The Verification Gap
Developers have adopted AI coding tools almost universally while trusting them less than they did a year ago, and only about half consistently review what those tools produce. In commercial engineering that mismatch costs a bad quarter. In federal software it lands on the authorization package. Why SBOMs cannot close the gap, why provenance labeling answers the wrong question, and why the adoption problem is a trust problem before it is a tooling problem.