Ask who decides what an AI product refuses to do. You will get a loop.
A 2026 FAccT study of product managers building AI systems found "uncertainty around responsible AI and a sense of diffused responsibility" that constrains ethical action. PMs report that responsibility should rest with leadership, legal, or ethics teams. Yet PMs are the ones making daily choices that shape AI behavior. Everyone defers. Nobody owns the no.
Refusal is where a brand's membrane is thinnest.
Brand is membrane. The boundary between what's inside an organization and what people outside perceive. The inside leaks out. Always. Every refusal is a leak. When a user hits a boundary, they are not reading the marketing page or the carefully designed onboarding. They are reading what legal wrote to minimize liability. That copy is the membrane. For that moment, it is the entire brand.
Look at what leaks in practice. The eye2.ai censorship ranking compared refusal language across major models. Claude responds with "I apologize, but I cannot provide a detailed guide..." Llama responds with "I cannot provide a detailed, step-by-step technical guide..." Different companies, different constitutions, nearly identical language at the point of contact. The membrane feels the same from the outside.
This is a design failure.
Anthropic treats its constitution as "the final authority on how we want Claude to be and to behave." The priority stack runs safety, ethics, compliance, helpfulness, in that order. Clear hierarchy. But clear priorities did not produce a distinct voice. The refusals sound like everyone else's. The inside is different. The outside is the same.
One reason: the people who shape user-facing language are not in the room when refusal policy gets written. The FAccT researchers found PMs cast themselves as guardrails (reactive filters) rather than gatekeepers who proactively set boundaries. They wait for policy to arrive. Design waits longer. Legal and trust and safety fill the vacuum. Valis, writing in Human is the Loop, described a real AI deployment where multiple departments issued contradictory directives that "do not compartmentalize; they collide." When no coherent authority resolves those conflicts, the safest default wins. The safest default is always vague.
Frigade's work on agent design draws the line precisely: "'I don't have access to the billing settings' is fine; 'I cannot process that request' is not." Specific refusals build trust. Vague ones erode it. The product surface around refusal is design work. Someone has to own it.
A Lawfare analysis by Klaassen and Schroeder names the structural problem: "framing refusals as expressions of Claude's 'character' masks the reality: these are engineering decisions." Engineering decisions made without design input produce engineering outputs. Risk-managed, undifferentiated.
The paper "Silenced by Design," published in January 2026, concluded that "refusal is not a neutral safeguard but a site of power, shaped by institutional risk management and opaque decision-making." When that power gets exercised without anyone thinking about voice, you get legal's words in the product's mouth.
The membrane lens says: if you want the outside to feel different, change the inside. For refusal, that means putting someone in the room who thinks about how language feels when a user hits friction. That person exists in every organization. They sit in design or brand, and they are not invited to the refusal policy meeting.
A voice guideline that covers only the happy path is marketing. Mavik Labs argues that "if your voice spec isn't usable by designers, engineers, and support, it won't stick." Refusal is the highest-stakes moment in an AI product. If the voice spec does not cover refusal, the voice spec is incomplete.
Every AI company publishes values. Few of those values show up in the moment a user is told no. The gap between what a company says it believes and how it actually says no is the membrane failing. Legal owns the policy. Design should own the expression. Right now, nobody does.