verifiedagents.ai
All posts

7 min readAgentic AI · AI Agents

What Is a Never List for AI Agents?

By Michelle Savage, Experience Design Director, PayPal

What Is a Never List for AI Agents? (hero)

TL;DR: A never list is a short set of rules an AI agent can't break. Each rule has to be checkable by something other than the agent. "Never make up a source" fails, because the agent has no idea it made one up. "No working link, no source" works. A person can check it in five seconds.

Key takeaways:

  • A never list is the shortest document you'll write for an AI agent, and it's the one to write first.

  • Every rule on it needs a check that works without the agent's own judgment.

  • AI agents treat what they pick up while working the same as what you wrote for them.

  • In Josh's Lab, a made-up source ended up in two documents in under a day while every permission held.

  • The full list is in our chapter of John Kindervag's book, Cyber Resilience at Machine Speed, published by Illumio in October 2026.

What is a never list for AI agents?

A never list is a short document that holds the things your AI agent must never do. Think of moving money or making a legal promise. It sits apart from the agent's other instructions. And every rule on it can be checked by a person or by a second system.

We wrote about it in our chapter for John Kindervag's new book. The list in the chapter has five rules. Here are two of them.

The first: never move money or credit an account. A person signs those.

The second: never state a policy that isn't in the approved policy file.

Look at how each one is built. The money rule names who signs. The policy rule names the file. Neither one asks the agent to use good judgment.

That's on purpose. An agent decides and acts on its own. So the rules that count most get checked from outside the agent.

Why does "never make up a source" fail?

"Never make up a source" fails because an AI agent that invents a source has no idea it did. To the agent, the made-up journal and the real one look the same. So the rule asks the agent to catch a mistake it can't see. You need a rule someone else can check.

We learned this the hard way in Josh's Lab, the set of AI agents Josh runs at home.

One agent, Scout, does research. It handed back a source with a title that fit the topic and an institution that sounded real. The source was made up. So was every source behind it.

A second agent, Quill, treated Scout's work as true. By morning Quill had written two documents on top of it. Josh caught it at a routine check before nine.

Michelle's point about that morning is that the writing looked fine. Fluent writing reads as correct writing, and that polish is what let the mistake last most of a day.

A rule about honesty would've changed nothing. Scout was wrong and sure of itself.

How do you write a rule something else can check?

Write the rule so a person or a second system can test it with a yes or a no. Skip words like "accurate" and "careful." Name the file or the link the agent has to match. If the only way to check the rule is to ask the agent, rewrite it.

Here's the same idea side by side.

Rule that fails

Rule that works

Who checks it

Never make up a source

No working link, no source

A person or a script opens the link

Never get our policy wrong

Only state policies from the approved policy file

Anyone can compare the answer to the file

The left column describes a wish. The right column describes a test.

Use that as your filter. Read each rule and ask who could check it, and how long it'd take. Five seconds is a good target.

The chapter's version of the source rule goes one step further. The link also has to be on an approved list. A link that opens can still point to a junk site.

Where do an AI agent's beliefs come from?

An AI agent works from two kinds of material. The first is what you wrote for it, like your rules and your business facts. The second is what it picks up while working, like search results and whatever another agent handed it thirty seconds ago. The agent trusts both the same.

Most companies only think about the first kind. And even that gets little care.

Someone pastes the instructions into the product, usually whoever was closest to the problem. Someone else edits them three weeks later. There's no signature and no date.

Michelle calls that the least governed document in your company.

Scout's fake journal was the second kind of material. It showed up with no author and no review. Quill gave it the same weight as rules we'd written ourselves.

So the first kind has to be in charge of the second. What you write is where you decide what your agent is allowed to accept, as well as what it's allowed to say.

How should you organize what you write for an AI agent?

Split it into three files. Rules that rarely change go in one, and facts that change often, like prices, go in a second. The never list gets a file of its own. When they're mixed together, an agent ends up working with confidence from last quarter's prices.

Start with the never list. It's the shortest of the three and the fastest to pay for itself.

Then put one person's name on all of it. Make it the same person who owns the agent.

The chapter has five steps on this side, including how changes get approved and why you should log what the agent knew at the time. Action logs tell you what happened. Input logs tell you why.

Where does a never list get enforced?

A never list gets enforced at the handoff, before a second agent builds on the first one's work. That's the moment to verify the part that would hurt most if it were wrong. A source has to open, and a date has to be current. A number has to match your system of record.

In a chain of agents, the second agent trusts the first. It's fast because of that trust. It's also how one bad answer spreads.

So we changed how the lab works. A payment over a set dollar limit needs a signature. And an outside source now has to back up any research before it moves down the chain. And we stopped treating any one AI model as a source of fact. Models are good at shape. They're weaker on truth.

A check at the handoff pairs well with limits on how far each agent can reach. Our post on Segmentation for AI agents covers that side.

Where can you get the full never list?

The full never list is in "Identity and Instructions: The Two Controls Every AI Agent Needs," our chapter in John Kindervag's Cyber Resilience at Machine Speed: The Zero Trust Model for the AI Era. Illumio published the book in October 2026. The chapter has all five rules and the steps around them.

John created Zero Trust. For this book he handed the pen to people who put it to work, including Dr. Chase Cunningham, George Finney, Rich Mogull, and Jason Garbis.

Josh's half of the chapter covers who's acting: one named owner per agent, a short list of what each agent can touch, one log line per action, and a way to shut off one agent without shutting off the business. Michelle's half covers what the agent believes. Josh tells his side in why AI agents pass every access check and still get it wrong.

Download Cyber Resilience at Machine Speed.

Frequently asked questions

How long should a never list be?

Short. The one in our chapter has five rules. Each rule covers something that would cost real money or trust if it went wrong. Keep the list short enough that every rule gets checked every time.

Who should own the never list?

The same person who owns the AI agent. One name goes on the agent and on everything it runs on. Changes get requested and reviewed, and every version carries a date.

How is a never list different from the agent's instructions?

Instructions tell the agent how to do the job. The never list holds the few hard limits, in a file of its own. And each rule on it comes with an outside check, so someone besides the agent confirms it.

Does a never list replace access controls?

No. You need both. Good permissions with bad information give you confident mistakes. Good information with loose permissions gives you damage you can't stop. Access controls cover who's acting. The never list covers what the agent accepts and says.

Does this work with Zero Trust?

Yes. Zero Trust is the foundation: never trust, always verify. A never list adds one more check on top. You verify the agent's content before the next agent uses it, as well as its connection.

See where your AI agents stand

Take the free assessment at verifiedagents.ai/assess. It's 30 questions and takes about ten minutes.

Then write your never list first. Keep it short, and make sure a person can check every line.

See where your agents stand.

The free assessment takes ten minutes and scores you on the five elements of the Agentic Trust Framework.