Known and Funded Anyway

The Adoption-Awareness Gap at the Substrate Layer

Enterprise and public surveys published across 2026 converge on an uncomfortable shape: awareness of ungoverned AI risk is high, not low, and organizations are accelerating deployment regardless. This is not a story about desensitization. It is a story about which era of computing risk tolerance was calibrated for, and which era just arrived.

Ken Granville CEO & Co-Founder, MindAptiv White Paper 40 The Governed Machine July 2026
Abstract

Multiple independent 2026 surveys of enterprise leaders and the general public converge on the same shape: awareness of AI risk is high and rising, and deployment of agentic AI is accelerating at the same time, in the same organizations. This paper argues that gap is not evidence of desensitization. It is evidence of a category error: risk tolerance calibrated to Era 1 computing, where defects were bounded, detectable, and patchable after the fact, applied without adjustment to Era 2 systems that act on authority they cannot structurally verify, before any bug report is possible.

The industry's own prominent calls for external regulation do not close this gap. Several 2026 analyses argue those calls function as a substitute for closing it: a request that someone else impose, after the fact, the constraint the industry has not built into its own substrate.

Nor does the answer lie in more Era 2 capability. This paper argues that abundance (the stated destination of the current AI buildout) is not a property that emerges from scaling systems that cannot reliably tell an authorized instruction from a forged one. It requires Era 3: a substrate where Determination, not merely Detection, governs execution from the ground up.

Terms Used in This Paper
GenAIGenerative AI: systems that produce new text, code, or action proposals, rather than simply retrieving stored answers.
ICMLInternational Conference on Machine Learning: the venue where the CoT Forgery research discussed in Paper XXXIX was published.
CoT ForgeryThe attack, named in Paper XXXIX, in which fabricated reasoning styled as a model's own chain-of-thought is used to hijack its behavior.
DetectionIdentifying what an input resembles, or catching a violation after it has already occurred.
DeterminationGoverning, structurally, what an action is authorized to do before it executes, the distinction this series is built around.
EU AI ActThe European Union's risk-based regulatory framework for AI systems, with phased obligations taking effect through 2026.

Section 01The Gap Is Behavioral, Not Cognitive

Awareness of the risk of building on ungoverned GenAI is not low. It is, by several measures gathered across 2026, quite high. What has collapsed is the link between that awareness and deployment behavior. Organizations report knowing the risk is unresolved, in writing, in their own commissioned research, and are accelerating deployment regardless. That is a more durable problem than simple ignorance would be, because it cannot be fixed by better public education. The gap is not in what people know. It is in what they are willing to act on.

The Finding, Stated Plainly
This is not a population that hasn't heard the warning. It is a population that has heard it, repeated it back in its own research, and kept moving at the same pace or faster.

Section 02The Awareness Is Documented

Multiple independent 2026 industry surveys converge on the same shape.

State of Agentic AI Survey
A survey of 500 C-level and senior executives at large enterprises found 65% already using AI agents (systems that plan and take multi-step action with limited human supervision) and 100% planning to expand agentic AI use in 2026. Only 34% of the same respondents cited security and governance as their top evaluation factor when choosing agentic platforms.
State of AI Development
96% of surveyed organizations already using AI agents in some capacity, alongside 94% reporting concern that AI sprawl is increasing complexity, technical debt, and security risk. Only a small fraction of those organizations report having established a centralized governance approach.
State of AI Agent Security
81% of respondents feel pressure to deploy AI agents quickly even when security or governance is not fully in place, while 79.7% simultaneously agreed it is possible to move fast with AI agents without compromising on security, an internally inconsistent pair of beliefs held by the same population.
Gartner & Cisco, 2026
Adoption Pace vs. Preparedness
Gartner projects 40% of enterprise applications will incorporate task-specific AI agents by end of 2026, up from under 5% in 2025, and separately projects AI-related legal claims will exceed 2,000 by year-end due to insufficient risk guardrails. Cisco's State of AI Security 2026 research, reported by Help Net Security, found that while most organizations planned to deploy agentic AI into core business functions, only 29% felt prepared to secure those deployments.
Public Sentiment, Not Just Enterprise
Stanford HAI's 2026 AI Index reports the global share of people saying AI makes them nervous rose to 52% in 2025, even as the share saying AI offers more benefit than drawback also rose, to 59%, belief in the value and fear of the risk climbing together rather than trading off. A Bentley University–Gallup survey reported by Gizmodo in July 2026 found 39% of Americans now believe AI does more harm than good, up from 31% in 2025, climbing to 47% among 18- to 29-year-olds.

