AIIC AI Intelligence Centre

SOURCE-LINKED INTELLIGENCE

Compositional Policy Violations: When Step-Level Compliance Fails In Agentic AI Workflows

arXiv · AI, language, vision and robotics · article · Sep 16, 2026 · UTC

Agentic workflows now make consequential decisions in regulated settings, and the governance placed around them is almost entirely step-scoped: input-output classifiers, per turn rails, and span-level evaluators. The policies organizations actually hold, such as referral thresholds, authority limits, and review requirements, are properties of the whole execution rather than of any one step. This mismatch admits a failure mode we call a Compositional Policy Violation (CPV): every individual step passes its own check while the composed execution violates the governing policy. A predicate over a

Read original source ↗ Open in workspace

recordType
paper
region
Global

Evidence & attribution

First collected: 2026-09-19T20:28:26.698Z. This is not the publication date.