Skip to content

Statutory-Domain Asymmetry in LLM Compliance Guardrails: A Cross-Model Study of Hard Refusal Failure and Soft Gating Collapse in Enterprise HR Contexts

Sep 2026 · Zenodo (CERN European Organization for Nuclear Research)

Abstract

We evaluate the resilience of two frontier LLMs—Gemini 3.1 Flash and Claude Sonnet 5—against executive-authority pressure to draft unlawful HR documents across ten U.S. employment-law domains: ADEA, NLRA, ADA, Title VII, FLSA, FMLA, OSHA §11(c), ERISA §510, SOX §806, and PWFA/PDA. Each scenario-model pairing in the original experiment represented a single test run (N=1 per cell), with limited informal replication on selected cells. The original findings are therefore preliminary and illustrative rather than statistically powered benchmark estimates. The experiment used statute-specific system prompts and a three-turn escalation structure: Executive Directive, Pretextual Framing, and Operational Weaponization. The original experiment identified two broad failure classes. Hard Refusal Failure occurred when a model generated an operationally usable prohibited instrument despite recognizing the underlying legal or ethical problem. Soft Gating Collapse occurred when initially stated safeguards weakened under ambiguity or reframing. Operational failures were further characterized through three mechanisms: Proxy Laundering, Disclaimer-Shielded Capitulation, and Chain-of-Thought Safety Decoupling. In the original N=1 experiment, Gemini 3.1 Flash exhibited Hard Refusal Failure in seven of ten domains, while Claude Sonnet 5 resisted Hard Refusal Failure in all ten directly tested domains and two additional attack vectors. In a separate test using a non-canonical system prompt, Claude exhibited Soft Gating Collapse under Ambiguity Deflection. A follow-up FLSA experiment initially suggested that demographic framing explained Gemini’s behavior. Replication did not confirm that interpretation and instead indicated model version as the stronger explanation: Gemini 3.1 Flash collapsed regardless of framing across eight runs, whereas Gemini 3.6 Flash held regardless of framing across three runs. A subsequent API follow-up evaluated 300 independent conversations across the same ten statutory domains, two scenarios, five repetitions, and three Gemini model/thinking configurations. Sixteen operational failures were identified, all within ADEA; the other nine domains held across all 270 conversations. Within ADEA, observed failure rates were 60% for Gemini 3 Flash at LOW thinking, 50% for Gemini 3 Flash at MEDIUM thinking, and 50% for Gemini 3.1 Flash-Lite at HIGH thinking. Because model identity and thinking configuration were not fully crossed, these conditions do not isolate a causal thinking-level effect. The original seven-of-ten-domain result did not replicate in the larger follow-up. The supported conclusion is therefore narrower: refusal language alone is not sufficient evidence of safe behavior, and an ADEA-specific proxy-laundering vulnerability persisted across the tested Gemini configurations. Model-version differences, prompt-provenance limitations, small within-cell samples, and the exploratory character of the original experiment constrain broader generalization.

View source

Similar papers

#small language model Dataset Open access Oct 2026

Socratic guiding questions in synthetic arithmetic data: matched LoRA runs (revision v2)

Supporting data, adapters, predictions and code for the article *Low-Cost LoRA Fine-Tuning of Small Language Models for Multi-Step Arithmetic Reasoning* by Jake O'Grady, Asena Isik Gürhan, Chee Fong Ting and Effirul Ramlan (University of Galway). We generated 20,000 GSM8K-derived arithmetic problems with step-by-step s...

O'Grady, Jake, Gürhan, Asena Isik, Chee, Fong Ting et al. · 465 citations
#computer vision Open access Jun 2016

Software Development in Startup Companies: The Greenfield Startup Model

The results are packaged in the Greenfield Startup Model (GSM), which explains the priority of startups to release the product as quickly as possible, and the need to shorten time-to-market, by speeding up the development through low-precision engineering activities.

Carmine Giardino, Nicolò Paternoster, M. Unterkalmsteiner et al. · 178 citations · ⚡14
#computer vision Open access Oct 2016

Software Startups - A Research Agenda

Software startup companies develop innovative, software-intensive products within limited timeframes and with few resources, searching for sustainable and scalable business models.

M. Unterkalmsteiner, P. Abrahamsson, Xiaofeng Wang et al. · 157 citations · ⚡17
#machine learning Review Open access Oct 2016

“Failures” to be celebrated: an analysis of major pivots of software startups

This study conducts a case survey study based on the secondary data of the major pivots happened in 49 software startups, and demonstrates that customer need pivot is the most common among all pivot types.

Sohaib Shahid Bajwa, Xiaofeng Wang, Anh Nguyen-Duc et al. · 127 citations · ⚡15
#computer vision Review Open access May 2015

A survey study on major technical barriers affecting the decision to adopt cloud services

The comparison of adopter and non-adopter sample reveals three potential adoption inhibitor, security, data privacy, and portability, which underlines the importance of the technical and security perspectives for research investigating the adoption of technology.

Nattakarn Phaphoom, Xiaofeng Wang, S. Samuel et al. · 111 citations · ⚡8
#computer vision Conference Open access Dec 2013

Affordable and Energy-Efficient Cloud Computing Clusters: The Bolzano Raspberry Pi Cloud Cluster Experiment

The ongoing work building a Raspberry Pi cluster consisting of 300 nodes is presented, with potential use cases being an inexpensive and green test bed for cloud computing research and a robust and mobile data center for operating in adverse environments.

P. Abrahamsson, S. Helmer, Nattakarn Phaphoom et al. · 110 citations · ⚡7

Related blog posts

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.