AbstractAI assistants revert to their own defaults unless something structural stops them. What that structure is, and whether it holds, is the subject of this field report: one operator's live production system, observed across roughly seventeen weeks while the platform changed underneath the work. The companion paper, The Feed Loop, established that a prohibition written into a persistent governance file reproduces the very pattern it was written to suppress, and proposed purging the contaminating file as the fix. This was proposed as the contAIn™ method. This paper takes the next step and reports what holds in its place: structural gates and positive criteria.In hard-gated project work, a prohibition is harmless, because the gate, not the rule, does the enforcing. In ungated, personality-bearing writing work, the same prohibition self-contaminates, because a file that must name what it forbids is read at the start of every session, re-seeding the pattern it bans. Purging those files, the companion's fix, does not hold on its own: the adversarial gate keeps long-running failures such as em dashes and staccato off the page, with the residual monitored. The controls hold in both environments. The constant across both, the thing that makes the record and the recovery possible while the platform keeps moving, is the human above the loop, directing the system rather than deferring to it, catching failures by hand. In this record, 112 catches were logged.The evidence is a dated, failure-only register of 705 classified failures across 227 sessions, logged between 21 February and 18 June 2026. The count and the origin are distinct: the 705 failures are the structured register, while the governance and gates themselves reach back to a December 2025 origin in a separate production project, documented in the narrative handovers that predate the register. Paper 1 named the mechanism in the writing environment; this paper reaches back to the December gated origin, the property project then the planning project, to report the contrast across both environments. The contribution is the documented production contrast and the scope condition that governs it: prohibition-based AI governance fails where governance is broad, personality-heavy and ungated, and gate-and-criterion AI governance holds where work is rules-based, judged on specific criteria, and enforced by structural gates.This paper was drafted by the kind of system whose failures it documents, and some of those failures occurred in its own making.