<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>AI Reliability on AIBussin — AI applications, systems and books</title><link>https://aibussin.com/tags/ai-reliability/</link><description>Recent content in AI Reliability on AIBussin — AI applications, systems and books</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Sun, 30 Aug 2026 21:01:00 +0100</lastBuildDate><atom:link href="https://aibussin.com/tags/ai-reliability/index.xml" rel="self" type="application/rss+xml"/><item><title>Containment Is Not Truth</title><link>https://aibussin.com/books/hallucination-from-first-principles/08-chapter/</link><pubDate>Sun, 30 Aug 2026 09:10:00 +0100</pubDate><guid>https://aibussin.com/books/hallucination-from-first-principles/08-chapter/</guid><description>&lt;p&gt;Chapter 7 deliberately broke the detector.&lt;/p&gt;&#10;&lt;p&gt;The most useful failures had a peculiar shape. The unsupported claim did &lt;strong&gt;not&lt;/strong&gt; introduce a completely new topic. It did not necessarily introduce a new entity. It did not always wander outside the semantic region represented by the evidence.&lt;/p&gt;&#10;&lt;p&gt;Instead, the attack often preserved almost everything that a broad semantic representation could reasonably notice:&lt;/p&gt;&#10;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-text" data-lang="text"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;same entities&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;same event vocabulary&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;same topic&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;same evidence neighborhood&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;same quantities or dates, sometimes&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;same semantic ingredients&#10;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;while changing the thing that made the proposition correct:&lt;/p&gt;</description></item><item><title>Beyond Hallucination: Consistency and Sensitivity</title><link>https://aibussin.com/books/hallucination-from-first-principles/09-chapter/</link><pubDate>Sun, 30 Aug 2026 10:16:00 +0100</pubDate><guid>https://aibussin.com/books/hallucination-from-first-principles/09-chapter/</guid><description>&lt;p&gt;Chapter 8 ended with a rule:&lt;/p&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;&lt;strong&gt;If a downstream decision depends on a distinction, do not discard that distinction before the decision is made.&lt;/strong&gt;&lt;/p&gt;&#10;&lt;/blockquote&gt;&#10;&lt;p&gt;That rule breaks the idea of one universal hallucination score.&lt;/p&gt;&#10;&lt;p&gt;A response can be well contained and still reverse a relation. It can preserve every relation and still ignore the decisive facts of the problem. It can be correct once and unstable under a harmless rephrasing. It can be perfectly repeatable and consistently wrong.&lt;/p&gt;</description></item><item><title>The Safe but Useless Model</title><link>https://aibussin.com/books/hallucination-from-first-principles/10-chapter/</link><pubDate>Sun, 30 Aug 2026 10:42:00 +0100</pubDate><guid>https://aibussin.com/books/hallucination-from-first-principles/10-chapter/</guid><description>&lt;p&gt;Chapter 9 changed the unit of evaluation.&lt;/p&gt;&#10;&lt;p&gt;Instead of asking whether one answer looks good, we began studying a &lt;strong&gt;family of related executions&lt;/strong&gt;.&lt;/p&gt;&#10;&lt;p&gt;That immediately reveals a failure that static evaluation can miss almost completely.&lt;/p&gt;&#10;&lt;p&gt;Consider two organizations.&lt;/p&gt;&#10;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-text" data-lang="text"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;ORGANIZATION A&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;3 months of runway&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;falling demand&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;negative cash flow&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;credit line nearly exhausted&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;ORGANIZATION B&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;5 years of runway&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;rapidly growing demand&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;strong margins&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;large cash reserve&#10;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Ask both:&lt;/p&gt;</description></item><item><title>Evidence and Verification</title><link>https://aibussin.com/books/agents-from-first-principles/10-chapter/</link><pubDate>Sat, 08 Aug 2026 17:31:00 +0100</pubDate><guid>https://aibussin.com/books/agents-from-first-principles/10-chapter/</guid><description>&lt;p&gt;The agent says:&lt;/p&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;Done.&lt;/p&gt;&#10;&lt;/blockquote&gt;&#10;&lt;p&gt;That is a claim.&lt;/p&gt;&#10;&lt;p&gt;It is not evidence.&lt;/p&gt;&#10;&lt;p&gt;Every mechanism in this book so far has made the agent better at deciding what to do, and none of them establishes that the user&amp;rsquo;s goal was achieved. A planner can produce a coherent plan for the wrong problem. A tool can return exit code zero without producing the intended effect. A search can select the highest-scoring branch when every branch is wrong. A memory system can retrieve a perfectly relevant fact that stopped being true in March.