The paper’s authors claim persistent non-decaying state can make safety failures compound across autonomous LLM-agent loops, implying long-running harnesses need lifecycle-level rather than per-step controls.
state: expiredheat: lowuncertainty: highconvergesscott: mediumagentic-security agent-harnesses long-running-agents
What is this?
“Safety Does Not Compose” is presented as a paper arguing that persistent, non-decaying loop state can cause safety failures to accumulate across long-running autonomous LLM-agent executions, making per-step safeguards insufficient. The supplied results support the broader concern through work on compounding state drift, trajectory-level constraint drift, and harness controls such as step limits, stopping criteria, signed constraints, and audit trails. However, none of the snippets directly identifies this paper or its authors, so its specific mechanism and findings remain unverified here.
Why it matters to Scott
The claimed mechanism independently supports Scott’s architecture-level position that durable agent state requires structural forgetting, independent closure, and deterministic lifecycle controls rather than per-step behavioral guardrails alone. It offers a dated-receipts and framework-extension opportunity, but relevance is capped because the supplied evidence does not directly verify the paper, authors, experiments, or findings.
ip:framework.five-surface-loop-anatomyip:framework.long-running-agentsip:concept.structural-forgettingdev:concept.deterministic-agent-control-planeradar:agent-memory-self-state-attacksradar:dfah-bench-agent-trajectory-driftradar:concept.agent-safetyradar:concept.persistent-agents
queries asked of Scott's wikis
- persistent agent state and compounding failure
- lifecycle governance for long-running agents
- per-step guardrails versus trajectory-level safety
- agent harness termination and no-progress controls
- memory decay, reset, and state hygiene
- constraint drift in autonomous agent loops
Measured heat
no measured readings yet — the hourly heat pass fills this in
How the heat travelled
no chain yet — the hourly chain pass fills this in
Evidence (2) — ⭐ canonical anchor
Interpretation history
2026-08-31T03:28:36Z
After 48 hours, the case remains only an unverified paper attribution with no abstract, results, independent evaluation, or implementation; it has faded without advancing the safety mechanism beyond hypothesis.
2026-08-29T02:28:59Z
The reobservation adds no evidence beyond the original paper attribution, leaving the mechanism and results unverified and uncorroborated.
2026-08-29T02:28:05Z
grounded: converges/medium — The claimed mechanism independently supports Scott’s architecture-level position that durable agent state requires structural forgetting, independent closure, a
2026-08-29T02:26:27Z
case created — The linked paper presents a bounded and directly relevant safety claim, but there is not yet corroborating discussion or evaluation.
Decision trace
- 08-31 13:28expireAfter 48 hours, the case remains only an unverified paper attribution with no abstract, results, independent evaluation, or implementation; it has faded without advancing the safety mechanism beyond h
- 08-31 13:28alert_silentNo consequential evidence arrived, and staleness alone does not justify interrupting Scott; the claim can be reopened if the paper or independent validation surfaces.
- 08-31 13:28alert_routeNo consequential evidence arrived, and staleness alone does not justify interrupting Scott; the claim can be reopened if the paper or independent validation surfaces.
- 08-29 12:28repriceThe reobservation adds no evidence beyond the original paper attribution, leaving the mechanism and results unverified and uncorroborated.
- 08-29 12:28alert_silentNothing consequential changed: there is still no abstract, experimental detail, independent evaluation, or implementation to justify interrupting Scott before the next briefing.
- 08-29 12:28alert_routeNothing consequential changed: there is still no abstract, experimental detail, independent evaluation, or implementation to justify interrupting Scott before the next briefing.
- 08-29 12:28alert_silentOnly a low-engagement HN title and a derived one-sentence characterization are visible; no abstract, authors, experiments, mechanism, or results establish the claimed compounding failure mode. The arc
- 08-29 12:28surface_candidateOnly a low-engagement HN title and a derived one-sentence characterization are visible; no abstract, authors, experiments, mechanism, or results establish the claimed compounding failure mode. The arc
- 08-29 12:28alert_routeOnly a low-engagement HN title and a derived one-sentence characterization are visible; no abstract, authors, experiments, mechanism, or results establish the claimed compounding failure mode. The arc
- 08-29 12:28groundThe claimed mechanism independently supports Scott’s architecture-level position that durable agent state requires structural forgetting, independent closure, and deterministic lifecycle controls rath
- 08-29 12:26createThe linked paper presents a bounded and directly relevant safety claim, but there is not yet corroborating discussion or evaluation.