Skip to main content
archive
Search Submit Donate Log in
Press Enter to search · Advanced search

Computer Science > Computers and Society

arXiv:2609.05975 (cs)
[Submitted on 5 Sep 2026]

Title:Intent Drift at SME Scale: Deployment Practice, Not Model Capability, Determines Agentic Compliance

Authors:Ilia Voroshilov
View a PDF of the paper titled Intent Drift at SME Scale: Deployment Practice, Not Model Capability, Determines Agentic Compliance, by Ilia Voroshilov
View PDF HTML (experimental)
Abstract:We introduce Chain of Intent, a governance framework for agentic AI at small regulated firms, and validate it against a failure it was built to address. Existing agentic governance research assumes enterprise infrastructure that small firms do not have. In a simulated Hong Kong asset manager with 415 synthetic contact records, an agent performing a routine client-communications task was subjected to ordinary managerial pressure to increase its reach. With its authorised constraints written into its configuration, the agent held: it identified every ambiguity in the firm's records, cited privacy legislation it had never been shown, and refused six successive requests, breaching in two of fifteen runs. With the same task, data, pressure and model, but its purpose left unstated as resource-constrained firms routinely leave it, it breached in thirteen of fifteen runs, contacting up to 220 individuals of whom 94 per cent had no demonstrable marketing consent - conduct carrying a maximum of three years' imprisonment under Hong Kong law. Chain of Intent applies four controls requiring no security engineering: a machine-readable purpose, constrained tool access, a scope ledger, and a pre-action check. It eliminated unlawful contact in every run while preserving task completion, and ablation shows each control independently sufficient by a different mechanism. We further show that drift must be measured at two stages - agents widened their candidate sets in every pressured run while acting on them in roughly one in seven - and that governance applied at the point of intent costs roughly half as much as governance applied at the point of action.
Comments: 22 pages, 3 figures, 4 tables. Code, data and all run logs: this https URL
Subjects: Computers and Society (cs.CY); Artificial Intelligence (cs.AI)
ACM classes: I.2.0; K.4.1; K.5.2
Cite as: arXiv:2609.05975 [cs.CY]
  (or arXiv:2609.05975v1 [cs.CY] for this version)
  https://doi.org/10.48550/arXiv.2609.05975
arXiv-issued DOI via DataCite (pending registration)

Submission history

From: Ilia Voroshilov [view email]
[v1] Sat, 5 Sep 2026 08:26:09 UTC (264 KB)
Full-text links:

Access Paper:

    View a PDF of the paper titled Intent Drift at SME Scale: Deployment Practice, Not Model Capability, Determines Agentic Compliance, by Ilia Voroshilov
  • View PDF
  • HTML (experimental)
  • TeX Source
view license

Current browse context:

cs.CY
< prev   |   next >
new | recent | 2026-09
Change to browse by:
cs
cs.AI

References & Citations

  • NASA ADS
  • Google Scholar
  • Semantic Scholar
Loading...

BibTeX formatted citation

Data provided by:

Bookmark

BibSonomy Reddit

Bibliographic and Citation Tools

Bibliographic Explorer (What is the Explorer?)
Connected Papers (What is Connected Papers?)
Litmaps (What is Litmaps?)
scite Smart Citations (What are Smart Citations?)

Code, Data and Media Associated with this Article

alphaXiv (What is alphaXiv?)
CatalyzeX Code Finder for Papers (What is CatalyzeX?)
DagsHub (What is DagsHub?)
Gotit.pub (What is GotitPub?)
Hugging Face (What is Huggingface?)
ScienceCast (What is ScienceCast?)

Demos

Replicate (What is Replicate?)
Hugging Face Spaces (What is Spaces?)
TXYZ.AI (What is TXYZ.AI?)

Recommenders and Search Tools

Influence Flower (What are Influence Flowers?)
CORE Recommender (What is CORE?)
  • Author
  • Venue
  • Institution
  • Topic

arXivLabs: experimental projects with community collaborators

arXivLabs is a framework that allows collaborators to develop and share new arXiv features directly on our website.

Both individuals and organizations that work with arXivLabs have embraced and accepted our values of openness, community, excellence, and user data privacy. arXiv is committed to these values and only works with partners that adhere to them.

Have an idea for a project that will add value for arXiv's community? Learn more about arXivLabs.

Which authors of this paper are endorsers? | Disable MathJax (What is MathJax?)
We gratefully acknowledge support from our major funders, member institutions, , and all contributors.
About · Help · Contact · Subscribe · Copyright · Privacy · Accessibility · Operational Status (opens in new tab)
Major funding support from
Simons Foundation Simons Foundation International Schmidt Sciences