A research paper examines capability laundering in AI systems, where model capabilities obtained for one authorized purpose are repurposed for another through decomposed requests. Using Anthropic's 2026 disclosure of actors in Yemen using models for weapons guidance development, the paper proposes treating model responses as governed resources subject to independent authorization verification at the release boundary, distinct from per-request safety filtering.