InflectAI, Inc.

Founder Note

Which Rules Matter Now?

Before an AI system decides whether an action is allowed, it has to recognize which policy regimes the action has approached.

  • Entity: InflectAI, Inc.
  • Published: September 3, 2026
  • Scholarly companion: arXiv:2608.30757

Before you send a sensitive email, there is sometimes a moment when you stop. You may not know the exact rule that applies. You have not pulled up the policy manual. Something about the email rings a bell, and you ask: should we get counsel involved?

The email may be fine. Counsel may ask for more facts. Counsel may point to a rule you did not know existed. The first decision came earlier. The email had reached a part of the institution that deserved attention.

An AI agent needs that reflex before it acts. Governance discussions often begin one step later, with the question of whether an action is allowed. That question needs the relevant rules, the relevant facts, the conditions and exceptions, and an authority that can make the decision. An agent cannot work through every rule in an institution every time it proposes an action. It has to recognize which rulebooks it has just wandered near.

That is the intuition behind my new arXiv paper, Which Rules Matter Now? Policy-Centroid Routing Before an Intelligent System Acts.

The Rulebooks In The Room

Consider a proposed action: send two weeks of customer-support transcripts to a new outside AI vendor so it can test automated summaries.

It arrives as an ordinary business request. Two weeks of customer-support transcripts. A new outside vendor. A processing location that has not yet been answered. Now privacy, information security, vendor procurement, AI governance, and perhaps cross-border transfer rules are all in the room. The system has not decided whether the proposal can proceed. It has discovered that the proposal is no longer a simple request.

The action arrives in the language of the world. The rules live in separate documents, written for different policy regimes. Before an AI agent gives a confident answer, it needs a way to surface the regimes that deserve review.

A proposed action positioned near privacy, information-security, and vendor-procurement policy regions.
A schematic of a proposed action near privacy, information-security, and vendor-procurement policy regions.

The figure is a schematic. The black point is the proposed action. The colored regions are bodies of policy. The dots inside them represent a declared center for each policy regime. An action near several regions should produce a review agenda with several items on it.

The agenda says: “This has become a procurement question, a privacy question, and a security question. Get the right people involved.”

Routing Before Judgment

The paper calls that first layer policy-centroid routing. It asks whether a proposed action and a collection of policy regimes can be represented in a shared semantic space, with each regime summarized by one or more declared representative points. The system measures proximity and sends the regimes that cross a declared threshold to authoritative review.

Routing brings the right rulebooks into view. Adjudication interprets those rulebooks against the facts. Enforcement carries out the decision. Collapsing those three jobs into one confident answer asks a routing system to make a decision it has not been given authority to make.

Policy-centroid routing stops after the first job. It says which rules the action may have approached, then hands the question to the authority that owns them.

A Theory Has To Be Allowed To Lose

The paper sets a clear bar for the idea. It contains six falsifiable propositions and seven follow-on studies. The studies have to show that the mechanism recovers more of the relevant policy stack under a fixed review burden. A longer and more expensive list does not count as success. The empirical work has not been run yet.

Several failure paths are already visible. A rare data-retention duty can disappear inside a broad privacy representation. An action can sit close to one obvious policy regime while a second, overlapping obligation goes missing. A conventional structured workflow, lexical search system, dense retriever, or direct classifier may perform as well or better. An unbounded review queue can turn caution into a new failure of its own.

Back To The Email

The original email can still go out. It may be perfectly fine. Before an AI agent sends it, the system should be able to say: this action may have reached privacy, security, and procurement. These are the rulebooks that need review before I continue.

That first moment of recognition is the problem the paper takes on. The studies will determine whether policy-centroid routing can carry it.

Sources And Notes

Thomson D. Nguy. “Which Rules Matter Now? Policy-Centroid Routing Before an Intelligent System Acts.” arXiv:2608.30757, 2026. https://arxiv.org/abs/2608.30757. The paper proposes a mechanism and study program. It reports no empirical efficacy result.