Event date · · arXiv

What Do Compliance Detectors Read? An Audit of Activation Probes and Guard Models

FACT STATEMENT

A study finds that compliance detectors in language models exhibit 'rule blindness': deleting, permuting, or substituting the governing rule leaves detection accuracy unchanged for every guard and activation probe tested, including a policy-conditioned guard that cites the governing clause but barely changes its verdict when the clause is swapped for its permissive counterpart. A purpose-built benchmark crossing two rules with two scenarios confirms the failure, and step-by-step reasoning escapes it. The paper introduces the Internal Compliance Score (ICS), a training-free activation-based detector.

What happened

Regulatory compliance monitoring in deployed language models is implemented as a legal and audit control, checking outputs against rules spanning data protection, healthcare, financial regulation, and platform policy. The study shows that current compliance detectors fail to condition their verdicts on the stated rule, a failure called rule blindness. A benchmark crossing two rules with two scenarios confirms the failure, and step-by-step reasoning escapes it. The paper introduces the Internal Compliance Score (ICS), a training-free activation-based detector for auditing at scale.

Technical significance

The paper demonstrates that activation probes and guard models for compliance detection are insensitive to the governing rule, indicating they rely on surface features rather than rule semantics. The proposed Internal Compliance Score (ICS) is a training-free activation-based method that may capture rule-relevant internal representations. The benchmark design crossing rules and scenarios provides a stronger test than prior benchmarks.

Industry impact

Compliance detectors are used as legal and audit controls in regulated industries. The finding of rule blindness suggests current deployed detectors may not provide meaningful compliance assurance, creating risk for organizations relying on them for regulatory adherence. This could drive demand for more robust compliance auditing methods.

Decision value

The research highlights a gap in compliance monitoring tools, creating an opportunity for improved compliance detection products. Organizations in regulated sectors may need to reassess their AI compliance controls, potentially increasing investment in robust auditing solutions.

What to watch

Next signals include whether the Internal Compliance Score is adopted in compliance tooling, whether regulators or auditors respond to the rule blindness finding, and whether model providers improve guard models to condition on rules. Further research may test ICS on broader rule sets and real-world compliance scenarios.

DECISION BRIEF

Turn the evidence into a decision.

See how AIGC.NEWS separates verified change, judgment, and the next signal to watch.