Papers1 provider · 3 records
August 12, 2026· Zenodo (CERN European Organization for Nuclear Research)
preprint
Open access

The Governance Patch-Gap: Machine-Speed Exploit Discovery Against Human-Speed Legal Repair

Abstract

Legal systems governed by rule of law are, structurally, rule systems. Like any rule system, they contain gaps between specification and intent, concentrated in the deliberately under-specified provisions that legal philosophers call "open texture." Those gaps have always been exploitable, but exploitation was rate-limited by the cost of legal expertise and the size of the corpus to be searched. That rate-limit is now collapsing. This paper introduces the governance patch-gap: the ratio between the rate at which AI accelerates the discovery of exploitable legal ambiguities and the rate at which legislatures, courts, and treaty bodies can repair them. Using the Highly Optimized Tolerance (HOT) framework from complex-systems theory, we map legal systems onto designed artifacts whose optimization against anticipated disputes concentrates fragility at the boundaries of the specification. We define the patch-gap as a ratio of discovery rate to repair rate, identify a threat taxonomy (corporate optimizer, state actor, misaligned autonomous agent), distinguish exploit discovery from exploit execution as separate governance problems, and examine three defensive strategies and the structural limits that prevent any defense from closing the gap entirely. The paper closes with three falsifiable predictions for 2027 to 2028. TL;DR summaries (five audiences) For the SME (legal theory / AI safety / complexity). Legal systems are HOT artifacts: drafters optimize against anticipated disputes, so residual fragility concentrates in Hart's penumbra (open texture), not in the core. The paper's object is a rate ratio G = $R_d/R_p$ and a stock S with $dS/dt$ = $R_d − R_p$; G is a definition, not a fitted dynamical model. Regime labels (G ≈ 2, 10², 10³+) are heuristics. SocioHack is an unreplicated sandbox (κ = 0.55); A1/VERITE is 36 already-vulnerable contracts. Rice / FLP / attestation in §6.4 are analogical extensions, not a derivation that courts instantiate those models. The load-bearing claim that survives if SocioHack fails is the work-factor collapse in adjacent formal systems plus the discovery/execution split. For the practitioner (counsel / CISO / compliance). Treat "AI found a loophole" and "an agent filed on it" as different problems. Discovery is a tool-governance issue (access, disclosure, audit of comment corpora). Execution is an agency-and-liability issue (who is the principal; human-in-the-loop above a dollar / classification / cross-border threshold). Disclosure mandates reach corporate repeat players and miss unsupervised agents. Do not spend the policy budget on formalizing "reasonable" or "public interest"; Catala-class work shrinks the core, not the penumbra. Immediate moves: require AI-use disclosure in filings and litigation; log agent actions that change regulatory classification. For the lay person. Laws have always had gray zones on purpose; words like "reasonable" so judges can handle new cases. Finding those gray zones used to be slow and expensive (years of lawyers). AI can search the whole tax code and regulation pile cheaply and flag gaps nobody has noticed. Passing a fix still takes months to years. The paper names that mismatch the governance patch-gap: machines find holes faster than legislatures and courts can close them. The holes were always there. What changed is the cost to find them. For the decision-maker (executive / funder / board). This is not a model-refusal problem and will not be closed by a better system prompt or a voluntary commitment letter. The asset at risk is the stock of known-but-unpatched legal ambiguities, which grows whenever discovery outruns repair. Adjacent formal systems (smart-contract exploit agents at USD 0.01 – USD 3.59 / attempt; attacker break-even ~USD 6k vs defender ~USD 60k) already show the cost collapse. Do not wait for SocioHack to replicate before treating discovery-versus-execution as two budget lines. Near-term: rate-limit execution (human-in-the-loop, disclosure). Do not buy "formally verified law" as a complete close. For governance (legislatures / agencies / treaty bodies). Every new AI rule written in open-textured natural language is another search surface. The EU AI Act Art. 6 "significant risk to fundamental rights" is the same kind of term as "undue burden." Three defenses, all bounded: (1) AI red-team of draft text before enactment .. useful, not exhaustive; (2) formal methods core only; (3) rate-limits buy time, do not close G. Conflating corporate optimizers, state arbitrage, and unsupervised agents produces the wrong instrument. The paper's falsifiers are public: AI-authored substantive rulemaking comments by end-2027; an attributed in-production exploit by end-2027; two governments or the EU publishing legislative red-team reports by mid-2028. Non-claims. G is a definition, not a fitted dynamical model. Regime magnitudes are order-of-magnitude heuristics. The SocioHack result is an unreplicated preprint treated as suggestive. Rice / FLP / attestation are analogical extensions, not a formal derivation that legal institutions instantiate those models. v1.1. Adds §4.5, an illustrative software companion (concept 10.5281/zenodo.21918091): a toy that generates Rd; G and the stocks are outputs, not legal measurements. No figures in the PDF.

Community

0 comments
Use Connect Wallet in the navigation

No discussion yet

Be the first to share a question or observation.