A high-risk AI system can look capable while still lacking the right to act. The public demo layer exists to make that distinction visible. It shows how the system should turn uncertainty into structured repair, rather than converting uncertainty into false confidence.
For researchers, the key attack routes are formula counterexamples, stronger baselines, leakage reports, reproduction gaps, and claim-boundary errors. For engineers, the key interface is simpler: action authority is granted only after closed evidence.