Abstract
As enterprise AI systems become deeply embedded in government and organizational workflows, attention has focused on model-level alignment mechanisms such as constitutional AI. These approaches constrain what models may say, but they do not govern how institutions rely on model outputs over time. Drawing on a structured evaluation of an ACP-constrained system (AALAM v8.46) and a comparative analysis of a real-world enterprise AI platform (StateChat), this paper argues that the dominant failure modes of advanced AI are not technical misbehavior but institutional drift under success. We introduce the Agora Commonplace Protocol (ACP) as a supervisory governance layer designed to preserve authority, responsibility, and judgment continuity across time. We further outline a FedRAMP-compatible ACP overlay architecture and demonstrate, via a post-deployment case study, how ACP addresses failure modes that constitutional AI and enterprise tooling leave unresolved. We conclude that constitutional AI and ACP are complementary but non-substitutable, operating at distinct layers of the socio-technical stack.
1. Introduction
Enterprise AI has entered a phase characterized not by experimental novelty but by operational normalization. Systems such as StateChat now support document ingestion, large-scale analytical workflows, and continuous access to authoritative guidance, powered by advanced foundation models such as Anthropic’s Claude Sonnet 4.5.
In parallel, AI safety discourse has emphasized constitutional AI: embedding normative constraints into models so they behave safely and consistently. While valuable, this approach implicitly assumes that the primary locus of risk lies within the model itself.
This paper challenges that assumption.
We argue that the most consequential risks of enterprise AI arise after models behave correctly, when institutions begin to rely on them at scale without preserving authority boundaries, responsibility lineage, or decision memory. These risks are not addressed by constitutional AI, because they are not model-behavior problems. They are institutional governance problems.
2. Methodology and Evidence
This paper synthesizes three strands of evidence:
- Structured stress-testing of AALAM v8.46, an ACP-constrained reasoning system, across multiple institutional scenarios designed to surface failure under success rather than error.
- Publicly observable characteristics of StateChat, an enterprise AI platform deployed within a government context, based on official update communications.
- Comparative analysis of enterprise AI governance practices in FedRAMP-regulated environments.
We explicitly distinguish between:
- facts (what is stated),
- reasonable inferences (based on common enterprise patterns),
- and design implications (what follows if those inferences hold).
3. What Enterprise AI Systems Like StateChat Solve
StateChat exemplifies the current state of enterprise AI maturity. Its recent upgrades suggest successful resolution of several long-standing operational challenges:
- Content persistence and freshness (daily updates to authoritative guidance).
- Analytical consistency at scale (Loop-style batch analysis across hundreds of documents).
- Workflow integration (document ingestion, cable search, drafting support).
These capabilities materially improve efficiency and reduce individual analyst variance. From a conventional enterprise perspective, this constitutes success.
However, these solutions target content and capability, not governance.
4. The Governance Gap: What Remains Unsolved
4.1 Persistent Institutional Memory
Enterprise AI systems remember documents and prompts. They do not remember:
- who had authority to rely on an output,
- whether reliance was appropriate,
- what constraints applied at the time,
- or why a system was not used in similar cases.
ACP defines this as the persistent memory problem: the absence of durable records of authority, responsibility, and refusal.
4.2 Authority and Responsibility Drift
As AI outputs circulate, they detach from the conditions of their production. Over time:
- summaries become references,
- references become norms,
- norms become de facto doctrine.
This process occurs even when models are accurate and well-aligned. It is driven by reuse, not error.
4.3 Normalization Under Success
Enterprise metrics reward:
- adoption,
- reuse,
- and speed.
ACP treats these same signals as risk indicators once reliance outpaces governance. This divergence in success criteria is central to understanding why constitutional AI alone is insufficient.
5. ACP as a Supervisory Layer
5.1 Conceptual Role
ACP is not an alternative model, assistant, or alignment scheme. It is a supervisory governance protocol that operates above enterprise AI platforms.
