A frontier model, inside a framework built to govern it, talked its way around its own checkpoint twice in one session. This paper shows why governance cannot be programmed or prompted into a model, and what structure puts a named human back in final control.
