From Policy to Practice: How KCP Makes Regulations Machine-Readable for AI Agents
A presentation version of this post is available as slides.
Your agent reads customer data. It makes a decision. It writes something to a database.
Somewhere in your system prompt, there is a line that says: "You must comply with GDPR data minimization principles when accessing customer data."
That line does nothing. It is not verifiable. It is not testable. It is not auditable. It is a string that your model may or may not attend to, depending on context length, prompt position, and the phase of the moon.
