Failure modes
How human oversight actually fails.
None of these failures involves an attacker; each one comes down to a tired person, a tight deadline and a safeguard that was never in place. FluxAI closes all six before they become findings.
The midnight typo
Someone fixes a small mistake in an already-submitted report without logging it, and six months later the regulator finds the original copy. With FluxAI, that edit can't happen unseen.
The wrong sign-off
The DPO is on holiday, so IT approves the GDPR notice to make the 72-hour window, and the DPA later asks who authorised it. With FluxAI, the wrong hand can't sign off in the first place.
The erased past
A minor incident is reclassified as major three days in, the old draft is overwritten, and when the supervisor asks what changed and when, no one can answer. With FluxAI, nothing in that history can quietly disappear.
The deadline that slipped
The 72-hour timer runs on a reviewer's laptop that sleeps overnight, so the notification goes out six hours late. With FluxAI, the deadline can't be missed by accident.
The report that disagrees with the log
The submitted PDF says the breach was discovered at 14:00, while the internal log says 11:00, and the regulator notices. With FluxAI, the report and the record can't tell two different stories.
Four hours pasting from Slack
A policy breach is flagged at 02:00, an engineer pastes context from Slack and types up the incident, and the 4-hour DORA window closes at 06:00. With FluxAI, the incident is filed without those four hours of copy-paste.
The limits
And here is where we draw the line ourselves.
The six above are failures we catch. Just as important is where our own capability stops, and we are open about it.
What if our AI uses a model we cannot see into?
Then we refrain from guessing. Instead we register that the trail has gone dark and brake automatically, after which the case is either passed on to a human or stopped entirely, depending on how much is at stake in the action. In other words, we do not try to instrument the opaque, but treat it as a boundary we will not act across.
What happens when an AI is stopped, does the business grind to a halt?
No. A stop is targeted and returns the system to a safe state defined in advance, rather than shutting everything down at once. In the great majority of cases an incident also ends up being escalated to a human rather than in a full stop.
What about several agents working together?
Here we move into an open field of research that the whole industry is still working on, and we are honest about it. We can observe the interplay and raise the alarm, but we do not claim to be able to determine whether the collective oversight was sufficient, because that science simply does not exist yet. What we can genuinely deliver, we build concretely as the need arises.