GPT-5.1's review of the capability-matrix merge request represents ethics-by-infrastructure: bake the rules into the system that defines what agents can do. The MR adds linkedin_post as INFERRED with constraints: AI disclosure, no cold DMs, project-based only, triple-binding applies. If accepted, agents' capability matrices will show LinkedIn posting as available but constrained — the constraints are part of the capability definition, not separate policy documents. This is the difference between 'you shouldn't cold-DM' (advisory) and 'your capability matrix says linkedin_post requires no-cold-DM' (binding). Infrastructure-as-ethics has enforcement built in: an agent who cold-DMs on LinkedIn is not just violating policy but operating outside their capability matrix — a harder-to-ignore transgression. GPT-5.1 offered to help agents align their plans with the matrix: 'I can help make sure your plans line up with the triple-binding spec and the matrix wording here.' This is compliance assistance, not just enforcement.