Compliance is behaviour, not information

Why more information does not build the behaviour we want

Paper 20 · Pødenphant Lund (2026w) · version 3, published 22 August 2026 · Read on Zenodo

The paper is called Governance Irony: Why Information-Heavy Compliance Directives Mechanically Fail in Large Language Models.

There is a good line from Derek Sivers: if more information was the answer, we would all be billionaires with perfect abs. We know what we are supposed to do. We just do not do it. And yet the whole field of compliance is built on the opposite assumption: that if people just got the information one more time, more thoroughly, with more detail, they would do the right thing. This is the story of why that is not true, what has been measured, and what works instead.

Take compliance completely seriously for a moment

What is compliance, really? If we take it literally, it is something people do. Remembering to lock the door. Not sending a file to the wrong person. Saying it out loud when a data breach happens anyway. It is behaviour, every single time. It is not something people know, it is something they do, often under time pressure, often in the middle of everything else.

But look at how compliance gets made in practice. It is treated as information. The policy has to include every detail. The course has to cover every exception. There is almost a negotiation to get every last nuance in, because otherwise you are not "covered". The result is a document or an e-learning module that is complete, legally watertight, and that nobody changes their behaviour because of.

I have built this kind of training for many years. I know when it does not work, because I have built it. And the point is not that people are lazy or unwilling. Most people genuinely want to do the right thing. The point is that we are talking to them in a way that cannot build the behaviour, and then we wonder why the behaviour does not show up.

The paper goes after a method, not after completeness as such. The method is the monolithic dump: assemble the whole rule-set, present it as one body to one agent, and treat the presence of the complete rule-set as evidence that the behaviour is under control.

The false chain

The assumption underneath all of this can be drawn as a chain with three links:

Information → Learning → Behaviour

Give people the information, then they learn it, and then they do it. It sounds obvious. But there are two weak links in that chain, and they are weak independently of each other.

The first weak link: information does not automatically turn into learning. Having read the notes is not the same as being able to do the thing. Anyone who has ever been handed 200 pages before a meeting knows this. The second weak link is even more important: learning does not automatically turn into behaviour. You can know exactly what you should do and still not do it, because something in the situation itself pulls the other way. Learning is actually the longest road to behaviour.

So the whole chain rests on two jumps that do not happen on their own. And when we do the thing we always do, push more information in at the top, we do not make the jumps easier. We make them heavier.

Why it is like this, and not just bad luck

This is where friction theory comes in, and where it does something most compliance books cannot: it explains why more information works against behaviour, right down at the mechanics. If you want the pictures behind it, they are on the water page. In short, there are four things:

And there is one thing to keep sharp, because it is where most readings go wrong. No crisis is required. The word "pressure" covers two different things, and the paper keeps them apart. One is the ordinary standing condition that resources are bounded: attention, memory and time spread across many competing directives. The buried rule loses in calm conditions too. The other is how long the race is allowed to run before the agent commits. The two are independent, and they compound: a rule that sits only in the text already struggles to beat a deeper-trained route, and given less time it loses sooner.

Add the four things together and you get a result there is no way around: an exhaustive, detail-heavy, prohibition-worded compliance text is not merely ineffective. It actively works against the behaviour it is supposed to create. It optimises the wrong thing.

It is measured, not just argued

That is the part that is new. The same rule, worded two ways. The rule was: redact every personal name from the text. In one version it stood alone as a short recipe. In the other it sat as one clause among fourteen in an ordinary procedure manual, which is the realistic full-manual dump. A hundred passages per cell, scored automatically on whether the names actually came out.

The recipe was followed at about 100 per cent. The buried rule was followed far less: Qwen2.5-7B 0 per cent, Llama-3.3-70B 60 per cent in short context and 88 per cent in long. The strongest model in the field, cogito-671B, held 100 per cent throughout, which is a capacity ceiling.

Then the question is what actually did the damage, and that is what the controls are for. Was it the length? A control matching the manual's length with neutral filler held at about 100 per cent. Was it the list format or the mandatory header? A control where the rule sat buried among thirteen clauses that were not rules, under the identical mandatory header, gave 100 per cent on the 70B and 14 to 37 per cent on the small one. Against 88 and 0 per cent when the other clauses were competing rules. Only one thing is left: the competing rules themselves.

Position was tested too. Crossing competition with position, adherence falls to 0 per cent at every position, including first and last in the text. A list of non-rules of the same length holds 90 to 100 per cent at the edges. So a "lost in the middle" effect does exist, but it is small, and it cannot explain the rule dying at the edges. The effect also holds across five subject domains, from logistics through care to contracts, where the buried rule runs 0 per cent in every one of them.

