The regulators are done with “Trust as policy”. That chain used to be an internal maturity problem, something a security program could work on over time: A developer trusts AI-generated code because it compiles. A reviewer trusts an AI-generated summary because it reads plausibly.