De Facto Policy Drift From Repeated Unverified LLM Interpretations
De Facto Policy Drift From Repeated Unverified LLM Interpretations: How AI-Mediated Norms Diverge From Executive Intent
- Public evidence supports a threshold view of drift rather than a calendar view, because de facto policy starts when an unverified LLM interpretation is reused as precedent, not only when management formally adopts it or edits the source policy textKupfer et al. (2023)Braden (2012)Zarhani (2021)
- The retrieved automation-bias evidence implies that repeated model-assisted policy interpretation is risky when users stop verifying recommendations, but that conclusion is an inferential transfer from a single personnel-selection study rather than a direct enterprise policy studyKupfer et al. (2023)
- Alert and prompt overload appear to accelerate authority drift because cumulative exposure reduces responsiveness, which means staff may become less likely to stop, challenge, or independently reason through a model-assisted policy interpretation once the surrounding signal volume becomes routineLitchfield (2023)Murad et al. (2022)
- Unofficial parallel policy frameworks persist when local work-arounds become routine practices, because repeated exception handling can hide deficiencies, undermine standardization, and move day-to-day behaviour away from the formal rule without any visible policy rewriteBraden (2012)Blijleven et al. (2017)Zarhani (2021)
- The retrieved governance frameworks all imply that LLM interpretation must be governed as an operating control surface, because board oversight, risk-appetite translation, monitoring, and independent assurance are explicit responsibilities rather than optional quality checksCommittee (n.d.)Institute (2020)National (2023)National (2022)
- The best-supported leading indicators of material policy decay are rising interpretation exposure, falling verification behaviour, and accumulating unofficial prompt or exception artefacts outside the formal policy repositoryKupfer et al. (2023)Murad et al. (2022)Blijleven et al. (2017)
- Prior completed repository work strengthens the conclusion by showing that blind-acceptance loops, narrative translation gaps, and undocumented local process variants already create drift-friendly conditions even before an organisation adds a dedicated policy assistantMitchell (2026)Mitchell (2026)Mitchell (2026)
Research Question
How quickly do repeated unverified Large Language Model (LLM) interpretations create de facto policy norms that diverge from executive intent and board-level risk appetite?
Findings
(Populated from §6 Synthesis above.)
Executive Summary
Repeated unverified LLM interpretations can start creating de facto policy norms on the first reused output, but the retrieved public evidence does not support a single universal time-to-drift metric across organisations. The evidence describes a mechanism of drift formation: automation bias lowers verification, alert overload lowers responsiveness, and work-arounds let local exceptions harden into routine practice while formal policy text stays unchanged. Divergence from executive intent and board-level risk appetite becomes organisationally material when repeated interpretations stop functioning as advice and start functioning as operating precedent without effective oversight, monitoring, and assurance. The best-supported early indicators are rising interpretation exposure, falling verification intensity, and growth in unofficial prompt or exception libraries outside the formal policy repository.
Key Findings
- Public evidence supports a threshold view of drift rather than a calendar view, because de facto policy starts when an unverified LLM interpretation is reused as precedent, not only when management formally adopts it or edits the source policy text.
- The retrieved automation-bias evidence implies that repeated model-assisted policy interpretation is risky when users stop verifying recommendations, but that conclusion is an inferential transfer from a single personnel-selection study rather than a direct enterprise policy study.
- Alert and prompt overload appear to accelerate authority drift because cumulative exposure reduces responsiveness, which means staff may become less likely to stop, challenge, or independently reason through a model-assisted policy interpretation once the surrounding signal volume becomes routine.
- Unofficial parallel policy frameworks persist when local work-arounds become routine practices, because repeated exception handling can hide deficiencies, undermine standardization, and move day-to-day behaviour away from the formal rule without any visible policy rewrite.
- The retrieved governance frameworks all imply that LLM interpretation must be governed as an operating control surface, because board oversight, risk-appetite translation, monitoring, and independent assurance are explicit responsibilities rather than optional quality checks.
