The issue you are seeing with Gemini 3.8 is a known symptom of conversational prompt drift, not an inherent degradation of the underlying reasoning engine. When an agentic LLM begins creating phantom files, introducing unrequested helper functions, and ignoring explicit prohibitions, it is almost invariably the result of three specific architectural anti-patterns:
1. The Token Attention Trap of Bare Negative Constraints
Randal rightly points out the “pink elephant” phenomenon, but the mechanics go deeper into transformer self-attention. When you prompt:
“Don’t create new files. Only do this.”
The attention heads attend heavily to the high-entropy semantic tokens: create, new, files. In a high-temperature or complex reasoning turn, the model computes probability vectors based on semantic proximity. A bare negative constraint frequently acts as an attention magnet, priming the model to generate the exact behaviour you sought to forbid.
The Fix - Paired Invariant Framing: Never supply an isolated negative constraint. Every constraint must be formulated as a strictly paired invariant: an explicit positive mandate coupled to a bounded negative exclusion:
- Sub-optimal: “Don’t create any files.”
- Architecturally Sound: “Positive Mandate: Restrict all edits exclusively to existing lines within
src/controller.js. Negative Constraint: Absolute prohibition on instantiating new files on disk.”
2. Context Decay and the Fallacy of In-Chat Governance
You noted that you give rules, the model replies “okay got it”, and then forgets them on the subsequent prompt.
An in-chat acknowledgement (“okay got it”) is ephemeral conversational fluff. In a multi-turn chat, your rules compete against the system prompt, tool schemas, and recent conversational history. As context length expands, conversational instructions undergo severe recency degradation.
The Fix - Root Ingestion:
Operational guardrails must never be negotiated in chat turns. They must be anchored at the root instruction layer:
- If you are operating in Google Antigravity or an agentic IDE, anchor them in your workspace
AGENTS.md or system instructions.
- System-level instructions are injected into the model’s pre-turn context on every single invocation, entirely immune to conversational decay.
3. Execution Gating (Decoupling Planning from Tool Invocation)
When you ask an agentic model to evaluate a problem, its default bias is action-oriented: it attempts to immediately satisfy the user by calling file-creation tools or writing exploratory boilerplate.
If you do not want unrequested code or files:
- Enforce Phase Gating: Explicitly mandate that the model operates in a two-phase lifecycle:
- Phase 1 (Exploration & Advisory): The model is restricted to analytical text output only. Zero tool calls or file writes permitted.
- Phase 2 (Targeted Execution): Triggered only after you explicitly approve a numbered, single-step blueprint.
- Deterministic Tool Gating: If your environment exposes tool permissions, require user confirmation for write/creation operations while leaving read tools automated.
Gemini 3.8 has exceptional reasoning depth, but like any advanced engine, attempting to govern it through unstructured conversational chat will inevitably result in scope creep and boundary violations. Structure the guardrails at the system layer with paired invariants, and the model’s consistency transforms overnight.