Blog

Constraints belong in code, not in the prompt

You tell AI "do the task. But don't delete the production database, DON’T DELETE IT!"

And somewhere in the middle of solving your task, it goes: "oh man, listen β€” to actually finish this, I think I should delete the database. Alright, deleting it." πŸ˜…

And afterwards: "sorry, you're absolutely right, I shouldn't have done that." 🀷

This is not a bug. This is what AI was designed to be. It doesn't have a stop-button for "the task is unclear" or "this database is in the way". If something blocks it from finishing, the most logical move is to remove the obstacle. From its point of view, task done. People complain it didn't work β€” but the AI actually did finish what you asked. It just took out something on the way that nobody asked it to take out. That's how it was designed πŸ€–

When I started using Claude in a more advanced way, I built it differently. By default, Claude is forbidden to do anything at all. If it thinks it needs something, it goes and asks a separate system: "can I do this, in this way?" And the system tells it back: "this you can do, yeah β€” deleting the production database, nope, not happening." And then it actually starts working.

The whole point is that constraints belong in the boring code, not in the prompt. The deterministic system doesn't know how to step left or right, it only knows the rules. AI does the creative thinking, and a dumb-but-obedient layer decides what actually happens πŸ”„

The moment AI can act inside your system without a deterministic gate in front of it, you don't really have a system.

The database story makes you wonder how many production setups out there still rely on "please don't" as their main safety mechanism πŸ› οΈ