AIIC AI Intelligence Centre

SOURCE-LINKED INTELLIGENCE

Safety Does Not Compose: Non-Decaying Loop State for Autonomous LLM Agents

arXiv · AI, language, vision and robotics · article · Aug 27, 2026 · UTC

Large language model agents are increasingly deployed as autonomous loops. Starting from one human goal, such a system repeatedly discovers work, plans, executes tool calls, verifies outcomes and persists state across many unattended iterations. The agent safeguards in wide use, however, are defined over a single trajectory, and their safety state is re-initialized when the next trajectory begins. We show that this is a failure of composition rather than an implementation detail. Our central result is a separation: against an attack whose evidence is fragmented across several iterations, every

Read original source ↗ Open in workspace

recordType
paper
region
Global

Evidence & attribution

First collected: 2026-09-21T08:32:02.028Z. This is not the publication date.