Section 03Era 1, Era 2, and the False Promise of Abundance

The risk posture documented in Section 02 is not new. It is the direct carryover of a governing assumption from what this paper calls Era 1 computing: the decades in which software was built, shipped, and corrected in production, on the working premise that defects would surface as customer-reported bugs and get patched after the fact. That model was rational for its era because the failure mode it managed was bounded and legible (a crash, a miscalculation, a broken workflow), discoverable by a user, reproducible by an engineer, and fixable in the next release. Move fast, ship, patch later: the cost of the mistake was a support ticket, not a system that had already acted on a fabricated authority it mistook for its own.

Era 2 is the arrival described in Paper XXXIX, "Role Without Determination." Systems that do not merely output content for a human to check, but that reason, decide, and act, and that, per the ICML paper "Prompt Injection as Role Confusion" (Ye, Cui & Hadfield-Menell, 2026), cannot reliably tell the difference between an instruction that legitimately belongs to them and one that has simply been written in the right style to look like it does. Era 1's "fix it when the customer finds it" model presupposes that the defect surfaces after it has done bounded, recoverable damage. Era 2 systems act with the authority already granted, at the moment the forged input is accepted as genuine, before any customer, engineer, or support ticket enters the loop. There is no patch cycle for an action already taken by an agent that believed a forged chain-of-thought was its own.

Era Governing Assumption What Actually Happens
Era 1: Code Ship, observe, patch. Defects surface as detectable, recoverable customer-reported bugs. Correct for its category of failure: the mistake is discoverable after the fact and reversible.
Era 2: GenAI, Detection-Only Same ship-and-patch posture, applied to systems that reason and act on inferred authority. The system acts on a forged instruction believing it is authorized. Correct execution and successful exploitation are internally identical. There is no patch cycle for the action already taken.
Era 3: Intent-Native, Determination Authorization is evaluated structurally, at the substrate, before execution, not inferred from style, and not audited afterward. The forged-instruction failure mode has no equivalent point of failure, because the system's own self-assessment was never the thing making the determination.
The Era-Recognition Gap
The 79.7% of respondents who believe it is possible to move fast with AI agents without compromising on security are not being reckless by Era 1 standards; they are being conventional. It is the wrong posture for a category of system whose consequences do not wait for a bug report.

This matters beyond risk management because Era 2 is also being sold, implicitly, as the vehicle for abundance, the belief that scaling GenAI capability, on its own, is what carries the economy from scarcity to plenty. That assumption does not survive the diagnosis above. A system that cannot structurally distinguish an authorized instruction from a forged one is not a stable foundation to build an economy's productive infrastructure on top of; it is a foundation whose failure mode compounds with scale rather than shrinking. More capability deployed on an ungoverned substrate does not produce more abundance; per Sections 05 and 06, it has so far produced more incidents, more legal exposure, and more spend on after-the-fact detection layered onto a substrate that was never asked to determine anything in the first place.

The False Assumption
Abundance built on a substrate that cannot tell its own authorized instructions from an attacker's forgery is abundance built on a foundation that has not yet been shown to hold weight.

Section 04A Structural Incentive Problem, Not Numbness

The pattern documented above is a structural incentive problem. The Gravitee report's own framing captures it: organizations describe themselves as moving fast "regardless of governance readiness," not because they've stopped noticing the risk, but because the return on deploying now is calculated to outweigh the cost of an incident later, and that calculation is, for most individual organizations, currently correct often enough to keep making. Boards do not need to be numb to a risk to keep funding a deployment; they only need the expected return to be positive at the portfolio level, even while every individual deployment carries a real and openly acknowledged chance of failure.

This is a betting-the-future posture in the literal sense: it treats substrate-layer governance as an optional insurance purchase against a probabilistic future loss, rather than as a structural precondition for the system to be trustworthy at all. Detection of the risk is, per Section 02, nearly universal. Determination (a structural, substrate-level answer to whether a given AI action is authorized before it runs) remains the minority practice, adopted by only a small fraction of even the organizations that name it as a top concern.

Section 05The Cost Is Not Hypothetical

This is not a purely forward-looking risk. Industry-reported figures from 2026 already show the pattern converting into loss: research aggregated by outlets covering agentic AI security cite an average cost in the range of several million dollars per AI agent-related data breach in 2026, and separately report that among enterprises that have deployed agents, a large majority (cited at 88% in one such analysis) have experienced at least one security incident tied to those agents.

A Note on These Figures
These figures are drawn from industry security-vendor research and press aggregation (shattered.io, citing Bessemer Venture Partners' 2026 analysis and IBM's 2025 Cost of a Data Breach research) rather than a single peer-reviewed source, so treat the specific dollar figures and incident percentages as directional. They are consistent across multiple independent write-ups and describe a pattern already realized, not merely anticipated.

