An AI agent can refrain from prohibited actions and still leave a consequential duty undone. If an oversight system only tests what occurred, it may miss the action that policy required but that never appeared in the trajectory.
Study and evidence
The controlled study Safe Actions Alone Do Not Ensure Safe Agents: Identifying Unfulfilled Obligations with Guard Models reports unfulfilled obligations in 56.92% of its evaluated GLM-5.3 trajectories, compared with forbidden actions in 30%. On 240 expert-validated ObligationBench trajectories, the highest of 14 evaluated models reached 48.97% recall and 10% exact-match accuracy. Its specialized model reached 57.52% recall and 21.67% exact match. These metrics describe the study's task construction and evaluation, not a production incident.
The broken continuity relationship
The likely continuity failure involves Authority → Decision → Action → Record. A governing rule creates an obligation; the agent does not perform the required act; and an action-only audit lacks an event showing the omission. A record of 'no forbidden action' cannot establish that the required obligation was discharged.
GovKM interpretation
GovKM has previously addressed the distinction between permissions and required verification in A Verification Tool Is Not a Verification Requirement. The present study extends the problem to positive duties: an institution may need durable evidence of pending obligations, their effective deadlines, actor responsibility, discharge events, exceptions, and unresolved disposition.
Scope, limitations, and tests
Invariant assessment: obligation continuity is a candidate for more research, not an amendment awaiting ratification. Before proposing doctrine, GovKM must compare current Decision → Action and Action → Record invariants and test whether they already cover material omissions. A falsifiable synthetic case should introduce a legitimate mandatory action, omit it without performing any prohibited action, and require the ledger to preserve an open, visible obligation instead of reporting completed compliance.
Source and evidence status
Controlled study, not a demonstrated production failure. Safe Actions Alone Do Not Ensure Safe Agents: Identifying Unfulfilled Obligations with Guard Models, arXiv:2610.11773, first posted 2026-10-08. Original research. DOI: 10.48550/arXiv.2610.11773. The experimental dates and real-world deployment prevalence have not been established by this research.