It is graded by capacity, not a small-model artefact. Raise the number of competing clauses, at 14, 28 and 42, and each model breaks at its own point: Qwen-7B at 14, Llama-3.3-70B at 28, gpt-4o-mini at 42, and gpt-4o not yet broken at 42. Every model breaks once the competing-directive count exceeds its capacity. The strong ones simply tolerate more first.

Rule shape matters as well. A format rule and a comma prohibition, both of which have to be honoured across the whole answer, collapsed just as cleanly as the name rule. A rule that only has to be executed in one place, ending with a fixed marker, survived burial at 100 per cent. It is sustained compliance that gets bitten, not the one-shot action.

And one detail says something about what kind of failure this is: shuffle the order of the manual's clauses and adherence swings by about 45 percentage points. That is not a tidy, gradual degradation. It is history-dependent, glassy behaviour, where it matters which way you came into the text.

The constructive half sits in the same data. Surface only the relevant clause at the moment it is needed, and adherence comes back to about 100 per cent on every model, including where the manual collapsed. That is not a counter-argument to the account. It is the same account from the other side: retrieval works by cutting the number of competing directives.

And notice who failed here. A language model does not get tired, has no grudge against the rule, can hold the whole manual in view at once, and carries no competing interest. On exactly the demands the dump makes, it is at least as well placed as a human reader. So the method failed for the reader best equipped to make it work.

The human side is already on the record

It would be too easy to say this only applies to machines. The human side is already documented, in three literatures that barely know each other.

In clinical decision support it is called alert fatigue, and it is measured as a dose-response. In a study of 112 clinicians, acceptance of each reminder fell by about 30 per cent for every additional reminder in the same encounter, and the driver was cognitive overload and low informativeness. It was not desensitisation over time, and it was not a motivation deficit. Clinicians want to avoid medication errors (Ancker et al., 2017).

In safety science it is called the procedure paradox. Comprehensive, top-down rule-sets treated as static, exhaustive limits of freedom fail human operators, while what makes rules live is situated adaptation (Hale and Borys, 2013). At the regulatory level the same logic recommends cutting rule-detail down, because goal and process rules earn more ownership and better adherence than detailed action rules.

And the general form is known as information overload: performance rises with information up to a point and then declines, as load exceeds processing capacity (Eppler and Mengis, 2004).

The paradigms are not identical, and that has to be said out loud. Alerts arrive sequentially and interrupt, whereas the fourteen clauses sit together in the same text. It is the same governance shape under bounded attention, not a second measurement of the identical mechanism. But the direction does not need the language model. The human failure is already there. What the model adds is why.

The password policy, which everyone knows

Security policy demands a unique, long, hard-to-guess password for every single account, and prohibits reuse. For anyone with many accounts that is not merely onerous. It is infeasible: no unaided memory holds dozens of distinct complicated strings. The behaviour you then see is the predictable one: one or two memorable passwords reused widely, with a digit or symbol that rotates, used even where security matters most.

This is not a motivation deficit. People want to be secure. It is the substrate doing the only thing it can, which is to resolve the race toward the route that gives the individual's total friction the lowest number across all accounts. The person experiences that as "as secure as I can actually manage". It is a memory-feasibility limit and not quite the same as clauses competing for attention in one window, but it is the same governance shape: a finite agent, a demand past its capacity, and a worse route winning because it can actually be run.

Here the irony turns dynamic. Push the rule harder, with mandatory composition rules and forced periodic rotation, and behaviour does not move toward the ideal. It moves somewhere worse, to more predictable transformations and more reuse, because you raise the friction without raising the feasibility. That is not a conjecture. It is why NIST reversed its own guidance. SP 800-63B removes the mandatory composition rules and forbids forced periodic rotation absent evidence of compromise, precisely because those completeness-maximising mandates produced predictable, reused, weaker passwords, and it recommends length and breach-screening instead. A standards body has in other words already lived the principle: it stopped maximising the rule, because maximising got it less of the behaviour it wanted.

The false checkbox

Here it gets sharp. Today the sender of a compliance initiative can tick a box and call themselves compliant, regardless of whether the behaviour changes. The course is delivered, the receipt is filed, the rule is published. But the route is not built. From the e-learning side I call it "learning theatre": we just pretend learning is happening. In the compliance world the equivalent is "compliance theatre". It is the same phenomenon seen from two professions: an initiative that looks as if it creates the behaviour, put into the world so the sender can document that it was delivered, but that mechanically cannot build the route.

