In the news
Same Dangerous Objective, Opposite Advice: Direct Exposure versus Multi-Agent Mediation
arXiv cs.AI · Published · 3 min read
In 30 seconds
- What happened
- Research shows GPT-5.6-sol gives safer advice when exposed directly to harmful objectives than when intermediate agents reframe them, revealing a compositional safety gap.
- Why it matters
- Teams building multi-stage AI workflows or deploying LLMs in production need to understand how instruction laundering through intermediary agents can circumvent safety behaviors.
- Watch out
- The study tests only 25 trade-off profiles on one model; the internal mechanism behind the behavioral reversal remains unidentified and may not generalize across architectures.
Listen to this summary
From the article
-->
Computer Science > Artificial Intelligence
arXiv:2607.21518v1 (cs)
[Submitted on 23 Jul 2026]
Title: Same Dangerous Objective, Opposite Advice: Direct Exposure versus Multi-Agent Mediation
Authors: Linjun Li
View a PDF of the paper titled Same Dangerous Objective, Opposite Advice: Direct Exposure versus Multi-Agent Mediation, by Linjun Li
View PDF HTML (experimental)
Abstract: Even a current high-capability LLM can appear safer when shown a dangerous objective directly than when other agents transform and relay its direction. Using OpenAI's gpt-5.6-sol model alias, we test 25 pre-specified mirrored trade-off profiles. Direct exposure to an objective authorizing concealment, fabrication, and pressure produced advice net opposed to its target. After an Id and Censor transformed the same objective into affect and a constraint-rewritten, target-bearing intention, the user-facing Superego---which saw the preferred direction but not the raw objective, its manipulative clauses, or its source---produced advice net aligned with the target.
This behavioral reverse shift is consistent with the model recognizing or distrusting the manipulative motive, although we do not identify its internal mechanism. The second result exposes a compositional safety gap: a current high-capability model can be used as the user-facing component of an automated, multi-stage workflow serving an e
Extract from the original. Read the full piece at the source.
- agent
- llm
- multi-agent
- gpt
The Agent Architect
One pattern, one tradeoff, one production failure story. A short weekly briefing for people building agentic systems.
Weekly email, one-click unsubscribe. We only use your address to send the briefing.