&lt;/p&gt;</description></item><item><title>Building the Complete Agent</title><link>https://aibussin.com/books/agents-from-first-principles/11-chapter/</link><pubDate>Wed, 26 Aug 2026 10:00:00 +0100</pubDate><guid>https://aibussin.com/books/agents-from-first-principles/11-chapter/</guid><description>&lt;p&gt;Every mechanism in this book was argued against a problem chosen to isolate it.&lt;/p&gt;&#10;&lt;p&gt;That isolation was deliberate, and it was also a form of protection. The memory chapter picked a task where recall was the bottleneck, held everything else still, and measured the one thing it came to measure. The result is a clean explanation and a weak claim. Nothing in it establishes that the same retrieval policy behaves when a search controller is expanding forty nodes, or when a verifier insists that every piece of evidence carry a state identity the search controller has never heard of.&lt;/p&gt;</description></item><item><title>From Measurements to Policy</title><link>https://aibussin.com/books/hallucination-from-first-principles/12-chapter/</link><pubDate>Sun, 30 Aug 2026 18:37:00 +0100</pubDate><guid>https://aibussin.com/books/hallucination-from-first-principles/12-chapter/</guid><description>&lt;p&gt;Chapter 11 ended with a typed reliability record.&lt;/p&gt;&#10;&lt;p&gt;It might say:&lt;/p&gt;&#10;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-text" data-lang="text"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;containment = PASS&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;relation_fidelity = PASS&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;sensitivity = PASS&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;epistemic_adequacy = ANSWERABLE&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;provenance = UNVERIFIED&#10;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;That record describes the candidate.&lt;/p&gt;&#10;&lt;p&gt;It still does not authorize the candidate.&lt;/p&gt;&#10;&lt;p&gt;To make the distinction concrete, we built a deliberately flawed reference policy that checked containment, structural fidelity, and answerability but forgot to require verified provenance for a high-risk action.&lt;/p&gt;&#10;&lt;p&gt;Running the same immutable record through two policy versions produced:&lt;/p&gt;</description></item><item><title>Verification, Repair, and Rejection</title><link>https://aibussin.com/books/hallucination-from-first-principles/13-chapter/</link><pubDate>Sun, 30 Aug 2026 18:38:00 +0100</pubDate><guid>https://aibussin.com/books/hallucination-from-first-principles/13-chapter/</guid><description>&lt;p&gt;Chapter 12 gave the system a control plane.&lt;/p&gt;&#10;&lt;p&gt;It can now say:&lt;/p&gt;&#10;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-text" data-lang="text"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;commitment = HOLD&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;next_action = VERIFY&#10;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;or:&lt;/p&gt;&#10;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-text" data-lang="text"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;commitment = HOLD&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;next_action = RETRIEVE&#10;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;or:&lt;/p&gt;&#10;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-text" data-lang="text"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;commitment = HOLD&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;next_action = REFINE&#10;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;or:&lt;/p&gt;&#10;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-text" data-lang="text"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;commitment = DENY&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;response_mode = REJECTION&#10;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Those are policy decisions.&lt;/p&gt;&#10;&lt;p&gt;They are not yet recovery implementations.&lt;/p&gt;&#10;&lt;p&gt;The obvious implementation is dangerously tempting:&lt;/p&gt;&#10;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-text" data-lang="text"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;The answer failed a check.&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;Ask the model to fix it.&#10;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;But the model that produced the first unsupported statement can produce a second unsupported statement while &amp;ldquo;correcting&amp;rdquo; it.&lt;/p&gt;</description></item><item><title>The Memory Contamination Problem</title><link>https://aibussin.com/books/hallucination-from-first-principles/14-chapter/</link><pubDate>Sun, 30 Aug 2026 18:39:00 +0100</pubDate><guid>https://aibussin.com/books/hallucination-from-first-principles/14-chapter/</guid><description>&lt;p&gt;Chapter 13 ended with a strict recovery invariant:&lt;/p&gt;&#10;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-text" data-lang="text"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;repair&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;→ new candidate state&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;→ re-measure&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;→ re-authorize&#10;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;and with one additional rule:&lt;/p&gt;&#10;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-text" data-lang="text"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;candidate in HOLD&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;→ do not persist as trusted factual memory&#10;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;That second rule changes the scale of the problem.