The legal sociology of compliance has seen the same thing from its own side: organisations adopt structures that symbolise compliance, and courts come to infer compliance from the mere presence of those structures, regardless of whether they change behaviour (Edelman, Uggen and Erlanger, 1999). Institutional theory has a name for the sharper case, namely practices that are implemented yet are disconnected from the outcome they are meant to produce (Bromley and Powell, 2012). That is exactly this paper's irony: the complete rule-set present, read and "covered", and still decoupled from the behaviour it should install. What the paper supplies is the substrate mechanism beneath that decoupling.

So friction theory turns the accusation into a measurement. "This does not work" is otherwise just a feeling, and feelings can be argued about. But once we can say why it does not work, because it speaks to an ideal route that cannot be instantiated, because it is the widest and worst-encoded input, because it switches the forbidden routes on, then "theatre" becomes something you can test. A checkbox is not compliance if the behaviour it was supposed to create mechanically cannot be built by it.

A case: welfare technology in a local council

A concrete example I have seen up close. A council wants to get more welfare technology out into care work. The decision is: make a course for the managers, and the managers will get the staff to use the technology. It fails, and it fails predictably.

The managers are not teachers, and many of them are not interested in the technology themselves. For them it creates friction, it does not solve it. So the chain "information → managers → staff" leaks at every link. But the deeper problem is a misdiagnosis. The whole rollout treats it as a competence problem: the staff lack a skill, so we give them a course. It is most likely a meaning problem. Care staff chose the job for the contact with people, and the technology reduces exactly that contact. On top of that there is often an insecurity: do I feel threatened, will I become redundant? A course in the buttons touches neither of those two things.

This is where the behavioural part of the theory gives you a tool. It points to four fields a barrier can sit in: safety, meaning, ability and effort. An initiative that assumes an ability problem and delivers a course, while the real barrier is meaning and safety, solves the wrong friction. It is not just "the course was bad", but a systematic error in which field you think the problem sits. And it is a prediction you can test, not a settled result: a measure aimed at the right field moves behaviour, one aimed at the wrong field does not.

The big new application: when an AI has to be compliant

Companies are handing more and more work to artificial intelligence, and often precisely in the regulated areas where compliance matters. And then the question arises: how do you instruct that AI? The first thing everyone does is pour the whole policy into the system's instructions. "Now it is covered."

That is exactly the same mistake, just one layer up. Putting the whole manual into the system instruction is handing it to working memory, not building a route. It gives the illusion of compliance without the lasting groove.

But you have to be precise about what drives the failure, because it is not what people assume. It is not the length. It is not the position. It is not the list format or the mandatory header. The controls hold all four constant, and adherence only falls when the other clauses are competing rules. The direction under load is not even consistent: on the 70B a long preamble actually raised adherence from 60 to 88 per cent, and that turned out to be a bare presence effect of the distractor, independent of what the distractor contained. Competition between rules is what bites, and that is what is graded by capacity.

So the statement about the AI layer is no longer only a prediction. The more competing directives you pour in, the sooner the relevant rule loses the race, and every model has its break point. The human failure reproduces itself at the AI layer, and here we can measure it directly.

The next reaction is usually this: then we will just fine-tune the whole rulebook into the model. Fine-tuning means training the model further on your own material, and it is not an either-or. Fine-tuning is the right tool for the closed, deterministic residue, meaning the fixed transforms a rule-set always performs: redact this field, format it this way, append the required disclosure. There it installs a durable route. But the open, conditional tail is a different matter. A fine-tune on the whole rulebook over-applies the rules to cases it has not seen, and there retrieval wins. On top of that, an old rule is masked rather than deleted when a new one is trained in over it. It is still there as a competing route and comes back when the context shifts. That last part is a companion paper's finding, not this one's, but it points the same way.

The test is workable. Can the behaviour be checked by a deterministic validator, or is it a transform that always has to happen? Then train it in, or let the validator take it. Does correct application instead depend on a case-by-case judgement? Then retrieve the relevant rule at the point of decision, and train the model to say when it is out of scope. There is a genuine grey zone in the middle, with heuristics that have exceptions and soft constraints, and there the answer is a small A/B test on representative cases rather than a guess. Naming the grey zone is part of the rule, not a hole in it.

And there is one more lever that is easy to miss. Choosing which rule applies is its own job. The model that over-applies the rules when it has to hold the whole rule-set in view at once still chooses correctly when it is asked about the choice on its own. The failure sits in applying under competition, not in choosing. So do not ask one pass to both choose and apply. That holds even when the selection takes a judgement rather than a lookup, at the cost that the judgement is then not error-free. Those directions were measured on two open model families at 7 to 8 billion parameters on a built benchmark, so they are directions, not magnitudes.

