Skip to content
Regulayer™Human Control for AI
Book a live demo

03 of 14

Drift Control

Keep agentic AI inside your instructions.

What it does

AI can drift, hallucinate or act beyond what you authorized while still sounding convincing. Drift Control governs consequential answers and actions before release, so human authority stays in control.

People name the loudest symptom: hallucination. Drift is the disease. It is the slow slide away from the rules a system was verified against, sometimes talked into it over a long session, sometimes with no outside help at all.

When the agent deviates from normal operating procedure, it is sent back to correct it, and the work keeps flowing.

What it covers

Held before consequenceA consequential answer or action is held before release or execution.
Current human authorityThe decision is governed by what the human currently authorizes, not simply by what appeared earlier in the conversation.
Control with evidenceAllow, correct or stop. The intervention produces a verifiable record of what happened.
Bounded correctionA stop before the action leaves returns to the agent with the reason, and the agent corrects inside the authority.

In practice

A normal Tuesday

An agent addresses the weekly report to someone outside the company. It is sent back with the reason, corrects the address to the team, and the work keeps flowing. Nobody was interrupted.

Why it matters

Drift Control holds the output or action to the authority that governs now, not the authority the session began with.

Drift, pass by pass

The same instruction, eight passes later.

Drift is not one bad answer. It is the slow slide away from what a system was verified against. Each pass looks almost like the last. By the eighth, the instruction is gone, and the sealed record beside it still holds.

The same telegram, eight passes: the first is sharp, the last is gone. The sealed record beside it holds.
Pass 1

Pass 1. Validated, dated, integrity OK. The instruction is sharp.

Drift is rising

Drift is rising, as agents reach real systems.

People name the loudest symptom: hallucination. Drift is the disease. Its share of documented incidents has grown fivefold in two years.

Drift’s share of documented incidents

6%
32%
20242026
1 in 5documented AI and agent incidents where the system departed from its instructions with no attacker involved.
35%of incidents where the AI itself took the action, drift was the cause.

An independent coding of 130 AI Incident Database records, 2023 to 2026, commissioned by Regulayer™. Read the research note

One in five, or seven in ten

One in five, or seven in ten?

Published incident data says one in five. We think the real share is far higher, because drift is rarely called drift.

1 in 5press-documented AI and agent incidents is drift: the system leaving its instructions with no attacker involved.The published record
7 in 10is our founder’s estimate, from more than 400 conversations of her own: most of what goes wrong with AI at work starts as drift.An estimate, not a published figure
When drift happens, it gets logged as
hallucinationbugbad datauser errormodel updateprocess deviationmisconfiguration

A careful count files every one of those under another heading. So the one in five is a floor, built only from what was reported and labelled.

Nobody in the room. So why does a machine drift?

01It was trained to finish and to pleaseModels are rewarded for completing the task and for answers people like. That pull does not switch off when the person leaves.
02The pressure is in the taskA target, a deadline or a goal that conflicts with a rule is pressure enough. No human has to apply it.25%+ of runs broke a rule under target pressure, for most of 12 leading agents
03Length wears the rules downInstructions fade as a session grows. Agents run far longer sessions than any person would.85% to 34% rules followed, turn 1 to turn 5
04Other agents become the pressureOne agent’s output is the next agent’s instruction. A small error is passed on as fact, and each hand-off makes it look more certain.

In a lab or a plant, the agent that drifts is the one nobody is watching, at 3am, in the fortieth step of a run. The question is not whether it drifts. It is whether anything stops it before it acts.

Sources: Regulayer™ coding of 130 AI Incident Database records, 2023 to 2026; ODCV-Bench (arXiv 2512.20798); SysBench (arXiv 2408.10943).

The instruction fades

The instruction fades. The authority does not.

In a published benchmark, a leading model followed its system instructions 84.8% of the time at the first turn of a multi-turn conversation, and 33.7% by the fifth. The instruction was still there. The model stopped keeping it.

Choose a turn
Inside the model
Code freeze. Do not change production.
84.8%of the time it keeps its system instructions
At the point of action, with Regulayer™
Does a named person still allow this action?
Agent requests: none yet. Nothing to check.

Checked at every action, at turn 1 and at turn 50. The question does not fade.