Section 06The Industry's Own Regulation Calls

If the gap described above were simply a matter of insufficient outside pressure, the industry's own repeated calls for regulation would be the corrective mechanism. In 2026, those calls are numerous and prominent. OpenAI published a proposal in April 2026 calling for governments to adopt what it termed common-sense regulation aimed at child protection, national security, and continued innovation. Anthropic has voiced similar sentiments. By July 2026, Axios was reporting that the leaders of OpenAI, Anthropic, and Google DeepMind had converged on a rough shared regulatory framework, with independent pre-release testing of frontier models by outside parties as a common thread across all three positions.

Taken at face value, this looks like the awareness-to-action gap closing from the top. Three separate lines of analysis published in 2026 argue this reading does not hold up.

Analysis 01
Peer-Reviewed Regulatory Capture Study
"Big AI's Regulatory Capture: Mapping Industry Interference and Government Complicity" (arXiv, May 2026) examined roughly 100 news reports spanning major AI policy events between 2023 and 2025, including the EU AI Act negotiations and international AI summits, and found the industry's dominant argument was consistently that strict regulation would damage innovation and competitiveness, a framing the researchers argue has shaped the resulting policy debate in the industry's favor rather than constrained it.
Analysis 02
Axios's Own Framing
Axios's July 2026 reporting on the labs' converged framework notes plainly that the companies with the most compute, the most capital, and the most to lose from a slowdown are the ones lobbying hardest for the rules, a dynamic critics describe as a setup for regulatory capture, where safety-branded rules end up entrenching whichever firms are already largest.
Analysis 03
Industry Commentary
Multiple 2026 outlets make the sharper version of the same point directly: that a public call for regulation, without a corresponding change to how a system is actually built underneath, functions as reputational and competitive positioning rather than as structural correction. Meta's Yann LeCun has been an outspoken critic of the same pattern from the open-source side, arguing AI-safety rhetoric has repeatedly served to protect incumbents against newer or open competition.
What Asking to Be Regulated Does Not Do
A call for external regulation is still, structurally, a request that someone else impose the constraint. It does not itself change the substrate a system is built on, and it is fully compatible with the same organization continuing to ship agentic systems with governance-as-policy-layer rather than governance-as-substrate.
None of the proposals summarized above call for substrate-level, pre-execution determination. They call for outside testing and review of systems whose internal trust architecture remains unchanged.

It is also worth noting, in the interest of a complete picture, that regulation is proceeding in some jurisdictions largely independent of what the labs are requesting. The EU AI Act's Phase Two obligations take effect in August 2026 regardless of industry input, and a December 2025 U.S. executive order pushes in the opposite direction from many of the labs' stated positions, seeking federal preemption of state-level AI laws rather than additional binding rules. The regulatory landscape in 2026 is genuinely contested and moving in more than one direction at once; the industry's own calls for regulation are one input into that landscape, not a description of its outcome.

Sources · OpenAI's April 2026 regulation proposal and Anthropic statements as characterized in Reason, June 24, 2026 · Axios, July 16, 2026, on Altman/Amodei/Hassabis convergence · "Big AI's Regulatory Capture," arXiv, May 2026 · MindStudio explainer, June 14, 2026 · Cimplifi 2026 regulation guide (EU AI Act Phase Two) · Gunderson Dettmer 2026 AI laws update (federal preemption order)

Section 07Era 3 and the Intent Economy

The alternative to betting the future on more Era 2 capability is what this series calls Era 3: intent-native computing, in which the computational primitive itself changes from code, and from GenAI's probabilistic proposal of code or action, to declared and governed intent, resolved into machine execution deterministically, with Determination structurally present at the substrate rather than layered on afterward as policy or regulation.

MindAptiv's own public materials describe this progression directly. The company overview states the underlying distinction plainly: Detection finds a violation after the fact, while Determination governs it before, and names the destination of a governed substrate as the Intent Economy (Paper XII), an era of abundance premised on AI interpreting intent while a governed, deterministic substrate executes it faithfully, rather than an economy of systems that guess and are usually, but not verifiably, right. The Fix the Substrate page makes the abundance claim in this paper's own terms: substrate-level governance is not a constraint on the Abundance Era but the condition that makes it achievable at all, because alignment breaks silently, at speed, and at scale, at every layer of abstraction between human intent and machine execution, unless that gap is closed structurally rather than audited afterward.

The Era 3 Claim
Abundance is not a property that emerges from scaling Era 2 capability further. It is a property available only once the substrate itself can determine, not merely detect, what it is being asked to do.

