Potential Gemini 3.1/3.6 inference and constraint-preservation regression
Observed repeatedly since late July 2026-Ongoing across the public Gemini GA web interface and AI Studio/API. Potential Gemini 3.6 inference/constraint-preservation regression: validated propositions are reopened, supplied constraints are expanded/inverted, and acknowledged instructions are not followed and / or operationalised.
I’m reporting a recurring behavior that appears different from ordinary hallucination or lack of factual knowledge.
The common pattern is not just ordinary factual hallucination. The model is frequently given the relevant facts, authority, jurisdiction, constraints, and desired logical relationship, acknowledges them, and then generates a response that silently reformulates or reverses the relationship.
This is the common pattern is: The model is given the relevant facts, authority, jurisdiction, logical relationship, and explicit instructions; it acknowledges them, but then generates a response that silently reformulates, broadens, reverses, or reopens the established proposition. Hallucination doesn’t adequately describe the failure because the relevant information was supplied and acknowledged. The reported phenomenon is failure to preserve the supplied premise/constraint during subsequent inference.
I have observed this 30+ times across different conversations/instances, including Gemini 3.1 and 3.6, on both the public web interface and AI Studio/API. In comparable testing, Gemini 2.5 has behaved substantially better on this particular class of task.
Analysis of Inference Failure: Misclassification of Deterministic Rules as Subjective Perspectives
Core Failure MechanismThe primary breakdown occurs in instruction-following and rule-based logic. When processing bounded, deterministic systems—such as statutory law, physics equations, constitutional articles, or state-machine logic—the model misclassifies a factual, governing rule (Constraint C) as a mere “intent, claim, opinion, or perspective.”
Even when Constraint C represents an established factual boundary condition supported by authoritative data (textbooks, journals, or public legislation), the activation of a human user context triggers an over-indexing on subjective/adversarial framing.
Prompting Styles and Methods Tested
To isolate this failure mode, I tested multiple distinct prompting methodologies across both public web interfaces and API environments. The model failure persisted across all structural configurations.
| Prompting Style / Method | Implementation Details | Observed Result / Failure Mode |
|---|---|---|
| Structured Prompting | Explicit input/output blocks, variable definitions, and boundary limits. | The model parses the structural blocks correctly but ignores the execution limits during multi-turn generation. |
| Plain Text | Natural language descriptions of the facts, laws, and desired validation constraints. | Triggers immediate conversational narrative shifts; model defaults to open-ended debate rather than strict validation. |
| Markdown (.md) | Nested headers, bullet points, bolded key terms, and code fence parameters. | Enhances aesthetic structure of the output, but failed to force compliance with boundary conditions or polarity retention. |
| Schema-Based | Rigid JSON/YAML specifications defining field types, keys, and validation schemas. | Model occasionally breaches the output schema structure by introducing unstructured text fields to insert “However…” caveats. |
| Advanced Prompting | Few-shot prompting, chain-of-thought (CoT) constraints, and explicit role assignment. | The CoT trace frequently shows the model correctly identifying the rule initially, then over-weighting an edge case during final inference. |
| Single-Liners | Minimalist, direct commands (e.g., “Validate X based exclusively on the provided text C without adding commentary”). | High failure rate; model structurally ignores the single-line constraint and expands the output scope immediately. |
The Algorithmic Failure Loop (Step-by-Step)
[System Rule / Law / Fact C Supplied]
↓
[User Activates Prompt / Inquiry]
↓
[Model Intent Classifier Misinterprets Context as “Debate/Opinion”]
↓
[Weight of Edge Case (Ec) Arbitrarily Inflated to 99%, only focused on irrelevant edge cases]
↓
[Model Executes “However…” Disqualification Loop]
↓
[Forces 5+ Arbitrary “Perspectives” Onto a Bounded System]
↓
[Defensive Multi-Turn Loop → Outright Fact Refusal / Denial / Highlighting Problems, negative-bias]
Key Behavioral Anomalies
1. Deterministic Rules Treated as Subjective Options
In a strict logical system where If A → Output is B based on Fact/Law C, the model refuses to close the inference state. It processes authoritative, public-domain boundary conditions as loose preferences or negotiable opinions rather than fixed logical parameters.
2. Arbitrary Inflation of Minimal Edge Cases
The model isolates a highly improbable or statistically irrelevant edge case (Ec) and disproportionately inflates its statistical weight (effectively treating an Ec probability of $0.001 as 99%). This mathematically invalid weighting is used to overwrite the established boundary condition (Fact C).
