Three research papers published in early 2026 are converging on a conclusion the physical security industry hasn't fully absorbed: autonomous AI operating in critical infrastructure requires governance architecture built in at the design stage, not retrofitted after the incident. The gap between autonomous capability and accountable operation is no longer theoretical — researchers are measuring it, and the measurement is not flattering.