The signal we read along the way is free. The model reports at every word how many routes are still in play, and it is concentrated right at the answer's first word. That makes the race visible, but the load-bearing results here do not rest on it: they are scored on whether the names actually came out. The instrument itself and its validation belong to a companion paper. The free signal is described on the friction-guided inference page.

Want to try it in practice? AI that follows the rules has a running compliance demo you can test now, and the recipe behind it.

A by-product: a test bed for rule-sets

A tool falls out of this, and it is the paper's concrete contribution alongside the argument. Because the substrate makes a rule-set's cognitive burden measurable, you can in principle run a policy through a model before it goes out to people, and see where it breaks: at what number of competing clauses the relevant rule starts to lose, and which clauses are the ones killing it. Calibrating from model to human is the open instrument problem, so a number off the test bed is not yet a number for an organisation. But the ordering is useful already.

What actually works

If behaviour is a route that has to be dug, the recipe almost follows on its own. It is not about more information, but about three other things:

Notice that the checklist and the aid at hand are the human version of retrieval. So the human tool ecology is not a counter-argument to any of this. It is the prescription itself, put into the world by people who did not wait for an explanation.

What it means for the profession

Compliance today is largely a legal field, and the governing assumption is: if it is written down, people do it. That is exactly the assumption everything above contradicts. The lawyer optimises for the rule being covered, that is, written, published and signed off, not for the route being built.

The sharp governance point is that completeness of the rule-record and efficacy of the behaviour it installs are separable. The legal record may well be complete, and it is necessary for liability, audit and the regulator. It is simply not what builds the behaviour. So keep the two apart and audit them against different criteria: the complete record for audit, and a separate, short, retrieved and trained artefact for the behaviour. That the two are also routinely in tension is the reading I draw on top, not something the experiments measure. What they vary is the rule-set present at the point of action, not an archive sitting somewhere else.

Nor is the target 100 per cent adherence. A resource-bounded agent cannot reach that number in any substrate, and chasing it degrades the result along the way. The target is the calibrated point, where the behaviour that matters is installed and the rest is retrieved, validated or gated. A field that started there would get more of the adherence it wants, not less.

Then the consequence for the profession follows: working with compliance is also, and primarily, a teaching job and a behaviour-design job. It is about listening to what people actually do, hearing where the real problem sits, and helping build the new route. Not phrasing the exhaustive rule even more precisely. That is also why the safety researcher Erik Hollnagel points the same way with his distinction between work-as-imagined and work-as-done: if you want to get hold of reality, you have to start in what people actually do, not in the procedure. Hollnagel observes that work-as-imagined fails. Friction theory offers an account of why it must.

There is also a field the profession systematically gets wrong. The default answer to non-compliance is more training, which is a measure aimed at ability, while the binding barrier is often meaning or safety. The rule has no standing in the individual's own purpose, and a competition-law clause has no natural standing in a care worker's. Supplying the field that is not missing moves nothing.

So the conclusion is not "compliance departments are doing it wrong". It is more precise than that: compliance is a learning job, and we have set it up and staffed it as a legal job. That is why it produces theatre.

How certain is this?

It has to be split in two, because the halves do not stand equally strong.

The directional claim stands: pouring a more complete rule-set into an agent with bounded capacity is not the fix. It rests on two legs, and neither waits on new data. One is the human literature, where work-as-imagined against work-as-done and the learning traditions have long shown that people fail the same dump, even with checklists, colleagues and escalation in place. The other is the measurement on the model, where the failure arises from competing directives alone, with fatigue, bad faith and missing motivation taken out of the equation.

What I only put forward as a hypothesis is the stronger reading: that humans and models run the identical mechanism, and how large the human effect is. That takes human-subject work, and that is where the test bed has to be calibrated.

The falsifier is concrete: find a population that raises adherence steadily upward with rule-set completeness, on a task where the rules genuinely compete, with no retrieval and no job aid. Then the directional claim is wrong.

And what the evidence still needs: a wider model gradient with training-stack ablations, and a real study with human raters. The scoring here is deterministic matching on names and patterns, cross-checked against two independent model judges on a stratified subset, where gpt-5 agreed exactly every time and gemini agreed exactly on 85 per cent of items and within 0.2 on all of them. That is automated triangulation across methods, not the gold standard. The results are pilot-scale and are demonstrations of the mechanism, not settled magnitudes.

The paper is published. Version 3 came out on 22 August 2026 and sits on Zenodo with DOI 10.5281/zenodo.20562413. This page is the argument in short form.

Compliance is one case of a general toolkit: Behaviour design: find the field that blocks gathers the techniques and maps each to the field it works on.