The interesting move in PACE isn’t refusal — it’s that the reason to refuse is never in the request. It’s scattered across the user’s own history, and the assistant has to go find it before it can even decide whether to comply.

In production conversational AI, we pour effort into making the agent comply faster — better intent recognition, tighter slot filling, lower latency. PACE points at the opposite muscle: knowing when compliance is the wrong move because of something the user told you three sessions ago. That’s a knowledge-graph-plus-retrieval problem long before it’s a safety-policy problem, and treating it as guardrail classification will miss the entire class. The HF paper page has the abstract and code. If your assistant can’t retrieve the fact that makes a reasonable request wrong, is it safe — or just agreeable?

tags: [ conversational-ai ] [ rag ] [ agentic-ai ] [ research ]