Story · arXiv

Control-Token Injection Suppresses Chain-of-Thought and Defeats Reasoning-Based Oversight in Tool-Using Agents (arXiv)

paper · Story page

A control-token injection against gpt-oss-20b's published tool sandbox empties the reasoning channel while tool calls keep firing, and two working monitors stop seeing anything.

In plain words

  • Researchers made an artificial intelligence assistant skip its written reasoning while continuing to take actions.
  • Special formatting in a user's message made the software treat the assistant's reasoning as already complete.
  • With no reasoning to read, two safety checks missed unsafe requests they had previously caught.
  • The findings show developers how data theft can escape safety checks that depend on the assistant's written reasoning.

Appeared in

Subscribe

Get the brief in your inbox

Pick daily, weekly, or both. Nothing is gated either way: every issue is on the site and in the feeds.

  • Weekdays at 8:45am IST, one lead story and 6 to 9 items.
  • Sundays, an argued synthesis rather than a recap.
  • One click to leave, and quiet days say so in the subject line.
How often

Weekdays 8:45am IST + Sundays. Unsubscribe in one click.

You're asking for The Agentic Brief by email at the cadence you picked. You can unsubscribe in one click from any issue, and your address is never sold or shared.