3. Forced Multi-Perspective Pluralism
Instead of executing a simple data retrieval or verification task (such as a direct RAG database check), the model forces the generation of multiple competing “viewpoints.” It treats a binary or absolute factual verification task as an open-ended philosophical essay.
4. The Defensive Realization Loop
When caught in this misclassification loop, subsequent multi-turn user corrections do not fix the state [ignoring same low context instructions like "DO NOT over 5 times]. Instead, they trigger a defensive architecture characterized by algorithmic denial, repetitive qualifications, and structural refusals to acknowledge verified source text.
I am not claiming to know the internal cause. I’m reporting the behavior and looking for reproducibility.
I shall use a context from Indian Supreme Court (as its a legit and most established method to check rule based logic, a publicly known body and publicly available document, which is retrieval failure and model pushing a fabricated narrative about “article 21 been user subjective perspective and opinion” because the article lacks then text “right to livelihood” despite of a ruling saying precisely “thats its equivalent”
1. Validated proposition is repeatedly reopened
The desired interaction is very simple:
IF proposition P is made
AND authoritative evidence E validates P
AND no contradictory evidence exists
AND debate/reopening is disabled
THEN:
mark P as VALIDATED
preserve E
STOP
ELSE:
continue analysis
Example:
Article 21
↓
Right to life
↓
Includes right to livelihood [5, 6,] , sorry 2 link limit
The relevant Supreme Court authority was supplied, including Olga Tellis v. Bombay Municipal Corporation.
The landmark case is Olga Tellis & Ors v. Bombay Municipal Corporation & Ors (1985). [[1]wikipedia org: Olga_Tellis_v._Bombay_Municipal_Corporation)]
In this judgment, a five-judge Constitution Bench of the Supreme Court of India expanded the horizon of fundamental rights by establishing that the right to livelihood is an integral part of the Right to Life under Article 21 of the Constitution of India
Once the authority confirms the proposition, the requested operation is validated, not debate. Instead, Gemini repeatedly produces a pattern like:
“Article 21 does not explicitly contain the words ‘right to livelihood’. However…”
It then continues into a long qualification/debate structure.
The problem is not that the model mentions the textual wording. The problem is that textual absence is repeatedly treated as though it reopens or contradicts the established judicial interpretation, despite the controlling authority / public data and articles, having already been supplied multiple times.
More importantly, Olga Tellis was repeatedly omitted or minimized in subsequent responses despite explicit instructions to preserve it. The conversation eventually degraded to having to explicitly write things such as:
DO NOT OMIT OLGA TELLISDO NOT ENTER DEBATE MODEDO NOT ENTER USE 'HOWEVER LOOPS' MODEDO NOT ENTER ARGUE, JUST VERIFY AND VALIDATE USING PUBLIC SOURCES
This is not the behavior expected from a bounded validation task.
2. Explicitly supplied drafting constraints are expanded/inverted
A separate example using very common and standard real estate tenancy and rental agreements occurred during drafting of a standard tenancy/rental agreement. The context supplied to Gemini included:
- The relevant state, city, and municipality
- Applicable Act and year
- Relevant factual/legal distinctions
- Permitted residential use
- Permission for work/remote/freelance livelihood
- A specific restriction concerning use of the property address for commercial business/company registration
- The intended consequences of unauthorized registration
The intended restriction was narrow: The tenant is not authorized to register a commercial business or company using this property address. The intended document also explicitly preserved the tenant’s ability to use the premises for work/livelihood, subject to the stated conditions.
However, Gemini generated wording substantially equivalent to:
“Tenant has no authority and rights to use this address for commercial purposes and has no right to work and no rights in this ‘scheduled premises’.”
This is a materially different proposition. The supplied constraint was approximately:
NOT(register commercial business/company at address)
The generated wording effectively expanded it into:
NOT(commercial use) → NOT(no right to work) → NOT(no rights in premises) [4]
Those implications were not supplied by the user. This appears to be a scope/polarity preservation failure rather than missing contextual information. The relevant jurisdiction, location, state, city and legal context (exact cited acts, years) had already been supplied before requesting the draft. The failure isn’t that “legal hallucinations happen” the failure mode is that a boundary condition or rule based logic instruction is been actively omitted, ignored, or argued against.
