Skip to content
Search
paperAugust 2026Unreviewed

Safety Does Not Compose: Non-Decaying Loop State for Autonomous LLM Agents

Chenmin Wu, H. Jia, Yang Liu, Ying-Guang Yang, Yu-Han Lin, Chong Zhang, Hao Zheng, Yu-Long Huang, Jian-Sheng Zhang, Yong-Zhi Qi, Shang Luo, Ke Xu, Jifeng Zhu, Bin Chong

Abstract

Large language model agents are increasingly deployed as autonomous loops. Starting from one human goal, such a system repeatedly discovers work, plans, executes tool calls, verifies outcomes and persists state across many unattended iterations. The agent safeguards in wide use, however, are defined over a single trajectory, and their safety state is re-initialized when the next trajectory begins. We show that this is a failure of composition rather than an implementation detail. Our central res

Categories

Cite

@misc{wu2026safety,
  title = {{Safety Does Not Compose: Non-Decaying Loop State for Autonomous LLM Agents}},
  author = {Chenmin Wu and H. Jia and Yang Liu and Ying-Guang Yang and Yu-Han Lin and Chong Zhang and Hao Zheng and Yu-Long Huang and Jian-Sheng Zhang and Yong-Zhi Qi and Shang Luo and Ke Xu and Jifeng Zhu and Bin Chong},
  year = {2026},
  month = aug,
  eprint = {2608.27141},
  archivePrefix = {arXiv},
  url = {https://www.semanticscholar.org/paper/106e267e5a85d840988eff8d6069a58ac4b313b5}
}