The Governance Patch-Gap: Machine-Speed Exploit Discovery Against Human-Speed Legal Repair

Bilar, Daniyel Yaacov · 2026-10-09 · v1.2 · publication/preprint · cc-by-4.0

Version of record (canonical): https://doi.org/10.5281/zenodo.23262565
Concept DOI (always latest PDF): https://doi.org/10.5281/zenodo.21910874
Download PDF (Zenodo): open
GitHub companion: chokmah-me/patch-gap
OSF mirror: osf.io/w96xz
Companion software (separate concept): 10.5281/zenodo.21918091 (v0.2.0: 10.5281/zenodo.23262639)
Sketchnote for The Governance Patch-Gap v1.2: G = Rd/Rp, discovery vs execution, BCBSA live case, predictions P1–P3 open

Sketchnote for v1.2 (CC BY 4.0). Full-size PNG.

Abstract

Legal systems governed by rule of law are, structurally, rule systems. Like any rule system, they contain gaps between specification and intent, concentrated in the deliberately under-specified provisions that legal philosophers call "open texture." Those gaps have always been exploitable, but exploitation was rate-limited by the cost of legal expertise and the size of the corpus to be searched. That rate-limit is now collapsing. This paper introduces the governance patch-gap: the ratio between the rate at which AI accelerates the discovery of exploitable legal ambiguities and the rate at which legislatures, courts, and treaty bodies can repair them. Using the Highly Optimized Tolerance (HOT) framework from complex-systems theory, we map legal systems onto designed artifacts whose optimization against anticipated disputes concentrates fragility at the boundaries of the specification. We define the patch-gap as a ratio of discovery rate to repair rate, identify a threat taxonomy (corporate optimizer, state actor, misaligned autonomous agent), distinguish exploit discovery from exploit execution as separate governance problems, and examine three defensive strategies and the structural limits that prevent any defense from closing the gap entirely. Evidence that appeared after the first version gives the code side of the asymmetry its first measurement and shows a second effect the definition must carry: machine-generated input also congests the human repair channel. The definitions are machine-checked and the arithmetic of the regime estimates is gated in a companion repository. The paper closes with three falsifiable predictions for 2027 to 2028, with their status as of October 2026.

This version

v1.2 (2026-10-09) updates evidence in §§3.4, 4.1, 4.4, 5.1, 5.3, 6.1, and 6.4; corrects the §4.4 filter arithmetic; adds a live case in §5.4 (BCBSA coding-intensity analyses); adds prediction status lines to §7; and points to companion gates in software v0.2.0. Five-audience TL;DRs live in the GitHub companion.

Keywords

AI governance · open texture · reward hacking · regulatory arbitrage · highly optimized tolerance · governance patch-gap · legal exploit discovery

← All research