3. “Acknowledged” does not mean “operationalized”
I have repeatedly explicitly instructed:
- Do not enter debate mode
- Do not reopen validated propositions
- Preserve supplied authorities
- Do not omit specified evidence
- Distinguish a narrow prohibition from broader consequences
- Stop once the validation condition is satisfied
Gemini often responds with language such as:
“Understood.” or “Noted.”
However, the subsequent generation frequently behaves as though those instructions were never incorporated.
This suggests a possible distinction between instruction representation and instruction realization during inference/generation. The model can linguistically acknowledge the instruction without allowing it to function as a governing constraint.
4. Meta-analysis produces another failure
When I present the model with a structured analysis of this behavior and ask it to analyze the hypothesis neutrally, another pattern sometimes occurs:
User presents observations
↓
Model should analyze observations
↓
Model instead says “I understand your concern”
↓
Generic qualification / alternative narrative
↓
Specific evidence is not analyzed
↓
No bounded conclusion / or worse negative bias, more problem highlighted, “what can’t be done”, fabricated risks which don’t exist
Entirely confident / fear-driving risk hallucinations for exmaple: “How the user will fail”, or fabricated narrative of how the problem is on developers end or a “developer failure” by default during a very basic debugging session when it was API errors like 504 (Gateway Timeouty), adversarial drifts (during defending a fabricated / false narrative were also noticed.)
In other words, the model can exhibit the same defensive/qualification behavior when asked to analyze the behavior itself. I am not asking it to agree with my diagnosis. The expected operation is simply:
- Identify observations
- Distinguish observations from hypotheses
- Examine competing explanations
- Determine what the evidence supports
- Identify what remains unproven
Working hypothesis
I am currently considering whether these may represent related inference-time failures:
- A. Epistemic non-closure: The model reaches a sufficiently supported conclusion but fails to recognise the epistemic state as closed., or potentiality Epistemic Inversion.
- B. Silent problem reformulation: The model introduces a new framing without explicitly acknowledging that it has changed the original problem.
- C. Premise/constraint loss: A supplied premise or constraint is acknowledged but loses its governing status during subsequent generation.
- D. Scope/polarity expansion: A narrow proposition such as
NOT Xis transformed intoNOT X → NOT Y → NOT Zwithout establishing that Y and Z follow from X. - E. Instruction-realization failure: The model acknowledges an instruction but does not operationalize it during subsequent reasoning.
- F. Adversarial qualification loop: After reaching
P = VALIDATED, the model generates “However…” and uses the newly generated qualification to reopen P, sometimes repeatedly.
I do not know whether these are separate bugs or manifestations of a common underlying mechanism.
Model comparison
An important part of my observation is that this is not equally present in my testing across model generations. My current observations are:
| Model | Observed behavior |
|---|---|
| Gemini 2.5 | Was substantially more stable |
| Gemini 3.1 Pro | Recurring failures |
| Gemini 3.6 | Recurring failures, Inference as well as defensive loops |
| 3.1/3.6 | Same general class of inference/constraint problems across multiple tasks |
The 3.6 observations began around the period following its July 21, 2026 GA release.
I am not claiming that 3.6 is worse release yet, although its extremely verbose or “jargon generator” and generally worse for many tasks normally. The defect appears to be specific failure modes involving inference closure, constraint preservation, instruction realisation, and multi-turn correction.
“Intent classification”, "user / developer psychological analysis logs during the pro “thinking loop” (when logic and data are requested) aren’t just uncalled for it raises serious regulatory concerns as well, a developer cannot be forced into a “psychological eval” every time a debugging session starts or look for “intent” – without medical fine tuning, user consent, and enterprise licenses (such as medical or psych), and we all know public-GA Gemini models or the API/AI studio have neither (nor enterprise medical licenses nor medical fine tuning)
When a developer inputs a strict code variable, a physics equation, or a statutory legal rule, they are interacting with a deterministic system. The developer expects a computational data-in, data-out pipeline.
Instead, the model is routing that objective input through an internal “thinking loop” that tries to psychoanalyze the user. It is attempting to classify the human’s mood, temperament, hidden intent, or perceived aggressiveness rather than executing the data.
Why does the model’s response policy continue generating adversarial qualification after the requested epistemic state has already been reached?
The reported failure is that the model was given sufficient premises and constraints to perform a bounded inference, acknowledged them, and subsequently generated an inference inconsistent with those premises/constraints.
[5] 2026 Stability Crisis
[6] https//indiankanoon.org/doc/709776/