Blog

Blog

Notes on the line between probabilistic components and deterministic controls.

  1. Audit you don't have to trust

    A complete audit log is not evidence if whoever produced it can rewrite it. Under a regulator, integrity has to be checkable by someone who doesn't trust the vendor.

  2. The agent proposes; the runtime presses the button

    Most agent governance contains a free-acting agent. The stronger move is never to let it act: the agent proposes, and the runtime presses the button.

  3. The refusal is a control output, not a conversation

    Venkat Peri is right that intent classification isn't a quality gate. In a regulated domain, a scope layer biased toward pass isn't one either: the refusal is a control output.

  4. A typed output is not a governed action

    Models that answer with a calibrated choice make deciding cheap. The schema guarantees the shape of the answer; who authorized acting on it is a separate question.

  5. You can't fight probabilism with probabilism

    Everyone agrees regulated agents need deterministic controls. The failures come from controls that are secretly probabilistic, and from not knowing where the line goes.