
Most enterprise AI agents learn company policy the same way: someone pastes it into the system prompt. Discount tiers, approval thresholds, refund windows and compliance exceptions pile up until the prompt reads like a policy manual, and the model treats it the way people treat policy manuals. It skims, weighs every clause against every request, and when two rules collide it picks whichever answer sounds most plausible. Afterwards nobody can say which rule produced the answer.
The fix is architectural. Rules move out of the prompt into a governed context layer, the hard yes or no moves to a business rules engine, and the model keeps the two jobs it does well: reading the request and writing the reply.
A language model predicts text. It approximates a rule from the words around it rather than executing it, and the more words there are, the looser the approximation gets. Chroma's July 2025 study Context Rot tested 18 models and found that they "do not maintain consistent performance across input lengths": the same task becomes less reliable as more text surrounds it. A prompt carrying every policy the business has makes each individual rule harder for the model to apply, and the failure is quiet. The agent raises no error. It gives a confident answer that breaks a rule nobody checked.
Weak data makes it worse. In Taming the Complexity of AI Data Readiness (Harvard Business Review Analytic Services, sponsored by Cloudera, March 2026), only 7% of respondents said their organisation's data is completely ready for AI. WRITER's 2026 survey of 2,400 executives and employees found that 97% of executives had deployed AI agents in the past year, while 23% reported significant ROI from them.

A semantic layer answers what the data means. It fixes "revenue" as the sum of paid orders, so every report and every agent uses the same number. Our five-layer context layer blueprint covers that foundation in detail.
A context layer answers how and when the AI may use the data: who may see the revenue figure, which discount policy applies to this customer, and what the agent does when a required field is empty. A rule that blocks refunds on orders older than 30 days lives here. Each rule is stored as a record with an ID, a condition, an outcome, a version and an owner, in a format a machine can query, such as JSON, YAML or a database table. The agent fetches the one rule that applies to the request in front of it instead of carrying all of them.
That record format is what makes the rules governable. When Finance changes the Gold-tier discount ceiling, someone edits one record, the version number moves, and every agent that queries the layer applies the new ceiling on its next call. Nobody retrains a model or rewrites a prompt.
A model should never decide on its own whether a discount, a refund or a data release is allowed. Splitting the work between probabilistic language and deterministic rules, an approach often called neurosymbolic AI, gives each decision to the component that makes it reliably. In practice every request runs through three steps.

Stating the rule before acting gives a reviewer something to check. When an answer is wrong, the log shows whether the agent fetched the wrong rule or the rule itself was wrong, and those two failures have different owners. The engine's verdict also works as an AI guardrail the model cannot argue its way around, because the model never makes the call.
Anthropic open-sourced the Model Context Protocol (MCP) in November 2024 as a standard way to connect AI assistants to the systems where data lives. For business rules, MCP gives the agent one interface for asking a rule server what applies, the same way it would ask a CRM for a customer record. Anthropic's September 2025 engineering post on context engineering makes the wider case: give the agent the smallest set of information that answers the question at hand, fetched when it needs it.
MCP is a convenience, and a context layer works without it. A rules API or an n8n workflow can serve the same records. What matters is that rules live outside the prompt and outside the model's weights, with one owner each.
Some teams ask whether to fine-tune the rules into the model instead. Research on rule distillation (Yang and colleagues, COLING 2025) shows models can be trained to follow textual rules better, which helps with rules that almost never change. Rules that change every quarter belong in the context layer, where an edit takes effect immediately and leaves a version history.
The written policy is rarely the whole policy. A Dutch Odoo implementation partner brought us in to automate scheduling for a dental care group: 200 practitioners, 1,500 appointments a week, and treatment series with healing intervals, role matching and urgency limits. Those interdependent rules were more than Odoo's data model was designed to handle. We moved them into a scheduling engine and inverted the logic, so the engine records when each practitioner is unavailable and an AI agent places appointments in the time that remains. Every night five sync workflows feed the planning step, and any appointment the agent cannot place produces a report explaining why. The full case is on our enterprise AI consulting page.
The same method maps the rules behind any agent:
Our AI Audit starts with this mapping for the workflow worth automating first, and how we work shows who owns each stage after it.
In healthcare, the context layer decides which fields an agent may read before any patient data reaches the model. Our post on context layers for protected healthcare environments walks through that boundary, and AI agents in healthcare shows the workflows it supports.
Outside healthcare, the NIST AI Risk Management Framework (AI RMF 1.0, January 2023) and its Generative AI Profile (NIST AI 600-1, July 2024) ask organisations to govern, map, measure and manage AI risk. A versioned rule store with a logged decision for every run gives that review something concrete to inspect: which rule applied, which version, and who owns it. Our enterprise AI governance page covers the approval and audit controls that sit around it.
A context layer sits between your data and your AI agents. It holds business definitions, permissions and rules as versioned records, so an agent fetches the rule that applies to each request instead of relying on a long system prompt. See our enterprise context layer service for how we build one.
A semantic layer defines what data means, such as how revenue is calculated. A context layer adds how and when the AI may use it: who may see it, which policy applies, and what to do when data is missing.
Hard limits, such as discount ceilings, approval thresholds and data access, belong in a rules engine that returns a fixed decision. The prompt tells the agent how to behave and when to call the engine. That split keeps decisions consistent and makes each one traceable to a rule and a version.
Context rot is Chroma's name for the drop in model reliability as the input grows. In its July 2025 study of 18 models, performance did not stay consistent across input lengths, which is why packing every rule into one prompt makes each rule less dependable.
No. MCP is a standard interface that many agent frameworks support, which makes rule servers easier to reuse across agents. A rules API or an n8n workflow can serve the same records.
In a 30-minute discovery call you speak directly with an AI engineer about the workflow you want to automate and the rules it has to follow. If an audit is the right first step, we will tell you and scope it on the call.
A 30-minute discovery call. You bring the process; we bring the plan.
Book a Discovery Call