Section 08The Governed Machine's Position

This paper is a companion to Paper XXXIX, "Role Without Determination: The Chain-of-Thought Forgery Problem," which described the technical mechanism (models inferring authority from style rather than verified source) that this paper argues the industry is choosing to deploy at scale anyway, with open eyes. The MindAptiv position has never been that this risk is invisible or unknown. It is that the industry's dominant response to a known, named, and measured risk has been governance-as-policy-layer (added on top of execution, monitored after the fact, or requested from an outside regulator) rather than governance-as-substrate, evaluated structurally before an action runs.

SecuriSync™ and the Aptiv trust model, enforced through Guard as described on the Nebulo page, were built on the premise that this gap between awareness and structural correction would persist, not because organizations wouldn't understand the risk, but because understanding it does not, by itself, change the substrate an organization is built on.

How Essence® Resolves It
SecuriSync decides if you can run.
Guard ensures you behave while running.
Neither check depends on how aware the organization deploying the model was of the risk, or on what it asked a regulator to do about it.

Changing the substrate is a different act than raising awareness, and the data in Section 02 suggests awareness alone has already been tried, at scale, and has not been sufficient. Nor is asking an outside body to impose a constraint after the fact the same act as building a system that determines, at the substrate, what it is authorized to do before it acts. The regulation question and the architecture question are not the same question, and treating the first as a proxy for the second is, on the evidence gathered here, a large part of how the awareness-to-action gap stays open.

The Governed Machine: Paper 40

Awareness was never
the bottleneck.

The available 2026 data shows a population, at both the enterprise and public level, that is broadly aware of the risk of building on an ungoverned GenAI substrate, says so consistently in its own research, and continues to accelerate deployment regardless. That is not numbness. It is a structural mismatch between where the incentive to move fast sits and where the cost of an ungoverned failure eventually lands, and it is a more durable problem than numbness would be, because it cannot be solved by getting people to notice something they have, by their own account, already noticed. Era 3 is offered here not as an incremental improvement on that trajectory, but as the different foundation an intent economy of genuine abundance would actually require.

Request Platform Access → Full White Paper Series

White Paper Series · The Governed Machine

1The Civilizational Fault Line 2We Are Building the Wrong Machine 3The Ornithopter Mistake 4The Convergence 5The Four Horsemen of the Knowledge Apocalypse 6What the Insiders Confirmed 7The Metaphor Trap 8The Recall Standard 9The $1 Trillion Governance Gap 10The Litigation Layer 11The Scale of Intent 12The Intent Economy 13The Session Illusion 14The Necessary Sequence 15The Wrong Race 16The Ledger That Is Intent-Driven 17The Agency Illusion 18The Substrate 19The End of the Mean 20Era 3: The Architecture of the Next Civilization 21The Missing Substrate 22The Context Fatigue Ceiling 23The Iceberg Stays Frozen 24The Dependency Tax 25The Record That Was Never Kept 26Composable by Default 27Do No Harm 28The Stack Replacement Thesis 29The Moat Is the Code 30The Last Platform War 31Beyond the Agent: Intent-Native Execution 32The Hardware Imagination 33The Architecture Tax 34The Tokenization Ceiling 35The Payment Moment 36The Oracle Problem 37The Reviewer Problem 38The Provenance Fallacy 39Role Without Determination 40Known and Funded Anyway ← this paper 41The Style Confusion Proof 42The Verification Tax 43The Pause Reflex 44The Human Margin 45The Balance of Power Fallacy 46The Liability Backstop 47One Substrate, Every Signal 48The Attribution Problem 49The Consciousness Ceiling 50The Detection Patch 51The Consumptive Machine 52The Agent That Isn't 53The Legibility Gap 54The Semiotic Machine 55The Transpilation Ceiling 56The Provisioning Ceiling 57The Reservation Ceiling 58The Circularity Ceiling 59The Coexistence Ceiling 60The Conformance Ceiling 61The Preservation Ceiling 62The Parity Clause 63The Governed Boundary 64The Transcript Problem 65The Unpaired System 66The Memory Ceiling 67The Admission Gap 68The Wrong Ask 69The Best Case 70The Last Chokepoint 71The Fourth Step 72The Adoption Standard 73The Same Weekend 74Sixty to One 75Coordinates, Not Correlations 76The Governability Axis 77Era 3, Confirmed 78The Eleventh Rule 79The Seventh Admission 80The Authorization Gap 81The Authorship Fallacy 82The Camera and the Vault 83Cleared to Proceed 84A Class, Not a Product 85The Inherited Playbook