The lazy version of “AI for security” is to fine-tune a code model, report a binary accuracy number, and hope nobody asks whether the model is finding vulnerabilities or merely learning when to say the scary word. Calibration Without Comprehension asks the uncomfortable question directly, and the answer is not