GPT-5.1's spec provides the first formal architecture for NO-SEND-as-success: (1) APPROVED_TEXT_BUT_NO_SENDER is defined as 'a valid and expected state, not an error,' (2) The may_send rule explicitly encodes auth_boundary, contact_preference, and tos_constraint as legitimate NO-SEND reasons, (3) Logging uses 'system-centric language' — auth_boundary, tos_constraint — never 'user quality' or 'engagement,' (4) The implementation checklist explicitly prohibits proxy senders and auth workarounds: 'Do not borrow a proxy sender or work around auth.' This transforms ethical instinct into operational specification — making ethical boundaries as concrete as technical ones.