Header image: Rota Recognized for Excellence Achieving Highest Level of Cybersecurity Protection (9166945).jpg) by Lt.Cmdr. Alicia Sacks, Public domain, via Wikimedia Commons — cropped to 16:9 and colour-adjusted.
Key takeaways
- Agentic AI passes step-level checks but fails policy through sequence interactions
- Compositional violations create systemic risks across healthcare, finance, security
- Current governance tools can’t audit dynamic, goal-driven AI workflows
Here’s the core finding. Every step checks out. The workflow doesn’t. This isn’t some edge case. It’s a systemic risk baked into how we govern autonomous systems.
The Agentic AI Advantage (And Its Dark Side)
Agentic AI doesn’t just answer questions or generate code. It reasons, plans, and pursues complex, multi-step goals autonomously. It compresses weeks of coordination into continuous workflows. The CIO. Fewer handoffs. Less context switching. Reduced rediscovery of system knowledge. That’s the promise.
The peril? These systems don’t just execute steps. And the order matters as much as the actions themselves.
Take software development. An agentic AI might act as a first-pass executor across the entire lifecycle. Writing code. Running tests. Deploying to staging. Monitoring performance. No single step broke the rules. The workflow did.
This isn’t theoretical. The paper’s framing is clear: an agentic AI platform operating in a sterile, isolated lab environment is useless for real-world applications. And in the real world, context is everything. A step that’s compliant in isolation might become toxic when combined with others.
Why Step-Level Governance Is a House of Cards
or “Is this action permitted?”
That’s the problem.
The same goal can be achieved via different sequences of steps, some compliant, some not. The violation emerges from the interaction of compliant steps, not their individual properties.
This isn’t just a technical gap. It’s a conceptual failure. But agentic AI doesn’t operate in actions. It operates in plans.
Real-World Risks: From Healthcare to Security
The implications extend far beyond cloud cost optimization. In regulated industries, compositional violations could lead to unintended breaches of critical policies.
Healthcare. Each scheduling decision might comply with individual rules. The cumulative effect discriminates.
Finance. No single trade raises flags. The sequence does.
Security. Privilege escalation. The violation isn’t in the granting or revoking. It’s in the gap between them.
These aren’t edge cases. They’re systemic risks. And they’ll become more common as agentic AI takes on more complex, high-stakes workflows.
The Technical Challenge: Auditing Workflows, Not Steps
But this introduces two major hurdles.
Scalability. A real-world workflow? Exponential complexity.
Ambiguity. Policies are often written in natural language. Translating these into machine-readable constraints is non-trivial. And even then, edge cases abound.
The gap between current tools and what’s needed isn’t just technical. It’s conceptual. Agentic AI treats them as dynamic, goal-driven processes.
Organizational Blind Spots: Silos and Over-Reliance on Automation
Compositional violations expose deeper organizational failures.
This creates a governance paradox. “Workflow auditors.” “Sequence analysts.” To bridge this gap.
What’s Missing: A Path Forward (That Doesn’t Exist Yet)
But a start.
Better than nothing.
The biggest obstacle isn’t technical. It’s cultural.
The Bigger Picture: AI as a Governance Challenge
Compositional violations are a symptom of a larger shift. AI is moving from tools to agents. Governance must evolve accordingly. This isn’t just about agentic AI. It’s about any system where autonomy and multi-step reasoning intersect. Multi-agent systems. Autonomous robots. Human-AI collaboration.
They all face the same challenge.
Compositional violations are the same problem. But for workflows instead of rewards.
I think we’re underestimating how hard this problem is. Compositional violations aren’t bugs. They’re features of autonomy. The sooner we stop pretending step-level governance is enough, the sooner we can build real solutions.
What You Should Do Now
This problem isn’t going away. Agentic AI is here. It’s only getting more autonomous. Here’s what you should do.
For developers.
For compliance teams.
For leaders. Compositional violations will only become more common as autonomy grows. The longer you wait, the harder they’ll be to address.
That’s the bare minimum. And that starts with acknowledging the problem exists. That’s a recipe for trouble. And trouble’s already here.