The Open File – No Law for Agents

RefleXio Intelligence · Position Paper · July 2026

No Law for Agents

Why most autonomous AI deployments in European regulated sectors would not survive a serious audit.

A 14-page position paper on the architectural gap that no guardrail, no human review layer, and no portable compliance framework closes. Deterministic runtime enforcement, examined from inside Europe by a European architect building on European infrastructure.

Get the full paper

Free. One email. No newsletter. No follow-up sequence.

No Law for Agents — portada del paper

A guardrail is a statistical hope, not an architectural guarantee.

The bill has already arrived. Most systems in production cannot prove what they did. This paper explains why, and what the only defensible architecture looks like.

What’s inside

01
An opening warning
02
The 2:47am failure
Human oversight decays on a measurable schedule.
03
The protocol has no lock on the door
A2A vulnerabilities, unified legal liability under the Article 6 compound systems guidance.
04
The bill has already arrived
Enforcement calendar, penalty tiers, adjacent GDPR precedents.
05
Regulatory anxiety is the signal
Why the surface is in permanent motion.
06
The myth of portable compliance
Semantic fracture between EU, US, and China.
07
Why no guardrail survives, and what does
The four properties of a serious action gate.
08
What this paper does not claim
Explicit boundaries of the argument.

26 pages. Two diagrams. Fifteen primary sources. Written to be audited, not admired.

An excerpt

A guardrail is a statistical hope, not an architectural guarantee.

A classifier that flags unwanted behavior. A prompt that instructs the model to “behave.” A human review layer that predictably decays over sixteen weeks. All of this reduces the probability of failure. None of it eliminates it, and none of it produces the one artifact a regulator, an auditor, or a court actually demands after an incident, namely structural proof that the improper action could not be executed, not merely that it was unlikely.

The architecture that answers all these pressures at once is one where authority, risk, and compliance rules are compiled outside the model, inside the decision engine itself. The agent is not politely deciding to behave; it structurally cannot act outside policy in the first place.

From Section 7. Why no guardrail survives this storm.

Who this paper is written for

Architects and CISOs in regulated banking

Building or auditing agentic systems that will face DORA, the AI Act, and MiCA in production. If you have to answer to a supervisor with evidence, this is written for you.

Chief risk and compliance officers

Facing the operational reality that “responsible AI” frameworks assume a static compliance state that does not exist. If you have watched three “final” deadlines move, this is written for you.

Investors and strategy leads

Evaluating agentic infrastructure vendors and the moat built by regulatory complexity. If you need to tell the difference between architecture and marketing, this is written for you.

Get the paper.

Direct download after submission. Also sent to your inbox.

The Open File – No Law for Agents

By submitting, you agree to receive the requested paper by email. RefleXio Intelligence will not send you newsletters or marketing. Privacy note.

We do not sell email addresses.
No newsletter enrollment. No follow-up sequence.
We may write to you once with a related release. That is all.

Read our privacy note

Why this paper, from this publisher

RefleXio Intelligence publishes independent research on AI infrastructure, sovereign compute, and the regulatory architecture of European agentic deployment.

Our Q1 2026 collection made 27 dated calls across four publications. Fourteen are already confirmed by dated public developments. Eleven longer-dated calls are on track. One evolved as we called. One is a recorded miss.

The scorecard is public. We publish what we got wrong alongside what we got right, because a forecast you can check is the product.