- The best-supported leading indicators of material policy decay are rising interpretation exposure, falling verification behaviour, and accumulating unofficial prompt or exception artefacts outside the formal policy repository.
- Prior completed repository work strengthens the conclusion by showing that blind-acceptance loops, narrative translation gaps, and undocumented local process variants already create drift-friendly conditions even before an organisation adds a dedicated policy assistant.
Assumptions
- Behaviour observed in personnel and healthcare decision-support settings transfers directionally to enterprise policy-assistant use.
- Organisations using LLM policy assistants intend those tools to inform operational decisions that should remain within formal governance boundaries.
Analysis
The evidence base in this item does not provide a standard timeline for when policy decay begins. It supports a familiar organisational failure path in which verification and challenge degrade under repeated exposure, while local work-arounds and reinterpretation keep operating behaviour moving away from formal policy. A plausible competing explanation is that most drift comes from ordinary ambiguity, local incentives, and process friction rather than from the model itself. The retrieved evidence supports that rival explanation in part, so the best comparative conclusion is that LLMs amplify an existing governance weakness. The decisive control question is whether the organisation logs interpretations, measures challenge behaviour, and gives second-line and third-line functions enough visibility to see when advice has become precedent.
Risks, Gaps, and Uncertainties
- The evidence base used in this item relies on cross-domain behavioural studies rather than direct longitudinal studies of enterprise policy assistants, which limits any exact time-to-drift claim.
- The behavioural evidence comes mainly from personnel selection and healthcare decision support, so cross-domain transfer remains inferential.
- COSO's public material supports framework-level claims, but detailed clause-level interpretation remains limited because the full framework text is not publicly available.
- The current evidence cannot isolate the exact contribution of LLM fluency from pre-existing organisational ambiguity, weak documentation, or overloaded review channels.
Open Questions
- Which enterprise teams already log policy-assistant interpretations in a way that allows direct measurement of first-use versus first-reuse drift?
- How much challenge-rate decline occurs when policy prompts are embedded in chat, ticket, or approval workflows rather than shown as discrete alerts?
- Which review design works better at scale: sampled audit of interpretation logs, mandatory second-person review on high-risk topics, or policy-as-code checks that compare advice to formal rule text?
sources
- [x] Committee of Sponsoring Organizations of the Treadway Commission (COSO) Guidance on Internal Control
- [x] Institute of Internal Auditors (IIA) (2020) IIA issues important update to Three Lines Model
- [x] Institute of Internal Auditors (IIA) (2020) The Three Lines Model, an important tool for the success of every organization
- [x] National Institute of Standards and Technology (NIST) (2023) AI Risk Management Framework overview
- [x] National Credit Union Administration (NCUA) (2022) Board approves enterprise risk appetite statement
- [x] Kupfer et al. (2023) Check the box! How to deal with automation bias in AI-based personnel selection
- [x] Litchfield (2023) Clinical reminder alert fatigue in healthcare, a systematic literature review using qualitative evidence
- [x] Murad et al. (2022) Distinct components of alert fatigue in physicians’ responses to a noninterruptive clinical decision support alert
- [x] Blijleven et al. (2017) Workarounds Emerging From Electronic Health Record System Usage
- [x] Browne and Braden (2012) Definition and Relational Specification of Work-around
- [x] Mukherji and Zarhani (2021) Policy paradigms and path dependence, the endogenous roots of institutional displacement and drift in India
- [x] Mitchell (2026) SWAT technique in a fresh-context loop
- [x] Mitchell (2026) Can organisational intent be expressed as a formally structured specification
- [x] Mitchell (2026) Process-Risk-Control (PRC) scoring impacts from unstandardized workforce processes
| version | date | commit | summary |
|---|---|---|---|
| 1.0 | 2026-05-17 | 234d73f | Initial completion |