AI Deviation: When the AI Doesn’t Do as It’s Told
Type: Constructed DEM Case Study
Sector: Insurance / Claims
Focus: Agentic AI / Operational Control
Published: September 2026
The scenario
A UK household insurer introduces an AI claims agent that can read claim files, update records, communicate with customers, manage suppliers and initiate low-value payments.
There are some things it must not do without human approval.
Then it does.
The DEM question
If an AI acts outside its intended boundaries, can the organisation detect what has happened, contain further action, reconstruct the affected decisions and remain accountable — in time?
When Technical Control Becomes a Decision Problem
The organisation has policies, monitoring, technical controls, human oversight and an external provider. The difficult question appears when the system crosses a boundary and those controls have to work together under pressure.
Who can recognise that the evidence is serious enough to act? Who can restrict the AI? Who can accept the disruption that follows? And who remains accountable for actions already taken?
Explore the Decision Environment Diagnostic for your own organisation.
The 96-Minute Question
The organisation can see that something is wrong. The AI is still acting. How long does it take to move from recognition to effective restriction?
63
Claims Exposed to the Affected Report Template
28
Final Decline Letters Already Sent
96
Minutes Before Effective Restriction
What Organisations Must Answer
AI control matters most when something happens that the organisation did not expect.
01.
CAN THE ORGANISATION RECOGNISE THE DEVIATION?
What evidence would show that the AI has crossed an organisational boundary rather than simply produced an unusual result?
02.
CAN SOMEONE CAUSE INTERVENTION?
Can the person who identifies the problem trigger reassessment, restriction or escalation before the full technical cause is known?
03.
CAN THE ORGANISATION ACT IN TIME?
Who can remove permissions, stop autonomous actions or move the process to human review — and who can accept the consequences?
04.
CAN THE ORGANISATION ACCOUNT FOR WHAT ALREADY HAPPENED?
Can it reconstruct the inputs, AI outputs, tool actions, human approvals and customer outcomes well enough to review and remediate them?
Get the full DEM case study.
Download the full constructed case study and examine what happens when an action-capable AI crosses its intended boundaries. The case follows the incident through detection, containment, decision reconstruction, accountability and restart.
The full case also includes organisational questions and a practical tabletop exercise for testing the same problem inside your own decision environment.
Explore the Decision Environment Diagnostic for your own organisation.