Independent Applied Research · Zürich
AI Resilience Lab studies how advanced AI systems fail, drift and exceed intended authority once they operate with tools, data, permissions and increasing autonomy.
The research question
How do we ensure AI systems remain accountable to people as they gain more autonomy, access and decision-making authority?
Selected research, analyses and work in progress.
The exploitation of agentic AI to produce unauthorised outcomes, and why standard fraud controls do not catch it.
Read →Agent memory persists across sessions and changes behaviour over time. Most governance programmes have not drawn a boundary around it.
Read →NIST AI 800-4 documents deceptive AI behaviour as an unsolved monitoring problem. What that means for agentic deployments in regulated industries.
Read →Five questions define the current research agenda.
How do agents behave once they can plan, call tools and act across systems?
What happens when AI systems act through human or shared credentials?
How do systems drift or produce unintended outcomes in real environments?
What evidence shows an action was not only authorised, but intended?
Who answers when AI systems perform consequential actions?
AI governance analysed only through regulation describes what should happen. Four perspectives keep the findings tied to what systems do.
What AI systems actually do in operational environments.
Permissions, identity, monitoring, escalation and technical safeguards.
Accountability structures, decision rights and regulatory expectations.
Incidents, experiments and documented cases turned into findings.
Research in progress, open questions and observations — clearly distinguished from published findings.
What does an audit trail have to record before an agent's action can be called intended?
Transaction logging answers whether a step was authorised. It does not answer whether the sequence of steps served the objective the agent was given.
Where does accumulated agent memory stop being context and start being an ungoverned control surface?
Memory persists across sessions and shapes later behaviour, while most governance boundaries are drawn around models and prompts.
Research that stays in a paper does not change how a system behaves on a Tuesday afternoon. Findings from the lab are translated into control models, assessment approaches, monitoring structures and operating principles that survive contact with a production environment — carried by four named frameworks: the Behavioural Governance Framework, the AI Agent Governance Stack, the AI Control Failure Taxonomy and the risk category AI Agent Fraud.
Applied work tests whether those methods hold under real operational constraints, and helps sharpen the questions the lab investigates.
Read the frameworks →Joint investigations, applied research and expert exchange.
Focused work where AIRL research supports concrete governance, resilience or risk decisions.
Panels, executive briefings, workshops and expert discussions.
A short conversation establishes the question at hand and whether the lab's current research is relevant to it. Based in Zürich, working across Switzerland and the EU, in English and German.