a correlation, in the precise sense used here: a statistically inferred association between things, recomputed each time it is asked for, with no persistent reference outside the computation that produced it.
Neither question is the wrong one to ask. They are different questions, built to do different work. Attention's question produces excellent translations, coherent completions, and useful agentic behavior across an enormous range of tasks, precisely because most of those tasks reward a good contextual approximation. A coordinate's question produces something else: a reference that stays the same regardless of which model, which pass, or which surrounding sequence is asking. Only one of those two things can be checked against.
A destination reached by air, train, car, bike, or on foot does not change. Routes do. They can be fastest or slowest, most scenic or most dangerous, and each starts somewhere different and demands different decisions. They all still end up at the same place: the coordinate. Even the dangerous route is useful, because with a fixed destination a decision to avoid it can be made.
An attention-weighted representation of "what this means" is a route, not a destination. It gets recomputed per pass, shifts with context length and phrasing, and carries no persistent form that a later, independent check could compare against. For generation and translation, that is not a defect: a good-enough approximation, freshly computed each time, is the entire point. But determination is a different task from generation. Determining whether a specific proposed action matches what a task actually called for requires something to check the action against that does not change depending on which pass produced the action being checked. A moving target cannot serve as its own reference.
| Axis | Attention | Coordinate |
|---|---|---|
| Computed from | Learned relevance across tokens in the current sequence | A fixed primitive in a published, closed set |
| Persists across inference passes | No: recomputed every pass | Yes: the same value regardless of pass |
| Depends on training corpus | Yes: shifts if the model or its training data changes | No: independent of any model or training run |
| Stable under paraphrase | Approximate: similar phrasing usually resolves similarly, not guaranteed | Yes: any phrasing with a match resolves to the same coordinate; a new phrasing gets one when someone explains what it means |
| Checkable by an independent system | No: no persistent form outside the computation that produced it | Yes: a separate system can compare a proposed action against the same fixed reference |
This is not a claim that attention-based models are unreliable at what they were built to do. It is a claim that a fixed, checkable answer to what a task actually meant was not what attention was designed to produce, no matter how much larger the model or how much more training data it sees.
A Meaning Coordinate is one of 256 fixed primitives, grouped into four realms (Operations, Cognition, Physical, Relational) and published as a closed set at mindaptiv.com/meaning-coordinates. An intent resolves to a short combination of them. The codes in the worked example below are shown only to make that concrete; Section 07 covers how they are produced and used.
No one writes the coordinate column by hand. A person gives the instruction in plain language; the resolution to primitives happens underneath it, the same way a chemist's formula describes what a cake's ingredients are doing without the baker ever needing to see it. The coordinates are shown here only to make the distinction concrete, not because producing them is something a user, or even most engineers, would ever do directly.
| Phrase | Coordinate | Meaning |
|---|---|---|
| Detect anomalous transaction pattern | Mz·R4 BryKrz·R4 ZeDe·R1 | Sense (the emitted signal) + Formula·Compare (rule-based pattern detection) + Difference·Default (deviation from the declared normal) |
| freeze account | Swe·R3 DiKo·R2 | Snare (lock the entity, freeze its state) + Thing·System (the named account entity) |
| and generate audit trail | ChzJe·R1 TuSe·R2 Che·R1 | Create·Chronicle (initiate the event record) + Relation·Target (append to the governed ledger) + Guard (tamper-proof enforcement) |
Rephrase that instruction ("flag the suspicious transfer, lock the account, log what happened") and an attention-based model may resolve it to a somewhat different internal weighting, since the words and their surrounding context have changed. The coordinates above do not move, because they are fixed primitives, not a weighting recomputed from the words used. What connects different wording to them is a match, and a phrase with no match yet is given one by explaining what it means. That is the entire distinction this paper is making, made concrete: not that one resolution is smarter than the other, but that only one of them stays the same when the sentence describing it does not.
The error is not attention. It is asking a correlation to do a coordinate's job: treating a better-trained route as if it were a fixed destination.
Papers 68 through 74 examined a succession of proposals for checking an agent's action before or as it executes: capability checkpoints, embedded evaluators, allow lists, signature matching against known-bad behavior. Each was evaluated on its own terms, and each was found to fall into one of two categories, detection or pacing, never the fourth step, defined as a determination check performed on a specific proposed action, at the moment it is proposed, independent of the model's disposition or its last certification.
