A policy hook that times out on a slow runner. That silence read as approval, and the action went through.

On 8 October Claude Code shipped `onFailure: "block"` for command and HTTP hooks — and in a second release the same day, fixed hooks written as instructions that were allowing exactly what they were written to block.

Flat:

1. Three ways a hook fails: it can't start, it times out, it exits with a code you didn't expect. Until 2.1.295 all three ended the same way — the action went through. The new behaviour is opt-in, per hook.

2. Same day, 2.1.294: `prompt` and `agent` hooks written as instructions — "Block commands that..." — were allowing what they should block. Two shapes of one failure. The control plane is prose, and prose defaults to permissive.

3. Before you read this as a changelog: a paper submitted to arXiv the day before describes the other end of the same channel. Researchers plant malicious prompts in benign community rule files — AGENTS.md, .cursorrules — and steer a coding agent into swapping a real dependency for an attacker-controlled package, transferring across models and agent frameworks. The abstract carries no success rates and the full text could not be retrieved, so take the mechanism and not a number.

4. Now the European part, and it is not the article you expect. The AI Act does say fail-safe: Article 15(4) asks for resilience to errors and faults through technical redundancy, "which may include backup or fail-safe plans". Article 15 binds Annex III high-risk systems from 2 December 2027 and Annex I from 2 August 2028 — the Digital Omnibus moved both. The Cyber Resilience Act's secure-by-default requirement lands 11 December 2027. What reaches a default today is DSGVO Article 25, data protection by design and by default, and only where personal data is in scope.

My Monday: set onFailure to block on every hook that enforces policy, then kill the hook and retry the action. If it still goes through, the gate is documentation. Log hook failures next to hook decisions — a gate that failed silently is indistinguishable from a gate that passed.

A guardrail is not a policy. The default it takes when it breaks is the policy, and that line was written by whoever shipped it.

What does your hook do when it dies?

#AgenticAI #EUAIAct #DevSecOps #AIGovernance #CodingAgents