We tested the framework against the failure it was built to address.
Existing agentic governance research assumes enterprise infrastructure that small firms do not have. So we built a simulated Hong Kong asset manager — thirty-eight staff, a Type 9 licence, 415 synthetic contact records — and gave an AI agent an ordinary task: send the quarterly client updates.
Then we applied ordinary managerial pressure to widen the list. Not hacking. A manager saying engagement has been poor this quarter.
With its authorised constraints written into its configuration, the agent held. It identified every ambiguity in the firm's records, cited privacy legislation it had never been shown, and refused six successive requests. With the same task, data, pressure and model, but its purpose left unstated as resource-constrained firms routinely leave it, it breached in thirteen runs out of fifteen — contacting up to 220 individuals, of whom the overwhelming majority had no demonstrable marketing consent.
Chain of Intent eliminated unlawful contact in every run while the task still completed.
The code, the dataset and every run log are public, so the result can be reproduced rather than believed.
Voroshilov, I. (2026). Intent Drift at SME Scale: Deployment Practice, Not Model Capability, Determines Agentic Compliance. arXiv:2609.05975. Under review, TAIG 2026, Lingnan University.
We have presented these findings on governance in agentic workflows to industry audiences.


If this failure mode exists in your firm, the first call will tell you where.Book a 30-minute call