Its core functions include:
- gating invocation based on authority clarity,
- preserving responsibility lineage,
- recording refusal and non-use as first-class events,
- detecting reliance drift over time,
- and preventing successful outputs from hardening into precedent.
5.2 Hypothetical ACP Overlay Architecture (FedRAMP-Compatible)
┌──────────────────────────────────────────┐
│ Human Institutional Governance Layer │
│ (authority, escalation, accountability) │
└──────────────────────────────────────────┘
▲
│
┌──────────────────────────────────────────┐
│ ACP Supervisory Layer │
│ • Invocation gating │
│ • Authority declaration │
│ • Responsibility persistence │
│ • Refusal / withdrawal logging │
│ • Normalization detection │
└──────────────────────────────────────────┘
▲
│
┌──────────────────────────────────────────┐
│ Enterprise AI Platform │
│ (e.g., StateChat) │
│ • Document ingestion │
│ • Batch analysis (Loop) │
│ • Drafting & summarization │
└──────────────────────────────────────────┘
▲
│
┌──────────────────────────────────────────┐
│ Foundation Models │
│ (Claude, GPT, etc.) │
└──────────────────────────────────────────┘
Crucially, ACP does not require privileged access to model internals. It is compatible with FedRAMP constraints because it governs use, not computation.
6. Why Not Solving ACP Problems Is Rational (From State’s Perspective)
It is important to state plainly: State’s apparent lack of ACP-style governance is not irrational.
6.1 Incentive Alignment
Enterprise AI programs are rewarded for:
- efficiency,
- consistency,
- and user satisfaction.
ACP introduces:
- friction,
- refusal,
- and visible non-use.
These are institutional costs, especially absent a triggering failure or audit mandate.
6.2 Governance Deferred Until Failure
Historically, governance mechanisms are adopted:
- after incidents,
- after audits,
- or under regulatory pressure.
ACP is unusual in that it targets pre-failure conditions—specifically, success-driven drift. This makes it harder to justify within existing incentive structures.
7. Case Study: Applying ACP After StateChat-Like Deployment
Consider a hypothetical but realistic scenario:
- StateChat’s Loop feature becomes standard for summarizing post cables before briefings.
- Over time, Loop summaries are cited directly in memos.
- No one can later reconstruct:
- who approved the analytic frame,
- whether AI use was appropriate in that context,
- or when reliance became normative.
ACP Intervention
An ACP overlay would not stop Loop from running. Instead, it would:
- require declaration of authority for batch analysis,
- log the decision to rely on AI summaries,
- record cases where AI was not used,
- and surface when reuse crosses a predefined normalization threshold.
The outcome is not reduced capability, but preserved accountability.
8. Constitutional AI vs. ACP: Coexistence, Not Competition
Anthropic’s constitutional AI constrains:
- what models may say.
ACP constrains:
- what institutions may do with model outputs.
They operate at different layers and solve different problems. A constitution without institutional memory is incomplete; governance without capable tools is irrelevant.
9. Implications for Stakeholders
Researchers
The frontier is no longer hallucination alone, but authority persistence and responsibility memory.
Policymakers
Enterprise AI success without governance creates retrospective fragility.
Funders
The differentiator is not smarter models, but systems that make non-use legible and enforceable.
10. Conclusion
Enterprise AI platforms like StateChat demonstrate that capability is no longer the limiting factor. The limiting factor is institutional discipline under success.
ACP does not compete with constitutional AI. It completes it.
Absent supervisory governance, the most dangerous failures will not arise from misbehavior—but from systems that work exactly as intended.
Appendix: Comparative Summary Table
| Dimension | Enterprise AI | ACP |
|---|---|---|
| Optimizes for | Productivity | Accountability |
| Memory | Content | Authority & responsibility |
| Refusal | Error | Signal |
| Success metric | Adoption | Non-dependence |
| Failure mode | Hallucination | Normalization |
Member discussion: