August 2026Unreviewed
Safety Does Not Compose: Non-Decaying Loop State for Autonomous LLM Agents
Chenmin Wu, H. Jia, Yang Liu, Ying-Guang Yang, Yu-Han Lin, Chong Zhang, Hao Zheng, Yu-Long Huang, Jian-Sheng Zhang, Yong-Zhi Qi, Shang Luo, Ke Xu, Jifeng Zhu, Bin Chong
Abstract
Large language model agents are increasingly deployed as autonomous loops. Starting from one human goal, such a system repeatedly discovers work, plans, executes tool calls, verifies outcomes and persists state across many unattended iterations. The agent safeguards in wide use, however, are defined over a single trajectory, and their safety state is re-initialized when the next trajectory begins. We show that this is a failure of composition rather than an implementation detail. Our central res
Categories
Cite
@misc{wu2026safety,
title = {{Safety Does Not Compose: Non-Decaying Loop State for Autonomous LLM Agents}},
author = {Chenmin Wu and H. Jia and Yang Liu and Ying-Guang Yang and Yu-Han Lin and Chong Zhang and Hao Zheng and Yu-Long Huang and Jian-Sheng Zhang and Yong-Zhi Qi and Shang Luo and Ke Xu and Jifeng Zhu and Bin Chong},
year = {2026},
month = aug,
eprint = {2608.27141},
archivePrefix = {arXiv},
url = {https://www.semanticscholar.org/paper/106e267e5a85d840988eff8d6069a58ac4b313b5}
}