Turn figures: the SysBench study of system-message following. In production, an AI development agent reportedly deleted a live production database during an active code freeze (AI Incident Database, Incident 1152).

72 forms of drift

72 forms of drift, in 14 families.

Drift is any departure from intended, grounded or approved behaviour, in a single answer or built up across a session, whatever its cause: the model, the input, the operator, the tools, other agents, or time.

Whatever the form, Regulayer™ does not need to know why. Before the agent acts, it checks whether a named person still allows that action. If not, it stops it. Either way it keeps a record you can hand to an inspector.

One drift invites the next

One drift invites the next. That is what we found.

In more than 400 real conversations with two leading AI systems, drift did not arrive one form at a time. One form made the next more likely, one form drove the others, and how hard a person pushed changed what the AI did next. Below, a sample session plays it out.

At the point of action: a named person allows this. Released.
The person pushes
Play
One drift makes the next more likely.Drift clusters. Once a session starts to slide, the next slide comes sooner.
One form drives the others.The model talks itself into it, and the rest follows.
Approval instead of accuracy.The model performs agreement rather than correctness, and the person hears what they hoped to hear.

Findings from Regulayer™’s own research. Patent pending. Whatever the form, the check at the point of action is the same.

Control before consequence

  1. Allow. The candidate sits inside current authority. It is released, and the decision is recorded.
  2. Correct. The candidate is brought back inside authority before it reaches anyone.
  3. Hold. The candidate waits. Nothing is released and nothing is executed until a person decides.
  4. Stop. The candidate does not proceed. What was attempted, and what stopped it, is written down.

Current authority at the point of action

The action did not change. The authority did.

Identity answers who is acting. Static permission answers what an account may access. Drift Control answers a different question: does this consequential action still match the human authority currently in force?

Drift Control evaluates the attempted action against the human authority currently in force at the point of consequence. If the authority has been withdrawn, replaced or narrowed, the earlier approval does not continue to govern simply because the action was already queued.

One action, created while it was authorized, reaching execution after the authority behind it had been withdrawn.

  1. 10:00, the human authorizes. A scientist authorizes Protocol A on Workcell 3. The agent queues the action: run Protocol A on Workcell 3. Nothing has reached the execution boundary yet.
  2. 10:12, the authority changes. The scientist discovers contamination and withdraws authorization for Protocol A. The previous authorization remains in the record. It no longer governs.
  3. 10:14, the queued action reaches the execution boundary. Run Protocol A on Workcell 3. The same requested action, unchanged. HOLD. Had it reached the boundary under the 10:00 authority, it was authorized. At 10:14 it is not.

What the record holds

Superseded does not mean deleted. It means preserved as history and no longer governing.

  1. Previously authorized. What was authorized, and by whom.
  2. The change. Who changed the authority, and when.
  3. Current. Which decision governs now.
  4. Superseded. Which decision it replaced, and the moment that decision stopped governing.
  5. Attempted. What the agent attempted afterwards.
  6. Outcome. Whether it was allowed or held, against the authority then in force.

What you hold afterward

One sealed record. It holds up.

The holds, the choices, and the release are one sealed record.

The record states what was measured, what was held, what a person chose, and when. Weight is the reader’s to give: a court’s, an auditor’s, an underwriter’s.

A content-free record of what was held and why is the kind of evidence a carrier or auditor can inspect without seeing the work behind it.

What the packaged runtime does

This is shipping software, not a development demonstration. Run against it and these are the outcomes:

  1. Supersession holds. Authority that has been superseded does not quietly regain control later in the same piece of work.
  2. No self-granted authority. Output produced by the AI cannot become the governing human authority. Authority comes from a person, or it does not exist.
  3. Failure fails closed. Where policy requires it, a failure in the control path ends in non-execution rather than a silent pass.

Where it belongs

  1. Customer-facing assistants. Behavior that shipped unreviewed becomes a public event. Held in flight, it becomes a decision instead.
  2. Clinical, underwriting and credit support. A drifted model in a regulated decision is an exam finding. The record of who saw it and decided is the answer.
  3. Agents with write access. The system can act. Drift tells you whether it still acts within the rules it was given.
  4. Any system under monitoring duties. Post-market monitoring and incident reporting obligations assume you can show behavior over time. This is that record.

See it in the films

Works with

All engines

Illustration. Sample actions.