Your AI Controls Can Pass Every Audit And Still Fail

I spent a good chunk of my career writing controls that passed their own audits. That is not a boast, it is the confession, and it took me an embarrassing number of years to understand what had actually happened. The controls were satisfied. The reports came back green.
And the thing I had written them to prevent was happening anyway, two floors down, in full view of people who had no idea they were doing anything unusual. Nobody lied to me. I had pointed the rule at the wrong noun.
Last Monday produced the cleanest example of that mistake I have ever seen, and it came from the most serious control regime ever applied to a commercial technology.
What happened in keelung
On August 24, prosecutors in Keelung, Taiwan indicted nine people over the diversion of Nvidia B300 AI servers to China. The mechanics are mundane in the way real fraud usually is. One hundred and thirty servers ordered against falsified end-user documents, seventy-four of them reaching China, fifty routed through Indonesia, sixteen shipped direct, eight taking the scenic route via Japan and Hong Kong. Fifty-six were stopped by customs before they left the island. Three of the nine defendants come from the two chip and server companies whose names you would recognize; the other six sit at a motherboard maker, a telecom carrier and four smaller trading and technology firms, which is where this sort of thing actually lives.
Then came the detail that stopped me.
Taiwan could not charge the export. Sending restricted AI chips to China is not a criminal offense there. So the island that manufactures the world's advanced AI silicon prosecuted the case as document forgery and breach of trust, paperwork offenses with a five-year ceiling. The United States charged three people separately back in March, under its own authorities.
No company is charged anywhere, by anyone. In the American filing the manufacturer is not even named; it appears throughout as "the U.S. Manufacturer." That is not an oversight. It is the shape of the entire problem.
The part that is not a crime at all
Now hold that against something CNBC reported five days earlier, in which nobody is accused of a crime. Chinese AI firms are reportedly renting access to export-controlled Nvidia chips that sit in Southeast Asian data centers, and doing it lawfully. Cassia King at the Institute for AI Policy and Strategy put the reason on the record about as plainly as it can be put: the regime "controls physical AI chips. It does not cover remote access to those chips."
Read the two stories together and the smuggling case stops looking like a crime wave. It starts looking like an inefficiency. Nine people are facing prison for physically moving objects that other companies are lawfully renting remote access to, from data centers in Thailand.
A White House official has already accused one Chinese lab of using GB300s through a facility in Thailand. The Remote Access Security Act passed the House in January and has gone nowhere in the Senate since. Across Malaysia, Indonesia and Thailand there are thirty-one planned hundred-megawatt-plus data centers against two operating today. Not one of them needs to break a law.
A rule that binds a container cannot hold a liquid
The control was written against an artifact: a physical accelerator, in a box, crossing a border. But the value was never in the box. The value is in the compute, and compute separates from its container the instant there is a network. So the market did the obvious thing and left the artifact exactly where the rule could see it, then moved the behavior instead.
Every party in that chain is compliant. No document is false. Nobody has a case to answer. The outcome the rule existed to prevent happens on schedule anyway, and no enforcement action is available to anybody, because nothing enforceable has occurred.
I want to be careful here, because the honest version of this is narrower than the slogan. Artifact controls work perfectly well when the thing you care about genuinely cannot be separated from the thing you are controlling. Lock up the uranium and you have meaningfully constrained the bomb. Lock up the accelerator and you have constrained almost nothing, because your adversary never wanted the accelerator in the first place. They wanted the arithmetic, and arithmetic travels at the speed of an API call.
Your controls have the same shape
This is the point at which it stops being a geopolitics story. Go and look at the AI controls your own organization has written in the past eighteen months. I will guess at the inventory and I expect to be close: an approved-model list, a deployment boundary, a vendor allowlist, a data-residency clause, and a policy specifying which model may touch which class of data.
Every one of those binds an artifact: a model name, a network perimeter, a legal entity, a storage region. And every one can be fully satisfied while the outcome it was written to prevent occurs, for precisely the reason the export regime failed. The capability is severable from the container.
The approved model is on the list, and the request was routed through a wrapper that is not. The data never left the region, though the embeddings of it did. The vendor is on the allowlist, and the four subprocessors behind their API are not, and nobody has ever told you their names.
I once watched a team pass a model-governance review on a Thursday and discover the following Tuesday that a retry path had been quietly failing over to an unapproved endpoint for five months. The review was accurate on the day it was signed. It described permissions, and permissions were never the thing that mattered.
None of that shows up in the compliance report. The report is green, and it is green accurately, which is the part that ought to bother you. Green is what a correctly functioning artifact control looks like while the capability strolls around the outside of it.
What actually survives this
The remedy is not another artifact control, and it is not a better allowlist. It is to stop asking what was authorized and start recording what actually happened. Those are different questions, and only one of them has an answer you can check afterward.
An outcome control has one useful property: it does not much care where the boundary was drawn, because it observes behavior rather than permission. Which model actually answered this question. What it actually had in front of it. Whether a second model from an unrelated family, looking at the same problem, reached the same conclusion. Whether any of that was written down in a form a hostile third party could read back later without taking your word for it.
That is the reason Coheria exists, and I will keep this short because the piece is not about us. We route every task across multiple model families rather than depending on a single vendor, because a closed door, whether it is a waitlist, a gated launch or an export block, should never get to decide what you are able to build. Specialized expert models from different families cross-check one another, on the working assumption that where one is blind another sees. Every decision then seals into an immutable hash-chained evidence log, because a claim about what your AI did is worth close to nothing when the only witness is the system making the claim.
It catches things and it corroborates them. It does not perform miracles, and anybody offering you miracles is really offering you a green dashboard with better typography. If you want the mechanics they are at coheria.ai, and the difference between those two products is the whole subject of this article.
The test i now apply
One question, and it takes about ten seconds per control. Does this rule bind an object or an outcome? If it binds an object, ask what that object is standing in for, then ask whether the thing it stands in for can move without it. If it can, you are not holding a control. You are holding a routing instruction, and somebody with a commercial reason to read it carefully has already read it more carefully than you have.
Nine people in Keelung are learning that distinction in a courtroom. Their better-advised competitors rented the compute instead and never broke a single law. Both routes deliver the same capability to the same customers; only one of them is a crime.