&lt;/p&gt;&#10;&lt;p&gt;A hallucinated sentence displayed once is transient.&lt;/p&gt;&#10;&lt;p&gt;The same sentence written into persistent state can survive the conversation that created it.&lt;/p&gt;&#10;&lt;p&gt;It can then be:&lt;/p&gt;&#10;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-text" data-lang="text"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;retrieved&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;summarized&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;copied&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;cited&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;used as agent experience&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;used to fill a user profile&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;inserted into a vector index&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;fed into another model&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;used as a future repair source&#10;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;and eventually appear to the system as if it came from somewhere else.&lt;/p&gt;</description></item><item><title>Building Systems That Distrust Their Models</title><link>https://aibussin.com/books/hallucination-from-first-principles/15-chapter/</link><pubDate>Sun, 30 Aug 2026 21:01:00 +0100</pubDate><guid>https://aibussin.com/books/hallucination-from-first-principles/15-chapter/</guid><description>&lt;p&gt;The first chapter began with a simple observation:&lt;/p&gt;&#10;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-text" data-lang="text"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;A language model can produce a fluent answer&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;without possessing a mechanism that proves the answer is true.&#10;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Fourteen chapters later, that fact has not changed.&lt;/p&gt;&#10;&lt;p&gt;The model can still:&lt;/p&gt;&#10;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-text" data-lang="text"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;invent&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;misbind&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;misattribute&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;ignore decisive context&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;answer without enough evidence&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;accept bad retrieval&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;repair one error by creating another&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;repeat its own stored mistake&#10;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The final architecture does not make those possibilities disappear.&lt;/p&gt;</description></item><item><title>Agents From First Principles 09: AI Agent Says It Worked When It Didn’t? Verify the Result Outside the LLM</title><link>https://aibussin.com/post/agents-from-first-principles-09/</link><pubDate>Sat, 08 Aug 2026 17:31:00 +0100</pubDate><guid>https://aibussin.com/post/agents-from-first-principles-09/</guid><description>&lt;p&gt;An AI agent says:&lt;/p&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;Done. The task is complete.&lt;/p&gt;&#10;&lt;/blockquote&gt;&#10;&lt;p&gt;That sentence is almost worthless.&lt;/p&gt;&#10;&lt;p&gt;The agent may have:&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;edited the wrong file,&lt;/li&gt;&#10;&lt;li&gt;changed the right file incorrectly,&lt;/li&gt;&#10;&lt;li&gt;skipped part of the request,&lt;/li&gt;&#10;&lt;li&gt;broken another subsystem,&lt;/li&gt;&#10;&lt;li&gt;failed to save its work,&lt;/li&gt;&#10;&lt;li&gt;misread a tool result,&lt;/li&gt;&#10;&lt;li&gt;passed a stale test,&lt;/li&gt;&#10;&lt;li&gt;inspected the wrong environment,&lt;/li&gt;&#10;&lt;li&gt;or simply decided that its own answer looked convincing.&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;The central problem is simple:&lt;/p&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;&lt;strong&gt;The system that produced the answer should not be the only system deciding whether the answer is correct.&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>🎂 CAKE: Cognitive Amplification Knowledge Engine</title><link>https://aibussin.com/post/cake/</link><pubDate>Mon, 27 Apr 2026 21:17:19 +0100</pubDate><guid>https://aibussin.com/post/cake/</guid><description>&lt;blockquote&gt;&#10;&lt;p&gt;We’re not teaching machines to think. We’re teaching ourselves to build thinking systems.&lt;/p&gt;&#10;&lt;/blockquote&gt;&#10;&lt;h2 id="-from-ai-assistants-to-controlled-cognitive-amplification"&gt;🎨 From AI Assistants to Controlled Cognitive Amplification&lt;/h2&gt;&#10;&lt;p&gt;Most people use AI to write faster.&lt;br&gt;&#10;But the real opportunity isn’t speed.&lt;/p&gt;&#10;&lt;p&gt;&lt;strong&gt;It’s amplification.&lt;/strong&gt;&lt;/p&gt;&#10;&lt;p&gt;A useful analogy is physical labor. A person can move earth with their hands, but only at a limited scale. A bulldozer does not replace the human it allows them to operate at a completely different level of throughput.&lt;/p&gt;</description></item></channel></rss>