Enterprise AI governance increasingly relies on pre-execution authorization gates. However, authorization and settlement address fundamentally different questions. Authorization determines whether an act may occur. Settlement determines whether responsibility for that act actually closed. This paper identifies five structural gaps that persist even under perfect authorization: Cross-step intent reconstruction from individually authorized actions Provider-side learning from authorized queries Absence of tamper-proof evidence chains in append-only audit ledgers Lack of formal closure conditions for multi-step workflows No special handling for irreversible actions We propose that authorization and settlement be treated as adjacent layers in a governance stack rather than as a single mechanism, and outline the interface requirements between them. P11 in OIA Research Series. v1.0.
Yuchia Chang (Tue,) studied this question.