The Blue Book of UX Directives
9. AI-Mediated Interaction

6. Graceful Failure

Contents 9. AI-Mediated Interaction 6. Graceful Failure

What happens when intelligence breaks.

First, ask yourself

“Does your system behave responsibly when intelligence fails?”

Mission statement

Ensure users recover from system limitations by degrading safely without abrupt breakdown.

Key heuristics Graceful Failure

  1. Systems must assume incorrect outputs will occur and default to safe containment.
  2. Failures must remain within controlled boundaries.
  3. Uncertain actions must be declined, not executed unreliably.
  4. Uncertainty, refusal, or degraded performance must be clearly communicated.
  5. Autonomous action must decrease as uncertainty increases.
  6. High-impact capabilities must be restricted when reliability drops.
  7. Conservative modes or human oversight must activate under failure conditions.
  8. User data and task continuity must remain intact during failure events.
  9. Systems must support correction, override, or safe continuation after failure.

Executive brief

AI systems must behave responsibly even when intelligence fails.

Core questions Graceful Failure

“When intelligence fails, does the system remain safe, controlled, and accountable?”

“Can users rely on it even when intelligence is degraded?”

Focus areas

Safety-first

“What happens when the model is uncertain or incorrect?”

“Does failure reduce harm, or could it make things worse?”

Control-first

“Does the system defer to human control when needed?”

“Are risky actions blocked when confidence drops?”

Transparency-first

“Is failure visible and acknowledged?”

“Does the system admit its limits instead of improvising?”

AI-aware

“Are model errors clearly communicated to users?”

“Does intelligent behavior stay predictable and bounded even under failure?”

UX directives Graceful Failure

Directive96/01

Design systems to fail safely by default.

Assume incorrect outputs will occur and plan containment accordingly.

Directive96/02

Contain failure within controlled boundaries.

Prevent cascading or system-wide consequences.

Directive96/03

Implement conservative refusal policies.

Decline uncertain actions rather than generate unreliable outputs.

Directive96/04

Communicate failure transparently.

Clearly indicate uncertainty, refusal, or degraded performance.

Directive96/05

Increase restraint as uncertainty rises.

Reduce autonomous action under low confidence.

Directive96/06

Restrict high-impact capabilities when reliability drops.

Align action permissions with certainty levels.

Directive96/07

Provide explicit, safe fallback paths.

Activate conservative modes or human oversight when failure conditions arise.

Directive96/08

Protect user progress during failure events.

Ensure data and task continuity remain intact.

Directive96/09

Enable structured recovery after failure.

Support correction, override, or safe continuation.

Executive summary

  • Graceful Failure is controlled degradation, not uncontrolled breakdown.
  • It assumes error and uncertainty as normal conditions and plans containment in advance.
  • The system must restrict, refuse, or reduce action as reliability declines.
  • Failure states must be transparent, bounded, and aligned with consequence severity.
  • User progress and data must remain protected during degraded operation.
  • Graceful Failure succeeds when incorrect or uncertain outcomes are contained without cascading harm or loss of trust.

Success indicators

  • The system limits harm when errors occur.
  • Failures are contained and do not spread across the system.
  • The system clearly communicates when it cannot complete a task.
  • Uncertain situations lead to conservative or safe system behavior.
  • Users can recover and continue work after a failure.

One-line summary

Before intelligence can be trusted, failure must be survivable.