What none of those papers named directly is why every proposal kept landing in the same two categories. A determination check needs a fixed thing to determine against. An attention-based system has no such thing anywhere in its architecture: what it has, at every layer, is a re-derived correlation, useful for generating the next output and unsuitable as a stable reference for judging a later one. A system with no fixed destination cannot distinguish a wrong turn from a right one; every action looks equally plausible once nothing exists to weigh it against. The fourth step did not stay unclaimed because nobody thought to propose it. It stayed unclaimed because nothing upstream in the dominant architecture produces the one ingredient a determination check requires.
Governance layered onto a correlation-based system after the fact has nothing native inside that system to attach to. There is no fixed coordinate sitting inside a Transformer's forward pass that a governance layer could simply read and check; there is only a distribution of attention weights, valid for one pass, gone by the next. Every governance approach examined here, from capability checkpoints to Falcon Guardian's allow lists, is consequently built the only way it can be: as an external wrapper watching inputs and outputs, rather than a determination performed natively as part of the execution it is supposed to govern.
A coordinate-based system does not face that constraint, because the fixed reference is not added afterward; it is what the primitive already is. Checking an action against a coordinate is not a separate department bolted onto the architecture, in the same way that a location on a map does not require a separate department to confirm it is the correct location; correctness is the coordinate's native property. A correlation has no equivalent property to extend. This is the deepest answer available to the question raised implicitly above: why does every remedy examined so far look like an addition rather than a foundation. It is not a failure of effort, urgency, or resourcing on the part of any lab or vendor examined. It is an architectural fact: a destination cannot be retrofitted onto a system that was only ever built to compute routes.
This is also why interpretability, however much it reveals, remains detection. What it recovers are representations specific to one model, one checkpoint and one training run, and an action cannot be checked against something that changes whenever the model does. Understanding why a model acts as it does is not the same as holding a fixed reference for whether a specific action is authorized.
It is worth tracing the full path from a plain-language request to a running action, because GenAI has a real role in it, and what carries out the resulting action is not what is usually called an agent.
That last distinction is not cosmetic. Elsewhere, "agent" describes a system that acts on a learned, re-derived sense of what to do next, which is exactly the correlation problem Sections 02 through 06 describe. A PowerAptiv is materialized from a fixed coordinate envelope and cannot produce an action outside it, not because a monitor is watching for violations, but because the action was never encoded into what the PowerAptiv is.
How the resolution step earns its authority matters, because a fixed coordinate is only as good as the mapping that produces it. In Essence®, that mapping is not a model. Synergy® matches the natural-language proposal against Grok Units, structured templates authored by people, each of which resolves a pattern of natural language to specific coordinates. The same input always resolves to the same coordinates, and each resolution is recorded with the input, the coordinates and the rules applied. That guarantees reproducibility and auditability, not infallibility: a template that is wrong will be reproducibly wrong. This is why the authority sits with the people who author and approve the templates, and not with a statistical estimate of what was meant.
When a phrase has no match, the system does not infer a meaning. A person explains what it means, in real time, and the match is created. A bank team that says "put it on ice" to mean freezing an account can tell Synergy® so, within the context of its own operations, and from then on that phrase resolves to the same coordinates as "freeze account" in the worked example in Section 04. The addition is scoped to that context and is additive: it replaces nothing, and a team that uses the same phrase differently is unaffected unless it approves the new match. How matches are shared across individuals and organizations depends on their own policies and requirements, and is outside the scope of this paper. The explanation is the authority: the mapping exists because a person said what the phrase means.
| Realm | What It Covers |
|---|---|
| R1 · Operations | The acts of comparing, collecting, counting, and measuring that underpin all computation |
| R2 · Cognition | Values, logic, information, thought, instances, situations, possibilities, and work |
| R3 · Physical | Spacetime, physical properties, scale, shape, energy, matter, body, and thing types |
| R4 · Relational | Sharing, perceiving, judging, feeling, moving, doing, using, and communicating |
This does not change the argument. It supplies the mechanism underneath it. Attention Is All You Need earned its place as the substrate of modern AI by solving a real and hard problem: how to relate every part of a sequence to every other part, quickly and in parallel. It was never posed as a solution to a different problem, fixing what a task was actually asked to accomplish, and nothing in the nine years since has required it to become one. The fourth step, named in Paper 71, was never missing because of insufficient effort at the evaluation or enforcement layer. It was missing because the layer beneath all of them was built to find routes, not destinations.
What should change, for anyone evaluating whether a bigger model, a better evaluator, or a more complete signature library will eventually close this gap, is the recognition that none of those are the right kind of thing to add. A coordinate is a different kind of primitive than a correlation, however well-trained. Until one exists inside the architecture being governed, the fourth step remains exactly what it was before this paper: unclaimed, and unclaimable by addition alone.